This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Problems

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My son has been using my computer lately and now I keep getting infections on my Malwarebytes scans. I had something called PUP Magoo on the last run and tried to remove them, but now get an error when I turn my computer on about a playpickle dll being missing.

Here is my Hijackthis log.

I ran OTL also and thought I saved it - but when I tried to run it - the computer suggested I run it in Avast Sandbox - and now I can't locate the files - so I think it didn't save them.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:11:12 PM, on 7/21/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Program Files (x86)\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Microsoft\BingBar\BingBar.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\Microsoft\BingBar\BingApp.exe
C:\windows\SysWOW64\Macromed\Flash\FlashUtil10t_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Janet\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie9
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie9
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: FCTBPos00Pos - {6FFB615D-E8CE-4ADD-8D9F-31C4BE9C26E4} - C:\Program Files (x86)\InboxDollars\Toolbar.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: InboxDollars - {47980628-3844-42AA-A0DD-E2D86BBA9600} - C:\Program Files (x86)\InboxDollars\Toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files (x86)\NetRatingsNetSight\NetSight\NielsenOnline.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Play Pickle] C:\Program Files (x86)\Play Pickle\playpickle32.exe a
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" UNATTENDED
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Nielsen Update (NielsenUpdate) - The Nielsen Company - C:\Program Files (x86)\NetRatingsNetSight\NetSight\NielsenUpdate.exe
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: Toshiba Laptop Checkup Application Launcher (Norton PC Checkup Application Launcher) - Symantec Corporation - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\SymcPCCULaunchSvc.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 14195 bytes

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, free_spirit_etc

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.
Hello there,

I need you to run OTL again but you have to save it to desktop and allow it to run under normal mode.

Can you post the latest MBAM log for me as well? - Split logs into two posts if it's too long.

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

On your next reply please post :
OTL log
GMER log
Checkup log
MBAM log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Thank you so very much!

When I tried to run OTL as adminstrator - I got an error EOIe system error - module OTL.exe at 000571A5 class not registered. When I just opened it to run - it worked.

Logs:

OTL logfile created on: 7/22/2011 11:11:19 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\Janet\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 1.59 Gb Available Physical Memory | 57.86% Memory free
5.49 Gb Paging File | 4.09 Gb Available in Paging File | 74.57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 287.63 Gb Total Space | 243.85 Gb Free Space | 84.78% Space Free | Partition Type: NTFS

Computer Name: JANET-PC | User Name: Janet | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Janet\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files (x86)\NetRatingsNetSight\NetSight\NielsenOnline.exe (The Nielsen Company)
PRC - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\Janet\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Alwil Software\Avast5\snxhk.dll (AVAST Software)
MOD - C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\dfshim.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msvcr100_clr0400.dll (Microsoft Corporation)
MOD - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\normaliz.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Norton PC Checkup Application Launcher) – C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (NielsenUpdate) – C:\Program Files (x86)\NetRatingsNetSight\NetSight\NielsenUpdate.exe (The Nielsen Company)
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (TMachInfo) – C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (PCCUJobMgr) – C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atipmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (tdcmdpst) – C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:64bit: - (TVALZ) – C:\Windows\SysNative\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (FwLnk) – C:\Windows\SysNative\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV - (nnfwdk) – C:\Program Files (x86)\NetRatingsNetSight\NetSight\meter1\nnfwdk64.sys (The Nielsen Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…A&bmod=TSNA
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…A&bmod=TSNA

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie9
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie9
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search..defaultengine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..defaultenginename: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..order.1: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..selectedEngine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..selectedEngineURL: "http://mp3tubetoolbar.com/?&prt=pinballtbfour01ff&clid=d0d4069c544a4434b946aa2daf990926&subid=&keywords={searchTerms}"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig?brand=TSNA&bmod=TSNA"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.3
FF - prefs.js..extensions.enabledItems: {D908A1CC-54B4-4af9-9BB4-964F5BD3CDB7}:1.0.0
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.5.0.7896
FF - prefs.js..network.proxy.type: 0

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.652: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.652: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D908A1CC-54B4-4af9-9BB4-964F5BD3CDB7}: C:\PROGRAM FILES (X86)\NETRATINGSNETSIGHT\NETSIGHT\METER1\FFADDON\ [2011/07/13 00:45:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/01/29 03:15:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/07/11 03:26:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D908A1CC-54B4-4af9-9BB4-964F5BD3CDB7}: C:\Program Files (x86)\NetRatingsNetSight\NetSight\meter1\FFAddon\ [2011/07/13 00:45:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/07/11 03:26:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/07/14 03:27:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/07/11 03:26:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/07/14 03:27:54 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/01/29 03:15:15 | 000,000,000 | —D | M]

[2011/01/08 03:21:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Janet\AppData\Roaming\Mozilla\Extensions
[2011/07/21 12:16:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Janet\AppData\Roaming\Mozilla\Firefox\Profiles\2tgbsxcq.default\extensions
[2011/05/17 13:12:44 | 000,002,333 | —- | M] () – C:\Users\Janet\AppData\Roaming\Mozilla\Firefox\Profiles\2tgbsxcq.default\searchplugins\askcom.xml
[2011/07/13 17:55:27 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/07/13 17:55:27 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/02/25 01:58:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/03/02 01:09:54 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\NPcol400.dll
[2011/03/02 01:09:54 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\NPcol500.dll
[2011/03/18 12:33:21 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2010/12/21 00:07:19 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 12:33:22 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2011/04/09 20:28:52 | 000,432,374 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 14880 more lines…
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll (Google Inc.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (InboxDollars BHO) - {6FFB615D-E8CE-4ADD-8D9F-31C4BE9C26E4} - C:\Program Files (x86)\InboxDollars\Toolbar.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll ()
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (InboxDollars) - {47980628-3844-42AA-A0DD-E2D86BBA9600} - C:\Program Files (x86)\InboxDollars\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (InboxDollars) - {47980628-3844-42AA-A0DD-E2D86BBA9600} - C:\Program Files (x86)\InboxDollars\Toolbar.dll ()
O4:64bit: - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [NielsenOnline] C:\Program Files (x86)\NetRatingsNetSight\NetSight\NielsenOnline.exe (The Nielsen Company)
O4 - HKLM..\Run: [Play Pickle] C:\Program Files (x86)\Play Pickle\playpickle32.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe (Toshiba)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{870a3177-e0db-11df-bffe-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{870a3177-e0db-11df-bffe-806e6f6e6963}\Shell\AutoRun\command - "" = D:\SETUP.EXE
O33 - MountPoints2\{870a3177-e0db-11df-bffe-806e6f6e6963}\Shell\configure\command - "" = D:\SETUP.EXE
O33 - MountPoints2\{870a3177-e0db-11df-bffe-806e6f6e6963}\Shell\install\command - "" = D:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/07/22 00:03:06 | 000,000,000 | —D | C] – C:\Users\Janet\AppData\Local\{F5781A76-D208-4030-A12A-8621A9F2BF1C}
[2011/07/21 21:27:52 | 000,000,000 | —D | C] – C:\Users\Janet\Desktop\Restaurants
[2011/07/21 21:25:38 | 000,000,000 | —D | C] – C:\Users\Janet\Desktop\Bonuses
[2011/07/21 21:12:25 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Users\Janet\Desktop\OTL.exe
[2011/07/21 21:09:48 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Janet\Desktop\HiJackThis.exe
[2011/07/21 04:38:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Play Pickle
[2011/07/19 13:22:16 | 000,000,000 | —D | C] – C:\Users\Janet\Desktop\HP Movie Tickets Used
[2011/07/19 12:29:25 | 000,000,000 | —D | C] – C:\Users\Janet\Desktop\2009 Taxes
[2011/07/16 11:06:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Safari
[2011/07/16 11:04:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/07/14 03:27:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2011/07/14 03:19:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe AIR
[2011/07/14 01:52:51 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieapfltr.dat
[2011/07/14 01:52:51 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieapfltr.dat
[2011/07/14 01:52:51 | 002,303,488 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript9.dll
[2011/07/14 01:52:51 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\jscript9.dll
[2011/07/14 01:52:51 | 001,492,992 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\inetcpl.cpl
[2011/07/14 01:52:51 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\inetcpl.cpl
[2011/07/14 01:52:51 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript.dll
[2011/07/14 01:52:51 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\jscript.dll
[2011/07/14 01:52:51 | 000,697,344 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msfeeds.dll
[2011/07/14 01:52:51 | 000,603,648 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\vbscript.dll
[2011/07/14 01:52:51 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\msfeeds.dll
[2011/07/14 01:52:51 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieapfltr.dll
[2011/07/14 01:52:51 | 000,452,608 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\dxtmsft.dll
[2011/07/14 01:52:51 | 000,448,512 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\html.iec
[2011/07/14 01:52:51 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieapfltr.dll
[2011/07/14 01:52:51 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\html.iec
[2011/07/14 01:52:51 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\dxtmsft.dll
[2011/07/14 01:52:51 | 000,282,112 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\dxtrans.dll
[2011/07/14 01:52:51 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieaksie.dll
[2011/07/14 01:52:51 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieui.dll
[2011/07/14 01:52:51 | 000,236,544 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\url.dll
[2011/07/14 01:52:51 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\url.dll
[2011/07/14 01:52:51 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieaksie.dll
[2011/07/14 01:52:51 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\dxtrans.dll
[2011/07/14 01:52:51 | 000,222,208 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msls31.dll
[2011/07/14 01:52:51 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msrating.dll
[2011/07/14 01:52:51 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieui.dll
[2011/07/14 01:52:51 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieUnatt.exe
[2011/07/14 01:52:51 | 000,165,888 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\iexpress.exe
[2011/07/14 01:52:51 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieakui.dll
[2011/07/14 01:52:51 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieakui.dll
[2011/07/14 01:52:51 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\msrating.dll
[2011/07/14 01:52:51 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\msls31.dll
[2011/07/14 01:52:51 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wextract.exe
[2011/07/14 01:52:51 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieakeng.dll
[2011/07/14 01:52:51 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\wextract.exe
[2011/07/14 01:52:51 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\iexpress.exe
[2011/07/14 01:52:51 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\occache.dll
[2011/07/14 01:52:51 | 000,145,920 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\iepeers.dll
[2011/07/14 01:52:51 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieUnatt.exe
[2011/07/14 01:52:51 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\IEAdvpack.dll
[2011/07/14 01:52:51 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieakeng.dll
[2011/07/14 01:52:51 | 000,123,392 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\occache.dll
[2011/07/14 01:52:51 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\iepeers.dll
[2011/07/14 01:52:51 | 000,114,176 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\admparse.dll
[2011/07/14 01:52:51 | 000,111,616 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\iesysprep.dll
[2011/07/14 01:52:51 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\IEAdvpack.dll
[2011/07/14 01:52:51 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\inseng.dll
[2011/07/14 01:52:51 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\admparse.dll
[2011/07/14 01:52:51 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mshtmled.dll
[2011/07/14 01:52:51 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\SetIEInstalledDate.exe
[2011/07/14 01:52:51 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\RegisterIEPKEYs.exe
[2011/07/14 01:52:51 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ie4uinit.exe
[2011/07/14 01:52:51 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\iesysprep.dll
[2011/07/14 01:52:51 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\iesetup.dll
[2011/07/14 01:52:51 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\icardie.dll
[2011/07/14 01:52:51 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\inseng.dll
[2011/07/14 01:52:51 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\tdc.ocx
[2011/07/14 01:52:51 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\SetIEInstalledDate.exe
[2011/07/14 01:52:51 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\RegisterIEPKEYs.exe
[2011/07/14 01:52:51 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\iesetup.dll
[2011/07/14 01:52:51 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ie4uinit.exe
[2011/07/14 01:52:51 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mshtmled.dll
[2011/07/14 01:52:51 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\icardie.dll
[2011/07/14 01:52:51 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\pngfilt.dll
[2011/07/14 01:52:51 | 000,063,488 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\tdc.ocx
[2011/07/14 01:52:51 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\pngfilt.dll
[2011/07/14 01:52:51 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\imgutil.dll
[2011/07/14 01:52:51 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mshtmler.dll
[2011/07/14 01:52:51 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mshtmler.dll
[2011/07/14 01:52:51 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\iernonce.dll
[2011/07/14 01:52:51 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\imgutil.dll
[2011/07/14 01:52:51 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\iernonce.dll
[2011/07/14 01:52:51 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\licmgr10.dll
[2011/07/14 01:52:51 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\licmgr10.dll
[2011/07/14 01:52:51 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mshta.exe
[2011/07/14 01:52:51 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\msfeedssync.exe
[2011/07/14 01:52:51 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msfeedssync.exe
[2011/07/13 17:55:58 | 000,000,000 | —D | C] – C:\Users\Janet\AppData\Roaming\Skype
[2011/07/13 17:55:05 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2011/07/13 17:55:01 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2011/07/13 00:38:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\NetRatingsNetSight
[2011/07/12 19:17:15 | 000,421,888 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\KernelBase.dll
[2011/07/12 19:17:12 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2011/07/12 19:17:12 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2011/07/12 19:17:12 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2011/07/12 19:17:12 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2011/07/12 19:17:12 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2011/07/12 19:17:12 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2011/07/12 19:17:12 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2011/07/12 19:17:12 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/07/12 19:17:12 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/07/12 19:17:12 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2011/07/12 19:17:12 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2011/07/12 19:17:12 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2011/07/12 19:17:12 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2011/07/12 19:17:12 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2011/07/12 19:17:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2011/07/12 19:17:11 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2011/07/12 19:17:11 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2011/07/12 19:17:11 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2011/07/12 19:17:11 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/07/12 19:17:11 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/07/12 19:17:11 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2011/07/12 19:17:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/07/12 19:17:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2011/07/12 19:17:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2011/07/12 19:17:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2011/07/12 19:17:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2011/07/12 19:17:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2011/07/12 19:17:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2011/07/12 19:17:03 | 001,162,752 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\kernel32.dll
[2011/07/12 19:17:02 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wow64win.dll
[2011/07/12 19:17:02 | 000,338,944 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\conhost.exe
[2011/07/12 19:17:02 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\winsrv.dll
[2011/07/12 19:16:59 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wow64.dll
[2011/07/12 19:16:59 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\setup16.exe
[2011/07/12 19:16:58 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntvdm64.dll
[2011/07/12 19:16:58 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntvdm64.dll
[2011/07/12 19:16:58 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wow64cpu.dll
[2011/07/12 19:16:58 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\instnm.exe
[2011/07/12 19:16:58 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\wow32.dll
[2011/07/12 19:16:57 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\user.exe
[2011/07/11 03:26:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared
[2011/07/11 03:26:37 | 000,198,848 | —- | C] (RealNetworks, Inc.) – C:\windows\SysWow64\rmoc3260.dll
[2011/07/11 03:26:28 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\windows\SysWow64\pndx5016.dll
[2011/07/11 03:26:28 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\windows\SysWow64\pndx5032.dll
[2011/07/11 03:26:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
[2011/07/11 03:26:27 | 000,272,896 | —- | C] (Progressive Networks) – C:\windows\SysWow64\pncrt.dll
[2011/07/11 03:26:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Real
[2011/07/11 03:26:12 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2011/07/11 03:26:10 | 000,000,000 | —D | C] – C:\Users\Janet\AppData\Roaming\Real
[2011/07/07 20:02:30 | 000,000,000 | —D | C] – C:\Users\Janet\Desktop\Fandango
[2011/07/06 06:26:54 | 000,000,000 | —D | C] – C:\Users\Janet\AppData\Roaming\FREEzeFrog
[2011/07/06 06:26:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\FREEzeFrog
[2011/07/06 06:23:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\FilmFanaticEI
[2011/07/01 19:51:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/07/01 19:50:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011/07/01 19:50:44 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/07/01 19:49:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011/07/01 19:49:32 | 000,000,000 | —D | C] – C:\Users\Janet\AppData\Local\Apple
[2011/07/01 19:49:30 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/06/29 05:38:16 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\drvinst.exe
[2011/06/29 05:38:15 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\devrtl.dll
[2011/06/29 05:38:12 | 002,315,776 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\tquery.dll
[2011/06/29 05:38:12 | 002,223,616 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mssrch.dll
[2011/06/29 05:38:12 | 001,401,344 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mssrch.dll
[2011/06/29 05:38:11 | 001,549,312 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\tquery.dll
[2011/06/29 05:38:11 | 000,491,520 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mssph.dll
[2011/06/29 05:38:11 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mssph.dll
[2011/06/29 05:38:11 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\SearchProtocolHost.exe
[2011/06/29 05:38:10 | 000,778,752 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mssvp.dll
[2011/06/29 05:38:10 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mssvp.dll
[2011/06/29 05:38:10 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mssphtb.dll
[2011/06/29 05:38:10 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mssphtb.dll
[2011/06/29 05:38:10 | 000,113,664 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\SearchFilterHost.exe
[2011/06/29 05:38:10 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msscntrs.dll
[2011/06/29 05:38:10 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\msscntrs.dll
[2011/06/23 08:18:22 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[7 C:\Users\Janet\Documents\*.tmp files -> C:\Users\Janet\Documents\*.tmp -> ]
[7 C:\Users\Janet\Desktop\*.tmp files -> C:\Users\Janet\Desktop\*.tmp -> ]
[19 C:\Users\Janet\AppData\Local\*.tmp files -> C:\Users\Janet\AppData\Local\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/22 23:04:01 | 000,000,898 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/22 23:04:01 | 000,000,894 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/22 22:54:39 | 000,151,638 | —- | M] () – C:\Users\Janet\Desktop\7 pm Closing Ceremony Summer 2011.jpeg.jpeg
[2011/07/22 22:51:10 | 000,186,585 | —- | M] () – C:\Users\Janet\Desktop\4 pm Closing Ceremony Summer 2011.jpeg
[2011/07/22 22:17:15 | 000,052,852 | —- | M] () – C:\Users\Janet\Desktop\rhapsody music billing detail july 22 2011.pdf
[2011/07/22 22:03:44 | 000,676,364 | —- | M] () – C:\Users\Janet\Desktop\CAP AM Movie Ticket Ryan 1.pdf
[2011/07/22 21:50:50 | 000,976,422 | —- | M] () – C:\Users\Janet\Desktop\HP MOVIE RYAN 1.pdf
[2011/07/22 19:52:22 | 000,015,792 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/22 19:52:22 | 000,015,792 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/22 19:44:26 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/07/22 19:44:20 | 2210,578,432 | -HS- | M] () – C:\hiberfil.sys
[2011/07/22 17:30:56 | 000,061,677 | —- | M] () – C:\Users\Janet\Desktop\staples 25% rewards.pdf
[2011/07/22 17:30:20 | 000,056,406 | —- | M] () – C:\Users\Janet\Desktop\staples 20% off.pdf
[2011/07/22 17:18:18 | 000,091,250 | —- | M] () – C:\Users\Janet\Desktop\staples gift card sam.pdf
[2011/07/22 14:17:47 | 000,082,664 | —- | M] () – C:\Users\Janet\Desktop\Staples Reward Card.pdf
[2011/07/21 23:25:42 | 000,154,573 | —- | M] () – C:\Users\Janet\Desktop\print.pdf
[2011/07/21 21:36:34 | 000,625,664 | —- | M] () – C:\Users\Janet\Desktop\dds.scr
[2011/07/21 21:12:27 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Users\Janet\Desktop\OTL.exe
[2011/07/21 21:09:48 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Janet\Desktop\HiJackThis.exe
[2011/07/21 12:08:42 | 000,726,316 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/07/21 12:08:42 | 000,624,178 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/07/21 12:08:42 | 000,106,522 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/07/20 14:24:41 | 000,113,686 | —- | M] () – C:\Users\Janet\Desktop\express mail track and confirm.pdf
[2011/07/19 02:37:09 | 000,013,885 | —- | M] () – C:\Users\Janet\Desktop\RewardCard.pdf
[2011/07/17 11:52:29 | 000,038,620 | —- | M] () – C:\Users\Janet\Desktop\Scotch Tape Sale - Target.pdf
[2011/07/17 02:45:34 | 000,001,307 | —- | M] () – C:\Users\Janet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2011/07/16 11:06:57 | 000,002,515 | —- | M] () – C:\Users\Janet\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/07/16 11:06:57 | 000,002,491 | —- | M] () – C:\Users\Public\Desktop\Safari.lnk
[2011/07/15 10:14:40 | 000,786,586 | —- | M] () – C:\Users\Janet\Documents\Janet Tucker Fulk SS card.jpg
[2011/07/15 03:04:57 | 000,049,023 | —- | M] () – C:\Users\Janet\Desktop\shipping label textbooksrus.pdf
[2011/07/15 01:32:12 | 000,348,726 | —- | M] () – C:\Users\Janet\Documents\my house.pdf
[2011/07/14 03:27:55 | 000,002,030 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/07/14 02:00:53 | 000,001,452 | —- | M] () – C:\Users\Janet\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/07/14 01:52:51 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\ieapfltr.dat
[2011/07/14 01:52:51 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\ieapfltr.dat
[2011/07/14 01:52:51 | 002,303,488 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\jscript9.dll
[2011/07/14 01:52:51 | 001,797,632 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\jscript9.dll
[2011/07/14 01:52:51 | 001,492,992 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\inetcpl.cpl
[2011/07/14 01:52:51 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\inetcpl.cpl
[2011/07/14 01:52:51 | 000,818,176 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\jscript.dll
[2011/07/14 01:52:51 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\jscript.dll
[2011/07/14 01:52:51 | 000,697,344 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\msfeeds.dll
[2011/07/14 01:52:51 | 000,603,648 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\vbscript.dll
[2011/07/14 01:52:51 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\msfeeds.dll
[2011/07/14 01:52:51 | 000,534,528 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\ieapfltr.dll
[2011/07/14 01:52:51 | 000,452,608 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\dxtmsft.dll
[2011/07/14 01:52:51 | 000,448,512 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\html.iec
[2011/07/14 01:52:51 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\ieapfltr.dll
[2011/07/14 01:52:51 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\html.iec
[2011/07/14 01:52:51 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\dxtmsft.dll
[2011/07/14 01:52:51 | 000,282,112 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\dxtrans.dll
[2011/07/14 01:52:51 | 000,267,776 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\ieaksie.dll
[2011/07/14 01:52:51 | 000,248,320 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\ieui.dll
[2011/07/14 01:52:51 | 000,236,544 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\url.dll
[2011/07/14 01:52:51 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\url.dll
[2011/07/14 01:52:51 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\ieaksie.dll
[2011/07/14 01:52:51 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\dxtrans.dll
[2011/07/14 01:52:51 | 000,222,208 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\msls31.dll
[2011/07/14 01:52:51 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\msrating.dll
[2011/07/14 01:52:51 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\ieui.dll
[2011/07/14 01:52:51 | 000,173,056 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\ieUnatt.exe
[2011/07/14 01:52:51 | 000,165,888 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\iexpress.exe
[2011/07/14 01:52:51 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\ieakui.dll
[2011/07/14 01:52:51 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\ieakui.dll
[2011/07/14 01:52:51 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\msrating.dll
[2011/07/14 01:52:51 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\msls31.dll
[2011/07/14 01:52:51 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\wextract.exe
[2011/07/14 01:52:51 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\ieakeng.dll
[2011/07/14 01:52:51 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\wextract.exe
[2011/07/14 01:52:51 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\iexpress.exe
[2011/07/14 01:52:51 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\occache.dll
[2011/07/14 01:52:51 | 000,145,920 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\iepeers.dll
[2011/07/14 01:52:51 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\ieUnatt.exe
[2011/07/14 01:52:51 | 000,135,168 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\IEAdvpack.dll
[2011/07/14 01:52:51 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\ieakeng.dll
[2011/07/14 01:52:51 | 000,123,392 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\occache.dll
[2011/07/14 01:52:51 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\iepeers.dll
[2011/07/14 01:52:51 | 000,114,176 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\admparse.dll
[2011/07/14 01:52:51 | 000,111,616 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\iesysprep.dll
[2011/07/14 01:52:51 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\IEAdvpack.dll
[2011/07/14 01:52:51 | 000,103,936 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\inseng.dll
[2011/07/14 01:52:51 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\admparse.dll
[2011/07/14 01:52:51 | 000,096,256 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\mshtmled.dll
[2011/07/14 01:52:51 | 000,091,648 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\SetIEInstalledDate.exe
[2011/07/14 01:52:51 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\RegisterIEPKEYs.exe
[2011/07/14 01:52:51 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\ie4uinit.exe
[2011/07/14 01:52:51 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\iesysprep.dll
[2011/07/14 01:52:51 | 000,085,504 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\iesetup.dll
[2011/07/14 01:52:51 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\icardie.dll
[2011/07/14 01:52:51 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\inseng.dll
[2011/07/14 01:52:51 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\tdc.ocx
[2011/07/14 01:52:51 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\SetIEInstalledDate.exe
[2011/07/14 01:52:51 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\RegisterIEPKEYs.exe
[2011/07/14 01:52:51 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\iesetup.dll
[2011/07/14 01:52:51 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\ie4uinit.exe
[2011/07/14 01:52:51 | 000,072,822 | —- | M] () – C:\windows\SysWow64\ieuinit.inf
[2011/07/14 01:52:51 | 000,072,822 | —- | M] () – C:\windows\SysNative\ieuinit.inf
[2011/07/14 01:52:51 | 000,072,704 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\mshtmled.dll
[2011/07/14 01:52:51 | 000,066,048 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\icardie.dll
[2011/07/14 01:52:51 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\pngfilt.dll
[2011/07/14 01:52:51 | 000,063,488 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\tdc.ocx
[2011/07/14 01:52:51 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\pngfilt.dll
[2011/07/14 01:52:51 | 000,049,664 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\imgutil.dll
[2011/07/14 01:52:51 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\mshtmler.dll
[2011/07/14 01:52:51 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\mshtmler.dll
[2011/07/14 01:52:51 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\iernonce.dll
[2011/07/14 01:52:51 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\imgutil.dll
[2011/07/14 01:52:51 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\iernonce.dll
[2011/07/14 01:52:51 | 000,030,720 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\licmgr10.dll
[2011/07/14 01:52:51 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\licmgr10.dll
[2011/07/14 01:52:51 | 000,012,288 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\mshta.exe
[2011/07/14 01:52:51 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\msfeedssync.exe
[2011/07/14 01:52:51 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\msfeedssync.exe
[2011/07/13 10:03:51 | 000,157,340 | —- | M] () – C:\Users\Janet\Desktop\ViewMailing.pdf
[2011/07/13 01:22:05 | 000,072,116 | —- | M] () – C:\Users\Janet\Desktop\entertainment book $6 offer inbox dollars.pdf
[2011/07/13 00:43:14 | 000,000,000 | -H– | M] () – C:\windows\SysNative\drivers\Msft_Kernel_nnfwdk64_01009.Wdf
[2011/07/13 00:43:12 | 000,000,000 | —- | M] () – C:\extensions.sqlite
[2011/07/12 19:44:23 | 000,404,520 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2011/07/11 16:39:43 | 000,000,000 | —- | M] () – C:\Users\Janet\AppData\Local\{E4E1BFE1-B1FA-437E-9CBB-C8D3B86D79A9}
[2011/07/11 03:27:00 | 000,001,279 | —- | M] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2011/07/11 03:26:37 | 000,198,848 | —- | M] (RealNetworks, Inc.) – C:\windows\SysWow64\rmoc3260.dll
[2011/07/11 03:26:28 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\windows\SysWow64\pndx5016.dll
[2011/07/11 03:26:28 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\windows\SysWow64\pndx5032.dll
[2011/07/11 03:26:27 | 000,272,896 | —- | M] (Progressive Networks) – C:\windows\SysWow64\pncrt.dll
[2011/07/11 03:26:23 | 000,499,712 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\msvcp71.dll
[2011/07/11 03:26:23 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\msvcr71.dll
[2011/07/11 02:34:52 | 000,000,000 | —- | M] () – C:\windows\SysWow64\config.nt
[2011/07/10 00:37:57 | 000,168,293 | —- | M] () – C:\Users\Janet\Documents\Recyclebank's Green Your Vacation Beach Checklist_0.pdf
[2011/07/08 02:21:34 | 000,000,000 | —- | M] () – C:\Users\Janet\AppData\Local\{202530B4-1931-420B-814F-E5325C46C800}
[2011/07/07 10:58:41 | 000,000,000 | —- | M] () – C:\Users\Janet\AppData\Local\{E4781A53-41DA-4269-B23D-05B7C1ED77A7}
[2011/07/06 19:52:42 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\windows\SysWow64\drivers\mbamswissarmy.sys
[2011/07/06 19:52:42 | 000,025,912 | —- | M] (Malwarebytes Corporation) – C:\windows\SysNative\drivers\mbam.sys
[2011/07/06 15:27:32 | 000,022,536 | —- | M] () – C:\Users\Janet\Documents\cc_20110706_152728.reg
[2011/07/05 13:22:37 | 000,036,030 | —- | M] () – C:\Users\Janet\Documents\siu eid secret phrase july 5 2011.pdf
[2011/07/05 11:19:33 | 000,000,000 | —- | M] () – C:\Users\Janet\AppData\Local\{66FE96DA-A279-404F-8073-A372CDF7648E}
[2011/07/04 06:43:53 | 000,040,112 | —- | M] (AVAST Software) – C:\windows\avastSS.scr
[2011/07/04 06:43:51 | 000,199,304 | —- | M] (AVAST Software) – C:\windows\SysWow64\aswBoot.exe
[2011/07/04 06:43:42 | 000,253,888 | —- | M] (AVAST Software) – C:\windows\SysNative\aswBoot.exe
[2011/07/04 06:36:56 | 000,600,920 | —- | M] (AVAST Software) – C:\windows\SysNative\drivers\aswSnx.sys
[2011/07/04 06:36:54 | 000,288,088 | —- | M] (AVAST Software) – C:\windows\SysNative\drivers\aswSP.sys
[2011/07/04 06:35:28 | 000,045,400 | —- | M] (AVAST Software) – C:\windows\SysNative\drivers\aswTdi.sys
[2011/07/04 06:32:35 | 000,031,064 | —- | M] (AVAST Software) – C:\windows\SysNative\drivers\aswRdr.sys
[2011/07/04 06:32:24 | 000,064,856 | —- | M] (AVAST Software) – C:\windows\SysNative\drivers\aswMonFlt.sys
[2011/07/04 06:32:14 | 000,022,360 | —- | M] (AVAST Software) – C:\windows\SysNative\drivers\aswFsBlk.sys
[2011/07/03 01:48:04 | 000,014,072 | —- | M] () – C:\Users\Janet\Documents\cc_20110703_014758.reg
[2011/07/01 19:51:02 | 000,001,856 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/06/28 22:55:20 | 000,080,796 | —- | M] () – C:\Users\Janet\Documents\walmart tire service.pdf
[2011/06/28 22:34:28 | 000,082,936 | —- | M] () – C:\Users\Janet\Documents\firestone tires quote.pdf
[2011/06/28 11:27:03 | 000,022,017 | —- | M] () – C:\Users\Janet\Documents\kelloggs rice krispies claim.pdf
[2011/06/27 01:04:05 | 001,860,710 | —- | M] () – C:\Users\Janet\Documents\DeCA million dollar vendors.PDF
[2011/06/26 21:13:58 | 000,001,232 | —- | M] () – C:\Users\Public\Desktop\Yazak.exe.lnk
[2011/06/26 03:43:20 | 000,032,064 | —- | M] () – C:\Users\Janet\Documents\Ryan SafeLink Enrollment ID number.pdf
[2011/06/26 03:42:13 | 000,165,775 | —- | M] () – C:\Users\Janet\Documents\Ryan SafeLink Phone Application.pdf
[2011/06/25 13:50:55 | 000,040,522 | —- | M] () – C:\Users\Janet\Documents\hgtv rebate form june 2011.PDF
[2011/06/24 21:35:02 | 000,353,900 | —- | M] () – C:\Users\Janet\Documents\Recyclebank's Green Your Vacation Travel Checklist.pdf
[2011/06/24 16:09:44 | 000,000,000 | —- | M] () – C:\Users\Janet\AppData\Local\{E187AD1B-9265-4364-833F-19038CCC8A96}
[2011/06/24 13:42:10 | 000,000,000 | —- | M] () – C:\Users\Janet\AppData\Local\{15C17BF0-6D74-4724-94C2-62B828B084C4}
[2011/06/24 12:28:17 | 000,000,000 | —- | M] () – C:\Users\Janet\AppData\Local\{2266435D-F249-46D6-8884-2D662E23D5D0}
[2011/06/23 09:26:47 | 000,035,984 | —- | M] () – C:\Users\Janet\Documents\siu secret phrase.pdf
[2011/06/23 08:18:23 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/06/23 05:08:11 | 000,081,332 | —- | M] () – C:\Users\Janet\Desktop\shoppers discounts and rewards savings circle june 23 2011.pdf
[2011/06/23 05:05:24 | 000,208,155 | —- | M] () – C:\Users\Janet\Desktop\promo savings circle confirmation page.pdf
[2011/06/23 04:09:30 | 004,964,868 | —- | M] () – C:\Users\Janet\Documents\$2 off 4 kraft food.PDF
[2011/06/23 03:21:02 | 000,206,916 | —- | M] () – C:\Users\Janet\Desktop\savings circle trial membership june 23 2011 sign up page.pdf
[7 C:\Users\Janet\Documents\*.tmp files -> C:\Users\Janet\Documents\*.tmp -> ]
[7 C:\Users\Janet\Desktop\*.tmp files -> C:\Users\Janet\Desktop\*.tmp -> ]
[19 C:\Users\Janet\AppData\Local\*.tmp files -> C:\Users\Janet\AppData\Local\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/22 22:55:02 | 000,151,638 | —- | C] () – C:\Users\Janet\Desktop\7 pm Closing Ceremony Summer 2011.jpeg.jpeg
[2011/07/22 22:52:09 | 000,186,585 | —- | C] () – C:\Users\Janet\Desktop\4 pm Closing Ceremony Summer 2011.jpeg
[2011/07/22 22:17:40 | 000,052,852 | —- | C] () – C:\Users\Janet\Desktop\rhapsody music billing detail july 22 2011.pdf
[2011/07/22 22:04:10 | 000,676,364 | —- | C] () – C:\Users\Janet\Desktop\CAP AM Movie Ticket Ryan 1.pdf
[2011/07/22 21:51:18 | 000,976,422 | —- | C] () – C:\Users\Janet\Desktop\HP MOVIE RYAN 1.pdf
[2011/07/22 17:31:24 | 000,061,677 | —- | C] () – C:\Users\Janet\Desktop\staples 25% rewards.pdf
[2011/07/22 17:30:34 | 000,056,406 | —- | C] () – C:\Users\Janet\Desktop\staples 20% off.pdf
[2011/07/22 17:18:38 | 000,091,250 | —- | C] () – C:\Users\Janet\Desktop\staples gift card sam.pdf
[2011/07/22 14:18:05 | 000,082,664 | —- | C] () – C:\Users\Janet\Desktop\Staples Reward Card.pdf
[2011/07/21 23:18:31 | 000,154,573 | —- | C] () – C:\Users\Janet\Desktop\print.pdf
[2011/07/21 21:36:33 | 000,625,664 | —- | C] () – C:\Users\Janet\Desktop\dds.scr
[2011/07/20 14:25:10 | 000,113,686 | —- | C] () – C:\Users\Janet\Desktop\express mail track and confirm.pdf
[2011/07/19 02:37:09 | 000,013,885 | —- | C] () – C:\Users\Janet\Desktop\RewardCard.pdf
[2011/07/17 11:52:47 | 000,038,620 | —- | C] () – C:\Users\Janet\Desktop\Scotch Tape Sale - Target.pdf
[2011/07/16 11:06:57 | 000,002,515 | —- | C] () – C:\Users\Janet\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/07/16 11:06:57 | 000,002,503 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk
[2011/07/16 11:06:57 | 000,002,491 | —- | C] () – C:\Users\Public\Desktop\Safari.lnk
[2011/07/15 10:15:50 | 000,786,586 | —- | C] () – C:\Users\Janet\Documents\Janet Tucker Fulk SS card.jpg
[2011/07/15 03:05:21 | 000,049,023 | —- | C] () – C:\Users\Janet\Desktop\shipping label textbooksrus.pdf
[2011/07/15 01:32:32 | 000,348,726 | —- | C] () – C:\Users\Janet\Documents\my house.pdf
[2011/07/14 03:27:55 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/07/14 03:27:55 | 000,002,030 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/07/14 02:00:53 | 000,001,424 | —- | C] () – C:\Users\Janet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/07/14 01:52:51 | 000,072,822 | —- | C] () – C:\windows\SysWow64\ieuinit.inf
[2011/07/14 01:52:51 | 000,072,822 | —- | C] () – C:\windows\SysNative\ieuinit.inf
[2011/07/13 10:04:03 | 000,157,340 | —- | C] () – C:\Users\Janet\Desktop\ViewMailing.pdf
[2011/07/13 01:22:32 | 000,072,116 | —- | C] () – C:\Users\Janet\Desktop\entertainment book $6 offer inbox dollars.pdf
[2011/07/13 00:43:14 | 000,000,000 | -H– | C] () – C:\windows\SysNative\drivers\Msft_Kernel_nnfwdk64_01009.Wdf
[2011/07/13 00:43:12 | 000,000,000 | —- | C] () – C:\extensions.sqlite
[2011/07/11 16:39:15 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{E4E1BFE1-B1FA-437E-9CBB-C8D3B86D79A9}
[2011/07/11 03:27:00 | 000,001,279 | —- | C] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2011/07/10 00:37:53 | 000,168,293 | —- | C] () – C:\Users\Janet\Documents\Recyclebank's Green Your Vacation Beach Checklist_0.pdf
[2011/07/08 02:19:55 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{202530B4-1931-420B-814F-E5325C46C800}
[2011/07/07 10:58:41 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{E4781A53-41DA-4269-B23D-05B7C1ED77A7}
[2011/07/06 15:27:30 | 000,022,536 | —- | C] () – C:\Users\Janet\Documents\cc_20110706_152728.reg
[2011/07/05 13:23:02 | 000,036,030 | —- | C] () – C:\Users\Janet\Documents\siu eid secret phrase july 5 2011.pdf
[2011/07/05 11:19:33 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{66FE96DA-A279-404F-8073-A372CDF7648E}
[2011/07/03 01:48:01 | 000,014,072 | —- | C] () – C:\Users\Janet\Documents\cc_20110703_014758.reg
[2011/07/01 19:51:02 | 000,001,856 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/07/01 19:49:30 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/06/28 22:55:36 | 000,080,796 | —- | C] () – C:\Users\Janet\Documents\walmart tire service.pdf
[2011/06/28 22:34:55 | 000,082,936 | —- | C] () – C:\Users\Janet\Documents\firestone tires quote.pdf
[2011/06/28 11:27:22 | 000,022,017 | —- | C] () – C:\Users\Janet\Documents\kelloggs rice krispies claim.pdf
[2011/06/27 01:06:49 | 001,860,710 | —- | C] () – C:\Users\Janet\Documents\DeCA million dollar vendors.PDF
[2011/06/26 21:13:58 | 000,001,232 | —- | C] () – C:\Users\Public\Desktop\Yazak.exe.lnk
[2011/06/26 03:43:45 | 000,032,064 | —- | C] () – C:\Users\Janet\Documents\Ryan SafeLink Enrollment ID number.pdf
[2011/06/26 03:42:48 | 000,165,775 | —- | C] () – C:\Users\Janet\Documents\Ryan SafeLink Phone Application.pdf
[2011/06/25 13:51:32 | 000,040,522 | —- | C] () – C:\Users\Janet\Documents\hgtv rebate form june 2011.PDF
[2011/06/24 21:34:58 | 000,353,900 | —- | C] () – C:\Users\Janet\Documents\Recyclebank's Green Your Vacation Travel Checklist.pdf
[2011/06/24 16:09:44 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{E187AD1B-9265-4364-833F-19038CCC8A96}
[2011/06/24 13:40:43 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{15C17BF0-6D74-4724-94C2-62B828B084C4}
[2011/06/24 12:28:17 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{2266435D-F249-46D6-8884-2D662E23D5D0}
[2011/06/23 09:27:06 | 000,035,984 | —- | C] () – C:\Users\Janet\Documents\siu secret phrase.pdf
[2011/06/23 05:08:41 | 000,081,332 | —- | C] () – C:\Users\Janet\Desktop\shoppers discounts and rewards savings circle june 23 2011.pdf
[2011/06/23 05:05:47 | 000,208,155 | —- | C] () – C:\Users\Janet\Desktop\promo savings circle confirmation page.pdf
[2011/06/23 04:13:37 | 004,964,868 | —- | C] () – C:\Users\Janet\Documents\$2 off 4 kraft food.PDF
[2011/06/23 03:22:03 | 000,206,916 | —- | C] () – C:\Users\Janet\Desktop\savings circle trial membership june 23 2011 sign up page.pdf
[2011/06/15 16:27:54 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{9FF9F6B7-BE69-49FE-873B-C59A2DDB20E4}
[2011/06/15 14:39:16 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{32A964C0-BB21-4EE8-9339-B6ACA2C7FFE0}
[2011/06/15 12:59:00 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{21C16F83-101C-424F-988F-BC346C2CEBFF}
[2011/06/11 16:32:41 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{2A916194-124B-45CE-9949-59866115D95D}
[2011/06/07 03:07:58 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{0ED0E7E4-ACF5-4288-A584-1E1DDCF814C0}
[2011/06/06 11:41:11 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{935500F2-04AD-4534-865C-088AFF49EFB3}
[2011/06/04 10:02:03 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{D67EC4AC-4E16-4B6F-926C-0D706B498DA4}
[2011/06/04 04:12:06 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{6D61D5AC-4B8D-40F6-9877-7EDC4E7956DF}
[2011/06/04 03:38:07 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{F8EC7972-C77D-433B-8276-73B13D73C9C2}
[2011/06/02 03:48:36 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{83AB1AC7-FB8B-4041-B0B2-CEDD6A4BE3DA}
[2011/06/02 03:45:21 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{96D0CF01-27C5-4766-B9A1-CC5BF6566E01}
[2011/06/01 10:29:25 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{585C7E70-98C4-4303-8EAE-F5C2CB9B3DFF}
[2011/05/22 23:06:17 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{73376D00-6336-4C1A-A549-8F667CAC1122}
[2011/05/14 10:51:22 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{D976CAE6-9920-4020-ADC4-CE70159CF718}
[2011/05/14 09:32:09 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{B7AD78D9-193D-4633-A68F-3E74009CD695}
[2011/05/13 11:24:49 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{329D1D5F-B729-49C5-A724-D6F0A0B7EA4F}
[2011/05/13 05:03:17 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{E9A53E5A-BD9D-4F4C-A087-DA0B895186FB}
[2011/05/03 21:38:52 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{C29A5C19-93C2-42E3-B899-6CD4E54B0470}
[2011/04/29 19:50:13 | 000,000,000 | —- | C] () – C:\Users\Janet\AppData\Local\{7C23BF19-1DBB-4630-A2FA-4CB8D5C43584}
[2011/02/04 20:46:25 | 000,000,080 | —- | C] () – C:\windows\TaxACT08.ini
[2011/02/04 20:44:48 | 000,000,060 | —- | C] () – C:\windows\TaxACT09.ini
[2011/01/29 02:59:52 | 000,208,529 | —- | C] () – C:\windows\hpoins41.dat
[2010/10/26 03:53:32 | 000,000,000 | —- | C] () – C:\windows\ativpsrm.bin
[2010/10/26 03:50:57 | 000,001,105 | —- | C] () – C:\windows\SysWow64\atipblag.dat
[2010/01/29 16:04:24 | 000,001,112 | —- | C] () – C:\windows\hpomdl41.dat
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat

========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.* >
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/04/04 00:22:27 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2011/07/13 00:43:12 | 000,000,000 | —- | M] () – C:\extensions.sqlite
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/07/22 19:44:20 | 2210,578,432 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 09:44:20 | 000,855,040 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:44:20 | 000,075,280 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:44:20 | 000,090,128 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:44:20 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:44:20 | 000,094,224 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:44:20 | 000,080,400 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:44:20 | 000,078,864 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:44:20 | 000,074,768 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2011/07/13 00:38:23 | 000,000,591 | —- | M] () – C:\nsinst.log
[2011/07/22 19:44:23 | 2947,440,640 | -HS- | M] () – C:\pagefile.sys
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:50:40 | 001,927,956 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:53:12 | 000,242,176 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/07/04 06:43:53 | 000,040,112 | —- | M] (AVAST Software) – C:\windows\avastSS.scr
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/07/14 02:00:53 | 000,000,221 | -HS- | M] () – C:\Users\Janet\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/07/21 21:09:48 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Janet\Desktop\HiJackThis.exe
[2011/02/25 01:41:33 | 158,067,944 | —- | M] () – C:\Users\Janet\Desktop\OOo_3.3.0_Win_x86_install-wJRE_en-US.exe
[2011/07/21 21:12:27 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Users\Janet\Desktop\OTL.exe
[2011/01/06 13:58:52 | 002,137,995 | —- | M] (ZakFromAnotherPlanet) – C:\Users\Janet\Desktop\VbRunDLLv3sp6.exe
[7 C:\Users\Janet\Desktop\*.tmp files -> C:\Users\Janet\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 188 bytes -> C:\Users\Janet\Desktop\express mail receipt amazon.jpeg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 188 bytes -> C:\Users\Janet\Desktop\7 pm Closing Ceremony Summer 2011.jpeg.jpeg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 188 bytes -> C:\Users\Janet\Desktop\4 pm Closing Ceremony Summer 2011.jpeg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 184 bytes -> C:\Users\Janet\Documents\Letter to Illinois Department of Revenue April 19 2011 Re 2009 Taxes.jpeg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 184 bytes -> C:\Users\Janet\Documents\2009 W-2 SWIC.jpeg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 168 bytes -> C:\Users\Janet\Documents\Ryan Rent Receipt January 2011 signed.jpeg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 168 bytes -> C:\Users\Janet\Documents\HP printer rebate.jpeg:3or4kl4x13tuuug3Byamue2s4b

< End of report >
OTL Extras logfile created on: 7/22/2011 11:11:19 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\Janet\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 1.59 Gb Available Physical Memory | 57.86% Memory free
5.49 Gb Paging File | 4.09 Gb Available in Paging File | 74.57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 287.63 Gb Total Space | 243.85 Gb Free Space | 84.78% Space Free | Partition Type: NTFS

Computer Name: JANET-PC | User Name: Janet | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{21E2A283-1416-AF26-6DA1-92FDE02224EB}" = ccc-utility64
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{48C0866E-57EB-444C-8371-8E4321066BC3}" = Network64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5792CD64-61B4-C448-0D22-3C51DD73AB2A}" = ATI Catalyst Install Manager
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A0E99122-25C1-4CA4-9063-499A2A814EB6}" = TOSHIBA ReelTime
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{BE930E38-7BB3-45B6-85B2-5251F374F844}" = 64 Bit HP CIO Components Installer
"{C14518AF-1A0F-4D39-8011-69BAA01CD380}" = TOSHIBA Bulletin Board
"{CCD42CCF-9AFF-4BC5-862A-38CCD3C8E8F8}" = HP Photosmart Premium C309g-m All-in-One Driver Software 14.0 Rel. 6
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CutePDF Writer Installation" = CutePDF Writer 2.8
"HP Imaging Device Functions" = HP Imaging Device Functions 14.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
"HPExtendedCapabilities" = HP Customer Participation Program 14.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Shop for HP Supplies" = Shop for HP Supplies
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02950E10-1AA3-DF62-FED5-42CBD4ADC5C1}" = CCC Help Dutch
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{073B89C3-BA88-41B5-965F-B35A88EAE838}" = TOSHIBA Supervisor Password
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D795777-9D60-4692-8386-F2B3F2B5E5BF}" = Label@Once 1.0
"{118F5964-DA03-7B46-BDEA-7C3FA203D293}" = CCC Help Spanish
"{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
"{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1B87C40B-A60B-4EF3-9A68-706CF4B69978}" = TOSHIBA Assist
"{1CF51B76-7485-410C-D06D-23D1060974D3}" = Catalyst Control Center Core Implementation
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21759FAC-AE5F-F171-EB4C-D2FBF66EDD04}" = CCC Help Czech
"{219B4856-468A-F0BB-8249-E630AD4E86C2}" = ccc-core-static
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23EA31D7-28CD-F7B3-024C-6EB784F1BC79}" = CCC Help Russian
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 23
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3135D885-9D9A-4B4D-8D45-9DB05DA115CA}" = Amazon Links
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3669F19D-D7C2-3240-C4EC-A57DECC124FC}" = CCC Help Japanese
"{38A0161D-7CD3-51AD-0ACB-F46DD34D2FF6}" = CCC Help Greek
"{39670BCD-6300-21D8-78A4-ECD68D0C4D95}" = CCC Help Chinese Standard
"{3B843B38-04B1-4CE6-8888-586273E0F289}" = Quickbooks Financial Center
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{46A46830-50AA-3326-7A57-72BB03E6B3EC}" = CCC Help Hungarian
"{47984ADB-54E9-BE8F-E39F-8B1FAAD4B192}" = CCC Help Polish
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{5570C266-C606-85BC-6E23-C858566E02DB}" = CCC Help Swedish
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5AF550B4-BB67-4E7E-82F1-2C4300279050}" = ToshibaRegistration
"{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter
"{5E620377-939F-3E6B-F328-4A69D9CA0D1B}" = CCC Help French
"{65F5F454-0029-045D-82ED-126F650B5C8F}" = Catalyst Control Center Graphics Previews Vista
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}" = Safari
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74DC0593-6BC6-4001-AD5F-D810AFB68D86}" = HP Update
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{836775DC-DC27-BC0C-7770-68E2591F6CC6}" = CCC Help Norwegian
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86236CB1-023D-82B2-A706-74ECFFA91A8E}" = Catalyst Control Center Graphics Previews Common
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B4BD0EF-A058-3F42-0AD8-763267A735D0}" = Catalyst Control Center Graphics Full New
"{8BD785CF-30C7-4182-B250-0D5FCE78D4DD}" = Catalyst Control Center - Branding
"{8BE504E9-0677-87AC-07D2-1A1428E17A92}" = Catalyst Control Center InstallProxy
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E9CEA3B-EBD1-439C-A01D-830CB39613C6}" = TOSHIBA Hardware Setup
"{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{91D25D3C-A6D8-78D4-CDE7-F70B93389A03}" = CCC Help Italian
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}" = TOSHIBA Application Installer
"{983CD6FE-8320-4B80-A8F6-0D0366E0AA22}" = TOSHIBA Media Controller
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CD5AC28-04E5-07A5-100D-953D2B3A8747}" = Catalyst Control Center Graphics Full Existing
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{AD8D84C3-D43A-776D-E4A8-2A4433BCBD32}" = CCC Help Korean
"{B0402CE4-783A-773C-239B-FF45BDFB400E}" = Catalyst Control Center Localization All
"{B32B60B9-C31B-3193-257A-2381305A0851}" = CCC Help German
"{B3B66630-DA7C-BD66-DFA4-F37AC82873EE}" = CCC Help Danish
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{B8615768-6D66-5E53-C4E1-6F7EC8D9BFFE}" = CCC Help English
"{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C289841E-5B5F-0198-F3FF-CB361D007DA3}" = CCC Help Thai
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Toshiba Online Backup
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C7BC4EBB-D88F-019D-8ED0-F42F89096B18}" = CCC Help Turkish
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CBDF1A29-D7F6-4E65-89F5-3300D475D6B9}" = Bing Bar
"{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D10D079D-EFDA-9601-98F8-F935A2A411A0}" = CCC Help Chinese Traditional
"{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3
"{DA84ECBF-4B79-47F2-B34C-95C38484C058}" = Skype Launcher
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DFD723B7-1762-73EC-32BC-A7D9E838808D}" = Catalyst Control Center Graphics Light
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E517094C-06B6-419F-8FFD-EF4F57972130}" = QuickTransfer
"{E6319C60-D4DF-4D4D-A077-9F46D656E4FB}" = C309g-m
"{E69992ED-A7F6-406C-9280-1C156417BC49}" = TOSHIBA Quality Application
"{E819AA87-4215-D35A-6872-BF97C32A9DB3}" = CCC Help Finnish
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE177519-70E3-4A94-B8DB-FD0B78D1A47E}" = PS_AIO_06_C309g-m_SW_Min
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}" = TOSHIBA Media Controller Plug-in
"{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
"{FD1F254C-48B2-A188-0127-03855BA15D16}" = CCC Help Portuguese
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"avast" = avast! Free Antivirus
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"Foxit Reader" = Foxit Reader
"HP Photo Creations" = HP Photo Creations
"ImagePrinter" = ImagePrinter 2.0.1
"InboxDollars" = InboxDollars
"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"InstallShield_{A0E99122-25C1-4CA4-9063-499A2A814EB6}" = TOSHIBA ReelTime
"InstallShield_{C14518AF-1A0F-4D39-8011-69BAA01CD380}" = TOSHIBA Bulletin Board
"InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"NetSight" = Nielsen
"NortonPCCheckup" = Toshiba Laptop Checkup
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"Play Pickle" = Play Pickle
"RealPlayer 12.0" = RealPlayer
"TaxACT 2008" = TaxACT 2008
"TaxACT 2008 Illinois" = TaxACT 2008 Illinois
"TaxACT 2009" = TaxACT 2009
"TaxACT 2009 Illinois" = TaxACT 2009 Illinois
"TOSHIBA Game Console" = WildTangent ORB Game Console
"VBRunDLL" = VBRunDLL 3.4
"WildTangent toshiba Master Uninstall" = WildTangent Games
"WinLiveSuite" = Windows Live Essentials
"WT083877" = Chuzzle Deluxe
"WT083885" = Zuma's Revenge
"WT083898" = Virtual Villagers - The Secret City
"WT083903" = Escape Rosecliff Island
"WT083929" = Bejeweled 2 Deluxe
"WT083957" = Jewel Quest 3
"WT083958" = Penguins!
"WT083959" = Polar Bowler
"WT083969" = Virtual Families
"WT084018" = FATE - The Traitor Soul
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"Yazak Chat" = Yazak Chat 8.91.3

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"d40704276e72b58f" = Zecco ForexTrader
"GoToMeeting" = GoToMeeting 4.5.0.457

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/19/2011 8:35:03 AM | Computer Name = Janet-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 7/19/2011 4:29:30 PM | Computer Name = Janet-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: c5c Start
Time: 01cc4643a1fcda7c Termination Time: 934 Application Path: C:\Program Files (x86)\Internet
Explorer\iexplore.exe Report Id:

Error - 7/19/2011 4:31:38 PM | Computer Name = Janet-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: hpswp_BHO.dll_unloaded, version: 0.0.0.0,
time stamp: 0x4ad4fb6d Exception code: 0xc0000005 Fault offset: 0x0cf770d0 Faulting
process id: 0x2094 Faulting application start time: 0x01cc46529052e1fe Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
hpswp_BHO.dll Report Id: 19da166f-b246-11e0-85cf-00266c8b4e93

Error - 7/21/2011 4:51:42 AM | Computer Name = Janet-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0x7e7e7e7e Faulting process id:
0x850 Faulting application start time: 0x01cc47821b0a759d Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: a72f9eb5-b376-11e0-b2a3-00266c8b4e93

Error - 7/21/2011 8:40:27 PM | Computer Name = Janet-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: Flash10t.ocx, version: 10.3.181.26,
time stamp: 0x4df339cd Exception code: 0xc0000005 Fault offset: 0x003ad5bf Faulting
process id: 0xad0 Faulting application start time: 0x01cc48077994eebb Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\windows\SysWOW64\Macromed\Flash\Flash10t.ocx Report Id: 31192b25-b3fb-11e0-b94c-00266c8b4e93

Error - 7/21/2011 10:19:08 PM | Computer Name = Janet-PC | Source = System Restore | ID = 8193
Description = Failed to create restore point (Process = C:\windows\system32\wbem\wmiprvse.exe;
Description = OTL Restore Point - 7/21/2011 9:19:03 PM; Error = 0x80070514).

Error - 7/22/2011 3:15:38 AM | Computer Name = Janet-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: SeaNote.dll_unloaded, version: 0.0.0.0,
time stamp: 0x4d7929b8 Exception code: 0xc0000005 Fault offset: 0x71980fd0 Faulting
process id: 0x1ca0 Faulting application start time: 0x01cc483d2d9dcd7e Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
SeaNote.dll Report Id: 65eb8cbe-b432-11e0-b598-00266c8b4e93

Error - 7/23/2011 12:07:15 AM | Computer Name = Janet-PC | Source = Application Error | ID = 1000
Description = Faulting application name: OTL.exe, version: 3.2.26.1, time stamp:
0x2a425e19 Faulting module name: KERNELBASE.dll, version: 6.1.7601.17625, time stamp:
0x4de8781e Exception code: 0x0eedfade Fault offset: 0x0000b9bc Faulting process id:
0x1628 Faulting application start time: 0x01cc48ee003720ca Faulting application path:
C:\Users\Janet\Desktop\OTL.exe Faulting module path: C:\windows\syswow64\KERNELBASE.dll
Report
Id: 3f4c2643-b4e1-11e0-9e63-00266c8b4e93

Error - 7/23/2011 12:08:36 AM | Computer Name = Janet-PC | Source = Application Error | ID = 1000
Description = Faulting application name: OTL.exe, version: 3.2.26.1, time stamp:
0x2a425e19 Faulting module name: KERNELBASE.dll, version: 6.1.7601.17625, time stamp:
0x4de8781e Exception code: 0x0eedfade Fault offset: 0x0000b9bc Faulting process id:
0x420 Faulting application start time: 0x01cc48ee31295ec5 Faulting application path:
C:\Users\Janet\Desktop\OTL.exe Faulting module path: C:\windows\syswow64\KERNELBASE.dll
Report
Id: 6f5d2c72-b4e1-11e0-9e63-00266c8b4e93

Error - 7/23/2011 12:13:27 AM | Computer Name = Janet-PC | Source = System Restore | ID = 8193
Description = Failed to create restore point (Process = C:\windows\system32\wbem\wmiprvse.exe;
Description = OTL Restore Point - 7/22/2011 11:13:22 PM; Error = 0x80070514).

[ System Events ]
Error - 7/6/2011 7:27:18 AM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7030
Description = The Mp3Tube Toolbar Updater Service service is marked as an interactive
service. However, the system is configured to not allow interactive services.
This service may not function properly.

Error - 7/6/2011 3:02:58 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7034
Description = The Mp3Tube Toolbar Updater Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 7/7/2011 1:47:34 PM | Computer Name = Janet-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Windows Internet Explorer 9 for Windows 7 for x64-based
Systems.

Error - 7/7/2011 1:51:01 PM | Computer Name = Janet-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Windows Internet Explorer 9 for Windows 7 for x64-based
Systems.

Error - 7/7/2011 8:43:30 PM | Computer Name = Janet-PC | Source = DCOM | ID = 10016
Description =

Error - 7/7/2011 8:43:38 PM | Computer Name = Janet-PC | Source = DCOM | ID = 10016
Description =

Error - 7/10/2011 12:58:27 PM | Computer Name = Janet-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Windows Internet Explorer 9 for Windows 7 for x64-based
Systems.

Error - 7/14/2011 2:49:09 AM | Computer Name = Janet-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Windows Internet Explorer 9 for Windows 7 for x64-based
Systems.

Error - 7/14/2011 12:29:52 PM | Computer Name = Janet-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Adobe
Acrobat Update Service service to connect.

Error - 7/21/2011 9:26:38 PM | Computer Name = Janet-PC | Source = DCOM | ID = 10010
Description =


< End of report >
GMER - I tried both of the downloads. I am not sure if I am doing them right. I tried running them - and at first they did a scan or something - I saw system things at the bottom, but it never gave me the Rootkit warning. It just stopped. Also - the things I was supposed to uncheck were not checked - nor did it give me the option of checking or unchecking those things. The only things that were checked were: Services, Registry, Files, C:\\ - the other things were not checked.

I wasn't sure what to do with that one - so I shut it.

The Security Check Log is:
Results of screen317's Security Check version 0.99.17
Windows 7 (UAC is enabled)
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
avast! Free Antivirus
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

MVPS Hosts File
Malwarebytes' Anti-Malware
Java™ 6 Update 22
Java™ 6 Update 23
Out of date Java installed!
Flash Player Out of Date!
Adobe Flash Player 10.2.152.32
Adobe Reader X (10.1.0)
Mozilla Firefox (3.6.16) Firefox Out of Date!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Norton ccSvcHst.exe
NetRatingsNetSight NetSight NielsenOnline.exe
NetRatingsNetSight NetSight meter1 NielsenOnline64.exe
Common Files Microsoft Shared Windows Live AvastSvc.exe -?-
Alwil Software Avast5 AvastUI.exe
``````````End of Log````````````

The Most Recent Malwarebytes log is:
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7175

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

7/22/2011 11:03:03 PM
mbam-log-2011-07-22 (23-03-03).txt

Scan type: Quick scan
Objects scanned: 193459
Time elapsed: 3 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


The PREVIOUS log - that had all the infections is:

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7175

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

7/21/2011 8:36:59 PM
mbam-log-2011-07-21 (20-36-59).txt

Scan type: Quick scan
Objects scanned: 193231
Time elapsed: 3 minute(s), 22 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 10
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\program files (x86)\play pickle\playpicklelib32.dll (PUP.Magoo) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{02F0243C-2E71-4a1a-A790-6C30888119D0} (PUP.Magoo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\PlayPickleText.Linker.1 (PUP.Magoo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\PlayPickleText.Linker (PUP.Magoo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02F0243C-2E71-4A1A-A790-6C30888119D0} (PUP.Magoo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{02F0243C-2E71-4A1A-A790-6C30888119D0} (PUP.Magoo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{02F0243C-2E71-4A1A-A790-6C30888119D0} (PUP.Magoo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{AEB04B5E-C981-47a9-B847-33EE4C92F6B9} (PUP.Magoo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AEB04B5E-C981-47A9-B847-33EE4C92F6B9} (PUP.Magoo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{AEB04B5E-C981-47A9-B847-33EE4C92F6B9} (PUP.Magoo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{AEB04B5E-C981-47A9-B847-33EE4C92F6B9} (PUP.Magoo) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\program files (x86)\play pickle\pptl.dll (PUP.Magoo) -> Quarantined and deleted successfully.
c:\program files (x86)\play pickle\playpicklelib32.dll (PUP.Magoo) -> Quarantined and deleted successfully.
We will disregard GMER. Please delete it. Thanks :)

1. All tools MUST be run from the executable. (.exe)
With Admin Rights (Right click, choose "Run as Administrator")


Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs

    **********************************************
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
That was kind of scary. Combo Fix didn't create a recovery console - so I guess I already have one. Once it ran I couldn't do anything. Everything I tried to open gave me an error that it was a key that was selected to be deleted. I couldn't open Avast, IE, Word, the calculator, anything. But once I rebooted the computer I am able to access those things again. Here is my log: It looks like I didn't have Windows Defender disabled. ComboFix 11-07-23.01 - Janet 07/23/2011 11:20:54.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2811.1715 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe c:\program files (x86)\FREEzeFrog c:\users\Janet\AppData\Roaming\FREEzeFrog c:\windows\security\Database\tmp.edb c:\windows\system32\Thumbs.db c:\windows\SysWow64\BSTIEPrintCtl1.dll . . ((((((((((((((((((((((((( Files Created from 2011-06-23 to 2011-07-23 ))))))))))))))))))))))))))))))) . . 2011-07-23 16:27 . 2011-07-23 16:27 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-07-23 16:19 . 2011-07-23 16:19 ——– d—–w- C:\32788R22FWJFW 2011-07-22 17:38 . 2011-07-13 04:53 8578896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{35C89289-06B0-4021-BBD0-206FFB6D555F}\mpengine.dll 2011-07-21 09:38 . 2011-07-22 01:40 ——– d—–w- c:\program files (x86)\Play Pickle 2011-07-16 16:06 . 2011-07-16 16:06 ——– d—–w- c:\program files (x86)\Safari 2011-07-16 16:04 . 2011-07-16 16:04 ——– d—–w- c:\program files (x86)\Apple Software Update 2011-07-15 08:53 . 2011-07-15 08:54 ——– d—–w- c:\users\Janet 2 2011-07-14 08:27 . 2011-07-14 08:27 ——– d—–w- c:\program files (x86)\Common Files\Adobe 2011-07-14 08:19 . 2011-07-14 08:19 ——– d—–w- c:\program files (x86)\Common Files\Adobe AIR 2011-07-13 22:55 . 2011-07-14 09:07 ——– d—–w- c:\users\Janet\AppData\Roaming\Skype 2011-07-13 22:55 . 2011-07-13 22:55 ——– d—–r- c:\program files (x86)\Skype 2011-07-13 22:55 . 2011-07-13 22:55 ——– d—–w- c:\programdata\Skype 2011-07-13 05:38 . 2011-07-13 05:38 ——– d—–w- c:\program files (x86)\NetRatingsNetSight 2011-07-13 00:16 . 2011-06-03 06:57 243200 —-a-w- c:\windows\system32\wow64.dll 2011-07-13 00:16 . 2011-06-03 05:57 25600 —-a-w- c:\windows\SysWow64\setup16.exe 2011-07-13 00:16 . 2011-06-03 06:57 13312 —-a-w- c:\windows\system32\wow64cpu.dll 2011-07-13 00:16 . 2011-06-03 06:57 16384 —-a-w- c:\windows\system32\ntvdm64.dll 2011-07-13 00:16 . 2011-06-03 06:00 14336 —-a-w- c:\windows\SysWow64\ntvdm64.dll 2011-07-13 00:16 . 2011-06-03 05:56 5120 —-a-w- c:\windows\SysWow64\wow32.dll 2011-07-13 00:16 . 2011-06-03 03:53 7680 —-a-w- c:\windows\SysWow64\instnm.exe 2011-07-13 00:16 . 2011-06-03 03:53 2048 —-a-w- c:\windows\SysWow64\user.exe 2011-07-11 21:39 . 2011-07-11 21:39 0 —ha-w- c:\users\Janet\AppData\Local\BIT8DDE.tmp 2011-07-11 08:27 . 2011-07-11 08:27 11776 —-a-w- c:\program files (x86)\Mozilla Firefox\plugins\nprjplug.dll 2011-07-11 08:26 . 2011-07-11 08:26 ——– d—–w- c:\program files (x86)\Common Files\xing shared 2011-07-11 08:26 . 2011-07-11 08:26 150712 —-a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppl3260.dll 2011-07-11 08:26 . 2011-07-11 08:26 105472 —-a-w- c:\program files (x86)\Mozilla Firefox\plugins\nprpjplug.dll 2011-07-11 08:26 . 2011-07-11 08:26 ——– d—–w- c:\program files (x86)\Real 2011-07-08 19:03 . 2011-07-08 19:04 ——– d—–w- c:\users\Ryan 2011-07-08 07:21 . 2011-07-08 07:21 0 —ha-w- c:\users\Janet\AppData\Local\BIT178A.tmp 2011-07-07 15:59 . 2011-07-07 15:59 0 —ha-w- c:\users\Janet\AppData\Local\BITA736.tmp 2011-07-06 11:23 . 2011-07-06 11:23 ——– d—–w- c:\program files (x86)\FilmFanaticEI 2011-07-05 16:19 . 2011-07-05 16:19 0 —ha-w- c:\users\Janet\AppData\Local\BIT2CD9.tmp 2011-07-02 00:50 . 2011-07-02 00:50 ——– d—–w- c:\programdata\Apple Computer 2011-07-02 00:49 . 2011-07-02 00:49 ——– d—–w- c:\program files (x86)\Common Files\Apple 2011-07-02 00:49 . 2011-07-02 00:49 ——– d—–w- c:\users\Janet\AppData\Local\Apple 2011-07-02 00:49 . 2011-07-02 00:49 ——– d—–w- c:\programdata\Apple 2011-07-01 17:33 . 2011-07-01 17:33 1811848 —-a-w- c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll 2011-06-24 21:10 . 2011-06-24 21:10 0 —ha-w- c:\users\Janet\AppData\Local\BIT7E81.tmp 2011-06-24 18:42 . 2011-06-24 18:42 0 —ha-w- c:\users\Janet\AppData\Local\BIT425.tmp 2011-06-24 17:29 . 2011-06-24 17:29 0 —ha-w- c:\users\Janet\AppData\Local\BIT9474.tmp . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-07-11 08:26 . 2010-01-30 04:03 499712 —-a-w- c:\windows\SysWow64\msvcp71.dll 2011-07-11 08:26 . 2009-11-18 02:49 348160 —-a-w- c:\windows\SysWow64\msvcr71.dll 2011-07-07 00:52 . 2011-01-10 04:27 41272 —-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-07-07 00:52 . 2011-01-10 04:27 25912 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-07-04 11:43 . 2010-12-11 05:55 40112 —-a-w- c:\windows\avastSS.scr 2011-07-04 11:43 . 2010-12-11 05:55 199304 —-a-w- c:\windows\SysWow64\aswBoot.exe 2011-07-04 11:43 . 2011-01-31 22:41 253888 —-a-w- c:\windows\system32\aswBoot.exe 2011-07-04 11:36 . 2011-06-05 16:17 600920 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2011-07-04 11:36 . 2010-12-11 05:55 288088 —-a-w- c:\windows\system32\drivers\aswSP.sys 2011-07-04 11:35 . 2010-12-11 05:55 45400 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2011-07-04 11:32 . 2010-12-11 05:55 31064 —-a-w- c:\windows\system32\drivers\aswRdr.sys 2011-07-04 11:32 . 2010-12-11 05:55 64856 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2011-07-04 11:32 . 2010-12-11 05:55 22360 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-06-23 13:18 . 2011-06-23 13:18 404640 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-06-15 21:28 . 2011-06-15 21:28 0 —ha-w- c:\users\Janet\AppData\Local\BIT6DFF.tmp 2011-06-15 19:40 . 2011-06-15 19:40 0 —ha-w- c:\users\Janet\AppData\Local\BIT8C58.tmp 2011-06-15 17:59 . 2011-06-15 17:59 0 —ha-w- c:\users\Janet\AppData\Local\BIT4059.tmp 2011-06-11 21:34 . 2011-06-11 21:34 0 —ha-w- c:\users\Janet\AppData\Local\BITEE74.tmp 2011-06-07 08:08 . 2011-06-07 08:08 0 —ha-w- c:\users\Janet\AppData\Local\BITC43A.tmp 2011-06-04 15:02 . 2011-06-04 15:02 0 —ha-w- c:\users\Janet\AppData\Local\BIT99B4.tmp 2011-06-03 05:57 . 2011-07-13 00:16 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2011-06-02 08:46 . 2011-06-02 08:46 0 —ha-w- c:\users\Janet\AppData\Local\BIT447E.tmp 2011-06-01 15:30 . 2011-06-01 15:30 0 —ha-w- c:\users\Janet\AppData\Local\BIT514A.tmp 2011-05-25 00:14 . 2010-12-11 05:12 270720 ——w- c:\windows\system32\MpSigStub.exe 2011-05-14 14:32 . 2011-05-14 14:32 0 —ha-w- c:\users\Janet\AppData\Local\BIT3217.tmp 2011-05-13 16:25 . 2011-05-13 16:25 0 —ha-w- c:\users\Janet\AppData\Local\BIT950D.tmp 2011-05-13 10:04 . 2011-05-13 10:04 0 —ha-w- c:\users\Janet\AppData\Local\BIT3CA2.tmp 2011-05-09 05:26 . 2009-07-14 02:36 152576 —-a-w- c:\windows\SysWow64\msclmd.dll 2011-05-09 05:26 . 2009-07-14 02:36 175616 —-a-w- c:\windows\system32\msclmd.dll 2011-05-04 02:39 . 2011-05-04 02:39 0 —ha-w- c:\users\Janet\AppData\Local\BIT731C.tmp 2011-05-03 06:58 . 2010-06-24 16:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-05-03 05:29 . 2011-06-16 01:43 976896 —-a-w- c:\windows\system32\inetcomm.dll 2011-05-03 04:30 . 2011-06-16 01:43 741376 —-a-w- c:\windows\SysWow64\inetcomm.dll 2011-04-29 03:06 . 2011-06-16 01:44 467456 —-a-w- c:\windows\system32\drivers\srv.sys 2011-04-29 03:05 . 2011-06-16 01:44 410112 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-04-29 03:05 . 2011-06-16 01:44 168448 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-04-27 02:40 . 2011-06-16 01:44 158208 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-04-27 02:39 . 2011-06-16 01:44 289280 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-04-27 02:39 . 2011-06-16 01:44 128000 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-04-25 05:33 . 2011-06-16 01:44 1923968 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-04-25 02:34 . 2011-06-16 01:44 499200 —-a-w- c:\windows\system32\drivers\afd.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{6FFB615D-E8CE-4ADD-8D9F-31C4BE9C26E4}] 2011-01-16 18:08 1530880 —-a-w- c:\program files (x86)\InboxDollars\Toolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{47980628-3844-42AA-A0DD-E2D86BBA9600}"= "c:\program files (x86)\InboxDollars\Toolbar.dll" [2011-01-16 1530880] . [HKEY_CLASSES_ROOT\clsid\{47980628-3844-42aa-a0dd-e2d86bba9600}] [HKEY_CLASSES_ROOT\FCTB000062133.IEToolbar.3] [HKEY_CLASSES_ROOT\TypeLib\{5DB5671F-D35B-419E-A124-0653A57FBCA1}] [HKEY_CLASSES_ROOT\FCTB000062133.IEToolbar] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "NortonOnlineBackupReminder"="c:\program files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" [2009-08-10 529256] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-07-13 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "TkBellExe"="c:\program files (x86)\Real\RealPlayer\Update\realsched.exe" [2011-07-11 273544] "NielsenOnline"="c:\program files (x86)\NetRatingsNetSight\NetSight\NielsenOnline.exe" [2010-11-17 47424] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] "Play Pickle"="c:\program files (x86)\Play Pickle\playpickle32.exe" [2011-07-21 109056] . c:\users\Janet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-3-29 227712] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-11 135664] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-05-06 191752] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-11 135664] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-06 137560] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 nnfwdk;Nielsen WFP Driver;c:\program files (x86)\NetRatingsNetSight\NetSight\meter1\nnfwdk64.sys [2010-10-04 25648] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S2 NielsenUpdate;Nielsen Update;c:\program files (x86)\NetRatingsNetSight\NetSight\NielsenUpdate.exe [2010-11-17 303936] S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x] S2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\SymcPCCULaunchSvc.exe [2011-06-01 123320] S2 PCCUJobMgr;Common Client Job Manager Service;c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe [2009-08-24 126392] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2011-07-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-11 22:41] . 2011-07-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-11 22:41] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-07-04 11:43 134384 —-a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.yahoo.com/?fr=fp-yie9 mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = [removed] [removed] [removed] FF - ProfilePath - c:\users\Janet\AppData\Roaming\Mozilla\Firefox\Profiles\2tgbsxcq.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?brand=TSNA&bmod=TSNA FF - prefs.js: network.proxy.type - 0 FF - Ext: Skype extension: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF - Ext: Nielsen: {D908A1CC-54B4-4af9-9BB4-964F5BD3CDB7} - c:\program files (x86)\NetRatingsNetSight\NetSight\meter1\FFAddon . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) WebBrowser-{47980628-3844-42AA-A0DD-E2D86BBA9600} - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) HKLM-Run-(Default) - (no file) . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCCUJobMgr] "ImagePath"="\"c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\diMaster.dll\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3507447898-1527847399-1597453590-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3507447898-1527847399-1597453590-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\Alwil Software\Avast5\AvastSvc.exe c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe . ************************************************************************** . Completion time: 2011-07-23 11:38:05 - machine was rebooted ComboFix-quarantined-files.txt 2011-07-23 16:38 . Pre-Run: 265,674,653,696 bytes free Post-Run: 265,510,154,240 bytes free . - - End Of File - - B2A1D77D8EE67FEAAD87F4833AEB3965
It is a preventative measure for you not to click anything to interfere the fixing process of CF. :) Are you still using playpickle or norton?

It is a preventative measure for you not to click anything to interfere the fixing process of CF. :)

Are you still using playpickle or norton?


Oh! That is good! I thought I fried the computer. LOL

I never did use playpickle. That must be something my son loaded. That was what came up as an error when I start my computer (after I removed the things Malwarebytes said were infected) - and now I notice this little pickle coming up in a window every time I go over an underlined word.

As far as Norton, I use the online backup. That is the only Norton I use. Is that a problem? If it is - I could get rid of it.
No not a problem at all, I just wanted to clarify certain things. :)

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

Folder::
c:\program files (x86)\Play Pickle
c:\program files (x86)\InboxDollars

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Play Pickle"=-

[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{6FFB615D-E8CE-4ADD-8D9F-31C4BE9C26E4}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{47980628-3844-42AA-A0DD-E2D86BBA9600}"=-


In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

===================================================

On your next reply please post :
Combofix log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Thanks! I ran the combo fix. The pcikle thing didn't come up when I restarted my computer this time. ComboFix 11-07-23.01 - Janet 07/24/2011 20:07:30.2.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2811.1727 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Janet\Desktop\CFSCRIPT.txt AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\InboxDollars c:\program files (x86)\InboxDollars\aboutTabs.7.js c:\program files (x86)\InboxDollars\aboutTabs.8.js c:\program files (x86)\InboxDollars\audio.bmp c:\program files (x86)\InboxDollars\banner_container.html c:\program files (x86)\InboxDollars\bookmark_off.bmp c:\program files (x86)\InboxDollars\bookmark_on.bmp c:\program files (x86)\InboxDollars\bookmarksplugin.dll c:\program files (x86)\InboxDollars\bubble_permissions.html c:\program files (x86)\InboxDollars\build c:\program files (x86)\InboxDollars\caching_banner.html c:\program files (x86)\InboxDollars\chevron.bmp c:\program files (x86)\InboxDollars\component.xsl c:\program files (x86)\InboxDollars\default.xml c:\program files (x86)\InboxDollars\efolder.bmp c:\program files (x86)\InboxDollars\email.bmp c:\program files (x86)\InboxDollars\email2.bmp c:\program files (x86)\InboxDollars\emailchecker_plugin.dll c:\program files (x86)\InboxDollars\facebook.feature c:\program files (x86)\InboxDollars\fbrss.xsl c:\program files (x86)\InboxDollars\ff.xsl c:\program files (x86)\InboxDollars\folder.bmp c:\program files (x86)\InboxDollars\Helper.dll c:\program files (x86)\InboxDollars\icons.bmp c:\program files (x86)\InboxDollars\iefavelem.bmp c:\program files (x86)\InboxDollars\images\amazon.bmp c:\program files (x86)\InboxDollars\images\ebay.bmp c:\program files (x86)\InboxDollars\images\email.bmp c:\program files (x86)\InboxDollars\images\email2.bmp c:\program files (x86)\InboxDollars\images\msgbox\down.gif c:\program files (x86)\InboxDollars\images\msgbox\hr.bmp c:\program files (x86)\InboxDollars\images\msgbox\mark.png c:\program files (x86)\InboxDollars\images\msgbox\mark_do.png c:\program files (x86)\InboxDollars\images\msgbox\mark_na.png c:\program files (x86)\InboxDollars\images\msgbox\navbg.bmp c:\program files (x86)\InboxDollars\images\msgbox\refresh.png c:\program files (x86)\InboxDollars\images\msgbox\refresh_do.png c:\program files (x86)\InboxDollars\images\msgbox\refresh_na.png c:\program files (x86)\InboxDollars\images\msgbox\trash.png c:\program files (x86)\InboxDollars\images\msgbox\trash_do.png c:\program files (x86)\InboxDollars\images\msgbox\trash_na.png c:\program files (x86)\InboxDollars\images\msgbox\unmark.png c:\program files (x86)\InboxDollars\images\msgbox\unmark_do.png c:\program files (x86)\InboxDollars\images\msgbox\unmark_na.png c:\program files (x86)\InboxDollars\images\msgbox\up.gif c:\program files (x86)\InboxDollars\images\ticker\left.gif c:\program files (x86)\InboxDollars\images\ticker\right.gif c:\program files (x86)\InboxDollars\images\weather\0.bmp c:\program files (x86)\InboxDollars\images\weather\1.bmp c:\program files (x86)\InboxDollars\images\weather\10.bmp c:\program files (x86)\InboxDollars\images\weather\11.bmp c:\program files (x86)\InboxDollars\images\weather\12.bmp c:\program files (x86)\InboxDollars\images\weather\13.bmp c:\program files (x86)\InboxDollars\images\weather\14.bmp c:\program files (x86)\InboxDollars\images\weather\15.bmp c:\program files (x86)\InboxDollars\images\weather\16.bmp c:\program files (x86)\InboxDollars\images\weather\17.bmp c:\program files (x86)\InboxDollars\images\weather\18.bmp c:\program files (x86)\InboxDollars\images\weather\19.bmp c:\program files (x86)\InboxDollars\images\weather\2.bmp c:\program files (x86)\InboxDollars\images\weather\20.bmp c:\program files (x86)\InboxDollars\images\weather\21.bmp c:\program files (x86)\InboxDollars\images\weather\22.bmp c:\program files (x86)\InboxDollars\images\weather\23.bmp c:\program files (x86)\InboxDollars\images\weather\24.bmp c:\program files (x86)\InboxDollars\images\weather\25.bmp c:\program files (x86)\InboxDollars\images\weather\26.bmp c:\program files (x86)\InboxDollars\images\weather\27.bmp c:\program files (x86)\InboxDollars\images\weather\28.bmp c:\program files (x86)\InboxDollars\images\weather\29.bmp c:\program files (x86)\InboxDollars\images\weather\3.bmp c:\program files (x86)\InboxDollars\images\weather\30.bmp c:\program files (x86)\InboxDollars\images\weather\31.bmp c:\program files (x86)\InboxDollars\images\weather\32.bmp c:\program files (x86)\InboxDollars\images\weather\33.bmp c:\program files (x86)\InboxDollars\images\weather\34.bmp c:\program files (x86)\InboxDollars\images\weather\35.bmp c:\program files (x86)\InboxDollars\images\weather\36.bmp c:\program files (x86)\InboxDollars\images\weather\37.bmp c:\program files (x86)\InboxDollars\images\weather\38.bmp c:\program files (x86)\InboxDollars\images\weather\39.bmp c:\program files (x86)\InboxDollars\images\weather\4.bmp c:\program files (x86)\InboxDollars\images\weather\40.bmp c:\program files (x86)\InboxDollars\images\weather\41.bmp c:\program files (x86)\InboxDollars\images\weather\42.bmp c:\program files (x86)\InboxDollars\images\weather\43.bmp c:\program files (x86)\InboxDollars\images\weather\44.bmp c:\program files (x86)\InboxDollars\images\weather\45.bmp c:\program files (x86)\InboxDollars\images\weather\46.bmp c:\program files (x86)\InboxDollars\images\weather\47.bmp c:\program files (x86)\InboxDollars\images\weather\5.bmp c:\program files (x86)\InboxDollars\images\weather\6.bmp c:\program files (x86)\InboxDollars\images\weather\7.bmp c:\program files (x86)\InboxDollars\images\weather\8.bmp c:\program files (x86)\InboxDollars\images\weather\9.bmp c:\program files (x86)\InboxDollars\images\weather\hr.bmp c:\program files (x86)\InboxDollars\images\weather\na.bmp c:\program files (x86)\InboxDollars\images\weather\png\0.png c:\program files (x86)\InboxDollars\images\weather\png\1.png c:\program files (x86)\InboxDollars\images\weather\png\10.png c:\program files (x86)\InboxDollars\images\weather\png\11.png c:\program files (x86)\InboxDollars\images\weather\png\12.png c:\program files (x86)\InboxDollars\images\weather\png\13.png c:\program files (x86)\InboxDollars\images\weather\png\14.png c:\program files (x86)\InboxDollars\images\weather\png\15.png c:\program files (x86)\InboxDollars\images\weather\png\16.png c:\program files (x86)\InboxDollars\images\weather\png\17.png c:\program files (x86)\InboxDollars\images\weather\png\18.png c:\program files (x86)\InboxDollars\images\weather\png\19.png c:\program files (x86)\InboxDollars\images\weather\png\2.png c:\program files (x86)\InboxDollars\images\weather\png\20.png c:\program files (x86)\InboxDollars\images\weather\png\21.png c:\program files (x86)\InboxDollars\images\weather\png\22.png c:\program files (x86)\InboxDollars\images\weather\png\23.png c:\program files (x86)\InboxDollars\images\weather\png\24.png c:\program files (x86)\InboxDollars\images\weather\png\25.png c:\program files (x86)\InboxDollars\images\weather\png\26.png c:\program files (x86)\InboxDollars\images\weather\png\27.png c:\program files (x86)\InboxDollars\images\weather\png\28.png c:\program files (x86)\InboxDollars\images\weather\png\29.png c:\program files (x86)\InboxDollars\images\weather\png\3.png c:\program files (x86)\InboxDollars\images\weather\png\30.png c:\program files (x86)\InboxDollars\images\weather\png\31.png c:\program files (x86)\InboxDollars\images\weather\png\32.pngc:\program files (x86)\InboxDollars\images\weather\png\33.png c:\program files (x86)\InboxDollars\images\weather\png\34.png c:\program files (x86)\InboxDollars\images\weather\png\35.png c:\program files (x86)\InboxDollars\images\weather\png\36.png c:\program files (x86)\InboxDollars\images\weather\png\37.png c:\program files (x86)\InboxDollars\images\weather\png\38.png c:\program files (x86)\InboxDollars\images\weather\png\39.png c:\program files (x86)\InboxDollars\images\weather\png\4.png c:\program files (x86)\InboxDollars\images\weather\png\40.png c:\program files (x86)\InboxDollars\images\weather\png\41.png c:\program files (x86)\InboxDollars\images\weather\png\42.png c:\program files (x86)\InboxDollars\images\weather\png\43.png c:\program files (x86)\InboxDollars\images\weather\png\44.png c:\program files (x86)\InboxDollars\images\weather\png\45.png c:\program files (x86)\InboxDollars\images\weather\png\46.png c:\program files (x86)\InboxDollars\images\weather\png\47.png c:\program files (x86)\InboxDollars\images\weather\png\5.png c:\program files (x86)\InboxDollars\images\weather\png\6.png c:\program files (x86)\InboxDollars\images\weather\png\7.png c:\program files (x86)\InboxDollars\images\weather\png\8.png c:\program files (x86)\InboxDollars\images\weather\png\9.png c:\program files (x86)\InboxDollars\images\weather\png\na.png c:\program files (x86)\InboxDollars\images\weather\png\Thumbs.db c:\program files (x86)\InboxDollars\images\wikipedia.bmp c:\program files (x86)\InboxDollars\images\yahoo.bmp c:\program files (x86)\InboxDollars\localization.xml c:\program files (x86)\InboxDollars\location.xsl c:\program files (x86)\InboxDollars\magglass.ico c:\program files (x86)\InboxDollars\manage_bookmarks.html c:\program files (x86)\InboxDollars\marquee.html c:\program files (x86)\InboxDollars\marquee_permissions.html c:\program files (x86)\InboxDollars\messaging.bmp c:\program files (x86)\InboxDollars\minus.bmp c:\program files (x86)\InboxDollars\msgbox_bubble.tmpl c:\program files (x86)\InboxDollars\msgbox_openmsg.tmpl c:\program files (x86)\InboxDollars\msgboxplugin.dll c:\program files (x86)\InboxDollars\offline.html c:\program files (x86)\InboxDollars\patch.bat c:\program files (x86)\InboxDollars\plus.bmp c:\program files (x86)\InboxDollars\podcast.bmp c:\program files (x86)\InboxDollars\podcast.xsl c:\program files (x86)\InboxDollars\radio.bmp c:\program files (x86)\InboxDollars\RadioPlugin.dll c:\program files (x86)\InboxDollars\resize.bmp c:\program files (x86)\InboxDollars\rssfeed.bmp c:\program files (x86)\InboxDollars\RSSReader_plugin.dll c:\program files (x86)\InboxDollars\search.xsl c:\program files (x86)\InboxDollars\SearchComponent.dll c:\program files (x86)\InboxDollars\settings c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_dropdwn_down.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_dropdwn_over.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_dropdwn_up.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_max_down.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_max_over.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_max_up.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_min_down.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_min_over.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_min_up.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_pause_down.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_pause_over.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_pause_up.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_play_down.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_play_over.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_play_up.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_playcntrl_over.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_playcntrl_up.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_stop_down.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_stop_over.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_stop_up.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_volcntrl_over.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\btn_volcntrl_up.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\Equalizer1.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\Equalizer2.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\Equalizer3.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\Equalizer4.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\Equalizer5.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\Equalizer6.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\playcntrl_bg.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\radio.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\radio_mask.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\radio_minimalized.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\radio_minimalized_mask.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\station.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\vol_01.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\vol_02.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\vol_03.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\volslide_bg.bmp c:\program files (x86)\InboxDollars\skins\radio\gray03\volslide_track.bmp c:\program files (x86)\InboxDollars\star_on.gif c:\program files (x86)\InboxDollars\ticker.html c:\program files (x86)\InboxDollars\Toolbar.dll c:\program files (x86)\InboxDollars\ToolbarUpdate.exe c:\program files (x86)\InboxDollars\TroubleShooter.exe c:\program files (x86)\InboxDollars\Uninst.exe c:\program files (x86)\InboxDollars\update_progress.html c:\program files (x86)\InboxDollars\version.txt c:\program files (x86)\InboxDollars\version.xsl c:\program files (x86)\InboxDollars\weather_bubble.tmpl c:\program files (x86)\InboxDollars\weatherplugin.dll c:\program files (x86)\Play Pickle c:\program files (x86)\Play Pickle\ars.cfg c:\program files (x86)\Play Pickle\playpickle32.exe c:\program files (x86)\Play Pickle\ppun.exe . . ((((((((((((((((((((((((( Files Created from 2011-06-25 to 2011-07-25 ))))))))))))))))))))))))))))))) . . 2011-07-25 01:19 . 2011-07-25 01:19 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-07-22 17:38 . 2011-07-13 04:53 8578896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{35C89289-06B0-4021-BBD0-206FFB6D555F}\mpengine.dll 2011-07-16 16:06 . 2011-07-16 16:06 ——– d—–w- c:\program files (x86)\Safari 2011-07-16 16:04 . 2011-07-16 16:04 ——– d—–w- c:\program files (x86)\Apple Software Update 2011-07-15 08:53 . 2011-07-15 08:54 ——– d—–w- c:\users\Janet 2 2011-07-14 08:27 . 2011-07-14 08:27 ——– d—–w- c:\program files (x86)\Common Files\Adobe 2011-07-14 08:19 . 2011-07-14 08:19 ——– d—–w- c:\program files (x86)\Common Files\Adobe AIR 2011-07-13 22:55 . 2011-07-14 09:07 ——– d—–w- c:\users\Janet\AppData\Roaming\Skype 2011-07-13 22:55 . 2011-07-13 22:55 ——– d—–r- c:\program files (x86)\Skype 2011-07-13 22:55 . 2011-07-13 22:55 ——– d—–w- c:\programdata\Skype 2011-07-13 05:38 . 2011-07-13 05:38 ——– d—–w- c:\program files (x86)\NetRatingsNetSight 2011-07-13 00:16 . 2011-06-03 06:57 243200 —-a-w- c:\windows\system32\wow64.dll 2011-07-13 00:16 . 2011-06-03 05:57 25600 —-a-w- c:\windows\SysWow64\setup16.exe 2011-07-13 00:16 . 2011-06-03 06:57 13312 —-a-w- c:\windows\system32\wow64cpu.dll 2011-07-13 00:16 . 2011-06-03 06:57 16384 —-a-w- c:\windows\system32\ntvdm64.dll 2011-07-13 00:16 . 2011-06-03 06:00 14336 —-a-w- c:\windows\SysWow64\ntvdm64.dll 2011-07-13 00:16 . 2011-06-03 05:56 5120 —-a-w- c:\windows\SysWow64\wow32.dll 2011-07-13 00:16 . 2011-06-03 03:53 7680 —-a-w- c:\windows\SysWow64\instnm.exe 2011-07-13 00:16 . 2011-06-03 03:53 2048 —-a-w- c:\windows\SysWow64\user.exe 2011-07-11 21:39 . 2011-07-11 21:39 0 —ha-w- c:\users\Janet\AppData\Local\BIT8DDE.tmp 2011-07-11 08:27 . 2011-07-11 08:27 11776 —-a-w- c:\program files (x86)\Mozilla Firefox\plugins\nprjplug.dll 2011-07-11 08:26 . 2011-07-11 08:26 ——– d—–w- c:\program files (x86)\Common Files\xing shared 2011-07-11 08:26 . 2011-07-11 08:26 150712 —-a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppl3260.dll 2011-07-11 08:26 . 2011-07-11 08:26 105472 —-a-w- c:\program files (x86)\Mozilla Firefox\plugins\nprpjplug.dll 2011-07-11 08:26 . 2011-07-11 08:26 ——– d—–w- c:\program files (x86)\Real 2011-07-08 19:03 . 2011-07-08 19:04 ——– d—–w- c:\users\Ryan 2011-07-08 07:21 . 2011-07-08 07:21 0 —ha-w- c:\users\Janet\AppData\Local\BIT178A.tmp 2011-07-07 15:59 . 2011-07-07 15:59 0 —ha-w- c:\users\Janet\AppData\Local\BITA736.tmp 2011-07-06 11:23 . 2011-07-06 11:23 ——– d—–w- c:\program files (x86)\FilmFanaticEI 2011-07-05 16:19 . 2011-07-05 16:19 0 —ha-w- c:\users\Janet\AppData\Local\BIT2CD9.tmp 2011-07-02 00:50 . 2011-07-02 00:50 ——– d—–w- c:\programdata\Apple Computer 2011-07-02 00:49 . 2011-07-02 00:49 ——– d—–w- c:\program files (x86)\Common Files\Apple 2011-07-02 00:49 . 2011-07-02 00:49 ——– d—–w- c:\users\Janet\AppData\Local\Apple 2011-07-02 00:49 . 2011-07-02 00:49 ——– d—–w- c:\programdata\Apple 2011-07-01 17:33 . 2011-07-01 17:33 1811848 —-a-w- c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-07-13 21:52 . 2011-02-14 22:05 71072 —-a-w- c:\windows\CouponPrinter.ocx 2011-07-11 08:26 . 2010-01-30 04:03 499712 —-a-w- c:\windows\SysWow64\msvcp71.dll 2011-07-11 08:26 . 2009-11-18 02:49 348160 —-a-w- c:\windows\SysWow64\msvcr71.dll 2011-07-07 00:52 . 2011-01-10 04:27 41272 —-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-07-07 00:52 . 2011-01-10 04:27 25912 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-07-04 11:43 . 2010-12-11 05:55 40112 —-a-w- c:\windows\avastSS.scr 2011-07-04 11:43 . 2010-12-11 05:55 199304 —-a-w- c:\windows\SysWow64\aswBoot.exe 2011-07-04 11:43 . 2011-01-31 22:41 253888 —-a-w- c:\windows\system32\aswBoot.exe 2011-07-04 11:36 . 2011-06-05 16:17 600920 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2011-07-04 11:36 . 2010-12-11 05:55 288088 —-a-w- c:\windows\system32\drivers\aswSP.sys 2011-07-04 11:35 . 2010-12-11 05:55 45400 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2011-07-04 11:32 . 2010-12-11 05:55 31064 —-a-w- c:\windows\system32\drivers\aswRdr.sys 2011-07-04 11:32 . 2010-12-11 05:55 64856 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2011-07-04 11:32 . 2010-12-11 05:55 22360 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-06-24 21:10 . 2011-06-24 21:10 0 —ha-w- c:\users\Janet\AppData\Local\BIT7E81.tmp 2011-06-24 18:42 . 2011-06-24 18:42 0 —ha-w- c:\users\Janet\AppData\Local\BIT425.tmp 2011-06-24 17:29 . 2011-06-24 17:29 0 —ha-w- c:\users\Janet\AppData\Local\BIT9474.tmp 2011-06-23 13:18 . 2011-06-23 13:18 404640 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-06-15 21:28 . 2011-06-15 21:28 0 —ha-w- c:\users\Janet\AppData\Local\BIT6DFF.tmp 2011-06-15 19:40 . 2011-06-15 19:40 0 —ha-w- c:\users\Janet\AppData\Local\BIT8C58.tmp 2011-06-15 17:59 . 2011-06-15 17:59 0 —ha-w- c:\users\Janet\AppData\Local\BIT4059.tmp 2011-06-11 21:34 . 2011-06-11 21:34 0 —ha-w- c:\users\Janet\AppData\Local\BITEE74.tmp 2011-06-07 08:08 . 2011-06-07 08:08 0 —ha-w- c:\users\Janet\AppData\Local\BITC43A.tmp 2011-06-04 15:02 . 2011-06-04 15:02 0 —ha-w- c:\users\Janet\AppData\Local\BIT99B4.tmp 2011-06-03 05:57 . 2011-07-13 00:16 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2011-06-02 08:46 . 2011-06-02 08:46 0 —ha-w- c:\users\Janet\AppData\Local\BIT447E.tmp 2011-06-01 15:30 . 2011-06-01 15:30 0 —ha-w- c:\users\Janet\AppData\Local\BIT514A.tmp 2011-05-25 00:14 . 2010-12-11 05:12 270720 ——w- c:\windows\system32\MpSigStub.exe 2011-05-14 14:32 . 2011-05-14 14:32 0 —ha-w- c:\users\Janet\AppData\Local\BIT3217.tmp 2011-05-13 16:25 . 2011-05-13 16:25 0 —ha-w- c:\users\Janet\AppData\Local\BIT950D.tmp 2011-05-13 10:04 . 2011-05-13 10:04 0 —ha-w- c:\users\Janet\AppData\Local\BIT3CA2.tmp 2011-05-09 05:26 . 2009-07-14 02:36 152576 —-a-w- c:\windows\SysWow64\msclmd.dll 2011-05-09 05:26 . 2009-07-14 02:36 175616 —-a-w- c:\windows\system32\msclmd.dll 2011-05-04 02:39 . 2011-05-04 02:39 0 —ha-w- c:\users\Janet\AppData\Local\BIT731C.tmp 2011-05-03 06:58 . 2010-06-24 16:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-05-03 05:29 . 2011-06-16 01:43 976896 —-a-w- c:\windows\system32\inetcomm.dll 2011-05-03 04:30 . 2011-06-16 01:43 741376 —-a-w- c:\windows\SysWow64\inetcomm.dll 2011-04-29 03:06 . 2011-06-16 01:44 467456 —-a-w- c:\windows\system32\drivers\srv.sys 2011-04-29 03:05 . 2011-06-16 01:44 410112 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-04-29 03:05 . 2011-06-16 01:44 168448 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-04-27 02:40 . 2011-06-16 01:44 158208 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-04-27 02:39 . 2011-06-16 01:44 289280 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-04-27 02:39 . 2011-06-16 01:44 128000 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys . . ((((((((((((((((((((((((((((( SnapShot@2011-07-23_16.33.34 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-14 04:54 . 2011-07-25 01:21 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-07-23 16:29 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-07-23 16:29 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-07-25 01:21 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-07-25 01:21 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2011-07-23 16:29 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-01-03 13:35 . 2011-07-24 04:41 70088 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin + 2010-10-26 08:42 . 2011-07-24 22:54 55810 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin - 2009-07-14 05:10 . 2011-07-23 14:58 48652 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2011-07-24 22:54 48652 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2010-12-11 04:54 . 2011-07-24 22:54 20422 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3507447898-1527847399-1597453590-1000_UserData.bin + 2009-07-14 04:46 . 2011-07-24 10:57 94000 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat + 2010-12-20 07:56 . 2011-07-23 16:47 5164 c:\windows\system32\wdi\ERCQueuedResolutions.dat + 2011-07-24 22:16 . 2011-07-24 22:16 9560 c:\windows\system32\NetworkList\Icons\{BC89A263-B14D-49D8-91EA-5D7A34CB1365}_48.bin + 2011-07-24 22:16 . 2011-07-24 22:16 4280 c:\windows\system32\NetworkList\Icons\{BC89A263-B14D-49D8-91EA-5D7A34CB1365}_32.bin + 2011-07-24 22:16 . 2011-07-24 22:16 2456 c:\windows\system32\NetworkList\Icons\{BC89A263-B14D-49D8-91EA-5D7A34CB1365}_24.bin + 2011-07-25 01:20 . 2011-07-25 01:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-07-23 16:28 . 2011-07-23 16:28 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2011-07-25 01:20 . 2011-07-25 01:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2011-07-23 16:28 . 2011-07-23 16:28 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2010-12-12 17:54 . 2011-07-24 18:34 257430 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin + 2009-07-14 02:36 . 2011-07-24 18:35 624178 c:\windows\system32\perfh009.dat - 2009-07-14 02:36 . 2011-07-23 11:41 624178 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-07-24 18:35 106522 c:\windows\system32\perfc009.dat - 2009-07-14 02:36 . 2011-07-23 11:41 106522 c:\windows\system32\perfc009.dat + 2009-07-14 05:01 . 2011-07-25 01:19 400920 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2011-07-23 16:27 400920 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2011-03-16 23:46 . 2011-07-21 16:09 799744 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3507447898-1527847399-1597453590-1000-12288.dat + 2011-03-16 23:46 . 2011-07-24 12:36 799744 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3507447898-1527847399-1597453590-1000-12288.dat + 2010-12-12 01:38 . 2011-07-25 01:20 1183632 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat - 2010-12-12 01:38 . 2011-07-18 20:54 1183632 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat + 2011-03-16 23:46 . 2011-07-25 01:20 8158960 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3507447898-1527847399-1597453590-1000-8192.dat + 2011-07-14 07:31 . 2011-07-25 01:20 23154920 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3507447898-1527847399-1597453590-1000-4096.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "NortonOnlineBackupReminder"="c:\program files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" [2009-08-10 529256] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-07-13 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "TkBellExe"="c:\program files (x86)\Real\RealPlayer\Update\realsched.exe" [2011-07-11 273544] "NielsenOnline"="c:\program files (x86)\NetRatingsNetSight\NetSight\NielsenOnline.exe" [2010-11-17 47424] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] . c:\users\Janet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-3-29 227712] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-11 135664] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-05-06 191752] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-11 135664] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-06 137560] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 nnfwdk;Nielsen WFP Driver;c:\program files (x86)\NetRatingsNetSight\NetSight\meter1\nnfwdk64.sys [2010-10-04 25648] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S2 NielsenUpdate;Nielsen Update;c:\program files (x86)\NetRatingsNetSight\NetSight\NielsenUpdate.exe [2010-11-17 303936] S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x] S2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\SymcPCCULaunchSvc.exe [2011-06-01 123320] S2 PCCUJobMgr;Common Client Job Manager Service;c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe [2009-08-24 126392] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2011-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-11 22:41] . 2011-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-11 22:41] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-07-04 11:43 134384 —-a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.yahoo.com/?fr=fp-yie9 mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.2.1 [removed] [removed] [removed] FF - ProfilePath - c:\users\Janet\AppData\Roaming\Mozilla\Firefox\Profiles\2tgbsxcq.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?brand=TSNA&bmod=TSNA FF - prefs.js: network.proxy.type - 0 FF - Ext: Skype extension: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF - Ext: Nielsen: {D908A1CC-54B4-4af9-9BB4-964F5BD3CDB7} - c:\program files (x86)\NetRatingsNetSight\NetSight\meter1\FFAddon . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) WebBrowser-{47980628-3844-42AA-A0DD-E2D86BBA9600} - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) AddRemove-InboxDollars - c:\program files (x86)\InboxDollars\Uninst.exe AddRemove-Play Pickle - c:\program files (x86)\Play Pickle\ppun.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCCUJobMgr] "ImagePath"="\"c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\diMaster.dll\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3507447898-1527847399-1597453590-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3507447898-1527847399-1597453590-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\Alwil Software\Avast5\AvastSvc.exe c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe . ************************************************************************** . Completion time: 2011-07-24 20:43:54 - machine was rebooted ComboFix-quarantined-files.txt 2011-07-25 01:43 ComboFix2.txt 2011-07-23 16:38 . Pre-Run: 264,118,849,536 bytes free Post-Run: 263,886,237,696 bytes free . - - End Of File - - 2AE181F64125C56294757CDDA2DCB496
That's good :)

Re-run Malwarebytes' Anti-Malware
  • Double-click MalwareBytes' (Note to Vista users, please right-click and select Run as Administrator.)
    • Go to Update tab to update Malwarebytes' Anti-Malware
  • Then click Check for Updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • Look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Select Uninstall application on close check box and push [external image: Posted Image]
===================================================

On your next reply please post :
MBAM log
ESET log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Thanks! I will get to that after I pick my son up from the movies. I still have that pickle guy popping up on the double underlined stuff. And I forgot to mention that last scan - on the combo fix - I moved the notepad over into combo fix and it said there was a newer version available and asked if I wanted to update - and I said No. So I just ran it with the version I downloaded yesterday.
I ran both. The ESET ran - and found 1 threat - Something from mypoints - But when I clicked on uninstall when finished - it did not uninstall - but it brought up a window that said it had not been installed correctly - and then gave me choices to reinstall, or to click that it was installed correctly. So I clicked that it was installed correctly - and it closed - but it is still on my desktop - and I can't find the scan log txt file in the program files. I can run it again - But I am not sure what I did wrong this time. Here is my malwarebytes log: Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7269 Windows 6.1.7601 Service Pack 1 Internet Explorer 9.0.8112.16421 7/25/2011 12:30:58 AM mbam-log-2011-07-25 (00-30-58).txt Scan type: Quick scan Objects scanned: 197169 Time elapsed: 3 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

I still have that pickle guy popping up on the double underlined stuff.

I don't quite get you; double underlined? :unsure:

Out of curiosity, how old is your son? :lol:

I ran both. The ESET ran - and found 1 threat - Something from mypoints - But when I clicked on uninstall when finished - it did not uninstall - but it brought up a window that said it had not been installed correctly - and then gave me choices to reinstall, or to click that it was installed correctly. So I clicked that it was installed correctly - and it closed - but it is still on my desktop - and I can't find the scan log txt file in the program files.

I can run it again - But I am not sure what I did wrong this time.

Can you run ESET again for me? Don't select Uninstall immediately, you can do that later and see if you can find the log. I'm sorry for causing the trouble.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI