This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

searchqu

43 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have scanned with "HijackThis and saved the logfile below-


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:48:30 PM, on 18/10/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Aprilbaby\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://googlechrome.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll
O4 - HKLM\..\Run: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HWSetup] "C:\Program Files\TOSHIBA\Utilities\HWSetup.exe" hwSetUP
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.gamehouse.com/games/beje2/popcaploader.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs:
O23 - Service: ABP_InstallCheckerService - Unknown owner - C:\Users\APRILB~1\AppData\Local\Temp\ABP_InstallChecker.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 12365 bytes
Hello and Welcome to WhatTheTech Forums

My name is BlackPegasus.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for
    further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to
    get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out
    the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.
  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to
    ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.
Hello Julie A


IMPORTANT NOTE : Please do not delete anything unless instructed to. DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
================
SPYBOT TEATIMER

* Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
* On the left hand side, click on Tools, then click on the Resident Icon in the list.
* Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
* Click on the "System Startup" icon in the List
* Uncheck the "TeaTimer" box and "OK" any prompts.
* If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
* Exit Spybot S&D when done and reboot your computer.
(When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.
===============
NEXT

Fix HijackThis entries
Important!
Please temporarily disable any anti-spyware programs you are using, listed Here
…so they will not interfere with the entries we will be fixing in HijackThis.

  • 1. Run HijackThis
  • If you are on the Main Menu page… Click "Do a system scan only"
  • If you are on the "scan & fix stuff" page… Press the Scan…button.
  • 2. When the scan finishes…Place a check mark next to the following entries (if they are still present):

    O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll
    O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - <http://www.gamehouse.com/games/beje2/popcaploader.cab>

  • 3. After checking these items… CLOSE ALL open windows except HijackThis
  • 4. Click the Fix Checked…button. Choose YES…when prompted to fix the selected items.
  • 5. Once it has fixed them, close HijackThis and reboot your computer normally.
===============
NEXT

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check Scan All Users
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
=======================
NEXT

Please download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
=======================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log and Extras.Txt
3. aswMBR log
4. Hows your computer running?
Hi Gail, Thanks for your help. I have followed your instructions up to the OTL scan and this is the notepad OTL.Txt …it did not give me an Extras.Txt


OTL logfile created on: 10/19/2011 9:16:08 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Aprilbaby\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.84 Gb Total Physical Memory | 2.49 Gb Available Physical Memory | 64.79% Memory free
7.68 Gb Paging File | 6.26 Gb Available in Paging File | 81.52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 360.84 Gb Total Space | 280.73 Gb Free Space | 77.80% Space Free | Partition Type: NTFS

Computer Name: APRILBABY-PC | User Name: Aprilbaby | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Aprilbaby\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\14.0.835.202\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\14.0.835.202\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\14.0.835.202\avutil-51.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\14.0.835.202\avformat-53.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\14.0.835.202\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV:64bit: - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (RSELSVC) – C:\Program Files\TOSHIBA\rselect\RSelSvc.exe (TOSHIBA Corporation)
SRV:64bit: - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agr64svc.exe (LSI Corporation)
SRV - (vToolbarUpdater) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (TMachInfo) – C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (cfWiMAXService) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs.exe (TOSHIBA CORPORATION)
SRV - (ConfigFree Gadget Service) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe (TOSHIBA CORPORATION)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ConfigFree Service) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (BcmSqlStartupSvc) – C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (RTL8187B) – C:\Windows\SysNative\drivers\RTL8187B.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (tdcmdpst) – C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (tos_sps64) – C:\Windows\SysNative\drivers\tos_sps64.sys (TOSHIBA Corporation)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (TVALZ) – C:\Windows\SysNative\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (LPCFilter) – C:\Windows\SysNative\drivers\LPCFilter.sys (COMPAL ELECTRONIC INC.)
DRV:64bit: - (PGEffect) – C:\Windows\SysNative\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV:64bit: - (TVALZFL) – C:\Windows\SysNative\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…U&bmod=TSAU


IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1601795646-3932628227-3861186438-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-1601795646-3932628227-3861186438-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-1601795646-3932628227-3861186438-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://googlechrome.com/
IE - HKU\S-1-5-21-1601795646-3932628227-3861186438-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKU\S-1-5-21-1601795646-3932628227-3861186438-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-AU
IE - HKU\S-1-5-21-1601795646-3932628227-3861186438-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 44 45 6C 9C 89 4F CC 01 [binary data]
IE - HKU\S-1-5-21-1601795646-3932628227-3861186438-1005\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Users\Aprilbaby\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll ( )
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Aprilbaby\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2011/10/18 07:22:19 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Aprilbaby\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\Aprilbaby\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\Aprilbaby\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.5.7_0\
CHR - Extension: AVG Safe Search = C:\Users\Aprilbaby\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1829_0\
CHR - Extension: Poppit = C:\Users\Aprilbaby\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\

O1 HOSTS File: ([2011/10/11 23:28:27 | 000,437,925 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15060 more lines…
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-1601795646-3932628227-3861186438-1005\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKU\S-1-5-21-1601795646-3932628227-3861186438-1005\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Aprilbaby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E66BBB5C-E405-4B49-BD10-ADB9DE361E42}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\avgsecuritytoolbar - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{83a6b3c3-c17c-11e0-9e3f-00262244fcb0}\Shell - "" = AutoRun
O33 - MountPoints2\{83a6b3c3-c17c-11e0-9e3f-00262244fcb0}\Shell\AutoRun\command - "" = "E:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/10/19 18:37:30 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{8FEC3575-E315-477D-B614-C44CA190CA28}
[2011/10/19 18:37:08 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{A39822E9-3165-4DA0-B368-0AC71E5709B2}
[2011/10/19 09:28:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Safari
[2011/10/19 09:27:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/10/19 09:26:39 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/10/19 09:26:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/10/19 09:26:39 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/10/19 09:20:49 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/10/19 09:20:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/10/19 06:36:37 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{666A3C8D-FAB0-4784-9607-94AE74E4B717}
[2011/10/19 06:36:25 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{AF05601C-DB9E-4688-A66D-6F582735260A}
[2011/10/18 07:22:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012
[2011/10/18 07:22:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2011/10/18 07:22:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG Secure Search
[2011/10/18 07:20:28 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Roaming\AVG2012
[2011/10/18 07:19:35 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2011/10/18 06:41:16 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{99B16A26-D0A3-4E21-9E18-520137059D2D}
[2011/10/18 06:37:22 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{F0D281EE-F520-4976-91E4-755F84030C57}
[2011/10/17 11:03:27 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{BC8C366F-8455-48DA-9A71-45FD24FDA64E}
[2011/10/16 20:26:38 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{27E74C64-A7A9-4F24-AD97-80CF1671D1DD}
[2011/10/16 08:25:59 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{13CACA87-5A91-423A-82C5-8ED999E65FA8}
[2011/10/16 08:25:48 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{0DBAAD0D-8B2A-490B-B0FB-D33BF3166499}
[2011/10/15 15:58:46 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{72B865E3-5CEB-4DA6-B244-C8B8C8C6481A}
[2011/10/15 15:58:25 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{8CB25497-EA8B-45B7-92C3-16FC31F11DF1}
[2011/10/14 23:56:16 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{B1469F49-2159-4DA4-BC42-104621D75E5D}
[2011/10/14 08:54:31 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{A8167AF8-D77C-4F04-8B07-86ABAA70FC24}
[2011/10/14 08:54:08 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{D1EFACF9-81C6-48F0-A170-B410C659A674}
[2011/10/13 23:30:44 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mshtmled.dll
[2011/10/13 23:30:43 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\url.dll
[2011/10/13 23:30:43 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mshtmled.dll
[2011/10/13 23:30:42 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\url.dll
[2011/10/13 23:30:41 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieui.dll
[2011/10/13 23:30:41 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieui.dll
[2011/10/13 23:30:40 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript9.dll
[2011/10/13 23:30:40 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript.dll
[2011/10/13 23:30:40 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\jscript.dll
[2011/10/13 20:53:41 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{A381CE23-25FD-4D06-9462-98B04DE8B18E}
[2011/10/13 15:43:39 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\psisdecd.dll
[2011/10/13 15:43:39 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\psisdecd.dll
[2011/10/13 15:43:39 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\psisrndr.ax
[2011/10/13 15:43:39 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\psisrndr.ax
[2011/10/13 15:43:10 | 000,861,696 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\oleaut32.dll
[2011/10/13 15:43:10 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\oleacc.dll
[2011/10/13 08:53:18 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{0E3B98C5-03E2-46BF-AE39-EB6019F05F4F}
[2011/10/13 08:52:56 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{4B7CE5EC-C7A5-42D6-8487-8DFE76AC83D5}
[2011/10/12 20:52:31 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{EDE3CAA1-FB44-4948-AEC2-1B03DF8DD25A}
[2011/10/12 08:51:47 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{BB14BF8D-C89B-44CB-8B47-0907357C4E40}
[2011/10/12 08:51:34 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{13075DE6-18FA-4C61-9C06-ED635091524B}
[2011/10/11 20:30:01 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{24D48A2D-ABFB-4777-BA36-E58BB30F013A}
[2011/10/11 08:29:24 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{A48A06A9-54F8-4000-87FC-F21B72BF59DB}
[2011/10/11 08:29:02 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{F3B682DA-3486-4CC2-89C0-E673DCC63289}
[2011/10/11 06:34:16 | 000,000,000 | —D | C] – C:\ProgramData\boost_interprocess
[2011/10/10 20:28:35 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{EA2E2457-DC0C-4D4B-A9B8-93C9C7671886}
[2011/10/10 11:13:36 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Roaming\vlc
[2011/10/10 11:08:55 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\Ilivid Player
[2011/10/10 11:07:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\iLivid
[2011/10/10 11:06:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
[2011/10/10 11:06:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\SearchCore for Browsers
[2011/10/10 11:06:33 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\PackageAware
[2011/10/10 08:28:00 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{AA478B35-9E42-403B-AA7A-342FA3B29C81}
[2011/10/10 08:27:38 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{F6A2B644-4AD8-46D1-AA01-73D8CC8F4CAE}
[2011/10/09 20:27:13 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{E751DCA0-57A6-4F10-8104-2BD93BB2D210}
[2011/10/09 08:26:30 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{289A651A-FE57-4114-BB7F-C268960BB510}
[2011/10/09 08:26:18 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{9353D0DB-CEEC-42E4-A32E-6AC808EF9873}
[2011/10/08 19:21:25 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{8039CDDF-DC2C-4E58-A19B-ABED513F5D9E}
[2011/10/08 19:20:49 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{9ADCA91E-1E3F-4E98-8C8A-36A3AA0A9514}
[2011/10/08 06:53:27 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{D0D92CD6-1577-4452-87F9-2EFD526D2F63}
[2011/10/08 06:53:16 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{EC966E9F-5ABE-488F-B7EA-28347933102E}
[2011/10/07 15:46:26 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{C3467A29-15F3-4EE6-AA18-1D6824E02A8A}
[2011/10/07 15:45:41 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{B24F5F35-494C-4C48-BA91-D0FCEF5C5000}
[2011/10/06 21:54:15 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{F558800C-D303-4C24-9A3D-2177DBFBA0BC}
[2011/10/06 09:53:38 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{25763E40-3527-4C31-A48F-20028D0F123A}
[2011/10/06 09:53:16 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{E07EFFE5-B4E5-4F01-A28B-9AEBA653D32F}
[2011/10/05 21:52:50 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{4C877BFD-3F3D-41A5-B15F-5199AE9F7DD6}
[2011/10/05 09:52:16 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{8E2501DC-0040-43EF-BB8C-4F259CAAA723}
[2011/10/05 09:51:53 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{7ED2E6D2-B404-419F-92C0-21816CE51A06}
[2011/10/05 08:13:34 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Roaming\DivoGames
[2011/10/05 07:47:36 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\Jack of all Tribes
[2011/10/04 21:51:28 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{D08E3EA0-4C41-4AD4-B266-25C3189AFB40}
[2011/10/04 09:50:52 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{8D894C72-AEC5-4464-84D9-A92562ADAA85}
[2011/10/04 09:50:10 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{B67A0780-9F32-4F92-8725-42D2DC611239}
[2011/10/03 21:40:55 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{38FAC41B-E1A9-4256-B256-C3DA97C7241F}
[2011/10/03 09:40:19 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{9CD56C2A-F2C4-4F9B-990E-0AA0FFE56011}
[2011/10/03 09:39:58 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{7E2B504D-9A0C-4814-82F7-7CB387E5E685}
[2011/10/02 21:00:08 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{B5FBB9DC-771E-4C97-A66E-DAE6114A74D7}
[2011/10/02 08:59:34 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{CD2F02EF-8764-4F0D-8AC9-5857D0B5743F}
[2011/10/02 08:58:23 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{5B647416-1AFE-4E5F-AEDF-7EBB0DAC5AF0}
[2011/10/01 20:33:29 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{FA7E657F-0B56-4F76-8864-820B52A5447E}
[2011/10/01 20:33:16 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{77AEB45B-03EC-45ED-BE00-51654E3D4D22}
[2011/10/01 08:14:11 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{B2615CC1-743C-4132-8B22-6A5D6065FDC8}
[2011/10/01 08:13:59 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{67EF4B5D-7656-49C1-9C6B-2EC215BA947D}
[2011/09/30 11:25:15 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{CC7CD3F0-FBEA-4BE7-B50A-348C2F487D08}
[2011/09/30 11:24:38 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{5AF35E64-E6AD-467A-9DD6-9D824E5B28FD}
[2011/09/29 23:24:01 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{AD2DE320-809A-4CCA-A826-52C9F813DC40}
[2011/09/29 10:18:29 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{7937800C-25AB-4772-B7D2-C30E477AD128}
[2011/09/29 10:18:07 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{A771A052-807F-416B-8309-664FE12283B6}
[2011/09/28 22:17:42 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{9CE0006E-E8DC-4F42-9E83-234DF3675BFB}
[2011/09/28 10:14:17 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{41B61112-8388-4A38-948F-3FA261DAEF58}
[2011/09/28 10:13:55 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{14F2EFDE-77B1-427E-9B4D-24C83C3BB8EB}
[2011/09/28 08:24:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pokie Magic Games
[2011/09/27 22:13:28 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{0169D235-718A-4AC3-AC32-34B1B9AAD6A5}
[2011/09/27 09:29:35 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{E2198BFD-96AD-418A-888C-049FDB331B88}
[2011/09/27 09:29:20 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{C33DD74E-B4B9-4AAD-8200-29A5DA5E52D0}
[2011/09/26 20:44:00 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{87311947-020F-467C-8411-0EF242E6BEB8}
[2011/09/26 12:48:41 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Roaming\Unity
[2011/09/26 12:40:00 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\Unity
[2011/09/26 08:00:11 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{2C8F7C4C-6C30-41AD-AF8C-55E3D12BC8E2}
[2011/09/26 07:59:58 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{8E28FB67-52D8-46D3-A482-B4DB37B19EC4}
[2011/09/25 10:02:03 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{4FC9FD28-EE1A-403A-BDAF-B3FF68D65325}
[2011/09/25 10:01:41 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{CCF6F62E-95C8-4B25-BF1D-AD90ECCAADEA}
[2011/09/24 22:01:19 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{FD9316D1-7AA0-47F7-A5DF-D397E55560FB}
[2011/09/24 10:00:43 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{F460E338-CD44-4282-852F-9805D2243D7C}
[2011/09/24 10:00:22 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{9E7E3FDB-9C28-46B5-8C49-832A6A36E127}
[2011/09/23 21:20:41 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{538D60FA-AC86-48BE-A851-EC549A2D89C0}
[2011/09/23 09:07:27 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{279DB0E4-D2E3-4BCC-802F-5547528A88B6}
[2011/09/23 09:07:04 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{5CD89A3D-FFCB-41FF-8C1C-13012602EEAD}
[2011/09/22 17:41:11 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{CEB949E8-EF53-4C9C-A520-C5E7220D8C8D}
[2011/09/21 23:14:02 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{817DD7FF-9424-4683-B26D-F2E534A2C940}
[2011/09/21 10:30:48 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{C7584E53-0F37-4EB2-A36E-E84530B05D40}
[2011/09/21 10:30:26 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{BB4C1A75-0DCB-4127-98F7-6EA4D3365364}
[2011/09/20 22:29:59 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{EE495CDB-6A1F-4BA6-BB88-57C2176F6D6D}
[2011/09/20 22:29:37 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{C5DCAC74-8F70-4288-AA90-98A811BE3561}
[2011/09/20 10:29:08 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{45E47050-9556-442D-912A-DF1F61C28F3C}
[2011/09/20 10:28:46 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{251A7D7C-8E9F-4ED3-98DE-A27F5C9C903D}
[2011/09/19 22:28:21 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\{EFC1C333-05DE-4EA2-AE83-B238F3B28758}
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/19 21:14:00 | 000,000,898 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/19 21:14:00 | 000,000,894 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/19 21:13:08 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/19 21:13:08 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/19 21:10:41 | 000,866,730 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/10/19 21:10:41 | 000,727,720 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/10/19 21:10:41 | 000,149,422 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/10/19 21:05:42 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/10/19 21:05:38 | 3092,934,656 | -HS- | M] () – C:\hiberfil.sys
[2011/10/19 18:09:43 | 000,333,832 | —- | M] () – C:\windows\SysNative\drivers\AVG\iavichjg.avm
[2011/10/19 09:28:34 | 000,002,515 | —- | M] () – C:\Users\Aprilbaby\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/10/19 09:28:34 | 000,002,491 | —- | M] () – C:\Users\Public\Desktop\Safari.lnk
[2011/10/19 09:27:59 | 106,837,329 | —- | M] () – C:\windows\SysNative\drivers\AVG\incavi.avm
[2011/10/19 09:27:21 | 000,001,794 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/10/18 07:22:20 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2011/10/16 08:26:23 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/14 08:37:05 | 000,472,944 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2011/10/11 23:28:27 | 000,437,925 | R— | M] () – C:\windows\SysNative\drivers\etc\hosts
[2011/10/11 23:13:42 | 000,437,925 | R— | M] () – C:\windows\SysNative\drivers\etc\hosts.20111011-232827.backup
[2011/10/05 19:17:57 | 000,002,355 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2011/10/04 23:48:40 | 000,437,695 | R— | M] () – C:\windows\SysNative\drivers\etc\hosts.20111011-231342.backup
[2011/09/28 08:24:56 | 000,002,275 | —- | M] () – C:\Users\Aprilbaby\Desktop\Pyramid Pays 2 HD.lnk
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/19 09:28:34 | 000,002,515 | —- | C] () – C:\Users\Aprilbaby\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/10/19 09:28:34 | 000,002,503 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk
[2011/10/19 09:28:34 | 000,002,491 | —- | C] () – C:\Users\Public\Desktop\Safari.lnk
[2011/10/19 09:27:21 | 000,001,794 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/10/18 07:22:20 | 000,000,976 | —- | C] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2011/09/28 08:24:56 | 000,002,275 | —- | C] () – C:\Users\Aprilbaby\Desktop\Pyramid Pays 2 HD.lnk
[2010/01/10 23:20:24 | 000,000,212 | —- | C] () – C:\windows\puzzle2.dat
[2010/01/04 22:37:23 | 000,004,096 | —- | C] () – C:\windows\d3dx.dat
[2009/11/23 20:26:40 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/11/23 08:09:51 | 000,808,936 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2009/11/23 07:54:52 | 000,000,000 | —- | C] () – C:\windows\NDSTray.INI
[2009/08/28 03:05:12 | 000,982,220 | —- | C] () – C:\windows\SysWow64\igkrng500.bin
[2009/08/28 03:05:12 | 000,439,300 | —- | C] () – C:\windows\SysWow64\igcompkrng500.bin
[2009/08/28 03:05:12 | 000,134,592 | —- | C] () – C:\windows\SysWow64\igfcg500.bin
[2009/08/28 03:05:12 | 000,092,216 | —- | C] () – C:\windows\SysWow64\igfcg500m.bin
[2009/07/14 16:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/14 13:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/14 13:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/14 11:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/14 10:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/14 08:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/11 08:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat
[2009/04/28 23:37:00 | 000,028,672 | —- | C] () – C:\windows\SysWow64\SPCtl.dll

========== LOP Check ==========

[2010/10/27 00:16:35 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\AVG
[2011/10/18 07:20:28 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\AVG2012
[2011/07/03 21:02:27 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\Babylonia
[2010/11/23 19:55:16 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\Big Fish
[2011/10/05 08:13:34 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\DivoGames
[2011/05/02 21:25:34 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\DreamDale
[2010/11/18 19:21:41 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\Dreamsdwell Stories
[2010/01/27 23:47:30 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\ERS G-Studio
[2010/02/25 17:32:19 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\Facebook
[2011/01/22 23:10:36 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\FairyTale
[2010/01/04 23:26:13 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\HSA
[2011/08/03 17:13:36 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\JewelMatch2
[2011/05/02 21:07:02 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\MB3
[2009/12/19 10:22:27 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\monkey money
[2011/01/16 18:34:26 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\My Games
[2010/06/16 21:52:22 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\OpenOffice.org
[2010/08/17 13:44:39 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\Pamela
[2009/12/19 10:08:37 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\PlayFirst
[2011/05/22 21:26:09 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\Purple Patch Games
[2011/04/27 18:46:07 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\School Zone Preferences
[2011/02/08 00:02:02 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\Sky Bros
[2011/05/02 21:03:46 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\SmashFrenzy3
[2011/04/24 20:40:58 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\Spooky Runes
[2010/12/20 08:51:51 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\Toshiba
[2011/05/17 22:52:10 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\Ulead Systems
[2011/09/26 12:48:41 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\Unity
[2011/02/23 19:33:42 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\URSE Games
[2010/05/12 16:06:09 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\VTExtra
[2009/11/22 17:49:10 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\WildTangent
[2011/04/05 17:37:36 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\WinBatch
[2011/02/09 17:19:54 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\YoudaGames
[2010/03/24 20:36:12 | 000,000,000 | —D | M] – C:\Users\Aprilbaby\AppData\Roaming\ZEMNOTT
[2011/10/03 05:50:01 | 000,032,584 | —- | M] () – C:\windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:5AE41FFB
@Alternate Data Stream - 209 bytes -> C:\ProgramData\TEMP:2EA99C48
@Alternate Data Stream - 196 bytes -> C:\ProgramData\TEMP:48081133
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:71612023
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:B7FB0CA5
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:4A406CFC
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:05BF1B63

< End of report >
Hello again, this is the log from the aswMBR scan - aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-10-19 22:15:44 —————————– 22:15:44.512 OS Version: Windows x64 6.1.7601 Service Pack 1 22:15:44.512 Number of processors: 2 586 0x170A 22:15:44.512 ComputerName: APRILBABY-PC UserName: Aprilbaby 22:15:45.622 Initialize success 22:16:01.389 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 22:16:01.405 Disk 0 Vendor: TOSHIBA_ FG01 Size: 381554MB BusType: 3 22:16:01.421 Disk 0 MBR read successfully 22:16:01.421 Disk 0 MBR scan 22:16:01.421 Disk 0 Windows VISTA default MBR code 22:16:01.421 Service scanning 22:16:02.700 Modules scanning 22:16:02.700 Disk 0 trace - called modules: 22:16:02.731 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 22:16:02.747 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c3b790] 22:16:02.747 3 CLASSPNP.SYS[fffff8800178143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800474e050] 22:16:02.747 Scan finished successfully 22:16:44.543 Disk 0 MBR has been saved successfully to "C:\Users\Aprilbaby\Desktop\MBR.dat" 22:16:44.543 The log file has been saved successfully to "C:\Users\Aprilbaby\Desktop\aswMBR.txt"
I found the Extras.Txt from the OTL scan -


OTL Extras logfile created on: 10/19/2011 9:16:08 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Aprilbaby\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.84 Gb Total Physical Memory | 2.49 Gb Available Physical Memory | 64.79% Memory free
7.68 Gb Paging File | 6.26 Gb Available in Paging File | 81.52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 360.84 Gb Total Space | 280.73 Gb Free Space | 77.80% Space Free | Partition Type: NTFS

Computer Name: APRILBABY-PC | User Name: Aprilbaby | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0B7465E2-1A7E-4D21-8670-94D9C11449B8}" = AVG 2012
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1E9E8BA6-FD0B-465D-AFA2-ECE10BF095F9}" = TOSHIBA Bulletin Board
"{1FB31F44-D4D0-4D76-944A-A1A5D79FD321}" = Windows Live Family Safety
"{5349A735-7482-406F-9FE4-3BB24608479D}" = AVG 2012
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{89F7D66C-777D-473B-AA11-319C0F190EAC}" = TOSHIBA Internal Modem Region Select Utility
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9ACF3FDB-C8E6-444C-8C64-13A221F7BFFD}" = Microsoft SQL Server Native Client
"{9C98CA38-4C1A-4AC8-B55C-169497C8826B}" = Apple Mobile Device Support
"{9CD0F7D3-B67F-4BF8-8784-D73AD229FF1E}" = iTunes
"{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}" = TOSHIBA PC Health Monitor
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{B636C9B9-A3F2-4DCE-ADCC-72E095018385}" = Microsoft SQL Server VSS Writer
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C2DDF845-7107-40E8-8D2A-8719F1799570}" = TOSHIBA ReelTime
"{CEA21F20-DBF4-464C-8B81-28B8508AFDDD}" = Windows Live Family Safety
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{EC8A40B2-096A-4EA4-B11A-167F87F293A7}" = iCloud
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"AVG" = AVG 2012
"HDMI" = Intel® Graphics Media Accelerator Driver
"LTMOH" = LSI V92 MOH Application
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOSHIBA Software Modem" = TOSHIBA Software Modem

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0f6a4080-a890-4d08-873f-ca211f828a6c}" = Cool Cat Casino
"{0FB630AB-7BD8-40AE-B223-60397D57C3C9}" = Realtek WLAN Driver
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1B87C40B-A60B-4EF3-9A68-706CF4B69978}" = TOSHIBA Assist
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 26
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{50F68032-B5B7-4513-9116-C978DBD8F27A}" = DVD MovieFactory for TOSHIBA
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{5E453519-60F6-4A4D-A0BF-16663F9B3536}" = Safari
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{6DEF11C0-35FF-4160-A543-FDD336C4DAE5}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_PROHYBRIDR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP2
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{C078C299-C2C2-4110-A6EF-8D5E66C228DA}" = e-tax 2011
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CC5CEC51-BC6F-486A-B1AA-EB284551A9EB}" = Bing Bar
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2004B8D-7791-4B35-A3FA-D8CA8BB4DD81}" = Direct DiscRecorder
"{F3529665-D75E-4D6D-98F0-745C78C68E9B}" = TOSHIBA ConfigFree
"{FBE569CA-BFEB-4E57-A674-F94D938E1AEF}" = e-tax 2010
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"am-dorasavesthecrystalkingdom" = Dora Saves the Crystal Kingdom!
"am-dorascarnival2boardwalkadventure" = Dora's Carnival 2 - Boardwalk Adventure
"amg-alchemistsapprentice" = Alchemist's Apprentice
"amg-artstories" = Art Stories
"amg-babylonia" = Babylonia
"amg-goldfever" = Gold Fever
"amg-heroesofkalevala" = Heroes of Kalevala
"amg-hotelmahjongdeluxe" = Hotel Mahjong Deluxe
"amg-jackofalltribes" = Jack of all Tribes
"amg-jewelmatch2" = Jewel Match 2
"amg-monkeymoney" = Monkey Money
"amg-smashfrenzy3" = Smash Frenzy 3
"amg-totemtribe" = Totem Tribe
"amg-woodvillechronicles" = Woodville Chronicles
"amg-youdafairy" = Youda Fairy
"am-jewelquestthesleeplessstarpremiumedition" = Jewel Quest - The Sleepless Star Premium Edition
"BFGC" = Big Fish Games: Game Manager
"BFG-Puzzle Quest" = Puzzle Quest
"BFG-The Treasures Of Montezuma" = The Treasures Of Montezuma
"BFG-The Treasures of Montezuma 2" = The Treasures of Montezuma 2
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP2
"Free WMA to MP3 Converter_is1" = Free WMA to MP3 Converter 1.16
"Google Chrome" = Google Chrome
"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"InstallShield_{1E9E8BA6-FD0B-465D-AFA2-ECE10BF095F9}" = TOSHIBA Bulletin Board
"InstallShield_{50F68032-B5B7-4513-9116-C978DBD8F27A}" = DVD MovieFactory for TOSHIBA
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"InstallShield_{89F7D66C-777D-473B-AA11-319C0F190EAC}" = TOSHIBA Internal Modem Region Select Utility
"InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"InstallShield_{C2DDF845-7107-40E8-8D2A-8719F1799570}" = TOSHIBA ReelTime
"InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"InstallShield_{F2004B8D-7791-4B35-A3FA-D8CA8BB4DD81}" = Direct DiscRecorder
"InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"OpenAL" = OpenAL
"PROHYBRIDR" = 2007 Microsoft Office system
"Pyramid Pays 2 HD_is1" = Pyramid Pays 2 HD v.9.26
"Sandlot Games Client Services 1.2.2_is1" = Sandlot Games Client Services 1.2.2
"Searchqu 406 MediaBar" = Windows iLivid Toolbar
"WildTangent toshiba Master Uninstall" = WildTangent Games
"WinLiveSuite" = Windows Live Essentials

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/19/2011 3:52:43 AM | Computer Name = Aprilbaby-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 10/19/2011 3:52:43 AM | Computer Name = Aprilbaby-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1045

Error - 10/19/2011 3:52:43 AM | Computer Name = Aprilbaby-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1045

Error - 10/19/2011 3:52:44 AM | Computer Name = Aprilbaby-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 10/19/2011 3:52:44 AM | Computer Name = Aprilbaby-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2340

Error - 10/19/2011 3:52:44 AM | Computer Name = Aprilbaby-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2340

Error - 10/19/2011 5:51:07 AM | Computer Name = Aprilbaby-PC | Source = TOSHIBA Service Station | ID = 0
Description = Cannot start service TMachInfo on computer '.'.

Error - 10/19/2011 5:51:07 AM | Computer Name = Aprilbaby-PC | Source = TOSHIBA Service Station | ID = 0
Description = TSS Load: could not communicate with TMachInfo service

Error - 10/19/2011 6:07:30 AM | Computer Name = Aprilbaby-PC | Source = TOSHIBA Service Station | ID = 0
Description = Cannot start service TMachInfo on computer '.'.

Error - 10/19/2011 6:07:30 AM | Computer Name = Aprilbaby-PC | Source = TOSHIBA Service Station | ID = 0
Description = TSS Load: could not communicate with TMachInfo service

[ Media Center Events ]
Error - 12/25/2009 8:08:52 PM | Computer Name = Aprilbaby-PC | Source = MCUpdate | ID = 0
Description = 11:08:52 AM - Error connecting to the internet. 11:08:52 AM - Unable
to contact server..

Error - 12/25/2009 8:08:59 PM | Computer Name = Aprilbaby-PC | Source = MCUpdate | ID = 0
Description = 11:08:57 AM - Error connecting to the internet. 11:08:57 AM - Unable
to contact server..

Error - 1/2/2010 9:52:35 PM | Computer Name = Aprilbaby-PC | Source = MCUpdate | ID = 0
Description = 12:52:34 PM - Error connecting to the internet. 12:52:34 PM - Unable
to contact server..

Error - 1/2/2010 9:52:45 PM | Computer Name = Aprilbaby-PC | Source = MCUpdate | ID = 0
Description = 12:52:40 PM - Error connecting to the internet. 12:52:40 PM - Unable
to contact server..

Error - 1/3/2010 12:16:57 AM | Computer Name = Aprilbaby-PC | Source = MCUpdate | ID = 0
Description = 3:16:52 PM - Error connecting to the internet. 3:16:55 PM - Unable
to contact server..

Error - 1/3/2010 12:17:04 AM | Computer Name = Aprilbaby-PC | Source = MCUpdate | ID = 0
Description = 3:17:02 PM - Error connecting to the internet. 3:17:02 PM - Unable
to contact server..

Error - 1/3/2010 1:17:09 AM | Computer Name = Aprilbaby-PC | Source = MCUpdate | ID = 0
Description = 4:17:09 PM - Error connecting to the internet. 4:17:09 PM - Unable
to contact server..

Error - 1/3/2010 1:17:16 AM | Computer Name = Aprilbaby-PC | Source = MCUpdate | ID = 0
Description = 4:17:15 PM - Error connecting to the internet. 4:17:15 PM - Unable
to contact server..

Error - 1/3/2010 2:17:22 AM | Computer Name = Aprilbaby-PC | Source = MCUpdate | ID = 0
Description = 5:17:22 PM - Error connecting to the internet. 5:17:22 PM - Unable
to contact server..

Error - 1/3/2010 2:17:28 AM | Computer Name = Aprilbaby-PC | Source = MCUpdate | ID = 0
Description = 5:17:27 PM - Error connecting to the internet. 5:17:27 PM - Unable
to contact server..

[ System Events ]
Error - 10/18/2011 6:29:13 PM | Computer Name = Aprilbaby-PC | Source = DCOM | ID = 10010
Description =

Error - 10/18/2011 6:30:37 PM | Computer Name = Aprilbaby-PC | Source = Service Control Manager | ID = 7000
Description = The ABP_InstallCheckerService service failed to start due to the following
error: %%2

Error - 10/18/2011 6:40:35 PM | Computer Name = Aprilbaby-PC | Source = bowser | ID = 8003
Description =

Error - 10/19/2011 1:40:39 AM | Computer Name = Aprilbaby-PC | Source = bowser | ID = 8003
Description =

Error - 10/19/2011 3:16:42 AM | Computer Name = Aprilbaby-PC | Source = bowser | ID = 8003
Description =

Error - 10/19/2011 4:52:40 AM | Computer Name = Aprilbaby-PC | Source = bowser | ID = 8003
Description =

Error - 10/19/2011 5:49:16 AM | Computer Name = Aprilbaby-PC | Source = Service Control Manager | ID = 7000
Description = The ABP_InstallCheckerService service failed to start due to the following
error: %%2

Error - 10/19/2011 5:52:31 AM | Computer Name = Aprilbaby-PC | Source = bowser | ID = 8003
Description =

Error - 10/19/2011 6:05:47 AM | Computer Name = Aprilbaby-PC | Source = Service Control Manager | ID = 7000
Description = The ABP_InstallCheckerService service failed to start due to the following
error: %%2

Error - 10/19/2011 6:16:31 AM | Computer Name = Aprilbaby-PC | Source = bowser | ID = 8003
Description =


< End of report >
Hi, I have also noticed that Internet Explorer is not working …whenever I try to open it I get a message ' Internet explorer cannot show web page.' searchqu opens whenever I click on Google Chrome. Hope you can help.
Hello Julie A,

Please do the following:

Hold down the Windows key and press R to open a run box
type the following text into the run box

appwiz.cpl

This will open your Programs And Features
A list of installed programs will populate
Remove the following programs:

Windows iLivid Toolbar
==================
Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKU\S-1-5-21-1601795646-3932628227-3861186438-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 44 45 6C 9C 89 4F CC 01 [binary data]
    O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4:64bit: - HKLM..\Run: [] File not found
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - Winlogon\Notify\igfxcui: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
    O33 - MountPoints2\{83a6b3c3-c17c-11e0-9e3f-00262244fcb0}\Shell - "" = AutoRun
    O33 - MountPoints2\{83a6b3c3-c17c-11e0-9e3f-00262244fcb0}\Shell\AutoRun\command - "" = "E:\WD SmartWare.exe" autoplay=true
    [2011/10/10 11:08:55 | 000,000,000 | —D | C] – C:\Users\Aprilbaby\AppData\Local\Ilivid Player
    [2011/10/10 11:07:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\iLivid
    [2011/10/10 11:06:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
    [2011/10/10 11:06:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\SearchCore for Browsers
    @Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:5AE41FFB
    @Alternate Data Stream - 209 bytes -> C:\ProgramData\TEMP:2EA99C48
    @Alternate Data Stream - 196 bytes -> C:\ProgramData\TEMP:48081133
    @Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:0B4227B4
    @Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:71612023
    @Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:B7FB0CA5
    @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:4A406CFC
    @Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:05BF1B63 
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
======================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log
3. How is the computer behaving?
Hi, I followed your instructions, when I went to uninstall 'windows ilivid toolbar' a message said it had already been uninstalled. All processes killed ========== OTL ========== HKU\S-1-5-21-1601795646-3932628227-3861186438-1005\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully! 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{83a6b3c3-c17c-11e0-9e3f-00262244fcb0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83a6b3c3-c17c-11e0-9e3f-00262244fcb0}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{83a6b3c3-c17c-11e0-9e3f-00262244fcb0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83a6b3c3-c17c-11e0-9e3f-00262244fcb0}\ not found. File "E:\WD SmartWare.exe" autoplay=true not found. C:\Users\Aprilbaby\AppData\Local\Ilivid Player folder moved successfully. C:\Program Files (x86)\iLivid\imageformats folder moved successfully. C:\Program Files (x86)\iLivid folder moved successfully. C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr folder moved successfully. C:\Program Files (x86)\Windows iLivid Toolbar folder moved successfully. C:\Program Files (x86)\SearchCore for Browsers\SearchCore for Browsers folder moved successfully. ADS C:\ProgramData\TEMP:5AE41FFB deleted successfully. ADS C:\ProgramData\TEMP:2EA99C48 deleted successfully. ADS C:\ProgramData\TEMP:48081133 deleted successfully. ADS C:\ProgramData\TEMP:0B4227B4 deleted successfully. ADS C:\ProgramData\TEMP:71612023 deleted successfully. ADS C:\ProgramData\TEMP:B7FB0CA5 deleted successfully. ADS C:\ProgramData\TEMP:4A406CFC deleted successfully. ADS C:\ProgramData\TEMP:05BF1B63 deleted successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users User: Aprilbaby ->Temp folder emptied: 437016068 bytes ->Temporary Internet Files folder emptied: 5173550621 bytes ->Java cache emptied: 327925 bytes ->Google Chrome cache emptied: 373127810 bytes ->Apple Safari cache emptied: 15952896 bytes ->Flash cache emptied: 64000 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 199790360 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 5,913.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 10212011_070211 Files\Folders moved on Reboot… C:\Users\Aprilbaby\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File move failed. C:\windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. Registry entries deleted on Reboot.. Internet Explorer still wont open and searchqu is still there when I open google chrome.
Hello Julie A,

Open Chrome and click on the little wrench up on the top right , then click on Options > Manage Search Engines and if Searchq is listed you can right click and delete it.
====================
NEXT


Download and Run ComboFix
  • Please download ComboFix from one of the following links.

    Link 1.

    Link 2.

    **IMPORTANT !!! Save ComboFix.exe to your Desktop**
  • Please disable any Antivirus or Firewall you have active, as shown in this topic. Please close all open application windows.
  • Double click on ComboFix.exe & follow the prompts
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console
[external image: Posted Image]
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper

====================
Please include in your next reply:
1. Any problem executing the instructions?
2. Combofix log
3. How is the computer behaving?
ComboFix 11-10-20.08 - Aprilbaby 21/10/2011 17:23:57.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.3933.2207 [GMT 11:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\xp c:\programdata\xp\EBLib.dll c:\programdata\xp\TPwSav.sys c:\windows\security\Database\tmp.edb . . ((((((((((((((((((((((((( Files Created from 2011-09-21 to 2011-10-21 ))))))))))))))))))))))))))))))) . . 2011-10-21 06:41 . 2011-10-21 06:41 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-10-20 21:24 . 2011-09-20 22:00 9049936 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F2E1C5ED-EF2E-4B9A-BB8D-F03EFF6B2C4F}\mpengine.dll 2011-10-20 20:02 . 2011-10-20 20:02 ——– d—–w- C:\_OTL 2011-10-19 12:34 . 2011-09-06 19:38 301912 —-a-w- c:\windows\system32\drivers\aswSP.sys 2011-10-19 12:34 . 2011-09-06 19:36 24408 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-10-19 12:34 . 2011-09-06 19:36 42328 —-a-w- c:\windows\system32\drivers\aswRdr.sys 2011-10-19 12:34 . 2011-09-06 19:36 58200 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2011-10-19 12:34 . 2011-09-06 19:38 601944 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2011-10-19 12:34 . 2011-09-06 19:45 254400 —-a-w- c:\windows\system32\aswBoot.exe 2011-10-19 12:34 . 2011-09-06 19:36 65368 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2011-10-19 12:34 . 2011-09-06 19:45 41184 —-a-w- c:\windows\avastSS.scr 2011-10-19 12:34 . 2011-09-06 19:45 199304 —-a-w- c:\windows\SysWow64\aswBoot.exe 2011-10-19 12:34 . 2011-10-19 12:34 ——– d—–w- c:\programdata\AVAST Software 2011-10-19 12:34 . 2011-10-19 12:34 ——– d—–w- c:\program files\AVAST Software 2011-10-19 11:57 . 2011-10-19 11:57 ——– d—–w- c:\windows\system32\Macromed 2011-10-18 22:28 . 2011-10-18 22:28 ——– d—–w- c:\program files (x86)\Safari 2011-10-18 22:26 . 2011-10-18 22:27 ——– d—–w- c:\program files\iTunes 2011-10-18 22:26 . 2011-10-18 22:27 ——– d—–w- c:\program files (x86)\iTunes 2011-10-18 22:26 . 2011-10-18 22:26 ——– d—–w- c:\program files\iPod 2011-10-18 22:20 . 2011-10-18 22:20 ——– d—–w- c:\program files\Bonjour 2011-10-18 22:20 . 2011-10-18 22:20 ——– d—–w- c:\program files (x86)\Bonjour 2011-10-17 20:22 . 2011-10-17 20:22 ——– d—–w- c:\program files (x86)\Common Files\AVG Secure Search 2011-10-17 20:22 . 2011-10-17 20:22 ——– d—–w- c:\program files (x86)\AVG Secure Search 2011-10-17 20:20 . 2011-10-17 20:20 ——– d—–w- c:\users\Aprilbaby\AppData\Roaming\AVG2012 2011-10-17 20:19 . 2011-10-17 20:38 ——– d—–w- c:\programdata\AVG2012 2011-10-13 04:45 . 2011-09-06 03:03 3138048 —-a-w- c:\windows\system32\win32k.sys 2011-10-13 04:43 . 2011-08-17 05:26 613888 —-a-w- c:\windows\system32\psisdecd.dll 2011-10-13 04:43 . 2011-08-17 05:25 108032 —-a-w- c:\windows\system32\psisrndr.ax 2011-10-13 04:43 . 2011-08-17 04:24 465408 —-a-w- c:\windows\SysWow64\psisdecd.dll 2011-10-13 04:43 . 2011-08-17 04:19 75776 —-a-w- c:\windows\SysWow64\psisrndr.ax 2011-10-13 04:43 . 2011-08-27 05:37 861696 —-a-w- c:\windows\system32\oleaut32.dll 2011-10-13 04:43 . 2011-08-27 05:37 331776 —-a-w- c:\windows\system32\oleacc.dll 2011-10-13 04:43 . 2011-08-27 04:26 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll 2011-10-13 04:43 . 2011-08-27 04:26 233472 —-a-w- c:\windows\SysWow64\oleacc.dll 2011-10-10 19:34 . 2011-10-10 19:34 ——– d—–w- c:\programdata\boost_interprocess 2011-10-10 00:13 . 2011-10-10 00:14 ——– d—–w- c:\users\Aprilbaby\AppData\Roaming\vlc 2011-10-10 00:06 . 2011-10-20 20:02 ——– d—–w- c:\program files (x86)\SearchCore for Browsers 2011-10-10 00:06 . 2011-10-10 00:06 ——– d—–w- c:\users\Aprilbaby\AppData\Local\PackageAware 2011-10-04 21:13 . 2011-10-04 21:13 ——– d—–w- c:\users\Aprilbaby\AppData\Roaming\DivoGames 2011-10-04 20:47 . 2011-10-04 20:54 ——– d—–w- c:\users\Aprilbaby\Jack of all Tribes 2011-09-26 01:48 . 2011-09-26 01:48 ——– d—–w- c:\users\Aprilbaby\AppData\Roaming\Unity 2011-09-26 01:40 . 2011-09-26 20:34 ——– d—–w- c:\users\Aprilbaby\AppData\Local\Unity . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-10-15 21:26 . 2011-06-03 22:42 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-09-12 19:30 . 2011-09-12 19:30 37456 —-a-w- c:\windows\system32\drivers\avgrkx64.sys 2011-08-31 07:00 . 2011-03-15 13:25 25416 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-08-30 12:05 . 2011-08-30 12:05 96104 —-a-w- c:\windows\system32\dns-sd.exe 2011-08-30 12:05 . 2011-08-30 12:05 85864 —-a-w- c:\windows\system32\dnssd.dll 2011-08-30 12:05 . 2011-08-30 12:05 61288 —-a-w- c:\windows\system32\jdns_sd.dll 2011-08-30 12:05 . 2011-08-30 12:05 212840 —-a-w- c:\windows\system32\dnssdX.dll 2011-08-30 12:05 . 2011-08-30 12:05 83816 —-a-w- c:\windows\SysWow64\dns-sd.exe 2011-08-30 12:05 . 2011-08-30 12:05 73064 —-a-w- c:\windows\SysWow64\dnssd.dll 2011-08-30 12:05 . 2011-08-30 12:05 50536 —-a-w- c:\windows\SysWow64\jdns_sd.dll 2011-08-30 12:05 . 2011-08-30 12:05 178536 —-a-w- c:\windows\SysWow64\dnssdX.dll 2011-08-15 09:23 . 2011-08-15 09:23 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-08-07 19:08 . 2011-08-07 19:08 46672 —-a-w- c:\windows\system32\drivers\avgmfx64.sys 2011-08-02 06:38 . 2011-08-02 06:38 51712 —-a-w- c:\windows\system32\drivers\usbaapl64.sys 2011-08-02 06:38 . 2011-08-02 06:38 4517664 —-a-w- c:\windows\system32\usbaaplrc.dll 2011-07-29 13:23 . 2011-07-29 13:23 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2011-07-29 13:23 . 2011-07-29 13:23 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2011-07-29 13:23 . 2011-07-29 13:23 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2011-07-29 13:23 . 2011-07-29 13:23 161792 —-a-w- c:\windows\SysWow64\msls31.dll 2011-07-29 13:23 . 2011-07-29 13:23 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2011-07-29 13:23 . 2011-07-29 13:23 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll 2011-07-29 13:23 . 2011-07-29 13:23 74752 —-a-w- c:\windows\SysWow64\iesetup.dll 2011-07-29 13:23 . 2011-07-29 13:23 63488 —-a-w- c:\windows\SysWow64\tdc.ocx 2011-07-29 13:23 . 2011-07-29 13:23 367104 —-a-w- c:\windows\SysWow64\html.iec 2011-07-29 13:23 . 2011-07-29 13:23 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll 2011-07-29 13:23 . 2011-07-29 13:23 152064 —-a-w- c:\windows\SysWow64\wextract.exe 2011-07-29 13:23 . 2011-07-29 13:23 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2011-07-29 13:23 . 2011-07-29 13:23 1427456 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2011-07-29 13:23 . 2011-07-29 13:23 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2011-07-29 13:23 . 2011-07-29 13:23 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2011-07-29 13:23 . 2011-07-29 13:23 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2011-07-29 13:23 . 2011-07-29 13:23 222208 —-a-w- c:\windows\system32\msls31.dll 2011-07-29 13:23 . 2011-07-29 13:23 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2011-07-29 13:23 . 2011-07-29 13:23 11776 —-a-w- c:\windows\SysWow64\mshta.exe 2011-07-29 13:23 . 2011-07-29 13:23 101888 —-a-w- c:\windows\SysWow64\admparse.dll 2011-07-29 13:23 . 2011-07-29 13:23 49664 —-a-w- c:\windows\system32\imgutil.dll 2011-07-29 13:23 . 2011-07-29 13:23 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2011-07-29 13:23 . 2011-07-29 13:23 12288 —-a-w- c:\windows\system32\mshta.exe 2011-07-29 13:23 . 2011-07-29 13:23 114176 —-a-w- c:\windows\system32\admparse.dll 2011-07-29 13:23 . 2011-07-29 13:23 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2011-07-29 13:23 . 2011-07-29 13:23 85504 —-a-w- c:\windows\system32\iesetup.dll 2011-07-29 13:23 . 2011-07-29 13:23 76800 —-a-w- c:\windows\system32\tdc.ocx 2011-07-29 13:23 . 2011-07-29 13:23 48640 —-a-w- c:\windows\system32\mshtmler.dll 2011-07-29 13:23 . 2011-07-29 13:23 448512 —-a-w- c:\windows\system32\html.iec 2011-07-29 13:23 . 2011-07-29 13:23 30720 —-a-w- c:\windows\system32\licmgr10.dll 2011-07-29 13:23 . 2011-07-29 13:23 160256 —-a-w- c:\windows\system32\wextract.exe 2011-07-29 13:23 . 2011-07-29 13:23 1492992 —-a-w- c:\windows\system32\inetcpl.cpl 2011-07-29 13:23 . 2011-07-29 13:23 135168 —-a-w- c:\windows\system32\IEAdvpack.dll 2011-07-29 13:23 . 2011-07-29 13:23 111616 —-a-w- c:\windows\system32\iesysprep.dll 2011-07-29 13:23 . 2011-07-29 13:23 603648 —-a-w- c:\windows\system32\vbscript.dll 2011-07-29 13:23 . 2011-07-29 13:23 165888 —-a-w- c:\windows\system32\iexpress.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-08-31 2532680] . [HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}] . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}] 2011-08-31 23:16 2532680 —-a-w- c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-08-31 2532680] . [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-22 39408] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-06-15 15141768] "msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-08-11 2446648] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2010-07-01 1295224] "SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2009-07-10 352256] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-01-14 34088] "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2009-06-02 423936] "AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2011-09-22 2404704] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-26 59240] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416] . c:\users\Aprilbaby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.2.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 ABP_InstallCheckerService;ABP_InstallCheckerService;c:\users\APRILB~1\AppData\Local\Temp\ABP_InstallChecker.exe [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 135664] R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-08-31 1025352] R3 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-09-11 5265248] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-14 183560] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 135664] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x] R4 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [2009-07-18 181616] R4 ConfigFree Gadget Service;ConfigFree Gadget Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [2009-07-15 42368] R4 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448] R4 RSELSVC;TOSHIBA Modem region select service;c:\program files\TOSHIBA\rselect\RSelSvc.exe [2009-07-07 65904] R4 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] R4 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-07-01 51576] R4 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-08-10 258928] R4 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-04 137560] R4 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-04 826224] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x] S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x] S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-01 192776] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x] S2 vToolbarUpdater;vToolbarUpdater;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [2011-10-17 246600] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}] 2010-11-20 12:17 302592 —-a-w- c:\windows\System32\cmd.exe . Contents of the 'Scheduled Tasks' folder . 2011-10-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 04:00] . 2011-10-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-29 04:00] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-09-06 19:45 134384 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 709976] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-24 11780712] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-02 365592] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-02 165912] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-02 387608] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://googlechrome.com/ mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSAU&bmod=TSAU mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 192.168.2.1 Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll . - - - - ORPHANS REMOVED - - - - . Notify-igfxcui - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-UnityWebPlayer - c:\users\Aprilbaby\AppData\Local\Unity\WebPlayer\Uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:00000009 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\program files\AVAST Software\Avast\defs\11102002\Sf.bin . *********************************************************************** Completion time: 2011-10-21 18:21:46 - machine was rebooted ComboFix-quarantined-files.txt 2011-10-21 07:21 . Pre-Run: 311,102,754,816 bytes free Post-Run: 310,715,232,256 bytes free . - - End Of File - - BCB13FA6F9E14688FC8ACBF5F8927FC3 Searchqu is still on my computer, and I cannot open any browser or Anti-virus progams unless I 'open as administrator'. When attempting to open these programs I get a message 'Illegal operation on a registry key that has been marked for deletion'. Over the last two days I have had a message pop up from AVG - about Internet Explorer using a large amount of memory.
Ok, I rebooted my computer… all programs appear to be working normally again, except Internet explorer which wont open - 'cannot find server' and Google chrome is still opening with searchqu. What happens next?
Hello Julie A,

Is AVG Anti-Virus your main anti-Virus program? the reason I ask is because I also see Avast Anti-Virus entries in your log which could be leftovers.



Download and Run SystemLook

Please download SystemLook from the link below and save it to your Desktop.
64bit
http://jpshortstuff.247Fixes.com/SystemLook_x64.exe
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    searchqu
    :folderfind
    searchqu
    :regfind
    searchqu
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt



===============================
NEXT

Please go to one of the below sites to scan the following files:

Virus Total
jotti.org
Kaspersky Virus File Scanner


click on Browse, and upload the following file for analysis:

c:\windows\system32\SetIEInstalledDate.exe
c:\windows\system32\IEAdvpack.dll



Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.
===============================
NEXT

ComboFix - CFScript

This script is for this user and computer ONLY! Using this tool incorrectly could cause problems with your operating system… preventing it from ever starting again!
You will not have Internet access when you execute ComboFix. All open windows will need to be closed!

Open notepad and copy/paste the text in the quotebox below into it:

Folder::
c:\program files (x86)\SearchCore for Browsers

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

=======================
Please include in your next reply:
1. Any problem executing the instructions?
2. SystemLook.txt
3. Virus Total results
4. combofix log
5. How is the computer behaving?
Hi Gail I had AVG as my main Anti-virus program but recently downloaded Avast also. Here is the log from Systemlook - SystemLook 30.07.11 by jpshortstuff Log created at 06:15 on 23/10/2011 by Aprilbaby Administrator - Elevation successful ========== filefind ========== Searching for "searchqu" No files found. ========== folderfind ========== Searching for "searchqu" No folders found. ========== regfind ========== Searching for "searchqu" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] "URL"="http://www.searchqu.com/web?src=ieb&appid=169&systemid=406&sr=0&q={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] "SuggestionsURL_JSON"="http://www.searchqu.com/suggest.php?src=ieb&appid=169&systemid=406&qu={searchTerms}&ft=json" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] "URL"="http://www.searchqu.com/web?src=ieb&appid=169&systemid=406&sr=0&q={searchTerms}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] "SuggestionsURL_JSON"="http://www.searchqu.com/suggest.php?src=ieb&appid=169&systemid=406&qu={searchTerms}&ft=json" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] "URL"="http://www.searchqu.com/web?src=ieb&appid=169&systemid=406&sr=0&q={searchTerms}" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] "SuggestionsURL_JSON"="http://www.searchqu.com/suggest.php?src=ieb&appid=169&systemid=406&qu={searchTerms}&ft=json" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SearchquMediaBar_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SearchquMediaBar_RASMANCS] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SetupDataMngr_searchqu_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SetupDataMngr_searchqu_RASMANCS] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}] @="ISearchQueryHelper" [HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] "URL"="http://www.searchqu.com/web?src=ieb&appid=169&systemid=406&sr=0&q={searchTerms}" [HKEY_USERS\S-1-5-21-1601795646-3932628227-3861186438-1005\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] "SuggestionsURL_JSON"="http://www.searchqu.com/suggest.php?src=ieb&appid=169&systemid=406&qu={searchTerms}&ft=json" -= EOF =-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI