[Inactive] Constantly reappearing deleted folder! - Page 2
Page 2 of 2 FirstFirst 12
Results 16 to 26 of 26

Thread: [Inactive] Constantly reappearing deleted folder!

  1. #16
    Join Date
    Sep 2010
    Location
    United Kingdom
    Posts
    66

    Extras.txt log

    OTL Extras logfile created on: 27/08/2011 16:33:45 - Run 1
    OTL by OldTimer - Version 3.2.26.5 Folder = C:\Users\Michelle\Desktop
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    3.25 Gb Total Physical Memory | 1.71 Gb Available Physical Memory | 52.64% Memory free
    6.71 Gb Paging File | 5.18 Gb Available in Paging File | 77.14% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 581.52 Gb Total Space | 242.83 Gb Free Space | 41.76% Space Free | Partition Type: NTFS
    Drive J: | 442.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
    Drive K: | 930.86 Gb Total Space | 524.27 Gb Free Space | 56.32% Space Free | Partition Type: NTFS

    Computer Name: MICHELLE-PC | User Name: Michelle | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
    Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
    Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
    Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
    "VistaSp1" = Reg Error: Unknown registry data type -- File not found
    "VistaSp2" = Reg Error: Unknown registry data type -- File not found

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-3795328490-2948772482-1105704417-1000]
    "EnableNotifications" = 1
    "EnableNotificationsRef" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0FA53075-0156-4FD4-95F4-FFFDAF72F256}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=file and printer sharing (spooler service - rpc-epmap) |
    "{1A7B7D77-BB50-4183-85BD-2E150266CDBF}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{1AB6DC13-8090-41A3-86D1-0C081DA3F01B}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |
    "{2C33666A-1ADA-4A4B-9514-7B9758080122}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{31EC1066-8B33-45C5-838A-DE2C276D6328}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
    "{4F35D02E-7CAC-4F88-929A-1BEC92F6E294}" = lport=139 | protocol=6 | dir=in | app=system |
    "{590A92CC-CC4B-43AF-A49B-0E135097E54F}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
    "{5AB0E9F9-29D0-47CA-8F33-57FE56F5C47F}" = lport=137 | protocol=17 | dir=in | app=system |
    "{5C1C199D-9C78-44A8-B2FC-944EFA364904}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe |
    "{5C4D71F2-594E-4653-8538-F04B5A73D98D}" = lport=49182 | protocol=6 | dir=in | name=akamai netsession interface |
    "{5FA56592-3C7F-4C1F-8439-32213A83D6E3}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |
    "{62F3DF59-6125-4385-A538-14FD592792B7}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{64622766-B3E6-49B4-BAFD-8212437AC945}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{87EF7966-5754-4424-90BE-15471129A49C}" = rport=139 | protocol=6 | dir=out | app=system |
    "{8B43A88B-1E4C-47DF-8154-307D2A98219C}" = lport=445 | protocol=6 | dir=in | app=system |
    "{A08A626C-F523-46A1-BB40-2A9D3B826C66}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |
    "{A6176AB5-7D6B-49D3-9F81-4EC854F24CAE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
    "{BDD9702A-D18F-4F4B-8FBB-F38955093A50}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{CA071E27-AD69-4CD1-8F41-BEF0773ECEA5}" = rport=445 | protocol=6 | dir=out | app=system |
    "{E15A701B-1312-4A0D-8BD2-2428099C26B5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{EB47C25E-10F1-4276-85B5-F75DC6BA5F64}" = rport=138 | protocol=17 | dir=out | app=system |
    "{EC6B24F2-4CB6-4F1C-80E5-5D4189B18719}" = lport=10243 | protocol=6 | dir=in | app=system |
    "{F2F1DFA8-D31F-4341-B867-D50D0D0EB3A4}" = rport=137 | protocol=17 | dir=out | app=system |
    "{F92659C2-5CEA-464F-B508-EC96B9891DCD}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{F9C6C22B-6844-4290-A0F6-194167004E5E}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{FB32B627-46E8-4B10-98FD-7DF4E68F1279}" = rport=10243 | protocol=6 | dir=out | app=system |
    "{FD4783AC-7BF6-49DC-AB8D-155DDD873B9E}" = lport=138 | protocol=17 | dir=in | app=system |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{013B0D67-D4A8-4AAF-99E3-68AAB1BE4BAA}" = protocol=6 | dir=in | app=c:\program files\addthis toolbar\troubleshooter.exe |
    "{05E02223-8B06-4908-8237-B4E18406A1B1}" = protocol=6 | dir=out | app=system |
    "{0EDB107F-1243-4719-A20E-C6C9BCEA0C76}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{11B88237-F5E9-4DE1-9A5D-D98C328169C7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{158943F1-0684-4AF1-8B13-026DAC41D736}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{15FE6B04-664A-46D4-8013-C1A81C6980BA}" = protocol=1 | dir=in | name=file and printer sharing (echo request - icmpv4-in) |
    "{2025AA85-DB83-48F9-908D-95BDAFFB3788}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
    "{34135D52-5C56-4159-9062-8EF2E0DFBEC8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{3DFFC60E-6DAE-42F2-A005-087A7C6E723B}" = protocol=17 | dir=in | app=c:\program files\addthis toolbar\toolbarupdate.exe |
    "{4CCAD550-9F39-4C87-952A-7D9B8725CA9E}" = protocol=6 | dir=in | app=c:\program files\ivt corporation\bluesoleil\bluesoleil.exe |
    "{614A0B3E-FAFE-4A43-B763-ED3D39F4E792}" = protocol=17 | dir=in | app=c:\program files\addthis toolbar\troubleshooter.exe |
    "{6DF52180-72D1-4EFD-AB22-91490E86AACC}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{6E3ED1FA-209C-4B19-B2E1-5ED81C453879}" = protocol=6 | dir=in | app=c:\program files\addthis toolbar\toolbarupdate.exe |
    "{6FDE41FC-32A4-4026-83B6-820F092E5808}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{6FEE9C19-DADF-4C35-A64F-589315C9FB29}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
    "{724F2141-CAF9-488A-A54B-95B99FE6E4DE}" = protocol=58 | dir=in | name=file and printer sharing (echo request - icmpv6-in) |
    "{7F4FC8E9-9D9A-4CDC-B6C2-444A46574C33}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
    "{8F8AE3FA-8887-4D10-BE46-3EB50FA9A575}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{9059F0CE-E912-4960-813D-D84E6E5F0A6B}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
    "{94A17803-39AA-40B9-B9C8-EF408F77C7F8}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
    "{97336E95-FEE2-4801-A3D4-FD7165856E0A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{A05355B2-CF79-4E79-BE82-1FE2E4829718}" = protocol=1 | dir=out | name=file and printer sharing (echo request - icmpv4-out) |
    "{A112473A-D492-4BD8-B283-A90C4822C816}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
    "{AC0EA413-6C73-448C-A8F3-7C57F305264F}" = dir=in | app=c:\program files\itunes\itunes.exe |
    "{B82CA632-E25F-40ED-8C40-AC5A3B32C69F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{B8D07956-874E-483E-BD61-CF9F1EDDB347}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{BCA988CC-6C3B-42D0-8947-E1A8B95E41EA}" = protocol=6 | dir=in | app=c:\program files\kodak\aio\center\networkprinterdiscovery.exe |
    "{C0B065A9-ED1E-4D8C-963F-C8AE4C07CB29}" = protocol=58 | dir=out | name=file and printer sharing (echo request - icmpv6-out) |
    "{C2D55C35-4789-456A-9B23-475C049124D8}" = protocol=17 | dir=in | app=c:\program files\kodak\aio\center\networkprinterdiscovery.exe |
    "{C86915DA-613C-44B6-82A9-34FB5A034ACF}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
    "{CFB99A36-D10A-428C-8C4B-24F12F3D6665}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{D9CE49A4-E7DC-4404-BC1F-16B779006A07}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{E1ADC91E-0300-4B33-9FD8-78693DBABE1B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{E3C8512B-6D22-4E03-A7BB-9D9586F87D57}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{E929E908-73BD-4C1B-AC39-090BE9383C85}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
    "{EE48E286-B3B3-4A63-8859-916D663141FA}" = protocol=17 | dir=in | app=c:\program files\ivt corporation\bluesoleil\bluesoleil.exe |
    "{F9876AAF-0BFC-442A-A0E4-5943D2008AC4}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
    "TCP Query User{036AE412-820C-4E8E-9CA4-48FE25868879}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
    "TCP Query User{0506FA44-D2C4-4529-84DB-95D1B6875B43}C:\program files\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files\winamp\winamp.exe |
    "TCP Query User{DD972515-D5CF-4236-81AD-E815302254AB}C:\program files\nero\nero 7\nero home\nerohome.exe" = protocol=6 | dir=in | app=c:\program files\nero\nero 7\nero home\nerohome.exe |
    "TCP Query User{F2A9FFF8-9814-4887-B804-E6BBEFAD43AA}C:\program files\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\program files\spotify\spotify.exe |
    "TCP Query User{FF3771EA-1E50-4690-B2D6-7DFDAA671D50}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
    "UDP Query User{0D6F9367-6AD9-4187-B85F-2BEEF86F1A4A}C:\program files\nero\nero 7\nero home\nerohome.exe" = protocol=17 | dir=in | app=c:\program files\nero\nero 7\nero home\nerohome.exe |
    "UDP Query User{43629091-BC6D-4E81-81AE-50F14FE80C7A}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
    "UDP Query User{5ACF3E43-202E-4137-8125-B8EDC833AB5B}C:\program files\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files\winamp\winamp.exe |
    "UDP Query User{A8D54F49-D8E0-4FD3-B6AE-DF02760A3657}C:\program files\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\program files\spotify\spotify.exe |
    "UDP Query User{C20C303F-DC89-4BF1-83B0-AAB4F468C2E4}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{01825C12-4EC3-4617-B700-4EF48ED8C187}" = Catalyst Control Center - Branding
    "{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
    "{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
    "{0470A728-2359-7467-3027-CC9A5948BE68}" = CCC Help German
    "{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
    "{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt
    "{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
    "{08B857DF-E6F9-4283-853A-4F329CC09A4F}" = ESET NOD32 Antivirus
    "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
    "{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
    "{0C432DEB-FBF2-A5E0-FDB7-4B39F7FAF0D4}" = Adobe Community Help
    "{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
    "{10934A28-0CC6-4B98-A14F-76B3546003AF}" = ksDIP
    "{10A44844-4465-456E-8C97-80BDD4F68845}" = Windows Live ID Sign-in Assistant
    "{1240A058-8BCE-4A3B-BF82-6E5B801D71BA}" = Garmin City Navigator Europe NT 2009 Update
    "{15D64BA8-DEF7-3F7D-C6F2-480978EB8EF0}" = CCC Help Greek
    "{15F4085A-BC98-4590-AFFD-03BBBE49524E}" = Garmin Communicator Plugin
    "{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
    "{1965C9BB-9114-4A50-AEC7-E62414BB117B}" = EASEUS Data Recovery Wizard Professional 4.3.6
    "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
    "{206FD69B-F9FE-4164-81BD-D52552BC9C23}" = GearDrvs
    "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
    "{22F2A60F-7FD4-A0A9-0AE2-BC90A95C6E11}" = CCC Help Japanese
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{237CD223-1B9D-47E8-A76C-E478B83CCEA2}" = File Uploader
    "{23B59ED4-C360-11D7-875B-0090CC005647}" = EPSON PRINT Image Framer Tool2.1
    "{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 24
    "{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}" = Kodak AIO Printer
    "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
    "{2A539CD9-0F75-4875-9A32-E06DD93C4114}" = Adobe Extension Manager CS3
    "{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox
    "{328019A7-0012-401D-96A2-4CDDD02675A8}" = Garmin POI Loader
    "{3A12C952-61D5-4C3B-B68B-8CFBE47E22F1}" = Adobe Setup
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{3C954B1D-5C28-C875-C39D-CBE0A616E2F8}" = CCC Help Czech
    "{42D2C1F2-1804-3D91-8B09-D1B95EF521DF}" = CCC Help French
    "{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
    "{4779C41B-FE50-F248-1E20-0099886A665F}" = CCC Help Hungarian
    "{48B41C3A-9A92-4B81-B653-C97FEB85C910}" = C4USelfUpdater
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
    "{4B719A70-F14A-4f5c-90B5-346B24B7FFF1}" = Windows 7 Upgrade Advisor
    "{4F5CE4A6-1552-B5DE-1806-0882ADEB90A5}" = Catalyst Control Center Graphics Previews Vista
    "{56BA241F-580C-43D2-8403-947241AAE633}" = center
    "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
    "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
    "{58E648C4-90A8-D518-2B93-F5C227D5AEF4}" = CCC Help Dutch
    "{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver
    "{5F5A5141-C170-D105-E52F-F4506B088BC6}" = Catalyst Control Center Core Implementation
    "{634B8365-D9EF-89AC-5352-B205EDA8BFCD}" = CCC Help Italian
    "{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
    "{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
    "{65F5B7AF-3363-11D7-BB6B-00018021113F}" = EPSON PhotoQuicker3.5
    "{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
    "{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
    "{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
    "{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
    "{6C11D561-620B-47DA-A693-4C597F3CDF40}" = EPSON Smart Panel
    "{6C556A90-E164-ACB3-BFA6-E99B6D0B66AE}" = ATI AVIVO Codecs
    "{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
    "{706EA4A8-97B5-4C29-A0F3-0B38C666F0C4}" = QuarkXPress
    "{709817E4-5439-4206-8738-796B34B623BD}" = MetaBoli
    "{71205483-637B-3C3E-F9CD-3888AB9B511F}" = CCC Help Chinese Standard
    "{715A33E0-5706-2161-1C08-EEE1BDAE28A6}" = ccc-utility
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{76AE104F-6C38-0E88-EF96-3160E7A6BB7F}" = Catalyst Control Center InstallProxy
    "{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.0.0.7
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
    "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{7BD0A2D8-4EA0-43C6-BDF8-DDA87B8031C6}" = PIF DESIGNER2.1
    "{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
    "{7F811A54-5A09-4579-90E1-C93498E230D9}" = Packard Bell Recovery Management
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{857CBF4A-192C-44B0-86A5-6281FCEFA1FE}" = FileOpen Client
    "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8A8F8391-4C2C-4BE1-A984-CD4A5A546467}" = EPSON Easy Photo Print
    "{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
    "{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
    "{8F85CC2C-4B26-4CF6-B835-DC59BCEDD287}" = Bluesoleil2.7.0.13 VoIP Release 071227
    "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
    "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
    "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
    "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
    "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2007
    "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
    "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007
    "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
    "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
    "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
    "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
    "{926466ED-BD5A-3FE7-9DA3-4AE3631DFB18}" = CCC Help Russian
    "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
    "{94393349-F976-6E15-A754-E48C1C090C3E}" = Catalyst Control Center Graphics Light
    "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9B97EC91-B3FD-4BFF-88FC-5345A26AC2E7}" = Adobe Illustrator CS5
    "{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
    "{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
    "{A4E56BBF-A48B-4D90-8C48-22DB3E244E46}" = Freecycle Internet Explorer Plugin
    "{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AB7032FF-AFED-4C58-AA5C-8473B273793A}" = HDReg
    "{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
    "{AC76BA86-1033-F400-7760-000000000004}{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
    "{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4
    "{AF860EA1-884F-A298-6C62-9F4BD1E7B44F}" = CCC Help English
    "{B1BB09AF-CD69-F510-2E39-C8FF94B05D7F}" = CCC Help Swedish
    "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 270.61
    "{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 270.61
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 270.61
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 270.61
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.1.34
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
    "{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
    "{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
    "{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
    "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
    "{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
    "{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
    "{BBB5BB17-41D2-5BD0-E058-28E58D78FEAC}" = CCC Help Thai
    "{BC1683EC-6826-0FD5-11B1-B251C9E20D93}" = CCC Help Danish
    "{BD8D8884-DC62-EDC9-EFE1-FEA1FE7D2A40}" = CCC Help Polish
    "{BE94C681-68E2-4561-8ABC-8D2E799168B4}" = essentials
    "{BEAAF33A-2F62-9D6C-8A6B-A6C15821ABED}" = CCC Help Portuguese
    "{BED9AEE2-4E0B-E4D7-CC55-E87D04CBD00E}" = Catalyst Control Center Graphics Full Existing
    "{BFBCF96F-7361-486A-965C-54B17AC35421}" = ocr
    "{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
    "{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
    "{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
    "{C515644E-60C8-4B92-BABA-3006AD0921DB}_is1" = Veedid Desktop To-Do List 1.7
    "{C73CA646-73B3-4AEF-A136-C37505745174}" = iTunes
    "{C768790F-04FB-11E0-9B2C-001AA037B01E}" = Google Earth
    "{C85E2B36-079C-C64A-BEB0-9D785C0106CB}" = ccc-core-static
    "{CA786CFF-1D31-4804-B436-F3405B14357F}" = Packard Bell Updator
    "{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
    "{CBE3C837-EDFB-427E-BB82-A4B31EDF07FF}" = ArcSoft TotalMedia Extreme
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{CEBADC53-2CDB-079E-9B9E-841B2EFBC2AC}" = CCC Help Chinese Traditional
    "{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
    "{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
    "{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
    "{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
    "{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
    "{D45E8C45-B601-4A80-AFD8-E16338744DE1}" = ArcSoft Panorama Maker 4
    "{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
    "{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3
    "{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
    "{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
    "{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
    "{DC5F786F-0733-46AC-8160-972A6906A872}" = WD SmartWare
    "{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
    "{DEB33594-238E-6E57-6552-938F73F8CE9F}" = CCC Help Turkish
    "{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Software
    "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
    "{E5E510EE-6D26-EFA5-59E2-EF47F9BF545F}" = ATI Catalyst Install Manager
    "{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
    "{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
    "{EB4D42D6-627A-424E-981F-1474AFF3CC29}" = ArcSoft MediaImpression SE for Kodak
    "{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}" = ScanToWeb
    "{ED869B12-B548-A868-A7C8-102FFDB470E1}" = Catalyst Control Center Localization All
    "{F01D5ED5-D53A-4468-B428-149DC2CB3110}" = Adobe Dreamweaver CS3
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F2D40132-421A-873C-9245-FAA5179B0D46}" = Skins
    "{F413B69D-4AD6-42AB-AEA5-0548989FAD50}" = Norton 360
    "{F4EA67C9-6748-4C1E-9AFF-04149AC75D95}" = Packard Bell ImageWriter
    "{F55A54F8-6129-387E-DE79-F5ED9284664A}" = CCC Help Finnish
    "{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
    "{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
    "{F90D6825-8F1F-4E3A-9E42-A9C8A9DD1033}" = Nero 7 Ultra Edition
    "{F93F9CAD-7956-88D1-B051-0E3C03C9B608}" = CCC Help Norwegian
    "{F9766AC1-1461-1033-B862-DF8FE1C033BE}" = Adobe InDesign CS5
    "{F99520C7-7EE6-472E-8DD8-E60003A9292F}" = WOT for Internet Explorer
    "{FB8E602B-020E-BF21-9B70-BA0789ACF8F6}" = Catalyst Control Center Graphics Full New
    "{FC0C2642-24E3-8AF2-B1E5-899758C67EF7}" = CCC Help Spanish
    "{FCEAC7EC-B8EC-447D-5689-CE40357CBE59}" = CCC Help Korean
    "{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
    "{FE24086F-3B0C-4C47-A874-97A7B8E2FBBE}" = aioscnnr
    "{FF3999BE-1A7B-4738-88AA-97BF14094A4A}" = PictureProject
    "49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
    "7-Zip" = 7-Zip 9.15 beta
    "AddThis Toolbar" = AddThis Toolbar
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "Adobe_435a6af7459cb02a9c1138113a26e93" = Adobe Dreamweaver CS3
    "Akamai" = Akamai NetSession Interface
    "AviSynth" = AviSynth 2.5
    "CCleaner" = CCleaner
    "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
    "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
    "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
    "Creative VF0090" = Creative WebCam Vista Plus Driver (1.02.02.0414)
    "Creative WebCam Center" = Creative WebCam Center
    "Creative WebCam Vista Plus User's Guide English" = Creative WebCam Vista Plus User's Guide (English)
    "Defraggler" = Defraggler
    "EasyBits Magic Desktop" = EasyBits Magic Desktop
    "ENTERPRISE" = Microsoft Office Enterprise 2007
    "EPSON Printer and Utilities" = EPSON Printer Software
    "EPSON Scanner" = EPSON Scan
    "ESET Online Scanner" = ESET Online Scanner v3
    "ESPRX620 Series Reference Guide" = ESPRX620 Series Reference Guide
    "ESPRX620 Software Guide" = ESPRX620 Software Guide
    "FileZilla Client" = FileZilla Client 3.5.0
    "Foxit Reader" = Foxit Reader
    "Get Yahoo! Messenger" = Get Yahoo! Messenger
    "KLiteCodecPack_is1" = K-Lite Codec Pack 5.5.1 (Full)
    "Magic ISO Maker v5.4 (build 0239)" = Magic ISO Maker v5.4 (build 0239)
    "MagicDisc 2.7.106" = MagicDisc 2.7.106
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Mozilla Firefox 5.0 (x86 en-GB)" = Mozilla Firefox 5.0 (x86 en-GB)
    "MP3 To Ringtone Gold_is1" = MP3 To Ringtone Gold 8.0
    "NEWT Professional 2.5_is1" = NEWT Professional 2.5.175
    "Nikon FotoShare" = Nikon FotoShare
    "NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
    "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
    "OJOsoft Total Video Converter_is1" = OJOsoft Total Video Converter
    "Pen Tablet Driver" = Bamboo
    "PowerISO" = PowerISO
    "PRJPRO" = Microsoft Office Project Professional 2007
    "RealPlayer 12.0" = RealPlayer
    "RocketDock_is1" = RocketDock 1.3.5
    "Secunia PSI" = Secunia PSI (2.0.0.2001)
    "Spotify" = Spotify
    "SystemRequirementsLab" = System Requirements Lab
    "uTorrent" = µTorrent
    "VLC media player" = VLC media player 1.1.7
    "Web Page Maker" = Web Page Maker 3.1
    "Web Page Maker_is1" = Web Page Maker V3.1
    "Winamp" = Winamp
    "WinLiveSuite_Wave3" = Windows Live Essentials
    "Works9SE" = Microsoft Works 9.0 SE
    "Yahoo! Companion" = Yahoo! Toolbar
    "Yahoo! Search Defender" = Yahoo! Search Protection
    "Yahoo! Software Update" = Yahoo! Software Update
    "YInstHelper" = Yahoo! Install Manager

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-3795328490-2948772482-1105704417-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "DAL Scanner" = DAL Scanner
    "Facebook Plug-In" = Facebook Plug-In
    "Game Organizer" = EasyBits GO
    "uTorrent" = µTorrent
    "Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-3795328490-2948772482-1105704417-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "DAL Scanner" = DAL Scanner
    "Facebook Plug-In" = Facebook Plug-In
    "uTorrent" = µTorrent
    "Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 25/08/2011 18:28:15 | Computer Name = Michelle-PC | Source = VSS | ID = 8194
    Description =

    Error - 25/08/2011 18:28:37 | Computer Name = Michelle-PC | Source = VSS | ID = 8194
    Description =

    Error - 25/08/2011 18:33:15 | Computer Name = Michelle-PC | Source = VSS | ID = 8194
    Description =

    Error - 25/08/2011 18:33:39 | Computer Name = Michelle-PC | Source = VSS | ID = 8194
    Description =

    Error - 25/08/2011 18:38:15 | Computer Name = Michelle-PC | Source = VSS | ID = 8194
    Description =

    Error - 25/08/2011 18:38:36 | Computer Name = Michelle-PC | Source = VSS | ID = 8194
    Description =

    Error - 25/08/2011 18:43:15 | Computer Name = Michelle-PC | Source = VSS | ID = 8194
    Description =

    Error - 25/08/2011 18:43:38 | Computer Name = Michelle-PC | Source = VSS | ID = 8194
    Description =

    Error - 27/08/2011 09:50:08 | Computer Name = Michelle-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 27/08/2011 09:54:04 | Computer Name = Michelle-PC | Source = MsiInstaller | ID = 11314
    Description =

    [ OSession Events ]
    Error - 10/02/2010 15:46:37 | Computer Name = Michelle-PC | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 22180
    seconds with 1860 seconds of active time. This session ended with a crash.

    Error - 03/02/2011 08:55:21 | Computer Name = Michelle-PC | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1
    seconds with 0 seconds of active time. This session ended with a crash.

    [ System Events ]
    Error - 25/08/2011 03:59:13 | Computer Name = Michelle-PC | Source = Print | ID = 19
    Description = The print spooler failed to share printer Send To OneNote 2007 with
    shared resource name Send To OneNote 2007. Error 2114. The printer cannot be used
    by others on the network.

    Error - 25/08/2011 04:00:18 | Computer Name = Michelle-PC | Source = Service Control Manager | ID = 7026
    Description =

    Error - 25/08/2011 04:01:18 | Computer Name = Michelle-PC | Source = WMPNetworkSvc | ID = 866312
    Description =

    Error - 25/08/2011 04:01:18 | Computer Name = Michelle-PC | Source = WMPNetworkSvc | ID = 866312
    Description =

    Error - 25/08/2011 05:24:47 | Computer Name = Michelle-PC | Source = Service Control Manager | ID = 7030
    Description =

    Error - 25/08/2011 05:32:15 | Computer Name = Michelle-PC | Source = Service Control Manager | ID = 7030
    Description =

    Error - 25/08/2011 05:35:51 | Computer Name = Michelle-PC | Source = Service Control Manager | ID = 7030
    Description =

    Error - 27/08/2011 09:49:59 | Computer Name = Michelle-PC | Source = WMPNetworkSvc | ID = 866312
    Description =

    Error - 27/08/2011 09:50:01 | Computer Name = Michelle-PC | Source = WMPNetworkSvc | ID = 866308
    Description =

    Error - 27/08/2011 09:50:09 | Computer Name = Michelle-PC | Source = Service Control Manager | ID = 7026
    Description =


    < End of report >

  2. #17
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      Code:
      :OTL
      IE - HKU\S-1-5-21-3795328490-2948772482-1105704417-1002\..\URLSearchHook: - Reg Error: Key error. File not found
      O16 - DPF: Garmin Communicator Plug-In http://download.garmin.com/gcp/ie/2....nAxControl.CAB (Reg Error: Key error.)
      [2011/08/22 11:13:43 | 000,000,000 | R--D | C] -- C:\Users\Michelle\Desktop\Shares
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.


    =====================================================

    Last scans...

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.



    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.



    3. Please, run F-Secure Online Scanner

    • Disable your Antivirus program.
    • Checkmark I have read and accepted the license terms.
    • Click on Run Check button.
    • Quick scan (recommended) option will come pre-checked. Don't change it.
    • Click on Start button.
    • When scan is done, in Step 3: Clean the files, leave all settings as they're.
    • Click Next button.
    • Click Full report... button.
    • Copy report's content and paste it into your next reply.

  3. #18
    Join Date
    Sep 2010
    Location
    United Kingdom
    Posts
    66

    OTL FIX LOG (The folder has gone!)

    All processes killed
    ========== OTL ==========
    Registry value HKEY_USERS\S-1-5-21-3795328490-2948772482-1105704417-1002\Software\Microsoft\Internet Explorer\URLSearchHooks\\ not found.
    Starting removal of ActiveX control Garmin Communicator Plug-In
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Garmin Communicator Plug-In\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Garmin Communicator Plug-In\ not found.
    Folder C:\Users\Michelle\Desktop\Shares\ not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes

    User: Michelle
    ->Temp folder emptied: 33844 bytes
    ->Temporary Internet Files folder emptied: 185337083 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 59896084 bytes
    ->Flash cache emptied: 3874 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: UpdatusUser
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 76279629 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 4042706 bytes

    Total Files Cleaned = 311.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default

    User: Default User

    User: Michelle
    ->Flash cache emptied: 0 bytes

    User: Public

    User: UpdatusUser

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.26.5 log created on 08282011_191848

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...

  4. #19
    Join Date
    Sep 2010
    Location
    United Kingdom
    Posts
    66

    SecurityCheck log

    Results of screen317's Security Check version 0.99.7
    Windows Vista Service Pack 2 (UAC is enabled)
    Internet Explorer 8
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    ESET NOD32 Antivirus
    ESET Online Scanner v3
    Norton 360
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    CCleaner
    Java(TM) 6 Update 24
    Out of date Java installed!
    Adobe Flash Player 10.2.152.32
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    ``````````End of Log````````````

  5. #20
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    1. Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    2. Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.

  6. #21
    Join Date
    Sep 2010
    Location
    United Kingdom
    Posts
    66

    F-Secure log

    Scanning Report
    Sunday, August 28, 2011 19:49:05 - 19:54:55
    Computer name: MICHELLE-PC
    Scanning type: Quick scan
    Target: System


    --------------------------------------------------------------------------------

    2 malware found
    TrackingCookie.2o7 (spyware)
    System (Disinfected)
    TrackingCookie.Advertising (spyware)
    System (Disinfected)

    --------------------------------------------------------------------------------

    Statistics
    Scanned:
    Files: 5295
    System: 5295
    Not scanned: 0
    Actions:
    Disinfected: 2
    Renamed: 0
    Deleted: 0
    Not cleaned: 0
    Submitted: 0

    --------------------------------------------------------------------------------

    Options
    Scanning engines:

    --------------------------------------------------------------------------------

    Copyright © 1998-2009 Product support | Send virus sample to F-Secure
    F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name. This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.

  7. #22
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Your computer is clean

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:


    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.


    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.


    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.

  8. #23
    Join Date
    Sep 2010
    Location
    United Kingdom
    Posts
    66

    Reset system restore log

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes

    User: Michelle
    ->Temp folder emptied: 185604752 bytes
    ->Temporary Internet Files folder emptied: 2505186 bytes
    ->Java cache emptied: 31649 bytes
    ->FireFox cache emptied: 20897852 bytes
    ->Flash cache emptied: 456 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: UpdatusUser
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 81650968 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 1896 bytes

    Total Files Cleaned = 277.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default

    User: Default User

    User: Michelle
    ->Flash cache emptied: 0 bytes

    User: Public

    User: UpdatusUser

    Total Flash Files Cleaned = 0.00 mb



    OTL by OldTimer - Version 3.2.26.5 log created on 08282011_200709

    Files\Folders moved on Reboot...
    File\Folder C:\Windows\temp\etilqs_aVCK3kf8t55bgOnYvIop not found!
    File\Folder C:\Windows\temp\etilqs_JDGIXFS2S8nez2azyZBP not found!
    File\Folder C:\Windows\temp\etilqs_RNyvsazF3oMiENcWBv7i not found!
    File\Folder C:\Windows\temp\etilqs_UqSmiPvWmhjFMoY6sLjA not found!

    Registry entries deleted on Reboot...

  9. #24
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    13. Please, let me know, how your computer is doing.
    Whenever ready....

  10. #25
    Join Date
    Sep 2010
    Location
    United Kingdom
    Posts
    66
    That darned folder has returned (

  11. #26
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    In this forum, we make sure, your computer is free of malware and your computer is clean
    Because the access to malware forum is very limited, your best option is to create new topic about your current issue, at Windows section.
    You'll get more attention.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •