This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] how do I remove MYWEBSEARCH ?

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

It sounds as though your Active X is not enabled…. How to enable ActiveX Controls in Microsoft Internet Explorer Step 1: Go to the Tools menu, and select Internet Options. Step 2: Once the Internet Options window appears, select the Security tab, and click Custom Level. Step 3: Scroll down to the ActiveX controls and plug-ins group, and ensure that all ActiveX options are set to either “Enable” or “Prompt”. Please make certain that the options “Download unsigned ActiveX controls” and “Initialize and Script ActiveX controls not marked as safe” are set to “Prompt”. Step 4: Click “OK” until you return to the browser. We will reset these to a more secure setting when we are done.
All security programs should be disabled while running an online viruse scan..so windows defender should be disabled…right click the windows defender icon in the system tray and choose exit
Hi,

just found out this information which may be relevant:

the ESET Online Scanner works with x64 (AMD64 and EMT64) versions of Microsoft Windows The ESET Online Scanner is a 32-bit application, which means it must be run through in the 32-bit version of Internet Explorer, and as an Administrator. To do so, right-click on the Internet Explorer (32-bit) icon in the Start Menu and select "Run as administrator" from the popup context menu.

So can you locate the 32bit version of IE and go from there
well that might explain why ESET won't work then… it was worth a try…


I was just concerned of what might be still remaining on your computer as MalwareBytes found Vundo..which can play havoc with a machine if there are any remnants.

Let's try another approach..I don't want to let you go till I'm satisfied you are clean…we'll try a different tool that I know works on 64 bit systems.

Before you do this go back to IE and reset the default settings…for your security settings

Step 1: Go to the Tools menu, and select Internet Options.
Step 2: Once the Internet Options window appears, select the Security tab, and click Custom Level.

click the reset default settings button


Now do this:

download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
  • Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program. Make sure you close all other programs and don't use the PC while the scan runs.
  • Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and post the information back here as an attachment. I will review it when it comes in. The last line is < End of Report >, so make sure that is the last line in the attached report.

Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way.
OTScanIt2 logfile created on: 4/10/2009 5:15:54 PM - Run 1
OTScanIt2 by OldTimer - Version 1.0.12.2	 Folder = c:\Users\Laura\OTScanIt2
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.75 Gb Total Physical Memory | 2.35 Gb Available Physical Memory | 62.70% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 293.33 Gb Total Space | 215.44 Gb Free Space | 73.45% Space Free | Partition Type: NTFS
Drive D: | 293.08 Gb Total Space | 292.98 Gb Free Space | 99.97% Space Free | Partition Type: NTFS
Drive E: | 104.87 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: LAURA-PC
Current User Name: Laura
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
 
[Processes - Safe List]
avgcsrvx.exe -> %ProgramFiles%\AVG\AVG8\avgcsrvx.exe -> [2009/02/05 16:17:12 | 00,687,896 | —- | M] (AVG Technologies CZ, s.r.o.)
avgemc.exe -> %ProgramFiles%\AVG\AVG8\avgemc.exe -> [2009/02/05 16:17:12 | 00,903,960 | —- | M] (AVG Technologies CZ, s.r.o.)
avgtray.exe -> %ProgramFiles%\AVG\AVG8\avgtray.exe -> [2009/02/05 16:17:12 | 01,601,304 | —- | M] (AVG Technologies CZ, s.r.o.)
avgwdsvc.exe -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2009/02/05 16:17:11 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.)
clmsserver.exe -> %ProgramFiles%\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe -> [2008/01/25 21:49:04 | 00,269,448 | —- | M] (CyberLink)
edsmsnloader32.exe -> %SystemDrive%\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe -> [2008/03/05 02:38:30 | 00,454,704 | —- | M] (Egis inc.)
edsservice.exe -> %SystemDrive%\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -> [2008/03/05 02:38:34 | 00,500,784 | —- | M] (Egis Incorporated)
ieuser.exe -> %ProgramFiles%\Internet Explorer\ieuser.exe -> [2008/01/20 22:50:38 | 00,299,520 | —- | M] (Microsoft Corporation)
jusched.exe -> %ProgramFiles%\Java\jre6\bin\jusched.exe -> [2009/01/26 17:49:39 | 00,136,600 | —- | M] (Sun Microsystems, Inc.)
lssrvc.exe -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> [2007/01/17 14:20:10 | 00,061,440 | —- | M] (Hewlett-Packard Company)
msnmsgr.exe -> %ProgramFiles%\Windows Live\Messenger\msnmsgr.exe -> [2009/02/06 18:51:28 | 03,885,408 | —- | M] (Microsoft Corporation)
otscanit2.exe -> %UserProfile%\OTScanIt2\OTScanIt2.exe -> [2009/04/08 13:39:08 | 00,493,568 | —- | M] (OldTimer Tools)
richvideo.exe -> %ProgramFiles%\CyberLink\Shared Files\RichVideo.exe -> [2006/07/19 14:36:58 | 00,262,247 | —- | M] ()
sdwinsec.exe -> %ProgramFiles%\Spybot - Search & Destroy\SDWinSec.exe -> [2009/01/26 16:31:10 | 01,153,368 | —- | M] (Safer Networking Ltd.)
seaport.exe -> %ProgramFiles%\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -> [2009/01/14 17:53:02 | 00,226,656 | —- | M] (Microsoft Corp.)
teatimer.exe -> %ProgramFiles%\Spybot - Search & Destroy\TeaTimer.exe -> [2009/01/26 16:31:16 | 02,144,088 | RHS- | M] (Safer Networking Limited)
thguard.exe -> %ProgramFiles%\TrojanHunter 5.0\THGuard.exe -> [2008/10/24 13:23:10 | 01,056,928 | —- | M] (Mischel Internet Security)
wlcomm.exe -> %ProgramFiles%\Windows Live\Contacts\wlcomm.exe -> [2009/02/06 17:07:48 | 00,027,512 | —- | M] (Microsoft Corporation)
 
[Win32 Services - Safe List]
(Acer HomeMedia Connect Service) Acer HomeMedia Connect Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe -> [2008/01/25 21:49:04 | 00,269,448 | —- | M] (CyberLink)
(AcerMemUsageCheckService) ePerformance Service [Win32_Own | Auto | Running] -> %SystemDrive%\Acer\Empowering Technology\ePerformance\MemCheck.exe -> [2007/10/17 13:38:20 | 00,028,672 | —- | M] ()
(avg8emc) AVG Free8 E-mail Scanner [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgemc.exe -> [2009/02/05 16:17:12 | 00,903,960 | —- | M] (AVG Technologies CZ, s.r.o.)
(avg8wd) AVG Free8 WatchDog [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2009/02/05 16:17:11 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.)
(clr_optimization_v2.0.50727_32) Microsoft .NET Framework NGEN v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2008/07/27 14:03:13 | 00,069,632 | —- | M] (Microsoft Corporation)
(clr_optimization_v2.0.50727_64) Microsoft .NET Framework NGEN v2.0.50727_X64 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -> [2008/07/27 14:01:49 | 00,093,184 | —- | M] (Microsoft Corporation)
(eDataSecurity Service) eDataSecurity Service [Win32_Own | Auto | Running] -> %SystemDrive%\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -> [2008/03/05 02:38:34 | 00,500,784 | —- | M] (Egis Incorporated)
(ehRecvr) Windows Media Center Receiver Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\ehome\ehRecvr.exe -> [2008/01/20 22:51:36 | 00,344,064 | —- | M] (Microsoft Corporation)
(ehSched) Windows Media Center Scheduler Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\ehome\ehsched.exe -> [2008/01/20 22:51:36 | 00,153,600 | —- | M] (Microsoft Corporation)
(ehstart) Windows Media Center Service Launcher [Win32_Shared | Auto | Stopped] -> %SystemRoot%\ehome\ehstart.dll -> [2006/11/02 11:03:48 | 00,015,360 | —- | M] (Microsoft Corporation)
(eRecoveryService) eRecovery Service [Win32_Own | Auto | Running] -> %SystemDrive%\Acer\Empowering Technology\eRecovery\eRecoveryService.exe -> [2007/09/10 18:28:18 | 00,057,344 | —- | M] (Acer Inc.)
(eSettingsService) eSettings Service [Win32_Own | Auto | Running] -> %SystemDrive%\Acer\Empowering Technology\eSettings\Service\capuserv.exe -> [2007/12/19 21:09:22 | 00,024,576 | —- | M] ()
(FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe -> [2008/06/19 21:17:12 | 00,046,104 | —- | M] (Microsoft Corporation)
(fsssvc) Windows Live Family Safety [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\Family Safety\fsssvc.exe -> [2009/02/06 18:08:58 | 00,533,360 | —- | M] (Microsoft Corporation)
(getPlus(R) Helper) getPlus(R) Helper [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\NOS\bin\getPlus_HelperSvc.exe -> [2008/10/06 10:18:06 | 00,033,752 | —- | M] (NOS Microsystems Ltd.)
(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2009/01/12 12:05:06 | 00,137,200 | —- | M] (Google)
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> %SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -> [2008/06/19 21:16:53 | 00,859,648 | —- | M] (Microsoft Corporation)
(LightScribeService) LightScribeService Direct Disc Labeling Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> [2007/01/17 14:20:10 | 00,061,440 | —- | M] (Hewlett-Packard Company)
(NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> %SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2008/06/19 21:16:54 | 00,119,808 | —- | M] (Microsoft Corporation)
(odserv) Microsoft Office Diagnostics Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\OFFICE12\ODSERV.EXE -> [2007/08/24 04:19:12 | 00,443,776 | —- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2006/10/26 17:03:08 | 00,145,184 | —- | M] (Microsoft Corporation)
(PcaSvc) Program Compatibility Assistant Service [Win32_Shared | Auto | Running] -> %SystemRoot%\sysnative\pcasvc.dll -> [2008/01/20 22:47:55 | 00,079,360 | —- | M] ()
(PerfHost) Performance Counter DLL Host [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\SysWow64\perfhost.exe -> [2008/01/20 22:51:00 | 00,019,968 | —- | M] (Microsoft Corporation)
(RichVideo) Cyberlink RichVideo Service(CRVS) [Win32_Own | Auto | Running] -> %ProgramFiles%\CyberLink\Shared Files\RichVideo.exe -> [2006/07/19 14:36:58 | 00,262,247 | —- | M] ()
(SBSDWSCService) SBSD Security Center Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Spybot - Search & Destroy\SDWinSec.exe -> [2009/01/26 16:31:10 | 01,153,368 | —- | M] (Safer Networking Ltd.)
(SeaPort) SeaPort [Win32_Own | Auto | Running] -> %ProgramFiles%\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -> [2009/01/14 17:53:02 | 00,226,656 | —- | M] (Microsoft Corp.)
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> %SystemDrive%\Program Files\Windows Media Player\wmpnetwk.exe -> [2008/01/20 22:52:15 | 01,216,000 | —- | M] (Microsoft Corporation)
 
[Driver Services - Safe List]
(AtiDCM) AtiDCM [Kernel | On_Demand | Stopped] -> %SystemRoot%\Temp\atidcmxx.sys -> [2007/08/16 00:20:44 | 00,017,280 | —- | M] (Advanced Micro Devices, Inc.)
(AvgLdx64) AVG Free AVI Loader Driver x64 [Kernel | System | Running] -> %SystemRoot%\sysnative\Drivers\avgldx64.sys -> [2009/02/05 16:17:16 | 00,414,216 | —- | M] ()
(AvgMfx64) AVG Free On-access Scanner Minifilter Driver x64 [File_System | System | Running] -> %SystemRoot%\sysnative\Drivers\avgmfx64.sys -> [2009/02/05 16:17:14 | 00,033,160 | —- | M] ()
(AvgTdiA) AVG Free8 Network Redirector x64 [Kernel | System | Running] -> %SystemRoot%\sysnative\Drivers\avgtdia.sys -> [2009/02/05 16:17:18 | 00,131,592 | —- | M] ()
(fssfltr) fssfltr [Kernel | On_Demand | Stopped] -> %SystemRoot%\sysnative\DRIVERS\fssfltr.sys -> [2009/02/06 18:42:12 | 00,061,808 | —- | M] ()
(HdAudAddService) Microsoft 1.1 UAA Function Driver for High Definition Audio Service [Kernel | On_Demand | Stopped] -> %SystemRoot%\sysnative\drivers\HdAudio.sys -> [2006/11/02 01:28:10 | 00,273,920 | —- | M] ()
(int15) int15 [Kernel | Auto | Running] -> %SystemDrive%\Acer\Empowering Technology\eRecovery\int15.sys -> [2006/10/04 15:45:16 | 00,015,656 | —- | M] ()
(MODEMCSA) Unimodem Streaming Filter Device [Kernel | On_Demand | Running] -> %SystemRoot%\sysnative\drivers\MODEMCSA.sys -> [2008/01/20 22:46:55 | 00,024,064 | —- | M] ()
(NVHDA) Service for NVIDIA High Definition Audio Driver [Kernel | On_Demand | Running] -> %SystemRoot%\sysnative\drivers\nvhda64v.sys -> [2008/04/28 13:02:40 | 00,055,328 | —- | M] ()
(PSDFilter) PSDFilter [File_System | Boot | Running] -> %SystemRoot%\sysnative\DRIVERS\psdfilter.sys -> [2008/03/05 02:39:20 | 00,022,064 | —- | M] ()
(PSDNServ) PSDNServ [Kernel | Auto | Running] -> %SystemRoot%\sysnative\DRIVERS\PSDNServ.sys -> [2008/03/05 02:39:22 | 00,021,040 | —- | M] ()
(psdvdisk) psdvdisk [Kernel | Auto | Running] -> %SystemRoot%\sysnative\DRIVERS\PSDVdisk.sys -> [2008/03/05 02:39:22 | 00,060,976 | —- | M] ()
(smserial) smserial [Kernel | On_Demand | Running] -> %SystemRoot%\sysnative\DRIVERS\smserial.sys -> [2007/02/02 11:37:48 | 01,453,056 | —- | M] ()
(WpdUsb) WpdUsb [Kernel | On_Demand | Stopped] -> %SystemRoot%\sysnative\DRIVERS\wpdusb.sys -> [2008/01/20 22:47:28 | 00,046,080 | —- | M] ()
 
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=1008&m=aspire_m5641 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> Reg Error: Invalid data type. -> 
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=1008&m=aspire_m5641 -> 
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 
HKEY_CURRENT_USER\: Main\\"Default_Page_URL" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=1008&m=aspire_m5641 -> 
HKEY_CURRENT_USER\: Main\\"Default_Secondary_Page_URL" -> Reg Error: Invalid data type. -> 
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\Windows\system32\blank.htm -> 
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_CURRENT_USER\: Main\\"SearchDefaultBranded" -> Reg Error: Invalid data type. -> 
HKEY_CURRENT_USER\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_CURRENT_USER\: Main\\"StartPageCache" -> Reg Error: Invalid data type. -> 
HKEY_CURRENT_USER\: URLSearchHooks\\"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" [HKLM] -> %SystemRoot%\SysWOW64\ieframe.dll [Microsoft Url Search Hook] -> [2009/01/15 02:07:53 | 06,069,248 | —- | M] (Microsoft Corporation)
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> 
< FireFox Settings [Prefs.js] > -> C:\Users\Laura\AppData\Roaming\Mozilla\FireFox\Profiles\sf4hx0jf.default\prefs.js -> 
browser.search.selectedEngine -> "MyWebSearch" ->
browser.startup.homepage -> "http://go.microsoft.com/fwlink/?LinkId=69157" ->
extensions.enabledItems -> {20a82645-c095-46ed-80e3-08825760534b}:1.0 ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8 ->
keyword.URL -> "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZJfox000&fl=0&ptb=j0XLgx1FOalA7EKUT2t_aQ&st=kwd&o=kwd&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&searchfor=" ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions ->  -> 
HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> %SystemRoot%\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/03/20 11:20:27 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions ->  -> 
HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS] -> [2009/03/28 18:35:57 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS] -> [2009/04/10 12:23:54 | 00,000,000 | —D | M]
< FireFox Extensions [User Folders] > -> 
 -> C:\Users\Laura\AppData\Roaming\mozilla\Extensions -> [2009/03/17 15:19:37 | 00,000,000 | —D | M]
 -> C:\Users\Laura\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2009/03/17 15:19:37 | 00,000,000 | —D | M]
 -> C:\Users\Laura\AppData\Roaming\mozilla\Firefox\Profiles\sf4hx0jf.default\extensions -> [2009/03/28 19:01:00 | 00,096,288 | —- | M] ()
< FireFox SearchPlugins [User Folders] > -> 
C:\Users\Laura\AppData\Roaming\Mozilla\FireFox\Profiles\sf4hx0jf.default\searchplugins\ -> C:\Users\Laura\AppData\Roaming\Mozilla\FireFox\Profiles\sf4hx0jf.default\searchplugins -> [2009/04/10 09:50:59 | 00,000,000 | —D | M]
mywebsearch.xml -> C:\Users\Laura\AppData\Roaming\Mozilla\FireFox\Profiles\sf4hx0jf.default\searchplugins\mywebsearch.xml -> [2009/04/10 09:50:59 | 00,009,895 | —- | M] ()
< FireFox Extensions [Program Folders] > -> 
 -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\extensions -> [2009/03/28 18:58:37 | 06,054,400 | —- | M] ()
 -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} -> [2009/03/28 18:58:37 | 06,054,400 | —- | M] ()
< FireFox Components [Program Folders] > -> 
C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\components\ -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\components -> [2009/03/28 18:35:57 | 00,000,000 | —D | M]
browserdirprovider.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\components\browserdirprovider.dll -> [2009/03/28 18:35:36 | 00,023,032 | —- | M] (Mozilla Foundation)
brwsrcmp.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\components\brwsrcmp.dll -> [2009/03/28 18:35:57 | 00,134,648 | —- | M] (Mozilla Foundation)
< FireFox Plugins [Program Folders] > -> 
C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\ -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins -> [2009/04/10 12:23:54 | 00,000,000 | —D | M]
npnul32.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npnul32.dll -> [2009/03/28 18:45:33 | 00,065,528 | —- | M] (mozilla.org)
npnul32.dll.moz-backup -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npnul32.dll -> [2009/03/28 18:45:33 | 00,065,528 | —- | M] (mozilla.org)
< FireFox SearchPlugins [Program Folders] > -> 
C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\ -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins -> [2009/03/17 15:19:31 | 00,000,000 | —D | M]
amazondotcom.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\amazondotcom.xml -> [2009/02/19 15:33:08 | 00,001,394 | —- | M] ()
answers.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\answers.xml -> [2009/02/19 15:33:08 | 00,002,193 | —- | M] ()
creativecommons.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\creativecommons.xml -> [2009/02/19 15:33:08 | 00,001,534 | —- | M] ()
eBay.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\eBay.xml -> [2009/02/19 15:33:08 | 00,002,343 | —- | M] ()
google.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\google.xml -> [2009/02/19 15:33:08 | 00,001,706 | —- | M] ()
wikipedia.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\wikipedia.xml -> [2009/02/19 15:33:08 | 00,001,178 | —- | M] ()
yahoo.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\yahoo.xml -> [2009/02/19 15:33:08 | 00,000,792 | —- | M] ()
< HOSTS File > (761 bytes and 20 lines) -> C:\Windows\System32\drivers\etc\Hosts -> 
Reset Hosts
127.0.0.1	   localhost
::1			 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/23 00:08:42 | 00,062,080 | —- | M] (Adobe Systems Incorporated)
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> %ProgramFiles%\AVG\AVG8\avgssie.dll [AVG Safe Search] -> [2009/02/05 16:17:12 | 01,078,552 | —- | M] (AVG Technologies CZ, s.r.o.)
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> [2009/01/26 16:31:02 | 01,879,896 | —- | M] (Safer Networking Limited)
{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} [HKLM] -> %ProgramFiles%\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [Search Helper] -> [2009/01/14 17:49:24 | 00,092,504 | —- | M] (Microsoft Corp.)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre6\bin\ssv.dll [Java(tm) Plug-In SSV Helper] -> [2009/01/26 17:49:39 | 00,320,920 | —- | M] (Sun Microsystems, Inc.)
{9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> %CommonProgramFiles%\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Windows Live Sign-in Helper] -> [2009/02/17 17:11:04 | 00,408,440 | —- | M] (Microsoft Corporation)
{A057A204-BACC-4D26-9990-79A187E2698E} [HKLM] -> %ProgramFiles%\AVG\AVG8\avgtoolbar.dll [AVG Security Toolbar] -> [2009/02/05 16:17:13 | 01,968,920 | —- | M] ([[[COMPANYNAME]]]—————————-)
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [Google Toolbar Helper] -> [2009/01/12 11:41:36 | 00,251,504 | —- | M] ()
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> %ProgramFiles%\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [Google Toolbar Notifier BHO] -> [2009/01/12 12:05:07 | 00,657,904 | —- | M] (Google Inc.)
{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [HKLM] -> %ProgramFiles%\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [Google Dictionary Compression sdch] -> [2009/01/12 11:41:34 | 00,522,224 | —- | M] (Google Inc.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> %ProgramFiles%\Java\jre6\bin\jp2ssv.dll [Java(tm) Plug-In 2 SSV Helper] -> [2009/01/26 17:49:38 | 00,034,816 | —- | M] (Sun Microsystems, Inc.)
{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} [HKLM] -> %ProgramFiles%\Windows Live\Toolbar\wltcore.dll [Windows Live Toolbar Helper] -> [2009/02/06 18:17:46 | 01,068,904 | —- | M] (Microsoft Corporation)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"{21FA44EF-376D-4D53-9B0F-8A89D3229068}" [HKLM] -> %ProgramFiles%\Windows Live\Toolbar\wltcore.dll [&Windows Live Toolbar] -> [2009/02/06 18:17:46 | 01,068,904 | —- | M] (Microsoft Corporation)
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2009/01/12 11:41:36 | 00,251,504 | —- | M] ()
"{5CBE3B7C-1E47-477e-A7DD-396DB0476E29}" [HKLM] -> %SystemDrive%\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [Acer eDataSecurity Management] -> [2008/03/05 02:37:46 | 00,142,896 | —- | M] (Egis Incorporated.)
"{A057A204-BACC-4D26-9990-79A187E2698E}" [HKLM] -> %ProgramFiles%\AVG\AVG8\avgtoolbar.dll [AVG Security Toolbar] -> [2009/02/05 16:17:13 | 01,968,920 | —- | M] ([[[COMPANYNAME]]]—————————-)
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 
ShellBrowser\\"{5CBE3B7C-1E47-477E-A7DD-396DB0476E29}" [HKLM] -> %SystemDrive%\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [Acer eDataSecurity Management] -> [2008/03/05 02:37:46 | 00,142,896 | —- | M] (Egis Incorporated.)
WebBrowser\\"{21FA44EF-376D-4D53-9B0F-8A89D3229068}" [HKLM] -> %ProgramFiles%\Windows Live\Toolbar\wltcore.dll [&Windows Live Toolbar] -> [2009/02/06 18:17:46 | 01,068,904 | —- | M] (Microsoft Corporation)
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2009/01/12 11:41:36 | 00,251,504 | —- | M] ()
WebBrowser\\"{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
WebBrowser\\"{A057A204-BACC-4D26-9990-79A187E2698E}" [HKLM] -> %ProgramFiles%\AVG\AVG8\avgtoolbar.dll [AVG Security Toolbar] -> [2009/02/05 16:17:13 | 01,968,920 | —- | M] ([[[COMPANYNAME]]]—————————-)
WebBrowser\\"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Acer Assist Launcher" -> %ProgramFiles%\Acer Assist\launcher.exe ["C:\Program Files (x86)\Acer Assist\launcher.exe"] -> [2007/02/02 14:05:00 | 01,261,568 | —- | M] ()
"Acer Product Registration" ->  ["C:\Program Files (x86)\Acer Registration\ACE1.exe" /startup] -> File not found
"Adobe Reader Speed Launcher" -> %ProgramFiles%\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2008/10/15 02:04:34 | 00,039,792 | —- | M] (Adobe Systems Incorporated)
"AVG8_TRAY" -> %ProgramFiles%\AVG\AVG8\avgtray.exe [C:\PROGRA~2\AVG\AVG8\avgtray.exe] -> [2009/02/05 16:17:12 | 01,601,304 | —- | M] (AVG Technologies CZ, s.r.o.)
"eRecoveryService" ->  [] -> File not found
"PCMMediaSharing" -> %ProgramFiles%\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe ["C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe"] -> [2008/01/25 21:49:06 | 00,204,908 | —- | M] ()
"QuickTime Task" -> %ProgramFiles%\QuickTime\QTTask.exe ["C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime] -> [2008/09/06 16:09:14 | 00,413,696 | —- | M] (Apple Inc.)
"SunJavaUpdateSched" -> %ProgramFiles%\Java\jre6\bin\jusched.exe ["C:\Program Files (x86)\Java\jre6\bin\jusched.exe"] -> [2009/01/26 17:49:39 | 00,136,600 | —- | M] (Sun Microsystems, Inc.)
"THGuard" -> %ProgramFiles%\TrojanHunter 5.0\THGuard.exe ["C:\Program Files (x86)\TrojanHunter 5.0\THGuard.exe"] -> [2008/10/24 13:23:10 | 01,056,928 | —- | M] (Mischel Internet Security)
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"ehTray.exe" -> %SystemRoot%\ehome\ehTray.exe [C:\Windows\ehome\ehTray.exe] -> [2008/01/20 22:51:33 | 00,138,240 | —- | M] (Microsoft Corporation)
"MsnMsgr" -> %ProgramFiles%\Windows Live\Messenger\MsnMsgr.Exe ["C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background] -> [2009/02/06 18:51:28 | 03,885,408 | —- | M] (Microsoft Corporation)
"SpybotSD TeaTimer" -> %ProgramFiles%\Spybot - Search & Destroy\TeaTimer.exe [C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe] -> [2009/01/26 16:31:16 | 02,144,088 | RHS- | M] (Safer Networking Limited)
"swg" -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> [2008/11/30 18:11:41 | 00,068,856 | —- | M] (Google Inc.)
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoActiveDesktop" ->  [1] -> File not found
\\"ForceActiveDesktopOn" ->  [0] -> File not found
\\"NoActiveDesktopChanges" ->  [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"ConsentPromptBehaviorAdmin" ->  [2] -> File not found
\\"ConsentPromptBehaviorUser" ->  [1] -> File not found
\\"EnableInstallerDetection" ->  [1] -> File not found
\\"EnableLUA" ->  [1] -> File not found
\\"EnableSecureUIAPaths" ->  [1] -> File not found
\\"EnableVirtualization" ->  [1] -> File not found
\\"PromptOnSecureDesktop" ->  [1] -> File not found
\\"ValidateAdminCodeSignatures" ->  [0] -> File not found
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"scforceoption" ->  [0] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
\\"FilterAdministratorToken" ->  [0] -> File not found
\\"EnableUIADesktopToggle" ->  [0] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats
\UIPI\Clipboard\ExceptionFormats\\"CF_TEXT" ->  [1] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_BITMAP" ->  [2] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_OEMTEXT" ->  [7] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_DIB" ->  [8] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_PALETTE" ->  [9] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_UNICODETEXT" ->  [13] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_DIBV5" ->  [17] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> 
&Search -> Reg Error: Value error. [Reg Error: Value error.] -> File not found
Add to Windows &Live Favorites ->  [http://favorites.live.com/quickadd.aspx] -> File not found
E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\Office12\EXCEL.EXE [res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000] -> [2008/10/18 19:30:22 | 17,931,616 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}:{5F7B1267-94A9-47F5-98DB-E99415F33AEC} [HKLM] -> %ProgramFiles%\Windows Live\Writer\WriterBrowserExtension.dll [Button: Blog This] -> [2009/02/06 18:07:54 | 00,187,248 | —- | M] (Microsoft Corporation)
{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}:{5F7B1267-94A9-47F5-98DB-E99415F33AEC} [HKLM] -> %ProgramFiles%\Windows Live\Writer\WriterBrowserExtension.dll [Menu: &Blog This in Windows Live Writer] -> [2009/02/06 18:07:54 | 00,187,248 | —- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [Button: Send to OneNote] -> [2007/12/13 03:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [Menu: S&end to OneNote] -> [2007/12/13 03:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [Button: Research] -> [2006/10/26 23:12:22 | 00,040,424 | —- | M] (Microsoft Corporation)
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Menu: Spybot - Search && Destroy Configuration] -> [2009/01/26 16:31:02 | 01,879,896 | —- | M] (Safer Networking Limited)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} [HKLM] -> http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUplden-us.cab [MSN Photo Upload Tool] -> 
{56762DEC-6B0D-4AB4-A8AD-989993B5D08B} [HKLM] -> http://www.eset.eu/buxus/docs/OnlineScanner.cab [OnlineScanner Control] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?AuthParam=1233006954_5421176eadb7f6f115f4978fea8ee869&GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab&File=jinstall-6u11-windows-i586-jc.cab&BHost=javadl.sun.com [Java Plug-in 1.6.0_11] -> 
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab [Java Plug-in 1.6.0_11] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab [Java Plug-in 1.6.0_11] -> 
{CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} [HKLM] -> http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab [get_atlcom Class] -> 
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{0387CC52-77EF-478D-801E-673037019A6E} ->	(NVIDIA nForce Networking Controller) -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
explorer.exe -> %SystemRoot%\system32\explorer.exe -> [2008/10/29 02:29:41 | 02,927,104 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad -> 
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> %SystemRoot%\SysWOW64\webcheck.dll [WebCheck] -> [2008/01/20 22:48:55 | 00,233,984 | —- | M] (Microsoft Corporation)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> 
"AlternateShell" -> cmd.exe -> 
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 -> 
"DisplayName" -> CD-ROM Driver -> 
"ImagePath" ->  [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > ->  -> 
E:\autorun.inf [[autorun] | open=launch.exe |  | ] -> E:\autorun.inf [ CDFS ] -> [2008/05/14 12:24:14 | 00,000,030 | R— | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> 
\{a7494194-969b-11dd-a387-806e6f6e6963}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a7494194-969b-11dd-a387-806e6f6e6963}\shell
\{a7494194-969b-11dd-a387-806e6f6e6963}\shell\\"" ->  [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a7494194-969b-11dd-a387-806e6f6e6963}\shell\AutoRun\command
\{a7494194-969b-11dd-a387-806e6f6e6963}\shell\AutoRun\command\\"" -> E:\launch.exe [E:\launch.exe] -> [2008/02/20 15:35:44 | 02,817,529 | R— | M] (SumTotal Systems, Inc.)
 
 
[Files/Folders - Created Within 30 Days]
OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2009/04/10 17:14:44 | 00,000,000 | —D | C]
OTScanIt2 -> %UserProfile%\OTScanIt2 -> [2009/04/10 17:10:55 | 00,000,000 | —D | C]
Malwarebytes -> %AppData%\Malwarebytes -> [2009/04/10 12:16:59 | 00,000,000 | —D | C]
mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009/04/10 12:16:57 | 00,015,504 | —- | C] (Malwarebytes Corporation)
Malwarebytes' Anti-Malware.lnk -> %SystemDrive%\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/04/10 12:16:57 | 00,000,852 | —- | C] ()
mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009/04/10 12:16:55 | 00,038,496 | —- | C] (Malwarebytes Corporation)
Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware -> [2009/04/10 12:16:54 | 00,000,000 | —D | C]
Malwarebytes -> %AllUsersProfile%\Malwarebytes -> [2009/04/10 12:16:54 | 00,000,000 | —D | C]
HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [2009/04/10 11:50:12 | 00,001,932 | —- | C] ()
Trend Micro -> %ProgramFiles%\Trend Micro -> [2009/04/10 11:50:11 | 00,000,000 | —D | C]
TrojanHunter -> %AppData%\TrojanHunter -> [2009/04/10 10:48:56 | 00,000,000 | —D | C]
TrojanHunter.lnk -> %UserProfile%\Desktop\TrojanHunter.lnk -> [2009/04/10 09:50:13 | 00,000,848 | —- | C] ()
streamhlp.dll -> %SystemRoot%\System32\streamhlp.dll -> [2009/04/10 09:50:08 | 00,059,392 | R— | C] ()
TrojanHunter 5.0 -> %ProgramFiles%\TrojanHunter 5.0 -> [2009/04/10 09:50:07 | 00,000,000 | —D | C]
AVGTOOLBAR -> %AppData%\AVGTOOLBAR -> [2009/04/09 14:20:17 | 00,000,000 | —D | C]
CyberLink -> %AppData%\CyberLink -> [2009/04/06 19:47:38 | 00,000,000 | —D | C]
Acer Arcade Live -> %UserProfile%\AppData\Local\Acer Arcade Live -> [2009/04/06 19:47:38 | 00,000,000 | —D | C]
.# -> %AppData%\.# -> [2009/04/06 19:46:16 | 00,000,000 | -HSD | C]
NTUSER.DAT{32386ee7-1f85-11de-a0f9-002185689a68}.TMContainer00000000000000000002.regtrans-ms -> %UserProfile%\NTUSER.DAT{32386ee7-1f85-11de-a0f9-002185689a68}.TMContainer00000000000000000002.regtrans-ms -> [2009/04/02 08:53:31 | 00,524,288 | -HS- | C] ()
NTUSER.DAT{32386ee7-1f85-11de-a0f9-002185689a68}.TMContainer00000000000000000001.regtrans-ms -> %UserProfile%\NTUSER.DAT{32386ee7-1f85-11de-a0f9-002185689a68}.TMContainer00000000000000000001.regtrans-ms -> [2009/04/02 08:53:31 | 00,524,288 | -HS- | C] ()
NTUSER.DAT{32386ee7-1f85-11de-a0f9-002185689a68}.TM.blf -> %UserProfile%\NTUSER.DAT{32386ee7-1f85-11de-a0f9-002185689a68}.TM.blf -> [2009/04/02 08:53:31 | 00,065,536 | -HS- | C] ()
Citrix -> %ProgramFiles%\Citrix -> [2009/04/01 10:57:37 | 00,000,000 | —D | C]
g2mdlhlpx.exe -> %UserProfile%\g2mdlhlpx.exe -> [2009/04/01 10:56:53 | 00,070,984 | —- | C] ()
My Stationery -> %UserProfile%\Documents\My Stationery -> [2009/03/26 13:31:45 | 00,000,000 | R-SD | C]
An old fan.eml -> %UserProfile%\Documents\An old fan.eml -> [2009/03/26 13:29:42 | 00,004,681 | —- | C] ()
NTUSER.DAT{5b0cda9d-1563-11de-8af7-002185689a68}.TMContainer00000000000000000002.regtrans-ms -> %UserProfile%\NTUSER.DAT{5b0cda9d-1563-11de-8af7-002185689a68}.TMContainer00000000000000000002.regtrans-ms -> [2009/03/20 11:26:35 | 00,524,288 | -HS- | C] ()
NTUSER.DAT{5b0cda9d-1563-11de-8af7-002185689a68}.TMContainer00000000000000000001.regtrans-ms -> %UserProfile%\NTUSER.DAT{5b0cda9d-1563-11de-8af7-002185689a68}.TMContainer00000000000000000001.regtrans-ms -> [2009/03/20 11:26:35 | 00,524,288 | -HS- | C] ()
NTUSER.DAT{5b0cda9d-1563-11de-8af7-002185689a68}.TM.blf -> %UserProfile%\NTUSER.DAT{5b0cda9d-1563-11de-8af7-002185689a68}.TM.blf -> [2009/03/20 11:26:35 | 00,065,536 | -HS- | C] ()
infocardcpl.cpl -> %SystemRoot%\System32\infocardcpl.cpl -> [2009/03/20 11:17:06 | 00,037,384 | —- | C] (Microsoft Corporation)
PresentationHostProxy.dll -> %SystemRoot%\System32\PresentationHostProxy.dll -> [2009/03/20 11:17:04 | 00,043,544 | —- | C] (Microsoft Corporation)
icardres.dll -> %SystemRoot%\System32\icardres.dll -> [2009/03/20 11:17:04 | 00,011,264 | —- | C] (Microsoft Corporation)
PresentationNative_v0300.dll -> %SystemRoot%\System32\PresentationNative_v0300.dll -> [2009/03/20 11:17:03 | 00,781,344 | —- | C] (Microsoft Corporation)
icardagt.exe -> %SystemRoot%\System32\icardagt.exe -> [2009/03/20 11:17:03 | 00,622,080 | —- | C] (Microsoft Corporation)
infocardapi.dll -> %SystemRoot%\System32\infocardapi.dll -> [2009/03/20 11:17:03 | 00,097,800 | —- | C] (Microsoft Corporation)
PresentationCFFRasterizerNative_v0300.dll -> %SystemRoot%\System32\PresentationCFFRasterizerNative_v0300.dll -> [2009/03/20 11:17:00 | 00,105,016 | —- | C] (Microsoft Corporation)
PresentationHost.exe -> %SystemRoot%\System32\PresentationHost.exe -> [2009/03/20 11:16:58 | 00,326,160 | —- | C] (Microsoft Corporation)
netfxperf.dll -> %SystemRoot%\System32\netfxperf.dll -> [2009/03/20 11:10:03 | 00,041,984 | —- | C] (Microsoft Corporation)
dfshim.dll -> %SystemRoot%\System32\dfshim.dll -> [2009/03/20 11:09:52 | 00,096,760 | —- | C] (Microsoft Corporation)
mscoree.dll -> %SystemRoot%\System32\mscoree.dll -> [2009/03/20 11:09:43 | 00,282,112 | —- | C] (Microsoft Corporation)
mscorier.dll -> %SystemRoot%\System32\mscorier.dll -> [2009/03/20 11:09:36 | 00,158,720 | —- | C] (Microsoft Corporation)
mscories.dll -> %SystemRoot%\System32\mscories.dll -> [2009/03/20 11:09:32 | 00,083,968 | —- | C] (Microsoft Corporation)
Michael Buble -> %UserProfile%\Documents\Michael Buble -> [2009/03/17 22:24:10 | 00,000,000 | —D | C]
Mozilla -> %UserProfile%\AppData\Local\Mozilla -> [2009/03/17 15:19:35 | 00,000,000 | —D | C]
Mozilla -> %AppData%\Mozilla -> [2009/03/17 15:19:35 | 00,000,000 | —D | C]
Mozilla Firefox.lnk -> %SystemDrive%\Users\Public\Desktop\Mozilla Firefox.lnk -> [2009/03/17 15:19:31 | 00,001,782 | —- | C] ()
Mozilla Firefox -> %ProgramFiles%\Mozilla Firefox -> [2009/03/17 15:19:29 | 00,000,000 | —D | C]
Kevin Rudolf & Lil Wayne - Let It Rock -> %UserProfile%\Documents\Kevin Rudolf & Lil Wayne - Let It Rock -> [2009/03/16 17:25:56 | 00,000,000 | —D | C]
Tracing -> %UserProfile%\Tracing -> [2009/03/16 15:43:51 | 00,000,000 | —D | C]
Microsoft Silverlight -> %ProgramFiles%\Microsoft Silverlight -> [2009/03/15 15:32:56 | 00,000,000 | —D | C]
Microsoft Sync Framework -> %ProgramFiles%\Microsoft Sync Framework -> [2009/03/15 15:30:40 | 00,000,000 | —D | C]
d3dx9_32.dll -> %SystemRoot%\System32\d3dx9_32.dll -> [2009/03/15 15:29:10 | 03,426,072 | —- | C] (Microsoft Corporation)
Microsoft SQL Server Compact Edition -> %ProgramFiles%\Microsoft SQL Server Compact Edition -> [2009/03/15 15:28:27 | 00,000,000 | —D | C]
My Sharing Folders.lnk -> %UserProfile%\Documents\My Sharing Folders.lnk -> [2009/03/15 15:27:06 | 00,000,801 | —- | C] ()
Microsoft -> %ProgramFiles%\Microsoft -> [2009/03/15 15:26:24 | 00,000,000 | —D | C]
Windows Live SkyDrive -> %ProgramFiles%\Windows Live SkyDrive -> [2009/03/15 15:26:09 | 00,000,000 | —D | C]
Windows Live -> %CommonProgramFiles%\Windows Live -> [2009/03/15 14:58:04 | 00,000,000 | —D | C]
Folder.jpg -> %UserProfile%\Documents\Folder.jpg -> [2009/03/14 11:09:50 | 00,011,056 | -HS- | C] ()
AlbumArt_{0B6BE3A3-9D5D-488B-8802-69C8D696E85F}_Large.jpg -> %UserProfile%\Documents\AlbumArt_{0B6BE3A3-9D5D-488B-8802-69C8D696E85F}_Large.jpg -> [2009/03/14 11:09:50 | 00,011,056 | -HS- | C] ()
AlbumArtSmall.jpg -> %UserProfile%\Documents\AlbumArtSmall.jpg -> [2009/03/14 11:09:50 | 00,002,443 | -HS- | C] ()
AlbumArt_{0B6BE3A3-9D5D-488B-8802-69C8D696E85F}_Small.jpg -> %UserProfile%\Documents\AlbumArt_{0B6BE3A3-9D5D-488B-8802-69C8D696E85F}_Small.jpg -> [2009/03/14 11:09:50 | 00,002,443 | -HS- | C] ()
03 - Eye Of The Beholder.mp3 -> %UserProfile%\Documents\03 - Eye Of The Beholder.mp3 -> [2009/03/14 11:00:35 | 10,926,433 | —- | C] ()
02 - …And Justice for All.mp3 -> %UserProfile%\Documents\02 - …And Justice for All.mp3 -> [2009/03/14 11:00:34 | 17,010,391 | —- | C] ()
08 - To Live Is To Die.mp3 -> %UserProfile%\Documents\08 - To Live Is To Die.mp3 -> [2009/03/14 11:00:34 | 16,192,174 | —- | C] ()
07 - The Frayed Ends Of Sanity.mp3 -> %UserProfile%\Documents\07 - The Frayed Ends Of Sanity.mp3 -> [2009/03/14 11:00:34 | 12,608,216 | —- | C] ()
01 - Blackened.mp3 -> %UserProfile%\Documents\01 - Blackened.mp3 -> [2009/03/14 11:00:34 | 11,641,710 | —- | C] ()
09 - Dyers Eve.mp3 -> %UserProfile%\Documents\09 - Dyers Eve.mp3 -> [2009/03/14 11:00:34 | 09,301,718 | —- | C] ()
~uTorrentPartFile_6A4B39D.dat -> %UserProfile%\Documents\~uTorrentPartFile_6A4B39D.dat -> [2009/03/14 11:00:34 | 00,137,876 | —- | C] ()
04 - One.mp3 -> %UserProfile%\Documents\04 - One.mp3 -> [2009/03/14 11:00:33 | 12,485,180 | —- | C] ()
05 - The Shortest Straw.mp3 -> %UserProfile%\Documents\05 - The Shortest Straw.mp3 -> [2009/03/14 11:00:33 | 11,477,819 | —- | C] ()
06 - Harvester Of Sorrow.mp3 -> %UserProfile%\Documents\06 - Harvester Of Sorrow.mp3 -> [2009/03/14 11:00:33 | 09,718,583 | —- | C] ()
Metallica - 1988 - And Justice For all -> %UserProfile%\Documents\Metallica - 1988 - And Justice For all -> [2009/03/14 09:47:53 | 00,000,000 | —D | C]
UB92Software -> %AppData%\UB92Software -> [2009/03/12 12:11:18 | 00,000,000 | —D | C]
Acer(Normal).ini -> %SystemRoot%\Acer(Normal).ini -> [2008/10/10 03:44:35 | 00,000,044 | —- | C] ()
Acer(Wide).ini -> %SystemRoot%\Acer(Wide).ini -> [2008/10/10 03:44:35 | 00,000,042 | —- | C] ()
eAPLauncher.ini -> %SystemRoot%\eAPLauncher.ini -> [2008/10/10 03:40:48 | 00,000,069 | —- | C] ()
INTEROP.IWSHRUNTIMELIBRARY.DLL -> %SystemRoot%\INTEROP.IWSHRUNTIMELIBRARY.DLL -> [2008/10/09 22:16:12 | 00,049,152 | —- | C] ( )
NTIBUN4.dll -> %SystemRoot%\System32\NTIBUN4.dll -> [2008/03/16 19:51:01 | 00,001,024 | RH– | C] ()
int15_64.sys -> %SystemRoot%\System32\drivers\int15_64.sys -> [2008/03/16 19:01:09 | 00,015,656 | —- | C] ()
generic.ini -> %SystemRoot%\generic.ini -> [2008/03/16 17:44:43 | 00,001,108 | —- | C] ()
Alaunch.ini -> %SystemRoot%\Alaunch.ini -> [2008/03/16 17:44:43 | 00,000,136 | —- | C] ()
OnlineScannerDLLA.dll -> %SystemRoot%\System32\OnlineScannerDLLA.dll -> [2008/02/11 09:39:26 | 00,253,952 | —- | C] ()
OnlineScannerDLLW.dll -> %SystemRoot%\System32\OnlineScannerDLLW.dll -> [2008/02/11 09:39:18 | 00,237,568 | —- | C] ()
OnlineScannerLang.dll -> %SystemRoot%\System32\OnlineScannerLang.dll -> [2008/02/08 13:53:46 | 00,110,592 | —- | C] ()
lnod32apiW.dll -> %SystemRoot%\System32\lnod32apiW.dll -> [2007/07/27 14:49:02 | 00,225,355 | —- | C] ()
lnod32apiA.dll -> %SystemRoot%\System32\lnod32apiA.dll -> [2007/07/27 14:49:02 | 00,196,683 | —- | C] ()
system.ini -> %SystemRoot%\system.ini -> [2006/11/02 08:34:27 | 00,000,219 | —- | C] ()
win.ini -> %SystemRoot%\win.ini -> [2006/11/02 08:34:27 | 00,000,144 | —- | C] ()
lnod32umc.dll -> %SystemRoot%\System32\lnod32umc.dll -> [2005/12/05 19:25:22 | 00,139,264 | —- | C] ()
lnod32upd.dll -> %SystemRoot%\System32\lnod32upd.dll -> [2005/12/05 12:37:10 | 00,106,496 | —- | C] ()
multiplex_vcd.dll -> %SystemRoot%\System32\multiplex_vcd.dll -> [2001/12/26 18:12:30 | 00,065,536 | —- | C] ()
Hmpg12.dll -> %SystemRoot%\System32\Hmpg12.dll -> [2001/09/04 01:46:38 | 00,110,592 | —- | C] ()
HMPV2_ENC.dll -> %SystemRoot%\System32\HMPV2_ENC.dll -> [2001/07/30 18:33:56 | 00,118,784 | —- | C] ()
HMPV2_ENC_MMX.dll -> %SystemRoot%\System32\HMPV2_ENC_MMX.dll -> [2001/07/24 00:04:36 | 00,118,784 | —- | C] ()
 
[Files/Folders - Modified Within 30 Days]
NTUSER.DAT -> %UserProfile%\NTUSER.DAT -> [2009/04/10 17:16:02 | 01,572,864 | -HS- | M] ()
opa12.dat -> %AllUsersProfile%\Microsoft\OFFICE\DATA\opa12.dat -> [2009/04/10 13:31:02 | 00,008,306 | —- | M] ()
EasyShare Registration RunOnce Task.job -> %SystemRoot%\tasks\EasyShare Registration RunOnce Task.job -> [2009/04/10 13:17:27 | 00,000,414 | —- | M] ()
qmgr1.dat -> %AllUsersProfile%\Microsoft\Network\Downloader\qmgr1.dat -> [2009/04/10 12:59:56 | 04,194,304 | —- | M] ()
qmgr0.dat -> %AllUsersProfile%\Microsoft\Network\Downloader\qmgr0.dat -> [2009/04/10 12:59:56 | 04,194,304 | —- | M] ()
NTUSER.DAT{32386ee7-1f85-11de-a0f9-002185689a68}.TMContainer00000000000000000001.regtrans-ms -> %UserProfile%\NTUSER.DAT{32386ee7-1f85-11de-a0f9-002185689a68}.TMContainer00000000000000000001.regtrans-ms -> [2009/04/10 12:57:14 | 00,524,288 | -HS- | M] ()
NTUSER.DAT{32386ee7-1f85-11de-a0f9-002185689a68}.TM.blf -> %UserProfile%\NTUSER.DAT{32386ee7-1f85-11de-a0f9-002185689a68}.TM.blf -> [2009/04/10 12:57:14 | 00,065,536 | -HS- | M] ()
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2009/04/10 12:56:55 | 00,000,006 | -H– | M] ()
bootstat.dat -> %SystemRoot%\bootstat.dat -> [2009/04/10 12:56:53 | 00,067,584 | –S- | M] ()
IconCache.db -> %UserProfile%\AppData\Local\IconCache.db -> [2009/04/10 12:56:02 | 01,476,494 | -H– | M] ()
Malwarebytes' Anti-Malware.lnk -> %SystemDrive%\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/04/10 12:16:57 | 00,000,852 | —- | M] ()
HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [2009/04/10 11:50:12 | 00,001,932 | —- | M] ()
streamhlp.dll -> %SystemRoot%\System32\streamhlp.dll -> [2009/04/10 09:50:14 | 00,059,392 | R— | M] ()
TrojanHunter.lnk -> %UserProfile%\Desktop\TrojanHunter.lnk -> [2009/04/10 09:50:13 | 00,000,848 | —- | M] ()
PublishedRacMonSWITable.DAT -> %AllUsersProfile%\Microsoft\RAC\PublishedData\PublishedRacMonSWITable.DAT -> [2009/04/10 09:24:22 | 00,109,056 | —- | M] ()
PublishedRacMonAFLTable.DAT -> %AllUsersProfile%\Microsoft\RAC\PublishedData\PublishedRacMonAFLTable.DAT -> [2009/04/10 09:24:22 | 00,023,184 | —- | M] ()
PublishedRacMonIndex.DAT -> %AllUsersProfile%\Microsoft\RAC\PublishedData\PublishedRacMonIndex.DAT -> [2009/04/10 09:24:22 | 00,003,144 | —- | M] ()
PublishedRacMonOSFTable.DAT -> %AllUsersProfile%\Microsoft\RAC\PublishedData\PublishedRacMonOSFTable.DAT -> [2009/04/10 09:24:22 | 00,001,104 | —- | M] ()
PublishedRacMonHFLTable.DAT -> %AllUsersProfile%\Microsoft\RAC\PublishedData\PublishedRacMonHFLTable.DAT -> [2009/04/10 09:24:22 | 00,000,000 | —- | M] ()
PublishedRacMonCLKTable.DAT -> %AllUsersProfile%\Microsoft\RAC\PublishedData\PublishedRacMonCLKTable.DAT -> [2009/04/10 09:24:22 | 00,000,000 | —- | M] ()
MCEDS.exe -> %UserProfile%\AppData\Local\Temp\CLDownload\CLSetup\_zTmp20090406234743\Download\MCEDS.exe -> [2009/04/06 19:48:20 | 00,131,072 | —- | M] ()
filesys.dll -> %UserProfile%\AppData\Local\Temp\b209632acd9f417aa867756a4415df74\filesys.dll -> [2009/04/06 19:46:16 | 00,182,272 | —- | M] ()
mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation)
mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation)
NTUSER.DAT{32386ee7-1f85-11de-a0f9-002185689a68}.TMContainer00000000000000000002.regtrans-ms -> %UserProfile%\NTUSER.DAT{32386ee7-1f85-11de-a0f9-002185689a68}.TMContainer00000000000000000002.regtrans-ms -> [2009/04/02 21:34:07 | 00,524,288 | -HS- | M] ()
NTUSER.DAT{5b0cda9d-1563-11de-8af7-002185689a68}.TMContainer00000000000000000001.regtrans-ms -> %UserProfile%\NTUSER.DAT{5b0cda9d-1563-11de-8af7-002185689a68}.TMContainer00000000000000000001.regtrans-ms -> [2009/04/02 08:51:15 | 00,524,288 | -HS- | M] ()
NTUSER.DAT{5b0cda9d-1563-11de-8af7-002185689a68}.TM.blf -> %UserProfile%\NTUSER.DAT{5b0cda9d-1563-11de-8af7-002185689a68}.TM.blf -> [2009/04/02 08:51:15 | 00,065,536 | -HS- | M] ()
g2mdlhlpx.exe -> %UserProfile%\g2mdlhlpx.exe -> [2009/04/01 10:56:55 | 00,070,984 | —- | M] ()
An old fan.eml -> %UserProfile%\Documents\An old fan.eml -> [2009/03/26 13:29:43 | 00,004,681 | —- | M] ()
NTUSER.DAT{5b0cda9d-1563-11de-8af7-002185689a68}.TMContainer00000000000000000002.regtrans-ms -> %UserProfile%\NTUSER.DAT{5b0cda9d-1563-11de-8af7-002185689a68}.TMContainer00000000000000000002.regtrans-ms -> [2009/03/20 11:26:35 | 00,524,288 | -HS- | M] ()
NTUSER.DAT{6e25059d-cada-11dd-aaa1-002185689a68}.TMContainer00000000000000000001.regtrans-ms -> %UserProfile%\NTUSER.DAT{6e25059d-cada-11dd-aaa1-002185689a68}.TMContainer00000000000000000001.regtrans-ms -> [2009/03/20 11:24:23 | 00,524,288 | -HS- | M] ()
NTUSER.DAT{6e25059d-cada-11dd-aaa1-002185689a68}.TM.blf -> %UserProfile%\NTUSER.DAT{6e25059d-cada-11dd-aaa1-002185689a68}.TM.blf -> [2009/03/20 11:24:23 | 00,065,536 | -HS- | M] ()
index.dat -> %UserProfile%\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2009/03/18 21:42:47 | 00,032,768 | -HS- | M] ()
index.dat -> %UserProfile%\AppData\Local\Temp\History\History.IE5\index.dat -> [2009/03/18 21:42:47 | 00,016,384 | -HS- | M] ()
index.dat -> %UserProfile%\AppData\Local\Temp\Cookies\index.dat -> [2009/03/18 21:42:47 | 00,016,384 | -HS- | M] ()
Mozilla Firefox.lnk -> %SystemDrive%\Users\Public\Desktop\Mozilla Firefox.lnk -> [2009/03/17 15:19:31 | 00,001,782 | —- | M] ()
My Sharing Folders.lnk -> %UserProfile%\Documents\My Sharing Folders.lnk -> [2009/03/15 15:27:06 | 00,000,801 | —- | M] ()
desktop.ini -> %UserProfile%\Documents\desktop.ini -> [2009/03/14 11:34:49 | 00,000,378 | -HS- | M] ()
02 - …And Justice for All.mp3 -> %UserProfile%\Documents\02 - …And Justice for All.mp3 -> [2009/03/14 11:11:38 | 17,010,391 | —- | M] ()
03 - Eye Of The Beholder.mp3 -> %UserProfile%\Documents\03 - Eye Of The Beholder.mp3 -> [2009/03/14 11:11:38 | 10,926,433 | —- | M] ()
08 - To Live Is To Die.mp3 -> %UserProfile%\Documents\08 - To Live Is To Die.mp3 -> [2009/03/14 11:11:19 | 16,192,174 | —- | M] ()
01 - Blackened.mp3 -> %UserProfile%\Documents\01 - Blackened.mp3 -> [2009/03/14 11:11:19 | 11,641,710 | —- | M] ()
05 - The Shortest Straw.mp3 -> %UserProfile%\Documents\05 - The Shortest Straw.mp3 -> [2009/03/14 11:10:46 | 11,477,819 | —- | M] ()
04 - One.mp3 -> %UserProfile%\Documents\04 - One.mp3 -> [2009/03/14 11:10:44 | 12,485,180 | —- | M] ()
09 - Dyers Eve.mp3 -> %UserProfile%\Documents\09 - Dyers Eve.mp3 -> [2009/03/14 11:10:28 | 09,301,718 | —- | M] ()
07 - The Frayed Ends Of Sanity.mp3 -> %UserProfile%\Documents\07 - The Frayed Ends Of Sanity.mp3 -> [2009/03/14 11:10:00 | 12,608,216 | —- | M] ()
06 - Harvester Of Sorrow.mp3 -> %UserProfile%\Documents\06 - Harvester Of Sorrow.mp3 -> [2009/03/14 11:10:00 | 09,718,583 | —- | M] ()
Folder.jpg -> %UserProfile%\Documents\Folder.jpg -> [2009/03/14 11:04:45 | 00,011,056 | -HS- | M] ()
AlbumArt_{0B6BE3A3-9D5D-488B-8802-69C8D696E85F}_Large.jpg -> %UserProfile%\Documents\AlbumArt_{0B6BE3A3-9D5D-488B-8802-69C8D696E85F}_Large.jpg -> [2009/03/14 11:04:45 | 00,011,056 | -HS- | M] ()
AlbumArtSmall.jpg -> %UserProfile%\Documents\AlbumArtSmall.jpg -> [2009/03/14 11:04:41 | 00,002,443 | -HS- | M] ()
AlbumArt_{0B6BE3A3-9D5D-488B-8802-69C8D696E85F}_Small.jpg -> %UserProfile%\Documents\AlbumArt_{0B6BE3A3-9D5D-488B-8802-69C8D696E85F}_Small.jpg -> [2009/03/14 11:04:41 | 00,002,443 | -HS- | M] ()
~uTorrentPartFile_6A4B39D.dat -> %UserProfile%\Documents\~uTorrentPartFile_6A4B39D.dat -> [2009/03/14 09:59:58 | 00,137,876 | —- | M] ()
µTorrent.lnk -> %UserProfile%\Desktop\µTorrent.lnk -> [2009/03/13 09:15:10 | 00,000,786 | —- | M] ()
wklntsk1.dat -> %AllUsersProfile%\Microsoft\Works\wklntsk1.dat -> [2008/12/16 15:44:22 | 00,000,000 | —- | M] ()
wkcalcat.dat -> %AllUsersProfile%\Microsoft\Works\wkcalcat.dat -> [2008/12/16 15:39:22 | 00,016,384 | —- | M] ()
john.dat -> %AllUsersProfile%\Microsoft\User Account Pictures\john.dat -> [2008/11/30 21:42:48 | 00,000,000 | —- | M] ()
index.dat -> %SystemRoot%\Temp\History\History.IE5\index.dat -> [2008/11/30 18:11:31 | 00,032,768 | -HS- | M] ()
index.dat -> %SystemRoot%\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2008/11/30 18:11:29 | 00,032,768 | -HS- | M] ()
index.dat -> %SystemRoot%\Temp\Cookies\index.dat -> [2008/11/30 18:11:29 | 00,016,384 | -HS- | M] ()
Laura.dat -> %AllUsersProfile%\Microsoft\User Account Pictures\Laura.dat -> [2008/11/30 18:11:25 | 00,000,000 | —- | M] ()
lock.dat -> %AllUsersProfile%\Microsoft\Crypto\RSA\MachineKeys\lock.dat -> [2008/03/16 19:04:01 | 00,000,266 | —- | M] ()
 
[Alternate Data Streams]
@Alternate Data Stream - 615 bytes -> %UserProfile%\Documents\An old fan.eml:OECustomProperty
< End of report >
Turn Security programs on after this fix and a reboot


Please do this:


Start OTScanIt2. Copy/Paste the information inside the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Registry - Safe List]
< FireFox Settings [Prefs.js] > -> C:\Users\Laura\AppData\Roaming\Mozilla\FireFox\Profiles\sf4hx0jf.default\prefs.js
YN -> browser.search.selectedEngine -> "MyWebSearch"
YN -> keyword.URL -> "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZJfox000&fl=0&ptb=j0XLgx1FOalA7EKUT2t_aQ&st=kwd&o=kwd&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&searchfor="
< FireFox SearchPlugins [User Folders] > ->
YY -> mywebsearch.xml -> C:\Users\Laura\AppData\Roaming\Mozilla\FireFox\Profiles\sf4hx0jf.default\searchplugins\mywebsearch.xml
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
YY -> \{a7494194-969b-11dd-a387-806e6f6e6963}\shell\AutoRun\command\\"" -> E:\launch.exe [E:\launch.exe]
[Files/Folders - Created Within 30 Days]
NY -> ~uTorrentPartFile_6A4B39D.dat -> %UserProfile%\Documents\~uTorrentPartFile_6A4B39D.dat
[Files/Folders - Modified Within 30 Days]
NY -> ~uTorrentPartFile_6A4B39D.dat -> %UserProfile%\Documents\~uTorrentPartFile_6A4B39D.dat
[Purity]
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix. If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix.
Post that log back here in your next reply.

If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTScanIt2 will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that log back here in your next reply.

Please include a fresh HJT log along with the OTSI log
[Registry - Safe List] Prefs.js: "MyWebSearch" removed from browser.search.selectedEngine Prefs.js: "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZJfox000&fl=0&ptb=j0XLgx1FOalA7EKUT2t_aQ&st=kwd&o=kwd&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&searchfor=" removed from keyword.URL C:\Users\Laura\AppData\Roaming\Mozilla\FireFox\Profiles\sf4hx0jf.default\searchplugins\mywebsearch.xml moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\ not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a7494194-969b-11dd-a387-806e6f6e6963}\shell\AutoRun\command\\ deleted successfully. File move failed. E:\launch.exe scheduled to be moved on reboot. [Files/Folders - Created Within 30 Days] C:\Users\Laura\Documents\~uTorrentPartFile_6A4B39D.dat moved successfully. [Files/Folders - Modified Within 30 Days] File C:\Users\Laura\Documents\~uTorrentPartFile_6A4B39D.dat not found! [Purity] Purity scan complete. [Empty Temp Folders] File delete failed. C:\Users\Laura\AppData\Local\Temp\etilqs_ujHrYpUyAw0a0nAf8Wwa scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\CLDigitalHome\PCMMediaServer.log scheduled to be deleted on reboot. Windows Temp folder emptied. File delete failed. C:\Users\Laura\AppData\Local\Mozilla\Firefox\Profiles\sf4hx0jf.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Users\Laura\AppData\Local\Mozilla\Firefox\Profiles\sf4hx0jf.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Users\Laura\AppData\Local\Mozilla\Firefox\Profiles\sf4hx0jf.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Users\Laura\AppData\Local\Mozilla\Firefox\Profiles\sf4hx0jf.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Users\Laura\AppData\Local\Mozilla\Firefox\Profiles\sf4hx0jf.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Users\Laura\AppData\Local\Mozilla\Firefox\Profiles\sf4hx0jf.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. RecycleBin -> emptied. Explorer started successfully < End of fix log > OTScanIt2 by OldTimer - Version 1.0.12.2 fix logfile created on 04102009_180857 Files moved on Reboot… File move failed. E:\launch.exe scheduled to be moved on reboot. File C:\Users\Laura\AppData\Local\Temp\etilqs_ujHrYpUyAw0a0nAf8Wwa not found! File move failed. C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt scheduled to be moved on reboot. File move failed. C:\Windows\temp\CLDigitalHome\PCMMediaServer.log scheduled to be moved on reboot. C:\Users\Laura\AppData\Local\Mozilla\Firefox\Profiles\sf4hx0jf.default\Cache\_CACHE_001_ moved successfully. C:\Users\Laura\AppData\Local\Mozilla\Firefox\Profiles\sf4hx0jf.default\Cache\_CACHE_002_ moved successfully. C:\Users\Laura\AppData\Local\Mozilla\Firefox\Profiles\sf4hx0jf.default\Cache\_CACHE_003_ moved successfully. C:\Users\Laura\AppData\Local\Mozilla\Firefox\Profiles\sf4hx0jf.default\Cache\_CACHE_MAP_ moved successfully. C:\Users\Laura\AppData\Local\Mozilla\Firefox\Profiles\sf4hx0jf.default\urlclassifier3.sqlite moved successfully. C:\Users\Laura\AppData\Local\Mozilla\Firefox\Profiles\sf4hx0jf.default\XUL.mfl moved successfully. Registry entries deleted on Reboot…
I ran hjt as a system and log didn't run. went to run as administer then tried to says its running..
do a reboot, then try and run HJT again…you should be clean now but I just want to make sure, then we have some clean up of the tools to do
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:34:45 PM, on 4/10/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\AVG\AVG8\avgtray.exe
C:\Program Files (x86)\TrojanHunter 5.0\THGuard.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5641
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5641
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5641
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~2\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~2\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [PCMMediaSharing] "C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe"
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files (x86)\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] "C:\Program Files (x86)\Acer Assist\launcher.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files (x86)\TrojanHunter 5.0\THGuard.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: ASETRES.EXE
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/…NPUplden-us.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1…=javadl.sun.com
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files (x86)\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11679 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI