This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Redirect in IE and Firefox

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

In Firefox or Windows IE when I do a Google Search, it redirects to a webpage I don’t want…no other odd behaviors noticed.



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:43:13 PM, on 6/7/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe
C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - (no file)
R3 - URLSearchHook: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyng.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: IEPlugin Class - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\PROGRA~2\ArcSoft\VIDEOD~1\ARCURL~1.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyng.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ToolbarBHO Class - {9519AF7E-638D-4933-BAD6-D33D23C79FE5} - C:\PROGRA~2\ArcSoft\RAWTHU~1\EXIFToolBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: TBSB05974 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - (no file)
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O3 - Toolbar: RAW Thumbnail Viewer - {F301665A-12F8-4331-804A-5BCBD379668C} - C:\PROGRA~2\ArcSoft\RAWTHU~1\EXIFToolBar.dll
O3 - Toolbar: (no name) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll
O3 - Toolbar: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyng.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Carbonite Backup] "C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
O4 - HKLM\..\Run: [Microsoft Default Manager] "c:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles(x86)%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Display] C:\Program Files (x86)\APC\APC PowerChute Personal Edition\DataCollectionLauncher.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\ssmmgr.exe /autorun
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe" -bootmode
O4 - HKCU\..\Run: [QuickenScheduledUpdates] C:\Program Files (x86)\Quicken\bagent.exe
O4 - HKCU\..\Run: [SmileboxTray] "C:\Users\S & L Andrews\AppData\Roaming\Smilebox\SmileboxTray.exe"
O4 - HKCU\..\Run: [win2dkdes] C:\Users\S & L Andrews\AppData\Roaming\win2dkdes\win2djws.exe
O4 - HKCU\..\Run: [Desktop Cleanup Wizard] rundll32.exe "C:\Users\S & L Andrews\Local Settings\Application Data\Desktop Cleanup Wizard\dskclean.dll", StartProt
O4 - HKCU\..\Run: [TivoServer] C:\Program Files (x86)\TiVo\Desktop\TiVoServer.exe /service /registry /auto:TivoServer
O4 - HKCU\..\Run: [TivoTransfer] C:\Program Files (x86)\TiVo\Desktop\TiVoTransfer.exe
O4 - HKCU\..\Run: [TivoNotify] C:\Program Files (x86)\TiVo\Desktop\TiVoNotify.exe /service /registry /auto:TivoNotify
O4 - HKCU\..\Run: [TranscodingService] C:\Program Files (x86)\TiVo\Desktop\Plus\\TranscodingService.exe
O4 - HKCU\..\Run: [PlayOn] C:\Program Files (x86)\MediaMall\PlayOn.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: ActivClient Agent.lnk = C:\Program Files\ActivIdentity\ActivClient\acsagent.exe
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files (x86)\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Snagit 9.lnk = C:\Program Files (x86)\TechSmith\Snagit 9\Snagit32.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
O8 - Extra context menu item: Read EXIF - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.0.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} - http://webiq005.webiqonline.com/WebIQ/Data…6-6D5536C585C9}
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab
O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} - http://coupons.smartsource.com/download/cscmv5X.cab
O16 - DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} - http://www.infospace.com/mypoints.main/tba…pointsSetup.exe
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} - http://h20264.www2.hp.com/ediags/dd/instal…osticsVista.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - (no file)
O23 - Service: ActivIdentity Shared Store Service (ac.sharedstore) - ActivIdentity - C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files (x86)\Carbonite\Carbonite Backup\carboniteservice.exe
O23 - Service: CLDTVHNService - Unknown owner - C:\Program Files (x86)\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate1c9c09a31e15c47) (gupdate1c9c09a31e15c47) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Easy Backup Button Service (HPBtnSrv) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_2.EXE
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: MediaMall Server - MediaMall Technologies, Inc. - C:\Program Files (x86)\MediaMall\MediaMallServer.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\SysWOW64\PSIService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Samsung UPD Service - Unknown owner - C:\Windows\System32\SUPDSvc.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files (x86)\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O24 - Desktop Component 0: (no name) - http://www.ty.com/wallpaper/Oct2006/OCT06_wallpaper_800.jpg

–
End of file - 21565 bytes
Hello andrews89,

Welcome to WTT.

Please re-open HijackThis and scan. Check the boxes next to all the entries listed below.

R3 - URLSearchHook: (no name) - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - (no file)
R3 - URLSearchHook: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyng.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyng.dll
O2 - BHO: TBSB05974 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - (no file)
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: (no name) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
O3 - Toolbar: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyng.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.0.cab
O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} - http://coupons.smartsource.com/download/cscmv5X.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab

Close all windows other than HijackThis, then click Fix checked.

Close HijackThis.

Next

  • Download OTL to your desktop.
  • Double click on the icon to run it.
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Files
    C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
    C:\Program Files (x86)\Zynga\tbZyng.dll
    C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE
    
    :Commands
    [purity]
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • It will produce a log for you on reboot, please post that log in your next reply.
Finally in this post

  • Close all windows and open OTL again.
  • Click Run Scan and let the program run uninterrupted
  • It will produce a log for you. Post the log here.
So when you return please post
  • OTL fix log
  • OTL scan log - OTL.txt & OTL.Extras.txt if it is there.

Note: Unless otherwise instructed always post the logs in the forum. If reports don't fit on one post. It might be necessary to break the logs up to get them on the forum. Just use as many posts as you need, that's fine. :)
All processes killed
========== FILES ==========
File\Folder C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll not found.
File\Folder C:\Program Files (x86)\Zynga\tbZyng.dll not found.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: AppData

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LogMeInRemoteUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LogMeInRemoteUser.Andrews-HomePC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: S & L Andrews
->Temp folder emptied: 1764169941 bytes
->Temporary Internet Files folder emptied: 398482871 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 166513400 bytes
->Opera cache emptied: 30683726 bytes
->Flash cache emptied: 2400361 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 13187757 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 100733 bytes
RecycleBin emptied: 7790095296 bytes

Total Files Cleaned = 9,695.00 mb


OTL by OldTimer - Version 3.2.5.3 log created on 06082010_011310

Files\Folders moved on Reboot…
C:\Users\S & L Andrews\AppData\Local\Temp\OLC\andrews1989_hotmail_com.txt moved successfully.
C:\Users\S & L Andrews\AppData\Local\Temp\Google Toolbar\GoogleToolbarWelcome.log moved successfully.
C:\Users\S & L Andrews\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\S & L Andrews\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{0ABDE9F3-100E-46D4-926A-4B960D17DF26}.tmp moved successfully.
C:\Users\S & L Andrews\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{76EAADCA-5662-46C1-8114-26137B5EC4A0}.tmp moved successfully.
C:\Users\S & L Andrews\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{7BB3FF4A-1727-4AC4-908C-AB6C41F4F404}.tmp moved successfully.
C:\Users\S & L Andrews\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{BBEF1132-6ABD-4E20-98DB-32D303E87860}.tmp moved successfully.
C:\Users\S & L Andrews\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U2G43HDH\updates[2].xml moved successfully.
C:\Users\S & L Andrews\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\REEY2L71\FAQs[1].xml moved successfully.
C:\Users\S & L Andrews\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\REEY2L71\iframescript[1].htm moved successfully.
C:\Users\S & L Andrews\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C4EQLKP2\de[1].htm moved successfully.
C:\Users\S & L Andrews\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ELGFSSU\Google_Redirect_IE_Firefox_t112484[1].htm moved successfully.
C:\Users\S & L Andrews\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ELGFSSU\iframe[1].htm moved successfully.
C:\Users\S & L Andrews\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
File\Folder C:\Windows\temp\logishrd\LVPrcInj03.dll not found!
File\Folder C:\Windows\temp\logishrd\LVPrcInj04.dll not found!

Registry entries deleted on Reboot…







OTL logfile created on: 6/8/2010 1:23:18 AM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\S & L Andrews\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 66.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.41 Gb Total Space | 334.82 Gb Free Space | 57.59% Space Free | Partition Type: NTFS
Drive D: | 14.76 Gb Total Space | 2.09 Gb Free Space | 14.15% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANDREWS-HOMEPC
Current User Name: S & L Andrews
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/06/08 01:11:43 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\S & L Andrews\Desktop\OTL.exe
PRC - [2010/05/19 01:55:34 | 003,364,208 | —- | M] (MediaMall Technologies, Inc.) – C:\Program Files (x86)\MediaMall\MediaMallServer.exe
PRC - [2010/05/19 01:54:24 | 000,053,248 | —- | M] (MediaMall Technologies, Inc.) – C:\Program Files (x86)\MediaMall\PlayOn.exe
PRC - [2010/05/12 20:27:33 | 000,186,760 | —- | M] () – C:\Program Files (x86)\Photodex\ProShowGold\scsiaccess.exe
PRC - [2010/05/12 20:15:58 | 000,372,103 | —- | M] () – C:\Users\S & L Andrews\AppData\Roaming\win2dkdes\win2djws.exe
PRC - [2010/04/16 20:04:42 | 000,077,672 | —- | M] (Intuit Inc.) – C:\Program Files (x86)\Quicken\bagent.exe
PRC - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/04/06 14:28:50 | 000,300,352 | —- | M] (Smilebox, Inc.) – C:\Users\S & L Andrews\AppData\Roaming\Smilebox\SmileboxTray.exe
PRC - [2010/03/24 13:58:22 | 000,309,760 | —- | M] (ArcSoft Inc.) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
PRC - [2010/03/18 11:19:26 | 000,207,360 | —- | M] (ArcSoft Inc.) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/03/18 11:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2010/02/25 18:21:50 | 000,126,392 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe
PRC - [2010/02/12 19:07:32 | 005,933,912 | —- | M] (Logitech Inc.) – C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe
PRC - [2009/11/02 13:17:08 | 000,604,888 | —- | M] (TiVo Inc.) – C:\Program Files (x86)\TiVo\Desktop\TiVoTransfer.exe
PRC - [2009/11/02 13:17:06 | 002,195,160 | —- | M] (TiVo Inc.) – C:\Program Files (x86)\TiVo\Desktop\TiVoServer.exe
PRC - [2009/11/02 13:17:04 | 000,430,808 | —- | M] (TiVo Inc.) – C:\Program Files (x86)\TiVo\Desktop\TiVoNotify.exe
PRC - [2009/10/20 14:50:34 | 000,128,296 | —- | M] (CyberLink Corp.) – c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
PRC - [2009/10/15 11:06:52 | 000,053,064 | —- | M] (TechSmith Corporation) – C:\Program Files (x86)\TechSmith\Snagit 9\TscHelp.exe
PRC - [2009/10/15 11:06:50 | 000,066,888 | —- | M] (TechSmith Corporation) – C:\Program Files (x86)\TechSmith\Snagit 9\SnagPriv.exe
PRC - [2009/10/15 11:06:46 | 006,287,176 | —- | M] (TechSmith Corporation) – C:\Program Files (x86)\TechSmith\Snagit 9\Snagit32.exe
PRC - [2009/10/14 14:36:56 | 002,793,304 | —- | M] () – C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009/10/14 14:34:18 | 000,560,472 | —- | M] () – C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2009/10/12 17:58:12 | 000,614,400 | —- | M] () – C:\Windows\Samsung\PanelMgr\SSMMgr.exe
PRC - [2009/10/07 02:47:22 | 000,125,464 | —- | M] (Logitech Inc.) – C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
PRC - [2009/09/17 18:40:44 | 000,075,048 | —- | M] () – C:\Program Files (x86)\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe
PRC - [2009/08/28 13:53:00 | 000,210,216 | —- | M] (CyberLink) – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/07/26 00:19:01 | 000,039,408 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/05/26 02:36:13 | 000,656,896 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
PRC - [2009/04/29 17:19:52 | 001,959,056 | R— | M] (Carbonite, Inc. (www.carbonite.com)) – C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteService.exe
PRC - [2009/04/29 17:19:50 | 000,669,840 | R— | M] (Carbonite, Inc.) – C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
PRC - [2009/01/06 23:25:02 | 000,689,464 | —- | M] (American Power Conversion Corporation) – C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe
PRC - [2009/01/06 23:24:54 | 000,656,696 | —- | M] (American Power Conversion Corporation) – C:\Program Files (x86)\APC\APC PowerChute Personal Edition\apcsystray.exe
PRC - [2008/12/04 13:00:26 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/12/04 13:00:20 | 000,186,904 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/11/20 11:47:28 | 000,062,768 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
PRC - [2008/09/30 18:59:26 | 000,192,512 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe
PRC - [2007/06/05 13:20:32 | 000,177,704 | —- | M] () – C:\Windows\SysWOW64\PSIService.exe


========== Modules (SafeList) ==========

MOD - [2010/06/08 01:11:43 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\S & L Andrews\Desktop\OTL.exe
MOD - [2009/07/13 19:15:07 | 000,486,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\comdlg32.dll
MOD - [2009/07/13 19:14:10 | 000,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/13 19:03:50 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/04/22 03:00:58 | 001,255,736 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\SysNative\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV:64bit: - [2010/03/16 17:04:24 | 000,167,280 | —- | M] (Samsung Electronics CO., LTD.) [On_Demand | Stopped] – C:\Windows\SysNative\SUPDSvc.exe – (Samsung UPD Service)
SRV:64bit: - [2010/03/10 23:29:46 | 000,202,752 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2009/10/07 02:47:10 | 000,191,000 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcS64)
SRV:64bit: - [2009/08/18 12:48:02 | 002,291,568 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE – (wlidsvc)
SRV:64bit: - [2009/07/13 19:41:59 | 000,229,888 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wwansvc.dll – (WwanSvc)
SRV:64bit: - [2009/07/13 19:41:56 | 000,202,240 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wbiosrvc.dll – (WbioSrvc)
SRV:64bit: - [2009/07/13 19:41:56 | 000,163,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\umpo.dll – (Power)
SRV:64bit: - [2009/07/13 19:41:55 | 000,044,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\themeservice.dll – (Themes)
SRV:64bit: - [2009/07/13 19:41:54 | 000,065,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\sppuinotify.dll – (sppuinotify)
SRV:64bit: - [2009/07/13 19:41:54 | 000,029,184 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\sensrsvc.dll – (SensrSvc)
SRV:64bit: - [2009/07/13 19:41:53 | 000,327,168 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\pnrpsvc.dll – (PNRPsvc)
SRV:64bit: - [2009/07/13 19:41:53 | 000,327,168 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\pnrpsvc.dll – (p2pimsvc)
SRV:64bit: - [2009/07/13 19:41:53 | 000,187,904 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\provsvc.dll – (HomeGroupProvider)
SRV:64bit: - [2009/07/13 19:41:53 | 000,067,072 | —- | M] (Microsoft Corporation) [Unknown | Running] – C:\Windows\SysNative\RpcEpMap.dll – (RpcEptMapper)
SRV:64bit: - [2009/07/13 19:41:53 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\pnrpauto.dll – (PNRPAutoReg)
SRV:64bit: - [2009/07/13 19:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/13 19:41:18 | 000,231,936 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\ListSvc.dll – (HomeGroupListener)
SRV:64bit: - [2009/07/13 19:40:54 | 001,127,936 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\FntCache.dll – (FontCache)
SRV:64bit: - [2009/07/13 19:40:28 | 000,314,368 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\dhcpcore.dll – (Dhcp)
SRV:64bit: - [2009/07/13 19:40:28 | 000,291,328 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\defragsvc.dll – (defragsvc)
SRV:64bit: - [2009/07/13 19:40:13 | 000,083,968 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\bthserv.dll – (bthserv)
SRV:64bit: - [2009/07/13 19:40:10 | 000,100,864 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\SysNative\bdesvc.dll – (BDESVC)
SRV:64bit: - [2009/07/13 19:40:05 | 000,114,688 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\AxInstSv.dll – (AxInstSV)
SRV:64bit: - [2009/07/13 19:40:01 | 000,032,256 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appidsvc.dll – (AppIDSvc)
SRV:64bit: - [2009/07/13 19:39:51 | 001,503,744 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wbengine.exe – (wbengine)
SRV:64bit: - [2009/07/13 19:39:28 | 003,524,608 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\sppsvc.exe – (sppsvc)
SRV:64bit: - [2009/07/13 19:39:11 | 000,689,152 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\FXSSVC.exe – (Fax)
SRV:64bit: - [2009/06/03 16:38:36 | 000,277,032 | —- | M] (ActivIdentity) [Auto | Running] – C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe – (ac.sharedstore)
SRV - [2010/05/19 01:55:34 | 003,364,208 | —- | M] (MediaMall Technologies, Inc.) [Auto | Running] – C:\Program Files (x86)\MediaMall\MediaMallServer.exe – (MediaMall Server)
SRV - [2010/05/12 20:27:33 | 000,186,760 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Photodex\ProShowGold\scsiaccess.exe – (ScsiAccess)
SRV - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/03/18 11:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2010/02/25 18:21:50 | 000,126,392 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe – (NIS)
SRV - [2009/12/27 19:20:44 | 000,000,000 | —D | M] [Unknown | Stopped] – C:\Windows\SysWOW64\Msdtc – (MSDTC)
SRV - [2009/11/02 13:17:00 | 001,098,968 | —- | M] (TiVo Inc.) [Disabled | Stopped] – C:\Program Files (x86)\TiVo\Desktop\TiVoBeacon.exe – (TivoBeacon2)
SRV - [2009/10/01 10:50:54 | 000,120,640 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe – (LMIMaint)
SRV - [2009/09/17 18:40:44 | 000,075,048 | —- | M] () [Auto | Running] – C:\Program Files (x86)\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe – (CLDTVHNService)
SRV - [2009/07/13 21:20:14 | 000,000,000 | —D | M] [On_Demand | Stopped] – C:\Windows\Vss – (VSS)
SRV - [2009/07/13 19:16:12 | 000,165,376 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysWOW64\provsvc.dll – (HomeGroupProvider)
SRV - [2009/07/13 19:15:11 | 000,253,440 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\dhcpcore.dll – (Dhcp)
SRV - [2009/07/13 14:30:11 | 000,061,056 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysWOW64\wbem\vds.mof – (vds)
SRV - [2009/06/10 14:39:58 | 000,089,920 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64)
SRV - [2009/04/29 17:19:52 | 001,959,056 | R— | M] (Carbonite, Inc. (www.carbonite.com)) [Auto | Running] – C:\Program Files (x86)\Carbonite\Carbonite Backup\carboniteservice.exe – (CarboniteService)
SRV - [2009/01/06 23:25:02 | 000,689,464 | —- | M] (American Power Conversion Corporation) [Auto | Running] – C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe – (APC UPS Service)
SRV - [2008/12/04 13:00:26 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2008/10/25 11:44:08 | 000,065,888 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe – (Microsoft Office Groove Audit Service)
SRV - [2008/09/30 18:59:26 | 000,192,512 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe – (HPBtnSrv)
SRV - [2008/07/24 18:46:08 | 000,057,920 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe – (LogMeIn)
SRV - [2007/09/12 19:27:24 | 002,999,664 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_2.EXE – (LiveUpdate)
SRV - [2007/06/05 13:20:32 | 000,177,704 | —- | M] () [Auto | Start_Pending] – C:\Windows\SysWOW64\PSIService.exe – (ProtexisLicensing)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/05/05 22:01:59 | 000,451,120 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symtdiv.sys – (SYMTDIv)
DRV:64bit: - [2010/04/28 23:03:51 | 000,150,064 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NISx64\1107000.00C\ironx64.sys – (SymIRON)
DRV:64bit: - [2010/04/21 21:02:20 | 000,221,232 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symefa64.sys – (SymEFA)
DRV:64bit: - [2010/04/21 20:29:51 | 000,505,392 | —- | M] (Symantec Corporation) [File_System | System | Running] – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtsp64.sys – (SRTSP)
DRV:64bit: - [2010/04/21 20:29:51 | 000,032,304 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtspx64.sys – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:64bit: - [2010/03/10 23:39:52 | 006,403,072 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2010/03/10 23:39:52 | 006,403,072 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atipmdag.sys – (amdkmdag)
DRV:64bit: - [2010/03/10 22:34:06 | 000,188,928 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2010/02/25 18:22:52 | 000,615,040 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NISx64\1107000.00C\cchpx64.sys – (ccHP)
DRV:64bit: - [2010/02/24 14:12:34 | 000,028,528 | —- | M] (MediaMall Technologies, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\povrtdev.sys – (msvad_simple)
DRV:64bit: - [2009/12/27 20:51:23 | 000,173,104 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS – (SymEvent)
DRV:64bit: - [2009/12/11 04:29:27 | 000,153,160 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\ksecpkg.sys – (KSecPkg)
DRV:64bit: - [2009/11/05 16:06:13 | 000,433,200 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symds64.sys – (SymDS)
DRV:64bit: - [2009/10/16 02:33:06 | 000,050,176 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2009/10/07 09:49:28 | 006,379,288 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\lvuvc64.sys – (LVUVC64) Logitech Webcam 905(UVC)
DRV:64bit: - [2009/10/07 09:47:46 | 000,327,704 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\lvrs64.sys – (LVRS64)
DRV:64bit: - [2009/10/07 02:45:50 | 000,030,232 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\LVPr2M64.sys – (LVPr2Mon)
DRV:64bit: - [2009/10/07 02:45:50 | 000,030,232 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\LVPr2M64.sys – (LVPr2M64)
DRV:64bit: - [2009/09/26 00:20:38 | 000,223,448 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\fvevol.sys – (fvevol)
DRV:64bit: - [2009/07/18 06:18:48 | 000,109,480 | —- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\jraid.sys – (JRAID)
DRV:64bit: - [2009/07/13 19:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2009/07/13 19:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:48:04 | 000,014,416 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\hwpolicy.sys – (hwpolicy)
DRV:64bit: - [2009/07/13 19:47:49 | 000,055,376 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fsdepends.sys – (FsDepends)
DRV:64bit: - [2009/07/13 19:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 19:45:56 | 000,022,096 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\wimmount.sys – (WIMMount)
DRV:64bit: - [2009/07/13 19:45:55 | 000,217,680 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\vhdmp.sys – (vhdmp)
DRV:64bit: - [2009/07/13 19:45:55 | 000,036,432 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\vdrvroot.sys – (vdrvroot)
DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 19:45:46 | 000,214,096 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\rdyboost.sys – (rdyboost)
DRV:64bit: - [2009/07/13 19:45:45 | 000,050,768 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\pcw.sys – (pcw)
DRV:64bit: - [2009/07/13 19:43:14 | 000,460,504 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\cng.sys – (CNG)
DRV:64bit: - [2009/07/13 18:17:46 | 000,024,064 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rdpbus.sys – (rdpbus)
DRV:64bit: - [2009/07/13 18:16:35 | 000,008,192 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\RDPREFMP.sys – (RDPREFMP)
DRV:64bit: - [2009/07/13 18:10:24 | 000,060,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\agilevpn.sys – (RasAgileVpn) WAN Miniport (IKEv2)
DRV:64bit: - [2009/07/13 18:09:26 | 000,012,800 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\wfplwf.sys – (WfpLwf)
DRV:64bit: - [2009/07/13 18:08:13 | 000,035,328 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ndiscap.sys – (NdisCap)
DRV:64bit: - [2009/07/13 18:07:21 | 000,024,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\vwifibus.sys – (vwifibus)
DRV:64bit: - [2009/07/13 18:07:13 | 000,227,840 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\1394ohci.sys – (1394ohci)
DRV:64bit: - [2009/07/13 18:07:00 | 000,350,208 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HdAudio.sys – (HdAudAddService)
DRV:64bit: - [2009/07/13 18:06:52 | 000,009,728 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\umpass.sys – (UmPass)
DRV:64bit: - [2009/07/13 18:06:32 | 000,109,568 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV:64bit: - [2009/07/13 18:06:28 | 000,040,448 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\winusb.sys – (WinUsb)
DRV:64bit: - [2009/07/13 18:06:24 | 000,008,192 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mshidkmdf.sys – (mshidkmdf)
DRV:64bit: - [2009/07/13 18:05:37 | 000,112,128 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WUDFPf.sys – (WudfPf)
DRV:64bit: - [2009/07/13 18:02:08 | 000,015,360 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\MTConfig.sys – (MTConfig)
DRV:64bit: - [2009/07/13 18:00:34 | 000,038,912 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CompositeBus.sys – (CompositeBus)
DRV:64bit: - [2009/07/13 18:00:13 | 000,006,656 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\beep.sys – (Beep)
DRV:64bit: - [2009/07/13 17:52:39 | 000,061,440 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\appid.sys – (AppID)
DRV:64bit: - [2009/07/13 17:50:17 | 000,029,696 | —- | M] (Microsoft Corporation) [Kernel | Unknown | Running] – C:\Windows\SysNative\drivers\scfilter.sys – (scfilter)
DRV:64bit: - [2009/07/13 17:37:18 | 000,040,448 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\discache.sys – (discache)
DRV:64bit: - [2009/07/13 17:31:06 | 000,026,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hidbatt.sys – (HidBatt)
DRV:64bit: - [2009/07/13 17:31:03 | 000,017,664 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\CmBatt.sys – (CmBatt)
DRV:64bit: - [2009/07/13 17:27:17 | 000,012,288 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\acpipmi.sys – (AcpiPmi)
DRV:64bit: - [2009/07/13 17:19:25 | 000,060,928 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdppm.sys – (AmdPPM)
DRV:64bit: - [2009/06/29 10:00:00 | 000,116,752 | —- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtiHdmi.sys – (AtiHdmiService)
DRV:64bit: - [2009/06/13 02:19:58 | 000,287,960 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\e1y62x64.sys – (e1yexpress) Intel®
DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/06/05 02:54:36 | 000,408,600 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2008/07/24 18:46:08 | 000,072,216 | —- | M] (LogMeIn, Inc.) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\LMIRfsDriver.sys – (LMIRfsDriver)
DRV:64bit: - [2008/07/24 18:45:20 | 000,011,552 | —- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\lmimirr.sys – (lmimirr)
DRV:64bit: - [2007/08/13 20:48:52 | 000,011,576 | —- | M] (Samsung Electronics) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\SSPORT.SYS – (SSPORT)
DRV - [2010/05/28 13:33:18 | 000,463,408 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100528.003\IDSviA64.sys – (IDSVia64)
DRV - [2010/05/26 21:49:00 | 000,475,696 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys – (eeCtrl)
DRV - [2010/05/26 21:49:00 | 000,132,656 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2010/05/10 17:47:43 | 001,773,104 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100607.034\EX64.SYS – (NAVEX15)
DRV - [2010/05/10 17:47:43 | 000,117,808 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100607.034\ENG64.SYS – (NAVENG)
DRV - [2010/04/29 11:44:04 | 000,678,448 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100429.001\BHDrvx64.sys – (BHDrvx64)
DRV - [2009/09/17 18:40:52 | 000,082,416 | —- | M] (Cyberlink Corp.) [Kernel | Auto | Running] – C:\Program Files (x86)\DirecTV\DirecTV\Kernel\DMP\ntk_dtv_64.sys – (ntk_dtv)
DRV - [2009/07/13 19:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
DRV - [2009/07/13 19:16:19 | 000,016,896 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysWOW64\winusb.dll – (WinUsb)
DRV - [2009/07/13 19:16:02 | 000,014,336 | —- | M] (Microsoft Corporation) [File_System | System | Running] – C:\Windows\SysWOW64\netbios.dll – (NetBIOS)
DRV - [2009/06/10 15:28:14 | 000,001,088 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysWOW64\wbem\mpsdrv.mof – (mpsdrv)
DRV - [2009/06/10 15:15:18 | 000,003,066 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysWOW64\wbem\tcpip.mof – (Tcpip)
DRV - [2008/07/24 18:46:10 | 000,015,928 | —- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys – (LMIInfo)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - Reg Error: Key error. File not found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us10.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.iwon.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta, = http://astalavista.box.sk/cgi-bin/robot?srch=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta, = +
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,# = %23
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,& = %26
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,? = %3F
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,+ = %2B
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,= = %3D
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs, = http://www.thebugs.ws/search.php?id=644&q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs, = +
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,# = %23
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,& = %26
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,? = %3F
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,+ = %2B
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,= = %3D
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy, = http://anonym.to/?http://%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy, = +
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,# = %23
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,& = %26
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,? = %3F
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,+ = %2B
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,= = %3D
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "http://bing.zugo.com/?cfg=2-76-0-10JY1"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:0.7.3
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.4.7amo
FF - prefs.js..extensions.enabledItems: [removed]:1.0.13
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.0.5
FF - prefs.js..extensions.enabledItems: {75CEEE46-9B64-46f8-94BF-54012DE155F0}:0.4
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:[removed]
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:3.6.3
FF - prefs.js..extensions.enabledItems: {8FFE139B-90A7-4460-A972-9D2738997F6D}:1.6.3
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.9
FF - prefs.js..extensions.enabledItems: {b9bfaf1c-a63f-47cd-8b9a-29526ced9060}:0.6
FF - prefs.js..extensions.enabledItems: {cd617375-6743-4ee8-bac4-fbf10f35729e}:2.7.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.8
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:2.0.0.11
FF - prefs.js..keyword.URL: "http://bing.zugo.com/s/?src=FF-Address&site=Bing&cfg=2-76-0-10JY1&q="


FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files (x86)\Real\RealPlayer\browserrecord [2009/12/27 19:01:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\ [2010/06/01 02:19:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/28 23:01:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\ [2010/01/26 16:42:56 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: C:\Program Files (x86)\ArcSoft\Video Downloader\Plugin_FireFox [2010/03/14 00:48:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\FireFox Extension [2010/03/14 00:51:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Flock\Extensions\\Components: C:\Program Files (x86)\Flock\flock\components [2010/04/03 08:13:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Flock\Extensions\\Plugins: C:\Program Files (x86)\Flock\flock\plugins [2010/06/01 00:34:39 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/04/04 16:50:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/06/01 00:40:13 | 000,000,000 | —D | M]

[2009/12/27 19:15:27 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Extensions
[2009/12/27 19:15:30 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (Coupon Manager) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{0C7E3F01-99E9-4095-9BDC-F84724960B57}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe6a}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (Print/Print Preview) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{19EB90DC-A456-458b-8AAC-616D91AAFCE1}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (Image Zoom) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{21350f60-90a5-11da-a72b-0800200c9a66}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{2A10B180-05EF-11D9-8C50-444553540001}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (FEBE) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (Gmail Manager) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (Firefox Companion for eBay) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (Searchbar Autosizer) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{655397ca-4766-496b-b7a8-3a5b176ee4c2}
[2009/12/27 19:15:29 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{909409b9-2e3b-4682-a5d1-71ca80a76456}
[2009/12/27 19:15:29 | 000,000,000 | —D | M] (Update Notifier) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
[2009/12/27 19:15:29 | 000,000,000 | —D | M] (TryAgain) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{992791ee-61dc-7b98-a8fd-dc49b7deeee9}
[2009/12/27 19:15:29 | 000,000,000 | —D | M] (More Tools Menu) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{9a7a67d3-3048-47fb-acde-d0f7ae51f86a}
[2009/12/27 19:15:29 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{a937b0b2-4a38-401a-a6a4-4a0b436fcfa6}
[2009/12/27 19:15:29 | 000,000,000 | —D | M] (Answers) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}
[2009/12/27 19:15:29 | 000,000,000 | —D | M] (Download Statusbar) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2009/12/27 19:15:30 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}-trash
[2009/12/27 19:15:30 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2009/12/27 19:15:30 | 000,000,000 | —D | M] () – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{DCBD1271-D228-4082-9FBC-36D9B7660B03}
[2009/12/27 19:15:30 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/07/30 20:07:02 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}-trash
[2009/12/27 19:15:30 | 000,000,000 | —D | M] (My Points Toolbar) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{eeb97566-866d-4551-b292-7de53fb9fe24}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\[removed]
[2009/12/27 19:15:28 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\[removed]
[2009/12/27 19:15:28 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\staged-xpis
[2009/12/27 19:15:28 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\[removed]
[2009/12/27 19:15:28 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\staged-xpis\[removed]
[2010/06/07 14:25:59 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions
[2010/04/10 08:23:33 | 000,000,000 | —D | M] (Screengrab) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/06/04 09:51:59 | 000,000,000 | —D | M] (Flagfox) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2010/05/03 00:08:49 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/04 09:51:59 | 000,000,000 | —D | M] (MeasureIt) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{75CEEE46-9B64-46f8-94BF-54012DE155F0}
[2010/05/20 16:48:02 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/05/03 00:08:49 | 000,000,000 | —D | M] (ReloadEvery) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2010/01/16 13:16:42 | 000,000,000 | —D | M] (QuickPageZoom) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{8FFE139B-90A7-4460-A972-9D2738997F6D}
[2010/06/04 09:51:59 | 000,000,000 | —D | M] (FireFTP) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2010/04/10 08:26:16 | 000,000,000 | —D | M] () – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}
[2010/04/10 08:23:32 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{cd617375-6743-4ee8-bac4-fbf10f35729e}
[2010/05/03 00:08:49 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/05/03 00:08:50 | 000,000,000 | —D | M] (Download Statusbar) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/06/04 09:51:59 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/12/27 19:15:35 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2010/06/04 09:51:59 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\[removed]
[2010/04/10 08:23:33 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\SkipScreen@SkipScreen
[2009/12/27 19:15:31 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\[removed]
[2010/06/04 09:51:59 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\staged-xpis
[2009/12/27 19:15:32 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\[removed]
[2010/05/03 01:27:53 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/04/18 13:46:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2005/08/29 13:32:12 | 000,106,496 | —- | M] (NetRatings, Inc.) – C:\Program Files (x86)\Mozilla Firefox\components\nmgkff10.dll
[2010/03/13 16:01:06 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll
[2009/11/19 15:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/01/04 15:41:16 | 000,114,688 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\plugins\npmozax.dll
[2009/11/19 15:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2008/01/10 12:56:29 | 000,024,673 | —- | M] (MyWebSearch.com) – C:\Program Files (x86)\Mozilla Firefox\plugins\NPMyWebS.dll
[2006/10/12 15:18:00 | 001,245,184 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\plugins\npRACtrl.dll
[2006/10/12 15:17:00 | 000,003,072 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\plugins\ractrlkeyhook.dll
[2006/02/13 10:07:00 | 000,245,408 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Mozilla Firefox\plugins\unicows.dll

O1 HOSTS File: ([2006/09/18 15:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (IEPlugin Class) - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\Program Files (x86)\ArcSoft\Video Downloader\ArcURLRecord.dll (ArcSoft, Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (ToolbarBHO Class) - {9519AF7E-638D-4933-BAD6-D33D23C79FE5} - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll (ArcSoft Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (RAW Thumbnail Viewer) - {F301665A-12F8-4331-804A-5BCBD379668C} - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll (ArcSoft Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [accrdsub] C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe (ActivIdentity)
O4:64bit: - HKLM..\Run: [acevents] C:\Program Files\ActivIdentity\ActivClient\acevents.exe (ActivIdentity)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [Display] C:\Program Files (x86)\APC\APC PowerChute Personal Edition\DataCollectionLauncher.exe (American Power Conversion Corporation)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Remote Solution] C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe ()
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.exe (Microsoft)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [Microsoft Default Manager] c:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.)
O4 - HKLM..\Run: [NvCplDaemon] File not found
O4 - HKLM..\Run: [NvMediaCenter] File not found
O4 - HKLM..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\ssmmgr.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files (x86)\Windows Defender\MSASCui.exe File not found
O4 - HKCU..\Run: [Desktop Cleanup Wizard] File not found
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [PlayOn] C:\Program Files (x86)\MediaMall\PlayOn.exe (MediaMall Technologies, Inc.)
O4 - HKCU..\Run: [QuickenScheduledUpdates] C:\Program Files (x86)\Quicken\bagent.exe (Intuit Inc.)
O4 - HKCU..\Run: [SmileboxTray] C:\Users\S & L Andrews\AppData\Roaming\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe ()
O4 - HKCU..\Run: [TivoNotify] C:\Program Files (x86)\TiVo\Desktop\TiVoNotify.exe (TiVo Inc.)
O4 - HKCU..\Run: [TivoServer] C:\Program Files (x86)\TiVo\Desktop\TiVoServer.exe (TiVo Inc.)
O4 - HKCU..\Run: [TivoTransfer] C:\Program Files (x86)\TiVo\Desktop\TiVoTransfer.exe (TiVo Inc.)
O4 - HKCU..\Run: [TranscodingService] C:\Program Files (x86)\TiVo\Desktop\Plus\\TranscodingService.exe ()
O4 - HKCU..\Run: [win2dkdes] C:\Users\S & L Andrews\AppData\Roaming\win2dkdes\win2djws.exe ()
O4:64bit: - HKLM..\RunOnce: [PCDrProfiler] C:\Program Files\PC-Doctor for Windows\RunProfiler.exe (PC-Doctor, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll (Google Inc.)
O8:64bit: - Extra context menu item: Read EXIF - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll (Google Inc.)
O8 - Extra context menu item: Read EXIF - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15:64bit: - ..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Reg Error: Key error.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Reg Error: Key error.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (Reg Error: Key error.)
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} http://webiq005.webiqonline.com/WebIQ/Data…6-6D5536C585C9} (Reg Error: Key error.)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} http://www.infospace.com/mypoints.main/tba…pointsSetup.exe (Reg Error: Key error.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} http://h20264.www2.hp.com/ediags/dd/instal…osticsVista.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\x-excid {9D6CC632-1337-4a33-9214-2DA092E776F4} - Reg Error: Key error. File not found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\x-excid {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\Windows\Downloaded Program Files\mimectl.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O22 - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - Reg Error: Key error. File not found
O24 - Desktop Components:0 () - http://www.ty.com/wallpaper/Oct2006/OCT06_wallpaper_800.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Users\S & L Andrews\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\S & L Andrews\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/06/08 01:20:07 | 000,000,000 | —D | C] – C:\ProgramData\Gosu
[2010/06/08 01:13:10 | 000,000,000 | —D | C] – C:\_OTL
[2010/06/08 01:11:40 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Users\S & L Andrews\Desktop\OTL.exe
[2010/06/07 14:23:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/06/07 09:22:05 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ActivIdentity
[2010/06/07 09:22:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\ActivIdentity
[2010/06/07 09:22:04 | 000,000,000 | —D | C] – C:\Program Files\ActivIdentity
[2010/06/07 09:16:24 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\Desktop\New folder
[2010/06/06 16:06:15 | 000,092,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WING.DLL
[2010/06/06 16:06:15 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WING32.DLL
[2010/06/06 15:41:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\SamsungPrinterLiveUpdate
[2010/06/06 15:38:56 | 029,771,072 | —- | C] (Samsung ) – C:\Users\S & L Andrews\Desktop\CLP-310_Print.exe
[2010/06/06 14:53:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Samsung Network Printer Utilities
[2010/06/06 14:33:11 | 000,701,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml2.dll
[2010/06/06 14:33:11 | 000,049,152 | —- | C] (Samsung Electronics) – C:\Windows\SysWow64\ssusbpn.dll
[2010/06/06 14:33:11 | 000,047,104 | —- | C] (Samsung Electronics) – C:\Windows\SysNative\ssusbp64.dll
[2010/06/06 14:33:11 | 000,038,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml2r.dll
[2010/06/06 14:33:11 | 000,021,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml2a.dll
[2010/06/06 14:33:11 | 000,000,000 | —D | C] – C:\Windows\Samsung
[2010/06/06 14:32:59 | 000,074,240 | —- | C] (Samsung Electronics) – C:\Windows\SysNative\ssdevm64.dll
[2010/06/06 14:32:58 | 000,081,920 | —- | C] (Samsung Electronics) – C:\Windows\SysWow64\ssdevm.dll
[2010/06/06 14:32:29 | 000,151,552 | —- | C] (SS) – C:\Windows\SysNative\cl31cci.exe
[2010/06/06 14:32:29 | 000,089,600 | —- | C] (SS) – C:\Windows\SysNative\cl31cci.dll
[2010/06/04 12:40:27 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\AppData\Roaming\Insight Software
[2010/06/04 12:40:27 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\AppData\Local\Insight Software
[2010/06/04 12:40:26 | 000,000,000 | —D | C] – C:\ProgramData\Insight Software
[2010/06/04 12:40:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Debt Analyzer 4
[2010/06/01 00:36:21 | 000,000,000 | -H-D | C] – C:\Windows\AxInstSV
[2010/06/01 00:09:45 | 000,000,000 | —D | C] – C:\ProgramData\Yahoo! Companion
[2010/06/01 00:09:45 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\AppData\Roaming\Yahoo!
[2010/06/01 00:09:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Yahoo!
[2010/06/01 00:03:29 | 001,403,904 | —- | C] (Hewlett-Packard Co.) – C:\Windows\SysNative\hpotiop5.dll
[2010/06/01 00:03:29 | 000,938,496 | —- | C] (Hewlett-Packard) – C:\Windows\SysNative\hpowiax5.dll
[2010/06/01 00:03:29 | 000,642,360 | —- | C] (Hewlett-Packard) – C:\Windows\SysNative\hpzids40.dll
[2010/06/01 00:03:29 | 000,540,672 | —- | C] (Hewlett-Packard) – C:\Windows\SysNative\hppldcoi.dll
[2010/06/01 00:03:29 | 000,505,344 | —- | C] (Hewlett-Packard Co.) – C:\Windows\SysNative\hpovst12.dll
[2010/05/31 11:23:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2010/05/31 10:38:44 | 000,000,000 | —D | C] – C:\Users\Public\Documents\pyTivo
[2010/05/30 00:27:00 | 000,000,000 | R–D | C] – C:\Users\S & L Andrews\Documents\My TiVo Recordings
[2010/05/30 00:27:00 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\AppData\Local\TiVo Desktop
[2010/05/30 00:27:00 | 000,000,000 | —D | C] – C:\ProgramData\TiVo
[2010/05/30 00:27:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\TiVo
[2010/05/30 00:27:00 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\Documents\My TiVo Recordings for Portables
[2010/05/30 00:21:28 | 024,435,416 | —- | C] (TiVo Inc.) – C:\Users\S & L Andrews\Desktop\TiVoDesktop2.8.exe
[2010/05/29 23:05:44 | 000,256,000 | —- | C] (SEC) – C:\Windows\SysNative\SIPDUtil.dll
[2010/05/29 23:05:44 | 000,167,280 | —- | C] (Samsung Electronics CO., LTD.) – C:\Windows\SysNative\SUPDSvc.exe
[2010/05/29 23:05:44 | 000,162,672 | —- | C] (Samsung Electronics CO., LTD.) – C:\Windows\SysNative\SUPDSvcA.dll
[2010/05/29 23:05:44 | 000,157,552 | —- | C] (SS) – C:\Windows\SysNative\spd__ci.exe
[2010/05/29 23:05:44 | 000,089,600 | —- | C] (SS) – C:\Windows\SysNative\spd__ci.dll
[2010/05/29 23:05:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Samsung
[2010/05/29 23:04:20 | 028,079,936 | —- | C] (Samsung ) – C:\Users\S & L Andrews\Desktop\SamsungUniversalPrintDriver.exe
[2010/05/29 12:34:44 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\AppData\Local\Desktop Cleanup Wizard
[2010/05/23 11:47:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2010/05/19 21:06:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Conduit
[2010/05/19 21:06:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Zynga
[2010/05/19 20:41:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\TV-Websites
[2010/05/19 20:41:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\MediaMall
[2010/05/19 20:41:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ffdshowEx
[2010/05/19 20:40:52 | 000,000,000 | —D | C] – C:\ProgramData\MediaMall
[2010/05/18 19:20:31 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010_psdata
[2010/05/12 20:15:59 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\AppData\Roaming\win2dkdes
[2010/05/10 18:19:13 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\Documents\Snagit Stamps
[1 C:\Users\S & L Andrews\*.tmp files -> C:\Users\S & L Andrews\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/08 01:25:15 | 010,223,616 | -HS- | M] () – C:\Users\S & L Andrews\NTUSER.DAT
[2010/06/08 01:21:46 | 000,000,880 | —- | M] () – C:\Windows\tasks\Google Software Updater.job
[2010/06/08 01:19:22 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/08 01:19:11 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/08 01:18:55 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/08 01:18:43 | 000,000,000 | —- | M] () – C:\Windows\SysNative\drivers\lvuvc.hs
[2010/06/08 01:18:33 | 529,915,903 | -HS- | M] () – C:\hiberfil.sys
[2010/06/08 01:17:30 | 004,461,489 | -H– | M] () – C:\Users\S & L Andrews\AppData\Local\IconCache.db
[2010/06/08 01:13:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/08 01:11:43 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\S & L Andrews\Desktop\OTL.exe
[2010/06/07 18:03:02 | 001,159,900 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\Cat.DB
[2010/06/07 15:00:33 | 000,011,104 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/07 15:00:33 | 000,011,104 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/07 14:36:12 | 000,003,011 | —- | M] () – C:\Users\S & L Andrews\Desktop\HiJackThis.lnk
[2010/06/07 09:23:55 | 000,002,146 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ActivClient Agent.lnk
[2010/06/07 09:16:24 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/07 09:16:24 | 000,615,122 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/07 09:16:24 | 000,103,496 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/06/06 16:06:29 | 000,000,138 | —- | M] () – C:\Users\Public\Desktop\SAMSUNG Dr.Printer.url
[2010/06/06 16:01:17 | 028,079,936 | —- | M] (Samsung ) – C:\Users\S & L Andrews\Desktop\SamsungUniversalPrintDriver.exe
[2010/06/06 15:57:12 | 000,000,926 | —- | M] () – C:\Users\Public\Desktop\Samsung Dr.Printer.lnk
[2010/06/06 15:38:56 | 029,771,072 | —- | M] (Samsung ) – C:\Users\S & L Andrews\Desktop\CLP-310_Print.exe
[2010/06/06 11:16:01 | 000,032,470 | —- | M] () – C:\Users\S & L Andrews\Desktop\51hoJrdomlL._SS400_.jpg
[2010/06/01 00:27:54 | 000,002,491 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2010/06/01 00:22:56 | 000,015,389 | —- | M] () – C:\Users\S & L Andrews\Desktop\Trees for wet sites.docx
[2010/06/01 00:22:20 | 000,014,131 | —- | M] () – C:\Users\S & L Andrews\Desktop\TREES WHICH THRIVE IN VERY WET SOIL.docx
[2010/06/01 00:19:01 | 013,496,320 | —- | M] () – C:\Users\S & L Andrews\Desktop\S & L Andrews's Quicken Data-2010-06-01.QDF-backup
[2010/06/01 00:16:59 | 454,645,531 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip FebMar 2010.pxc
[2010/06/01 00:16:17 | 064,580,179 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.pxc
[2010/06/01 00:15:49 | 000,210,855 | —- | M] () – C:\Windows\hpoins21.dat
[2010/06/01 00:15:40 | 000,244,379 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.psh
[2010/06/01 00:08:59 | 000,002,169 | —- | M] () – C:\Users\Public\Desktop\HP Photosmart Essential 3.5.lnk
[2010/06/01 00:07:39 | 000,002,101 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/05/31 23:59:21 | 000,001,081 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk
[2010/05/31 23:56:21 | 000,501,248 | —- | M] () – C:\Users\S & L Andrews\Desktop\Backup.wlt
[2010/05/31 11:30:24 | 000,008,032 | —- | M] () – C:\Users\S & L Andrews\Desktop\www.playonscripts.com-{ea65016a-3111-405a-819c-92c7b72679ab}.dtapart
[2010/05/31 10:31:41 | 002,954,640 | —- | M] () – C:\Users\S & L Andrews\Desktop\pyTivo-wmcbrine-2009.03.19-RC1.zip
[2010/05/30 00:27:03 | 000,000,970 | —- | M] () – C:\Users\Public\Desktop\TiVo Desktop.lnk
[2010/05/21 13:07:54 | 001,827,461 | —- | M] () – C:\Users\S & L Andrews\Desktop\pocket_informant_pro910_us_smart_setup.exe
[2010/05/19 23:52:17 | 000,008,192 | —- | M] () – C:\Users\S & L Andrews\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/19 20:41:09 | 000,002,043 | —- | M] () – C:\Users\Public\Desktop\PlayOn.lnk
[2010/05/18 19:09:22 | 000,244,395 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.bak
[2010/05/14 16:55:31 | 000,241,041 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b01
[2010/05/14 16:39:14 | 000,223,164 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b02
[2010/05/14 16:39:05 | 000,223,164 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b03
[2010/05/14 16:31:47 | 000,222,116 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b04
[2010/05/14 16:28:19 | 000,204,920 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b05
[2010/05/14 00:32:01 | 000,000,172 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\isolate.ini
[2010/05/12 20:15:59 | 000,000,002 | —- | M] () – C:\Users\S & L Andrews\tenmy.ini
[2010/05/12 20:15:58 | 000,372,103 | —- | M] () – C:\Users\S & L Andrews\win2djws.exe
[2010/05/12 20:15:56 | 000,136,704 | —- | M] () – C:\Users\S & L Andrews\pod822.exe
[2010/05/10 18:21:55 | 000,702,689 | —- | M] () – C:\Users\S & L Andrews\Desktop\tivo lifetime auction.jpg
[2010/05/10 18:19:15 | 000,002,037 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snagit 9.lnk
[2010/05/10 05:50:16 | 000,000,016 | —- | M] () – C:\Windows\popcinfo.dat
[1 C:\Users\S & L Andrews\*.tmp files -> C:\Users\S & L Andrews\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/07 14:23:25 | 000,003,011 | —- | C] () – C:\Users\S & L Andrews\Desktop\HiJackThis.lnk
[2010/06/07 09:22:07 | 000,002,146 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ActivClient Agent.lnk
[2010/06/06 15:57:12 | 000,000,926 | —- | C] () – C:\Users\Public\Desktop\Samsung Dr.Printer.lnk
[2010/06/06 15:40:59 | 000,005,430 | —- | C] () – C:\Windows\AnyWeb Print.ico
[2010/06/06 14:33:14 | 000,000,138 | —- | C] () – C:\Users\Public\Desktop\SAMSUNG Dr.Printer.url
[2010/06/06 14:33:12 | 000,482,408 | —- | C] () – C:\Windows\ssndii.exe
[2010/06/06 14:32:28 | 000,022,016 | —- | C] () – C:\Windows\SysNative\cl31cl6.dll
[2010/06/06 14:32:28 | 000,000,357 | —- | C] () – C:\Windows\SysNative\cl31cl6.smt
[2010/06/06 11:15:57 | 000,032,470 | —- | C] () – C:\Users\S & L Andrews\Desktop\51hoJrdomlL._SS400_.jpg
[2010/06/01 00:22:55 | 000,015,389 | —- | C] () – C:\Users\S & L Andrews\Desktop\Trees for wet sites.docx
[2010/06/01 00:22:18 | 000,014,131 | —- | C] () – C:\Users\S & L Andrews\Desktop\TREES WHICH THRIVE IN VERY WET SOIL.docx
[2010/06/01 00:19:00 | 013,496,320 | —- | C] () – C:\Users\S & L Andrews\Desktop\S & L Andrews's Quicken Data-2010-06-01.QDF-backup
[2010/06/01 00:08:58 | 000,002,169 | —- | C] () – C:\Users\Public\Desktop\HP Photosmart Essential 3.5.lnk
[2010/06/01 00:07:39 | 000,002,101 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/05/31 23:59:21 | 000,001,081 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk
[2010/05/31 11:30:23 | 000,008,032 | —- | C] () – C:\Users\S & L Andrews\Desktop\www.playonscripts.com-{ea65016a-3111-405a-819c-92c7b72679ab}.dtapart
[2010/05/31 10:31:42 | 002,954,640 | —- | C] () – C:\Users\S & L Andrews\Desktop\pyTivo-wmcbrine-2009.03.19-RC1.zip
[2010/05/31 10:28:31 | 014,868,480 | —- | C] () – C:\Users\S & L Andrews\Desktop\python-2.6.2.amd64.msi
[2010/05/30 00:27:03 | 000,000,970 | —- | C] () – C:\Users\Public\Desktop\TiVo Desktop.lnk
[2010/05/29 23:05:46 | 000,011,502 | —- | C] () – C:\Windows\Dr. Printer Icon.ico
[2010/05/29 23:05:44 | 000,358,912 | —- | C] () – C:\Windows\SysNative\DscPnt.dll
[2010/05/29 23:05:44 | 000,259,440 | —- | C] () – C:\Windows\SUPDRun.exe
[2010/05/29 23:05:44 | 000,027,648 | —- | C] () – C:\Windows\SysNative\spd__l.dll
[2010/05/29 23:05:44 | 000,000,357 | —- | C] () – C:\Windows\SysNative\spd__l.smt
[2010/05/21 13:07:48 | 001,827,461 | —- | C] () – C:\Users\S & L Andrews\Desktop\pocket_informant_pro910_us_smart_setup.exe
[2010/05/19 20:41:09 | 000,002,043 | —- | C] () – C:\Users\Public\Desktop\PlayOn.lnk
[2010/05/14 16:28:19 | 064,580,179 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.pxc
[2010/05/14 16:28:19 | 000,244,395 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.bak
[2010/05/14 16:28:19 | 000,244,379 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.psh
[2010/05/14 16:28:19 | 000,241,041 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b01
[2010/05/14 16:28:19 | 000,223,164 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b03
[2010/05/14 16:28:19 | 000,223,164 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b02
[2010/05/14 16:28:19 | 000,222,116 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b04
[2010/05/14 16:28:19 | 000,204,920 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b05
[2010/05/12 20:15:59 | 000,000,002 | —- | C] () – C:\Users\S & L Andrews\tenmy.ini
[2010/05/12 20:15:57 | 000,372,103 | —- | C] () – C:\Users\S & L Andrews\win2djws.exe
[2010/05/12 20:15:55 | 000,136,704 | —- | C] () – C:\Users\S & L Andrews\pod822.exe
[2010/05/10 18:21:09 | 000,702,689 | —- | C] () – C:\Users\S & L Andrews\Desktop\tivo lifetime auction.jpg
[2010/05/10 18:19:15 | 000,002,037 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snagit 9.lnk
[2010/02/14 16:10:23 | 000,000,171 | —- | C] () – C:\Windows\QUICKEN.INI
[2009/10/18 12:01:05 | 001,970,176 | —- | C] () – C:\Windows\SysWow64\d3dx9.dll
[2009/09/23 20:27:14 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/09/12 16:30:19 | 000,189,952 | —- | C] () – C:\Windows\Qcard32.dll
[2009/07/28 14:47:24 | 000,000,074 | —- | C] () – C:\Windows\MPLAYER.INI
[2009/07/28 02:15:57 | 000,111,104 | —- | C] () – C:\Windows\SysWow64\MVCL13N.DLL
[2009/07/28 02:08:16 | 000,338,944 | —- | C] () – C:\Windows\SysWow64\lffpx7.dll
[2009/07/28 02:08:16 | 000,122,880 | —- | C] () – C:\Windows\SysWow64\LFKODAK.DLL
[2009/07/28 02:07:17 | 000,001,336 | —- | C] () – C:\Windows\viewer.ini
[2009/07/28 02:07:08 | 000,631,808 | —- | C] () – C:\Windows\SysWow64\RWDL6DMX.DLL
[2009/07/28 02:07:07 | 000,631,808 | —- | C] () – C:\Windows\SysWow64\RWDL6BMX.DLL
[2009/07/28 02:07:06 | 000,630,784 | —- | C] () – C:\Windows\SysWow64\RWDL6AMX.DLL
[2009/07/28 02:07:04 | 000,032,768 | —- | C] () – C:\Windows\SysWow64\CPUINF32.DLL
[2009/07/28 01:48:51 | 000,000,458 | —- | C] () – C:\Windows\btw.ini
[2009/07/28 01:48:49 | 000,633,344 | —- | C] () – C:\Windows\SysWow64\RWDL6CMX.DLL
[2009/07/28 01:25:41 | 000,000,022 | —- | C] () – C:\Windows\VDECK.INI
[2009/07/28 01:16:26 | 000,044,544 | —- | C] () – C:\Windows\SysWow64\gif89.dll
[2009/07/28 01:15:42 | 000,000,766 | —- | C] () – C:\Windows\SIERRA.INI
[2009/07/26 23:10:56 | 000,001,680 | -HS- | C] () – C:\Windows\SysWow64\KGyGaAvL.sys
[2009/07/22 00:53:08 | 000,354,816 | —- | C] () – C:\Windows\SysWow64\pythoncom26.dll
[2009/07/22 00:53:08 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\pywintypes26.dll
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2008/12/29 11:30:20 | 000,000,070 | —- | C] () – C:\Windows\TaxACT08.ini
[2007/10/28 09:21:49 | 000,000,084 | —- | C] () – C:\Windows\EPSPRX580.ini
[2007/10/18 12:04:23 | 000,000,031 | -H– | C] () – C:\Windows\uccspecc.sys
[2006/11/06 16:49:36 | 000,000,322 | —- | C] () – C:\Windows\primopdf.ini
[2006/05/02 16:38:24 | 000,000,748 | —- | C] () – C:\Windows\SetBrowser.ini
[2002/03/20 16:01:05 | 000,006,688 | R— | C] () – C:\Windows\SysWow64\Digita.sys
[2002/03/20 16:00:19 | 000,049,152 | R— | C] () – C:\Windows\SysWow64\TransportUSB.dll
[2002/03/20 16:00:19 | 000,049,152 | R— | C] () – C:\Windows\SysWow64\TransportSerial.dll
[2002/03/20 16:00:18 | 000,049,152 | R— | C] () – C:\Windows\SysWow64\TransportIrDA.dll
[2002/03/20 16:00:18 | 000,049,152 | R— | C] () – C:\Windows\SysWow64\TransportIrCOMM.dll
< End of report >




OTL Extras logfile created on: 6/8/2010 1:23:18 AM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\S & L Andrews\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 66.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.41 Gb Total Space | 334.82 Gb Free Space | 57.59% Space Free | Partition Type: NTFS
Drive D: | 14.76 Gb Total Space | 2.09 Gb Free Space | 14.15% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANDREWS-HOMEPC
Current User Name: S & L Andrews
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
.url [@ = InternetShortcut] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [ACDSee Photo Manager 12.Manage] – "C:\Program Files (x86)\ACD Systems\ACDSee\12.0\ACDSeeQV12.exe" "%1" (ACD Systems International Inc.)
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MIF5BA~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDSee Photo Manager 12.Manage] – "C:\Program Files (x86)\ACD Systems\ACDSee\12.0\ACDSeeQV12.exe" "%1" (ACD Systems International Inc.)
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MIF5BA~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0CE0034E-2119-4CDF-9597-DE28390A77F1}" = MobileMe Control Panel
"{26A24AE4-039D-4CA4-87B4-2F86416015FF}" = Java™ 6 Update 15 (64-bit)
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{404BB1FF-A84F-432F-B77B-301E88E8D1C7}" = Apple Mobile Device Support
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4FFA2088-8317-3B14-93CD-4C699DB37843}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
"{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer
"{5F240DB8-0D74-4F13-86C3-929760392A8D}" = HP Remote Software
"{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Windows Mobile Device Center
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{7EA2D88A-C8B7-4102-8644-0A437B6FC143}" = Neat Mobile Scanner Driver
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{850C7AF6-7376-464D-A69C-E8419EC7ACA7}" = Microsoft IntelliType Pro 7.0
"{86E45973-5352-439F-A115-2E8EE4D40140}" = ActivClient CAC x64
"{8A2BC7D4-A7D3-45D5-B3D2-394718C53C41}" = Neat ADF Scanner 2008 Driver
"{8DA5428C-3D35-317C-2FBA-485AAC49E9C0}" = ccc-utility64
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{92DBCA36-9B41-4DD1-941A-AED149DD37F0}" = Windows Mobile Device Center Driver Update
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96D5EB02-DE18-4DCD-A713-929B4461CA8D}" = iTunes
"{987FE247-4E69-4A2E-A961-D14F901FDBF6}" = Logitech Webcam Software
"{988329F4-A1A1-4D51-803C-EF2725A97627}" = HP Photosmart All-In-One Driver Software 13.0 Rel. 2
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{A55F1206-BFA7-4027-92B8-CE4EFDBC3CF2}" = Neat ADF Scanner Driver
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{C19D4D8F-4433-4F6D-9F0C-79589FD0B973}" = Bonjour
"{CCC50A42-892B-AF23-6188-6E8D2FDF34E3}" = ATI Catalyst Install Manager
"{D1108D4B-72F8-419F-88C5-ABB8DC09B3C7}" = Neat Mobile Scanner (Silver) Driver
"{D2E8F543-D23A-4A38-AFFC-4BDEBFBA6FDA}" = HP MediaSmart SmartMenu
"{DDE25FC9-892D-4D24-9325-3BAA5C15ACA9}" = Neat Mobile Scanner 2008 Driver
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"OfficeTrial" = Microsoft Office Home and Student 60 day trial
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"Shop for HP Supplies" = Shop for HP Supplies
"Taskbar Shuffle_is1" = Taskbar Shuffle 64-bit version 2.5

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{01A1A019-E1D8-482A-BE17-5E118D17C0A0}" = ArcSoft Print Creations - Brochures & Flyers
"{0295F89F-F698-4101-9A7D-49F407EC2D82}" = HP Active Support Library
"{03BF5CB1-B72E-4CA6-A278-F65680F05420}" = HP Picasso Media Center Add-In
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{0BDE949A-3CF5-3852-B4F7-92EAE4F25F73}" = CCC Help English
"{0DB87EAC-F695-4D59-9609-C93119AE6B35}" = SAMSUNG Dr.Printer
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{1896E712-2B3D-45eb-BCE9-542742A51032}" = PictureMover
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1CC069FA-1A86-402E-9787-3F04E652C67A}" = HP Support Information
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{1DD125EA-7614-F1B0-D0C4-5B934B67B1E3}" = CCC Help French
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{20292BBB-C7D7-4526-9E38-42C4A5C2A3A6}" = H&R Block Deluxe + Efile 2009
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20EFC9AA-BBC1-4DFD-81FF-99654F71CBF8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java™ 6 Update 20
"{28727940-2343-A5BB-59DC-6A88C81DC8CD}" = CCC Help Japanese
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{290CA856-3737-4874-864B-BA142F4823C8}_is1" = HP MediaSmart Demo
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{30B056AF-F414-4B68-B9B0-6EFDB9FCDF18}" = ArcSoft MediaImpression 2
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{374E83F9-1DAA-3AA1-5E29-80166AE44E6A}" = CCC Help Hungarian
"{3C569633-C8DE-46E2-BB8F-F65198681C2F}" = Corel Photo Album 7
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3CE47E6B-AE27-4E40-AC54-329EED96B933}" = ArcSoft Print Creations - Funhouse II
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{3E991666-4704-0503-3A88-CE17DD7332AD}" = CCC Help German
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{44C05309-60F4-410B-BC32-31733CFF1A49}" = Microsoft Digital Image Suite Anniversary Edition Editor
"{45350494-82B7-3E53-85B7-79A1AD9AE080}" = Catalyst Control Center Graphics Light
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{479F8C12-576B-4A58-AB78-4B70F7012AA8}" = DIRECTV2PC Playback Advisor
"{47F36D92-E58E-456D-B73C-3382737E4C42}" = HP Update
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{4E839090-3B68-436A-B3CF-A2A08C38DD26}" = TiVo Desktop 2.8
"{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}" = Logitech Vid
"{4FE542EB-FF0B-4739-94DD-25C8AE0AB259}" = Microsoft Digital Image Suite Anniversary Edition Library
"{525E7F71-67C1-806E-69D0-892CC3CE2F8E}" = Catalyst Control Center Graphics Full Existing
"{537306C2-CDAC-F606-5D46-D5727F58FAD3}" = Catalyst Control Center Graphics Previews Vista
"{538BFFBB-6D0B-4CBA-8F3D-E2C9A3EC9812}" = PlayOn
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{5660022E-F3F2-4126-8CC5-9726C47150EB}" = Microsoft Windows Live OneCare Resources v2.5.2900.24
"{57B78E85-9F09-4D1F-2ECE-42CA4281A318}" = CCC Help Greek
"{58141AC0-058E-57EA-55F8-5D8BAAEE790B}" = CCC Help Czech
"{5A0C892E-FD1C-4203-941E-0956AED20A6A}" = APC PowerChute Personal Edition
"{5C47C8B6-77FF-4FC7-A388-66FCF9CFC24C}" = Snagit 9.1.3
"{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
"{5D1C82E7-7EC0-4404-A8AD-36C3B444BC34}" = ArcSoft Print Creations - Poster Creator
"{5D9B17E4-5C34-45B2-9C95-8B9DB4CF7AF3}" = HP_Network_UserGuide
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67431FA8-4B89-42DD-A68E-30D77F6C8D99}_is1" = HP Easy Backup
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{685B0843-6C8D-4E42-B60D-2B86B45526E0}" = PS_AIO_02_Software_Min
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6B437F94-056F-4791-AF2C-0D10E2706AF0}" = PanoStandAlone
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6CF08AD2-00C5-4A63-B74B-2EFFFAFEBE1A}" = Microsoft Outlook Web Access S/MIME
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{6DC0888B-688C-5DA7-42F0-A2BFF3DEF94C}" = CCC Help Polish
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{72736F5F-520D-472A-88CC-7B02872FD34E}" = ATI Catalyst Registration
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A43E42-3658-4DD9-8551-FACDA3632538}" = HP Advisor
"{757DD0A5-3EBF-9D11-D317-2897BDF826EC}" = CCC Help Swedish
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{784BEA84-FA66-4B19-BB80-7B545F248AC6}" = HP Total Care Setup
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7BD1EAE4-2E08-4087-8600-44B0ACB0C887}" = NeatWorks Core Files
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{7F1B3341-A94E-4F5C-B587-CA0EB964221E}" = Microsoft Money Shared Libraries
"{7F831576-6246-42C7-B523-55B3F96509CC}" = LogMeIn
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{82FAC25D-D0E1-4D60-9268-F3DD958BF052}" = ArcSoft RAW Thumbnail Viewer
"{83102DA6-AFB3-6D2F-9A2E-B2DCE733CBE2}" = CCC Help Norwegian
"{8318FEFD-F467-44D6-82B8-129374BFE9B1}" = Opera 9.62
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{87BB78C4-F36D-4D93-A7C7-F80F18219848}" = AMD DnD V1.0.19
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{885744A4-1A01-44B0-858A-0AE6738CBCF7}" = PrimoPDF Redistribution Package
"{885F5AC6-4413-4D30-99A9-F4494BFA4923}" = Logitech Harmony Remote Software 7
"{88DDBE5E-8AC0-F463-AC50-E56FAA2E3CEB}" = Catalyst Control Center Graphics Previews Common
"{897B3B21-8691-26F5-97E8-A9955C20BB20}" = Catalyst Control Center HydraVision Full
"{89EAD745-088B-4160-B964-42C4D4D273AD}" = Family Tree Maker 2010
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8D7133DE-27D2-47E5-B248-4180278D32AA}" = Catalyst Control Center - Branding
"{8FA3864D-209B-2936-ABF3-4E018890E934}" = CCC Help Dutch
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0017-0000-0000-0000000FF1CE}_SharePointDesigner_{E1C33B03-3FE9-45BF-91E4-0266F38618C6}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
"{90120000-0017-0409-0000-0000000FF1CE}_SharePointDesigner_{E1044ED2-E4AD-4B39-B500-31109750F6B4}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_SharePointDesigner_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_SharePointDesigner_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_SharePointDesigner_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISER_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_SharePointDesigner_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_SharePointDesigner_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{94F8D42D-BB31-4858-9705-7D756D8D9655}" = PS_AIO_02_Software
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{95F875CC-1B85-43E6-B3E0-13EA04F3D995}" = ArcSoft Print Creations - Photo Prints
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4D3FF6-FFDD-4E4E-B887-4BF378174F04}" = ArcSoft PhotoStudio 6
"{9AE27CE5-2442-EEA6-1D66-ED8D95E2EDF6}" = HydraVision
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9CC89170-000B-457D-91F1-53691F85B223}" = Python 2.6.1
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}" = HP Recovery Manager RSS
"{A26A10B0-4E27-5722-556B-E1485D8EE0F3}" = CCC Help Korean
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A5CBD7C5-CF16-443F-A4F2-3503C9DE311B}" = ACDSee Photo Manager 12
"{A660669C-4BD3-EB18-7B49-D71F00D62DBE}" = CCC Help Spanish
"{A842C34B-2083-6947-BC0E-5654BDBADCDA}" = Catalyst Control Center Graphics Full New
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC3F3DCF-39D2-B628-146E-93548CDDAD89}" = CCC Help Danish
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{AE469025-08BA-4B2A-915D-CC7765132419}" = Default Manager
"{AFA196FB-2500-C411-3C85-51BF31949684}" = Catalyst Control Center InstallProxy
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B28635AB-1DF3-4F07-BFEA-975D911B549B}" = hpphotosmartdisclabelplugin
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B6971C63-4702-242B-D86E-845BFF61D1F4}" = CCC Help Finnish
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B74E020A-CC78-5F2C-E0D7-77FD61AC7F9F}" = CCC Help Italian
"{B84739A3-F943-47E4-95D8-96381EF5AC48}" = HP Customer Experience Enhancements
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{b9be267c-e096-4cce-a4fd-f24eec004938}" = PS_AIO_02_ProductContext
"{BA3B34EB-3F4B-0E19-0916-971C1AD3F0AD}" = Catalyst Control Center InstallProxy
"{BB493D5B-11E5-2D0A-96D2-442696E38D3D}" = CCC Help Thai
"{BCB26DBE-2868-7093-99B2-5E80FB77E92D}" = CCC Help Turkish
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C206015D-DAC5-407C-A54B-6D7776A0881C}" = SetIP
"{C2CA124B-9DCE-C502-98DC-8B8F71A9D597}" = CCC Help Chinese Traditional
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{c600ab3d-8b64-41df-bf36-b3d87ce0706b}" = C7200_Help
"{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution
"{C73A3AB4-99A4-45E5-B77F-09A3065E0D6A}" = Microsoft IntelliType Pro 6.1
"{C79BF5BB-5671-41C0-A028-E9A2097D1AAD}" = Microsoft Live Search Toolbar
"{C82185E8-C27B-4EF4-2007-4444BC2C2B6D}" = Microsoft Streets & Trips 2007 with GPS Locator
"{C8B44566-839A-459C-A73D-49764CE216CC}" = ArcSoft Video Downloader
"{C90A377A-68E9-463F-B963-86FBFA61B400}" = PCmover Professional
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB166F48-6219-2DFD-8800-191BE6F5923A}" = ccc-core-static
"{CCF6F57B-F6B4-4508-BF45-63AAC9DE416A}" = Quicken 2010
"{CECEB0FF-5C45-4b50-9A00-C596E36D88F4}" = C7200
"{D07A8E7E-D324-4945-BA8C-E532AD008FF3}" = Microsoft Windows OneCare Live v2.5.2900.24
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{D3A65357-1A44-7D70-62C7-B347D3EBB181}" = CCC Help Chinese Standard
"{D433ABC3-0CD8-4BB0-B6A9-84501B4B47B7}" = ArcSoft PhotoImpression 5
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{D4CD3A46-8A30-4DE2-A5B8-F68CBD6EAB61}" = Masque 2009 Card, Mahjongg and Solitaire Games
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan
"{D9D8F2CF-FE2D-4644-9762-01F916FE90A9}" = HPPhotoSmartDiscLabel_PaperLabel
"{DA0BF7AB-88EB-4675-8FA1-531EAD938821}" = SnagIt 8
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E0B71631-6AA8-C596-A485-8480E92DD745}" = Catalyst Control Center Core Implementation
"{E2486DE6-CC2E-48C0-AD20-C2C142FA1636}" = APC PowerChute Personal Edition v2.2
"{E26B83D1-C0BB-41BC-8F44-31D5354DD6AF}" = Microsoft Windows OneCare Live AntiSpyware and AntiVirus
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E664F020-95AF-CD89-25AC-BFBAFF6F984F}" = CCC Help Russian
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{E9B10AA5-E5F6-4DEF-A435-FB20704AF1E8}" = DIRECTV2PC™
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{EA244656-8567-4A75-19EC-1F5707E122A6}" = CCC Help Portuguese
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EDEA8AB7-7683-4ED2-AA19-E6C078064C0D}" = Microsoft WSE 3.0
"{EE295D30-A10C-44F6-B14C-05E0D99429E4}" = FTMVistaUpdater
"{F03EC055-F34E-4F6B-A684-8A370E11A304}" = ArcSoft Print Creations
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3B58D4E-7324-44E4-A6B3-65D2DB8D1FE9}" = Microsoft Protection Service
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F95F178B-56AD-4fab-87F8-FA81E66C7D68}" = Network
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"3D Deck" = 3D Deck 3.0
"3D Landscape" = Sierra 3D Landscape
"AC Tool" = AC Tool
"Active@ ISO Burner v 1.1" = Active@ ISO Burner v 1.1
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"AncestryView" = AncestryView
"Ask Toolbar_is1" = Ask Toolbar
"AuctionTamer Pro" = AuctionTamer Pro
"Bejeweled 2 Deluxe 1.0" = Bejeweled 2 Deluxe 1.0
"Bejeweled Deluxe 1.861" = Bejeweled Deluxe 1.861
"Belarc Advisor" = Belarc Advisor 7.2
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Carbonite Backup" = Carbonite
"Cheat Engine 5.5_is1" = Cheat Engine 5.5
"Core FTP Lite 1.3b" = Core FTP Lite 1.3b
"Coupon Printer for Windows2.0" = Coupon Printer for Windows
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"CutePDF Writer Installation" = CutePDF Writer 2.7
"DebtAnalyzer4_is1" = Debt Analyzer 4
"Electrical Wiring" = Electrical Wiring
"Emperor's Mahjong for Windows" = Emperor's Mahjong for Windows
"ENTERPRISER" = Microsoft Office Enterprise 2007
"Family Tree Maker 2010" = Family Tree Maker 2010
"FLAC" = FLAC 1.2.1b (remove only)
"Flock" = Flock 1.2
"Garden Encyclopedia" = Sierra Garden Encyclopedia
"Handmark® Monopoly® for Pocket PC" = Handmark® Monopoly® for Pocket PC
"Handmark® Scrabble® for Pocket PC" = Handmark® Scrabble® for Pocket PC
"HijackThis" = HijackThis 2.0.2
"Home Improvement Encyclopedia" = Home Improvement Encyclopedia
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Remote Solution" = HP Remote Solution
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"HPOCR" = OCR Software by I.R.I.S. 10.0
"Ilium Software eWallet_is1" = eWallet 5.0.2 Professional Edition (Windows Mobile)
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{479F8C12-576B-4A58-AB78-4B70F7012AA8}" = DIRECTV2PC Playback Advisor
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{E9B10AA5-E5F6-4DEF-A435-FB20704AF1E8}" = DIRECTV2PC™
"Jewel Quest 2_is1" = Jewel Quest 2
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Magic FLAC to MP3 Converter_is1" = Magic FLAC to MP3 Converter 3.12
"Money2008b" = Microsoft Money Plus
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MP Navigator EX 2.0" = Canon MP Navigator EX 2.0
"MyWebSearch bar Uninstall" = My Web Search (Smiley Central)
"NeatWorks" = NeatWorks
"NIS" = Norton Internet Security
"Ogg Codecs" = Ogg Codecs 0.81.15562
"Photo LandDesigner" = Sierra Photo LandDesigner
"Photodex Presenter" = Photodex Presenter
"Picasa 3" = Picasa 3
"PictureItSuite_v12" = Microsoft Digital Image Suite Anniversary Edition
"Pretty Good Solitaire 2k" = Pretty Good Solitaire 2k
"PrimoPDF3.2" = PrimoPDF
"ProShow Gold" = ProShow Gold
"pywin32-py2.6" = Python 2.6 pywin32-212
"RealPlayer 6.0" = RealPlayer
"Samsung CLP-310 Series" = Samsung CLP-310 Series
"Samsung Universal Print Driver" = Samsung Universal Print Driver
"Sierra Home Architect" = Sierra Home Architect
"Sierra Photo Garden Designer" = Sierra Photo Garden Designer
"Sierra Photo Home Interiors" = Sierra Photo Home Interiors
"Sierra Utilities" = Sierra Utilities
"ThumbsPlus7" = ThumbsPlus version 7.0
"uTorrent" = µTorrent
"VBirthday 3.2 GOLD" = VBirthday 3.2 GOLD
"VLC media player" = VLC media player 1.0.5
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Yahoo! Companion" = Yahoo! Toolbar
"Zynga Toolbar" = Zynga Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Smilebox" = Smilebox

========== Last 10 Event Log Errors ==========

[ ActivIdentity Events ]
Error - 6/7/2010 11:25:33 AM | Computer Name = Andrews-HomePC | Source = ActivClient | ID = 769
Description = No exchange account

Error - 6/7/2010 11:30:19 AM | Computer Name = Andrews-HomePC | Source = ActivClient | ID = 769
Description = No exchange account


========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Hello andrews89,

Please download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy & Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

After that

  • Close all windows and open OTL again.
  • Click Run Scan and let the program run uninterrupted
  • It will produce a log for you. Post the log here.
So when you return please post
  • MBAM log
  • OTL log
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4178

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

6/8/2010 6:46:06 AM
mbam-log-2010-06-08 (06-46-06).txt

Scan type: Quick scan
Objects scanned: 150573
Time elapsed: 3 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 143
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 41

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\Users\S & L Andrews\Local Settings\Application Data\Desktop Cleanup Wizard\dskclean.dll (Trojan.Agent) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\funwebproducts.datacontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.datacontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0f8ecf4f-3646-4c3a-8881-8e138ffcaf70} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b813095c-81c0-4e40-aa14-67520372b987} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c9d7be3e-141a-4c85-8cd6-32461f3df2c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{cff4ce82-3aa2-451f-9b77-7165605fb835} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8e6f1832-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a9571378-68a1-443d-b082-284f960c6d17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{53ced2d0-5e9a-4761-9005-648404e6f7e5} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{938aa51a-996c-4884-98ce-80dd16a5c9da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d9fffb27-d62a-4d64-8cec-1ff006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AppDataLow\HavingFunOnline (Adware.BHO.FL) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\desktop cleanup wizard (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files (x86)\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Mozilla Firefox\repairv35pro.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Mozilla Firefox\plugins\NPMyWebS.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3IMSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\MyWebSearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\S & L Andrews\Local Settings\Application Data\Desktop Cleanup Wizard\dskclean.dll (Trojan.Agent) -> Delete on reboot.




OTL logfile created on: 6/8/2010 7:01:53 AM - Run 2
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\S & L Andrews\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 62.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.41 Gb Total Space | 334.75 Gb Free Space | 57.58% Space Free | Partition Type: NTFS
Drive D: | 14.76 Gb Total Space | 2.09 Gb Free Space | 14.15% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANDREWS-HOMEPC
Current User Name: S & L Andrews
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/06/08 01:11:43 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\S & L Andrews\Desktop\OTL.exe
PRC - [2010/05/19 01:55:34 | 003,364,208 | —- | M] (MediaMall Technologies, Inc.) – C:\Program Files (x86)\MediaMall\MediaMallServer.exe
PRC - [2010/05/19 01:54:24 | 000,053,248 | —- | M] (MediaMall Technologies, Inc.) – C:\Program Files (x86)\MediaMall\PlayOn.exe
PRC - [2010/05/12 20:27:33 | 000,186,760 | —- | M] () – C:\Program Files (x86)\Photodex\ProShowGold\scsiaccess.exe
PRC - [2010/05/12 20:15:58 | 000,372,103 | —- | M] () – C:\Users\S & L Andrews\AppData\Roaming\win2dkdes\win2djws.exe
PRC - [2010/04/16 20:04:42 | 000,077,672 | —- | M] (Intuit Inc.) – C:\Program Files (x86)\Quicken\bagent.exe
PRC - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/04/06 14:28:50 | 000,300,352 | —- | M] (Smilebox, Inc.) – C:\Users\S & L Andrews\AppData\Roaming\Smilebox\SmileboxTray.exe
PRC - [2010/03/24 13:58:22 | 000,309,760 | —- | M] (ArcSoft Inc.) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
PRC - [2010/03/18 11:19:26 | 000,207,360 | —- | M] (ArcSoft Inc.) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/03/18 11:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2010/02/25 18:21:50 | 000,126,392 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe
PRC - [2010/02/12 19:07:32 | 005,933,912 | —- | M] (Logitech Inc.) – C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe
PRC - [2009/11/02 13:17:08 | 000,604,888 | —- | M] (TiVo Inc.) – C:\Program Files (x86)\TiVo\Desktop\TiVoTransfer.exe
PRC - [2009/11/02 13:17:06 | 002,195,160 | —- | M] (TiVo Inc.) – C:\Program Files (x86)\TiVo\Desktop\TiVoServer.exe
PRC - [2009/11/02 13:17:04 | 000,430,808 | —- | M] (TiVo Inc.) – C:\Program Files (x86)\TiVo\Desktop\TiVoNotify.exe
PRC - [2009/10/20 14:50:34 | 000,128,296 | —- | M] (CyberLink Corp.) – c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
PRC - [2009/10/15 11:06:52 | 000,053,064 | —- | M] (TechSmith Corporation) – C:\Program Files (x86)\TechSmith\Snagit 9\TscHelp.exe
PRC - [2009/10/15 11:06:50 | 000,066,888 | —- | M] (TechSmith Corporation) – C:\Program Files (x86)\TechSmith\Snagit 9\SnagPriv.exe
PRC - [2009/10/15 11:06:46 | 007,168,328 | —- | M] (TechSmith Corporation) – C:\Program Files (x86)\TechSmith\Snagit 9\SnagitEditor.exe
PRC - [2009/10/15 11:06:46 | 006,287,176 | —- | M] (TechSmith Corporation) – C:\Program Files (x86)\TechSmith\Snagit 9\Snagit32.exe
PRC - [2009/10/14 14:36:56 | 002,793,304 | —- | M] () – C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009/10/14 14:34:18 | 000,560,472 | —- | M] () – C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2009/10/12 17:58:12 | 000,614,400 | —- | M] () – C:\Windows\Samsung\PanelMgr\SSMMgr.exe
PRC - [2009/10/07 02:47:22 | 000,125,464 | —- | M] (Logitech Inc.) – C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
PRC - [2009/09/17 18:40:44 | 000,075,048 | —- | M] () – C:\Program Files (x86)\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe
PRC - [2009/08/28 13:53:00 | 000,210,216 | —- | M] (CyberLink) – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/07/26 00:19:01 | 000,039,408 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/05/26 02:36:13 | 000,656,896 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
PRC - [2009/04/29 17:19:52 | 001,959,056 | R— | M] (Carbonite, Inc. (www.carbonite.com)) – C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteService.exe
PRC - [2009/04/29 17:19:50 | 000,669,840 | R— | M] (Carbonite, Inc.) – C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
PRC - [2009/01/06 23:25:02 | 000,689,464 | —- | M] (American Power Conversion Corporation) – C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe
PRC - [2009/01/06 23:24:54 | 000,656,696 | —- | M] (American Power Conversion Corporation) – C:\Program Files (x86)\APC\APC PowerChute Personal Edition\apcsystray.exe
PRC - [2008/12/04 13:00:26 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/12/04 13:00:20 | 000,186,904 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/11/20 11:47:28 | 000,062,768 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
PRC - [2008/09/30 18:59:26 | 000,192,512 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe
PRC - [2007/06/05 13:20:32 | 000,177,704 | —- | M] () – C:\Windows\SysWOW64\PSIService.exe


========== Modules (SafeList) ==========

MOD - [2010/06/08 01:11:43 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\S & L Andrews\Desktop\OTL.exe
MOD - [2009/07/13 19:15:07 | 000,486,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\comdlg32.dll
MOD - [2009/07/13 19:14:10 | 000,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/13 19:03:50 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/04/22 03:00:58 | 001,255,736 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\SysNative\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV:64bit: - [2010/03/16 17:04:24 | 000,167,280 | —- | M] (Samsung Electronics CO., LTD.) [On_Demand | Stopped] – C:\Windows\SysNative\SUPDSvc.exe – (Samsung UPD Service)
SRV:64bit: - [2010/03/10 23:29:46 | 000,202,752 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2009/10/07 02:47:10 | 000,191,000 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcS64)
SRV:64bit: - [2009/08/18 12:48:02 | 002,291,568 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE – (wlidsvc)
SRV:64bit: - [2009/07/13 19:41:59 | 000,229,888 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wwansvc.dll – (WwanSvc)
SRV:64bit: - [2009/07/13 19:41:56 | 000,202,240 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wbiosrvc.dll – (WbioSrvc)
SRV:64bit: - [2009/07/13 19:41:56 | 000,163,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\umpo.dll – (Power)
SRV:64bit: - [2009/07/13 19:41:55 | 000,044,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\themeservice.dll – (Themes)
SRV:64bit: - [2009/07/13 19:41:54 | 000,065,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\sppuinotify.dll – (sppuinotify)
SRV:64bit: - [2009/07/13 19:41:54 | 000,029,184 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\sensrsvc.dll – (SensrSvc)
SRV:64bit: - [2009/07/13 19:41:53 | 000,327,168 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\pnrpsvc.dll – (PNRPsvc)
SRV:64bit: - [2009/07/13 19:41:53 | 000,327,168 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\pnrpsvc.dll – (p2pimsvc)
SRV:64bit: - [2009/07/13 19:41:53 | 000,187,904 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\provsvc.dll – (HomeGroupProvider)
SRV:64bit: - [2009/07/13 19:41:53 | 000,067,072 | —- | M] (Microsoft Corporation) [Unknown | Running] – C:\Windows\SysNative\RpcEpMap.dll – (RpcEptMapper)
SRV:64bit: - [2009/07/13 19:41:53 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\pnrpauto.dll – (PNRPAutoReg)
SRV:64bit: - [2009/07/13 19:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/13 19:41:18 | 000,231,936 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\ListSvc.dll – (HomeGroupListener)
SRV:64bit: - [2009/07/13 19:40:54 | 001,127,936 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\FntCache.dll – (FontCache)
SRV:64bit: - [2009/07/13 19:40:28 | 000,314,368 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\dhcpcore.dll – (Dhcp)
SRV:64bit: - [2009/07/13 19:40:28 | 000,291,328 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\defragsvc.dll – (defragsvc)
SRV:64bit: - [2009/07/13 19:40:13 | 000,083,968 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\bthserv.dll – (bthserv)
SRV:64bit: - [2009/07/13 19:40:10 | 000,100,864 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\SysNative\bdesvc.dll – (BDESVC)
SRV:64bit: - [2009/07/13 19:40:05 | 000,114,688 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\AxInstSv.dll – (AxInstSV)
SRV:64bit: - [2009/07/13 19:40:01 | 000,032,256 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appidsvc.dll – (AppIDSvc)
SRV:64bit: - [2009/07/13 19:39:51 | 001,503,744 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wbengine.exe – (wbengine)
SRV:64bit: - [2009/07/13 19:39:28 | 003,524,608 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\SysNative\sppsvc.exe – (sppsvc)
SRV:64bit: - [2009/07/13 19:39:11 | 000,689,152 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\FXSSVC.exe – (Fax)
SRV:64bit: - [2009/06/03 16:38:36 | 000,277,032 | —- | M] (ActivIdentity) [Auto | Running] – C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe – (ac.sharedstore)
SRV - [2010/05/19 01:55:34 | 003,364,208 | —- | M] (MediaMall Technologies, Inc.) [Auto | Running] – C:\Program Files (x86)\MediaMall\MediaMallServer.exe – (MediaMall Server)
SRV - [2010/05/12 20:27:33 | 000,186,760 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Photodex\ProShowGold\scsiaccess.exe – (ScsiAccess)
SRV - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/03/18 11:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2010/02/25 18:21:50 | 000,126,392 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe – (NIS)
SRV - [2009/12/27 19:20:44 | 000,000,000 | —D | M] [Unknown | Stopped] – C:\Windows\SysWOW64\Msdtc – (MSDTC)
SRV - [2009/11/02 13:17:00 | 001,098,968 | —- | M] (TiVo Inc.) [Disabled | Stopped] – C:\Program Files (x86)\TiVo\Desktop\TiVoBeacon.exe – (TivoBeacon2)
SRV - [2009/10/01 10:50:54 | 000,120,640 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe – (LMIMaint)
SRV - [2009/09/17 18:40:44 | 000,075,048 | —- | M] () [Auto | Running] – C:\Program Files (x86)\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe – (CLDTVHNService)
SRV - [2009/07/13 21:20:14 | 000,000,000 | —D | M] [On_Demand | Running] – C:\Windows\Vss – (VSS)
SRV - [2009/07/13 19:16:12 | 000,165,376 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysWOW64\provsvc.dll – (HomeGroupProvider)
SRV - [2009/07/13 19:15:11 | 000,253,440 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\dhcpcore.dll – (Dhcp)
SRV - [2009/07/13 14:30:11 | 000,061,056 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysWOW64\wbem\vds.mof – (vds)
SRV - [2009/06/10 14:39:58 | 000,089,920 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64)
SRV - [2009/04/29 17:19:52 | 001,959,056 | R— | M] (Carbonite, Inc. (www.carbonite.com)) [Auto | Running] – C:\Program Files (x86)\Carbonite\Carbonite Backup\carboniteservice.exe – (CarboniteService)
SRV - [2009/01/06 23:25:02 | 000,689,464 | —- | M] (American Power Conversion Corporation) [Auto | Running] – C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe – (APC UPS Service)
SRV - [2008/12/04 13:00:26 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2008/10/25 11:44:08 | 000,065,888 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe – (Microsoft Office Groove Audit Service)
SRV - [2008/09/30 18:59:26 | 000,192,512 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe – (HPBtnSrv)
SRV - [2008/07/24 18:46:08 | 000,057,920 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe – (LogMeIn)
SRV - [2007/09/12 19:27:24 | 002,999,664 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_2.EXE – (LiveUpdate)
SRV - [2007/06/05 13:20:32 | 000,177,704 | —- | M] () [Auto | Start_Pending] – C:\Windows\SysWOW64\PSIService.exe – (ProtexisLicensing)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/05/05 22:01:59 | 000,451,120 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symtdiv.sys – (SYMTDIv)
DRV:64bit: - [2010/04/28 23:03:51 | 000,150,064 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NISx64\1107000.00C\ironx64.sys – (SymIRON)
DRV:64bit: - [2010/04/21 21:02:20 | 000,221,232 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symefa64.sys – (SymEFA)
DRV:64bit: - [2010/04/21 20:29:51 | 000,505,392 | —- | M] (Symantec Corporation) [File_System | System | Running] – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtsp64.sys – (SRTSP)
DRV:64bit: - [2010/04/21 20:29:51 | 000,032,304 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtspx64.sys – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:64bit: - [2010/03/10 23:39:52 | 006,403,072 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2010/03/10 23:39:52 | 006,403,072 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atipmdag.sys – (amdkmdag)
DRV:64bit: - [2010/03/10 22:34:06 | 000,188,928 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2010/02/25 18:22:52 | 000,615,040 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\NISx64\1107000.00C\cchpx64.sys – (ccHP)
DRV:64bit: - [2010/02/24 14:12:34 | 000,028,528 | —- | M] (MediaMall Technologies, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\povrtdev.sys – (msvad_simple)
DRV:64bit: - [2009/12/27 20:51:23 | 000,173,104 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS – (SymEvent)
DRV:64bit: - [2009/12/11 04:29:27 | 000,153,160 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\ksecpkg.sys – (KSecPkg)
DRV:64bit: - [2009/11/05 16:06:13 | 000,433,200 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symds64.sys – (SymDS)
DRV:64bit: - [2009/10/16 02:33:06 | 000,050,176 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2009/10/07 09:49:28 | 006,379,288 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\lvuvc64.sys – (LVUVC64) Logitech Webcam 905(UVC)
DRV:64bit: - [2009/10/07 09:47:46 | 000,327,704 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\lvrs64.sys – (LVRS64)
DRV:64bit: - [2009/10/07 02:45:50 | 000,030,232 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\LVPr2M64.sys – (LVPr2Mon)
DRV:64bit: - [2009/10/07 02:45:50 | 000,030,232 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\LVPr2M64.sys – (LVPr2M64)
DRV:64bit: - [2009/09/26 00:20:38 | 000,223,448 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\fvevol.sys – (fvevol)
DRV:64bit: - [2009/07/18 06:18:48 | 000,109,480 | —- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\jraid.sys – (JRAID)
DRV:64bit: - [2009/07/13 19:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2009/07/13 19:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:48:04 | 000,014,416 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\hwpolicy.sys – (hwpolicy)
DRV:64bit: - [2009/07/13 19:47:49 | 000,055,376 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fsdepends.sys – (FsDepends)
DRV:64bit: - [2009/07/13 19:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 19:45:56 | 000,022,096 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\wimmount.sys – (WIMMount)
DRV:64bit: - [2009/07/13 19:45:55 | 000,217,680 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\vhdmp.sys – (vhdmp)
DRV:64bit: - [2009/07/13 19:45:55 | 000,036,432 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\vdrvroot.sys – (vdrvroot)
DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 19:45:46 | 000,214,096 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\rdyboost.sys – (rdyboost)
DRV:64bit: - [2009/07/13 19:45:45 | 000,050,768 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\pcw.sys – (pcw)
DRV:64bit: - [2009/07/13 19:43:14 | 000,460,504 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\cng.sys – (CNG)
DRV:64bit: - [2009/07/13 18:17:46 | 000,024,064 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rdpbus.sys – (rdpbus)
DRV:64bit: - [2009/07/13 18:16:35 | 000,008,192 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\RDPREFMP.sys – (RDPREFMP)
DRV:64bit: - [2009/07/13 18:10:24 | 000,060,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\agilevpn.sys – (RasAgileVpn) WAN Miniport (IKEv2)
DRV:64bit: - [2009/07/13 18:09:26 | 000,012,800 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\wfplwf.sys – (WfpLwf)
DRV:64bit: - [2009/07/13 18:08:13 | 000,035,328 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ndiscap.sys – (NdisCap)
DRV:64bit: - [2009/07/13 18:07:21 | 000,024,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\vwifibus.sys – (vwifibus)
DRV:64bit: - [2009/07/13 18:07:13 | 000,227,840 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\1394ohci.sys – (1394ohci)
DRV:64bit: - [2009/07/13 18:07:00 | 000,350,208 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HdAudio.sys – (HdAudAddService)
DRV:64bit: - [2009/07/13 18:06:52 | 000,009,728 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\umpass.sys – (UmPass)
DRV:64bit: - [2009/07/13 18:06:32 | 000,109,568 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV:64bit: - [2009/07/13 18:06:28 | 000,040,448 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\winusb.sys – (WinUsb)
DRV:64bit: - [2009/07/13 18:06:24 | 000,008,192 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mshidkmdf.sys – (mshidkmdf)
DRV:64bit: - [2009/07/13 18:05:37 | 000,112,128 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WUDFPf.sys – (WudfPf)
DRV:64bit: - [2009/07/13 18:02:08 | 000,015,360 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\MTConfig.sys – (MTConfig)
DRV:64bit: - [2009/07/13 18:00:34 | 000,038,912 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CompositeBus.sys – (CompositeBus)
DRV:64bit: - [2009/07/13 18:00:13 | 000,006,656 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\beep.sys – (Beep)
DRV:64bit: - [2009/07/13 17:52:39 | 000,061,440 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\appid.sys – (AppID)
DRV:64bit: - [2009/07/13 17:50:17 | 000,029,696 | —- | M] (Microsoft Corporation) [Kernel | Unknown | Running] – C:\Windows\SysNative\drivers\scfilter.sys – (scfilter)
DRV:64bit: - [2009/07/13 17:37:18 | 000,040,448 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\discache.sys – (discache)
DRV:64bit: - [2009/07/13 17:31:06 | 000,026,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hidbatt.sys – (HidBatt)
DRV:64bit: - [2009/07/13 17:31:03 | 000,017,664 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\CmBatt.sys – (CmBatt)
DRV:64bit: - [2009/07/13 17:27:17 | 000,012,288 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\acpipmi.sys – (AcpiPmi)
DRV:64bit: - [2009/07/13 17:19:25 | 000,060,928 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdppm.sys – (AmdPPM)
DRV:64bit: - [2009/06/29 10:00:00 | 000,116,752 | —- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtiHdmi.sys – (AtiHdmiService)
DRV:64bit: - [2009/06/13 02:19:58 | 000,287,960 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\e1y62x64.sys – (e1yexpress) Intel®
DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/06/05 02:54:36 | 000,408,600 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2008/07/24 18:46:08 | 000,072,216 | —- | M] (LogMeIn, Inc.) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\LMIRfsDriver.sys – (LMIRfsDriver)
DRV:64bit: - [2008/07/24 18:45:20 | 000,011,552 | —- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\lmimirr.sys – (lmimirr)
DRV:64bit: - [2007/08/13 20:48:52 | 000,011,576 | —- | M] (Samsung Electronics) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\SSPORT.SYS – (SSPORT)
DRV - [2010/05/28 13:33:18 | 000,463,408 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100528.003\IDSviA64.sys – (IDSVia64)
DRV - [2010/05/26 21:49:00 | 000,475,696 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys – (eeCtrl)
DRV - [2010/05/26 21:49:00 | 000,132,656 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2010/05/10 17:47:43 | 001,773,104 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100607.034\EX64.SYS – (NAVEX15)
DRV - [2010/05/10 17:47:43 | 000,117,808 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100607.034\ENG64.SYS – (NAVENG)
DRV - [2010/04/29 11:44:04 | 000,678,448 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100429.001\BHDrvx64.sys – (BHDrvx64)
DRV - [2009/09/17 18:40:52 | 000,082,416 | —- | M] (Cyberlink Corp.) [Kernel | Auto | Running] – C:\Program Files (x86)\DirecTV\DirecTV\Kernel\DMP\ntk_dtv_64.sys – (ntk_dtv)
DRV - [2009/07/13 19:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
DRV - [2009/07/13 19:16:19 | 000,016,896 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysWOW64\winusb.dll – (WinUsb)
DRV - [2009/07/13 19:16:02 | 000,014,336 | —- | M] (Microsoft Corporation) [File_System | System | Running] – C:\Windows\SysWOW64\netbios.dll – (NetBIOS)
DRV - [2009/06/10 15:28:14 | 000,001,088 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysWOW64\wbem\mpsdrv.mof – (mpsdrv)
DRV - [2009/06/10 15:15:18 | 000,003,066 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysWOW64\wbem\tcpip.mof – (Tcpip)
DRV - [2008/07/24 18:46:10 | 000,015,928 | —- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys – (LMIInfo)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - Reg Error: Key error. File not found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us10.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.iwon.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta, = http://astalavista.box.sk/cgi-bin/robot?srch=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta, = +
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,# = %23
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,& = %26
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,? = %3F
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,+ = %2B
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,= = %3D
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs, = http://www.thebugs.ws/search.php?id=644&q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs, = +
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,# = %23
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,& = %26
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,? = %3F
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,+ = %2B
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,= = %3D
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy, = http://anonym.to/?http://%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy, = +
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,# = %23
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,& = %26
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,? = %3F
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,+ = %2B
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,= = %3D
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "http://bing.zugo.com/?cfg=2-76-0-10JY1"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:0.7.3
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.4.7amo
FF - prefs.js..extensions.enabledItems: [removed]:1.0.13
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.0.5
FF - prefs.js..extensions.enabledItems: {75CEEE46-9B64-46f8-94BF-54012DE155F0}:0.4
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:[removed]
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:3.6.3
FF - prefs.js..extensions.enabledItems: {8FFE139B-90A7-4460-A972-9D2738997F6D}:1.6.3
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.9
FF - prefs.js..extensions.enabledItems: {b9bfaf1c-a63f-47cd-8b9a-29526ced9060}:0.6
FF - prefs.js..extensions.enabledItems: {cd617375-6743-4ee8-bac4-fbf10f35729e}:2.7.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.8
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:2.0.0.11
FF - prefs.js..keyword.URL: "http://bing.zugo.com/s/?src=FF-Address&site=Bing&cfg=2-76-0-10JY1&q="


FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files (x86)\Real\RealPlayer\browserrecord [2009/12/27 19:01:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\ [2010/06/01 02:19:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/28 23:01:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\ [2010/01/26 16:42:56 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: C:\Program Files (x86)\ArcSoft\Video Downloader\Plugin_FireFox [2010/03/14 00:48:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\FireFox Extension [2010/03/14 00:51:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Flock\Extensions\\Components: C:\Program Files (x86)\Flock\flock\components [2010/04/03 08:13:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Flock\Extensions\\Plugins: C:\Program Files (x86)\Flock\flock\plugins [2010/06/01 00:34:39 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/04/04 16:50:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/06/01 00:40:13 | 000,000,000 | —D | M]

[2009/12/27 19:15:27 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Extensions
[2009/12/27 19:15:30 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (Coupon Manager) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{0C7E3F01-99E9-4095-9BDC-F84724960B57}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe6a}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (Print/Print Preview) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{19EB90DC-A456-458b-8AAC-616D91AAFCE1}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (Image Zoom) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{21350f60-90a5-11da-a72b-0800200c9a66}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{2A10B180-05EF-11D9-8C50-444553540001}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (FEBE) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (Gmail Manager) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (Firefox Companion for eBay) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] (Searchbar Autosizer) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{655397ca-4766-496b-b7a8-3a5b176ee4c2}
[2009/12/27 19:15:29 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{909409b9-2e3b-4682-a5d1-71ca80a76456}
[2009/12/27 19:15:29 | 000,000,000 | —D | M] (Update Notifier) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
[2009/12/27 19:15:29 | 000,000,000 | —D | M] (TryAgain) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{992791ee-61dc-7b98-a8fd-dc49b7deeee9}
[2009/12/27 19:15:29 | 000,000,000 | —D | M] (More Tools Menu) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{9a7a67d3-3048-47fb-acde-d0f7ae51f86a}
[2009/12/27 19:15:29 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{a937b0b2-4a38-401a-a6a4-4a0b436fcfa6}
[2009/12/27 19:15:29 | 000,000,000 | —D | M] (Answers) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}
[2009/12/27 19:15:29 | 000,000,000 | —D | M] (Download Statusbar) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2009/12/27 19:15:30 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}-trash
[2009/12/27 19:15:30 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2009/12/27 19:15:30 | 000,000,000 | —D | M] () – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{DCBD1271-D228-4082-9FBC-36D9B7660B03}
[2009/12/27 19:15:30 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/07/30 20:07:02 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}-trash
[2009/12/27 19:15:30 | 000,000,000 | —D | M] (My Points Toolbar) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\{eeb97566-866d-4551-b292-7de53fb9fe24}
[2009/12/27 19:15:28 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\[removed]
[2009/12/27 19:15:28 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\[removed]
[2009/12/27 19:15:28 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\staged-xpis
[2009/12/27 19:15:28 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\[removed]
[2009/12/27 19:15:28 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\69ky2rlu.default\extensions\staged-xpis\[removed]
[2010/06/07 14:25:59 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions
[2010/04/10 08:23:33 | 000,000,000 | —D | M] (Screengrab) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/06/04 09:51:59 | 000,000,000 | —D | M] (Flagfox) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2010/05/03 00:08:49 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/04 09:51:59 | 000,000,000 | —D | M] (MeasureIt) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{75CEEE46-9B64-46f8-94BF-54012DE155F0}
[2010/05/20 16:48:02 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/05/03 00:08:49 | 000,000,000 | —D | M] (ReloadEvery) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2010/01/16 13:16:42 | 000,000,000 | —D | M] (QuickPageZoom) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{8FFE139B-90A7-4460-A972-9D2738997F6D}
[2010/06/04 09:51:59 | 000,000,000 | —D | M] (FireFTP) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2010/04/10 08:26:16 | 000,000,000 | —D | M] () – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}
[2010/04/10 08:23:32 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{cd617375-6743-4ee8-bac4-fbf10f35729e}
[2010/05/03 00:08:49 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/05/03 00:08:50 | 000,000,000 | —D | M] (Download Statusbar) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/06/04 09:51:59 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/12/27 19:15:35 | 000,000,000 | —D | M] (No name found) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2010/06/04 09:51:59 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\[removed]
[2010/04/10 08:23:33 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\SkipScreen@SkipScreen
[2009/12/27 19:15:31 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\[removed]
[2010/06/04 09:51:59 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\staged-xpis
[2009/12/27 19:15:32 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\[removed]
[2010/05/03 01:27:53 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/04/18 13:46:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2005/08/29 13:32:12 | 000,106,496 | —- | M] (NetRatings, Inc.) – C:\Program Files (x86)\Mozilla Firefox\components\nmgkff10.dll
[2010/03/13 16:01:06 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll
[2009/11/19 15:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/01/04 15:41:16 | 000,114,688 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\plugins\npmozax.dll
[2009/11/19 15:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2006/10/12 15:18:00 | 001,245,184 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\plugins\npRACtrl.dll
[2006/10/12 15:17:00 | 000,003,072 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\plugins\ractrlkeyhook.dll
[2006/02/13 10:07:00 | 000,245,408 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Mozilla Firefox\plugins\unicows.dll

O1 HOSTS File: ([2006/09/18 15:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (IEPlugin Class) - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\Program Files (x86)\ArcSoft\Video Downloader\ArcURLRecord.dll (ArcSoft, Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (ToolbarBHO Class) - {9519AF7E-638D-4933-BAD6-D33D23C79FE5} - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll (ArcSoft Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (RAW Thumbnail Viewer) - {F301665A-12F8-4331-804A-5BCBD379668C} - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll (ArcSoft Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [accrdsub] C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe (ActivIdentity)
O4:64bit: - HKLM..\Run: [acevents] C:\Program Files\ActivIdentity\ActivClient\acevents.exe (ActivIdentity)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [Display] C:\Program Files (x86)\APC\APC PowerChute Personal Edition\DataCollectionLauncher.exe (American Power Conversion Corporation)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Remote Solution] C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe ()
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.exe (Microsoft)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [Microsoft Default Manager] c:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.)
O4 - HKLM..\Run: [NvCplDaemon] File not found
O4 - HKLM..\Run: [NvMediaCenter] File not found
O4 - HKLM..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\ssmmgr.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files (x86)\Windows Defender\MSASCui.exe File not found
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [PlayOn] C:\Program Files (x86)\MediaMall\PlayOn.exe (MediaMall Technologies, Inc.)
O4 - HKCU..\Run: [QuickenScheduledUpdates] C:\Program Files (x86)\Quicken\bagent.exe (Intuit Inc.)
O4 - HKCU..\Run: [SmileboxTray] C:\Users\S & L Andrews\AppData\Roaming\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe ()
O4 - HKCU..\Run: [TivoNotify] C:\Program Files (x86)\TiVo\Desktop\TiVoNotify.exe (TiVo Inc.)
O4 - HKCU..\Run: [TivoServer] C:\Program Files (x86)\TiVo\Desktop\TiVoServer.exe (TiVo Inc.)
O4 - HKCU..\Run: [TivoTransfer] C:\Program Files (x86)\TiVo\Desktop\TiVoTransfer.exe (TiVo Inc.)
O4 - HKCU..\Run: [TranscodingService] C:\Program Files (x86)\TiVo\Desktop\Plus\\TranscodingService.exe ()
O4 - HKCU..\Run: [win2dkdes] C:\Users\S & L Andrews\AppData\Roaming\win2dkdes\win2djws.exe ()
O4:64bit: - HKLM..\RunOnce: [PCDrProfiler] C:\Program Files\PC-Doctor for Windows\RunProfiler.exe (PC-Doctor, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll (Google Inc.)
O8:64bit: - Extra context menu item: Read EXIF - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll (Google Inc.)
O8 - Extra context menu item: Read EXIF - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15:64bit: - ..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Reg Error: Key error.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Reg Error: Key error.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (Reg Error: Key error.)
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} http://webiq005.webiqonline.com/WebIQ/Data…6-6D5536C585C9} (Reg Error: Key error.)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} http://www.infospace.com/mypoints.main/tba…pointsSetup.exe (Reg Error: Key error.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} http://h20264.www2.hp.com/ediags/dd/instal…osticsVista.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\x-excid {9D6CC632-1337-4a33-9214-2DA092E776F4} - Reg Error: Key error. File not found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\x-excid {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\Windows\Downloaded Program Files\mimectl.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O22 - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - Reg Error: Key error. File not found
O24 - Desktop Components:0 () - http://www.ty.com/wallpaper/Oct2006/OCT06_wallpaper_800.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Users\S & L Andrews\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\S & L Andrews\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/06/08 06:50:15 | 000,000,000 | —D | C] – C:\ProgramData\Gosu
[2010/06/08 06:41:01 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\AppData\Roaming\Malwarebytes
[2010/06/08 06:40:54 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/06/08 06:40:53 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/06/08 06:40:53 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/06/08 06:40:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/06/08 01:13:10 | 000,000,000 | —D | C] – C:\_OTL
[2010/06/08 01:11:40 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Users\S & L Andrews\Desktop\OTL.exe
[2010/06/07 14:23:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/06/07 09:22:05 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ActivIdentity
[2010/06/07 09:22:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\ActivIdentity
[2010/06/07 09:22:04 | 000,000,000 | —D | C] – C:\Program Files\ActivIdentity
[2010/06/06 16:06:15 | 000,092,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WING.DLL
[2010/06/06 16:06:15 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WING32.DLL
[2010/06/06 15:41:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\SamsungPrinterLiveUpdate
[2010/06/06 14:53:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Samsung Network Printer Utilities
[2010/06/06 14:33:11 | 000,701,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml2.dll
[2010/06/06 14:33:11 | 000,049,152 | —- | C] (Samsung Electronics) – C:\Windows\SysWow64\ssusbpn.dll
[2010/06/06 14:33:11 | 000,047,104 | —- | C] (Samsung Electronics) – C:\Windows\SysNative\ssusbp64.dll
[2010/06/06 14:33:11 | 000,038,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml2r.dll
[2010/06/06 14:33:11 | 000,021,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml2a.dll
[2010/06/06 14:33:11 | 000,000,000 | —D | C] – C:\Windows\Samsung
[2010/06/06 14:32:59 | 000,074,240 | —- | C] (Samsung Electronics) – C:\Windows\SysNative\ssdevm64.dll
[2010/06/06 14:32:58 | 000,081,920 | —- | C] (Samsung Electronics) – C:\Windows\SysWow64\ssdevm.dll
[2010/06/06 14:32:29 | 000,151,552 | —- | C] (SS) – C:\Windows\SysNative\cl31cci.exe
[2010/06/06 14:32:29 | 000,089,600 | —- | C] (SS) – C:\Windows\SysNative\cl31cci.dll
[2010/06/04 12:40:27 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\AppData\Roaming\Insight Software
[2010/06/04 12:40:27 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\AppData\Local\Insight Software
[2010/06/04 12:40:26 | 000,000,000 | —D | C] – C:\ProgramData\Insight Software
[2010/06/04 12:40:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Debt Analyzer 4
[2010/06/01 00:36:21 | 000,000,000 | -H-D | C] – C:\Windows\AxInstSV
[2010/06/01 00:09:45 | 000,000,000 | —D | C] – C:\ProgramData\Yahoo! Companion
[2010/06/01 00:09:45 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\AppData\Roaming\Yahoo!
[2010/06/01 00:09:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Yahoo!
[2010/06/01 00:03:29 | 001,403,904 | —- | C] (Hewlett-Packard Co.) – C:\Windows\SysNative\hpotiop5.dll
[2010/06/01 00:03:29 | 000,938,496 | —- | C] (Hewlett-Packard) – C:\Windows\SysNative\hpowiax5.dll
[2010/06/01 00:03:29 | 000,642,360 | —- | C] (Hewlett-Packard) – C:\Windows\SysNative\hpzids40.dll
[2010/06/01 00:03:29 | 000,540,672 | —- | C] (Hewlett-Packard) – C:\Windows\SysNative\hppldcoi.dll
[2010/06/01 00:03:29 | 000,505,344 | —- | C] (Hewlett-Packard Co.) – C:\Windows\SysNative\hpovst12.dll
[2010/05/31 11:23:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2010/05/31 10:38:44 | 000,000,000 | —D | C] – C:\Users\Public\Documents\pyTivo
[2010/05/30 00:27:00 | 000,000,000 | R–D | C] – C:\Users\S & L Andrews\Documents\My TiVo Recordings
[2010/05/30 00:27:00 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\AppData\Local\TiVo Desktop
[2010/05/30 00:27:00 | 000,000,000 | —D | C] – C:\ProgramData\TiVo
[2010/05/30 00:27:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\TiVo
[2010/05/30 00:27:00 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\Documents\My TiVo Recordings for Portables
[2010/05/29 23:05:44 | 000,256,000 | —- | C] (SEC) – C:\Windows\SysNative\SIPDUtil.dll
[2010/05/29 23:05:44 | 000,167,280 | —- | C] (Samsung Electronics CO., LTD.) – C:\Windows\SysNative\SUPDSvc.exe
[2010/05/29 23:05:44 | 000,162,672 | —- | C] (Samsung Electronics CO., LTD.) – C:\Windows\SysNative\SUPDSvcA.dll
[2010/05/29 23:05:44 | 000,157,552 | —- | C] (SS) – C:\Windows\SysNative\spd__ci.exe
[2010/05/29 23:05:44 | 000,089,600 | —- | C] (SS) – C:\Windows\SysNative\spd__ci.dll
[2010/05/29 23:05:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Samsung
[2010/05/29 23:04:20 | 028,079,936 | —- | C] (Samsung ) – C:\Users\S & L Andrews\Desktop\SamsungUniversalPrintDriver.exe
[2010/05/29 12:34:44 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\AppData\Local\Desktop Cleanup Wizard
[2010/05/23 11:47:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2010/05/19 21:06:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Conduit
[2010/05/19 21:06:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Zynga
[2010/05/19 20:41:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\TV-Websites
[2010/05/19 20:41:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\MediaMall
[2010/05/19 20:41:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ffdshowEx
[2010/05/19 20:40:52 | 000,000,000 | —D | C] – C:\ProgramData\MediaMall
[2010/05/18 19:20:31 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010_psdata
[2010/05/12 20:15:59 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\AppData\Roaming\win2dkdes
[2010/05/10 18:19:13 | 000,000,000 | —D | C] – C:\Users\S & L Andrews\Documents\Snagit Stamps
[1 C:\Users\S & L Andrews\*.tmp files -> C:\Users\S & L Andrews\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/08 07:03:55 | 010,223,616 | -HS- | M] () – C:\Users\S & L Andrews\NTUSER.DAT
[2010/06/08 06:59:06 | 000,011,104 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/08 06:59:06 | 000,011,104 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/08 06:51:37 | 000,000,880 | —- | M] () – C:\Windows\tasks\Google Software Updater.job
[2010/06/08 06:49:02 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/08 06:48:48 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/08 06:48:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/08 06:48:31 | 000,000,000 | —- | M] () – C:\Windows\SysNative\drivers\lvuvc.hs
[2010/06/08 06:48:21 | 529,915,903 | -HS- | M] () – C:\hiberfil.sys
[2010/06/08 06:47:23 | 006,291,456 | -H– | M] () – C:\Users\S & L Andrews\AppData\Local\IconCache.db
[2010/06/08 06:40:56 | 000,001,015 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/08 06:37:09 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/08 01:11:43 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\S & L Andrews\Desktop\OTL.exe
[2010/06/07 18:03:02 | 001,159,900 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\Cat.DB
[2010/06/07 14:36:12 | 000,003,011 | —- | M] () – C:\Users\S & L Andrews\Desktop\HiJackThis.lnk
[2010/06/07 09:23:55 | 000,002,146 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ActivClient Agent.lnk
[2010/06/07 09:16:24 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/07 09:16:24 | 000,615,122 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/07 09:16:24 | 000,103,496 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/06/06 16:01:17 | 028,079,936 | —- | M] (Samsung ) – C:\Users\S & L Andrews\Desktop\SamsungUniversalPrintDriver.exe
[2010/06/01 00:22:56 | 000,015,389 | —- | M] () – C:\Users\S & L Andrews\Desktop\Trees for wet sites.docx
[2010/06/01 00:22:20 | 000,014,131 | —- | M] () – C:\Users\S & L Andrews\Desktop\TREES WHICH THRIVE IN VERY WET SOIL.docx
[2010/06/01 00:19:01 | 013,496,320 | —- | M] () – C:\Users\S & L Andrews\Desktop\S & L Andrews's Quicken Data-2010-06-01.QDF-backup
[2010/06/01 00:16:59 | 454,645,531 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip FebMar 2010.pxc
[2010/06/01 00:16:17 | 064,580,179 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.pxc
[2010/06/01 00:15:49 | 000,210,855 | —- | M] () – C:\Windows\hpoins21.dat
[2010/06/01 00:15:40 | 000,244,379 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.psh
[2010/06/01 00:07:39 | 000,002,101 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/05/31 23:59:21 | 000,001,081 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk
[2010/05/31 23:56:21 | 000,501,248 | —- | M] () – C:\Users\S & L Andrews\Desktop\Backup.wlt
[2010/05/31 11:30:24 | 000,008,032 | —- | M] () – C:\Users\S & L Andrews\Desktop\www.playonscripts.com-{ea65016a-3111-405a-819c-92c7b72679ab}.dtapart
[2010/05/21 13:07:54 | 001,827,461 | —- | M] () – C:\Users\S & L Andrews\Desktop\pocket_informant_pro910_us_smart_setup.exe
[2010/05/19 23:52:17 | 000,008,192 | —- | M] () – C:\Users\S & L Andrews\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/18 19:09:22 | 000,244,395 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.bak
[2010/05/14 16:55:31 | 000,241,041 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b01
[2010/05/14 16:39:14 | 000,223,164 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b02
[2010/05/14 16:39:05 | 000,223,164 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b03
[2010/05/14 16:31:47 | 000,222,116 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b04
[2010/05/14 16:28:19 | 000,204,920 | —- | M] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b05
[2010/05/14 00:32:01 | 000,000,172 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\isolate.ini
[2010/05/12 20:15:59 | 000,000,002 | —- | M] () – C:\Users\S & L Andrews\tenmy.ini
[2010/05/12 20:15:58 | 000,372,103 | —- | M] () – C:\Users\S & L Andrews\win2djws.exe
[2010/05/12 20:15:56 | 000,136,704 | —- | M] () – C:\Users\S & L Andrews\pod822.exe
[2010/05/10 18:21:55 | 000,702,689 | —- | M] () – C:\Users\S & L Andrews\Desktop\tivo lifetime auction.jpg
[2010/05/10 18:19:15 | 000,002,037 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snagit 9.lnk
[2010/05/10 05:50:16 | 000,000,016 | —- | M] () – C:\Windows\popcinfo.dat
[1 C:\Users\S & L Andrews\*.tmp files -> C:\Users\S & L Andrews\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/08 06:40:56 | 000,001,015 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/07 14:23:25 | 000,003,011 | —- | C] () – C:\Users\S & L Andrews\Desktop\HiJackThis.lnk
[2010/06/07 09:22:07 | 000,002,146 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ActivClient Agent.lnk
[2010/06/06 15:40:59 | 000,005,430 | —- | C] () – C:\Windows\AnyWeb Print.ico
[2010/06/06 14:33:12 | 000,482,408 | —- | C] () – C:\Windows\ssndii.exe
[2010/06/06 14:32:28 | 000,022,016 | —- | C] () – C:\Windows\SysNative\cl31cl6.dll
[2010/06/06 14:32:28 | 000,000,357 | —- | C] () – C:\Windows\SysNative\cl31cl6.smt
[2010/06/01 00:22:55 | 000,015,389 | —- | C] () – C:\Users\S & L Andrews\Desktop\Trees for wet sites.docx
[2010/06/01 00:22:18 | 000,014,131 | —- | C] () – C:\Users\S & L Andrews\Desktop\TREES WHICH THRIVE IN VERY WET SOIL.docx
[2010/06/01 00:19:00 | 013,496,320 | —- | C] () – C:\Users\S & L Andrews\Desktop\S & L Andrews's Quicken Data-2010-06-01.QDF-backup
[2010/06/01 00:07:39 | 000,002,101 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/05/31 23:59:21 | 000,001,081 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk
[2010/05/31 11:30:23 | 000,008,032 | —- | C] () – C:\Users\S & L Andrews\Desktop\www.playonscripts.com-{ea65016a-3111-405a-819c-92c7b72679ab}.dtapart
[2010/05/29 23:05:46 | 000,011,502 | —- | C] () – C:\Windows\Dr. Printer Icon.ico
[2010/05/29 23:05:44 | 000,358,912 | —- | C] () – C:\Windows\SysNative\DscPnt.dll
[2010/05/29 23:05:44 | 000,259,440 | —- | C] () – C:\Windows\SUPDRun.exe
[2010/05/29 23:05:44 | 000,027,648 | —- | C] () – C:\Windows\SysNative\spd__l.dll
[2010/05/29 23:05:44 | 000,000,357 | —- | C] () – C:\Windows\SysNative\spd__l.smt
[2010/05/21 13:07:48 | 001,827,461 | —- | C] () – C:\Users\S & L Andrews\Desktop\pocket_informant_pro910_us_smart_setup.exe
[2010/05/14 16:28:19 | 064,580,179 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.pxc
[2010/05/14 16:28:19 | 000,244,395 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.bak
[2010/05/14 16:28:19 | 000,244,379 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.psh
[2010/05/14 16:28:19 | 000,241,041 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b01
[2010/05/14 16:28:19 | 000,223,164 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b03
[2010/05/14 16:28:19 | 000,223,164 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b02
[2010/05/14 16:28:19 | 000,222,116 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b04
[2010/05/14 16:28:19 | 000,204,920 | —- | C] () – C:\Users\S & L Andrews\Desktop\Utah Trip 2 FebMar 2010.b05
[2010/05/12 20:15:59 | 000,000,002 | —- | C] () – C:\Users\S & L Andrews\tenmy.ini
[2010/05/12 20:15:57 | 000,372,103 | —- | C] () – C:\Users\S & L Andrews\win2djws.exe
[2010/05/12 20:15:55 | 000,136,704 | —- | C] () – C:\Users\S & L Andrews\pod822.exe
[2010/05/10 18:21:09 | 000,702,689 | —- | C] () – C:\Users\S & L Andrews\Desktop\tivo lifetime auction.jpg
[2010/05/10 18:19:15 | 000,002,037 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snagit 9.lnk
[2010/02/14 16:10:23 | 000,000,171 | —- | C] () – C:\Windows\QUICKEN.INI
[2009/10/18 12:01:05 | 001,970,176 | —- | C] () – C:\Windows\SysWow64\d3dx9.dll
[2009/09/23 20:27:14 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/09/12 16:30:19 | 000,189,952 | —- | C] () – C:\Windows\Qcard32.dll
[2009/07/28 14:47:24 | 000,000,074 | —- | C] () – C:\Windows\MPLAYER.INI
[2009/07/28 02:15:57 | 000,111,104 | —- | C] () – C:\Windows\SysWow64\MVCL13N.DLL
[2009/07/28 02:08:16 | 000,338,944 | —- | C] () – C:\Windows\SysWow64\lffpx7.dll
[2009/07/28 02:08:16 | 000,122,880 | —- | C] () – C:\Windows\SysWow64\LFKODAK.DLL
[2009/07/28 02:07:17 | 000,001,336 | —- | C] () – C:\Windows\viewer.ini
[2009/07/28 02:07:08 | 000,631,808 | —- | C] () – C:\Windows\SysWow64\RWDL6DMX.DLL
[2009/07/28 02:07:07 | 000,631,808 | —- | C] () – C:\Windows\SysWow64\RWDL6BMX.DLL
[2009/07/28 02:07:06 | 000,630,784 | —- | C] () – C:\Windows\SysWow64\RWDL6AMX.DLL
[2009/07/28 02:07:04 | 000,032,768 | —- | C] () – C:\Windows\SysWow64\CPUINF32.DLL
[2009/07/28 01:48:51 | 000,000,458 | —- | C] () – C:\Windows\btw.ini
[2009/07/28 01:48:49 | 000,633,344 | —- | C] () – C:\Windows\SysWow64\RWDL6CMX.DLL
[2009/07/28 01:25:41 | 000,000,022 | —- | C] () – C:\Windows\VDECK.INI
[2009/07/28 01:16:26 | 000,044,544 | —- | C] () – C:\Windows\SysWow64\gif89.dll
[2009/07/28 01:15:42 | 000,000,766 | —- | C] () – C:\Windows\SIERRA.INI
[2009/07/26 23:10:56 | 000,001,680 | -HS- | C] () – C:\Windows\SysWow64\KGyGaAvL.sys
[2009/07/22 00:53:08 | 000,354,816 | —- | C] () – C:\Windows\SysWow64\pythoncom26.dll
[2009/07/22 00:53:08 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\pywintypes26.dll
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2008/12/29 11:30:20 | 000,000,070 | —- | C] () – C:\Windows\TaxACT08.ini
[2007/10/28 09:21:49 | 000,000,084 | —- | C] () – C:\Windows\EPSPRX580.ini
[2007/10/18 12:04:23 | 000,000,031 | -H– | C] () – C:\Windows\uccspecc.sys
[2006/11/06 16:49:36 | 000,000,322 | —- | C] () – C:\Windows\primopdf.ini
[2006/05/02 16:38:24 | 000,000,748 | —- | C] () – C:\Windows\SetBrowser.ini
[2002/03/20 16:01:05 | 000,006,688 | R— | C] () – C:\Windows\SysWow64\Digita.sys
[2002/03/20 16:00:19 | 000,049,152 | R— | C] () – C:\Windows\SysWow64\TransportUSB.dll
[2002/03/20 16:00:19 | 000,049,152 | R— | C] () – C:\Windows\SysWow64\TransportSerial.dll
[2002/03/20 16:00:18 | 000,049,152 | R— | C] () – C:\Windows\SysWow64\TransportIrDA.dll
[2002/03/20 16:00:18 | 000,049,152 | R— | C] () – C:\Windows\SysWow64\TransportIrCOMM.dll
< End of report >
Hello andrews89,

Please run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.iwon.com/
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta, = http://astalavista.box.sk/cgi-bin/robot?srch=%s
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta, = +
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,# = %23
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,& = %26
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,? = %3F
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,+ = %2B
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\asta,= = %3D
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs, = http://www.thebugs.ws/search.php?id=644&q=%s
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs, = +
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,# = %23
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,& = %26
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,? = %3F
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,+ = %2B
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\bugs,= = %3D
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy, = http://anonym.to/?http://%s
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy, = +
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,# = %23
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,& = %26
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,? = %3F
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,+ = %2B
    IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\proxy,= = %3D
    FF - prefs.js..browser.search.selectedEngine: "Bing"
    FF - prefs.js..browser.startup.homepage: "http://bing.zugo.com/?cfg=2-76-0-10JY1"
    FF - prefs.js..extensions.enabledItems: [removed]:0.7.3
    FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.5.8.6
    FF - prefs.js..keyword.URL: "http://bing.zugo.com/s/?src=FF-Address&site=Bing&cfg=2-76-0-10JY1&q="
    [2010/05/20 16:48:02 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
    [2010/06/04 09:51:59 | 000,000,000 | —D | M] – C:\Users\S & L Andrews\AppData\Roaming\Mozilla\Firefox\Profiles\m5g5att4.default\extensions\[removed]
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - No CLSID value found.
    O4:64bit: - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [] File not found
    O16 - DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} http://www.infospace.com/mypoints.main/tba…pointsSetup.exe (Reg Error: Key error.)
    
    :Commands
    [resethosts]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • It will produce a log for you on reboot, please post that log in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI