This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win32pornpopup

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is the results of my kaspersky scan. I will do the other scan too and post the results. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Friday, July 9, 2010 Operating system: Microsoft (build 7600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Friday, July 09, 2010 12:38:57 Records in database: 4242247 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Objects scanned: 224430 Threats found: 6 Infected objects found: 10 Suspicious objects found: 8 Scan duration: 03:50:26 File name / Threat / Threats count C:\Users\Amy\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Bookthink\0D2F03E6-00000037.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Amy\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Bookthink\0D812904-00000051.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Amy\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Bookthink\2D265E10-0000003A.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Amy\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Bookthink\47DF0F37-00000059.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Amy\AppData\Local\Microsoft\Windows Mail\migbackup\Local Folders\Inbox\Bookthink\19BD1DFC-00000059.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Amy\AppData\Local\Microsoft\Windows Mail\migbackup\Local Folders\Inbox\Bookthink\25B46DE7-00000037.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Amy\AppData\Local\Microsoft\Windows Mail\migbackup\Local Folders\Inbox\Bookthink\43731188-0000003A.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Amy\AppData\Local\Microsoft\Windows Mail\migbackup\Local Folders\Inbox\Bookthink\63CA0AA5-00000051.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Amy\Documents\My Silent Team\auction_giveaway_collection.zip Infected: Trojan-PSW.Win32.LdPinch.angw 1 C:\Users\Amy\Documents\My Silent Team\auction_giveaway_collection.zip Infected: Trojan-PSW.Win32.LdPinch.anpl 3 C:\Users\Amy\Documents\My Silent Team\auction_giveaway_collection.zip Infected: Trojan-PSW.Win32.LdPinch.anrx 4 C:\Users\Amy\Documents\My Silent Team\auction_giveaway_collection.zip Infected: Trojan-PSW.Win32.LdPinch.anht 1 C:\Users\Amy\Documents\Quality Ebay Things\Mystery_Shopping.zip Infected: Trojan-Clicker.JS.Iframe.cb 1 Selected area has been scanned.
OTL logfile created on: 7/9/2010 7:36:49 PM - Run 1
OTL by OldTimer - Version 3.2.8.1 Folder = C:\Users\Amy\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 29.00% Memory free
6.00 Gb Paging File | 3.00 Gb Available in Paging File | 53.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218.20 Gb Total Space | 16.15 Gb Free Space | 7.40% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 372.52 Gb Total Space | 48.08 Gb Free Space | 12.91% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: AMY-PC
Current User Name: Amy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Amy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Amy\AppData\Local\Temp\jkos-Amy\binaries\ScanningProcess.exe (Kaspersky Lab.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files (x86)\Brother\ControlCenter3\BrccMCtl.exe (Brother Industries, Ltd.)
PRC - C:\Program Files (x86)\Brother\Brmfcmon\BrMfimon.exe (Brother Industries, Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\X3watch\x3watch.exe (Tiger Green Productions LLC)


========== Modules (SafeList) ==========

MOD - C:\Users\Amy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:64bit: - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:64bit: - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV:64bit: - (MemeoBackgroundService) – C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe (Memeo)
SRV - (GoogleDesktopManager-051210-111108) – C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (GameConsoleService) – C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (SBSDWSCService) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (ALWIL Software)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (VClone) – C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (ApfiltrService) – C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://ebaysellingcoach.blogspot.com/2009/02/thrift-store-items-to-sell-on-ebay-huge.html|http://www.safbaby.com/12-things-your-child-should-avoid-in-2010|http://www.tammysrecipes.com/homemade_wheat_bread|http://www.localharvest.org/search.jsp?m&lat=42.240869&lon=-83.719353&scale=10&ty=-1&p=3|http://www.happinessprojecttoolbox.com/inspiration_boards.html|http://groups.yahoo.com/group/a2unschooling/|http://www.debralynndadd.com/|http://www.homeschool-curriculum-for-life.com/|http://www.havefunteaching.com/videos/character-education/|http://www.facebook.com/home.php?#!/?ref=home|http://board.mfwbooks.com/viewforum.php?f=30|http://board.mfwbooks.com/viewforum.php?f=22|http://board.mfwbooks.com/viewforum.php?f=3|http://www.kaspersky.com/kos/eng/partner/default/pages/default/main.html?n=1278697880531|http://maps.google.com/|http://annarbor.craigslist.org/gms/|http://forums.whatthetech.com/index.php?showtopic=112992&st=0&#entry665663"

FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox [2010/01/19 17:23:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/06/28 19:23:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/07/02 19:51:06 | 000,000,000 | —D | M]

[2010/07/08 21:19:03 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\extensions
[2010/04/27 10:40:47 | 000,000,000 | —D | M] (AI Roboform Toolbar for Firefox) – C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\extensions\{22119944-ED35-4ab1-910B-E619EA06A115}
[2010/01/19 18:46:30 | 000,000,000 | —D | M] (No name found) – C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\extensions\{2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}
[2010/03/15 14:39:35 | 000,000,000 | —D | M] (Swag Bucks Toolbar) – C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
[2010/04/27 10:40:46 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\extensions\[removed]
[2010/05/29 16:23:54 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/01/21 08:51:58 | 000,000,000 | —D | M] (Firefox (default)) – C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/05/29 16:23:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/01/21 08:51:58 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions\[removed]
[2010/06/24 16:46:38 | 000,119,808 | —- | M] (Google) – C:\Program Files (x86)\Mozilla Firefox\components\GoogleDesktopMozilla.dll
[2010/01/21 08:51:52 | 000,067,688 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\jar50.dll
[2010/01/21 08:51:52 | 000,054,368 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\jsd3250.dll
[2010/01/21 08:51:52 | 000,034,944 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\myspell.dll
[2010/01/21 08:51:53 | 000,046,712 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\spellchk.dll
[2010/01/21 08:51:54 | 000,172,136 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\xpinstal.dll
[2010/03/17 14:56:16 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll
[2009/11/19 18:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/05/29 16:23:38 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/19 18:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2010/01/21 08:51:57 | 000,022,656 | —- | M] (mozilla.org) – C:\Program Files (x86)\Mozilla Firefox\plugins\npnul32.dll
[2007/03/22 20:23:30 | 000,017,248 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFFICE.DLL
[2010/03/29 09:03:44 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files (x86)\Mozilla Firefox\plugins\npPandoWebInst.dll
[2010/06/19 15:34:11 | 000,103,864 | —- | M] (Adobe Systems Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
[2010/01/20 11:55:21 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
[2010/01/20 11:55:21 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
[2010/01/20 11:55:22 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
[2010/01/20 11:55:22 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
[2010/01/20 11:55:22 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
[2010/01/20 11:55:22 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
[2010/01/20 11:55:22 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
[2010/01/21 08:51:57 | 000,001,514 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazondotcom.xml
[2010/01/21 08:51:57 | 000,002,193 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\answers.xml
[2010/01/21 08:51:57 | 000,001,038 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\creativecommons.xml
[2010/01/21 08:51:57 | 000,001,046 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay.xml
[2010/01/21 08:51:57 | 000,002,351 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\google.xml
[2010/06/24 16:46:40 | 000,002,020 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\googledesktop.xml
[2010/01/21 08:51:58 | 000,000,792 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo.xml

O1 HOSTS File: ([2010/01/19 15:34:53 | 000,373,541 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 12871 more lines…
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [WD Anywhere Backup] C:\Program Files\WD\WD Anywhere Backup\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [RoboForm] C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GigaTribe.lnk = C:\Program Files (x86)\GigaTribe\gigatribe.exe (Gigatribe SAS)
O4 - Startup: C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\X3watch.lnk = C:\Program Files (x86)\X3watch\x3watch.exe (Tiger Green Productions LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files (x86)\Evernote\Evernote3\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files (x86)\Evernote\Evernote3\enbar.dll (Evernote Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files (x86)\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files (x86)\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~2\Google\GOOGLE~1\GO36F4~1.DLL) - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{72c959d4-0caf-11df-8116-a4badb9cdf4b}\Shell - "" = AutoRun
O33 - MountPoints2\{72c959d4-0caf-11df-8116-a4badb9cdf4b}\Shell\AutoRun\command - "" = M:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/07/09 19:32:56 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Amy\Desktop\OTL.exe
[2010/07/08 19:17:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2010/07/08 13:54:58 | 000,000,000 | —D | C] – C:\Users\Amy\AppData\Roaming\SUPERAntiSpyware.com
[2010/07/08 13:54:58 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/07/08 13:54:53 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2010/07/08 13:54:51 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/07/08 13:54:00 | 009,070,816 | —- | C] (SUPERAntiSpyware.com) – C:\Users\Amy\Desktop\SUPERAntiSpyware.exe
[2010/07/06 18:50:54 | 000,444,416 | —- | C] (OldTimer Tools) – C:\Users\Amy\Desktop\TFC.exe
[2010/07/06 14:37:58 | 000,000,000 | —D | C] – C:\Users\Amy\AppData\Roaming\Malwarebytes
[2010/07/06 14:37:49 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/07/06 14:37:47 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/07/06 14:37:46 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/07/06 14:37:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/07/02 19:50:52 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/07/02 07:55:10 | 000,038,848 | —- | C] (ALWIL Software) – C:\Windows\avastSS.scr
[2010/06/22 18:46:38 | 000,000,000 | —D | C] – C:\Users\Amy\AppData\Roaming\Reallusion
[2010/06/22 18:07:49 | 000,000,000 | —D | C] – C:\Users\Amy\Documents\Dell WebCam Central
[2010/06/22 18:07:49 | 000,000,000 | —D | C] – C:\ProgramData\Creative
[2010/06/22 18:07:48 | 000,000,000 | —D | C] – C:\Users\Amy\AppData\Roaming\Creative
[2010/06/22 14:58:07 | 000,000,000 | —D | C] – C:\Users\Amy\Documents\MFW Proverbs
[2010/06/21 20:00:14 | 000,000,000 | —D | C] – C:\Users\Amy\Documents\TOS Expo

========== Files - Modified Within 30 Days ==========

[2010/07/09 19:39:53 | 006,815,744 | -HS- | M] () – C:\Users\Amy\NTUSER.DAT
[2010/07/09 19:32:53 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Amy\Desktop\OTL.exe
[2010/07/09 19:28:59 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/07/08 19:14:19 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/08 19:14:19 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/08 19:05:49 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/07/08 19:05:30 | 2384,744,448 | -HS- | M] () – C:\hiberfil.sys
[2010/07/08 19:04:43 | 001,774,278 | -H– | M] () – C:\Users\Amy\AppData\Local\IconCache.db
[2010/07/08 14:29:07 | 000,040,448 | —- | M] () – C:\Users\Amy\Documents\yard sales 0710.doc
[2010/07/08 14:22:57 | 000,000,426 | —- | M] () – C:\Windows\BRWMARK.INI
[2010/07/08 13:54:52 | 000,001,810 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/07/08 13:54:18 | 009,070,816 | —- | M] (SUPERAntiSpyware.com) – C:\Users\Amy\Desktop\SUPERAntiSpyware.exe
[2010/07/06 18:50:53 | 000,444,416 | —- | M] (OldTimer Tools) – C:\Users\Amy\Desktop\TFC.exe
[2010/07/06 14:37:51 | 000,001,011 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/05 20:01:56 | 004,973,446 | —- | M] () – C:\Users\Amy\Desktop\Summer Learning Across the USA.pdf
[2010/07/04 18:07:32 | 012,466,723 | —- | M] () – C:\Users\Amy\Desktop\Invitations to Science Inquiry.pdf
[2010/07/03 08:14:02 | 000,098,304 | —- | M] () – C:\Users\Amy\Documents\Summer Activities 2010.doc
[2010/07/02 19:51:08 | 000,002,016 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/07/02 07:55:10 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2010/07/02 07:29:47 | 015,554,320 | —- | M] () – C:\Users\Amy\Desktop\QofACStsKFlood061610.mp3
[2010/06/28 19:18:19 | 013,825,394 | —- | M] () – C:\Users\Amy\Desktop\OHC-amphibians.pdf
[2010/06/28 16:57:33 | 000,038,848 | —- | M] (ALWIL Software) – C:\Windows\avastSS.scr
[2010/06/28 16:57:12 | 000,165,032 | —- | M] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2010/06/28 16:37:56 | 000,051,280 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2010/06/28 16:37:36 | 000,121,936 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2010/06/28 16:33:17 | 000,028,752 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswRdr.sys
[2010/06/28 16:33:00 | 000,061,008 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/06/28 16:32:36 | 000,020,048 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2010/06/21 19:45:31 | 002,337,795 | —- | M] () – C:\Users\Amy\Desktop\the-san-currclick.pdf
[2010/06/14 21:01:59 | 000,920,183 | —- | M] () – C:\Users\Amy\Desktop\My Favorite Spring Constellation 20100502 (Green).pdf
[2010/06/14 21:01:47 | 001,462,008 | —- | M] () – C:\Users\Amy\Desktop\My Favorite Spring Constellation 20100502.pdf
[2010/06/10 12:17:42 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/10 12:17:42 | 000,615,360 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/10 12:17:42 | 000,103,702 | —- | M] () – C:\Windows\SysNative\perfc009.dat

========== Files Created - No Company Name ==========

[2010/07/08 14:29:06 | 000,040,448 | —- | C] () – C:\Users\Amy\Documents\yard sales 0710.doc
[2010/07/08 13:54:52 | 000,001,810 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/07/06 14:37:51 | 000,001,011 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/05 20:01:44 | 004,973,446 | —- | C] () – C:\Users\Amy\Desktop\Summer Learning Across the USA.pdf
[2010/07/04 18:07:08 | 012,466,723 | —- | C] () – C:\Users\Amy\Desktop\Invitations to Science Inquiry.pdf
[2010/07/03 08:14:01 | 000,098,304 | —- | C] () – C:\Users\Amy\Documents\Summer Activities 2010.doc
[2010/07/02 07:29:04 | 015,554,320 | —- | C] () – C:\Users\Amy\Desktop\QofACStsKFlood061610.mp3
[2010/06/28 19:17:36 | 013,825,394 | —- | C] () – C:\Users\Amy\Desktop\OHC-amphibians.pdf
[2010/06/21 19:45:30 | 002,337,795 | —- | C] () – C:\Users\Amy\Desktop\the-san-currclick.pdf
[2010/06/14 21:01:58 | 000,920,183 | —- | C] () – C:\Users\Amy\Desktop\My Favorite Spring Constellation 20100502 (Green).pdf
[2010/06/14 21:01:44 | 001,462,008 | —- | C] () – C:\Users\Amy\Desktop\My Favorite Spring Constellation 20100502.pdf
[2010/01/27 16:29:02 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2010/01/20 13:17:04 | 000,000,257 | —- | C] () – C:\Windows\Brpfx04a.ini
[2010/01/20 13:17:04 | 000,000,094 | —- | C] () – C:\Windows\brpcfx.ini
[2010/01/20 13:16:36 | 000,000,426 | —- | C] () – C:\Windows\BRWMARK.INI
[2010/01/20 13:15:47 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2010/01/20 13:15:46 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2010/01/20 13:15:41 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\BRTCPCON.DLL
[2010/01/20 13:15:34 | 000,000,114 | —- | C] () – C:\Windows\SysWow64\BRLMW03A.INI
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2010/03/17 14:56:16 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\E-centives
[2010/03/10 16:42:59 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\GoodSync
[2010/01/21 14:52:09 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\WD
[2010/01/19 20:17:52 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\x3watch
[2009/07/14 01:08:49 | 000,017,898 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >

Extras.txt

OTL Extras logfile created on: 7/9/2010 7:36:49 PM - Run 1
OTL by OldTimer - Version 3.2.8.1 Folder = C:\Users\Amy\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 29.00% Memory free
6.00 Gb Paging File | 3.00 Gb Available in Paging File | 53.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218.20 Gb Total Space | 16.15 Gb Free Space | 7.40% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 372.52 Gb Total Space | 48.08 Gb Free Space | 12.91% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: AMY-PC
Current User Name: Amy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{26A24AE4-039D-4CA4-87B4-2F86416014FF}" = Java™ 6 Update 14 (64-bit)
"{7BB67E6C-4AA2-426b-8AC0-19460E94A4D7}" = WD Anywhere Backup
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9EFC40E3-5F31-4F75-8445-286273F74D8E}" = Apple Mobile Device Support
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{C9C243B9-03BD-44BA-A592-AB09630AE2D2}" = iTunes
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
"{E60B7350-EA5F-41E0-9D6F-E508781E36D2}" = Dell Dock
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"Dell Wireless WLAN Card Utility" = Dell Wireless WLAN Card Utility
"HDMI" = Intel® Graphics Media Accelerator Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}" = Microsoft Visual C++ 2005 Redistributable
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{0D025345-1033-4F35-A5CE-68CDCDE6CC03}" = Evernote
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2DA5F129-11AC-4F11-8188-B2F07EAAC20A}" = Cozi
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}" = Banctec Service Agreement
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{A1BBEE16-49B1-42F2-95B8-54C8C6A1C0C3}" = Brother MFL-Pro Suite MFC-9320CW
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}" = Pando
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"AI RoboForm" = AI RoboForm (All Users)
"avast5" = avast! Free Antivirus
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Dell Webcam Central" = Dell Webcam Central
"Google Desktop" = Google Desktop
"GoToAssist" = GoToAssist 8.0.0.514
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (2.0.0.20)" = Mozilla Firefox (2.0.0.20)
"Picasa 3" = Picasa 3
"ShalSoft.GigaTribe_is1" = GigaTribe 3.01.001
"ST6UNST #1" = AuctionSage
"VLC media player" = VLC media player 1.0.3
"WildTangent dell Master Uninstall" = WildTangent Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"X3watch_is1" = X3watch 5.0.6

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/25/2010 8:00:14 AM | Computer Name = Amy-PC | Source = Customer Experience Improvement Program | ID = 1006
Description =

Error - 6/26/2010 3:04:34 AM | Computer Name = Amy-PC | Source = Customer Experience Improvement Program | ID = 1006
Description =

Error - 6/26/2010 10:00:10 PM | Computer Name = Amy-PC | Source = Customer Experience Improvement Program | ID = 1006
Description =

Error - 6/27/2010 5:00:08 PM | Computer Name = Amy-PC | Source = Customer Experience Improvement Program | ID = 1006
Description =

Error - 6/28/2010 12:00:18 PM | Computer Name = Amy-PC | Source = Customer Experience Improvement Program | ID = 1006
Description =

Error - 6/29/2010 6:00:10 AM | Computer Name = Amy-PC | Source = Customer Experience Improvement Program | ID = 1006
Description =

Error - 6/29/2010 7:00:09 AM | Computer Name = Amy-PC | Source = Customer Experience Improvement Program | ID = 1006
Description =

Error - 6/30/2010 2:00:09 AM | Computer Name = Amy-PC | Source = Customer Experience Improvement Program | ID = 1006
Description =

Error - 6/30/2010 9:00:10 PM | Computer Name = Amy-PC | Source = Customer Experience Improvement Program | ID = 1006
Description =

Error - 7/1/2010 4:00:09 PM | Computer Name = Amy-PC | Source = Customer Experience Improvement Program | ID = 1006
Description =

[ Broadcom Wireless LAN Events ]
Error - 1/19/2010 2:18:26 AM | Computer Name = Amy-PC | Source = WLAN-Tray | ID = 0
Description = 01:18:26, Tue, Jan 19, 10 Error - Unable to get current user admin
status

Error - 1/19/2010 2:18:42 AM | Computer Name = Amy-PC | Source = WLAN-Tray | ID = 0
Description = 01:18:42, Tue, Jan 19, 10 Error - Unable to get current user admin
status

Error - 1/19/2010 2:20:22 AM | Computer Name = Amy-PC | Source = WLAN-Tray | ID = 0
Description = 00:20:22, Tue, Jan 19, 10 Error - Unable to switch user context, authentication
information not set correctly

Error - 4/15/2010 3:35:39 AM | Computer Name = Amy-PC | Source = WLAN-Tray | ID = 0
Description = 03:35:39, Thu, Apr 15, 10 Error - Unable to gain access to user store


[ System Events ]
Error - 7/5/2010 8:03:34 AM | Computer Name = Amy-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk8\DR8.

Error - 7/5/2010 7:02:48 PM | Computer Name = Amy-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk6\DR6.

Error - 7/5/2010 7:02:50 PM | Computer Name = Amy-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk8\DR8.

Error - 7/5/2010 8:49:43 PM | Computer Name = Amy-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk6\DR14.

Error - 7/6/2010 2:13:28 PM | Computer Name = Amy-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.

Error - 7/6/2010 2:58:43 PM | Computer Name = Amy-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk8\DR8.

Error - 7/6/2010 2:59:16 PM | Computer Name = Amy-PC | Source = DCOM | ID = 10005
Description =

Error - 7/6/2010 2:59:16 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Search service to connect.

Error - 7/6/2010 2:59:16 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7000
Description = The Windows Search service failed to start due to the following error:
%%1053

Error - 7/6/2010 6:51:59 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7034
Description = The Dock Login Service service terminated unexpectedly. It has done
this 1 time(s).


< End of report >
Hi,

You need to enable windows to Show all Files and Folders
Instructions for your Operating System HERE

You need to delete these

C:\Users\Amy\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Bookthink <–Everything inside this folder
C:\Users\Amy\Documents\My Silent Team\auction_giveaway_collection.zip
C:\Users\Amy\Documents\Quality Ebay Things\Mystery_Shopping.zip


Looks like we are going to have to remove it manually

Run a scan with Spybot , post the report please



Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :folderfind
    Win32.Pornpopup 
    :filefind
    Win32.Pornpopup 
    :regfind
    Win32.Pornpopup
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Here's the result of my spybot scan. I haven't done the Systemlook yet. Burstmedia 2 entries, browser Doubleclick 1 entry, browser MediaPlex, 6 entries, browser Right Media, 1 entry, browser Win32.pornpopup, 7 entries, browser Zedo, 1 entry, browser
So this is interesting. Here are the results of my scan: SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 12:43 on 10/07/2010 by Amy (Administrator - Elevation successful) ========== folderfind ========== Searching for "Win32.Pornpopup" No folders found. ========== filefind ========== Searching for "Win32.Pornpopup" No files found. ========== regfind ========== Searching for "Win32.Pornpopup" No data found. -=End Of File=- But when I ran spybot again right after I still got the same results as my previous post plus LinkSynergy, 4 entries.
Hi,

http://www.systenance.com/indexdat.php
This program should get rid of it. It was successful on other threads. You seem to handle instructions very well so I am linking you to the page with screenshots and all that will show you how to run it

How to use Index.dat analyzer?

Choose one of three categories from the pull down menu: History, Cookies or Cache. Mark the checkboxes for the entries you want to delete and press “ Delete Cheched ” button. You can check and uncheck all entries at once and you have nice filter that can help you shorten the list to find what you are looking for.

With Win 7 , after you download it you will have to right click and select RUN AS ADMINISTRATOR

Please post back and let me know if this solved it
First back up your registry with ERUNT

Backup Your Registry with ERUNT:
  • Download erunt.zip to your Desktop from here:
    http://aumha.org/downloads/erunt.zip
  • Right-click erunt.zip, select Extract All… and follow the prompts to extract ERUNT to a new folder on your Desktop
  • Inside the new folder, double-click ERUNT.exe to start the program
  • OK all the prompts to back up your registry to the default location.
Note: to restore your registry, go to the backup folder and start ERDNT.exe



To remove Win32.Pornpopup, you must first stop any Win32.Pornpopup processes that are running in your computer's memory. To stop all Win32.Pornpopup processes, press CTRL+ALT+DELETE to open the Windows Task Manager. Click on the "Processes" tab, search for Win32.Pornpopup, then right-click it and select "End Process" key.


REGEDIT4

[-HKEY_LOCAL_MACHINE\Software\Win32.Pornpopup]


Copy the entire contents inside the Quote box and Paste it into Notepad ( this will only work with Notepad ) name the file Regfix.reg and in the drop down box, save it as All Files. Save it to your desktop. Then Rightclick on the Regfix.reg file and click on Merge, when it asks you to merge with the Registry, say yes.

If you saved the file correctly it should look like this [external image: Posted Image]



Let me know how it went
Empty your Spybot Recovery (quarantine) folder * Open Spybot and click on the "Recovery" button. * The items that Spybot has quarantined will be listed. * Place a check mark in the box next to each item listed and that click on "Purge Selected Items". * Empty your recycle bin. Run spybot again and see if its gone
That didn't work, but it got me thinking about Spybot. So I played around and found where I could view a detailed report of my last scan, so here it is. I hope this helps! It seems it's a cookie, but when I look at the cookies in Firefox I can never find it. Does it have another name?


— Search result list —
Win32.PornPopUp: Tracking cookie (Firefox: Amy (default)) (Cookie, fixed)


Win32.PornPopUp: Tracking cookie (Firefox: Amy (default)) (Cookie, fixed)


Win32.PornPopUp: Tracking cookie (Firefox: Amy (default)) (Cookie, fixed)


Win32.PornPopUp: Tracking cookie (Firefox: Amy (default)) (Cookie, fixed)


Win32.PornPopUp: Tracking cookie (Firefox: Amy (default)) (Cookie, fixed)


Win32.PornPopUp: Tracking cookie (Firefox: Amy (default)) (Cookie, fixed)


MediaPlex: Tracking cookie (Firefox: Amy (default)) (Cookie, fixed)


MediaPlex: Tracking cookie (Firefox: Amy (default)) (Cookie, fixed)


MediaPlex: Tracking cookie (Firefox: Amy (default)) (Cookie, fixed)


MediaPlex: Tracking cookie (Firefox: Amy (default)) (Cookie, fixed)



— Spybot - Search & Destroy version: 1.6.2 (build: 20090126) —

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe ([removed])
2010-01-19 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll ([removed])
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll ([removed])
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2010-06-29 Includes\Adware.sbi (*)
2010-07-06 Includes\AdwareC.sbi (*)
2010-01-25 Includes\Cookies.sbi (*)
2009-11-03 Includes\Dialer.sbi (*)
2010-07-06 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2010-07-06 Includes\HijackersC.sbi (*)
2010-06-09 Includes\iPhone.sbi (*)
2010-01-20 Includes\Keyloggers.sbi (*)
2010-07-06 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2010-06-01 Includes\Malware.sbi (*)
2010-07-06 Includes\MalwareC.sbi (*)
2010-05-18 Includes\PUPS.sbi (*)
2010-07-06 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-07-06 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-06-29 Includes\Spyware.sbi (*)
2010-07-06 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-06-29 Includes\Trojans.sbi (*)
2010-07-06 Includes\TrojansC-02.sbi (*)
2010-07-06 Includes\TrojansC-03.sbi (*)
2010-07-06 Includes\TrojansC-04.sbi (*)
2010-07-06 Includes\TrojansC-05.sbi (*)
2010-07-06 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll



— System information —
Unknown Windows version 6.1 (Build: 7600) (6.1.7600)


— Startup entries list —
Located: HK_LM:Run, Adobe ARM
command: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
file: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
size: 976832
MD5: 0B232C77D822983397674AEEC9AB59DC

Located: HK_LM:Run, Adobe Reader Speed Launcher
command: "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
file: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
size: 35760
MD5: A32B25970003B6ABA027EFF8EEDA12A3

Located: HK_LM:Run, avast5
command: "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
file: C:\Program Files\Alwil Software\Avast5\avastUI.exe
size: 2837864
MD5: 38AE7A942FC3FAB1C6A27EB65DE8F827

Located: HK_LM:Run, BrMfcWnd
command: C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
file: C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe
size: 1159168
MD5: 4D5D968FE6AE6BF94A807F73F7FF6B3D

Located: HK_LM:Run, ControlCenter3
command: C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun
file: C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe
size: 114688
MD5: 4DE3EF07E0854547309C6B40235A9D44

Located: HK_LM:Run, Dell Webcam Central
command: "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
file: C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
size: 409744
MD5: 80B62FF105908EC9E4B072AFB1CFC824

Located: HK_LM:Run, DellSupportCenter
command: "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
file: C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
size: 206064
MD5: 00D1FB0073B4A8BD2989EA8FF4CC792B

Located: HK_LM:Run, Desktop Disc Tool
command: "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
file: c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
size: 498160
MD5: 0647EF247A5D0402E74FE89F5F6A8A11

Located: HK_LM:Run, Google Desktop Search
command: "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
file: C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
size: 30192
MD5: 9F5F2F0FB0A7F5AA9F16B9A7B6DAD89F

Located: HK_LM:Run, iTunesHelper
command: "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
file: C:\Program Files (x86)\iTunes\iTunesHelper.exe
size: 141600
MD5: 68A553BDFA855C4F1074696682FCDEB6

Located: HK_LM:Run, PDVDDXSrv
command: "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
file: C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
size: 140520
MD5: 1F5A26DF97C33CD24A8ED4D4A1FF1348

Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
file: C:\Program Files (x86)\QuickTime\QTTask.exe
size: 417792
MD5: 55D7A219AD8D0DB8980528944152A6FD

Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
file: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
size: 248040
MD5: 52DB6CDAC5BC7A1FC884E97C41C91213

Located: HK_CU:Run, RoboForm
where: S-1-5-21-310056545-2846266270-3799731783-1000…
command: "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
file: C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
size: 160328
MD5: DAB4CF23E3E5A81B01BE8E3664965AF1

Located: HK_CU:Run, SUPERAntiSpyware
where: S-1-5-21-310056545-2846266270-3799731783-1000…
command: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
file: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
size: 2957040
MD5: 24C4194E6636570F7931BA6A96798FE2

Located: Startup (user), GigaTribe.lnk
where: C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup…
command: C:\Program Files (x86)\GigaTribe\gigatribe.exe
file: C:\Program Files (x86)\GigaTribe\gigatribe.exe
size: 4358144
MD5: A40A3C9A80F6E5E85D201470A8847659

Located: Startup (user), X3watch.lnk
where: C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup…
command: C:\Program Files (x86)\X3watch\x3watch.exe
file: C:\Program Files (x86)\X3watch\x3watch.exe
size: 299008
MD5: 5874152545D734CB74960189D9B29B46



— Browser helper object list —
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} (AcroIEHelperStub)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: AcroIEHelperStub
CLSID name: Adobe PDF Link Helper
Path: C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\
Long name: AcroIEHelperShim.dll
Short name: ACROIE~2.DLL
Date (created): 6/19/2010 3:29:34 PM
Date (last access): 7/2/2010 7:51:02 PM
Date (last write): 6/19/2010 3:29:34 PM
Filesize: 75200
Attributes: archive
MD5: 6D9042F1443A601DA8DC24D991EDDD0A
CRC32: 10990AC8
Version: 9.3.3.177

{5C255C8A-E604-49b4-9D64-90988571CECB} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:

{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} (Search Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: Search Helper
CLSID name: Search Helper
Path: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\
Long name: SEPsearchhelperie.dll
Short name: SEPSEA~1.DLL
Date (created): 5/14/2010 11:00:26 AM
Date (last access): 6/10/2010 3:06:16 AM
Date (last write): 5/14/2010 11:00:26 AM
Filesize: 191792
Attributes: archive
MD5: 69974B4FB022B6FB8691BF537B4C1A26
CRC32: FFCD8C8F
Version: 3.0.126.0

{724d43a9-0d85-11d4-9908-00400523e39a} (RoboForm)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: RoboForm
CLSID name:
description: RoboForm
classification: Legitimate
known filename: RoboForm.dll
info link: http://www.roboform.com/
info source: TonyKlein
Path: C:\Program Files (x86)\Siber Systems\AI RoboForm\
Long name: roboform.dll
Short name:
Date (created): 1/19/2010 5:23:20 PM
Date (last access): 1/19/2010 5:23:20 PM
Date (last write): 3/8/2010 12:18:12 PM
Filesize: 6021696
Attributes: archive
MD5: 4A4DC87BE203BE1D7EB219C28863A8D4
CRC32: 444C5D15
Version: 6.9.99.0

{9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Windows Live Sign-in Helper
Path: C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\
Long name: WindowsLiveLogin.dll
Short name: WINDOW~1.DLL
Date (created): 1/22/2009 5:41:30 PM
Date (last access): 1/11/2010 4:51:22 PM
Date (last write): 1/22/2009 5:41:30 PM
Filesize: 408448
Attributes: archive
MD5: B7899C3E21B299D7A3C0DA96CAE340BD
CRC32: 288935F8
Version: 5.0.818.5

{DBC80044-A445-435b-BC74-9C25C1C588A9} (Java™ Plug-In 2 SSV Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Java™ Plug-In 2 SSV Helper
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: jp2ssv.dll
Short name:
Date (created): 5/29/2010 4:23:36 PM
Date (last access): 5/29/2010 4:23:36 PM
Date (last write): 5/29/2010 4:23:36 PM
Filesize: 41760
Attributes: archive
MD5: 385BD69743EA92E76CDF07B3345A25D5
CRC32: D47CB5BA
Version: 6.0.200.2

{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} (Windows Live Toolbar Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Windows Live Toolbar Helper
Path: C:\Program Files (x86)\Windows Live\Toolbar\
Long name: wltcore.dll
Short name:
Date (created): 2/6/2009 8:17:46 PM
Date (last access): 1/11/2010 4:53:14 PM
Date (last write): 2/6/2009 8:17:46 PM
Filesize: 1068904
Attributes: archive
MD5: 28455424E3C8B81661C5A40E18066BB1
CRC32: E5BA354B
Version: 14.0.8064.206



— ActiveX list —
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_20
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: jp2iexp.dll
Short name:
Date (created): 5/29/2010 4:23:36 PM
Date (last access): 5/29/2010 4:23:36 PM
Date (last write): 5/29/2010 4:23:36 PM
Filesize: 108320
Attributes: archive
MD5: 3F7C69FF524EC11535342108A350A76F
CRC32: 28370E95
Version: 6.0.200.2

{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_20
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: jp2iexp.dll
Short name:
Date (created): 5/29/2010 4:23:36 PM
Date (last access): 5/29/2010 4:23:36 PM
Date (last write): 5/29/2010 4:23:36 PM
Filesize: 108320
Attributes: archive
MD5: 3F7C69FF524EC11535342108A350A76F
CRC32: 28370E95
Version: 6.0.200.2

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_20
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
description:
classification: Legitimate
known filename: npjpi150_06.dll
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: npjpi160_20.dll
Short name: NPJPI1~1.DLL
Date (created): 5/29/2010 4:23:40 PM
Date (last access): 5/29/2010 4:23:40 PM
Date (last write): 5/29/2010 4:23:40 PM
Filesize: 136992
Attributes: archive
MD5: E06930C34F16C8AD24AD79502F40026A
CRC32: 529E0B62
Version: 6.0.200.2

{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
Installer: C:\Windows\Downloaded Program Files\swflash.inf
Codebase: http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\Windows\SysWow64\Macromed\Flash\
Long name: Flash10e.ocx
Short name:
Date (created): 1/26/2010 8:58:36 PM
Date (last access): 4/2/2010 8:33:02 AM
Date (last write): 1/26/2010 8:58:36 PM
Filesize: 3981080
Attributes: readonly archive
MD5: C06E6E160F34CE092301BD2B29067F3F
CRC32: D922F8F5
Version: 10.0.45.2



— Process list —
PID: 0 ( 0) [System]
PID: 3196 ( 628) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
size: 186904
MD5: 5AF1E9600E3FF841E522703A4993ED0C
PID: 3224 ( 628) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
size: 160328
MD5: DAB4CF23E3E5A81B01BE8E3664965AF1
PID: 3336 ( 628) C:\Program Files (x86)\X3watch\x3watch.exe
size: 299008
MD5: 5874152545D734CB74960189D9B29B46
PID: 3620 (3288) C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
size: 140520
MD5: 1F5A26DF97C33CD24A8ED4D4A1FF1348
PID: 3628 (3288) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
size: 409744
MD5: 80B62FF105908EC9E4B072AFB1CFC824
PID: 3636 (3288) C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
size: 498160
MD5: 0647EF247A5D0402E74FE89F5F6A8A11
PID: 3644 (3288) C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
size: 206064
MD5: 00D1FB0073B4A8BD2989EA8FF4CC792B
PID: 3652 (3288) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
size: 2837864
MD5: 38AE7A942FC3FAB1C6A27EB65DE8F827
PID: 3672 (3288) C:\Program Files (x86)\iTunes\iTunesHelper.exe
size: 141600
MD5: 68A553BDFA855C4F1074696682FCDEB6
PID: 3680 (3288) C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
size: 30192
MD5: 9F5F2F0FB0A7F5AA9F16B9A7B6DAD89F
PID: 3704 (3288) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe
size: 1159168
MD5: 4D5D968FE6AE6BF94A807F73F7FF6B3D
PID: 3744 (3288) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
size: 248040
MD5: 52DB6CDAC5BC7A1FC884E97C41C91213
PID: 3924 (3712) C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe
size: 872448
MD5: 36E5CA5DCE72A831A3F7C7ED8AEA83AE
PID: 3004 (3704) C:\Program Files (x86)\Brother\Brmfcmon\BrMfimon.exe
size: 143360
MD5: 03ED4235F1E428A79B86287E6AD108F4
PID: 3804 (3680) C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
size: 30192
MD5: 9F5F2F0FB0A7F5AA9F16B9A7B6DAD89F
PID: 5108 (4792) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
size: 7678568
MD5: 8F93743D81634DB09023C41154B3E320
PID: 2068 ( 628) C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
size: 5365592
MD5: 0477C2F9171599CA5BC3307FDFBA8D89
PID: 3324 ( 628) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
size: 113488
MD5: 5EBA224D227654AD998EFFDCD1B30BFE
PID: 5088 ( 652) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
size: 27512
MD5: 654480EA67078C7B4C6C8BA871B07D5D
PID: 4 ( 0) System
PID: 272 ( 4) smss.exe
PID: 364 ( 348) csrss.exe
PID: 416 ( 348) wininit.exe
size: 96256
PID: 432 ( 408) csrss.exe
PID: 492 ( 408) winlogon.exe
PID: 504 ( 416) services.exe
PID: 528 ( 416) lsass.exe
PID: 540 ( 416) lsm.exe
PID: 652 ( 504) svchost.exe
size: 20992
PID: 744 ( 504) svchost.exe
size: 20992
PID: 840 ( 504) svchost.exe
size: 20992
PID: 888 ( 504) svchost.exe
size: 20992
PID: 916 ( 504) svchost.exe
size: 20992
PID: 952 ( 504) stacsv64.exe
PID: 584 ( 504) svchost.exe
size: 20992
PID: 1040 ( 504) DockLogin.exe
PID: 1168 ( 504) svchost.exe
size: 20992
PID: 1256 ( 504) WLTRYSVC.EXE
PID: 1264 ( 888) wlanext.exe
size: 77312
PID: 1272 ( 364) conhost.exe
PID: 1308 (1256) BCMWLTRY.EXE
PID: 1352 ( 504) AvastSvc.exe
PID: 1700 ( 504) spoolsv.exe
PID: 1728 ( 504) svchost.exe
size: 20992
PID: 1860 ( 504) SASCore64.exe
PID: 1880 ( 504) AppleMobileDeviceService.exe
PID: 1904 ( 504) mDNSResponder.exe
PID: 1964 ( 504) svchost.exe
size: 20992
PID: 2004 ( 504) MemeoBackgroundService.exe
PID: 960 ( 504) SeaPort.exe
PID: 1812 ( 504) svchost.exe
size: 20992
PID: 2060 ( 504) svchost.exe
size: 20992
PID: 2116 ( 504) IAANTmon.exe
PID: 2272 ( 504) SDWinSec.exe
PID: 1280 ( 504) sprtsvc.exe
PID: 2896 ( 504) wmpnetwk.exe
PID: 108 ( 504) SearchIndexer.exe
size: 428032
PID: 2240 ( 652) WmiPrvSE.exe
PID: 2428 ( 504) C:\Windows\System32\taskhost.exe
PID: 604 ( 888) C:\Windows\System32\dwm.exe
PID: 628 (1556) C:\Windows\explorer.exe
size: 2870272
MD5: 9AAAEC8DAC27AA17B053E6352AD233AE
PID: 3108 ( 628) C:\Program Files\DellTPad\Apoint.exe
size: 305664
MD5: 5FA0584E20C0E983F83FAABBF42DFFFA
PID: 3116 ( 628) C:\Program Files\IDT\WDM\sttray64.exe
size: 444416
MD5: 5F3D8F0243E653BEDEB9AC6F04B7CF79
PID: 3124 ( 628) C:\Windows\System32\igfxtray.exe
PID: 3132 ( 628) C:\Windows\System32\hkcmd.exe
PID: 3152 ( 628) C:\Windows\System32\igfxpers.exe
PID: 3160 ( 628) C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
size: 4968960
MD5: 1F83CB91A9830038DBE7CD1BA1921205
PID: 3172 ( 628) C:\Program Files\Dell\QuickSet\quickset.exe
size: 3180624
MD5: B60457F40BBF5EAE380FC110B21C4978
PID: 3280 ( 628) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
size: 2957040
MD5: 24C4194E6636570F7931BA6A96798FE2
PID: 3364 ( 652) C:\Windows\System32\igfxsrvc.exe
PID: 3832 (3108) ApMsgFwd.exe
PID: 3876 (3856) C:\Program Files\DellTPad\ApntEx.exe
size: 23552
MD5: 9D9B61AF3DBDC1490CBC508C8380510B
PID: 3892 ( 432) C:\Windows\System32\conhost.exe
PID: 3916 (3108) C:\Program Files\DellTPad\hidfind.exe
size: 91648
MD5: D7FCD621FC17B4EDD453D0F5C22A7DA6
PID: 4324 ( 504) svchost.exe
size: 20992
PID: 4500 ( 504) iPodService.exe
PID: 5076 ( 108) SearchProtocolHost.exe
size: 164352
PID: 1384 ( 108) SearchFilterHost.exe
size: 86528


— Browser start & search pages list —
Spybot - Search & Destroy browser pages report, 7/11/2010 7:03:27 PM

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\Windows\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.google.com
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
Preserve
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.google.com/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
http://www.google.com/search/?q=%s
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
C:\Windows\SysWOW64\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://go.microsoft.com/fwlink/?LinkId=54896


— Winsock Layered Service Provider list —
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 3: MSAFD Tcpip [TCP/IPv6]
GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IPv6 protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 4: MSAFD Tcpip [UDP/IPv6]
GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IPv6 protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 5: MSAFD Tcpip [RAW/IPv6]
GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IPv6 protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 6: RSVP TCPv6 Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 7: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 8: RSVP UDPv6 Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 9: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Namespace Provider 0: Network Location Awareness Legacy (NLAv1) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename:
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace

Namespace Provider 1: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename:
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP

Namespace Provider 2: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS

Namespace Provider 3: E-mail Naming Shim Provider
GUID: {964ACBA2-B2BC-40EB-8C6A-A6DB40161CAE}
Filename:

Namespace Provider 4: PNRP Cloud Namespace Provider
GUID: {03FE89CE-766D-4976-B9C1-BB9BC42C7B4D}
Filename:

Namespace Provider 5: PNRP Name Namespace Provider
GUID: {03FE89CD-766D-4976-B9C1-BB9BC42C7B4D}
Filename:
Hi Amy,

We have been leaning towards IE so lets see what removing cookies in Firefox does. I had a thread about a month ago and this removed real easy but I have been following 2 others where it just wont go, but there is an answer so just hang in there

X3watch
<–Are you aware of this installed program?



Before you proceed write down any log on names or passwords you may need to access sites that you frequent , especially banking or shopping sites as we are going to remove all cookies

Open up Firefox and go to Tools> Options > Privacy tab and click on Remove Individual cookies and click on Remove all cookies ok your way out, close Firefox, reboot your system , open Firefox and see if there gone, then also run another scan with Spybot and post the log like you just did
I am aware of x3watch, thanks.

So, it worked! So far I am win32.pornpopup free! The log is posted below and I will check for the next couple of days to see if it stays gone. Do you have any idea of what the name of the cookie was so I could block it? It wasn't win32.pornpopup because I checked for that.

Also, when I did the Kaspersky scan and it found those trojans, should I be concerned that my installed antivirus didn't catch them?

Thanks so much!


— Search result list —
Congratulations!: No immediate threats were found. (Status)



— Spybot - Search & Destroy version: 1.6.2 (build: 20090126) —

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe ([removed])
2010-01-19 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll ([removed])
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll ([removed])
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2010-06-29 Includes\Adware.sbi (*)
2010-07-06 Includes\AdwareC.sbi (*)
2010-01-25 Includes\Cookies.sbi (*)
2009-11-03 Includes\Dialer.sbi (*)
2010-07-06 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2010-07-06 Includes\HijackersC.sbi (*)
2010-06-09 Includes\iPhone.sbi (*)
2010-01-20 Includes\Keyloggers.sbi (*)
2010-07-06 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2010-06-01 Includes\Malware.sbi (*)
2010-07-06 Includes\MalwareC.sbi (*)
2010-05-18 Includes\PUPS.sbi (*)
2010-07-06 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-07-06 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-06-29 Includes\Spyware.sbi (*)
2010-07-06 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-06-29 Includes\Trojans.sbi (*)
2010-07-06 Includes\TrojansC-02.sbi (*)
2010-07-06 Includes\TrojansC-03.sbi (*)
2010-07-06 Includes\TrojansC-04.sbi (*)
2010-07-06 Includes\TrojansC-05.sbi (*)
2010-07-06 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll



— System information —
Unknown Windows version 6.1 (Build: 7600) (6.1.7600)


— Startup entries list —
Located: HK_LM:Run, Adobe ARM
command: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
file: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
size: 976832
MD5: 0B232C77D822983397674AEEC9AB59DC

Located: HK_LM:Run, Adobe Reader Speed Launcher
command: "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
file: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
size: 35760
MD5: A32B25970003B6ABA027EFF8EEDA12A3

Located: HK_LM:Run, avast5
command: "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
file: C:\Program Files\Alwil Software\Avast5\avastUI.exe
size: 2837864
MD5: 38AE7A942FC3FAB1C6A27EB65DE8F827

Located: HK_LM:Run, BrMfcWnd
command: C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
file: C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe
size: 1159168
MD5: 4D5D968FE6AE6BF94A807F73F7FF6B3D

Located: HK_LM:Run, ControlCenter3
command: C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun
file: C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe
size: 114688
MD5: 4DE3EF07E0854547309C6B40235A9D44

Located: HK_LM:Run, Dell Webcam Central
command: "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
file: C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
size: 409744
MD5: 80B62FF105908EC9E4B072AFB1CFC824

Located: HK_LM:Run, DellSupportCenter
command: "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
file: C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
size: 206064
MD5: 00D1FB0073B4A8BD2989EA8FF4CC792B

Located: HK_LM:Run, Desktop Disc Tool
command: "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
file: c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
size: 498160
MD5: 0647EF247A5D0402E74FE89F5F6A8A11

Located: HK_LM:Run, Google Desktop Search
command: "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
file: C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
size: 30192
MD5: 9F5F2F0FB0A7F5AA9F16B9A7B6DAD89F

Located: HK_LM:Run, iTunesHelper
command: "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
file: C:\Program Files (x86)\iTunes\iTunesHelper.exe
size: 141600
MD5: 68A553BDFA855C4F1074696682FCDEB6

Located: HK_LM:Run, PDVDDXSrv
command: "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
file: C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
size: 140520
MD5: 1F5A26DF97C33CD24A8ED4D4A1FF1348

Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
file: C:\Program Files (x86)\QuickTime\QTTask.exe
size: 417792
MD5: 55D7A219AD8D0DB8980528944152A6FD

Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
file: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
size: 248040
MD5: 52DB6CDAC5BC7A1FC884E97C41C91213

Located: HK_CU:Run, RoboForm
where: S-1-5-21-310056545-2846266270-3799731783-1000…
command: "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
file: C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
size: 160328
MD5: DAB4CF23E3E5A81B01BE8E3664965AF1

Located: HK_CU:Run, SUPERAntiSpyware
where: S-1-5-21-310056545-2846266270-3799731783-1000…
command: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
file: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
size: 2957040
MD5: 24C4194E6636570F7931BA6A96798FE2

Located: Startup (user), GigaTribe.lnk
where: C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup…
command: C:\Program Files (x86)\GigaTribe\gigatribe.exe
file: C:\Program Files (x86)\GigaTribe\gigatribe.exe
size: 4358144
MD5: A40A3C9A80F6E5E85D201470A8847659

Located: Startup (user), X3watch.lnk
where: C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup…
command: C:\Program Files (x86)\X3watch\x3watch.exe
file: C:\Program Files (x86)\X3watch\x3watch.exe
size: 299008
MD5: 5874152545D734CB74960189D9B29B46



— Browser helper object list —
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} (AcroIEHelperStub)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: AcroIEHelperStub
CLSID name: Adobe PDF Link Helper
Path: C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\
Long name: AcroIEHelperShim.dll
Short name: ACROIE~2.DLL
Date (created): 6/19/2010 3:29:34 PM
Date (last access): 7/2/2010 7:51:02 PM
Date (last write): 6/19/2010 3:29:34 PM
Filesize: 75200
Attributes: archive
MD5: 6D9042F1443A601DA8DC24D991EDDD0A
CRC32: 10990AC8
Version: 9.3.3.177

{5C255C8A-E604-49b4-9D64-90988571CECB} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:

{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} (Search Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: Search Helper
CLSID name: Search Helper
Path: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\
Long name: SEPsearchhelperie.dll
Short name: SEPSEA~1.DLL
Date (created): 5/14/2010 11:00:26 AM
Date (last access): 6/10/2010 3:06:16 AM
Date (last write): 5/14/2010 11:00:26 AM
Filesize: 191792
Attributes: archive
MD5: 69974B4FB022B6FB8691BF537B4C1A26
CRC32: FFCD8C8F
Version: 3.0.126.0

{724d43a9-0d85-11d4-9908-00400523e39a} (RoboForm)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: RoboForm
CLSID name:
description: RoboForm
classification: Legitimate
known filename: RoboForm.dll
info link: http://www.roboform.com/
info source: TonyKlein
Path: C:\Program Files (x86)\Siber Systems\AI RoboForm\
Long name: roboform.dll
Short name:
Date (created): 1/19/2010 5:23:20 PM
Date (last access): 1/19/2010 5:23:20 PM
Date (last write): 3/8/2010 12:18:12 PM
Filesize: 6021696
Attributes: archive
MD5: 4A4DC87BE203BE1D7EB219C28863A8D4
CRC32: 444C5D15
Version: 6.9.99.0

{9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Windows Live Sign-in Helper
Path: C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\
Long name: WindowsLiveLogin.dll
Short name: WINDOW~1.DLL
Date (created): 1/22/2009 5:41:30 PM
Date (last access): 1/11/2010 4:51:22 PM
Date (last write): 1/22/2009 5:41:30 PM
Filesize: 408448
Attributes: archive
MD5: B7899C3E21B299D7A3C0DA96CAE340BD
CRC32: 288935F8
Version: 5.0.818.5

{DBC80044-A445-435b-BC74-9C25C1C588A9} (Java™ Plug-In 2 SSV Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Java™ Plug-In 2 SSV Helper
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: jp2ssv.dll
Short name:
Date (created): 5/29/2010 4:23:36 PM
Date (last access): 5/29/2010 4:23:36 PM
Date (last write): 5/29/2010 4:23:36 PM
Filesize: 41760
Attributes: archive
MD5: 385BD69743EA92E76CDF07B3345A25D5
CRC32: D47CB5BA
Version: 6.0.200.2

{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} (Windows Live Toolbar Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Windows Live Toolbar Helper
Path: C:\Program Files (x86)\Windows Live\Toolbar\
Long name: wltcore.dll
Short name:
Date (created): 2/6/2009 8:17:46 PM
Date (last access): 1/11/2010 4:53:14 PM
Date (last write): 2/6/2009 8:17:46 PM
Filesize: 1068904
Attributes: archive
MD5: 28455424E3C8B81661C5A40E18066BB1
CRC32: E5BA354B
Version: 14.0.8064.206



— ActiveX list —
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_20
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: jp2iexp.dll
Short name:
Date (created): 5/29/2010 4:23:36 PM
Date (last access): 5/29/2010 4:23:36 PM
Date (last write): 5/29/2010 4:23:36 PM
Filesize: 108320
Attributes: archive
MD5: 3F7C69FF524EC11535342108A350A76F
CRC32: 28370E95
Version: 6.0.200.2

{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_20
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: jp2iexp.dll
Short name:
Date (created): 5/29/2010 4:23:36 PM
Date (last access): 5/29/2010 4:23:36 PM
Date (last write): 5/29/2010 4:23:36 PM
Filesize: 108320
Attributes: archive
MD5: 3F7C69FF524EC11535342108A350A76F
CRC32: 28370E95
Version: 6.0.200.2

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_20
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
description:
classification: Legitimate
known filename: npjpi150_06.dll
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: npjpi160_20.dll
Short name: NPJPI1~1.DLL
Date (created): 5/29/2010 4:23:40 PM
Date (last access): 5/29/2010 4:23:40 PM
Date (last write): 5/29/2010 4:23:40 PM
Filesize: 136992
Attributes: archive
MD5: E06930C34F16C8AD24AD79502F40026A
CRC32: 529E0B62
Version: 6.0.200.2

{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
Installer: C:\Windows\Downloaded Program Files\swflash.inf
Codebase: http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\Windows\SysWow64\Macromed\Flash\
Long name: Flash10e.ocx
Short name:
Date (created): 1/26/2010 8:58:36 PM
Date (last access): 4/2/2010 8:33:02 AM
Date (last write): 1/26/2010 8:58:36 PM
Filesize: 3981080
Attributes: readonly archive
MD5: C06E6E160F34CE092301BD2B29067F3F
CRC32: D922F8F5
Version: 10.0.45.2



— Process list —
PID: 0 ( 0) [System]
PID: 2352 (1788) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
size: 186904
MD5: 5AF1E9600E3FF841E522703A4993ED0C
PID: 2376 (1788) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
size: 160328
MD5: DAB4CF23E3E5A81B01BE8E3664965AF1
PID: 2536 (2416) C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
size: 140520
MD5: 1F5A26DF97C33CD24A8ED4D4A1FF1348
PID: 2544 (2416) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
size: 409744
MD5: 80B62FF105908EC9E4B072AFB1CFC824
PID: 2552 (2416) C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
size: 498160
MD5: 0647EF247A5D0402E74FE89F5F6A8A11
PID: 2560 (2416) C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
size: 206064
MD5: 00D1FB0073B4A8BD2989EA8FF4CC792B
PID: 2584 (2416) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
size: 2837864
MD5: 38AE7A942FC3FAB1C6A27EB65DE8F827
PID: 2608 (2416) C:\Program Files (x86)\iTunes\iTunesHelper.exe
size: 141600
MD5: 68A553BDFA855C4F1074696682FCDEB6
PID: 2620 (2416) C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
size: 30192
MD5: 9F5F2F0FB0A7F5AA9F16B9A7B6DAD89F
PID: 2700 (2416) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe
size: 1159168
MD5: 4D5D968FE6AE6BF94A807F73F7FF6B3D
PID: 2796 (2620) C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
size: 30192
MD5: 9F5F2F0FB0A7F5AA9F16B9A7B6DAD89F
PID: 2936 (2416) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
size: 248040
MD5: 52DB6CDAC5BC7A1FC884E97C41C91213
PID: 3040 (2788) C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe
size: 872448
MD5: 36E5CA5DCE72A831A3F7C7ED8AEA83AE
PID: 2456 (1788) C:\Program Files (x86)\X3watch\x3watch.exe
size: 299008
MD5: 5874152545D734CB74960189D9B29B46
PID: 3252 (2700) C:\Program Files (x86)\Brother\Brmfcmon\BrMfimon.exe
size: 143360
MD5: 03ED4235F1E428A79B86287E6AD108F4
PID: 152 (1788) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
size: 113488
MD5: 5EBA224D227654AD998EFFDCD1B30BFE
PID: 3448 ( 648) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
size: 27512
MD5: 654480EA67078C7B4C6C8BA871B07D5D
PID: 5028 (1788) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
size: 7678568
MD5: 8F93743D81634DB09023C41154B3E320
PID: 5816 (1788) C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
size: 5365592
MD5: 0477C2F9171599CA5BC3307FDFBA8D89
PID: 4 ( 0) System
PID: 272 ( 4) smss.exe
PID: 364 ( 348) csrss.exe
PID: 416 ( 348) wininit.exe
size: 96256
PID: 432 ( 408) csrss.exe
PID: 492 ( 408) winlogon.exe
PID: 504 ( 416) services.exe
PID: 528 ( 416) lsass.exe
PID: 540 ( 416) lsm.exe
PID: 648 ( 504) svchost.exe
size: 20992
PID: 740 ( 504) svchost.exe
size: 20992
PID: 836 ( 504) svchost.exe
size: 20992
PID: 884 ( 504) svchost.exe
size: 20992
PID: 912 ( 504) svchost.exe
size: 20992
PID: 948 ( 504) stacsv64.exe
PID: 332 ( 504) svchost.exe
size: 20992
PID: 1048 ( 504) DockLogin.exe
PID: 1184 ( 504) svchost.exe
size: 20992
PID: 1264 ( 504) WLTRYSVC.EXE
PID: 1272 ( 884) wlanext.exe
size: 77312
PID: 1280 ( 364) conhost.exe
PID: 1316 (1264) BCMWLTRY.EXE
PID: 1360 ( 504) AvastSvc.exe
PID: 1764 ( 884) C:\Windows\System32\dwm.exe
PID: 1788 (1752) C:\Windows\explorer.exe
size: 2870272
MD5: 9AAAEC8DAC27AA17B053E6352AD233AE
PID: 1908 ( 504) spoolsv.exe
PID: 1944 ( 504) svchost.exe
size: 20992
PID: 1960 ( 504) C:\Windows\System32\taskhost.exe
PID: 1500 ( 504) SASCore64.exe
PID: 1468 ( 504) AppleMobileDeviceService.exe
PID: 1460 ( 504) mDNSResponder.exe
PID: 2020 ( 504) svchost.exe
size: 20992
PID: 2076 (1788) C:\Program Files\DellTPad\Apoint.exe
size: 305664
MD5: 5FA0584E20C0E983F83FAABBF42DFFFA
PID: 2096 (1788) C:\Program Files\IDT\WDM\sttray64.exe
size: 444416
MD5: 5F3D8F0243E653BEDEB9AC6F04B7CF79
PID: 2104 (1788) C:\Windows\System32\igfxtray.exe
PID: 2172 (1788) C:\Windows\System32\hkcmd.exe
PID: 2252 (1788) C:\Windows\System32\igfxpers.exe
PID: 2260 ( 648) C:\Windows\System32\igfxsrvc.exe
PID: 2308 (1788) C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
size: 4968960
MD5: 1F83CB91A9830038DBE7CD1BA1921205
PID: 2344 (1788) C:\Program Files\Dell\QuickSet\quickset.exe
size: 3180624
MD5: B60457F40BBF5EAE380FC110B21C4978
PID: 2408 (1788) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
size: 2957040
MD5: 24C4194E6636570F7931BA6A96798FE2
PID: 3636 ( 504) SeaPort.exe
PID: 3684 ( 504) svchost.exe
size: 20992
PID: 3720 ( 504) svchost.exe
size: 20992
PID: 3764 ( 504) IAANTmon.exe
PID: 3940 ( 504) SDWinSec.exe
size: 1153368
MD5: 794D4B48DFB6E999537C7C3947863463
PID: 864 ( 648) WmiPrvSE.exe
PID: 3820 ( 504) SearchIndexer.exe
size: 428032
PID: 1412 ( 504) iPodService.exe
PID: 4656 (2076) ApMsgFwd.exe
PID: 4680 (4672) C:\Program Files\DellTPad\ApntEx.exe
size: 23552
MD5: 9D9B61AF3DBDC1490CBC508C8380510B
PID: 4700 ( 432) C:\Windows\System32\conhost.exe
PID: 4716 (2076) C:\Program Files\DellTPad\hidfind.exe
size: 91648
MD5: D7FCD621FC17B4EDD453D0F5C22A7DA6
PID: 4996 ( 504) wmpnetwk.exe
PID: 2200 ( 504) svchost.exe
size: 20992
PID: 2528 ( 504) sprtsvc.exe
PID: 356 (3820) SearchProtocolHost.exe
size: 164352
PID: 1100 (3820) SearchFilterHost.exe
size: 86528


— Browser start & search pages list —
Spybot - Search & Destroy browser pages report, 7/12/2010 11:46:30 AM

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\Windows\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.google.com
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
Preserve
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.google.com/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
http://www.google.com/search/?q=%s
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
C:\Windows\SysWOW64\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://go.microsoft.com/fwlink/?LinkId=54896


— Winsock Layered Service Provider list —
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 3: MSAFD Tcpip [TCP/IPv6]
GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IPv6 protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 4: MSAFD Tcpip [UDP/IPv6]
GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IPv6 protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 5: MSAFD Tcpip [RAW/IPv6]
GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IPv6 protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 6: RSVP TCPv6 Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 7: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 8: RSVP UDPv6 Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 9: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Namespace Provider 0: Network Location Awareness Legacy (NLAv1) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename:
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace

Namespace Provider 1: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename:
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP

Namespace Provider 2: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS

Namespace Provider 3: E-mail Naming Shim Provider
GUID: {964ACBA2-B2BC-40EB-8C6A-A6DB40161CAE}
Filename:

Namespace Provider 4: PNRP Cloud Namespace Provider
GUID: {03FE89CE-766D-4976-B9C1-BB9BC42C7B4D}
Filename:

Namespace Provider 5: PNRP Name Namespace Provider
GUID: {03FE89CD-766D-4976-B9C1-BB9BC42C7B4D}
Filename:
Hello Amy :thumbup:

Well, not all AVs are the same, what one program finds another may not but you still need it so do not ever uninstall it. Spyware programs are the same way, this one just may not have been added to the database yet for removal.

You can try this, open Firefox and go to Tools> Options> Privacy > Exceptions and then type these in and select block

win32.pornpopup
win32.pornpopup.com
win32.pornpopup.net


You can do the same for IE

Open IE and go to Tools> Internet Options > Privacy Tab > Sites and add the above in

I am glad we finally got rid of it. I will leave this thread open for you for a few days, please post back and let me know how its going
It's back. I wish I knew what the name of the cookie was so that I could block it. Is there a danger in blocking all cookies?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI