This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

An ounce of prevention

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I recently purchased a new lap top this spring. And getting that 2010 anti virus malware today on my work PC made me realize I need to protect my laptop better! I'm just looking for ways to tweek my system, make my laptop more secure. I currently use Trend Micro to protect me, but is there more I can be doing? I downloaded Malwarebytes and ran it tonight with nothing found. I want to keep it that way! I've had such good luck in the past when i come here with problems, I thought I"d come back again to get advice on preventlon!!! thank you guys for all your help!! Don't know what I"d do without you! Dar
Hello,

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 48 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________


If you are using Win 7/Vista, you will need to right click and choose "Run as Administrator" to run the tools we will use.


Since you are here, might as well take a better at look at your pc? :)

Will give you advise afterwards.

Please do the following:

OTL:
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on your C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
–Next–

[external image: Posted Image]
Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
  • Double click GMER.exe.
    [external image: Posted Image]
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
      [external image: Posted Image]
      Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Please copy and paste the report into your Post.

To post in your next reply:
1. OTL logs.
2. GMER log.
OTL.TXT FILE:

OTL logfile created on: 8/7/2010 10:11:43 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\DARLENE'S\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453.66 Gb Total Space | 341.57 Gb Free Space | 75.29% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DARLENES-PC
Current User Name: DARLENE'S
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/08/04 19:08:03 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\OTL.exe
PRC - [2010/07/19 06:28:47 | 000,353,736 | —- | M] (IncrediMail, Ltd.) – C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
PRC - [2010/07/19 06:28:46 | 000,255,432 | —- | M] (IncrediMail, Ltd.) – C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
PRC - [2010/06/29 02:47:30 | 000,304,448 | —- | M] (Smilebox, Inc.) – C:\Users\DARLENE'S\AppData\Roaming\Smilebox\SmileboxTray.exe
PRC - [2010/03/30 08:29:14 | 001,676,128 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Office\Office14\ONENOTE.EXE
PRC - [2010/03/29 20:26:00 | 000,227,712 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2010/03/17 16:53:24 | 000,207,872 | —- | M] (Alcatel-Lucent) – C:\Program Files (x86)\Common Files\Motive\McciContextHookShim.exe
PRC - [2010/02/24 18:12:30 | 000,242,560 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/12/17 06:51:23 | 000,039,408 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/10/29 16:31:16 | 000,244,480 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe
PRC - [2009/10/29 16:31:00 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
PRC - [2009/10/13 15:25:54 | 000,186,904 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/10/13 15:25:30 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2009/09/30 08:01:32 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/09/30 08:01:30 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/09/17 02:50:14 | 001,157,640 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2009/08/28 05:38:58 | 001,150,496 | —- | M] (Acer Incorporated) – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
PRC - [2009/08/03 12:05:48 | 000,498,160 | —- | M] () – C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2009/07/28 17:29:40 | 001,507,448 | —- | M] (Suyin) – C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe
PRC - [2009/07/03 22:47:12 | 000,240,160 | —- | M] (Acer) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
PRC - [2009/06/30 21:24:46 | 000,762,224 | —- | M] (Microsoft Corporation) – C:\Windows\vVX3000.exe
PRC - [2009/04/16 03:52:06 | 000,091,432 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) – C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe


========== Modules (SafeList) ==========

MOD - [2010/08/04 19:08:03 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\OTL.exe
MOD - [2009/07/13 21:15:36 | 000,022,016 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\linkinfo.dll
MOD - [2009/07/13 21:14:10 | 000,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/13 21:09:00 | 000,002,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\normaliz.dll
MOD - [2009/07/13 21:03:50 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/06/29 13:49:27 | 000,128,752 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE – (!SASCORE)
SRV:64bit: - [2010/06/04 18:23:38 | 000,055,648 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2010/05/26 13:37:18 | 002,290,048 | —- | M] (Microsoft Corp.) [Auto | Running] – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE – (wlidsvc)
SRV:64bit: - [2010/03/29 21:16:03 | 000,917,768 | —- | M] (Trend Micro Inc.) [On_Demand | Running] – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe – (TmProxy)
SRV:64bit: - [2010/03/29 21:16:03 | 000,836,432 | —- | M] (Trend Micro Inc.) [Auto | Running] – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe – (SfCtlCom)
SRV:64bit: - [2010/03/29 21:16:03 | 000,570,632 | —- | M] (Trend Micro Inc.) [On_Demand | Running] – C:\Program Files\Trend Micro\BM\TMBMSRV.exe – (TMBMServer)
SRV:64bit: - [2009/11/02 16:48:18 | 000,126,352 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\TurboBoost\TurboBoost.exe – (TurboBoost)
SRV:64bit: - [2009/10/29 15:10:02 | 000,844,320 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe – (ePowerSvc)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/03 22:47:12 | 000,240,160 | —- | M] (Acer) [Auto | Running] – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe – (Updater Service)
SRV - [2010/03/18 14:27:14 | 000,138,576 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_64)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/02/24 18:12:30 | 000,242,560 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2009/10/29 16:31:00 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) [Auto | Running] – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe – (NTI IScheduleSvc)
SRV - [2009/10/13 15:25:30 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2009/09/30 08:01:32 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2009/09/30 08:01:30 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/08/28 05:38:58 | 001,150,496 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe – (Greg_Service)
SRV - [2009/04/28 23:21:18 | 000,436,736 | —- | M] (Conexant Systems, Inc.) [Auto | Running] – C:\Windows\SysWOW64\XAudio64.dll – (HsfXAudioService)
SRV - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Running] – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
SRV - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/04/21 18:18:46 | 010,326,784 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/03/29 21:16:12 | 000,107,536 | —- | M] (Trend Micro Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\tmtdi.sys – (tmtdi)
DRV:64bit: - [2010/02/17 14:23:05 | 000,014,920 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2010/02/17 14:23:05 | 000,012,360 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2009/12/04 12:40:30 | 000,265,744 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\tmxpflt.sys – (tmxpflt)
DRV:64bit: - [2009/12/04 12:39:44 | 000,042,000 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\tmpreflt.sys – (tmpreflt)
DRV:64bit: - [2009/12/04 12:30:22 | 002,007,056 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\vsapint.sys – (vsapint)
DRV:64bit: - [2009/11/06 00:56:06 | 001,550,848 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2009/11/02 16:48:02 | 000,013,784 | —- | M] () [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\TurboB.sys – (TurboB)
DRV:64bit: - [2009/10/29 18:56:34 | 000,244,736 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2009/10/26 00:39:44 | 000,151,936 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/10/23 01:27:12 | 000,307,760 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2009/10/13 15:16:40 | 000,409,624 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/09/17 00:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/09/01 21:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2009/08/05 16:43:58 | 000,320,040 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\k57nd60a.sys – (k57nd60a) Broadcom NetLink ™
DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 17:59:33 | 005,020,672 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/07/09 07:00:00 | 000,055,280 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2009/06/30 21:24:50 | 002,060,144 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VX3000.sys – (VX3000)
DRV:64bit: - [2009/06/24 06:23:24 | 000,205,472 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtHDMIVX.sys – (RTHDMIAzAudService)
DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/08 19:08:00 | 000,020,520 | —- | M] (GARMIN Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\grmnusb.sys – (grmnusb)
DRV:64bit: - [2009/05/05 20:46:08 | 000,018,432 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2009/05/05 20:46:08 | 000,016,896 | —- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV:64bit: - [2009/04/28 23:21:08 | 000,010,240 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\XAudio64.sys – (XAudio)
DRV:64bit: - [2009/02/12 10:24:56 | 001,485,824 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAX_DPV.sys – (HSF_DPV)
DRV:64bit: - [2009/02/12 10:20:56 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAXHWAZL.sys – (CAXHWAZL)
DRV:64bit: - [2009/02/12 10:19:34 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAX_CNXT.sys – (winachsf)
DRV:64bit: - [2006/06/17 18:27:24 | 000,017,024 | —- | M] (Conexant) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\mdmxsdk.sys – (mdmxsdk)
DRV - [2010/03/17 16:53:38 | 000,021,248 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2010/03/17 16:53:22 | 000,020,096 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2009/09/01 21:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV - [2009/03/25 23:16:08 | 000,025,608 | —- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysWOW64\Drivers\DKbFltr.sys – (DKbFltr) Dritek Keyboard Filter Driver (64-bit)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://forums.whatthetech.com/index.php?sh…mp;#entry673572
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "https://addons.mozilla.org/en-US/firefox/search/?sort=weeklydownloads&pp;=20&pid;=1&cat;=all&q;=remember+password&lver;=3.6|http://sn122w.snt122.mail.live.com/default.aspx?wa=wsignin1.0|http://www.facebook.com/PeachyDar|http://www.youtube.com/user/PEACHYDAR1|http://www.legacy.com/obituaries/postgazette/obituary-browse.aspx?page=1&recentdate;=0&entriesperpage;=25|http://www.designsbysick.com/votingresults|http://www.sewforum.com/viewforum.php?f=16"
FF - prefs.js..extensions.enabledItems: {3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}:2.2
FF - prefs.js..extensions.enabledItems: [removed]:6.0
FF - prefs.js..extensions.enabledItems: {27182e60-b5f3-411c-b545-b44205977502}:1.0
FF - prefs.js..extensions.enabledItems: morningCoffee@shaneliesegang:1.33
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/06/25 23:13:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\Firefox [2010/06/25 23:16:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/06/25 23:16:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/08/04 19:50:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/08/04 19:50:14 | 000,000,000 | —D | M]

[2010/08/04 19:50:45 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Extensions
[2010/08/04 20:40:42 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions
[2010/08/04 20:40:41 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\morningCoffee@shaneliesegang
[2010/08/04 19:50:16 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files (x86)\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [DriverAccess] C:\Program Files (x86)\Driver Assure Corp\DriverAccess\DriverAccess.exe File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4:64bit: - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
O4:64bit: - HKLM..\Run: [VX3000] C:\Windows\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VideoWebCamera] C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe (Suyin)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files (x86)\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SmileboxTray] C:\Users\DARLENE'S\AppData\Roaming\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint Preview - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8:64bit: - Extra context menu item: Se&nd; to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {2FF8D282-F78A-4A33-ABC2-49E72A341482} http://riteaid.storefront.com/images/globa…eUpload1_10.CAB (SFImageUpload1_10.ImageUpload)
O16 - DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} http://static.ak.facebook.com/fbplugin/win…b?1271503612707 (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl-esd.sun.com/update/1.4.2/jin…indows-i586.cab (Java Plug-in 1.4.2_19)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corp.)
O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/08/06 19:03:10 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\FREDERICK MD
[2010/08/04 20:59:22 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/08/04 20:59:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010/08/04 20:55:22 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\SUPERAntiSpyware.com
[2010/08/04 20:55:22 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/08/04 20:55:16 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2010/08/04 20:55:15 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/08/04 19:50:27 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Local\Mozilla
[2010/08/04 19:50:26 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\Mozilla
[2010/08/04 19:50:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2010/08/04 19:07:59 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\OTL.exe
[2010/08/04 18:50:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/08/04 18:32:52 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\Malwarebytes
[2010/08/04 18:29:47 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/08/04 18:29:46 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/08/04 18:29:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/08/04 18:29:46 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/08/01 11:25:02 | 000,000,000 | R–D | C] – C:\Users\DARLENE'S\Desktop\DESIGNS FROM SEWING ROOM
[2010/07/31 15:33:23 | 002,957,656 | —- | C] (PKWARE, Inc.) – C:\Users\DARLENE'S\Desktop\ZIPReader[1].exe
[2010/07/31 13:48:51 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Local\Unzip Wizard
[2010/07/31 13:48:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Unzip Wizard
[2010/07/31 12:37:11 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Documents\Outlook Files
[2010/07/30 06:14:34 | 000,000,000 | —D | C] – C:\Windows\en
[2010/07/30 06:10:57 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2010/07/28 20:00:11 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\Captured Videos
[2010/07/25 21:54:52 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\Mathew stands
[2010/07/18 15:58:57 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\TOUR AMERICA
[2010/07/18 14:38:36 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\BRP TUNNELS
[2010/07/17 16:07:05 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/07/14 22:21:07 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[1 C:\Users\DARLENE'S\Documents\*.tmp files -> C:\Users\DARLENE'S\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/07 10:14:10 | 012,058,624 | -HS- | M] () – C:\Users\DARLENE'S\NTUSER.DAT
[2010/08/07 09:54:37 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/07 09:29:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/07 07:38:25 | 000,001,299 | —- | M] () – C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2010/08/07 06:43:42 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/07 06:43:42 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/07 06:36:09 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/07 06:36:00 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/07 06:35:52 | 2962,309,120 | -HS- | M] () – C:\hiberfil.sys
[2010/08/06 21:48:07 | 004,656,790 | -H– | M] () – C:\Users\DARLENE'S\AppData\Local\IconCache.db
[2010/08/06 19:51:25 | 000,012,800 | —- | M] () – C:\Users\DARLENE'S\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/06 19:22:46 | 000,035,918 | —- | M] () – C:\Users\DARLENE'S\Documents\NEW TRIKE.wlmp
[2010/08/05 07:47:25 | 000,013,555 | —- | M] () – C:\Users\DARLENE'S\Documents\FREDERICK MD TO HOME'.xlsx
[2010/08/05 07:43:58 | 000,012,360 | —- | M] () – C:\Users\DARLENE'S\Documents\TO FREDERICK.xlsx
[2010/08/05 05:40:40 | 000,000,824 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfud.bin
[2010/08/05 05:40:08 | 000,000,824 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfss.bin
[2010/08/04 20:59:27 | 000,001,289 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/04 20:59:27 | 000,001,265 | —- | M] () – C:\Users\DARLENE'S\Desktop\Spybot - Search & Destroy.lnk
[2010/08/04 20:55:16 | 000,001,815 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/04 19:50:33 | 000,000,000 | —- | M] () – C:\Windows\nsreg.dat
[2010/08/04 19:50:18 | 000,001,970 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/08/04 19:50:18 | 000,001,946 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/08/04 19:08:03 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\OTL.exe
[2010/08/04 19:01:54 | 000,015,389 | —- | M] () – C:\Users\DARLENE'S\Desktop\AUGUST 4TH LOG
[2010/08/04 18:50:02 | 000,002,995 | —- | M] () – C:\Users\DARLENE'S\Desktop\HiJackThis.lnk
[2010/08/04 18:29:50 | 000,001,040 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/08/04 18:29:50 | 000,001,016 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/01 20:55:19 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/08/01 20:55:19 | 000,624,178 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/08/01 20:55:19 | 000,106,522 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/08/01 14:48:08 | 000,339,550 | —- | M] () – C:\Users\DARLENE'S\Desktop\goldwing trike md.jpg.png
[2010/07/31 15:33:17 | 002,957,656 | —- | M] (PKWARE, Inc.) – C:\Users\DARLENE'S\Desktop\ZIPReader[1].exe
[2010/07/31 12:37:17 | 000,001,138 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2010/07/31 12:01:11 | 000,000,064 | —- | M] () – C:\Users\DARLENE'S\Documents\Database1.laccdb
[2010/07/31 11:59:23 | 004,083,712 | —- | M] () – C:\Users\DARLENE'S\Documents\Database1.accdb
[2010/07/31 11:52:28 | 002,098,569 | —- | M] () – C:\Users\DARLENE'S\Documents\TP101918099_template.accdt
[2010/07/29 21:06:51 | 000,014,108 | —- | M] () – C:\Users\DARLENE'S\Documents\SHOPPING LIST.xlsx
[2010/07/28 18:30:44 | 000,002,347 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/07/25 15:50:46 | 000,135,779 | —- | M] () – C:\Users\DARLENE'S\Documents\LONGABERGER BASKET 2007 RIDE.wlmp
[2010/07/24 21:25:01 | 000,008,142 | —- | M] () – C:\Users\DARLENE'S\Documents\MATHEW SLEEPS OVER.wlmp
[2010/07/23 06:33:47 | 000,953,136 | —- | M] () – C:\Users\DARLENE'S\Documents\tee pee bags.docx
[2010/07/21 18:04:57 | 000,001,244 | —- | M] () – C:\Users\DARLENE'S\AppData\Roaming\wklnhst.dat
[2010/07/19 21:21:04 | 000,015,590 | —- | M] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 10 min.wlmp
[2010/07/19 20:43:36 | 000,013,699 | —- | M] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 18 MIN.wlmp
[2010/07/19 06:29:08 | 000,002,012 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk
[2010/07/18 21:25:30 | 000,201,554 | —- | M] () – C:\Users\DARLENE'S\Documents\BROOKVILLE BAT RIDE.wlmp
[2010/07/18 19:56:22 | 000,188,922 | —- | M] () – C:\Users\DARLENE'S\Documents\blackwater falls 2006.wlmp
[2010/07/17 15:23:38 | 000,097,586 | —- | M] () – C:\Users\DARLENE'S\Documents\ASHEVILLE DAY FIVE.wlmp
[2010/07/17 14:54:37 | 000,031,499 | —- | M] () – C:\Users\DARLENE'S\Documents\JUNE 2010 RIDE ITINERARY.xlsx
[2010/07/17 13:34:02 | 000,014,005 | —- | M] () – C:\Users\DARLENE'S\Documents\2006 GOLD WING MILES.xlsx
[2010/07/08 20:50:33 | 000,039,931 | —- | M] () – C:\Users\DARLENE'S\Documents\NC 2010 DIRECTIONS.xlsx
[1 C:\Users\DARLENE'S\Documents\*.tmp files -> C:\Users\DARLENE'S\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/06 19:22:46 | 000,035,918 | —- | C] () – C:\Users\DARLENE'S\Documents\NEW TRIKE.wlmp
[2010/08/05 07:47:25 | 000,013,555 | —- | C] () – C:\Users\DARLENE'S\Documents\FREDERICK MD TO HOME'.xlsx
[2010/08/05 07:43:57 | 000,012,360 | —- | C] () – C:\Users\DARLENE'S\Documents\TO FREDERICK.xlsx
[2010/08/04 20:59:27 | 000,001,289 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/04 20:59:27 | 000,001,265 | —- | C] () – C:\Users\DARLENE'S\Desktop\Spybot - Search & Destroy.lnk
[2010/08/04 20:55:16 | 000,001,815 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/04 19:50:33 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/08/04 19:50:18 | 000,001,970 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/08/04 19:50:18 | 000,001,946 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/08/04 19:01:54 | 000,015,389 | —- | C] () – C:\Users\DARLENE'S\Desktop\AUGUST 4TH LOG
[2010/08/04 18:50:02 | 000,002,995 | —- | C] () – C:\Users\DARLENE'S\Desktop\HiJackThis.lnk
[2010/08/04 18:29:50 | 000,001,040 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/08/04 18:29:50 | 000,001,016 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/01 14:48:08 | 000,339,550 | —- | C] () – C:\Users\DARLENE'S\Desktop\goldwing trike md.jpg.png
[2010/07/31 12:37:17 | 000,001,138 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2010/07/31 11:59:18 | 000,000,064 | —- | C] () – C:\Users\DARLENE'S\Documents\Database1.laccdb
[2010/07/31 11:52:45 | 004,083,712 | —- | C] () – C:\Users\DARLENE'S\Documents\Database1.accdb
[2010/07/31 11:52:36 | 002,098,569 | —- | C] () – C:\Users\DARLENE'S\Documents\TP101918099_template.accdt
[2010/07/29 05:52:59 | 000,001,299 | —- | C] () – C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2010/07/25 15:50:46 | 000,135,779 | —- | C] () – C:\Users\DARLENE'S\Documents\LONGABERGER BASKET 2007 RIDE.wlmp
[2010/07/24 21:25:01 | 000,008,142 | —- | C] () – C:\Users\DARLENE'S\Documents\MATHEW SLEEPS OVER.wlmp
[2010/07/23 06:33:47 | 000,953,136 | —- | C] () – C:\Users\DARLENE'S\Documents\tee pee bags.docx
[2010/07/19 20:44:40 | 000,015,590 | —- | C] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 10 min.wlmp
[2010/07/18 21:25:30 | 000,201,554 | —- | C] () – C:\Users\DARLENE'S\Documents\BROOKVILLE BAT RIDE.wlmp
[2010/07/18 19:56:22 | 000,188,922 | —- | C] () – C:\Users\DARLENE'S\Documents\blackwater falls 2006.wlmp
[2010/07/18 10:37:42 | 000,013,699 | —- | C] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 18 MIN.wlmp
[2010/07/17 15:23:38 | 000,097,586 | —- | C] () – C:\Users\DARLENE'S\Documents\ASHEVILLE DAY FIVE.wlmp
[2010/07/08 20:35:54 | 000,039,931 | —- | C] () – C:\Users\DARLENE'S\Documents\NC 2010 DIRECTIONS.xlsx
[2010/03/29 21:03:09 | 000,000,065 | —- | C] () – C:\Windows\wininit.ini
[2009/12/17 06:24:10 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2009/12/17 06:24:10 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/26 17:24:18 | 000,015,498 | —- | C] () – C:\Windows\VX3000.ini

========== LOP Check ==========

[2010/04/17 07:27:31 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Facebook
[2010/06/06 11:52:18 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\GARMIN
[2010/07/26 05:42:24 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Smilebox
[2010/03/28 18:43:41 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Template
[2010/06/05 06:54:31 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Windows Live Writer
[2010/06/20 06:46:48 | 000,000,366 | —- | M] () – C:\Windows\Tasks\Driver Fetch.job
[2010/07/14 05:18:43 | 000,032,586 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >
OTL.TXT FILE:

OTL logfile created on: 8/7/2010 10:11:43 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\DARLENE'S\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453.66 Gb Total Space | 341.57 Gb Free Space | 75.29% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DARLENES-PC
Current User Name: DARLENE'S
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/08/04 19:08:03 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\OTL.exe
PRC - [2010/07/19 06:28:47 | 000,353,736 | —- | M] (IncrediMail, Ltd.) – C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
PRC - [2010/07/19 06:28:46 | 000,255,432 | —- | M] (IncrediMail, Ltd.) – C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
PRC - [2010/06/29 02:47:30 | 000,304,448 | —- | M] (Smilebox, Inc.) – C:\Users\DARLENE'S\AppData\Roaming\Smilebox\SmileboxTray.exe
PRC - [2010/03/30 08:29:14 | 001,676,128 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Office\Office14\ONENOTE.EXE
PRC - [2010/03/29 20:26:00 | 000,227,712 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2010/03/17 16:53:24 | 000,207,872 | —- | M] (Alcatel-Lucent) – C:\Program Files (x86)\Common Files\Motive\McciContextHookShim.exe
PRC - [2010/02/24 18:12:30 | 000,242,560 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/12/17 06:51:23 | 000,039,408 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/10/29 16:31:16 | 000,244,480 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe
PRC - [2009/10/29 16:31:00 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
PRC - [2009/10/13 15:25:54 | 000,186,904 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/10/13 15:25:30 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2009/09/30 08:01:32 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/09/30 08:01:30 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/09/17 02:50:14 | 001,157,640 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2009/08/28 05:38:58 | 001,150,496 | —- | M] (Acer Incorporated) – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
PRC - [2009/08/03 12:05:48 | 000,498,160 | —- | M] () – C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2009/07/28 17:29:40 | 001,507,448 | —- | M] (Suyin) – C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe
PRC - [2009/07/03 22:47:12 | 000,240,160 | —- | M] (Acer) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
PRC - [2009/06/30 21:24:46 | 000,762,224 | —- | M] (Microsoft Corporation) – C:\Windows\vVX3000.exe
PRC - [2009/04/16 03:52:06 | 000,091,432 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) – C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe


========== Modules (SafeList) ==========

MOD - [2010/08/04 19:08:03 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\OTL.exe
MOD - [2009/07/13 21:15:36 | 000,022,016 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\linkinfo.dll
MOD - [2009/07/13 21:14:10 | 000,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/13 21:09:00 | 000,002,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\normaliz.dll
MOD - [2009/07/13 21:03:50 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/06/29 13:49:27 | 000,128,752 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE – (!SASCORE)
SRV:64bit: - [2010/06/04 18:23:38 | 000,055,648 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2010/05/26 13:37:18 | 002,290,048 | —- | M] (Microsoft Corp.) [Auto | Running] – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE – (wlidsvc)
SRV:64bit: - [2010/03/29 21:16:03 | 000,917,768 | —- | M] (Trend Micro Inc.) [On_Demand | Running] – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe – (TmProxy)
SRV:64bit: - [2010/03/29 21:16:03 | 000,836,432 | —- | M] (Trend Micro Inc.) [Auto | Running] – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe – (SfCtlCom)
SRV:64bit: - [2010/03/29 21:16:03 | 000,570,632 | —- | M] (Trend Micro Inc.) [On_Demand | Running] – C:\Program Files\Trend Micro\BM\TMBMSRV.exe – (TMBMServer)
SRV:64bit: - [2009/11/02 16:48:18 | 000,126,352 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\TurboBoost\TurboBoost.exe – (TurboBoost)
SRV:64bit: - [2009/10/29 15:10:02 | 000,844,320 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe – (ePowerSvc)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/03 22:47:12 | 000,240,160 | —- | M] (Acer) [Auto | Running] – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe – (Updater Service)
SRV - [2010/03/18 14:27:14 | 000,138,576 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_64)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/02/24 18:12:30 | 000,242,560 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2009/10/29 16:31:00 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) [Auto | Running] – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe – (NTI IScheduleSvc)
SRV - [2009/10/13 15:25:30 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2009/09/30 08:01:32 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2009/09/30 08:01:30 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/08/28 05:38:58 | 001,150,496 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe – (Greg_Service)
SRV - [2009/04/28 23:21:18 | 000,436,736 | —- | M] (Conexant Systems, Inc.) [Auto | Running] – C:\Windows\SysWOW64\XAudio64.dll – (HsfXAudioService)
SRV - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Running] – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
SRV - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/04/21 18:18:46 | 010,326,784 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/03/29 21:16:12 | 000,107,536 | —- | M] (Trend Micro Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\tmtdi.sys – (tmtdi)
DRV:64bit: - [2010/02/17 14:23:05 | 000,014,920 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2010/02/17 14:23:05 | 000,012,360 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2009/12/04 12:40:30 | 000,265,744 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\tmxpflt.sys – (tmxpflt)
DRV:64bit: - [2009/12/04 12:39:44 | 000,042,000 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\tmpreflt.sys – (tmpreflt)
DRV:64bit: - [2009/12/04 12:30:22 | 002,007,056 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\vsapint.sys – (vsapint)
DRV:64bit: - [2009/11/06 00:56:06 | 001,550,848 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2009/11/02 16:48:02 | 000,013,784 | —- | M] () [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\TurboB.sys – (TurboB)
DRV:64bit: - [2009/10/29 18:56:34 | 000,244,736 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2009/10/26 00:39:44 | 000,151,936 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/10/23 01:27:12 | 000,307,760 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2009/10/13 15:16:40 | 000,409,624 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/09/17 00:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/09/01 21:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2009/08/05 16:43:58 | 000,320,040 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\k57nd60a.sys – (k57nd60a) Broadcom NetLink ™
DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 17:59:33 | 005,020,672 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/07/09 07:00:00 | 000,055,280 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2009/06/30 21:24:50 | 002,060,144 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VX3000.sys – (VX3000)
DRV:64bit: - [2009/06/24 06:23:24 | 000,205,472 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtHDMIVX.sys – (RTHDMIAzAudService)
DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/08 19:08:00 | 000,020,520 | —- | M] (GARMIN Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\grmnusb.sys – (grmnusb)
DRV:64bit: - [2009/05/05 20:46:08 | 000,018,432 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2009/05/05 20:46:08 | 000,016,896 | —- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV:64bit: - [2009/04/28 23:21:08 | 000,010,240 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\XAudio64.sys – (XAudio)
DRV:64bit: - [2009/02/12 10:24:56 | 001,485,824 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAX_DPV.sys – (HSF_DPV)
DRV:64bit: - [2009/02/12 10:20:56 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAXHWAZL.sys – (CAXHWAZL)
DRV:64bit: - [2009/02/12 10:19:34 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAX_CNXT.sys – (winachsf)
DRV:64bit: - [2006/06/17 18:27:24 | 000,017,024 | —- | M] (Conexant) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\mdmxsdk.sys – (mdmxsdk)
DRV - [2010/03/17 16:53:38 | 000,021,248 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2010/03/17 16:53:22 | 000,020,096 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2009/09/01 21:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV - [2009/03/25 23:16:08 | 000,025,608 | —- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysWOW64\Drivers\DKbFltr.sys – (DKbFltr) Dritek Keyboard Filter Driver (64-bit)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://forums.whatthetech.com/index.php?sh…mp;#entry673572
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "https://addons.mozilla.org/en-US/firefox/search/?sort=weeklydownloads&pp;=20&pid;=1&cat;=all&q;=remember+password&lver;=3.6|http://sn122w.snt122.mail.live.com/default.aspx?wa=wsignin1.0|http://www.facebook.com/PeachyDar|http://www.youtube.com/user/PEACHYDAR1|http://www.legacy.com/obituaries/postgazette/obituary-browse.aspx?page=1&recentdate;=0&entriesperpage;=25|http://www.designsbysick.com/votingresults|http://www.sewforum.com/viewforum.php?f=16"
FF - prefs.js..extensions.enabledItems: {3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}:2.2
FF - prefs.js..extensions.enabledItems: [removed]:6.0
FF - prefs.js..extensions.enabledItems: {27182e60-b5f3-411c-b545-b44205977502}:1.0
FF - prefs.js..extensions.enabledItems: morningCoffee@shaneliesegang:1.33
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/06/25 23:13:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\Firefox [2010/06/25 23:16:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/06/25 23:16:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/08/04 19:50:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/08/04 19:50:14 | 000,000,000 | —D | M]

[2010/08/04 19:50:45 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Extensions
[2010/08/04 20:40:42 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions
[2010/08/04 20:40:41 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\morningCoffee@shaneliesegang
[2010/08/04 19:50:16 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files (x86)\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [DriverAccess] C:\Program Files (x86)\Driver Assure Corp\DriverAccess\DriverAccess.exe File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4:64bit: - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
O4:64bit: - HKLM..\Run: [VX3000] C:\Windows\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VideoWebCamera] C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe (Suyin)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files (x86)\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SmileboxTray] C:\Users\DARLENE'S\AppData\Roaming\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint Preview - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8:64bit: - Extra context menu item: Se&nd; to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {2FF8D282-F78A-4A33-ABC2-49E72A341482} http://riteaid.storefront.com/images/globa…eUpload1_10.CAB (SFImageUpload1_10.ImageUpload)
O16 - DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} http://static.ak.facebook.com/fbplugin/win…b?1271503612707 (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl-esd.sun.com/update/1.4.2/jin…indows-i586.cab (Java Plug-in 1.4.2_19)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corp.)
O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/08/06 19:03:10 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\FREDERICK MD
[2010/08/04 20:59:22 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/08/04 20:59:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010/08/04 20:55:22 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\SUPERAntiSpyware.com
[2010/08/04 20:55:22 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/08/04 20:55:16 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2010/08/04 20:55:15 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/08/04 19:50:27 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Local\Mozilla
[2010/08/04 19:50:26 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\Mozilla
[2010/08/04 19:50:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2010/08/04 19:07:59 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\OTL.exe
[2010/08/04 18:50:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/08/04 18:32:52 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\Malwarebytes
[2010/08/04 18:29:47 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/08/04 18:29:46 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/08/04 18:29:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/08/04 18:29:46 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/08/01 11:25:02 | 000,000,000 | R–D | C] – C:\Users\DARLENE'S\Desktop\DESIGNS FROM SEWING ROOM
[2010/07/31 15:33:23 | 002,957,656 | —- | C] (PKWARE, Inc.) – C:\Users\DARLENE'S\Desktop\ZIPReader[1].exe
[2010/07/31 13:48:51 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Local\Unzip Wizard
[2010/07/31 13:48:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Unzip Wizard
[2010/07/31 12:37:11 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Documents\Outlook Files
[2010/07/30 06:14:34 | 000,000,000 | —D | C] – C:\Windows\en
[2010/07/30 06:10:57 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2010/07/28 20:00:11 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\Captured Videos
[2010/07/25 21:54:52 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\Mathew stands
[2010/07/18 15:58:57 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\TOUR AMERICA
[2010/07/18 14:38:36 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\BRP TUNNELS
[2010/07/17 16:07:05 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/07/14 22:21:07 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[1 C:\Users\DARLENE'S\Documents\*.tmp files -> C:\Users\DARLENE'S\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/07 10:14:10 | 012,058,624 | -HS- | M] () – C:\Users\DARLENE'S\NTUSER.DAT
[2010/08/07 09:54:37 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/07 09:29:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/07 07:38:25 | 000,001,299 | —- | M] () – C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2010/08/07 06:43:42 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/07 06:43:42 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/07 06:36:09 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/07 06:36:00 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/07 06:35:52 | 2962,309,120 | -HS- | M] () – C:\hiberfil.sys
[2010/08/06 21:48:07 | 004,656,790 | -H– | M] () – C:\Users\DARLENE'S\AppData\Local\IconCache.db
[2010/08/06 19:51:25 | 000,012,800 | —- | M] () – C:\Users\DARLENE'S\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/06 19:22:46 | 000,035,918 | —- | M] () – C:\Users\DARLENE'S\Documents\NEW TRIKE.wlmp
[2010/08/05 07:47:25 | 000,013,555 | —- | M] () – C:\Users\DARLENE'S\Documents\FREDERICK MD TO HOME'.xlsx
[2010/08/05 07:43:58 | 000,012,360 | —- | M] () – C:\Users\DARLENE'S\Documents\TO FREDERICK.xlsx
[2010/08/05 05:40:40 | 000,000,824 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfud.bin
[2010/08/05 05:40:08 | 000,000,824 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfss.bin
[2010/08/04 20:59:27 | 000,001,289 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/04 20:59:27 | 000,001,265 | —- | M] () – C:\Users\DARLENE'S\Desktop\Spybot - Search & Destroy.lnk
[2010/08/04 20:55:16 | 000,001,815 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/04 19:50:33 | 000,000,000 | —- | M] () – C:\Windows\nsreg.dat
[2010/08/04 19:50:18 | 000,001,970 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/08/04 19:50:18 | 000,001,946 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/08/04 19:08:03 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\OTL.exe
[2010/08/04 19:01:54 | 000,015,389 | —- | M] () – C:\Users\DARLENE'S\Desktop\AUGUST 4TH LOG
[2010/08/04 18:50:02 | 000,002,995 | —- | M] () – C:\Users\DARLENE'S\Desktop\HiJackThis.lnk
[2010/08/04 18:29:50 | 000,001,040 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/08/04 18:29:50 | 000,001,016 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/01 20:55:19 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/08/01 20:55:19 | 000,624,178 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/08/01 20:55:19 | 000,106,522 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/08/01 14:48:08 | 000,339,550 | —- | M] () – C:\Users\DARLENE'S\Desktop\goldwing trike md.jpg.png
[2010/07/31 15:33:17 | 002,957,656 | —- | M] (PKWARE, Inc.) – C:\Users\DARLENE'S\Desktop\ZIPReader[1].exe
[2010/07/31 12:37:17 | 000,001,138 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2010/07/31 12:01:11 | 000,000,064 | —- | M] () – C:\Users\DARLENE'S\Documents\Database1.laccdb
[2010/07/31 11:59:23 | 004,083,712 | —- | M] () – C:\Users\DARLENE'S\Documents\Database1.accdb
[2010/07/31 11:52:28 | 002,098,569 | —- | M] () – C:\Users\DARLENE'S\Documents\TP101918099_template.accdt
[2010/07/29 21:06:51 | 000,014,108 | —- | M] () – C:\Users\DARLENE'S\Documents\SHOPPING LIST.xlsx
[2010/07/28 18:30:44 | 000,002,347 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/07/25 15:50:46 | 000,135,779 | —- | M] () – C:\Users\DARLENE'S\Documents\LONGABERGER BASKET 2007 RIDE.wlmp
[2010/07/24 21:25:01 | 000,008,142 | —- | M] () – C:\Users\DARLENE'S\Documents\MATHEW SLEEPS OVER.wlmp
[2010/07/23 06:33:47 | 000,953,136 | —- | M] () – C:\Users\DARLENE'S\Documents\tee pee bags.docx
[2010/07/21 18:04:57 | 000,001,244 | —- | M] () – C:\Users\DARLENE'S\AppData\Roaming\wklnhst.dat
[2010/07/19 21:21:04 | 000,015,590 | —- | M] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 10 min.wlmp
[2010/07/19 20:43:36 | 000,013,699 | —- | M] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 18 MIN.wlmp
[2010/07/19 06:29:08 | 000,002,012 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk
[2010/07/18 21:25:30 | 000,201,554 | —- | M] () – C:\Users\DARLENE'S\Documents\BROOKVILLE BAT RIDE.wlmp
[2010/07/18 19:56:22 | 000,188,922 | —- | M] () – C:\Users\DARLENE'S\Documents\blackwater falls 2006.wlmp
[2010/07/17 15:23:38 | 000,097,586 | —- | M] () – C:\Users\DARLENE'S\Documents\ASHEVILLE DAY FIVE.wlmp
[2010/07/17 14:54:37 | 000,031,499 | —- | M] () – C:\Users\DARLENE'S\Documents\JUNE 2010 RIDE ITINERARY.xlsx
[2010/07/17 13:34:02 | 000,014,005 | —- | M] () – C:\Users\DARLENE'S\Documents\2006 GOLD WING MILES.xlsx
[2010/07/08 20:50:33 | 000,039,931 | —- | M] () – C:\Users\DARLENE'S\Documents\NC 2010 DIRECTIONS.xlsx
[1 C:\Users\DARLENE'S\Documents\*.tmp files -> C:\Users\DARLENE'S\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/06 19:22:46 | 000,035,918 | —- | C] () – C:\Users\DARLENE'S\Documents\NEW TRIKE.wlmp
[2010/08/05 07:47:25 | 000,013,555 | —- | C] () – C:\Users\DARLENE'S\Documents\FREDERICK MD TO HOME'.xlsx
[2010/08/05 07:43:57 | 000,012,360 | —- | C] () – C:\Users\DARLENE'S\Documents\TO FREDERICK.xlsx
[2010/08/04 20:59:27 | 000,001,289 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/04 20:59:27 | 000,001,265 | —- | C] () – C:\Users\DARLENE'S\Desktop\Spybot - Search & Destroy.lnk
[2010/08/04 20:55:16 | 000,001,815 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/04 19:50:33 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/08/04 19:50:18 | 000,001,970 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/08/04 19:50:18 | 000,001,946 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/08/04 19:01:54 | 000,015,389 | —- | C] () – C:\Users\DARLENE'S\Desktop\AUGUST 4TH LOG
[2010/08/04 18:50:02 | 000,002,995 | —- | C] () – C:\Users\DARLENE'S\Desktop\HiJackThis.lnk
[2010/08/04 18:29:50 | 000,001,040 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/08/04 18:29:50 | 000,001,016 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/01 14:48:08 | 000,339,550 | —- | C] () – C:\Users\DARLENE'S\Desktop\goldwing trike md.jpg.png
[2010/07/31 12:37:17 | 000,001,138 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2010/07/31 11:59:18 | 000,000,064 | —- | C] () – C:\Users\DARLENE'S\Documents\Database1.laccdb
[2010/07/31 11:52:45 | 004,083,712 | —- | C] () – C:\Users\DARLENE'S\Documents\Database1.accdb
[2010/07/31 11:52:36 | 002,098,569 | —- | C] () – C:\Users\DARLENE'S\Documents\TP101918099_template.accdt
[2010/07/29 05:52:59 | 000,001,299 | —- | C] () – C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2010/07/25 15:50:46 | 000,135,779 | —- | C] () – C:\Users\DARLENE'S\Documents\LONGABERGER BASKET 2007 RIDE.wlmp
[2010/07/24 21:25:01 | 000,008,142 | —- | C] () – C:\Users\DARLENE'S\Documents\MATHEW SLEEPS OVER.wlmp
[2010/07/23 06:33:47 | 000,953,136 | —- | C] () – C:\Users\DARLENE'S\Documents\tee pee bags.docx
[2010/07/19 20:44:40 | 000,015,590 | —- | C] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 10 min.wlmp
[2010/07/18 21:25:30 | 000,201,554 | —- | C] () – C:\Users\DARLENE'S\Documents\BROOKVILLE BAT RIDE.wlmp
[2010/07/18 19:56:22 | 000,188,922 | —- | C] () – C:\Users\DARLENE'S\Documents\blackwater falls 2006.wlmp
[2010/07/18 10:37:42 | 000,013,699 | —- | C] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 18 MIN.wlmp
[2010/07/17 15:23:38 | 000,097,586 | —- | C] () – C:\Users\DARLENE'S\Documents\ASHEVILLE DAY FIVE.wlmp
[2010/07/08 20:35:54 | 000,039,931 | —- | C] () – C:\Users\DARLENE'S\Documents\NC 2010 DIRECTIONS.xlsx
[2010/03/29 21:03:09 | 000,000,065 | —- | C] () – C:\Windows\wininit.ini
[2009/12/17 06:24:10 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2009/12/17 06:24:10 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/26 17:24:18 | 000,015,498 | —- | C] () – C:\Windows\VX3000.ini

========== LOP Check ==========

[2010/04/17 07:27:31 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Facebook
[2010/06/06 11:52:18 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\GARMIN
[2010/07/26 05:42:24 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Smilebox
[2010/03/28 18:43:41 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Template
[2010/06/05 06:54:31 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Windows Live Writer
[2010/06/20 06:46:48 | 000,000,366 | —- | M] () – C:\Windows\Tasks\Driver Fetch.job
[2010/07/14 05:18:43 | 000,032,586 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >
FOUND IT!!!

OTL logfile created on: 8/7/2010 10:11:43 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\DARLENE'S\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453.66 Gb Total Space | 341.57 Gb Free Space | 75.29% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DARLENES-PC
Current User Name: DARLENE'S
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/08/04 19:08:03 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\OTL.exe
PRC - [2010/07/19 06:28:47 | 000,353,736 | —- | M] (IncrediMail, Ltd.) – C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
PRC - [2010/07/19 06:28:46 | 000,255,432 | —- | M] (IncrediMail, Ltd.) – C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
PRC - [2010/06/29 02:47:30 | 000,304,448 | —- | M] (Smilebox, Inc.) – C:\Users\DARLENE'S\AppData\Roaming\Smilebox\SmileboxTray.exe
PRC - [2010/03/30 08:29:14 | 001,676,128 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Office\Office14\ONENOTE.EXE
PRC - [2010/03/29 20:26:00 | 000,227,712 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2010/03/17 16:53:24 | 000,207,872 | —- | M] (Alcatel-Lucent) – C:\Program Files (x86)\Common Files\Motive\McciContextHookShim.exe
PRC - [2010/02/24 18:12:30 | 000,242,560 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/12/17 06:51:23 | 000,039,408 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/10/29 16:31:16 | 000,244,480 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe
PRC - [2009/10/29 16:31:00 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
PRC - [2009/10/13 15:25:54 | 000,186,904 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/10/13 15:25:30 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2009/09/30 08:01:32 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/09/30 08:01:30 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/09/17 02:50:14 | 001,157,640 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2009/08/28 05:38:58 | 001,150,496 | —- | M] (Acer Incorporated) – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
PRC - [2009/08/03 12:05:48 | 000,498,160 | —- | M] () – C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2009/07/28 17:29:40 | 001,507,448 | —- | M] (Suyin) – C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe
PRC - [2009/07/03 22:47:12 | 000,240,160 | —- | M] (Acer) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
PRC - [2009/06/30 21:24:46 | 000,762,224 | —- | M] (Microsoft Corporation) – C:\Windows\vVX3000.exe
PRC - [2009/04/16 03:52:06 | 000,091,432 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) – C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe


========== Modules (SafeList) ==========

MOD - [2010/08/04 19:08:03 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\OTL.exe
MOD - [2009/07/13 21:15:36 | 000,022,016 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\linkinfo.dll
MOD - [2009/07/13 21:14:10 | 000,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/13 21:09:00 | 000,002,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\normaliz.dll
MOD - [2009/07/13 21:03:50 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/06/29 13:49:27 | 000,128,752 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE – (!SASCORE)
SRV:64bit: - [2010/06/04 18:23:38 | 000,055,648 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2010/05/26 13:37:18 | 002,290,048 | —- | M] (Microsoft Corp.) [Auto | Running] – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE – (wlidsvc)
SRV:64bit: - [2010/03/29 21:16:03 | 000,917,768 | —- | M] (Trend Micro Inc.) [On_Demand | Running] – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe – (TmProxy)
SRV:64bit: - [2010/03/29 21:16:03 | 000,836,432 | —- | M] (Trend Micro Inc.) [Auto | Running] – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe – (SfCtlCom)
SRV:64bit: - [2010/03/29 21:16:03 | 000,570,632 | —- | M] (Trend Micro Inc.) [On_Demand | Running] – C:\Program Files\Trend Micro\BM\TMBMSRV.exe – (TMBMServer)
SRV:64bit: - [2009/11/02 16:48:18 | 000,126,352 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\TurboBoost\TurboBoost.exe – (TurboBoost)
SRV:64bit: - [2009/10/29 15:10:02 | 000,844,320 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe – (ePowerSvc)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/03 22:47:12 | 000,240,160 | —- | M] (Acer) [Auto | Running] – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe – (Updater Service)
SRV - [2010/03/18 14:27:14 | 000,138,576 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_64)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/02/24 18:12:30 | 000,242,560 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2009/10/29 16:31:00 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) [Auto | Running] – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe – (NTI IScheduleSvc)
SRV - [2009/10/13 15:25:30 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2009/09/30 08:01:32 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2009/09/30 08:01:30 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/08/28 05:38:58 | 001,150,496 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe – (Greg_Service)
SRV - [2009/04/28 23:21:18 | 000,436,736 | —- | M] (Conexant Systems, Inc.) [Auto | Running] – C:\Windows\SysWOW64\XAudio64.dll – (HsfXAudioService)
SRV - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Running] – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
SRV - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/04/21 18:18:46 | 010,326,784 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/03/29 21:16:12 | 000,107,536 | —- | M] (Trend Micro Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\tmtdi.sys – (tmtdi)
DRV:64bit: - [2010/02/17 14:23:05 | 000,014,920 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2010/02/17 14:23:05 | 000,012,360 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2009/12/04 12:40:30 | 000,265,744 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\tmxpflt.sys – (tmxpflt)
DRV:64bit: - [2009/12/04 12:39:44 | 000,042,000 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\tmpreflt.sys – (tmpreflt)
DRV:64bit: - [2009/12/04 12:30:22 | 002,007,056 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\vsapint.sys – (vsapint)
DRV:64bit: - [2009/11/06 00:56:06 | 001,550,848 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2009/11/02 16:48:02 | 000,013,784 | —- | M] () [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\TurboB.sys – (TurboB)
DRV:64bit: - [2009/10/29 18:56:34 | 000,244,736 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2009/10/26 00:39:44 | 000,151,936 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/10/23 01:27:12 | 000,307,760 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2009/10/13 15:16:40 | 000,409,624 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/09/17 00:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/09/01 21:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2009/08/05 16:43:58 | 000,320,040 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\k57nd60a.sys – (k57nd60a) Broadcom NetLink ™
DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 17:59:33 | 005,020,672 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/07/09 07:00:00 | 000,055,280 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2009/06/30 21:24:50 | 002,060,144 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VX3000.sys – (VX3000)
DRV:64bit: - [2009/06/24 06:23:24 | 000,205,472 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtHDMIVX.sys – (RTHDMIAzAudService)
DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/08 19:08:00 | 000,020,520 | —- | M] (GARMIN Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\grmnusb.sys – (grmnusb)
DRV:64bit: - [2009/05/05 20:46:08 | 000,018,432 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2009/05/05 20:46:08 | 000,016,896 | —- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV:64bit: - [2009/04/28 23:21:08 | 000,010,240 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\XAudio64.sys – (XAudio)
DRV:64bit: - [2009/02/12 10:24:56 | 001,485,824 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAX_DPV.sys – (HSF_DPV)
DRV:64bit: - [2009/02/12 10:20:56 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAXHWAZL.sys – (CAXHWAZL)
DRV:64bit: - [2009/02/12 10:19:34 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAX_CNXT.sys – (winachsf)
DRV:64bit: - [2006/06/17 18:27:24 | 000,017,024 | —- | M] (Conexant) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\mdmxsdk.sys – (mdmxsdk)
DRV - [2010/03/17 16:53:38 | 000,021,248 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2010/03/17 16:53:22 | 000,020,096 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2009/09/01 21:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV - [2009/03/25 23:16:08 | 000,025,608 | —- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysWOW64\Drivers\DKbFltr.sys – (DKbFltr) Dritek Keyboard Filter Driver (64-bit)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://forums.whatthetech.com/index.php?sh…mp;#entry673572
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "https://addons.mozilla.org/en-US/firefox/search/?sort=weeklydownloads&pp;=20&pid;=1&cat;=all&q;=remember+password&lver;=3.6|http://sn122w.snt122.mail.live.com/default.aspx?wa=wsignin1.0|http://www.facebook.com/PeachyDar|http://www.youtube.com/user/PEACHYDAR1|http://www.legacy.com/obituaries/postgazette/obituary-browse.aspx?page=1&recentdate;=0&entriesperpage;=25|http://www.designsbysick.com/votingresults|http://www.sewforum.com/viewforum.php?f=16"
FF - prefs.js..extensions.enabledItems: {3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}:2.2
FF - prefs.js..extensions.enabledItems: [removed]:6.0
FF - prefs.js..extensions.enabledItems: {27182e60-b5f3-411c-b545-b44205977502}:1.0
FF - prefs.js..extensions.enabledItems: morningCoffee@shaneliesegang:1.33
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/06/25 23:13:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\Firefox [2010/06/25 23:16:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/06/25 23:16:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/08/04 19:50:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/08/04 19:50:14 | 000,000,000 | —D | M]

[2010/08/04 19:50:45 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Extensions
[2010/08/04 20:40:42 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions
[2010/08/04 20:40:41 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\morningCoffee@shaneliesegang
[2010/08/04 19:50:16 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files (x86)\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [DriverAccess] C:\Program Files (x86)\Driver Assure Corp\DriverAccess\DriverAccess.exe File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4:64bit: - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
O4:64bit: - HKLM..\Run: [VX3000] C:\Windows\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VideoWebCamera] C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe (Suyin)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files (x86)\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SmileboxTray] C:\Users\DARLENE'S\AppData\Roaming\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint Preview - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8:64bit: - Extra context menu item: Se&nd; to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {2FF8D282-F78A-4A33-ABC2-49E72A341482} http://riteaid.storefront.com/images/globa…eUpload1_10.CAB (SFImageUpload1_10.ImageUpload)
O16 - DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} http://static.ak.facebook.com/fbplugin/win…b?1271503612707 (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl-esd.sun.com/update/1.4.2/jin…indows-i586.cab (Java Plug-in 1.4.2_19)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corp.)
O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/08/06 19:03:10 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\FREDERICK MD
[2010/08/04 20:59:22 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/08/04 20:59:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010/08/04 20:55:22 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\SUPERAntiSpyware.com
[2010/08/04 20:55:22 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/08/04 20:55:16 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2010/08/04 20:55:15 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/08/04 19:50:27 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Local\Mozilla
[2010/08/04 19:50:26 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\Mozilla
[2010/08/04 19:50:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2010/08/04 19:07:59 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\OTL.exe
[2010/08/04 18:50:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/08/04 18:32:52 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\Malwarebytes
[2010/08/04 18:29:47 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/08/04 18:29:46 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/08/04 18:29:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/08/04 18:29:46 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/08/01 11:25:02 | 000,000,000 | R–D | C] – C:\Users\DARLENE'S\Desktop\DESIGNS FROM SEWING ROOM
[2010/07/31 15:33:23 | 002,957,656 | —- | C] (PKWARE, Inc.) – C:\Users\DARLENE'S\Desktop\ZIPReader[1].exe
[2010/07/31 13:48:51 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Local\Unzip Wizard
[2010/07/31 13:48:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Unzip Wizard
[2010/07/31 12:37:11 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Documents\Outlook Files
[2010/07/30 06:14:34 | 000,000,000 | —D | C] – C:\Windows\en
[2010/07/30 06:10:57 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2010/07/28 20:00:11 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\Captured Videos
[2010/07/25 21:54:52 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\Mathew stands
[2010/07/18 15:58:57 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\TOUR AMERICA
[2010/07/18 14:38:36 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\BRP TUNNELS
[2010/07/17 16:07:05 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/07/14 22:21:07 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[1 C:\Users\DARLENE'S\Documents\*.tmp files -> C:\Users\DARLENE'S\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/07 10:14:10 | 012,058,624 | -HS- | M] () – C:\Users\DARLENE'S\NTUSER.DAT
[2010/08/07 09:54:37 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/07 09:29:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/07 07:38:25 | 000,001,299 | —- | M] () – C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2010/08/07 06:43:42 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/07 06:43:42 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/07 06:36:09 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/07 06:36:00 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/07 06:35:52 | 2962,309,120 | -HS- | M] () – C:\hiberfil.sys
[2010/08/06 21:48:07 | 004,656,790 | -H– | M] () – C:\Users\DARLENE'S\AppData\Local\IconCache.db
[2010/08/06 19:51:25 | 000,012,800 | —- | M] () – C:\Users\DARLENE'S\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/06 19:22:46 | 000,035,918 | —- | M] () – C:\Users\DARLENE'S\Documents\NEW TRIKE.wlmp
[2010/08/05 07:47:25 | 000,013,555 | —- | M] () – C:\Users\DARLENE'S\Documents\FREDERICK MD TO HOME'.xlsx
[2010/08/05 07:43:58 | 000,012,360 | —- | M] () – C:\Users\DARLENE'S\Documents\TO FREDERICK.xlsx
[2010/08/05 05:40:40 | 000,000,824 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfud.bin
[2010/08/05 05:40:08 | 000,000,824 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfss.bin
[2010/08/04 20:59:27 | 000,001,289 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/04 20:59:27 | 000,001,265 | —- | M] () – C:\Users\DARLENE'S\Desktop\Spybot - Search & Destroy.lnk
[2010/08/04 20:55:16 | 000,001,815 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/04 19:50:33 | 000,000,000 | —- | M] () – C:\Windows\nsreg.dat
[2010/08/04 19:50:18 | 000,001,970 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/08/04 19:50:18 | 000,001,946 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/08/04 19:08:03 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\OTL.exe
[2010/08/04 19:01:54 | 000,015,389 | —- | M] () – C:\Users\DARLENE'S\Desktop\AUGUST 4TH LOG
[2010/08/04 18:50:02 | 000,002,995 | —- | M] () – C:\Users\DARLENE'S\Desktop\HiJackThis.lnk
[2010/08/04 18:29:50 | 000,001,040 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/08/04 18:29:50 | 000,001,016 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/01 20:55:19 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/08/01 20:55:19 | 000,624,178 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/08/01 20:55:19 | 000,106,522 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/08/01 14:48:08 | 000,339,550 | —- | M] () – C:\Users\DARLENE'S\Desktop\goldwing trike md.jpg.png
[2010/07/31 15:33:17 | 002,957,656 | —- | M] (PKWARE, Inc.) – C:\Users\DARLENE'S\Desktop\ZIPReader[1].exe
[2010/07/31 12:37:17 | 000,001,138 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2010/07/31 12:01:11 | 000,000,064 | —- | M] () – C:\Users\DARLENE'S\Documents\Database1.laccdb
[2010/07/31 11:59:23 | 004,083,712 | —- | M] () – C:\Users\DARLENE'S\Documents\Database1.accdb
[2010/07/31 11:52:28 | 002,098,569 | —- | M] () – C:\Users\DARLENE'S\Documents\TP101918099_template.accdt
[2010/07/29 21:06:51 | 000,014,108 | —- | M] () – C:\Users\DARLENE'S\Documents\SHOPPING LIST.xlsx
[2010/07/28 18:30:44 | 000,002,347 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/07/25 15:50:46 | 000,135,779 | —- | M] () – C:\Users\DARLENE'S\Documents\LONGABERGER BASKET 2007 RIDE.wlmp
[2010/07/24 21:25:01 | 000,008,142 | —- | M] () – C:\Users\DARLENE'S\Documents\MATHEW SLEEPS OVER.wlmp
[2010/07/23 06:33:47 | 000,953,136 | —- | M] () – C:\Users\DARLENE'S\Documents\tee pee bags.docx
[2010/07/21 18:04:57 | 000,001,244 | —- | M] () – C:\Users\DARLENE'S\AppData\Roaming\wklnhst.dat
[2010/07/19 21:21:04 | 000,015,590 | —- | M] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 10 min.wlmp
[2010/07/19 20:43:36 | 000,013,699 | —- | M] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 18 MIN.wlmp
[2010/07/19 06:29:08 | 000,002,012 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk
[2010/07/18 21:25:30 | 000,201,554 | —- | M] () – C:\Users\DARLENE'S\Documents\BROOKVILLE BAT RIDE.wlmp
[2010/07/18 19:56:22 | 000,188,922 | —- | M] () – C:\Users\DARLENE'S\Documents\blackwater falls 2006.wlmp
[2010/07/17 15:23:38 | 000,097,586 | —- | M] () – C:\Users\DARLENE'S\Documents\ASHEVILLE DAY FIVE.wlmp
[2010/07/17 14:54:37 | 000,031,499 | —- | M] () – C:\Users\DARLENE'S\Documents\JUNE 2010 RIDE ITINERARY.xlsx
[2010/07/17 13:34:02 | 000,014,005 | —- | M] () – C:\Users\DARLENE'S\Documents\2006 GOLD WING MILES.xlsx
[2010/07/08 20:50:33 | 000,039,931 | —- | M] () – C:\Users\DARLENE'S\Documents\NC 2010 DIRECTIONS.xlsx
[1 C:\Users\DARLENE'S\Documents\*.tmp files -> C:\Users\DARLENE'S\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/06 19:22:46 | 000,035,918 | —- | C] () – C:\Users\DARLENE'S\Documents\NEW TRIKE.wlmp
[2010/08/05 07:47:25 | 000,013,555 | —- | C] () – C:\Users\DARLENE'S\Documents\FREDERICK MD TO HOME'.xlsx
[2010/08/05 07:43:57 | 000,012,360 | —- | C] () – C:\Users\DARLENE'S\Documents\TO FREDERICK.xlsx
[2010/08/04 20:59:27 | 000,001,289 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/04 20:59:27 | 000,001,265 | —- | C] () – C:\Users\DARLENE'S\Desktop\Spybot - Search & Destroy.lnk
[2010/08/04 20:55:16 | 000,001,815 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/04 19:50:33 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/08/04 19:50:18 | 000,001,970 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/08/04 19:50:18 | 000,001,946 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/08/04 19:01:54 | 000,015,389 | —- | C] () – C:\Users\DARLENE'S\Desktop\AUGUST 4TH LOG
[2010/08/04 18:50:02 | 000,002,995 | —- | C] () – C:\Users\DARLENE'S\Desktop\HiJackThis.lnk
[2010/08/04 18:29:50 | 000,001,040 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/08/04 18:29:50 | 000,001,016 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/01 14:48:08 | 000,339,550 | —- | C] () – C:\Users\DARLENE'S\Desktop\goldwing trike md.jpg.png
[2010/07/31 12:37:17 | 000,001,138 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2010/07/31 11:59:18 | 000,000,064 | —- | C] () – C:\Users\DARLENE'S\Documents\Database1.laccdb
[2010/07/31 11:52:45 | 004,083,712 | —- | C] () – C:\Users\DARLENE'S\Documents\Database1.accdb
[2010/07/31 11:52:36 | 002,098,569 | —- | C] () – C:\Users\DARLENE'S\Documents\TP101918099_template.accdt
[2010/07/29 05:52:59 | 000,001,299 | —- | C] () – C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2010/07/25 15:50:46 | 000,135,779 | —- | C] () – C:\Users\DARLENE'S\Documents\LONGABERGER BASKET 2007 RIDE.wlmp
[2010/07/24 21:25:01 | 000,008,142 | —- | C] () – C:\Users\DARLENE'S\Documents\MATHEW SLEEPS OVER.wlmp
[2010/07/23 06:33:47 | 000,953,136 | —- | C] () – C:\Users\DARLENE'S\Documents\tee pee bags.docx
[2010/07/19 20:44:40 | 000,015,590 | —- | C] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 10 min.wlmp
[2010/07/18 21:25:30 | 000,201,554 | —- | C] () – C:\Users\DARLENE'S\Documents\BROOKVILLE BAT RIDE.wlmp
[2010/07/18 19:56:22 | 000,188,922 | —- | C] () – C:\Users\DARLENE'S\Documents\blackwater falls 2006.wlmp
[2010/07/18 10:37:42 | 000,013,699 | —- | C] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 18 MIN.wlmp
[2010/07/17 15:23:38 | 000,097,586 | —- | C] () – C:\Users\DARLENE'S\Documents\ASHEVILLE DAY FIVE.wlmp
[2010/07/08 20:35:54 | 000,039,931 | —- | C] () – C:\Users\DARLENE'S\Documents\NC 2010 DIRECTIONS.xlsx
[2010/03/29 21:03:09 | 000,000,065 | —- | C] () – C:\Windows\wininit.ini
[2009/12/17 06:24:10 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2009/12/17 06:24:10 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/26 17:24:18 | 000,015,498 | —- | C] () – C:\Windows\VX3000.ini

========== LOP Check ==========

[2010/04/17 07:27:31 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Facebook
[2010/06/06 11:52:18 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\GARMIN
[2010/07/26 05:42:24 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Smilebox
[2010/03/28 18:43:41 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Template
[2010/06/05 06:54:31 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Windows Live Writer
[2010/06/20 06:46:48 | 000,000,366 | —- | M] () – C:\Windows\Tasks\Driver Fetch.job
[2010/07/14 05:18:43 | 000,032,586 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >
ARK.TXT FILE

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-07 10:33:16
Windows 6.1.7600
Running: gmer.exe


—- Registry - GMER 1.0.15 —-

Reg HKCU\Software\Microsoft\Windows Live\Companion\[removed]@bcc83232988af65e389bad2b38e95ae1\r\n 0x82 0x43 0x5A 0xC6 …
Reg HKCU\Software\Microsoft\Windows Live\Companion\[removed]@a2d8788a7bb8c88aa5853ace47e64533\r\n 0x9C 0x4C 0x52 0xED …
Reg HKCU\Software\Microsoft\Windows Live\Companion\[removed]@9cb660535e3b1ddabc72fc8637cecba5\r\n 0x23 0x0C 0xA0 0x1E …
Reg HKCU\Software\Microsoft\Windows Live\Companion\[removed]@e78b10df37f7d10e9314511ff1f29dd0\r\n 0x75 0xB9 0xFD 0x01 …

—- EOF - GMER 1.0.15 —-
Hi,

You have a lot of toolbars there. You use all of them?

Also, You have two anti spyware running on your computer, Spybot and Superantispyware. Running more than one anti spyware at the same time does not only slow down your computer but provides less protection than they are programmed to do, due to the fact that they will be conflicting with each other rather than providing sufficient protection for your computer. Please uninstall one of your anti spyware before proceeding with any of the fixes.


Please post Extras.Txt in your next reply as you've posted the same log.

–Next–

While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent our tools from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click Advanced mode if not already selected.
  • Choose Yes at the Warning prompt.
  • Expand the Tools menu.
  • Click Resident.
  • Uncheck the Resident TeaTimer (Protection of overall system settings) active. box.
  • In the File menu click Exit to exit Spybot Search & Destroy.
  • Reboot your computer.
    (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.)
–Next–

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • Then post the result and a new OTL log in your next reply. ( don't check the boxes beside LOP Check or Purity this time )
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


To post in your next reply:
1. Extras.txt.
2. OTL fix log.
3. Malwarebytes' log.
Sorry for the delay - we were out on the goldwing all weekend…..now back to business.

I now only have spy bot, I removed the super one. I cannot find the extras.txt file - so I am running the OTL again to see if I can locate it. I have tried to search for it - but it's just not there to find.

So I guess I am at a halt until this OTL is done running. there is no Extra.txt file - just this OTL file.

OTL logfile created on: 8/9/2010 8:09:08 PM - Run 2
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\DARLENE'S\Desktop\WEEKLY SCANS
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 54.00% Memory free
7.00 Gb Paging File | 5.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453.66 Gb Total Space | 337.41 Gb Free Space | 74.38% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DARLENES-PC
Current User Name: DARLENE'S
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/08/04 19:08:03 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\WEEKLY SCANS\OTL.exe
PRC - [2010/07/19 06:28:47 | 000,353,736 | —- | M] (IncrediMail, Ltd.) – C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
PRC - [2010/07/19 06:28:46 | 000,255,432 | —- | M] (IncrediMail, Ltd.) – C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
PRC - [2010/07/13 17:31:45 | 000,304,304 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
PRC - [2010/06/29 02:47:30 | 000,304,448 | —- | M] (Smilebox, Inc.) – C:\Users\DARLENE'S\AppData\Roaming\Smilebox\SmileboxTray.exe
PRC - [2010/06/14 17:55:20 | 000,231,888 | —- | M] (Adobe Systems, Inc.) – C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe
PRC - [2010/06/07 17:33:40 | 004,176,760 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
PRC - [2010/06/07 17:02:44 | 000,053,632 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Live\Companion\companionuser.exe
PRC - [2010/06/07 16:16:20 | 000,025,968 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
PRC - [2010/03/29 20:26:00 | 000,227,712 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2010/03/17 16:53:24 | 000,207,872 | —- | M] (Alcatel-Lucent) – C:\Program Files (x86)\Common Files\Motive\McciContextHookShim.exe
PRC - [2010/02/24 18:12:30 | 000,318,848 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
PRC - [2010/02/24 18:12:30 | 000,242,560 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/12/17 06:51:23 | 000,039,408 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/10/29 16:31:16 | 000,244,480 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe
PRC - [2009/10/29 16:31:00 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
PRC - [2009/10/13 15:25:54 | 000,186,904 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/10/13 15:25:30 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2009/09/30 08:01:32 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/09/30 08:01:30 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/09/17 02:50:14 | 001,157,640 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2009/08/28 05:38:58 | 001,150,496 | —- | M] (Acer Incorporated) – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
PRC - [2009/08/03 12:05:48 | 000,498,160 | —- | M] () – C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2009/07/28 17:29:40 | 001,507,448 | —- | M] (Suyin) – C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe
PRC - [2009/07/03 22:47:12 | 000,240,160 | —- | M] (Acer) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
PRC - [2009/06/30 21:24:46 | 000,762,224 | —- | M] (Microsoft Corporation) – C:\Windows\vVX3000.exe
PRC - [2009/04/16 03:52:06 | 000,091,432 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | —- | M] (Safer-Networking Ltd.) – C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe


========== Modules (SafeList) ==========

MOD - [2010/08/04 19:08:03 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\WEEKLY SCANS\OTL.exe
MOD - [2009/07/13 21:14:10 | 000,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/13 21:03:50 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - File not found [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE – (!SASCORE)
SRV:64bit: - [2010/06/04 18:23:38 | 000,055,648 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2010/05/26 13:37:18 | 002,290,048 | —- | M] (Microsoft Corp.) [Auto | Running] – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE – (wlidsvc)
SRV:64bit: - [2010/03/29 21:16:03 | 000,917,768 | —- | M] (Trend Micro Inc.) [On_Demand | Running] – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe – (TmProxy)
SRV:64bit: - [2010/03/29 21:16:03 | 000,836,432 | —- | M] (Trend Micro Inc.) [Auto | Running] – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe – (SfCtlCom)
SRV:64bit: - [2010/03/29 21:16:03 | 000,570,632 | —- | M] (Trend Micro Inc.) [On_Demand | Running] – C:\Program Files\Trend Micro\BM\TMBMSRV.exe – (TMBMServer)
SRV:64bit: - [2009/11/02 16:48:18 | 000,126,352 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\TurboBoost\TurboBoost.exe – (TurboBoost)
SRV:64bit: - [2009/10/29 15:10:02 | 000,844,320 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe – (ePowerSvc)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/03 22:47:12 | 000,240,160 | —- | M] (Acer) [Auto | Running] – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe – (Updater Service)
SRV - [2010/03/18 14:27:14 | 000,138,576 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_64)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/02/24 18:12:30 | 000,242,560 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2009/10/29 16:31:00 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) [Auto | Running] – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe – (NTI IScheduleSvc)
SRV - [2009/10/13 15:25:30 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2009/09/30 08:01:32 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2009/09/30 08:01:30 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/08/28 05:38:58 | 001,150,496 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe – (Greg_Service)
SRV - [2009/04/28 23:21:18 | 000,436,736 | —- | M] (Conexant Systems, Inc.) [Auto | Running] – C:\Windows\SysWOW64\XAudio64.dll – (HsfXAudioService)
SRV - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Stopped] – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
SRV - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/04/21 18:18:46 | 010,326,784 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/03/29 21:16:12 | 000,107,536 | —- | M] (Trend Micro Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\tmtdi.sys – (tmtdi)
DRV:64bit: - [2009/12/04 12:40:30 | 000,265,744 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\tmxpflt.sys – (tmxpflt)
DRV:64bit: - [2009/12/04 12:39:44 | 000,042,000 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\tmpreflt.sys – (tmpreflt)
DRV:64bit: - [2009/12/04 12:30:22 | 002,007,056 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\vsapint.sys – (vsapint)
DRV:64bit: - [2009/11/06 00:56:06 | 001,550,848 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2009/11/02 16:48:02 | 000,013,784 | —- | M] () [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\TurboB.sys – (TurboB)
DRV:64bit: - [2009/10/29 18:56:34 | 000,244,736 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2009/10/26 00:39:44 | 000,151,936 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/10/23 01:27:12 | 000,307,760 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2009/10/13 15:16:40 | 000,409,624 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/09/17 00:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/09/01 21:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2009/08/05 16:43:58 | 000,320,040 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\k57nd60a.sys – (k57nd60a) Broadcom NetLink ™
DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 17:59:33 | 005,020,672 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/07/09 07:00:00 | 000,055,280 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2009/06/30 21:24:50 | 002,060,144 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VX3000.sys – (VX3000)
DRV:64bit: - [2009/06/24 06:23:24 | 000,205,472 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtHDMIVX.sys – (RTHDMIAzAudService)
DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/08 19:08:00 | 000,020,520 | —- | M] (GARMIN Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\grmnusb.sys – (grmnusb)
DRV:64bit: - [2009/05/05 20:46:08 | 000,018,432 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2009/05/05 20:46:08 | 000,016,896 | —- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV:64bit: - [2009/04/28 23:21:08 | 000,010,240 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\XAudio64.sys – (XAudio)
DRV:64bit: - [2009/02/12 10:24:56 | 001,485,824 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAX_DPV.sys – (HSF_DPV)
DRV:64bit: - [2009/02/12 10:20:56 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAXHWAZL.sys – (CAXHWAZL)
DRV:64bit: - [2009/02/12 10:19:34 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAX_CNXT.sys – (winachsf)
DRV:64bit: - [2006/06/17 18:27:24 | 000,017,024 | —- | M] (Conexant) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\mdmxsdk.sys – (mdmxsdk)
DRV - [2010/03/17 16:53:38 | 000,021,248 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2010/03/17 16:53:22 | 000,020,096 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2009/09/01 21:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV - [2009/03/25 23:16:08 | 000,025,608 | —- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysWOW64\Drivers\DKbFltr.sys – (DKbFltr) Dritek Keyboard Filter Driver (64-bit)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://forums.whatthetech.com/index.php?sh…mp;#entry673572
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "https://addons.mozilla.org/en-US/firefox/search/?sort=weeklydownloads&pp;=20&pid;=1&cat;=all&q;=remember+password&lver;=3.6|http://sn122w.snt122.mail.live.com/default.aspx?wa=wsignin1.0|http://www.facebook.com/PeachyDar|http://www.youtube.com/user/PEACHYDAR1|http://www.legacy.com/obituaries/postgazette/obituary-browse.aspx?page=1&recentdate;=0&entriesperpage;=25|http://www.designsbysick.com/votingresults|http://www.sewforum.com/viewforum.php?f=16"
FF - prefs.js..extensions.enabledItems: {3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}:2.2
FF - prefs.js..extensions.enabledItems: [removed]:6.0
FF - prefs.js..extensions.enabledItems: {27182e60-b5f3-411c-b545-b44205977502}:1.0
FF - prefs.js..extensions.enabledItems: morningCoffee@shaneliesegang:1.33
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/06/25 23:13:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\Firefox [2010/06/25 23:16:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/06/25 23:16:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/08/04 19:50:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/08/04 19:50:14 | 000,000,000 | —D | M]

[2010/08/04 19:50:45 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Extensions
[2010/08/04 20:40:42 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions
[2010/08/04 20:40:41 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\morningCoffee@shaneliesegang
[2010/08/04 19:50:16 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files (x86)\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [DriverAccess] C:\Program Files (x86)\Driver Assure Corp\DriverAccess\DriverAccess.exe File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4:64bit: - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
O4:64bit: - HKLM..\Run: [VX3000] C:\Windows\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VideoWebCamera] C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe (Suyin)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files (x86)\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SmileboxTray] C:\Users\DARLENE'S\AppData\Roaming\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint Preview - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8:64bit: - Extra context menu item: Se&nd; to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {2FF8D282-F78A-4A33-ABC2-49E72A341482} http://riteaid.storefront.com/images/globa…eUpload1_10.CAB (SFImageUpload1_10.ImageUpload)
O16 - DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} http://static.ak.facebook.com/fbplugin/win…b?1271503612707 (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl-esd.sun.com/update/1.4.2/jin…indows-i586.cab (Java Plug-in 1.4.2_19)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corp.)
O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/08/09 20:06:03 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Users\DARLENE'S\Desktop\spybotsd162.exe
[2010/08/08 21:02:45 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\rfk 2010
[2010/08/07 15:29:45 | 000,000,000 | R–D | C] – C:\Users\DARLENE'S\Desktop\WEEKLY SCANS
[2010/08/07 11:48:37 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\ASHEVILLE 2010
[2010/08/07 10:26:49 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\gmer
[2010/08/06 19:03:10 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\FREDERICK MD
[2010/08/04 20:59:22 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/08/04 20:59:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010/08/04 20:55:22 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\SUPERAntiSpyware.com
[2010/08/04 20:55:22 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/08/04 20:55:16 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2010/08/04 19:50:27 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Local\Mozilla
[2010/08/04 19:50:26 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\Mozilla
[2010/08/04 19:50:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2010/08/04 18:50:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/08/04 18:32:52 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\Malwarebytes
[2010/08/04 18:29:47 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/08/04 18:29:46 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/08/04 18:29:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/08/04 18:29:46 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/08/01 11:25:02 | 000,000,000 | R–D | C] – C:\Users\DARLENE'S\Desktop\DESIGNS FROM SEWING ROOM
[2010/07/31 15:33:23 | 002,957,656 | —- | C] (PKWARE, Inc.) – C:\Users\DARLENE'S\Desktop\ZIPReader[1].exe
[2010/07/31 13:48:51 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Local\Unzip Wizard
[2010/07/31 13:48:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Unzip Wizard
[2010/07/31 12:37:11 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Documents\Outlook Files
[2010/07/30 06:14:34 | 000,000,000 | —D | C] – C:\Windows\en
[2010/07/30 06:10:57 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2010/07/28 20:00:11 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\Captured Videos
[2010/07/25 21:54:52 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\Mathew stands
[2010/07/18 15:58:57 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\TOUR AMERICA
[2010/07/18 14:38:36 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\BRP TUNNELS
[2010/07/17 16:07:05 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/07/14 22:21:07 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[1 C:\Users\DARLENE'S\Documents\*.tmp files -> C:\Users\DARLENE'S\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/09 20:13:30 | 012,058,624 | -HS- | M] () – C:\Users\DARLENE'S\NTUSER.DAT
[2010/08/09 20:07:09 | 000,001,289 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/09 20:06:11 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Users\DARLENE'S\Desktop\spybotsd162.exe
[2010/08/09 19:59:39 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/09 19:59:39 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/09 19:52:09 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/09 19:52:01 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/09 19:52:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/09 19:51:53 | 2962,309,120 | -HS- | M] () – C:\hiberfil.sys
[2010/08/09 19:50:54 | 004,682,749 | -H– | M] () – C:\Users\DARLENE'S\AppData\Local\IconCache.db
[2010/08/09 19:29:01 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/09 18:55:43 | 000,001,299 | —- | M] () – C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2010/08/09 06:01:44 | 000,015,739 | —- | M] () – C:\Users\DARLENE'S\Documents\2006 GOLD WING MILES.xlsx
[2010/08/08 21:19:23 | 000,014,336 | —- | M] () – C:\Users\DARLENE'S\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/07 15:39:28 | 000,033,235 | —- | M] () – C:\Users\DARLENE'S\Desktop\HE009.pes
[2010/08/06 19:22:46 | 000,035,918 | —- | M] () – C:\Users\DARLENE'S\Documents\NEW TRIKE.wlmp
[2010/08/05 07:47:25 | 000,013,555 | —- | M] () – C:\Users\DARLENE'S\Documents\FREDERICK MD TO HOME'.xlsx
[2010/08/05 07:43:58 | 000,012,360 | —- | M] () – C:\Users\DARLENE'S\Documents\TO FREDERICK.xlsx
[2010/08/05 05:40:40 | 000,000,824 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfud.bin
[2010/08/05 05:40:08 | 000,000,824 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfss.bin
[2010/08/04 19:50:33 | 000,000,000 | —- | M] () – C:\Windows\nsreg.dat
[2010/08/04 19:50:18 | 000,001,970 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/08/04 19:50:18 | 000,001,946 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/08/04 18:29:50 | 000,001,040 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/08/01 20:55:19 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/08/01 20:55:19 | 000,624,178 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/08/01 20:55:19 | 000,106,522 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/08/01 14:48:08 | 000,339,550 | —- | M] () – C:\Users\DARLENE'S\Desktop\goldwing trike md.jpg.png
[2010/07/31 15:33:17 | 002,957,656 | —- | M] (PKWARE, Inc.) – C:\Users\DARLENE'S\Desktop\ZIPReader[1].exe
[2010/07/31 12:37:17 | 000,001,138 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2010/07/31 12:01:11 | 000,000,064 | —- | M] () – C:\Users\DARLENE'S\Documents\Database1.laccdb
[2010/07/31 11:59:23 | 004,083,712 | —- | M] () – C:\Users\DARLENE'S\Documents\Database1.accdb
[2010/07/31 11:52:28 | 002,098,569 | —- | M] () – C:\Users\DARLENE'S\Documents\TP101918099_template.accdt
[2010/07/29 21:06:51 | 000,014,108 | —- | M] () – C:\Users\DARLENE'S\Documents\SHOPPING LIST.xlsx
[2010/07/28 18:30:44 | 000,002,347 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/07/25 15:50:46 | 000,135,779 | —- | M] () – C:\Users\DARLENE'S\Documents\LONGABERGER BASKET 2007 RIDE.wlmp
[2010/07/24 21:25:01 | 000,008,142 | —- | M] () – C:\Users\DARLENE'S\Documents\MATHEW SLEEPS OVER.wlmp
[2010/07/23 06:33:47 | 000,953,136 | —- | M] () – C:\Users\DARLENE'S\Documents\tee pee bags.docx
[2010/07/21 18:04:57 | 000,001,244 | —- | M] () – C:\Users\DARLENE'S\AppData\Roaming\wklnhst.dat
[2010/07/19 21:21:04 | 000,015,590 | —- | M] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 10 min.wlmp
[2010/07/19 20:43:36 | 000,013,699 | —- | M] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 18 MIN.wlmp
[2010/07/19 06:29:08 | 000,002,012 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk
[2010/07/18 21:25:30 | 000,201,554 | —- | M] () – C:\Users\DARLENE'S\Documents\BROOKVILLE BAT RIDE.wlmp
[2010/07/18 19:56:22 | 000,188,922 | —- | M] () – C:\Users\DARLENE'S\Documents\blackwater falls 2006.wlmp
[2010/07/17 15:23:38 | 000,097,586 | —- | M] () – C:\Users\DARLENE'S\Documents\ASHEVILLE DAY FIVE.wlmp
[2010/07/17 14:54:37 | 000,031,499 | —- | M] () – C:\Users\DARLENE'S\Documents\JUNE 2010 RIDE ITINERARY.xlsx
[1 C:\Users\DARLENE'S\Documents\*.tmp files -> C:\Users\DARLENE'S\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/09 20:07:09 | 000,001,289 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/07 15:39:28 | 000,033,235 | —- | C] () – C:\Users\DARLENE'S\Desktop\HE009.pes
[2010/08/06 19:22:46 | 000,035,918 | —- | C] () – C:\Users\DARLENE'S\Documents\NEW TRIKE.wlmp
[2010/08/05 07:47:25 | 000,013,555 | —- | C] () – C:\Users\DARLENE'S\Documents\FREDERICK MD TO HOME'.xlsx
[2010/08/05 07:43:57 | 000,012,360 | —- | C] () – C:\Users\DARLENE'S\Documents\TO FREDERICK.xlsx
[2010/08/04 19:50:33 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/08/04 19:50:18 | 000,001,970 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/08/04 19:50:18 | 000,001,946 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/08/04 18:29:50 | 000,001,040 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/08/01 14:48:08 | 000,339,550 | —- | C] () – C:\Users\DARLENE'S\Desktop\goldwing trike md.jpg.png
[2010/07/31 12:37:17 | 000,001,138 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2010/07/31 11:59:18 | 000,000,064 | —- | C] () – C:\Users\DARLENE'S\Documents\Database1.laccdb
[2010/07/31 11:52:45 | 004,083,712 | —- | C] () – C:\Users\DARLENE'S\Documents\Database1.accdb
[2010/07/31 11:52:36 | 002,098,569 | —- | C] () – C:\Users\DARLENE'S\Documents\TP101918099_template.accdt
[2010/07/29 05:52:59 | 000,001,299 | —- | C] () – C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2010/07/25 15:50:46 | 000,135,779 | —- | C] () – C:\Users\DARLENE'S\Documents\LONGABERGER BASKET 2007 RIDE.wlmp
[2010/07/24 21:25:01 | 000,008,142 | —- | C] () – C:\Users\DARLENE'S\Documents\MATHEW SLEEPS OVER.wlmp
[2010/07/23 06:33:47 | 000,953,136 | —- | C] () – C:\Users\DARLENE'S\Documents\tee pee bags.docx
[2010/07/19 20:44:40 | 000,015,590 | —- | C] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 10 min.wlmp
[2010/07/18 21:25:30 | 000,201,554 | —- | C] () – C:\Users\DARLENE'S\Documents\BROOKVILLE BAT RIDE.wlmp
[2010/07/18 19:56:22 | 000,188,922 | —- | C] () – C:\Users\DARLENE'S\Documents\blackwater falls 2006.wlmp
[2010/07/18 10:37:42 | 000,013,699 | —- | C] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 18 MIN.wlmp
[2010/07/17 15:23:38 | 000,097,586 | —- | C] () – C:\Users\DARLENE'S\Documents\ASHEVILLE DAY FIVE.wlmp
[2010/03/29 21:03:09 | 000,000,065 | —- | C] () – C:\Windows\wininit.ini
[2009/12/17 06:24:10 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2009/12/17 06:24:10 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/26 17:24:18 | 000,015,498 | —- | C] () – C:\Windows\VX3000.ini

========== LOP Check ==========

[2010/04/17 07:27:31 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Facebook
[2010/06/06 11:52:18 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\GARMIN
[2010/07/26 05:42:24 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Smilebox
[2010/03/28 18:43:41 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Template
[2010/06/05 06:54:31 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\Windows Live Writer
[2010/06/20 06:46:48 | 000,000,366 | —- | M] () – C:\Windows\Tasks\Driver Fetch.job
[2010/07/14 05:18:43 | 000,032,586 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >
Now that I have posted this - I'm on my way to do the Malaware bytes run again…… Here is the log file that popped up after the reboot: All processes killed ========== OTL ========== 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator User: All Users User: DARLENE'S ->Temp folder emptied: 64455645 bytes ->Temporary Internet Files folder emptied: 533662003 bytes ->Java cache emptied: 240990 bytes ->FireFox cache emptied: 51287059 bytes ->Google Chrome cache emptied: 6185329 bytes ->Flash cache emptied: 51443 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 100766 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50199 bytes RecycleBin emptied: 7350183028 bytes Total Files Cleaned = 7,635.00 mb [EMPTYFLASH] User: Administrator User: All Users User: DARLENE'S ->Flash cache emptied: 0 bytes User: Default User: Default User User: Public Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.9.1 log created on 08092010_202920 Files\Folders moved on Reboot… C:\Users\DARLENE'S\AppData\Local\Temp\Low\Google Toolbar\GoogleToolbarWelcome.log moved successfully. C:\Users\DARLENE'S\AppData\Local\Temp\Low\~DFB2BB1D3C9E2E6CBF.TMP moved successfully. C:\Users\DARLENE'S\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\DARLENE'S\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LHJX9LUM\like[2].php moved successfully. C:\Users\DARLENE'S\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FSPDQTUB\index[1].htm moved successfully. C:\Users\DARLENE'S\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\06QOMTYG\iframe[1].htm moved successfully. Registry entries deleted on Reboot…
Trend Micro ran it's nightly scan and told me it found this: Trend Micro AntiVirus X a kJ Mn resolved Threats (1 items found) Please decide what to do about the unresolved or possible threat found. rEiXN0W’ , ‘r Item y Status Details Cryp_Mangled Unresolved security threat Afile showing signs of a possible infection has been found. If possible, please quarantine or delete this file right away. Infected tile: 6daeße.msi (view location) Threat name: Cryp_Mangled Type: Generic O GetHelp si Resolved Threats (6 items found) ®Help Close J I went to the logs and seen this too: View .‘ Select a log view: [Virus Scan ijew J Log Date Detailed Log 8/9/2010 8/8/2010 7/25/2010 lime ‘r Status Threat Name 21:41 Ignored Successfully Cryp_Mangled $ 21:11 Ignored Successfully Cryp_Mangled 21:11 Ignored Successfully Cryp_Mangled 21:10 Ignored Successfully Cryp_Mangled I don' t know if this cryp_mangeld file is bad or not…..Im none too happy with trend micro for ignoring it….. what do ya think? I looked in my quarantine and it has been found and quarantined. And I found this in the quarentine: The Trojan flouse Quarantine isolates software containing hidden features that could threaten your security. To release a harmless program from the quarantine. cli& Restore. Clidc Delete to remove selected programs from your computer permanently. I—a—I V Date Quarantined Status TRDJ_JAVA.AZ 2010,07,25 fl:07 Trojan Found TROJ_JAVA.AZ 2010/07/25 22:08 Trojan Found III. ,, __________________ here is the malaware log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4412 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 8/9/2010 8:46:59 PM mbam-log-2010-08-09 (20-46-59).txt Scan type: Quick scan Objects scanned: 143332 Time elapsed: 5 minute(s), 38 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I have not been prompted to restart…. dar
Hi, Please refrain from running any tools other than those advised as they sometimes complicate things. Am currently reviewing your log .

Hi,

Please refrain from running any tools other than those advised as they sometimes complicate things.

Am currently reviewing your log .



hI

I'm sorry - it runs via a schedule all the time - it just happened to be running at the time I sat here to do this with you. I'm sorry.

dar
Hi,

It seems you've run the OTL scan before running the advised fix.

It's good that MBAM didn't find anything :thumbup:

Let's do this:

Run OTL again, under Extra Registry box, click on Use Safelist and leave the rest to the default value then run a scan. This scan shall now produce 2 logs, OTL.txt and Extras.txt. Please post both when done. Thanks.
:thumbup:


Not sure what all has been done….looks like greek to me…

OTL logfile created on: 8/9/2010 9:11:30 PM - Run 3
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\DARLENE'S\Desktop\WEEKLY SCANS
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 46.00% Memory free
7.00 Gb Paging File | 5.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453.66 Gb Total Space | 344.83 Gb Free Space | 76.01% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DARLENES-PC
Current User Name: DARLENE'S
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/08/04 19:08:03 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\WEEKLY SCANS\OTL.exe
PRC - [2010/07/19 06:28:47 | 000,353,736 | —- | M] (IncrediMail, Ltd.) – C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
PRC - [2010/07/19 06:28:46 | 000,255,432 | —- | M] (IncrediMail, Ltd.) – C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
PRC - [2010/07/13 17:31:45 | 000,304,304 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
PRC - [2010/06/29 02:47:30 | 000,304,448 | —- | M] (Smilebox, Inc.) – C:\Users\DARLENE'S\AppData\Roaming\Smilebox\SmileboxTray.exe
PRC - [2010/06/14 17:55:20 | 000,231,888 | —- | M] (Adobe Systems, Inc.) – C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe
PRC - [2010/06/07 17:33:40 | 004,176,760 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
PRC - [2010/06/07 17:02:44 | 000,053,632 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Live\Companion\companionuser.exe
PRC - [2010/06/07 16:16:20 | 000,025,968 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
PRC - [2010/03/29 20:26:00 | 000,227,712 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2010/03/17 16:53:24 | 000,207,872 | —- | M] (Alcatel-Lucent) – C:\Program Files (x86)\Common Files\Motive\McciContextHookShim.exe
PRC - [2010/02/24 18:12:30 | 000,318,848 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
PRC - [2010/02/24 18:12:30 | 000,242,560 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/12/17 06:51:23 | 000,039,408 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/10/29 16:31:16 | 000,244,480 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe
PRC - [2009/10/29 16:31:00 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
PRC - [2009/10/13 15:25:54 | 000,186,904 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/10/13 15:25:30 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2009/09/30 08:01:32 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/09/30 08:01:30 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/09/17 02:50:14 | 001,157,640 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2009/08/28 05:38:58 | 001,150,496 | —- | M] (Acer Incorporated) – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
PRC - [2009/08/03 12:05:48 | 000,498,160 | —- | M] () – C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2009/07/28 17:29:40 | 001,507,448 | —- | M] (Suyin) – C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe
PRC - [2009/07/03 22:47:12 | 000,240,160 | —- | M] (Acer) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
PRC - [2009/06/30 21:24:46 | 000,762,224 | —- | M] (Microsoft Corporation) – C:\Windows\vVX3000.exe
PRC - [2009/04/16 03:52:06 | 000,091,432 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe


========== Modules (SafeList) ==========

MOD - [2010/08/04 19:08:03 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\DARLENE'S\Desktop\WEEKLY SCANS\OTL.exe
MOD - [2009/07/13 21:14:10 | 000,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/13 21:03:50 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - File not found [Auto | Stopped] – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE – (!SASCORE)
SRV:64bit: - [2010/06/04 18:23:38 | 000,055,648 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2010/05/26 13:37:18 | 002,290,048 | —- | M] (Microsoft Corp.) [Auto | Running] – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE – (wlidsvc)
SRV:64bit: - [2010/03/29 21:16:03 | 000,917,768 | —- | M] (Trend Micro Inc.) [On_Demand | Running] – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe – (TmProxy)
SRV:64bit: - [2010/03/29 21:16:03 | 000,836,432 | —- | M] (Trend Micro Inc.) [Auto | Running] – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe – (SfCtlCom)
SRV:64bit: - [2010/03/29 21:16:03 | 000,570,632 | —- | M] (Trend Micro Inc.) [On_Demand | Running] – C:\Program Files\Trend Micro\BM\TMBMSRV.exe – (TMBMServer)
SRV:64bit: - [2009/11/02 16:48:18 | 000,126,352 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\TurboBoost\TurboBoost.exe – (TurboBoost)
SRV:64bit: - [2009/10/29 15:10:02 | 000,844,320 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe – (ePowerSvc)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/03 22:47:12 | 000,240,160 | —- | M] (Acer) [Auto | Running] – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe – (Updater Service)
SRV - [2010/03/18 14:27:14 | 000,138,576 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_64)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/02/24 18:12:30 | 000,242,560 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2009/10/29 16:31:00 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) [Auto | Running] – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe – (NTI IScheduleSvc)
SRV - [2009/10/13 15:25:30 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2009/09/30 08:01:32 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2009/09/30 08:01:30 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/08/28 05:38:58 | 001,150,496 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe – (Greg_Service)
SRV - [2009/04/28 23:21:18 | 000,436,736 | —- | M] (Conexant Systems, Inc.) [Auto | Running] – C:\Windows\SysWOW64\XAudio64.dll – (HsfXAudioService)
SRV - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Running] – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
SRV - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/04/21 18:18:46 | 010,326,784 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/03/29 21:16:12 | 000,107,536 | —- | M] (Trend Micro Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\tmtdi.sys – (tmtdi)
DRV:64bit: - [2009/12/04 12:40:30 | 000,265,744 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\tmxpflt.sys – (tmxpflt)
DRV:64bit: - [2009/12/04 12:39:44 | 000,042,000 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\tmpreflt.sys – (tmpreflt)
DRV:64bit: - [2009/12/04 12:30:22 | 002,007,056 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\vsapint.sys – (vsapint)
DRV:64bit: - [2009/11/06 00:56:06 | 001,550,848 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2009/11/02 16:48:02 | 000,013,784 | —- | M] () [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\TurboB.sys – (TurboB)
DRV:64bit: - [2009/10/29 18:56:34 | 000,244,736 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2009/10/26 00:39:44 | 000,151,936 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/10/23 01:27:12 | 000,307,760 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2009/10/13 15:16:40 | 000,409,624 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/09/17 00:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/09/01 21:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2009/08/05 16:43:58 | 000,320,040 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\k57nd60a.sys – (k57nd60a) Broadcom NetLink ™
DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 17:59:33 | 005,020,672 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/07/09 07:00:00 | 000,055,280 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2009/06/30 21:24:50 | 002,060,144 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VX3000.sys – (VX3000)
DRV:64bit: - [2009/06/24 06:23:24 | 000,205,472 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtHDMIVX.sys – (RTHDMIAzAudService)
DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/08 19:08:00 | 000,020,520 | —- | M] (GARMIN Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\grmnusb.sys – (grmnusb)
DRV:64bit: - [2009/05/05 20:46:08 | 000,018,432 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2009/05/05 20:46:08 | 000,016,896 | —- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV:64bit: - [2009/04/28 23:21:08 | 000,010,240 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\XAudio64.sys – (XAudio)
DRV:64bit: - [2009/02/12 10:24:56 | 001,485,824 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAX_DPV.sys – (HSF_DPV)
DRV:64bit: - [2009/02/12 10:20:56 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAXHWAZL.sys – (CAXHWAZL)
DRV:64bit: - [2009/02/12 10:19:34 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAX_CNXT.sys – (winachsf)
DRV:64bit: - [2006/06/17 18:27:24 | 000,017,024 | —- | M] (Conexant) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\mdmxsdk.sys – (mdmxsdk)
DRV - [2010/03/17 16:53:38 | 000,021,248 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2010/03/17 16:53:22 | 000,020,096 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2009/09/01 21:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV - [2009/03/25 23:16:08 | 000,025,608 | —- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysWOW64\Drivers\DKbFltr.sys – (DKbFltr) Dritek Keyboard Filter Driver (64-bit)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…54z105a4482y249

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://forums.whatthetech.com/index.php?sh…mp;#entry673572
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "https://addons.mozilla.org/en-US/firefox/search/?sort=weeklydownloads&pp;=20&pid;=1&cat;=all&q;=remember+password&lver;=3.6|http://sn122w.snt122.mail.live.com/default.aspx?wa=wsignin1.0|http://www.facebook.com/PeachyDar|http://www.youtube.com/user/PEACHYDAR1|http://www.legacy.com/obituaries/postgazette/obituary-browse.aspx?page=1&recentdate;=0&entriesperpage;=25|http://www.designsbysick.com/votingresults|http://www.sewforum.com/viewforum.php?f=16"
FF - prefs.js..extensions.enabledItems: {3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}:2.2
FF - prefs.js..extensions.enabledItems: [removed]:6.0
FF - prefs.js..extensions.enabledItems: {27182e60-b5f3-411c-b545-b44205977502}:1.0
FF - prefs.js..extensions.enabledItems: morningCoffee@shaneliesegang:1.33
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/06/25 23:13:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\Firefox [2010/06/25 23:16:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/06/25 23:16:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/08/04 19:50:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/08/04 19:50:14 | 000,000,000 | —D | M]

[2010/08/04 19:50:45 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Extensions
[2010/08/04 20:40:42 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions
[2010/08/04 20:40:41 | 000,000,000 | —D | M] – C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\morningCoffee@shaneliesegang
[2010/08/04 19:50:16 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files (x86)\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [DriverAccess] C:\Program Files (x86)\Driver Assure Corp\DriverAccess\DriverAccess.exe File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4:64bit: - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
O4:64bit: - HKLM..\Run: [VX3000] C:\Windows\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VideoWebCamera] C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe (Suyin)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files (x86)\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SmileboxTray] C:\Users\DARLENE'S\AppData\Roaming\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint Preview - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8:64bit: - Extra context menu item: Se&nd; to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {2FF8D282-F78A-4A33-ABC2-49E72A341482} http://riteaid.storefront.com/images/globa…eUpload1_10.CAB (SFImageUpload1_10.ImageUpload)
O16 - DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} http://static.ak.facebook.com/fbplugin/win…b?1271503612707 (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl-esd.sun.com/update/1.4.2/jin…indows-i586.cab (Java Plug-in 1.4.2_19)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corp.)
O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/08/09 20:59:00 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\KENNYWOOD
[2010/08/09 20:29:20 | 000,000,000 | —D | C] – C:\_OTL
[2010/08/09 20:06:03 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Users\DARLENE'S\Desktop\spybotsd162.exe
[2010/08/08 21:02:45 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\rfk 2010
[2010/08/07 15:29:45 | 000,000,000 | R–D | C] – C:\Users\DARLENE'S\Desktop\WEEKLY SCANS
[2010/08/07 11:48:37 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\ASHEVILLE 2010
[2010/08/07 10:26:49 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\gmer
[2010/08/06 19:03:10 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\FREDERICK MD
[2010/08/04 20:59:22 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/08/04 20:59:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010/08/04 20:55:22 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\SUPERAntiSpyware.com
[2010/08/04 20:55:22 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/08/04 20:55:16 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2010/08/04 19:50:27 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Local\Mozilla
[2010/08/04 19:50:26 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\Mozilla
[2010/08/04 19:50:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2010/08/04 18:50:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/08/04 18:32:52 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Roaming\Malwarebytes
[2010/08/04 18:29:47 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/08/04 18:29:46 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/08/04 18:29:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/08/04 18:29:46 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/08/01 11:25:02 | 000,000,000 | R–D | C] – C:\Users\DARLENE'S\Desktop\DESIGNS FROM SEWING ROOM
[2010/07/31 15:33:23 | 002,957,656 | —- | C] (PKWARE, Inc.) – C:\Users\DARLENE'S\Desktop\ZIPReader[1].exe
[2010/07/31 13:48:51 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\AppData\Local\Unzip Wizard
[2010/07/31 13:48:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Unzip Wizard
[2010/07/31 12:37:11 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Documents\Outlook Files
[2010/07/30 06:14:34 | 000,000,000 | —D | C] – C:\Windows\en
[2010/07/30 06:10:57 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2010/07/28 20:00:11 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\Captured Videos
[2010/07/25 21:54:52 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\Mathew stands
[2010/07/18 15:58:57 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\TOUR AMERICA
[2010/07/18 14:38:36 | 000,000,000 | —D | C] – C:\Users\DARLENE'S\Desktop\BRP TUNNELS
[2010/07/17 16:07:05 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/07/14 22:21:07 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[1 C:\Users\DARLENE'S\Documents\*.tmp files -> C:\Users\DARLENE'S\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/09 21:15:46 | 012,058,624 | -HS- | M] () – C:\Users\DARLENE'S\NTUSER.DAT
[2010/08/09 21:06:44 | 000,001,299 | —- | M] () – C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2010/08/09 20:41:29 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/09 20:41:29 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/09 20:34:01 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/09 20:33:33 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/09 20:33:32 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/09 20:33:26 | 2962,309,120 | -HS- | M] () – C:\hiberfil.sys
[2010/08/09 20:32:44 | 004,722,264 | -H– | M] () – C:\Users\DARLENE'S\AppData\Local\IconCache.db
[2010/08/09 20:29:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/09 20:07:09 | 000,001,289 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/09 20:06:11 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Users\DARLENE'S\Desktop\spybotsd162.exe
[2010/08/09 06:01:44 | 000,015,739 | —- | M] () – C:\Users\DARLENE'S\Documents\2006 GOLD WING MILES.xlsx
[2010/08/08 21:19:23 | 000,014,336 | —- | M] () – C:\Users\DARLENE'S\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/07 15:39:28 | 000,033,235 | —- | M] () – C:\Users\DARLENE'S\Desktop\HE009.pes
[2010/08/06 19:22:46 | 000,035,918 | —- | M] () – C:\Users\DARLENE'S\Documents\NEW TRIKE.wlmp
[2010/08/05 07:47:25 | 000,013,555 | —- | M] () – C:\Users\DARLENE'S\Documents\FREDERICK MD TO HOME'.xlsx
[2010/08/05 07:43:58 | 000,012,360 | —- | M] () – C:\Users\DARLENE'S\Documents\TO FREDERICK.xlsx
[2010/08/05 05:40:40 | 000,000,824 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfud.bin
[2010/08/05 05:40:08 | 000,000,824 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfss.bin
[2010/08/04 19:50:33 | 000,000,000 | —- | M] () – C:\Windows\nsreg.dat
[2010/08/04 19:50:18 | 000,001,970 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/08/04 19:50:18 | 000,001,946 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/08/04 18:29:50 | 000,001,040 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/08/01 20:55:19 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/08/01 20:55:19 | 000,624,178 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/08/01 20:55:19 | 000,106,522 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/08/01 14:48:08 | 000,339,550 | —- | M] () – C:\Users\DARLENE'S\Desktop\goldwing trike md.jpg.png
[2010/07/31 15:33:17 | 002,957,656 | —- | M] (PKWARE, Inc.) – C:\Users\DARLENE'S\Desktop\ZIPReader[1].exe
[2010/07/31 12:37:17 | 000,001,138 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2010/07/31 12:01:11 | 000,000,064 | —- | M] () – C:\Users\DARLENE'S\Documents\Database1.laccdb
[2010/07/31 11:59:23 | 004,083,712 | —- | M] () – C:\Users\DARLENE'S\Documents\Database1.accdb
[2010/07/31 11:52:28 | 002,098,569 | —- | M] () – C:\Users\DARLENE'S\Documents\TP101918099_template.accdt
[2010/07/29 21:06:51 | 000,014,108 | —- | M] () – C:\Users\DARLENE'S\Documents\SHOPPING LIST.xlsx
[2010/07/28 18:30:44 | 000,002,347 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/07/25 15:50:46 | 000,135,779 | —- | M] () – C:\Users\DARLENE'S\Documents\LONGABERGER BASKET 2007 RIDE.wlmp
[2010/07/24 21:25:01 | 000,008,142 | —- | M] () – C:\Users\DARLENE'S\Documents\MATHEW SLEEPS OVER.wlmp
[2010/07/23 06:33:47 | 000,953,136 | —- | M] () – C:\Users\DARLENE'S\Documents\tee pee bags.docx
[2010/07/21 18:04:57 | 000,001,244 | —- | M] () – C:\Users\DARLENE'S\AppData\Roaming\wklnhst.dat
[2010/07/19 21:21:04 | 000,015,590 | —- | M] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 10 min.wlmp
[2010/07/19 20:43:36 | 000,013,699 | —- | M] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 18 MIN.wlmp
[2010/07/19 06:29:08 | 000,002,012 | —- | M] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk
[2010/07/18 21:25:30 | 000,201,554 | —- | M] () – C:\Users\DARLENE'S\Documents\BROOKVILLE BAT RIDE.wlmp
[2010/07/18 19:56:22 | 000,188,922 | —- | M] () – C:\Users\DARLENE'S\Documents\blackwater falls 2006.wlmp
[2010/07/17 15:23:38 | 000,097,586 | —- | M] () – C:\Users\DARLENE'S\Documents\ASHEVILLE DAY FIVE.wlmp
[2010/07/17 14:54:37 | 000,031,499 | —- | M] () – C:\Users\DARLENE'S\Documents\JUNE 2010 RIDE ITINERARY.xlsx
[1 C:\Users\DARLENE'S\Documents\*.tmp files -> C:\Users\DARLENE'S\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/09 20:07:09 | 000,001,289 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/07 15:39:28 | 000,033,235 | —- | C] () – C:\Users\DARLENE'S\Desktop\HE009.pes
[2010/08/06 19:22:46 | 000,035,918 | —- | C] () – C:\Users\DARLENE'S\Documents\NEW TRIKE.wlmp
[2010/08/05 07:47:25 | 000,013,555 | —- | C] () – C:\Users\DARLENE'S\Documents\FREDERICK MD TO HOME'.xlsx
[2010/08/05 07:43:57 | 000,012,360 | —- | C] () – C:\Users\DARLENE'S\Documents\TO FREDERICK.xlsx
[2010/08/04 19:50:33 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/08/04 19:50:18 | 000,001,970 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/08/04 19:50:18 | 000,001,946 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/08/04 18:29:50 | 000,001,040 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/08/01 14:48:08 | 000,339,550 | —- | C] () – C:\Users\DARLENE'S\Desktop\goldwing trike md.jpg.png
[2010/07/31 12:37:17 | 000,001,138 | —- | C] () – C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2010/07/31 11:59:18 | 000,000,064 | —- | C] () – C:\Users\DARLENE'S\Documents\Database1.laccdb
[2010/07/31 11:52:45 | 004,083,712 | —- | C] () – C:\Users\DARLENE'S\Documents\Database1.accdb
[2010/07/31 11:52:36 | 002,098,569 | —- | C] () – C:\Users\DARLENE'S\Documents\TP101918099_template.accdt
[2010/07/29 05:52:59 | 000,001,299 | —- | C] () – C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2010/07/25 15:50:46 | 000,135,779 | —- | C] () – C:\Users\DARLENE'S\Documents\LONGABERGER BASKET 2007 RIDE.wlmp
[2010/07/24 21:25:01 | 000,008,142 | —- | C] () – C:\Users\DARLENE'S\Documents\MATHEW SLEEPS OVER.wlmp
[2010/07/23 06:33:47 | 000,953,136 | —- | C] () – C:\Users\DARLENE'S\Documents\tee pee bags.docx
[2010/07/19 20:44:40 | 000,015,590 | —- | C] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 10 min.wlmp
[2010/07/18 21:25:30 | 000,201,554 | —- | C] () – C:\Users\DARLENE'S\Documents\BROOKVILLE BAT RIDE.wlmp
[2010/07/18 19:56:22 | 000,188,922 | —- | C] () – C:\Users\DARLENE'S\Documents\blackwater falls 2006.wlmp
[2010/07/18 10:37:42 | 000,013,699 | —- | C] () – C:\Users\DARLENE'S\Documents\DRAGON 2010 18 MIN.wlmp
[2010/07/17 15:23:38 | 000,097,586 | —- | C] () – C:\Users\DARLENE'S\Documents\ASHEVILLE DAY FIVE.wlmp
[2010/03/29 21:03:09 | 000,000,065 | —- | C] () – C:\Windows\wininit.ini
[2009/12/17 06:24:10 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2009/12/17 06:24:10 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/26 17:24:18 | 000,015,498 | —- | C] () – C:\Windows\VX3000.ini
< End of report >
EXTRAS,TXT
OTL Extras logfile created on: 8/9/2010 9:11:30 PM - Run 3
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\DARLENE'S\Desktop\WEEKLY SCANS
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 46.00% Memory free
7.00 Gb Paging File | 5.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453.66 Gb Total Space | 344.83 Gb Free Space | 76.01% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DARLENES-PC
Current User Name: DARLENE'S
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP1700" = Canon iP1700
"{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}" = Intel® Turbo Boost Technology Monitor
"{709BE6E5-DE39-4E2F-9B9B-8DE299519495}" = Windows Live MIME IFilter
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro AntiVirus
"{76C32FF0-2957-4F56-8B5D-F62E3FB6B609}" = Windows Live ID Sign-in Assistant
"{8AA463DE-2446-40A9-9C8F-E9C225E072D5}" = Windows Live Remote Client
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D2B0322-44AE-460E-9283-4D2D7A9205AE}" = Trend Micro AntiVirus
"{AD712BC2-B0CD-4187-B8F3-B74932F77C9E}" = Windows Live Remote Client Resources
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{E4E1C2C2-37A1-4409-B26D-BFA3A52CDE6A}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy Software Installer
"{FC347CBB-0E51-4AD9-B97F-46C121DA2432}" = Windows Live Remote Service Resources
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"CanonMyPrinter" = Canon My Printer
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{007EA334-6071-41BF-B8C7-4C4E37E49DA7}" = Messenger Companion
"{035C76D2-7D8E-484D-8CA3-686C0B474A2B}" = MSVCRT
"{07766F89-EFAA-4635-86B7-636B89EA2C0D}" = Bing Bar Platform
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{0CA72D12-F6C6-4D43-A2A0-41F5AA17E2B6}" = Netflix in Windows Media Center
"{11EFF057-8ED2-4321-A19D-D673DECB36CC}" = Junk Mail filter update
"{15F4085A-BC98-4590-AFFD-03BBBE49524E}" = Garmin Communicator Plugin
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{224935E4-2014-4B22-95DC-2CCF5428B4BF}" = Windows Live Writer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2578D94A-A88A-4643-9DAA-F0A5E981EB04}" = Windows Live Messenger
"{2607FE6B-1D61-46E5-A544-54666B0EF908}" = Windows Live Mail
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"{2C4F4D53-78D6-41FB-A4D7-105C537464EB}" = Mesh Runtime
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{328019A7-0012-401D-96A2-4CDDD02675A8}" = Garmin POI Loader
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Gateway Power Management
"{3F62782D-2798-4540-B493-F6472197900E}" = Microsoft Search Enhancement Pack
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{46BAF2A0-3789-4E49-B000-4BB64426D1BF}" = Windows Live Installer
"{46C106C9-3856-4A6A-AAC8-7070FBA02D2F}" = Windows Live Movie Maker
"{4EC66844-AE87-47DC-B02D-E36C75EAF22C}" = Windows Live Sync Beta
"{510D2239-6C2E-457B-9590-485EC552D94D}" = Garmin USB Drivers
"{52CDDA92-56B6-4BA5-BD8D-E13B186008CB}" = D3DX10
"{58B42F3F-EC8D-4A53-9813-5EA43C4E9350}" = Garmin City Navigator North America NT 2009
"{58FA5D40-E35A-47ED-8AFA-68CCC758559E}" = Garmin MapSource
"{61E7F654-7D99-4C69-94D8-DF53E297AF9B}" = Windows Live Photo Common
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{6592C2B8-949A-4C88-BCB9-0990A218B215}" = Windows Live UX Platform
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{67E4EE98-59F4-4210-89A6-A20AF5BEC689}" = Microsoft Streets and Trips 2005
"{6917F87D-921D-4EFA-9AA5-8CDEA9E28520}" = MSVCRT_amd64
"{6B0AE911-A3F4-4D55-9CA7-C76DC2BCEA86}" = Windows Live UX Platform Language Pack
"{6D9021DC-CF1B-4148-8C80-6D8E8A8A33EB}" = Video Web Camera
"{7148F0A8-6813-11D6-A77B-00B0D0142190}" = Java 2 Runtime Environment, SE v1.4.2_19
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{74B0BEB0-2EB3-448F-B8E9-40983BC902E1}" = Windows Live SOXE Definitions
"{75AE8014-1184-4BC0-B279-C879540719EE}" = PhotoMail Maker
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7A8E7F22-3628-4846-A578-516BDCB2CEAA}" = Windows Live Sync Beta
"{7EFA8362-CE86-46E7-BEB9-B2DB4F0D0EE6}" = Windows Live Photo Gallery Beta
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Gateway Recovery Management
"{828DB235-8D79-4E39-A327-AEC9A1185070}" = LiveUpload to Facebook
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83BC206C-98A5-4CF3-B884-2B58CD4AB951}" = Windows Live Writer
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E74FC72-018A-4EC5-86AA-D8021309D484}" = Windows Live Messenger
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{91803386-4FBD-4C38-9644-26B0F9464031}" = Windows Live Photo Gallery
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95140000-0048-0409-0000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 32-bit
"{95140000-0079-0409-0000-0000000FF1CE}" = Windows Live Provider for Microsoft Outlook Social Connector 32-bit
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9D0467C4-F69C-4E9D-8765-7774D8971F5C}" = Windows Live Messenger Companion Core
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet TV for Windows Media Center
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{A3D88A98-506E-4CFC-B294-E256C679B0EE}" = Microsoft Store Download Manager
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5BD2B33-FDB8-4DE5-87B3-2810CAF4A6E4}" = Windows Live PIMT Platform
"{C2687C43-507E-4D4B-A30A-3C836C756226}" = Windows Live Mail
"{C2D129C0-7508-11DF-9F1B-005056806466}" = Google Earth
"{D17111CB-C992-42A9-9D56-C19395102AAA}" = Garmin WebUpdater
"{D4790ACB-4BB4-4FE6-9F64-1D4486C8E40C}" = Windows Live Photo Common Beta
"{D65F8E34-C050-4E6C-86DB-D2B9075749A0}" = Windows Live Sync ActiveX Control for Remote Connections
"{D943C8AC-9E03-4C2D-B54C-A28ABE931665}" = Windows Live Movie Maker
"{E24DFAA7-9495-4F7D-BB9E-211C2D0A76E5}" = Windows Live Writer Resources
"{E2D09AC2-4153-4817-AAEB-24F92A8BCE88}" = Windows Media Center Add-in for Flash
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EACF374B-9D4C-4A07-8EB3-706BD8DAA650}" = Windows Live Essentials Beta
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Gateway Updater
"{EE338AB8-4E85-4C04-AC07-1357A266DD35}" = Windows Live Writer
"{EFBE9DAB-9C80-4911-847B-2A2C25E8F9CB}" = Windows Live SOXE
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FA5D1C9E-154D-49B1-8CF0-DF5FAB6171EA}" = Windows Live Communications Platform
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Best Buy Software Installer" = Best Buy Software Installer
"CameraUserGuide-PSSX120IS" = Canon PowerShot SX120 IS Camera User Guide
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDC8" = Canon Utilities CameraWindow DC 8
"CameraWindowLauncher" = Canon Utilities CameraWindow
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-WebPrint" = Easy-WebPrint
"Gateway InfoCentre" = Gateway InfoCentre
"Gateway Registration" = Gateway Registration
"Gateway Screensaver" = Gateway ScreenSaver
"Gateway Welcome Center" = Welcome Center
"Google Chrome" = Google Chrome
"Identity Card" = Identity Card
"IncrediMail" = IncrediMail 2.0
"InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Gateway MyBackup
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"MyCamera" = Canon Utilities MyCamera
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"Personal Printing Guide" = Canon Personal Printing Guide
"PhotoMail" = PhotoMail Maker
"PhotoStitch" = Canon Utilities PhotoStitch
"Picasa 3" = Picasa 3
"Software Guide" = Canon DIGITAL CAMERA Solution Disk Software Guide
"The Unzip Wizard" = The Unzip Wizard
"Verizon Help and Support" = Verizon Help and Support Tool
"WinLiveSuite" = Windows Live Essentials Beta
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Smilebox" = Smilebox

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI