This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help deleting qusearch virus

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This thing is annoying and I have heard it may be a key logger. I used nortan avast and mbam. I am on windows 7
Please run the following diagnostic scan

  • Download OTL and save it to your desktop.
  • Double click on the [external image: Posted Image] icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top, make sure Standard output is selected.
  • Under the Extra Registry section, check Use SafeList
  • Under Custom scan's and fixes section paste in the below text


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    nvraid.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button.
  • Do not change any other settings. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
OTL logfile created on: 6/10/2011 4:17:27 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Steve\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.97 Gb Total Physical Memory | 6.25 Gb Available Physical Memory | 78.44% Memory free
15.93 Gb Paging File | 14.20 Gb Available in Paging File | 89.15% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 683.58 Gb Total Space | 530.97 Gb Free Space | 77.67% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 7.80 Gb Free Space | 52.02% Space Free | Partition Type: NTFS
Drive M: | 931.50 Gb Total Space | 177.61 Gb Free Space | 19.07% Space Free | Partition Type: NTFS

Computer Name: HOM | User Name: Steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/06/10 16:15:45 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\Steve\Desktop\OTL.exe
PRC - [2011/05/31 15:01:54 | 000,140,952 | —- | M] (Google Inc.) – C:\Users\Steve\AppData\Local\Google\Update\1.3.21.57\GoogleCrashHandler.exe
PRC - [2011/04/16 20:45:11 | 000,130,008 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
PRC - [2010/09/22 18:11:26 | 000,640,440 | —- | M] (Adobe Systems Inc.) – C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
PRC - [2010/01/07 17:11:28 | 000,140,520 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2009/07/21 17:06:26 | 000,554,224 | —- | M] (Dell Inc.) – c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
PRC - [2008/12/18 15:05:28 | 000,155,648 | —- | M] (Stardock Corporation) – C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2006/08/14 01:07:00 | 000,102,400 | —- | M] () – C:\Program Files (x86)\Roxio\Media Experience\DMXLauncher.exe


========== Modules (SafeList) ==========

MOD - [2011/06/10 16:15:45 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\Steve\Desktop\OTL.exe
MOD - [2010/11/20 08:19:48 | 002,341,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msi.dll
MOD - [2010/11/20 07:55:09 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
MOD - [2009/07/13 21:16:14 | 000,040,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\sfc_os.dll
MOD - [2009/07/13 21:15:44 | 000,015,872 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msiltcfg.dll
MOD - [2009/07/13 21:10:22 | 000,002,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\sfc.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2008/12/18 15:05:28 | 000,155,648 | —- | M] (Stardock Corporation) [Auto | Running] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV - [2011/04/16 20:45:11 | 000,130,008 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe – (N360)
SRV - [2010/04/03 15:48:51 | 000,651,720 | —- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/10/29 07:54:44 | 000,865,832 | —- | M] (McAfee, Inc.) [Disabled | Stopped] – C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe – (mcmscsvc)
SRV - [2009/07/21 17:06:26 | 000,554,224 | —- | M] (Dell Inc.) [Auto | Running] – c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe – (hnmsvc)
SRV - [2009/07/08 12:54:34 | 000,359,952 | —- | M] (McAfee, Inc.) [Disabled | Stopped] – c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe – (McProxy)
SRV - [2009/07/07 20:10:02 | 002,482,848 | —- | M] (McAfee, Inc.) [Disabled | Stopped] – c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe – (McNASvc)
SRV - [2009/06/10 17:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/06/10 11:59:54 | 000,309,744 | —- | M] (Sonic Solutions) [Disabled | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe – (RoxLiveShare10)
SRV - [2009/06/10 11:59:46 | 000,166,384 | —- | M] (Sonic Solutions) [Auto | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe – (RoxWatch10)
SRV - [2009/06/10 11:58:46 | 001,124,848 | —- | M] (Sonic Solutions) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe – (RoxMediaDB10)
SRV - [2006/08/10 04:11:14 | 000,057,344 | —- | M] (Sonic Solutions) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe – (Roxio UPnP Renderer 9)
SRV - [2006/08/10 04:10:50 | 000,294,912 | —- | M] (Sonic Solutions) [Auto | Stopped] – C:\Program Files (x86)\Common Files\Sonic Shared\RoxioUpnpService9.exe – (Roxio Upnp Server 9)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/05/28 08:29:26 | 000,174,200 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS – (SymEvent)
DRV:64bit: - [2011/03/30 23:04:12 | 000,043,640 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\SymIMV.sys – (SymIM)
DRV:64bit: - [2011/03/30 23:00:09 | 000,744,568 | R— | M] (Symantec Corporation) [File_System | System | Running] – C:\Windows\SysNative\drivers\N360x64\0501000.01D\srtsp64.sys – (SRTSP)
DRV:64bit: - [2011/03/30 23:00:09 | 000,040,568 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\N360x64\0501000.01D\srtspx64.sys – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:64bit: - [2011/03/21 20:39:49 | 000,382,584 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\N360x64\0501000.01D\symnets.sys – (SymNetS)
DRV:64bit: - [2011/03/21 13:22:06 | 000,452,200 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2011/03/14 22:31:23 | 000,912,504 | R— | M] (Symantec Corporation) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\N360x64\0501000.01D\SymEFA64.sys – (SymEFA)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/02/18 16:36:58 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/02/11 19:16:38 | 010,628,640 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2011/01/27 02:47:10 | 000,450,680 | R— | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\N360x64\0501000.01D\SymDS64.sys – (SymDS)
DRV:64bit: - [2011/01/27 01:07:06 | 000,171,128 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\N360x64\0501000.01D\Ironx64.sys – (SymIRON)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/08/20 23:59:12 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2010/07/11 13:13:00 | 000,082,816 | —- | M] (VSO Software) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\pcouffin.sys – (pcouffin)
DRV:64bit: - [2010/06/16 14:38:08 | 000,092,160 | —- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys – (RimUsb)
DRV:64bit: - [2010/04/03 19:09:11 | 000,711,712 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\timntr.sys – (timounter)
DRV:64bit: - [2010/04/03 19:09:11 | 000,081,952 | —- | M] (Acronis) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\tifsfilt.sys – (tifsfilter)
DRV:64bit: - [2010/02/24 07:06:20 | 000,726,816 | —- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\netr7364.sys – (netr7364)
DRV:64bit: - [2010/01/05 19:04:02 | 000,528,232 | —- | M] (McAfee, Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\mfehidk.sys – (mfehidk)
DRV:64bit: - [2010/01/05 18:04:02 | 000,121,504 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mfeapfk.sys – (mfeapfk)
DRV:64bit: - [2009/11/04 17:54:06 | 000,102,472 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mfeavfk.sys – (mfeavfk)
DRV:64bit: - [2009/11/04 17:54:06 | 000,049,480 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mfesmfk.sys – (mfesmfk)
DRV:64bit: - [2009/09/15 14:13:34 | 000,043,008 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMP50a64.sys – (MREMP50a64)
DRV:64bit: - [2009/09/15 14:13:34 | 000,040,960 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRESP50a64.sys – (MRESP50a64)
DRV:64bit: - [2009/07/16 13:32:26 | 000,176,144 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\Mpfp.sys – (MPFP)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 20:10:47 | 000,011,264 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\rootmdm.sys – (ROOTMODEM)
DRV:64bit: - [2009/07/13 14:24:56 | 000,138,752 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService) Intel®
DRV:64bit: - [2009/06/10 17:22:14 | 000,034,640 | —- | M] (SingleClick Systems) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\packet.sys – (Packet)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/20 04:00:00 | 000,055,280 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2009/01/09 17:02:08 | 000,031,744 | —- | M] (Research in Motion Ltd) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\RimSerial_AMD64.sys – (RimVSerPort)
DRV:64bit: - [2008/10/24 11:55:28 | 000,043,008 | R— | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtTeam60.sys – (TEAM) Realtek Virtual Miniport Driver for Teaming (NDIS 6.0)
DRV:64bit: - [2008/10/24 11:55:28 | 000,043,008 | R— | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtTeam60.sys – (RTTEAMPT) Realtek Teaming Protocol Driver (NDIS 6.2)
DRV:64bit: - [2008/07/21 07:18:30 | 000,026,624 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\RtNdPt60.sys – (RtNdPt60)
DRV:64bit: - [2008/07/10 07:28:50 | 000,170,496 | —- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Rtlh64.sys – (RTL8169)
DRV:64bit: - [2007/12/03 11:20:54 | 000,024,064 | R— | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtVlan60.sys – (RTVLANPT) Realtek Vlan Protocol Driver (NDIS 6.2)
DRV:64bit: - [2006/08/09 04:32:46 | 000,058,880 | —- | M] (Sonic Solutions) [File_System | System | Stopped] – C:\Windows\SysNative\drivers\RxFilter.sys – (RxFilter)
DRV:64bit: - [2006/08/08 09:18:52 | 000,010,360 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\Windows\SysNative\DLA\DLADResE.SYS – (DLADResE)
DRV:64bit: - [2006/08/08 09:18:42 | 000,136,952 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\Windows\SysNative\DLA\DLAUDFAE.SYS – (DLAUDFAE)
DRV:64bit: - [2006/08/08 09:18:42 | 000,044,152 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\Windows\SysNative\DLA\DLABMFSE.SYS – (DLABMFSE)
DRV:64bit: - [2006/08/08 09:18:40 | 000,143,096 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\Windows\SysNative\DLA\DLAUDF_E.SYS – (DLAUDF_E)
DRV:64bit: - [2006/08/08 09:18:38 | 000,033,656 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\Windows\SysNative\DLA\DLAOPIOE.SYS – (DLAOPIOE)
DRV:64bit: - [2006/08/08 09:18:36 | 000,041,976 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\Windows\SysNative\DLA\DLABOIOE.SYS – (DLABOIOE)
DRV:64bit: - [2006/08/08 09:18:36 | 000,018,040 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\Windows\SysNative\DLA\DLAPoolE.SYS – (DLAPoolE)
DRV:64bit: - [2006/08/08 09:18:34 | 000,141,432 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\Windows\SysNative\DLA\DLAIFS_E.SYS – (DLAIFS_E)
DRV:64bit: - [2006/08/01 20:06:26 | 000,039,288 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\Windows\SysNative\drivers\DLARTL_E.SYS – (DLARTL_E)
DRV:64bit: - [2006/08/01 20:06:26 | 000,015,992 | —- | M] (Sonic Solutions) [File_System | System | Stopped] – C:\Windows\SysNative\drivers\DLACDBHE.SYS – (DLACDBHE)
DRV:64bit: - [2006/08/01 19:46:36 | 000,063,608 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\DRVEDDM.SYS – (DRVEDDM)
DRV:64bit: - [2006/07/21 11:21:28 | 000,122,776 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\DRVECDB.SYS – (DRVECDB)
DRV - [2011/06/09 18:39:39 | 002,011,768 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20110609.032\EX64.SYS – (NAVEX15)
DRV - [2011/06/09 18:39:39 | 000,117,880 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20110609.032\ENG64.SYS – (NAVENG)
DRV - [2011/06/02 21:08:18 | 000,488,056 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110604.001\IDSviA64.sys – (IDSVia64)
DRV - [2011/05/09 20:01:21 | 000,481,912 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys – (eeCtrl)
DRV - [2011/04/18 20:35:53 | 001,127,032 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110518.001\BHDrvx64.sys – (BHDrvx64)
DRV - [2010/01/07 17:11:30 | 000,146,928 | —- | M] (CyberLink Corp.) [2011/03/20 08:10:44] [Kernel | Auto | Running] – C:\Program Files (x86)\CyberLink\PowerDVD DX\000.fcl – ({1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7})
DRV - [2009/06/10 17:21:26 | 000,027,472 | —- | M] (SingleClick Systems) [Kernel | Auto | Running] – C:\Windows\SysWOW64\drivers\packet.sys – (Packet)
DRV - [2006/08/09 04:32:46 | 000,058,880 | —- | M] (Sonic Solutions) [File_System | System | Stopped] – C:\Windows\SysWOW64\drivers\RxFilter.sys – (RxFilter)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://google.com/
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/firefox"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:4.51
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;="


FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2011/05/28 08:58:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn\ [2011/05/28 08:29:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/04 19:21:38 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/01/25 19:42:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/06/05 22:17:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/06/05 22:17:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0b12\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 12\components [2011/06/05 22:17:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0b12\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 12\plugins

[2011/06/08 21:35:02 | 000,000,000 | —D | M] (No name found) – C:\Users\Steve\AppData\Roaming\Mozilla\Extensions
[2011/06/08 21:34:59 | 000,000,000 | —D | M] (No name found) – C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions
[2011/06/08 21:56:13 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2010/09/02 15:15:26 | 000,001,953 | —- | M] () – C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\searchplugins\bing-zugo.xml
[2011/05/28 12:19:15 | 000,002,469 | —- | M] () – C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\searchplugins\safesearch.xml
[2011/06/08 21:34:57 | 000,002,501 | —- | M] () – C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\searchplugins\SearchResults.xml
[2011/06/09 18:50:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/05/16 10:20:52 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/19 11:41:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/26 11:30:20 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/22 09:25:10 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/06/09 18:50:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) –
[2011/05/28 08:29:04 | 000,000,000 | —D | M] (Norton Toolbar) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\COFFPLGN
[2011/05/28 08:58:16 | 000,000,000 | —D | M] (Symantec IPS) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPLGN
() (No name found) – C:\USERS\STEVE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MQXFO7A9.DEFAULT\EXTENSIONS\[removed]
[2011/05/07 19:31:16 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2011/06/09 18:50:34 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/05/07 19:31:17 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml
[2011/06/08 21:34:57 | 000,002,501 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\SearchResults.xml

O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0FEF2D2C-CDA6-45E4-B2ED-9DF7C50C95FF} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files (x86)\Roxio\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: bing.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ct-mls.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: mlxchange.com ([ctmls] http in Trusted sites)
O15 - HKCU\..Trusted Domains: rexplorer.net ([]* in Trusted sites)
O16 - DPF: {0D859AF0-C75E-11D4-B760-00E0B81077E8} http://ctmls.mlxchange.com/5.1.01.9506/Con…FileCruiser.cab (FileCruiser Class)
O16 - DPF: {16FD824B-8E7B-11D2-9855-00802962956C} http://ctmls.mlxchange.com/5.1.01.9506/Control/Specfile.cab (Specfile Control)
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} http://support.rexplorer.net/iftw_install//iftwclix.cab (InstallFromTheWeb ActiveX Control)
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} http://ctmls.mlxchange.com/5.1.01.9506/Con…ClientUtils.cab (MLS Client Utils)
O16 - DPF: {78523E50-56EB-11D3-B739-CAA1986A452F} http://ctmls.mlxchange.com/5.1.01.9506/Control/LiteGrid.cab (LiteGridCtl Class)
O16 - DPF: {7A7537FC-5988-11D3-8B33-00104B9E5A4A} http://ctmls.mlxchange.com/5.1.01.9506/Con…IRCWebPrint.cab (IRCWwwPrint Class)
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} http://ctmls.mlxchange.com/5.1.01.9506/Control/IRCSharc.cab (GeacRevw Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {B198A72B-B4C3-42B5-B8DA-B364E76429AA} http://ctmls.mlxchange.com/5.1.01.9506/Control/WebDog.cab (Cerebus Class)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {F060A272-A18A-11D3-B75B-00E0B81077E8} http://ctmls.mlxchange.com/5.1.01.9506/Con…CustomCtrls.cab (DropList Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (MACHINE BootExecut) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/06/10 16:15:43 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Users\Steve\Desktop\OTL.exe
[2011/06/10 15:59:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/06/10 15:59:30 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011/06/10 15:52:59 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\Systweak
[2011/06/10 15:52:56 | 000,018,816 | —- | C] (Systweak Inc., (www.systweak.com)) – C:\Windows\SysNative\roboot64.exe
[2011/06/10 15:07:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/06/10 15:07:08 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/06/09 18:53:07 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/06/09 18:51:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2011/06/09 18:50:47 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/06/09 18:50:47 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/06/09 18:50:47 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/06/09 15:26:27 | 000,253,888 | —- | C] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2011/06/09 15:24:35 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2011/06/09 15:24:35 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2011/06/09 07:21:59 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\NPE
[2011/06/08 21:43:06 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\vlc
[2011/06/08 21:34:57 | 000,000,000 | —D | C] – C:\ProgramData\boost_interprocess
[2011/06/08 21:34:27 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\PackageAware
[2011/06/06 15:57:05 | 000,000,000 | —D | C] – C:\Users\Steve\Desktop\Nathan's ipod folder
[2011/06/06 15:49:21 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\WinRAR
[2011/06/06 15:49:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinRAR
[2011/06/05 22:19:11 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\Apple Computer
[2011/06/05 22:19:11 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\Apple Computer
[2011/06/05 22:18:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/06/05 22:18:37 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/06/05 22:18:37 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2011/06/05 22:17:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/06/05 22:17:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011/06/05 22:17:19 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/06/05 22:17:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/06/05 22:17:10 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\Apple
[2011/06/05 22:16:49 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/06/05 22:16:37 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/06/05 22:16:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/06/05 22:16:32 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/06/05 22:16:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011/05/31 21:45:52 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\Memorex
[2011/05/28 08:29:28 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2011/05/25 14:09:14 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Support Center
[2011/05/25 14:08:52 | 000,000,000 | —D | C] – C:\Program Files\Dell Support Center
[2011/05/25 07:36:12 | 000,027,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/05/24 20:34:48 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\acccore
[2011/05/24 20:34:47 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\AOL
[2011/05/24 20:34:47 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\AIM
[2011/05/24 20:05:25 | 000,000,000 | —D | C] – C:\ProgramData\AIM
[2011/05/24 20:05:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Software Update Utility
[2011/05/24 20:05:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AOL
[2011/05/19 19:02:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 8 Qt
[2011/05/19 19:02:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\DVDFab 8 Qt
[2011/05/18 19:45:13 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2011/05/18 19:45:13 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2011/05/18 15:23:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\TotalRecipeSearch_14EI
[2011/05/12 21:56:26 | 000,000,000 | —D | C] – C:\Users\Steve\New folder (2)
[2010/07/11 13:13:00 | 000,082,816 | —- | C] (VSO Software) – C:\Users\Steve\AppData\Roaming\pcouffin.sys
[2006/07/11 14:29:00 | 000,028,672 | R— | C] ( ) – C:\Windows\SysWow64\DivXGraphBuilderCallback.dll

========== Files - Modified Within 30 Days ==========

[2011/06/10 16:15:57 | 000,011,104 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/10 16:15:57 | 000,011,104 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/10 16:15:45 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\Steve\Desktop\OTL.exe
[2011/06/10 16:08:19 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/10 16:07:57 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/10 16:07:40 | 2120,097,791 | -HS- | M] () – C:\hiberfil.sys
[2011/06/10 16:06:56 | 000,001,660 | —- | M] () – C:\Windows\SysNative\ASOROSet.bin
[2011/06/10 15:56:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1025321475-1952006879-3800771920-1000UA.job
[2011/06/10 15:34:44 | 000,002,655 | —- | M] () – C:\Users\Steve\Desktop\Microsoft Word.lnk
[2011/06/10 15:19:43 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2011/06/10 15:07:14 | 000,001,785 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/06/10 15:06:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/09 18:58:20 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1025321475-1952006879-3800771920-1000Core.job
[2011/06/09 18:53:19 | 000,002,315 | —- | M] () – C:\Users\Steve\Desktop\Google Chrome.lnk
[2011/06/09 18:50:33 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2011/06/09 18:50:33 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/06/09 18:50:33 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/06/09 18:50:33 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/06/09 15:26:28 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2011/06/09 04:58:40 | 001,660,698 | —- | M] () – C:\Windows\SysNative\drivers\N360x64\0501000.01D\Cat.DB
[2011/06/08 23:04:55 | 000,386,072 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/08 22:18:18 | 000,001,115 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/07 13:03:14 | 000,018,816 | —- | M] (Systweak Inc., (www.systweak.com)) – C:\Windows\SysNative\roboot64.exe
[2011/06/05 22:17:24 | 000,001,847 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/06/04 15:30:30 | 032,887,084 | —- | M] () – C:\Users\Steve\AppData\Local\rx_image.Cache
[2011/05/31 22:03:42 | 000,305,331 | —- | M] () – C:\Users\Steve\interesting.jpg
[2011/05/31 21:43:59 | 000,739,918 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/05/31 21:43:59 | 000,632,708 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/05/31 21:43:59 | 000,110,342 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/05/31 15:03:40 | 000,002,058 | —- | M] () – C:\Users\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/29 09:11:30 | 000,039,984 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,025,912 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/05/28 08:56:10 | 000,002,390 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2011/05/28 08:29:26 | 000,174,200 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2011/05/28 08:29:26 | 000,007,488 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2011/05/28 08:29:26 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2011/05/28 07:17:02 | 000,001,940 | —- | M] () – C:\Users\Steve\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/26 23:00:00 | 000,000,338 | —- | M] () – C:\Windows\tasks\Regwork.job
[2011/05/25 21:52:18 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2011/05/24 20:05:31 | 000,000,374 | -H– | M] () – C:\IPH.PH
[2011/05/24 15:17:14 | 000,044,255 | —- | M] () – C:\Users\Steve\Shadowrobot8888.jpg
[2011/05/22 08:35:58 | 000,005,632 | —- | M] () – C:\Users\Steve\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/19 19:31:04 | 000,389,602 | —- | M] () – C:\Users\Steve\Desktop\Category_Fact_Sheets.pdf
[2011/05/19 19:26:09 | 001,187,257 | —- | M] () – C:\Users\Steve\Desktop\RC2009_bridges.pdf
[2011/05/19 19:02:43 | 000,001,022 | —- | M] () – C:\Users\Steve\Desktop\DVDFab 8 Qt.lnk

========== Files Created - No Company Name ==========

[2011/06/10 16:01:33 | 000,001,660 | —- | C] () – C:\Windows\SysNative\ASOROSet.bin
[2011/06/10 15:34:44 | 000,002,655 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Word.lnk
[2011/06/10 15:07:14 | 000,001,785 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/06/09 18:53:18 | 000,002,315 | —- | C] () – C:\Users\Steve\Desktop\Google Chrome.lnk
[2011/06/09 18:51:26 | 000,000,908 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1025321475-1952006879-3800771920-1000UA.job
[2011/06/09 18:51:23 | 000,000,856 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1025321475-1952006879-3800771920-1000Core.job
[2011/06/09 15:26:27 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2011/06/08 22:18:17 | 000,001,115 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/05 22:17:23 | 000,001,847 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/31 22:03:55 | 000,305,331 | —- | C] () – C:\Users\Steve\interesting.jpg
[2011/05/25 14:09:41 | 000,000,564 | —- | C] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2011/05/25 14:09:39 | 000,000,506 | —- | C] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2011/05/24 20:05:08 | 000,000,374 | -H– | C] () – C:\IPH.PH
[2011/05/24 15:17:14 | 000,044,255 | —- | C] () – C:\Users\Steve\Shadowrobot8888.jpg
[2011/05/19 19:31:04 | 000,389,602 | —- | C] () – C:\Users\Steve\Desktop\Category_Fact_Sheets.pdf
[2011/05/19 19:26:08 | 001,187,257 | —- | C] () – C:\Users\Steve\Desktop\RC2009_bridges.pdf
[2011/05/19 19:02:42 | 000,001,022 | —- | C] () – C:\Users\Steve\Desktop\DVDFab 8 Qt.lnk
[2011/05/18 17:04:44 | 000,001,940 | —- | C] () – C:\Users\Steve\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/03/20 14:17:43 | 032,887,084 | —- | C] () – C:\Users\Steve\AppData\Local\rx_image.Cache
[2011/03/20 13:55:17 | 000,056,056 | —- | C] () – C:\Windows\SysWow64\DLAAPI_W.DLL
[2011/03/20 13:55:17 | 000,000,132 | —- | C] () – C:\Windows\wininit.ini
[2011/03/20 13:41:14 | 000,755,554 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/03/13 13:25:35 | 000,005,632 | —- | C] () – C:\Users\Steve\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/02 16:37:30 | 000,090,112 | —- | C] () – C:\Windows\SysWow64\imsfchk.dll
[2011/03/02 16:37:30 | 000,053,248 | —- | C] () – C:\Windows\SysWow64\imslevel.dll
[2011/01/31 19:22:03 | 000,225,280 | —- | C] () – C:\Windows\SysWow64\net_rim_plazmic_flint_dialog.dll
[2010/08/25 20:34:30 | 000,982,240 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2010/08/25 20:34:30 | 000,439,308 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2010/08/25 20:34:30 | 000,092,356 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2010/07/11 13:13:00 | 000,099,384 | —- | C] () – C:\Users\Steve\AppData\Roaming\inst.exe
[2010/07/11 13:13:00 | 000,007,859 | —- | C] () – C:\Users\Steve\AppData\Roaming\pcouffin.cat
[2010/07/11 13:13:00 | 000,001,167 | —- | C] () – C:\Users\Steve\AppData\Roaming\pcouffin.inf
[2010/06/15 15:59:08 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\imsaiff.dll
[2010/04/06 18:43:58 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2010/04/04 19:18:08 | 000,220,535 | —- | C] () – C:\Windows\hpwins05.dat
[2010/04/04 19:18:08 | 000,002,751 | —- | C] () – C:\Windows\hpwmdl05.dat
[2010/04/03 19:39:49 | 000,000,000 | —- | C] () – C:\Users\Steve\AppData\Roaming\wklnhst.dat
[2010/02/07 19:37:50 | 000,146,432 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2010/02/07 19:37:50 | 000,072,704 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2010/02/07 19:32:45 | 000,134,592 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 10:12:52 | 000,217,088 | —- | C] () – C:\Windows\SysWow64\missouri.dll
[2006/08/15 15:54:02 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\px.ini
[2006/08/09 04:19:50 | 000,520,192 | —- | C] () – C:\Windows\SysWow64\CddbPlaylist2Roxio.dll
[2006/08/09 04:19:50 | 000,204,800 | —- | C] () – C:\Windows\SysWow64\CddbFileTaggerRoxio.dll
[2006/08/09 01:00:00 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\besch.exe
[2006/08/09 01:00:00 | 000,028,672 | —- | C] () – C:\Windows\SysWow64\besched.dll
[2005/07/15 14:36:35 | 000,524,288 | —- | C] () – C:\Windows\SysWow64\DivXsm.exe
[2005/07/15 14:35:56 | 000,831,488 | —- | C] () – C:\Windows\SysWow64\libeay32.dll
[2005/07/15 14:35:56 | 000,159,744 | —- | C] () – C:\Windows\SysWow64\ssleay32.dll
[2005/07/15 14:35:24 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2003/10/02 01:00:00 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\lockout.dll
[2003/10/02 01:00:00 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\lockres.dll
[2002/08/09 08:18:44 | 000,036,864 | —- | C] () – C:\Windows\SysWow64\pandoras.dll

========== LOP Check ==========

[2011/05/24 20:35:11 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\acccore
[2011/02/01 13:36:56 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\Blackberry Desktop
[2011/04/18 14:28:27 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\Dev-Cpp
[2011/05/31 21:45:52 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\Memorex
[2011/04/18 11:52:13 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\Notepad++
[2011/05/25 14:07:28 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\PCDr
[2011/01/31 19:22:03 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\Plazmic
[2011/01/31 19:28:59 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\Research In Motion
[2011/06/10 16:01:50 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\Systweak
[2010/04/03 19:39:56 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\Template
[2010/05/02 16:19:22 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\Tific
[2010/07/11 13:13:35 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\Vso
[2010/02/07 20:22:18 | 000,000,340 | —- | M] () – C:\Windows\Tasks\McDefragTask.job
[2011/05/01 05:35:35 | 000,000,318 | —- | M] () – C:\Windows\Tasks\McQcTask.job
[2011/05/25 21:52:18 | 000,000,564 | —- | M] () – C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2011/05/26 23:00:00 | 000,000,338 | —- | M] () – C:\Windows\Tasks\Regwork.job
[2011/03/26 08:56:59 | 000,032,624 | —- | M] () – C:\Windows\Tasks\SCHEDLGU(59).TXT
[2011/03/26 08:56:59 | 000,032,624 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/06/10 15:19:43 | 000,000,506 | —- | M] () – C:\Windows\Tasks\SystemToolsDailyTest.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/13 21:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysNative\drivers\AGP440.sys
[2009/07/13 21:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009/07/13 21:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009/07/13 21:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/13 21:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\drivers\atapi.sys
[2009/07/13 21:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009/07/13 21:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009/07/13 21:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/13 21:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 21:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 21:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\SysNative\cngaudit.dll
[2009/07/13 21:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2008/07/15 08:14:10 | 000,395,288 | —- | M] (Intel Corporation) MD5=07FB761600EFF44AF02C35B8B57E5863 – C:\Drivers\storage\R191912\IaStor.sys
[2008/07/15 08:14:10 | 000,395,288 | —- | M] (Intel Corporation) MD5=07FB761600EFF44AF02C35B8B57E5863 – C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_55ef5f4d4432a543\iaStor.sys
[2008/07/15 08:14:10 | 000,395,288 | —- | M] (Intel Corporation) MD5=07FB761600EFF44AF02C35B8B57E5863 – C:\Windows\SysNative\DriverStore\FileRepository\iastor.inf_amd64_neutral_7d1fabcba616244f\iaStor.sys
[2009/06/04 19:54:36 | 000,408,600 | —- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 – C:\DELL\drivers\R235596\IaStor.sys

< MD5 for: IASTORV.SYS >
[2010/11/20 09:33:38 | 000,410,496 | —- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D – C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010/11/20 09:33:38 | 000,410,496 | —- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011/03/11 02:19:16 | 000,410,496 | —- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011/03/11 02:41:26 | 000,410,496 | —- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 – C:\Windows\SysNative\drivers\iaStorV.sys
[2011/03/11 02:41:26 | 000,410,496 | —- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 – C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011/03/11 02:41:26 | 000,410,496 | —- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011/03/11 02:23:00 | 000,410,496 | —- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011/03/11 02:25:49 | 000,410,496 | —- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009/07/13 21:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/13 21:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010/11/20 09:27:22 | 000,695,808 | —- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 – C:\Windows\SysNative\netlogon.dll
[2010/11/20 09:27:22 | 000,695,808 | —- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010/11/20 08:20:28 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B – C:\Windows\SysWOW64\netlogon.dll
[2010/11/20 08:20:28 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009/07/13 21:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVRAID.SYS >
[2011/03/11 02:41:34 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD – C:\Windows\SysNative\drivers\nvraid.sys
[2011/03/11 02:41:34 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvraid.sys
[2011/03/11 02:41:34 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvraid.sys
[2009/07/13 21:48:27 | 000,149,056 | —- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvraid.sys
[2010/11/20 09:33:48 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=5D9FD91F3D38DC9DA01E3CB5FA89CD48 – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvraid.sys
[2010/11/20 09:33:48 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=5D9FD91F3D38DC9DA01E3CB5FA89CD48 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvraid.sys
[2011/03/11 02:19:21 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=666CA16F17914C1CD3616CF16DE0A6EA – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvraid.sys
[2011/03/11 02:23:06 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=A4D9C9A608A97F59307C2F2600EDC6A4 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvraid.sys
[2011/03/11 02:25:53 | 000,148,352 | —- | M] (NVIDIA Corporation) MD5=A5C82EB2F72AA004887F90B84A771F73 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvraid.sys

< MD5 for: NVSTOR.SYS >
[2009/07/13 21:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011/03/11 02:23:06 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011/03/11 02:25:53 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011/03/11 02:19:21 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011/03/11 02:41:34 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A – C:\Windows\SysNative\drivers\nvstor.sys
[2011/03/11 02:41:34 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011/03/11 02:41:34 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010/11/20 09:33:48 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010/11/20 09:33:48 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/13 21:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/13 21:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010/11/20 08:21:04 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 – C:\Windows\SysWOW64\scecli.dll
[2010/11/20 08:21:04 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/20 09:27:25 | 000,232,960 | —- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C – C:\Windows\SysNative\scecli.dll
[2010/11/20 09:27:25 | 000,232,960 | —- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\drivers\*.sys /90 >
[2011/05/29 09:11:30 | 000,039,984 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWOW64\drivers\mbamswissarmy.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> C:\Users\Steve\Documents\Presentation2.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Steve\Documents\Presentation1:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Steve\Documents\Presentation1.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Steve\Documents\Mountain Side Snow Wp TW.png:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Steve\Documents\Hamden Bradley:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Steve\Documents\gameCard.png:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Steve\Documents\flickr-1438110499-original.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Steve\Documents\Derby Warehouse:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Steve\Desktop\Nathan's ipod folder:Roxio EMC Stream

< End of report >
OTL Extras logfile created on: 6/10/2011 4:17:28 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Steve\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.97 Gb Total Physical Memory | 6.25 Gb Available Physical Memory | 78.44% Memory free
15.93 Gb Paging File | 14.20 Gb Available in Paging File | 89.15% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 683.58 Gb Total Space | 530.97 Gb Free Space | 77.67% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 7.80 Gb Free Space | 52.02% Space Free | Partition Type: NTFS
Drive M: | 931.50 Gb Total Space | 177.61 Gb Free Space | 19.07% Space Free | Partition Type: NTFS

Computer Name: HOM | User Name: Steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{02AD9D20-03D2-4DE0-8793-E8253026AD86}" = EMCGadgets64
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{18155797-EF2E-4699-9A16-FE787C4C10DB}" = iTunes
"{22ABA92B-6C1B-46D8-AC2B-C48EEAE172A9}" = VD64Inst
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{8F473675-D702-45F9-8EBC-342B40C17BF5}" = Apple Mobile Device Support
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{A219F6D7-D2AD-4DD5-AC31-C23AA2E18084}" = HP OfficeJet L7300/L7500/7600/7700
"{E60B7350-EA5F-41E0-9D6F-E508781E36D2}" = Dell Dock
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"ATT-SST-UversePortal" = AT&T Portal
"CCleaner" = CCleaner
"Dell Support Center" = Dell Support Center
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Shop for HP Supplies" = Shop for HP Supplies

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{098122AB-C605-4853-B441-C0A4EB359B75}" = DirectXInstallService
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2656D0AB-9EA4-4C58-A117-635F3CED8B93}" = Microsoft UI Engine
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java™ 6 Update 26
"{2B4C7E1E-E446-4740-ADB5-9842E742EE8A}" = Windows Live Toolbar
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3EC92206-C4A6-49CF-A272-92F75CB1D5F3}" = bpd_scan
"{3FB3647F-B6A6-46B4-8613-A09BCFAB80F0}" = Roxio Creator Premier 10
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{469EF13B-4AD0-48D7-AF89-6B92278293E2}" = Roxio Creator Premier
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A8B8118-1C13-48F1-81FB-A5101C2111A8}" = L7500
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{61FEAA90-615B-4243-B7DA-075D0898C018}" = BPDSoftware
"{625304B0-2976-473B-AD81-5CA376093F03}" = Xingtone Ringtone Maker
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{7236672F-6430-439E-9B27-27EDEAF1D676}" = Diagnostic Utility
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{84A78614-0E4B-4A4E-BA8C-2B0A05A08E4E}" = BlackBerry Desktop Software 6.0.1
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Roxio CinePlayer Decoder Pack
"{8F968232-15C6-4872-84C2-9FCDAA1AEAB6}" = MPM
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90024193-9F13-4877-89D5-A1CDF0CBBF28}" = Feedback Tool
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{913D0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Standard for Students and Teachers
"{938B1CD7-7C60-491E-AA90-1F1888168240}" = Roxio Easy Media Creator 9 Suite
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{99B8D963-82E9-4062-8068-77FD918D34ED}" = ProductContext
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A639BD63-8CE6-11D5-B4CC-00105A07274A}" = REXplorer Component Upgrade
"{A6BFA328-0A46-42EF-B414-8B67E87A2B1F}" = 7500_7600_7700_Help
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAA0C1E1-8F39-4AB0-9283-78140537BB40}" = BPDSoftware_Ini
"{AC76BA86-1033-0000-7760-000000000004}" = Adobe Acrobat 9 Pro
"{AC76BA86-1033-0000-7760-000000000004}_944" = Adobe Acrobat 9.4.4 - CPSID_83708
"{AC76BA86-1033-0000-7760-000000000004}{AC76BA86-1033-0000-7760-000000000004}" = Adobe Acrobat 9 Pro
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator Premier
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F66A31D9-7831-4FBA-BA02-C411C0047CC5}" = Dell Remote Access
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.0.1
"DVDFab 7_is1" = DVDFab 7.0.7.0 (08/06/2010)
"DVDFab 8 Qt_is1" = DVDFab 8.0.9.2 (12/05/2011) Qt
"DVDFab 8_is1" = DVDFab 8.0.8.5 (19/03/2011)
"Halo Combat Evolved" = Halo Combat Evolved
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.0.1200
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"Mozilla Firefox 4.0b12 (x86 en-US)" = Mozilla Firefox 4.0b12 (x86 en-US)
"MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
"N360" = Norton 360
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Companion" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/10/2011 8:17:18 AM | Computer Name = HOM | Source = WinMgmt | ID = 10
Description =

Error - 6/10/2011 8:19:27 AM | Computer Name = HOM | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/10/2011 9:04:06 AM | Computer Name = HOM | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files (x86)\Research
In Motion\BlackBerry Desktop\MailServerMAPIProxy64.exe". Dependent Assembly Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 6/10/2011 9:04:09 AM | Computer Name = HOM | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Research In Motion\AppLoader\MailServerMAPIProxy64.exe". Dependent Assembly
Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 6/10/2011 9:04:09 AM | Computer Name = HOM | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files (x86)\Research
In Motion\BlackBerry Desktop\IntelliSync\Connectors\MS Outlook Connector\X64\MsOutlookApiProxy.exe".
Dependent
Assembly Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 6/10/2011 9:04:43 AM | Computer Name = HOM | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 6/10/2011 3:20:51 PM | Computer Name = HOM | Source = WinMgmt | ID = 10
Description =

Error - 6/10/2011 3:29:23 PM | Computer Name = HOM | Source = WinMgmt | ID = 10
Description =

Error - 6/10/2011 3:37:26 PM | Computer Name = HOM | Source = WinMgmt | ID = 10
Description =

Error - 6/10/2011 4:09:22 PM | Computer Name = HOM | Source = WinMgmt | ID = 10
Description =

[ Media Center Events ]
Error - 5/22/2011 5:13:19 AM | Computer Name = HOM | Source = MCUpdate | ID = 0
Description = 5:13:18 AM - Error connecting to the internet. 5:13:18 AM - Unable
to contact server..

Error - 5/22/2011 6:14:00 AM | Computer Name = HOM | Source = MCUpdate | ID = 0
Description = 6:14:00 AM - Error connecting to the internet. 6:14:00 AM - Unable
to contact server..

Error - 5/22/2011 6:14:31 AM | Computer Name = HOM | Source = MCUpdate | ID = 0
Description = 6:14:30 AM - Error connecting to the internet. 6:14:30 AM - Unable
to contact server..

Error - 5/22/2011 7:15:12 AM | Computer Name = HOM | Source = MCUpdate | ID = 0
Description = 7:15:12 AM - Error connecting to the internet. 7:15:12 AM - Unable
to contact server..

Error - 5/22/2011 7:15:43 AM | Computer Name = HOM | Source = MCUpdate | ID = 0
Description = 7:15:42 AM - Error connecting to the internet. 7:15:42 AM - Unable
to contact server..

Error - 5/22/2011 8:16:24 AM | Computer Name = HOM | Source = MCUpdate | ID = 0
Description = 8:16:24 AM - Error connecting to the internet. 8:16:24 AM - Unable
to contact server..

Error - 5/22/2011 8:16:55 AM | Computer Name = HOM | Source = MCUpdate | ID = 0
Description = 8:16:54 AM - Error connecting to the internet. 8:16:54 AM - Unable
to contact server..

Error - 5/29/2011 5:46:21 PM | Computer Name = HOM | Source = MCUpdate | ID = 0
Description = 5:46:17 PM - Error connecting to the internet. 5:46:17 PM - Unable
to contact server..

Error - 6/5/2011 8:07:49 AM | Computer Name = HOM | Source = MCUpdate | ID = 0
Description = 8:07:49 AM - Error connecting to the internet. 8:07:49 AM - Unable
to contact server..

Error - 6/5/2011 8:07:59 AM | Computer Name = HOM | Source = MCUpdate | ID = 0
Description = 8:07:54 AM - Error connecting to the internet. 8:07:54 AM - Unable
to contact server..

[ System Events ]
Error - 6/10/2011 3:20:24 PM | Computer Name = HOM | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RxFilter SASDIFSV SASKUTIL

Error - 6/10/2011 3:27:42 PM | Computer Name = HOM | Source = Application Popup | ID = 876
Description = Driver DLACDBHE.SYS has been blocked from loading.

Error - 6/10/2011 3:28:59 PM | Computer Name = HOM | Source = Service Control Manager | ID = 7000
Description = The McciServiceHost service failed to start due to the following error:
%%2

Error - 6/10/2011 3:29:16 PM | Computer Name = HOM | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RxFilter SASDIFSV SASKUTIL

Error - 6/10/2011 3:35:42 PM | Computer Name = HOM | Source = Application Popup | ID = 876
Description = Driver DLACDBHE.SYS has been blocked from loading.

Error - 6/10/2011 3:36:18 PM | Computer Name = HOM | Source = Service Control Manager | ID = 7000
Description = The McciServiceHost service failed to start due to the following error:
%%2

Error - 6/10/2011 3:36:39 PM | Computer Name = HOM | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RxFilter SASDIFSV SASKUTIL

Error - 6/10/2011 4:03:37 PM | Computer Name = HOM | Source = Application Popup | ID = 876
Description = Driver DLACDBHE.SYS has been blocked from loading.

Error - 6/10/2011 4:07:37 PM | Computer Name = HOM | Source = Application Popup | ID = 876
Description = Driver DLACDBHE.SYS has been blocked from loading.

Error - 6/10/2011 4:08:53 PM | Computer Name = HOM | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RxFilter SASDIFSV SASKUTIL


< End of report >
Hi,

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2011/06/08 21:56:13 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
    O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0FEF2D2C-CDA6-45E4-B2ED-9DF7C50C95FF} - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log



NEXT

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
All processes killed
========== OTL ==========
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\components folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\searchbar folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\options folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\weatherbutton\panels\images folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\weatherbutton\panels folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\weatherbutton\icons folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\weatherbutton folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\uwa folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\radio\images folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\radio\css folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\radio folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\images folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\default\images folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\default\css folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\default folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\css folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.PPCBully folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\css folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\images folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\css folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\css folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\skin folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\images folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\css folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2 folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\com.djboxservice.dj.DJBox\thumbs folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\com.djboxservice.dj.DJBox folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\modules folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\lib folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\data\search folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\data folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome folder moved successfully.
C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\mqxfo7a9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} folder moved successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0FEF2D2C-CDA6-45E4-B2ED-9DF7C50C95FF} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FEF2D2C-CDA6-45E4-B2ED-9DF7C50C95FF}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Steve\Desktop\cmd.bat deleted successfully.
C:\Users\Steve\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: Steve
->Flash cache emptied: 681 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: Steve
->Temp folder emptied: 1404994 bytes
->Temporary Internet Files folder emptied: 2962796 bytes
->Java cache emptied: 38608103 bytes
->FireFox cache emptied: 53180266 bytes
->Google Chrome cache emptied: 12088407 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 896624 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50400 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 326 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 104.00 mb


OTL by OldTimer - Version 3.2.23.0 log created on 06102011_172433

Files\Folders moved on Reboot…
C:\Users\Steve\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot…
If it sticks longer than half an hour, then it is probably hung, so open task manager (ctrl + alt + delete) and look for the following processes

pev.exe, sed.exe, cfxxx.exe > if you seen them > end the process


now please delete the copy that you have on your desktop and download a fresh copy but rename it to iexplore before saving it to your desktop > now boot into safe mode and run it

> tap F8 repeatedly on boot up until an option menu appears > arrow up to "safe mode"

If ComboFix still wont run then run it the following way:

Press the WinKey + R to open a run box

copy / paste the following command into the open run box and press OK

ComboFix /nombr
Im sorry I have important things to do this weekend can we rescedule to Monday in the afternoon. P.S the process you told me to end kept coming back what does that mean?
Both ways wouldn't work any suggestions. Combo fix just sits there now but it could at least scan the first time. Also IE is faster than my other browsers is that bad?
Please run the following:
Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)

NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI