Jump to content

El Tel

Advanced Member
  • Content Count

    322
  • Joined

  • Last visited

Everything posted by El Tel

  1. Hi Thanks for the help, Team-viewer is up and working as this reply is from "Remote Access" You are a "Star Man" Now to find a place to sort out Skype update from MSN. While I was connected up he Said why don't we try Skype, we used to MSN all the time, but never bothered to Up-Date to Skype. I've got Skype working on my PC, that up-dated with no problem; but when I try it on here It stops with this Can't put a picture in here? Anyway off to find a "Topic Slot" for Help Regards El Tel
  2. Hi ... I've dragged this topic out the past as it just about covers my needs and to give the kind people who have already replied the recognition they deserve. My requirements. That being to access my "Brother In Laws" PC some 40 miles away from the comfort of my home. I have to connect up on a regular basis, even if it is just to allow / block a pop up, find a file. This I've found to be far easier than have him turn up on the doorstep with his tower unit in hand. He would first phone me Saying "Hi Bro, what are you up to right now" ... (The door Bell would ring, I would say, "Hang on someone is at the door" ... He would say ... "It's me, put the kettle on and could you fix this while I'm here, (I would have opened the door by now ... ROFL ... "What's up") I've locked mi'sen out of "Whatever" or this no longer works" I hope you kind of guess my dilemma. I have used "NTR Connect" but that stopped working, and one other; but for life of me I can't remember what that was. Probably because it was to hard to use. Please bear in mind that I'm only ONE-UP from a ID 10 T ... PC user myself ... ROFL ... BadBinary gave the above link, to which I already use "LogMeIn"; but this is were my dilemma starts. As of today 21 January 2014, with no prior E-Mail warning; apart from "LogMeIn is no longer FREE" (I just LOVE that word FREE) Therefore I'm busy searching for a FREE alternative. Before I go off and try "Team Viewer" is it still FREE and will I need my "Brother In Law" to bring his tower unit to me first, so that I can remove LogMeIn.? XPS9000 link looks way over my head ROFL. But I did note paragraph 2 about "File Sharing" This I have mastered with "Allway Sync" My Favorites into "Drop Box" taking full advantage of the FREE extra space by sending an "Invite" to "Drop Box" first, accept it; then do the reverse of the remote PC once I've set it up. Therefore when I'm connected up to his PC, it is the same as mine; more importantly all my stuff is backed up. And vise-a-versa. Well that's my "TIP" not my best tip, that would be ... "Never put a "Bulb" in your back pocket and sit down" ... ROFL Regards El Tel
  3. Hi Stamford Glad you have it sorted now, as for the shop "Re-selling" good as new. They need excommunicating. Regards El Tel
  4. Hi Have you tried the default password for your existing router, if you haven't change it. Failing that I would try to reset it to the factory default as in page 4 of the manual you supplied, as it could have been changed by the previous owner. Regards El Tel
  5. Hi. Something similar happened to me when a friend had cleaned the laptop while she waited for some updates to finish and had accidentally turned off the Wireless function ie: like in flight mode. Had me scratching my head for sometime. On looking on-line for a (pdf) user manual it's [FN+F2] to bring the Icon back on. Regards El Tel
  6. El Tel

    Virtual KVM

    Hi This deserves bringing out the closet, as I've been using this GR8 program for 4 yrs now. I also like the fact that you can reduce the area in which the mouse jumps from one screen to the next. Regards El Tel
  7. Hi ... Ho no not again I worked this out from the 1st post, he just wanted an Icon like one he was used to in his quick launch bar. Umm ... I just add to the thousands I have categorised in my Favourites As with moving files and Folder, left click just moves them; right click gives you the opportunity to copy them, like a template... Something to work with, but with the URL right click also gives you the chance to make it available off-line. Perhaps it's a left over from the Dial-Up days. Make it available Off-Line and Hang-Up then read it later off-line with a cupp'a of whatever takes your fancy ... Regards El Tel
  8. Hi... Here is how I create a "Desk Top Shortcut from my Browser. Once I've first located it as in the image I shrink it down so I can see some of my desktop. Assume the Image below is anything you want to make a shortcut for. Then I "Right Click and Hold" the Icon that is next to the URL in the Address Bar, while holding down the right mouse button I move it to a empty space anywhere on my "Desktop" then let go of the mouse button and wait for a "Pop Up Window" to appear then select "Create A Shortcut Here" ... From my desktop I "Drag & Drop" to my "Quick Launch Bar" This might B a GR8 Tip for everybody... Regards El Tel
  9. Hi Had a similar problem myself. The tip I got was, when the window opens up instead of using the Maximise button. Move the window so that the top left is as close as you can get it to the top left corner, then drag out the bottom right hand corner to the bottom right hand corner of the screen as near as you can. Then use the Maximise button to square it all up. Next Hold the "Ctrl" button while you navigate to the "White" X in "Red" box top right and close it. Then "Shut Down" and "Switch On" Regards El Tel Edit Typo
  10. Hi Juliet I have read the posts from that link and note PC2 version does look right while PC1 looks slightly different. So I will let it update the next time I see the notice. Regards El Tel
  11. Hi I bags your old Laptop ... I have 2 PC's sitting next 2 each other and this is how I transfer files between them, along with Dropbox for Remote access. First I set up a Mshome Network on PC1 so I can see it on PC2 when I connect to that Mshome Network see pictures below. I then create a new shared folder on PC1 within that shared folder, which then can be seen on PC2 almost instantly. After locating a folder on PC1 (To be Moved) I hold the right mouse key down while navigating to the network shared folder on PC1 then let go of the right mouse button while it is hovering over the right folder. From the pop-up window I click on "COPY" then make mi sen a coffee while the folder is copied. You will then see it appear on PC2. Depending on how big the folder is it could take some time. After they are safely on PC2 I do a similar thing on PC2 shared folder to the appropriate place within the Documents and Settings User Name destination. I hope the above pictures help. When I am happy the folder and all the files within are accessible on PC2 with PC1 switched off, I can delete them from the shared network folder. Job done... If I need access to any folders and or files I use Dropbox to which I can invite anybody to it. That way we can both take advantage of extra Free storage. Regards El Tel
  12. Hi I have two PC's side by side, both with AVG 2012 and both update the virus database daily. One PC1 keeps saying AVG a new free version available and needs to be updated, while the other PC2 has never offered the update. These are the versions on each PC1 & PC2 If it is fake how do I stop the popup notice. Regards El Tel
  13. Hi I am all for progress with programs and operating systems, but the likes of Bill Gates forget the one fundamental thing. It is my PC, not his. ( I do with it as I like, within the law. ) All program writers should keep this in mind and not hog valuable PC resources, to which many are often used a couple of times, and then the user closes that program, moves onto something else, but part of the programs stays in memory just in case. Wrong. All programs should completely remove themselves once closed, flush out memory ready for what ever the user wises to proceed with; remember it his PC not the program writers. This is why a universal "Boot and Close Program" is needed. It's main criteria should first read what is available, memory, processor speed, plus what is needed etc, then advise the user what is possible then load accordingly; then store this information to disk within the "Boot and Close Program" folder for ease of access. Anybody up for the challenge. Regards El Tel
  14. Hi Y Normally when I see something like that red screen. Panic sets in thinking it's some kind of virus attack and I'm looking to get out as quick as I can, even pulled the plug on 2 occasions when the browser wouldn't close. But this time I hit print screen 1st. I've never clicked on "Go to my home page instead". Assuming that was the virus payload, the bit that does the damage; the lead you into a false sense of security. After reading your reply, clicking more information, I noted that there was the option to report it as "I think this is a safe website" so I did. On the red screen in big letters, it should say that it is part of "Microsoft Smartscreen Filter" which I had forgot was turned on. Thanks for your help, I did get to nirsoft in the end. Regards El Tel
  15. Hi Just following this thread and when I went to NirSoft link I got this Hence no IEHistoryView Regards El Tel
  16. Hi How Cool is that... Wicked... Thanks for the share Regards El Tel
  17. Hi Tom K I have just been connected up to his PC to check it out. It is now running like a dream. I kind of hoped in way I had trouble again with AVG, but alas it loaded perfectly ok this time. I've noted down your preferences for Anti Virus software and if it goes pear shape again I will consider an alternative. And Thanks for putting my mind at rest with Hijackthis log missing files. Many Many Thanks for all your hard work. Regards El Tel
  18. Hi Tom K The PC is running smoothly... I 'll have a search for a new download for AVG FREE UK version other than from "CNet . com". I can't swear but I have feelings thats where that Registry Tool came from by mistake or bundled up with the download. I Thank you for all your Hard Work and Time. You are a man. Regards El Tel
  19. Hi Tom K Nothing has gone easy on his PC. Sorry you drew the short straw on this. I feel like a lamb sent to slaughter myself The AVG removal tool gave this error "2011-05-12 16:44:22,795 ERROR Wrong application platform. Use corresponding application version for 32bit or 64bit systems" along with A Google search came up with some Download Tools several of them. The second one down worked. Now I think AVG has been removed. I had to manually remove an AVG 10 Folder to a folder on my own PC just in case, but it is off his PC. This is a massive remove log below "Running zap for product code {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}:12/05/2011 18:53:00.89" C:\Users\El Tel\Desktop>C:\Users\ELTEL~1\AppData\Local\Temp\avg-a837d665-4317-4a32-b89f-b474ee940207.exe TW! {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} /nologo ***** Zapping data for user S-1-5-18 for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} ***** MsiZapInfo: Performing operations for user S-1-5-18 Searching for the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} cached package. . . Removed file: C:\Windows\Installer\22b5f.msi Searching for install property data for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Removed \E39F8D28C8A8ECC48BF89AE9F4D3CE7A\InstallProperties Searching for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data in the HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall key. . . Removed \{82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} Searching user's global config location for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes... Removed upgrade code 'E39F8D28C8A8ECC48BF89AE9F4D3CE7A' at HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Removed \Features Removed \Patches Removed \Usage Removed \Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching per-machine global config location for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching old global config location for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Microsoft\Windows\CurrentVersion\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching per-machine location for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Classes\Installer\UpgradeCodes... Removed upgrade code 'E39F8D28C8A8ECC48BF89AE9F4D3CE7A' at HKLM\Software\Classes\Installer\UpgradeCodes Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Classes\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Classes\Installer\Components for published component data for the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Searching HKLM\Software\Classes\Installer\Assemblies for .Net assembly data for the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Searching HKLM\Software\Classes\Installer\Win32Assemblies for Win32 assembly data for the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Searching HKLM\Software\Classes\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Removed \Media Removed \Net Removed \SourceList Removed \Software\Classes\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A Searching HKLM\Software\Classes\Installer\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Removed \Software\Classes\Installer\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A Searching for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} in per-user managed location. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching for shared DLL counts for components tied to the product E39F8D28C8A8ECC48BF89AE9F4D3CE7A. . . HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Components key is not present. Searching for shared DLL counts for components tied to the product E39F8D28C8A8ECC48BF89AE9F4D3CE7A. . . Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\sc.dat Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\sb.dat Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\avgmfarx.dll Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\avgmfapx.exe Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\ph.dat Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\avgatend.stp Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\cf.dat Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\sc.dat.xcd Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\avgatupd.stp Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\sb2.dat Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\HtmLayout.dll Reduced shared DLL count to 999 for: C:\ProgramData\AVG10\IDS\config\internalList.zip Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\avgupd.sig Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\avgupdx.dll Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\js.dat Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG10\sb.dat.xcd Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A client info data. . . Removed client of component 02B5D3BBE36CD054192F35D45661E5B6 Removed client of component 038273005BAE4A44FBF57335CECC954A Removed client of component 03B656C6C2AA2F44EA80221C0B7875A8 Removed client of component 042671E0252CEA84689EA0CB0F2959EE Removed client of component 044DB212FED836D41A4FE00EE9DC100E Removed client of component 05DA3C1A9735FC6459D070A81923EF71 Removed client of component 05FA1762803A8494BBF0B3EBE96D0AAC Removed client of component 061EEE5D984E24D4E8DD5DF6A0C485F4 Removed client of component 08723566687B1934B810079941853519 Removed client of component 09D57A7D52A27834ABE806C7B192FE65 Removed client of component 0B4D42C75C0910E4291C96EF80AE4A06 Removed client of component 0B81368A39B8DD644B1B6FF7CE4683B0 Removed client of component 0C8E35977A7CB764FA6C2391AEFB1D5D Removed client of component 0D70348724D142A4EAA4F638D54A97D6 Removed client of component 0EA055A37B1DB2A4BA77154703995499 Removed client of component 0F7BE1AE5A42FAC47A89CE2B4EEE7CD1 Removed client of component 119F0421DE6B1564DB33CE0D640F82B9 Removed client of component 142B1337F93DC1842A8B819ADF74399A Removed client of component 146B292F66D388944ACC6D39A7391289 Removed client of component 14D5FFE54E51D30498208A61319F2896 Removed client of component 158ED5515654E8344AF5F0FFC1D4998C Removed client of component 16C4829923A9EA04A80B9B261B630758 Removed client of component 17ED36C5FE08205499392BCCF7B5C709 Removed client of component 18D705324F6F6CB46A5ADE791C613605 Removed client of component 190CBB0CBAE51144680AD2FF383DF038 Removed client of component 1972D055C1A5F3D439EF6577BD323176 Removed client of component 199BE8FC07C810947BF29C10ABE02E04 Removed client of component 19A2AA3BB8E94A845983355AF7AD235C Removed client of component 1ACC957DED687B0429F9306C9BA33B9B Removed client of component 1BD7AFAD188455B4E88D1407BB3E3422 Removed client of component 1C286DA0094343F42AC2AE881FDF1646 Removed client of component 1CEF753AA513EC14783EBD8CBA5C79BD Removed client of component 1CF4728E6EAF5C244A7B363616615EE3 Removed client of component 1D6D7A76136EC7F4F94194704B567B76 Removed client of component 1E1E5546DE1021640BC34E872AC8699E Removed client of component 1F66A49279DC4B64F8D923A910E85304 Removed client of component 1F96050D2B9C8124CB63B995CA303E72 Removed client of component 2041B93C30F5E5549B3EE8DD5C501F29 Removed client of component 208F00E9F61CE7643B5C39B7E2961F72 Removed client of component 20CDE49C59E993742A7DA10843B976AB Removed client of component 20E617439F0F0874F9796AC716BA2550 Removed client of component 21753453B38F45549BF97D12D98FBFD4 Removed client of component 21F8040D4EFB2184C93600D1DAB67824 Removed client of component 236DA740634D3B74D9C750B59F4FBE2C Removed client of component 254968AEB0C431E40AD8B935986009D4 Removed client of component 25CF3F5C8758BBB4DAF9A8855BBC150B Removed client of component 262DEC570D5E8684483BE95DDA53E376 Removed client of component 275596C0E3F9C044E8052AB4B272A233 Removed client of component 2766A92CF5FB2A845BF223AD88835B11 Removed client of component 28111DB372446E244BE74F909108CA51 Removed client of component 28DE6AAFA7DF76345BE5DECC8017A986 Removed client of component 2A4860A6274B3B44D8A49CD3DE487D5B Removed client of component 2ABE9BEA9BCC01A40A1CEC350425F7C6 Removed client of component 2BD2962EDE32B4847BE3EFF6F4088D39 Removed client of component 2C3D8BA6EF8F6A642BB5EAD7900807EB Removed client of component 2D539B57F40242E4CA6CF9C65398CCF8 Removed client of component 2D56CCBB52263F141A29BD9F3755DA87 Removed client of component 2E48EA61FB7BE474BAB37654550180D3 Removed client of component 2EBE4911CA052B245A77EF07F5C7FFC8 Removed client of component 2EE4318A8A2AF3D478133903A540AFCF Removed client of component 2FAB89FA32B946A459D7C8992E88F76C Removed client of component 3084C66744E921543BDFB5A6978862F8 Removed client of component 3164ED50FDE7FF442B1C3B8983D6D4EF Removed client of component 31E8EF8CCB311F84AAEFCB73B0872748 Removed client of component 346AA024609CE524F95C8DF6C0A4499D Removed client of component 356F0772C31509D4A9063FD112CC8207 Removed client of component 35700D2BEB7C10343A7EF68BC64F1F16 Removed client of component 359ECDCCD3B03434DABDD3C9B108D6EA Removed client of component 35CE4D8B1CD1852459D5C9814EA25CF0 Removed client of component 3808D1B60A205D44190F8D70BE50C5E5 Removed client of component 38BBD8BC21F93FE44BFFD61ACF65ED33 Removed client of component 38DBC2A97F8FE9244A611D9A63E812CE Removed client of component 39F70EDEF7568844A90CAB9778624D52 Removed client of component 3C38FF15DB37A994F8529B3CF182C98E Removed client of component 3E277BB2FA71CC04C918FD3DC294655E Removed client of component 3EF15E7441D99DB4EBE3466B86F299CA Removed client of component 3F2F917D9144FCB4E9724F00FDC381EB Removed client of component 3F39A00BF86D74C499507439A1C88E17 Removed client of component 3F63B5861A8FCE34FBE7C659601C50B5 Removed client of component 3F9D4A79D1ACB8B4BB67B4FA80AC0C08 Removed client of component 4193A0F7653A52F4983A75C522E6FDAF Removed client of component 422C0D311E964AC4A811A9EE5E385F89 Removed client of component 42E94D4B8B146A14E94A6F076BE32046 Removed client of component 452C08BAEAD21F64F8D99C2C0CEFA3D2 Removed client of component 456395DE75454274F88FC7FC839F10AA Removed client of component 46770F93D8BC0D845A15CB16175658BF Removed client of component 46A19BC1DF607E74998E113E432BC70E Removed client of component 46DDE38572305774E95B73023C670186 Removed client of component 484D07E3DFDCC7042BFB757F29F93C8D Removed client of component 49F7029E336722449AB0FB53C4AB6D06 Removed client of component 4CA04824181946F4192DDBB214DC148A Removed client of component 4CF6BD130E1D7D34CB34757F14894DAC Removed client of component 4D01797DD7EAD684CB6C1A82098DADC4 Removed client of component 4D0F8D601AD5CDF46868DEB4DA0A79C1 Removed client of component 4EEF0667AC8682540B223D95E1327B37 Removed client of component 5009F1514BC3FC44BB7D5C73BB04C8B1 Removed client of component 504B229677ED6FB408CE6CFC6C7A5D75 Removed client of component 50B09B06CDAFC0E40B4D45446583FC84 Removed client of component 50D60A9C5EC17BC45B6617EA5F0E2E95 Removed client of component 515897A71A2F9C9418DFA49E7ABA3558 Removed client of component 527EC73B0D01C58488E931A5FF57D2DD Removed client of component 53325026A7E767841931B2012507CADC Removed client of component 534E95E66C590274AA00760327627FB6 Removed client of component 536A9DDC92829114785BFCC60397332D Removed client of component 53B1A220D412D9F4889926613F7D8C84 Removed client of component 55443FFE81F6E8246B3F0DB3451622A3 Removed client of component 557FABB0CFD0F2A489753ABD0DCACED6 Removed client of component 56007132D4EA24249A2D6B13705A3A88 Removed client of component 560BCECF1C1DE9946BC5F9335C1EF6BA Removed client of component 572EFEB84D7988D41868BC46E63175F9 Removed client of component 5A37C2D004AF8DE44B7B8CF3F074011D Removed client of component 5A582AFBFA37ED544B9CE7113A447CDD Removed client of component 5A7A66CE82D4A15408ED6F0879250245 Removed client of component 5AC7DF09045927342B57E8580F4F3C3C Removed client of component 5B213F41228A0A241B98F1FAD6599B34 Removed client of component 5CA9956D46E2A784DB1C37FAFBB7534D Removed client of component 5EE5F94C74BD52F4DBB15E8266E7EAD2 Removed client of component 614DB733238EED4419DC809EED87F9DE Removed client of component 622DA33FAC27DB141BE3764B21D8FDAF Removed client of component 62349A9365449AD428E05243408CD26F Removed client of component 624BB461518C0F94CB88FFBA9572EEC0 Removed client of component 628181AD3D4FF8047B991C82551D260F Removed client of component 65A7EF5FE6132F944B6C73BADE8E2EF9 Removed client of component 65D469FD10D3BAD4BB0E32C5DE4CF813 Removed client of component 67479F382DAEBDC42887D338758D3ED4 Removed client of component 67D0CFAA01E141648AF4CED9C9674C33 Removed client of component 69A6F144A153F364499AD9E627047D55 Removed client of component 6A93A02ADE963AB4EA3963505708CD0D Removed client of component 6AF166B4AFE6B27479E2C1DD06DDC6CC Removed client of component 6AF82F4C11D637542B3D081FA12BECF1 Removed client of component 6D8684F49BDB6EA468BE0ECA75BC8247 Removed client of component 6E6FF127F8160714980354ACCC5F115B Removed client of component 710369C53E01E194EB3B1D70D079BECA Removed client of component 713733403B6623740A0C6726180BC050 Removed client of component 71A76FC9C98D6CD4E924D5A97BF37A1A Removed client of component 72CFEE980CF3D334DBD06404F2BC76AF Removed client of component 7309A42DE3C6A59419F00AF92729F30D Removed client of component 7335F3A683DF6414BA53E3BC927A3F90 Removed client of component 74B487886CE1B7B4BA2AA21A3E0F756D Removed client of component 76AF2CAFD0BA08F4FB87AB77F7A7153C Removed client of component 774F2D3700943ED45809F2747645B8AE Removed client of component 777CF069BDD3D914796C15525C4C0E29 Removed client of component 7807090397DF2BE4785478B73671B0FB Removed client of component 78373055C36C6D444AB59C5870C92D4A Removed client of component 787DAE6523949D443ADEAFC0A16422CC Removed client of component 799AD62729023C24D95D6153C84A26B5 Removed client of component 7A60F5D829989804884CD98CA40644EC Removed client of component 7A80C837F8705DB49921A423B399D1EE Removed client of component 7AE8A4C6FA6F1144EB0A7F8EDC02E54C Removed client of component 7B37B61E01A6C1F408FBB1F5119ED4E6 Removed client of component 7B6A8D4EA2164C241B3BC6B32E673BB4 Removed client of component 7BB95CCC171D0C84B8C0F71D873E27E0 Removed client of component 7D56681770BC9684D9BAC0110537224F Removed client of component 7D574CDB7C7209D479BB58E16EAF61D8 Removed client of component 7DC84CC5D61C8044EA493FD043E84ECD Removed client of component 7DE6AF5528770684F840259B04AE06B2 Removed client of component 7E6E4CF4D1F83D64BBA509E073D6FC12 Removed client of component 7E9E1269558E5D746B4FE30BBC34331A Removed client of component 7EA7B382A8A2F5641889FFD311F914CB Removed client of component 8078B1BE59A52AB4FA7AF0C3664B0874 Removed client of component 80A65306D0A511F4495892E514AF46E9 Removed client of component 80B8B4AB423B7E849A69BC1D881AB9FF Removed client of component 812650AB922197D4F89F278FDB22370F Removed client of component 83684C77A6998F04B8CBD9287F5106E4 Removed client of component 8383B208068BBF541942F74C36B228B5 Removed client of component 84CD1ED275C97C243A5B5020DA3B125C Removed client of component 84D3D3A2F1D879C4FB0C7076A63FACD9 Removed client of component 85F2A6A7018BA454DB2401D7342D8DF6 Removed client of component 862DD31D0E166B248863A6721F7A43F2 Removed client of component 86EC69F0D2949FB47A43547EE2007F32 Removed client of component 877E6F3B966216149BA2E9B6088154C8 Removed client of component 88564E146649AFE4384DCDFB6D84DF28 Removed client of component 891782562174A5043B638EF0A6A2AFE6 Removed client of component 8B5BC1C170CABFA4D85081BEEA06E6A9 Removed client of component 8C5CE9B9ADC669F47A747E30C085450D Removed client of component 8C5D453380758C048B356DCEE05B6872 Removed client of component 8CC393E6BC374634E93F8D4003BC32B3 Removed client of component 8EA37F1A5BAA1F04AAEA5E7FA1323667 Removed client of component 9116BDADFB52D1D4B8EAE84F58BFC20F Removed client of component 915AB6037E7AE204285693BC72E0B7D7 Removed client of component 91B3D5F6462B6DB4683A621BF88BA257 Removed client of component 925ED1FE1D8204E40AE425737663FE5A Removed client of component 937F46D7D0CE298438C0798B47601D03 Removed client of component 943E3306582E7D8408DF36D24E18459F Removed client of component 946753B71D253D540B2B0C6782E21EF2 Removed client of component 95083F66D53D68A48B7909032900678B Removed client of component 954D62EF3534B2644AABE3F517F8D8CE Removed client of component 964A33E77500CC34B8D3F5DEAD6212A6 Removed client of component 9664BA4F1C76AA44CA18D7B5960806D5 Removed client of component 9A9BCA6AA153AB244AC954C7BB242C89 Removed client of component 9C39C80809FAD194C98272242A2A9FA2 Removed client of component 9D0CD3169E713D448A27C5C8EBB374A8 Removed client of component 9E2FC7DED3ABDB843A0DE682A028C61F Removed client of component 9E8AA7D91434644479E9F017A2A2A750 Removed client of component 9ED8FC6AE0A3E3441AC440382778432E Removed client of component A04E7678D2EEF1244AD921C7B84D181A Removed client of component A0513AEF7C219284DA9518167EE77082 Removed client of component A1A67CC53DE1C5E44B525ACF76443532 Removed client of component A26CE9BE23710D548B016E3D862A3AD9 Removed client of component A356DB03D439C944BA8E4936AF9FA85C Removed client of component A5358247F42D82A41BD1D77A98141F8A Removed client of component A5F74ECDA88BA174E967BDE71E2F0201 Removed client of component A754AE0AE1C52EC498470B0914896271 Removed client of component A831AADB50070434A9A0057491F3F61F Removed client of component A84BFF637FE162D48BD8530DB7FA24DA Removed client of component A8C97FE663C197C49861E6DEF176B168 Removed client of component A90B54E7594581E4DABC7DA3D1D3C30D Removed client of component ABDC99C292EA1A748B17A2F0F6CA990C Removed client of component AEC4428EA000C324181FE263620DA9F7 Removed client of component AEE191DB8BA62FB44B3602E0FB2F7864 Removed client of component B04C49EB8233D034392320185F97E907 Removed client of component B0E297D94344B5E4D95EC487B714918C Removed client of component B0EBEB8B90FD2A44D817161A42C4F27C Removed client of component B1581F48DCD87E04D964A1BB8D9EF9AF Removed client of component B23B04DE31DCE024186C6B4803F75148 Removed client of component B25CC2EF41E94EF46B7F45F17BFAE802 Removed client of component B52395BCD5BDFEA4DA22A5CDB8F88F8E Removed client of component B57D22049FBE9A940AC7822DFD834CAE Removed client of component B58B590F2EA568E4FAE9E8A4EBBB3A36 Removed client of component B591DB3C13D1EEE42A41720AF676BBEA Removed client of component B5C062C5B6B0FFC4F96CB01D74389136 Removed client of component B6A42D58B82A0644BBE264F68F856F8A Removed client of component B6D0804A314D9794CB2DC1CA9447CC87 Removed client of component B7AA62F40BBCFDA499B2FA4C6B01E8D7 Removed client of component B8967D2B8DC3DD4449D3D4B65C20B7D9 Removed client of component BAFF687AF446F5B46A7FB37B12D2BBB0 Removed client of component BB4FC25E0325B9445BD1E6A2676147C7 Removed client of component BDD0C5613AF897D4197F8F5FEDB45732 Removed client of component BEEDE10259F196E45A2A98C49E71C0A9 Removed client of component C0DA5C95B68D19542A4BC7C51C6E5FA0 Removed client of component C16DD91DD6A92A9498C6531D8485BF6A Removed client of component C22E7ECE09559B049977F27E8F4517CD Removed client of component C3D68B4EDEE987446840EFF887474B48 Removed client of component C4074F74B9612E4479EFD8DBDB3FC460 Removed client of component C4CFB718387E9EB45B407A8E4B14264A Removed client of component C643EA603CC66CB42A0988C1AFB7CAC7 Removed client of component C6DFC883752E2C14CA91A7CD690AF7D6 Removed client of component C70FDFDD1A3694241B265AF70F95753E Removed client of component C7897ED9687975D42A469351DCF48727 Removed client of component C886527D8FC6F67409CC1785EAD83508 Removed client of component C8D411B293EC5C84EB6AAC10E34FE08B Removed client of component C8F17408A6868B04EA7005829E3E3B70 Removed client of component C8F5FBEFA4609544990E91C8ABDA1EB8 Removed client of component C97EA56203BCDE74DAACD518592BEA97 Removed client of component CA359A336EDC03340B7B442545633E87 Removed client of component CAA4C879396FB664189237238D2761FA Removed client of component CAF2D68B590D4E44C90BDEA1ACE6110E Removed client of component CB1C591D54803FF44AAFF260B0F2FDF8 Removed client of component CCBB7A82FA587804E9E17372C8FEA953 Removed client of component CD493820DBE49A64EB37FF35162D46E1 Removed client of component CE24EB5395D4098408985C1A8EF7FD72 Removed client of component CE79C231997464846920C2A6994F757B Removed client of component D1E982AFA3FA41141BF084AC7002D3AC Removed client of component D2F87B9E0B4A4E345A7D2339EFE0CDCF Removed client of component D31C167A1DA8B6D4887F815D67940A4A Removed client of component D37BBEEA71DA17D44A6441D5A27ABAF7 Removed client of component D3A36F44E4E202F45886B8D066E9867B Removed client of component D45FAF5A8F39D104AB2430EA7B8D9247 Removed client of component D6782606088F3E646A9BE10C752FE64C Removed client of component D85FC556BA486264680C6EDF290EEF87 Removed client of component D9CDB1BF92AD81E4C80B5060C7B0DF01 Removed client of component D9D35EAC325B16A4D89C951913E73C3D Removed client of component DAE4C5F4AF338234BAAF316742642FBD Removed client of component DB66AFEE3FD2EAA4E9A6F9C1515116D5 Removed client of component DC10F42CD6A97854898E1D65A1467111 Removed client of component DD1AA34331839734B98B9A254F0E6B17 Removed client of component DF1484F6E83C36A43960BAE096851914 Removed client of component DF22920DD20934B4C9F7642118A3E348 Removed client of component E09228E6A4E974D48B82F23BFE74F89E Removed client of component E174053F35F54E84796121374566A3F6 Removed client of component E17757F5019034F499CD2FF9EA0D3F9E Removed client of component E1807EEC121E86049A3B21536FFDE8FD Removed client of component E3B3405267B1A6342A9FF2172BD5E948 Removed client of component E41B494CC536D2140A47BF7060989593 Removed client of component E4E566A623D410D41A6ACA249ECAE651 Removed client of component E6122A5031470E04CA85FC411D2251F9 Removed client of component E74FB79A32C918C45BC9C5EDF28CBAAE Removed client of component E8E2113991FD883468F598115552E136 Removed client of component EA955E849BA389C42AF280F65C6712B6 Removed client of component EB9940BABCBF03C4E8BDCDE75AE4C5E6 Removed client of component EC151EFFB5D460A4090BC574BCD03104 Removed client of component EC3D273082FE98740B392E23766278E0 Removed client of component EDC61D5A9F1EEDB4A8F907F92CE5F74A Removed client of component EEAA7902D0BB32D499F91081D870A7C6 Removed client of component EF76D2C7D5D1FBB48908C9CFB40F6F42 Removed client of component F0839BF88786D904D842E3A12C0E09FD Removed client of component F0AD3378160920F4F8C4765D7F6E2E39 Removed client of component F2B3340058B51CA43ACC4909FB710651 Removed client of component F33E0818678B19248B36A6D1F5CC799D Removed client of component F51F80D2012C87544B318F1DFBB3F709 Removed client of component F72A2D39AF133F1408555D2169B80C5A Removed client of component F762B380CA9EA734F9DDC58C6F2F3ACB Removed client of component F89C76444B0DEFA4780CFAF01216C97F Removed client of component F984E318247A20E4486C8146FA280C07 Removed client of component FD52503A76ABF414D8E9CD0410E2F482 Removed client of component FE9B611DDB47CB64BA7DFEF4AA0D9A36 Removed client of component FEAAE1DCD1014914289DADAB25AF586B Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A client info data. . . Searching for Installer files and folders associated with the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Searching for files and folders in the user's profile. . . Searching for files and folders in the %WINDIR%\Installer folder ***** Zapping data for user S-1-5-18 for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} ***** MsiZapInfo: Performing operations for user S-1-5-18 Searching for the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} cached package. . . Searching for install property data for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Searching user's global config location for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching per-machine global config location for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching old global config location for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Microsoft\Windows\CurrentVersion\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching per-machine location for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Classes\Installer\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Classes\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Classes\Installer\Components for published component data for the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Searching HKLM\Software\Classes\Installer\Assemblies for .Net assembly data for the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Searching HKLM\Software\Classes\Installer\Win32Assemblies for Win32 assembly data for the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Searching HKLM\Software\Classes\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKLM\Software\Classes\Installer\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} in per-user managed location. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching for shared DLL counts for components tied to the product E39F8D28C8A8ECC48BF89AE9F4D3CE7A. . . HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Components key is not present. Searching for shared DLL counts for components tied to the product E39F8D28C8A8ECC48BF89AE9F4D3CE7A. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A client info data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A client info data. . . Searching for Installer files and folders associated with the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Searching for files and folders in the user's profile. . . Searching for files and folders in the %WINDIR%\Installer folder ***** Zapping data for user S-1-5-21-909527836-1280678326-320050609-1003 for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} ***** MsiZapInfo: Performing operations for user S-1-5-21-909527836-1280678326-320050609-1003 Searching for the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} cached package. . . Searching for install property data for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Searching user's global config location for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-909527836-1280678326-320050609-1003\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-909527836-1280678326-320050609-1003\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-909527836-1280678326-320050609-1003\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching per-machine global config location for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching old global config location for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Microsoft\Windows\CurrentVersion\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching per-machine location for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Classes\Installer\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Classes\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Classes\Installer\Components for published component data for the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Searching HKLM\Software\Classes\Installer\Assemblies for .Net assembly data for the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Searching HKLM\Software\Classes\Installer\Win32Assemblies for Win32 assembly data for the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Searching HKLM\Software\Classes\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKLM\Software\Classes\Installer\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching old per-user location for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Classes\Installer\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Classes\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKCU\Software\Classes\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKCU\Software\Classes\Installer\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching per-user location for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Microsoft\Installer\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Microsoft\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKCU\Software\Microsoft\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKCU\Software\Microsoft\Installer\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching for product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7} in per-user managed location. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-909527836-1280678326-320050609-1003\Installer\UpgradeCodes... Searching for patches for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-909527836-1280678326-320050609-1003\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-909527836-1280678326-320050609-1003\Installer\Products\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-909527836-1280678326-320050609-1003\Installer\Features\E39F8D28C8A8ECC48BF89AE9F4D3CE7A for product feature data. . . Searching for shared DLL counts for components tied to the product E39F8D28C8A8ECC48BF89AE9F4D3CE7A. . . HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Components key is not present. Searching for shared DLL counts for components tied to the product E39F8D28C8A8ECC48BF89AE9F4D3CE7A. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A client info data. . . Searching for product E39F8D28C8A8ECC48BF89AE9F4D3CE7A client info data. . . Searching for Installer files and folders associated with the product {82D8F93E-8A8C-4CCE-B88F-A99E4F3DECA7}. . . Searching for files and folders in the user's profile. . . Searching for files and folders in the %WINDIR%\Installer folder "Running zap for product code {742DF898-7ABE-4CF4-8557-5D17C400D49C}:12/05/2011 18:53:01.83" C:\Users\El Tel\Desktop>C:\Users\ELTEL~1\AppData\Local\Temp\avg-a837d665-4317-4a32-b89f-b474ee940207.exe TW! {742DF898-7ABE-4CF4-8557-5D17C400D49C} /nologo ***** Zapping data for user S-1-5-18 for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} ***** MsiZapInfo: Performing operations for user S-1-5-18 Searching for the product {742DF898-7ABE-4CF4-8557-5D17C400D49C} cached package. . . Removed file: C:\Windows\Installer\5ffc9.msi Searching for install property data for product {742DF898-7ABE-4CF4-8557-5D17C400D49C}. . . Removed \898FD247EBA74FC45875D5714C004DC9\InstallProperties Searching for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data in the HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall key. . . Removed \{742DF898-7ABE-4CF4-8557-5D17C400D49C} Searching user's global config location for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes... Removed upgrade code '898FD247EBA74FC45875D5714C004DC9' at HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Removed \Features Removed \Patches Removed \Usage Removed \Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\898FD247EBA74FC45875D5714C004DC9 Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching per-machine global config location for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes... Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching old global config location for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes... Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Microsoft\Windows\CurrentVersion\Installer\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching per-machine location for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Classes\Installer\UpgradeCodes... Removed upgrade code '898FD247EBA74FC45875D5714C004DC9' at HKLM\Software\Classes\Installer\UpgradeCodes Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Classes\Installer\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKLM\Software\Classes\Installer\Components for published component data for the product {742DF898-7ABE-4CF4-8557-5D17C400D49C}. . . Searching HKLM\Software\Classes\Installer\Assemblies for .Net assembly data for the product {742DF898-7ABE-4CF4-8557-5D17C400D49C}. . . Searching HKLM\Software\Classes\Installer\Win32Assemblies for Win32 assembly data for the product {742DF898-7ABE-4CF4-8557-5D17C400D49C}. . . Searching HKLM\Software\Classes\Installer\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Removed \Media Removed \Net Removed \SourceList Removed \Software\Classes\Installer\Products\898FD247EBA74FC45875D5714C004DC9 Searching HKLM\Software\Classes\Installer\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Removed \Software\Classes\Installer\Features\898FD247EBA74FC45875D5714C004DC9 Searching for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} in per-user managed location. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\UpgradeCodes... Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching for shared DLL counts for components tied to the product 898FD247EBA74FC45875D5714C004DC9. . . HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Components key is not present. Searching for shared DLL counts for components tied to the product 898FD247EBA74FC45875D5714C004DC9. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 client info data. . . Removed client of component 30EC774F6371B044A932CFA7E5F864A8 Removed client of component 6860D4C172F342148B20044D4C8D338A Removed client of component 87D1821D58851D742A203109E817A846 Removed client of component DEB6A604126113741A7FAADD3CFD5F1E Searching for product 898FD247EBA74FC45875D5714C004DC9 client info data. . . Searching for Installer files and folders associated with the product {742DF898-7ABE-4CF4-8557-5D17C400D49C}. . . Searching for files and folders in the user's profile. . . Searching for files and folders in the %WINDIR%\Installer folder ***** Zapping data for user S-1-5-18 for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} ***** MsiZapInfo: Performing operations for user S-1-5-18 Searching for the product {742DF898-7ABE-4CF4-8557-5D17C400D49C} cached package. . . Searching for install property data for product {742DF898-7ABE-4CF4-8557-5D17C400D49C}. . . Searching user's global config location for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes... Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching per-machine global config location for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes... Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching old global config location for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes... Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Microsoft\Windows\CurrentVersion\Installer\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching per-machine location for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Classes\Installer\UpgradeCodes... Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Classes\Installer\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKLM\Software\Classes\Installer\Components for published component data for the product {742DF898-7ABE-4CF4-8557-5D17C400D49C}. . . Searching HKLM\Software\Classes\Installer\Assemblies for .Net assembly data for the product {742DF898-7ABE-4CF4-8557-5D17C400D49C}. . . Searching HKLM\Software\Classes\Installer\Win32Assemblies for Win32 assembly data for the product {742DF898-7ABE-4CF4-8557-5D17C400D49C}. . . Searching HKLM\Software\Classes\Installer\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Searching HKLM\Software\Classes\Installer\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} in per-user managed location. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\UpgradeCodes... Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching for shared DLL counts for components tied to the product 898FD247EBA74FC45875D5714C004DC9. . . HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Components key is not present. Searching for shared DLL counts for components tied to the product 898FD247EBA74FC45875D5714C004DC9. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 client info data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 client info data. . . Searching for Installer files and folders associated with the product {742DF898-7ABE-4CF4-8557-5D17C400D49C}. . . Searching for files and folders in the user's profile. . . Searching for files and folders in the %WINDIR%\Installer folder ***** Zapping data for user S-1-5-21-909527836-1280678326-320050609-1003 for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} ***** MsiZapInfo: Performing operations for user S-1-5-21-909527836-1280678326-320050609-1003 Searching for the product {742DF898-7ABE-4CF4-8557-5D17C400D49C} cached package. . . Searching for install property data for product {742DF898-7ABE-4CF4-8557-5D17C400D49C}. . . Searching user's global config location for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes... Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-909527836-1280678326-320050609-1003\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-909527836-1280678326-320050609-1003\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-909527836-1280678326-320050609-1003\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching per-machine global config location for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes... Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching old global config location for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes... Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Microsoft\Windows\CurrentVersion\Installer\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching per-machine location for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Classes\Installer\UpgradeCodes... Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Classes\Installer\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKLM\Software\Classes\Installer\Components for published component data for the product {742DF898-7ABE-4CF4-8557-5D17C400D49C}. . . Searching HKLM\Software\Classes\Installer\Assemblies for .Net assembly data for the product {742DF898-7ABE-4CF4-8557-5D17C400D49C}. . . Searching HKLM\Software\Classes\Installer\Win32Assemblies for Win32 assembly data for the product {742DF898-7ABE-4CF4-8557-5D17C400D49C}. . . Searching HKLM\Software\Classes\Installer\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Searching HKLM\Software\Classes\Installer\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching old per-user location for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Classes\Installer\UpgradeCodes... Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Classes\Installer\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKCU\Software\Classes\Installer\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Searching HKCU\Software\Classes\Installer\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching per-user location for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} data. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Microsoft\Installer\UpgradeCodes... Searching for patches for product 898FD247EBA74FC45875D5714C004DC9 in Software\Microsoft\Installer\Products\898FD247EBA74FC45875D5714C004DC9\Patches Searching HKCU\Software\Microsoft\Installer\Products\898FD247EBA74FC45875D5714C004DC9 for product data. . . Searching HKCU\Software\Microsoft\Installer\Features\898FD247EBA74FC45875D5714C004DC9 for product feature data. . . Searching for product {742DF898-7ABE-4CF4-8557-5D17C400D49C} in per-user managed location. . . Searching for product 898FD247EBA74FC45875D5714C004DC9 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-909527836-1280678326-320050609-10
  20. Hi Tom K That link worked a treat. I can't seem to get around this AVG licence. Clicking on fix doesn't sort it out either. I did a manual scan to see if that worked. When some 15 Min's into the scan this appeared I have no idea where this came from and my Brother-In-Law was a little vague? It dose show up in add remove programs. When the scan finished I moved to one side to check the results of the scan, then I closed the window. I have not tried to Un-Install AVG again because it refused to when I ran into trouble with ComboFix. Is there a AVG complete removal tool because I'm thinking there is / was something left over when I got ComboFix to work prior to me Re-Installing AVG. Here is HijackThis log and there seems to be several missing files Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 18:34:35, on 10/05/2011 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: C:\Program Files (x86)\Lexmark S300-S400 Series\lxeamon.exe C:\Program Files (x86)\Lexmark S300-S400 Series\ezprint.exe C:\Windows\vsnpstd3.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Users\El Tel\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe C:\Program Files (x86)\QuickTime\qttask.exe C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\AVG\AVG10\avgtray.exe C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Program Files (x86)\Trend Micro\HijackThis\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.my.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.pack...d5v135y4923924n R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [sSDMonitor] C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background O4 - Startup: Dropbox.lnk = El Tel\AppData\Roaming\Dropbox\bin\Dropbox.exe O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {0FADB9AA-6955-4319-B538-BB1461E11A28} (NTR Plugin 1.2.4.2) - https://www.ntrconne...ugin1242v_2.cab O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset...lineScanner.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.ad...Plus/1.6/gp.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgemc.exe O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: lxeaCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\x64\3\\lxeaserv.exe O23 - Service: lxea_device - - C:\Windows\system32\lxeacoms.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe O23 - Service: NTRConnect (ntrconnect) - Unknown owner - C:\Program Files (x86)\NTR global\NTRconnect\NTRconnect.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: Oberon Media Game Console service (OberonGameConsoleService) - Unknown owner - C:\Program Files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Updater Service - Acer - C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 12345 bytes Regards El Tel
  21. Hi Tom K As before I had an awful job un-installing Combo-Fix it sure doesn't like AVG 2011 Free Version. In the end I had to un-install and then re-install AVG from the original download saved to disk. On re-installing I had some trouble with the Free Licence being not recognised luckily I did a Screen Shot from the first time I installed it, the Licence number had changed mysteriously Um-mm I have no answer for that at all. It plain refused to acknowledge it and I therefore located a new AVG from "CNet Downloads" and tried that with the exact same issue with the new licence number there appearers to be two extra numbers added from somewhere 4UY9X-NSVVL-O4BZQ-QIMCL-QTDCH On installing above Below after Installing 4UY9X-NSVVL-O4BZQ-QIMCL-QTDCH-4 Perhaps AVG leaves something in the registry on Un-installing I don't know. At some stage not sure when, a pop up asked if I wanted to turn on "Windows Defender" which was a new one on me, but I said yes at the time. It did a scan and I haven't seen it since I couldn't see an Icon for it either. Old Timer worked like a dream in every way. I've read "Preventing Malware" but the link for Tony Klein "nutnworks" was blocked by my on-line "DynDNS Dynamic Network Service" as Spyware? As it turned out to "Third Party Cookies" which don't get allowed on my PC, I do allow "Main and Session Cookies" no site should force you to allow Third Party Cookies hence I didn't read it. It was getting late so I will have to wait until I can connect back up to sort out AVG, I did read that when I get AVG back up and running Windows Defender would be turned off. Regards El Tel
  22. Hi Tom K Old Timer worked a dream, I did temporary De-activated AVG. Peace of mind I think. All processes killed ========== PROCESSES ========== ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\{C18CB140-0BBB-11D4-8FE8-0088CC102438}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C18CB140-0BBB-11D4-8FE8-0088CC102438}\ not found. ========== FILES ========== ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes User: All Users User: Bryn Limited ->Temp folder emptied: 258456 bytes ->Temporary Internet Files folder emptied: 144002497 bytes ->Java cache emptied: 16006643 bytes ->FireFox cache emptied: 23892532 bytes ->Flash cache emptied: 144015 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: dixon ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 21869908 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 1058 bytes User: Dust Bin Lids ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 91872949 bytes ->Java cache emptied: 585091 bytes ->FireFox cache emptied: 66204599 bytes ->Flash cache emptied: 469724 bytes User: El Tel ->Temp folder emptied: 16541028 bytes ->Temporary Internet Files folder emptied: 52708906 bytes ->Java cache emptied: 1 bytes ->Flash cache emptied: 2824 bytes User: Guest ->Temp folder emptied: 1526 bytes ->Temporary Internet Files folder emptied: 55143959 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 2905 bytes User: Public ->Temp folder emptied: 0 bytes User: shirl ->Temp folder emptied: 0 bytes User: shirley ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 438816 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 71471 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67496 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 468.00 mb OTM by OldTimer - Version 3.1.17.2 log created on 05072011_085355 Files moved on Reboot... C:\Users\El Tel\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot... ..................................................................................................................... All Re-Booted fine, I still have control of his PC & my Sisters Laptop Finger x'd Once again you are a man Regards El Tel
  23. Hi Tom K I had trouble posting my previous reply for what ever reason so I came home. I have now ran into the same problem I had while I was at my Sisters with AVG being temporary disabled with this message Hence I've got the script on the desktop, but after it is dropped into Combofix it runs for a short while then disappeared. Regards El Tel
  24. Hi Tom K I didn't make it for the full English Breakfast, something cropped up. Had a bit of trouble disabling AVG, but sorted it. ComboFix 11-05-05.04 - El Tel 06/05/2011 16:02:36.1.3 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.2815.1645 [GMT 1:00] Running from: c:\users\El Tel\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\FullRemove.exe C:\readme.txt c:\users\dixon\AppData\Roaming\.# . . ((((((((((((((((((((((((( Files Created from 2011-04-06 to 2011-05-06 ))))))))))))))))))))))))))))))) . . 2011-05-06 15:08 . 2011-05-06 15:08 -------- d-----w- c:\users\Guest\AppData\Local\temp 2011-05-06 15:08 . 2011-05-06 15:08 -------- d-----w- c:\users\Dust Bin Lids\AppData\Local\temp 2011-05-06 14:59 . 2011-05-06 14:59 -------- d-----w- C:\32788R22FWJFW 2011-05-06 14:07 . 2011-05-06 14:07 -------- d-----w- c:\users\El Tel\AppData\Local\{1380B545-9C36-44D8-8922-EE0BFABC2992} 2011-05-06 08:25 . 2011-05-06 08:25 -------- d-----w- c:\users\El Tel\AppData\Local\{BB66765B-C928-463B-B94D-A1DB2B832FC1} 2011-05-05 20:52 . 2011-05-05 20:52 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{30F530A4-80FE-42FF-A785-F9D801EB4CB1} 2011-05-05 12:19 . 2011-05-05 12:19 -------- d-----w- c:\users\Guest\Tracing 2011-05-05 07:14 . 2011-05-05 07:15 -------- d-----w- c:\users\El Tel\AppData\Local\{EB8B75B4-AF3C-45AB-BD99-85F9DA5F1A97} 2011-05-05 05:33 . 2011-05-05 05:33 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{677CAFA1-6F4F-4AE1-A01F-24F581976957} 2011-05-04 15:34 . 2011-05-04 15:34 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{F2ED5762-44AE-45C5-9A24-810F668091EA} 2011-05-04 07:02 . 2011-05-04 07:02 -------- d-----w- c:\windows\system32\SPReview 2011-05-04 07:01 . 2011-05-04 07:01 -------- d-----w- c:\windows\system32\EventProviders 2011-05-04 06:59 . 2010-11-05 01:57 48976 ----a-w- c:\windows\system32\netfxperf.dll 2011-05-04 06:59 . 2010-11-05 01:57 1942856 ----a-w- c:\windows\system32\dfshim.dll 2011-05-04 06:57 . 2010-11-20 13:33 140672 ----a-w- c:\windows\system32\drivers\msdsm.sys 2011-05-04 06:56 . 2010-11-20 13:27 10240 ----a-w- c:\windows\system32\rdpcfgex.dll 2011-05-04 06:52 . 2010-11-20 13:27 524288 ----a-w- c:\windows\system32\wmicmiplugin.dll 2011-05-04 06:52 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll 2011-05-04 06:52 . 2010-11-20 13:27 1225216 ----a-w- c:\windows\system32\wbem\wbemcore.dll 2011-05-04 06:52 . 2010-11-20 13:27 933376 ----a-w- c:\windows\system32\SmiEngine.dll 2011-05-04 06:52 . 2010-11-20 13:25 199168 ----a-w- c:\windows\system32\PkgMgr.exe 2011-05-04 06:51 . 2010-11-20 13:26 422912 ----a-w- c:\windows\system32\drvstore.dll 2011-05-04 06:51 . 2010-11-20 13:26 399872 ----a-w- c:\windows\system32\dpx.dll 2011-05-04 06:49 . 2011-05-04 06:49 -------- d-----w- c:\users\El Tel\AppData\Local\{93C35592-558D-43C5-ADA5-19DEAB9572C9} 2011-05-04 06:36 . 2011-01-17 11:09 197120 ----a-w- c:\windows\system32\d3d10_1.dll 2011-05-04 06:36 . 2011-01-17 05:47 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll 2011-05-04 06:36 . 2010-11-20 13:26 321024 ----a-w- c:\windows\system32\d3d10_1core.dll 2011-05-04 06:36 . 2010-11-20 12:18 219136 ----a-w- c:\windows\SysWow64\d3d10_1core.dll 2011-05-04 03:33 . 2011-05-04 03:33 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{B7232148-B27C-47E6-B4DB-B4AAEF7FBDA3} 2011-05-03 18:48 . 2011-05-03 18:48 -------- d-----w- c:\users\El Tel\AppData\Local\{EDCAC1B1-4845-463B-BCF6-E31554C1D1A1} 2011-05-03 18:30 . 2011-05-03 18:30 -------- d-----w- c:\program files (x86)\Common Files\Java 2011-05-03 13:27 . 2011-05-03 13:27 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{70A80498-A3DF-4317-8813-0F50B641BE41} 2011-05-03 06:47 . 2011-05-03 06:48 -------- d-----w- c:\users\El Tel\AppData\Local\{390F89BD-851B-4FE9-96A6-D0C736EE2C70} 2011-05-02 19:29 . 2011-05-02 19:29 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{63EBF81C-9FEF-4630-802C-1EFB42CF6D89} 2011-05-02 16:51 . 2011-05-02 16:51 -------- d-----w- c:\program files (x86)\ESET 2011-05-02 16:29 . 2011-05-02 16:29 -------- d-----w- c:\users\El Tel\AppData\Local\{6D02BC31-911A-4792-9DE9-1CAE7903973B} 2011-05-02 07:17 . 2011-05-02 07:17 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{EC9599F3-4C0B-4554-A05F-EA2E1F21D399} 2011-05-01 18:01 . 2011-05-01 18:01 -------- d-----w- c:\users\El Tel\AppData\Local\{79674D28-82CB-40BA-AF9F-245C3C3380DF} 2011-05-01 16:30 . 2011-05-01 16:30 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{F47B8C8D-1A57-4BB3-A4F0-E128FA88CA61} 2011-05-01 04:29 . 2011-05-01 04:29 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{F571DA48-F5B5-4B65-B82A-0898A2807F92} 2011-04-30 10:48 . 2011-04-30 10:48 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{4493BB22-E400-4928-93F0-2FD0C12F2CDE} 2011-04-30 06:19 . 2011-04-30 06:20 -------- d-----w- c:\users\El Tel\AppData\Local\{01A06640-624F-41BD-A844-FA8B5ADC1561} 2011-04-29 19:08 . 2011-04-29 19:08 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{AD4BDAE0-265A-48A4-8A55-F24976C35057} 2011-04-29 07:07 . 2011-04-29 07:07 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{33562C3C-EF80-4269-A1C4-FB34DB92B787} 2011-04-28 19:06 . 2011-04-28 19:06 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{6611D1A0-A691-44F7-8F81-8E5A96EEC2E1} 2011-04-28 16:58 . 2011-04-28 16:58 -------- d-----w- c:\users\El Tel\AppData\Roaming\SUPERAntiSpyware.com 2011-04-28 16:58 . 2011-04-28 16:58 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2011-04-28 16:58 . 2011-04-28 16:58 -------- d-----w- c:\programdata\!SASCORE 2011-04-28 16:58 . 2011-04-28 16:59 -------- d-----w- c:\program files\SUPERAntiSpyware 2011-04-28 13:07 . 2011-04-28 13:07 388096 ----a-r- c:\users\El Tel\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-04-28 10:23 . 2011-04-28 10:23 -------- d-----w- c:\users\El Tel\AppData\Roaming\Malwarebytes 2011-04-28 10:23 . 2010-12-20 17:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-04-28 10:23 . 2011-04-28 10:23 -------- d-----w- c:\programdata\Malwarebytes 2011-04-28 10:23 . 2011-04-28 10:23 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-04-28 10:23 . 2010-12-20 17:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-04-28 09:38 . 2011-04-28 09:38 -------- d-----w- c:\users\El Tel\AppData\Local\{1D3A2E4C-179E-4169-A2EA-6F77D38D8E6A} 2011-04-28 04:05 . 2011-04-28 04:05 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{2B3913DA-435E-4667-92B3-EB63121C4795} 2011-04-27 13:39 . 2011-04-27 13:39 -------- d-----w- c:\users\El Tel\AppData\Local\{53C3A166-C5F7-4053-9D42-B6EE70ABEECC} 2011-04-27 12:53 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer.exe 2011-04-27 12:53 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\SysWow64\explorer.exe 2011-04-27 12:51 . 2011-03-12 12:08 1465344 ----a-w- c:\windows\system32\XpsPrint.dll 2011-04-27 12:51 . 2011-03-12 11:23 870912 ----a-w- c:\windows\SysWow64\XpsPrint.dll 2011-04-27 12:50 . 2011-03-11 06:41 1659776 ----a-w- c:\windows\system32\drivers\ntfs.sys 2011-04-27 12:50 . 2011-03-11 06:33 2565632 ----a-w- c:\windows\system32\esent.dll 2011-04-27 12:50 . 2011-03-11 05:33 1699328 ----a-w- c:\windows\SysWow64\esent.dll 2011-04-27 12:50 . 2011-03-11 06:41 189824 ----a-w- c:\windows\system32\drivers\storport.sys 2011-04-27 12:50 . 2011-03-11 06:41 166272 ----a-w- c:\windows\system32\drivers\nvstor.sys 2011-04-27 12:50 . 2011-03-11 06:41 148352 ----a-w- c:\windows\system32\drivers\nvraid.sys 2011-04-27 12:50 . 2011-03-11 06:41 410496 ----a-w- c:\windows\system32\drivers\iaStorV.sys 2011-04-27 12:50 . 2011-03-11 06:41 27008 ----a-w- c:\windows\system32\drivers\amdxata.sys 2011-04-27 12:50 . 2011-03-11 06:41 107904 ----a-w- c:\windows\system32\drivers\amdsata.sys 2011-04-27 12:50 . 2011-03-11 06:30 96768 ----a-w- c:\windows\system32\fsutil.exe 2011-04-27 12:50 . 2011-03-11 05:31 74240 ----a-w- c:\windows\SysWow64\fsutil.exe 2011-04-27 12:48 . 2011-02-18 10:51 31232 ----a-w- c:\windows\system32\prevhost.exe 2011-04-27 12:48 . 2011-02-18 05:39 31232 ----a-w- c:\windows\SysWow64\prevhost.exe 2011-04-27 12:43 . 2011-04-27 12:43 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{93B50A45-BDC5-4C38-9DDC-F5C58FADE0F3} 2011-04-27 12:32 . 2011-04-27 12:32 -------- d-----w- c:\users\El Tel\AppData\Local\{92C0150D-F102-47D8-84E4-7CE651F01DB1} 2011-04-27 10:27 . 2011-04-27 10:27 -------- d-----w- c:\users\dixon\AppData\Local\{6F757B46-2F14-4F67-986C-0590E2158D86} 2011-04-27 06:47 . 2011-04-27 06:47 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{922AD605-7D19-4291-8384-743E6C8F1C0E} 2011-04-26 21:12 . 2011-04-26 21:12 -------- d-----w- c:\program files (x86)\Trend Micro 2011-04-26 21:07 . 2011-04-26 21:08 -------- d-----w- c:\users\El Tel\AppData\Local\{58E61256-2807-4F73-84F9-F52220B7FD4D} 2011-04-26 20:41 . 2011-04-26 20:41 -------- d-----w- c:\users\El Tel\AppData\Local\Google 2011-04-26 17:57 . 2011-04-26 17:57 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{7ED5C301-021F-4AED-88FD-1881FC8521D7} 2011-04-25 22:00 . 2011-04-25 22:00 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{530E41C2-52BC-4D8B-9418-A2EB8CDB79BD} 2011-04-25 08:00 . 2011-04-25 08:00 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{EB6D8A39-5A8F-427F-A4A0-D1EB42FF9D1A} 2011-04-24 19:59 . 2011-04-24 19:59 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{0B02D848-2B2C-41CC-88BB-F49FEB547516} 2011-04-24 04:07 . 2011-04-24 04:07 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{B3D46CB4-EFBA-4362-A3A7-8A2AF575599D} 2011-04-23 14:10 . 2011-04-23 14:10 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{9A9679E3-7F27-4691-8A15-49C26BF1574C} 2011-04-22 19:57 . 2011-04-22 19:58 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{40B54645-9BD3-4DA0-AEEE-FC37E72B1EB0} 2011-04-22 07:56 . 2011-04-22 07:57 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{8F5AB6E3-B395-4844-9CB9-6432A1FB5BE5} 2011-04-21 19:56 . 2011-04-21 19:56 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{F453E030-890F-41C1-9B6D-1431ECCC7F78} 2011-04-21 18:02 . 2011-04-27 10:28 -------- d-----w- c:\users\dixon\AppData\Local\Windows Live 2011-04-21 18:02 . 2011-04-21 18:02 -------- d-----w- c:\users\dixon\AppData\Local\{73714353-AEC5-4F8A-969B-B9A605C80A66} 2011-04-21 07:55 . 2011-04-21 07:55 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{71CAC62D-0D29-48B0-9915-AF04CE647D98} 2011-04-20 19:54 . 2011-04-20 19:54 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{2F104B97-890D-46D1-8743-CD2637592E5A} 2011-04-20 07:53 . 2011-04-20 07:54 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{F1255C71-7853-4E86-B8B8-02653E5C24E2} 2011-04-19 19:17 . 2011-04-19 19:17 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{B6FE9061-6920-42FF-BC76-FCAADFEFCBE2} 2011-04-19 12:10 . 2011-05-05 20:52 -------- d-----r- c:\users\Bryn Limited\Dropbox 2011-04-19 12:08 . 2011-05-05 20:52 -------- d-----w- c:\users\Bryn Limited\AppData\Roaming\Dropbox 2011-04-19 05:57 . 2011-04-19 05:57 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{9CE2A4E7-482F-4405-9317-57F959A4C3B3} 2011-04-18 17:56 . 2011-04-18 17:56 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{15E6CE74-7EA6-4EC2-8EAF-D23757BC737A} 2011-04-18 05:55 . 2011-04-18 05:55 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{5E2AB35F-F569-49D6-A3C6-C5D8AC471C47} 2011-04-17 17:54 . 2011-04-17 17:55 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{505FC396-7D4C-4927-9CD4-D7B5A4FC3972} 2011-04-17 05:53 . 2011-04-17 05:54 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{3F906FB2-8DC4-47F3-8557-A1C944035CB7} 2011-04-16 17:53 . 2011-04-16 17:53 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{EA2DF3C8-4E7E-41A6-AA8C-E1C0838717CE} 2011-04-16 05:35 . 2011-04-16 05:35 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{1951A8BD-C11C-41BD-B037-57D6194DC2F6} 2011-04-15 11:33 . 2011-04-15 11:34 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{5C36293D-7F72-4603-886A-ACC5D9C07547} 2011-04-14 23:33 . 2011-04-14 23:33 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{C6A2FE62-9E98-4CF9-96AB-2DF73B77EF20} 2011-04-14 10:40 . 2011-03-01 08:57 32592 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\np_gp.dll 2011-04-14 10:39 . 2011-04-27 13:38 -------- d-----w- c:\programdata\NOS 2011-04-14 10:39 . 2011-04-27 12:38 -------- d-----w- c:\program files (x86)\NOS 2011-04-14 10:27 . 2011-04-14 10:27 -------- d-----w- c:\users\El Tel\AppData\Local\{0FF0A447-8A59-4320-A5BF-14D41D3675BD} 2011-04-14 09:58 . 2011-04-14 09:59 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{D3BFFD55-09EA-42B1-B5B2-705CA159A77C} 2011-04-14 05:52 . 2011-03-03 06:24 183296 ----a-w- c:\windows\system32\dnsrslvr.dll 2011-04-14 02:39 . 2011-04-14 02:39 103864 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll 2011-04-14 02:39 . 2011-04-14 02:39 103864 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll 2011-04-13 20:46 . 2011-04-13 20:46 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{EDD78E7D-53A9-4556-91DA-DAA6500787F5} 2011-04-13 10:54 . 2011-04-13 10:54 -------- d-----w- c:\users\El Tel\AppData\Local\{6AE3DC88-D390-4262-A384-7FB20B8BDF7C} 2011-04-12 20:49 . 2011-04-12 20:50 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{5EE291C7-A8F2-4506-92C6-466D51C3D00A} 2011-04-11 20:57 . 2011-04-11 20:57 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{668E0582-ED75-4D67-9350-C6723A5A40B2} 2011-04-11 06:26 . 2011-04-11 06:26 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{3FA90C10-37A4-4411-B05B-9044C061E2BE} 2011-04-10 18:25 . 2011-04-10 18:25 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{34D756A8-457C-4D26-8470-1B205BA1C728} 2011-04-10 06:24 . 2011-04-10 06:25 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{9A70EEE8-8AAD-4938-8DD6-5A41AEE125B9} 2011-04-09 17:56 . 2011-04-09 17:56 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{2B30C600-AA07-4F06-AF61-83364FAE3D6A} 2011-04-09 05:55 . 2011-04-09 05:55 -------- d-----w- c:\users\Bryn Limited\AppData\Local\{1DFF729C-A644-4F74-80FB-E38AE9A2D0E5} . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-04 07:23 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll 2011-05-04 07:23 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll 2011-04-14 04:07 . 2010-10-15 19:08 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll 2011-03-09 04:54 . 2010-06-24 11:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-03-04 06:19 . 2011-04-27 12:51 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2011-03-04 06:19 . 2011-04-27 12:51 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2011-02-19 12:05 . 2011-03-09 04:58 1139200 ----a-w- c:\windows\system32\FntCache.dll 2011-02-19 12:04 . 2011-03-09 04:58 1544192 ----a-w- c:\windows\system32\DWrite.dll 2011-02-19 12:04 . 2011-03-09 04:58 902656 ----a-w- c:\windows\system32\d2d1.dll 2011-02-19 06:30 . 2011-03-09 04:58 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll 2011-02-19 06:30 . 2011-03-09 04:58 739840 ----a-w- c:\windows\SysWow64\d2d1.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760] "QuickTime Task"="c:\program files (x86)\QuickTime\qttask.exe" [2010-06-12 98304] "WinPatrol"="c:\program files (x86)\BillP Studios\WinPatrol\winpatrol.exe" [2010-05-31 323976] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] "SSDMonitor"="c:\program files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe" [2010-08-05 104408] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672] . c:\users\Bryn Limited\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\El Tel\AppData\Roaming\Dropbox\bin\Dropbox.exe [N/A] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . R0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x] R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [x] R2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG10\avgwdsvc.exe [x] R2 lxeaCATSCustConnectService;lxeaCATSCustConnectService;c:\windows\system32\spool\DRIVERS\x64\3\\lxeaserv.exe [2010-04-14 45736] R3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe [2009-07-14 27136] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x] R4 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x] R4 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x] R4 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x] S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752] S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-08 169312] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] S2 Greg_Service;GRegService;c:\program files (x86)\Packard Bell\Registration\GregHSRW.exe [2009-08-28 1150496] S2 lxea_device;lxea_device;c:\windows\system32\lxeacoms.exe [2010-01-07 1052328] S2 ntrconnect;ntrconnect;c:\program files (x86)\NTR global\NTRconnect\NTRconnect.exe [2010-02-11 403184] S2 OberonGameConsoleService;Oberon Media Game Console service;c:\program files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe [2009-08-29 44312] S2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [2010-08-05 583640] S2 Updater Service;Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2009-07-04 240160] S3 NTRvdd;NTRvdd;c:\windows\system32\DRIVERS\NTRvdd.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper . Contents of the 'Scheduled Tasks' folder . 2011-05-02 c:\windows\Tasks\RMSchedule.job - c:\program files (x86)\Registry Mechanic\RegMech.exe [2011-02-01 08:46] . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\Bryn Limited\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\Bryn Limited\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\Bryn Limited\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\Bryn Limited\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-20 7981088] "lxeamon.exe"="c:\program files (x86)\Lexmark S300-S400 Series\lxeamon.exe" [2010-01-18 770728] "EzPrint"="c:\program files (x86)\Lexmark S300-S400 Series\ezprint.exe" [2010-01-18 139944] "snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0809&m=imedia_s3210&r=173602101606p03d5v135y4923924n mLocal Page = c:\windows\SysWOW64\blank.htm IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM LSP: %SYSTEMROOT%\system32\nvLsp.dll DPF: {0FADB9AA-6955-4319-B538-BB1461E11A28} - hxxps://www.ntrconnect.com/main/mod/setup/beta/ntrplugin1242v_2.cab FF - ProfilePath - . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file) Toolbar-Locked - (no file) AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-909527836-1280678326-320050609-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-909527836-1280678326-320050609-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-05-06 16:09:59 ComboFix-quarantined-files.txt 2011-05-06 15:09 . Pre-Run: 111,113,003,008 bytes free Post-Run: 111,166,251,008 bytes free . - - End Of File - - 25FD6340C66BA249C0A6CC0EFC539B91 Regards El Tel
×
×
  • Create New...