This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

high memory usage - suspect svchost.exe? [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

It appears there are multiple versions of svchost.exe running and Norton 360 reports on occasion high memory usage by this process

Here are the text files:

OTL logfile created on: 1/13/2012 12:39:15 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Duane\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1021.87 Mb Total Physical Memory | 201.50 Mb Available Physical Memory | 19.72% Memory free
2.26 Gb Paging File | 0.79 Gb Available in Paging File | 35.22% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 204.21 Gb Free Space | 68.51% Space Free | Partition Type: NTFS

Computer Name: SHANNONOCONNER | User Name: Duane | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Duane\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe (Uniblue Systems Limited)
PRC - C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe (Uniblue Systems Limited)
PRC - C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE (CANON INC.)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Uniblue\RegistryBooster\locale\en\en.dll ()
MOD - C:\Program Files\Uniblue\RegistryBooster\InstallerExtensions.dll ()
MOD - C:\Program Files\Uniblue\RegistryBooster\cwebpage.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()


========== Win32 Services (SafeList) ==========

SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (N360) – C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120112.034\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120112.034\NAVENG.SYS (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20120112.002\IDSvix86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20111223.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\N360\0501000.01D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\N360\0501000.01D\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\system32\drivers\N360\0501000.01D\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\N360\0501000.01D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymDS) – C:\Windows\system32\drivers\N360\0501000.01D\SYMDS.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\N360\0501000.01D\Ironx86.SYS (Symantec Corporation)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (R5U870FLx86) – C:\Windows\System32\drivers\R5U870FLx86.sys (Ricoh)
DRV - (R5U870FUx86) – C:\Windows\System32\drivers\R5U870FUx86.sys (Ricoh)
DRV - (HBtnKey) – C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://att.my.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 50 89 D0 EB AE BA CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 06 90 AC 10 51 77 11 41 BB D5 A9 4C 86 3C 2E B1 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/12/30 17:36:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2012/01/05 08:40:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn_2011_7_4_3 [2012/01/13 11:39:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

[2012/01/13 07:29:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/09/18 08:32:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/15 22:43:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/12/14 17:28:20 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2010/05/10 09:55:35 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2009/11/19 15:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/11/10 05:54:13 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 15:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2006/09/18 15:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE (CANON INC.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKCU..\Run: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/C/B…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Insta…hpdetect118.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7B0BDAFF-C44F-439D-8D11-2E15C3F35CB7}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = comfile] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/01/13 12:19:08 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Roaming\Uniblue
[2012/01/13 12:18:55 | 000,000,000 | -H-D | C] – C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2012/01/13 12:18:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
[2012/01/13 12:18:54 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2012/01/13 12:18:09 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\PackageAware
[2012/01/13 07:01:43 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\Adobe
[2012/01/11 18:44:42 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\NPE
[2012/01/11 11:12:48 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\shannon pics
[2012/01/11 06:14:40 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciseq.dll
[2012/01/11 06:14:31 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\packager.dll
[2012/01/11 06:14:27 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2012/01/11 06:14:16 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2012/01/11 06:14:15 | 000,497,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2012/01/09 00:08:32 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\ceiva
[2012/01/05 08:26:09 | 000,000,000 | —D | C] – C:\bf6cf6c4002208f661226346e13c06b4
[2012/01/01 23:00:11 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\CrashDumps
[2012/01/01 22:37:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/01/01 22:34:59 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/01/01 22:34:32 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/01/01 22:16:27 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2012/01/01 22:10:11 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2012/01/01 22:09:55 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/01/01 17:12:09 | 000,331,384 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\symtdiv.sys
[2012/01/01 17:12:09 | 000,296,568 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\symnets.sys
[2012/01/01 17:12:08 | 000,744,568 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\SymEFA.sys
[2012/01/01 17:12:08 | 000,516,216 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\srtsp.sys
[2012/01/01 17:12:08 | 000,340,088 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\SymDS.sys
[2012/01/01 17:12:08 | 000,136,312 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\Ironx86.sys
[2012/01/01 17:12:08 | 000,050,168 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\N360\0501000.01D\srtspx.sys
[2012/01/01 17:11:39 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\N360\0501000.01D
[2012/01/01 15:14:16 | 000,000,000 | —D | C] – C:\Program Files\Hewlett-Packard
[2012/01/01 15:12:38 | 000,000,000 | —D | C] – C:\Program Files\HP
[2011/12/30 22:26:39 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\johns pics 2
[2011/12/30 21:56:04 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\eds pics
[2011/12/30 10:21:04 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\johns pics
[2011/12/30 09:56:01 | 000,000,000 | —D | C] – C:\Users\Duane\Desktop\michaels pics
[2011/12/27 21:21:09 | 000,000,000 | —D | C] – C:\Users\Duane\Documents\Symantec
[2011/12/27 21:15:53 | 000,106,928 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2011/12/27 21:15:45 | 000,126,584 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2011/12/27 21:15:35 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2011/12/27 21:15:35 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/12/27 21:14:36 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\N360
[2011/12/27 21:14:32 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
[2011/12/27 21:14:32 | 000,000,000 | —D | C] – C:\Program Files\Norton 360
[2011/12/27 21:14:18 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2011/12/27 21:14:18 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2011/12/27 19:27:11 | 000,114,688 | —- | C] (RICOH) – C:\Windows\System32\RicohMediadriverVer.dll
[2011/12/27 19:27:10 | 000,090,112 | —- | C] (Sony Corporation) – C:\Windows\System32\snymsico.dll
[2011/12/27 19:27:10 | 000,048,128 | —- | C] (REDC) – C:\Windows\System32\drivers\rimmptsk.sys
[2011/12/27 19:27:10 | 000,044,544 | —- | C] (REDC) – C:\Windows\System32\drivers\rimsptsk.sys
[2011/12/27 19:27:10 | 000,038,400 | —- | C] (REDC) – C:\Windows\System32\drivers\rixdptsk.sys
[2011/12/27 19:27:09 | 000,172,032 | —- | C] (Ricoh Company,Ltd) – C:\Windows\System32\rixdicon.dll
[2011/12/27 18:51:26 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\ElevatedDiagnostics
[2011/12/27 17:58:23 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
[2011/12/27 17:58:22 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2011/12/19 08:42:19 | 001,393,736 | —- | C] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Users\Duane\gotomypc_626.exe
[2011/12/16 18:01:03 | 000,414,368 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/12/14 20:35:30 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Roaming\Google
[2011/12/14 20:31:16 | 000,000,000 | —D | C] – C:\Program Files\Google
[2011/12/14 20:30:23 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\Apps
[2011/12/14 20:30:22 | 000,000,000 | —D | C] – C:\Users\Duane\AppData\Local\Deployment
[2011/12/14 19:29:24 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/12/14 19:29:24 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/12/14 19:29:24 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/12/14 19:29:23 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/12/14 19:29:23 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/12/14 19:29:23 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/12/14 19:29:23 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/12/14 19:29:23 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/12/14 19:29:22 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/12/14 19:29:22 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/12/14 19:29:22 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/12/14 19:29:22 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/12/14 19:29:22 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/12/14 19:29:22 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/12/14 19:29:22 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/12/14 19:29:22 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/12/14 19:29:22 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/12/14 19:29:21 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/12/14 19:29:21 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/12/14 19:29:21 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/12/14 19:29:21 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/12/14 19:29:21 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/12/14 19:29:21 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/12/14 19:29:21 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/12/14 19:29:20 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/12/14 19:29:20 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/12/14 19:29:20 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/12/14 19:29:20 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/12/14 19:29:20 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/12/14 19:29:19 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/12/14 19:29:19 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/12/14 19:29:19 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/12/14 19:29:19 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/12/14 19:29:19 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/12/14 19:29:19 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/12/14 19:29:19 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/12/14 19:29:18 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/12/14 17:29:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/12/14 17:28:03 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/12/14 17:28:03 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/12/14 17:28:03 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/12/14 16:58:08 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/12/14 16:58:07 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/12/14 16:58:04 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2011/12/14 16:58:04 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2011/12/14 16:58:04 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2011/12/14 16:58:04 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2011/12/14 16:57:54 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/12/14 16:57:00 | 002,043,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/12/14 16:56:54 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2011/12/14 16:56:47 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/12/14 16:56:21 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2011/12/14 16:56:21 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll

========== Files - Modified Within 30 Days ==========

[2012/01/13 12:36:02 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/13 12:19:21 | 000,000,332 | —- | M] () – C:\Windows\tasks\RegistryBooster.job
[2012/01/13 12:19:01 | 000,001,593 | —- | M] () – C:\Users\Duane\Desktop\Uniblue RegistryBooster.lnk
[2012/01/13 12:19:01 | 000,001,583 | —- | M] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Uniblue RegistryBooster.lnk
[2012/01/13 11:42:08 | 000,065,684 | —- | M] () – C:\ProgramData\nvModes.001
[2012/01/13 11:41:42 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/13 11:39:49 | 000,004,176 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/13 11:39:49 | 000,004,176 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/13 11:39:22 | 000,371,864 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/01/13 11:39:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/13 11:38:55 | 1072,283,648 | -HS- | M] () – C:\hiberfil.sys
[2012/01/13 07:53:10 | 000,000,866 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/12 19:53:56 | 000,001,726 | -H– | M] () – C:\Users\Duane\Documents\Default.rdp
[2012/01/12 11:51:18 | 244,283,466 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/01/11 20:55:22 | 000,116,527 | —- | M] () – C:\Users\Duane\Desktop\attachments_2012_01_11.zip
[2012/01/11 19:02:34 | 002,262,806 | —- | M] () – C:\Windows\System32\drivers\N360\0501000.01D\Cat.DB
[2012/01/11 13:58:28 | 000,065,684 | —- | M] () – C:\ProgramData\nvModes.dat
[2012/01/09 19:10:59 | 000,607,406 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/01/09 19:10:59 | 000,105,014 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/01/09 00:14:14 | 000,007,168 | —- | M] () – C:\Users\Duane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/08 12:51:02 | 002,256,051 | —- | M] () – C:\Users\Duane\Desktop\attachments_2012_01_08.zip
[2012/01/08 10:50:46 | 000,880,042 | —- | M] () – C:\Users\Duane\Desktop\DSCF0851.JPG
[2012/01/08 10:50:46 | 000,827,589 | —- | M] () – C:\Users\Duane\Desktop\DSCF0800.JPG
[2012/01/08 10:50:46 | 000,637,889 | —- | M] () – C:\Users\Duane\Desktop\100_5250.JPG
[2012/01/02 01:01:22 | 000,001,356 | —- | M] () – C:\Users\Duane\AppData\Local\d3d9caps.dat
[2012/01/01 22:37:23 | 000,001,624 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/01/01 17:18:27 | 000,002,100 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2012/01/01 17:13:01 | 000,126,584 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2012/01/01 17:13:01 | 000,007,468 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2012/01/01 17:13:01 | 000,000,806 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2012/01/01 13:01:01 | 000,001,940 | —- | M] () – C:\Users\Duane\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/12/29 11:46:45 | 000,001,680 | —- | M] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Snipping Tool.lnk
[2011/12/26 11:05:42 | 000,001,847 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/12/24 11:15:20 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2011/12/19 08:42:23 | 001,393,736 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Users\Duane\gotomypc_626.exe
[2011/12/16 18:01:03 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/12/14 20:06:45 | 000,000,903 | —- | M] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/14 19:29:46 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2011/12/14 19:29:46 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2011/12/14 19:29:24 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/12/14 19:29:24 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/12/14 19:29:24 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/12/14 19:29:23 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/12/14 19:29:23 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/12/14 19:29:23 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/12/14 19:29:23 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/12/14 19:29:23 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/12/14 19:29:22 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/12/14 19:29:22 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/12/14 19:29:22 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/12/14 19:29:22 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/12/14 19:29:22 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/12/14 19:29:22 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/12/14 19:29:22 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/12/14 19:29:22 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/12/14 19:29:22 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/12/14 19:29:22 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/12/14 19:29:21 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/12/14 19:29:21 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/12/14 19:29:21 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/12/14 19:29:21 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/12/14 19:29:21 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/12/14 19:29:21 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/12/14 19:29:21 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/12/14 19:29:20 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/12/14 19:29:20 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/12/14 19:29:20 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/12/14 19:29:20 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/12/14 19:29:20 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/12/14 19:29:19 | 001,798,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/12/14 19:29:19 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/12/14 19:29:19 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/12/14 19:29:19 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/12/14 19:29:19 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/12/14 19:29:19 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/12/14 19:29:19 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/12/14 19:29:18 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/12/14 19:19:11 | 000,000,206 | —- | M] () – C:\Windows\System32\MRT.INI

========== Files Created - No Company Name ==========

[2012/01/13 12:19:13 | 000,000,332 | —- | C] () – C:\Windows\tasks\RegistryBooster.job
[2012/01/13 12:19:01 | 000,001,593 | —- | C] () – C:\Users\Duane\Desktop\Uniblue RegistryBooster.lnk
[2012/01/13 12:19:01 | 000,001,583 | —- | C] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Uniblue RegistryBooster.lnk
[2012/01/13 07:53:09 | 000,000,866 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/11 20:55:21 | 000,116,527 | —- | C] () – C:\Users\Duane\Desktop\attachments_2012_01_11.zip
[2012/01/08 12:51:32 | 000,880,042 | —- | C] () – C:\Users\Duane\Desktop\DSCF0851.JPG
[2012/01/08 12:51:32 | 000,827,589 | —- | C] () – C:\Users\Duane\Desktop\DSCF0800.JPG
[2012/01/08 12:51:32 | 000,637,889 | —- | C] () – C:\Users\Duane\Desktop\100_5250.JPG
[2012/01/08 12:51:01 | 002,256,051 | —- | C] () – C:\Users\Duane\Desktop\attachments_2012_01_08.zip
[2012/01/01 22:37:22 | 000,001,624 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/01/01 17:17:03 | 002,262,806 | —- | C] () – C:\Windows\System32\drivers\N360\0501000.01D\Cat.DB
[2012/01/01 17:12:09 | 000,000,000 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymDS.cat
[2012/01/01 17:11:42 | 000,003,373 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymEFA.inf
[2012/01/01 17:11:42 | 000,002,792 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymDS.inf
[2012/01/01 17:11:42 | 000,001,474 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymNetV.inf
[2012/01/01 17:11:42 | 000,001,446 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymNet.inf
[2012/01/01 17:11:42 | 000,001,389 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\srtspx.inf
[2012/01/01 17:11:42 | 000,001,383 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\srtsp.inf
[2012/01/01 17:11:42 | 000,000,742 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\Iron.inf
[2012/01/01 17:11:39 | 000,007,877 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\symnetv.cat
[2012/01/01 17:11:39 | 000,007,528 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\iron.cat
[2012/01/01 17:11:39 | 000,007,458 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymNet.cat
[2012/01/01 17:11:39 | 000,007,456 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\SymEFA.cat
[2012/01/01 17:11:39 | 000,007,454 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\srtspx.cat
[2012/01/01 17:11:39 | 000,007,450 | R— | C] () – C:\Windows\System32\drivers\N360\0501000.01D\srtsp.cat
[2012/01/01 17:11:39 | 000,000,172 | —- | C] () – C:\Windows\System32\drivers\N360\0501000.01D\isolate.ini
[2011/12/30 09:57:21 | 000,007,168 | —- | C] () – C:\Users\Duane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/29 11:46:45 | 000,001,680 | —- | C] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Snipping Tool.lnk
[2011/12/28 00:05:46 | 000,001,940 | —- | C] () – C:\Users\Duane\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/12/27 21:15:45 | 000,007,468 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2011/12/27 21:15:45 | 000,000,806 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2011/12/27 21:15:13 | 000,002,100 | —- | C] () – C:\Users\Public\Desktop\Norton 360.lnk
[2011/12/24 11:15:20 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2011/12/14 20:31:45 | 000,000,884 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/14 20:31:41 | 000,000,880 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/14 20:06:45 | 000,000,903 | —- | C] () – C:\Users\Duane\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/14 19:29:22 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/12/14 19:19:11 | 000,000,206 | —- | C] () – C:\Windows\System32\MRT.INI
[2010/09/16 18:58:46 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/09/12 15:39:41 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/09/12 15:39:40 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/09/11 08:56:35 | 000,001,356 | —- | C] () – C:\Users\Duane\AppData\Local\d3d9caps.dat
[2010/01/24 17:38:13 | 000,420,405 | —- | C] () – C:\Windows\hpoins21.dat.temp
[2010/01/24 17:38:13 | 000,008,138 | —- | C] () – C:\Windows\hpomdl21.dat.temp
[2010/01/24 17:15:45 | 000,238,023 | —- | C] () – C:\Windows\hpoins21.dat
[2010/01/24 17:15:45 | 000,008,138 | —- | C] () – C:\Windows\hpomdl21.dat
[2010/01/07 18:47:45 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/01/01 15:01:46 | 000,004,984 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2009/12/31 13:32:11 | 000,000,256 | —- | C] () – C:\Windows\System32\pool.bin
[2009/12/30 12:21:29 | 000,000,412 | —- | C] () – C:\Windows\MAXLINK.INI
[2009/12/19 20:46:27 | 000,065,684 | —- | C] () – C:\ProgramData\nvModes.001
[2009/12/19 20:46:25 | 000,065,684 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.DLL
[2009/08/03 14:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2006/11/02 06:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 06:47:37 | 000,371,864 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 06:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 04:33:01 | 000,607,406 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 04:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 04:33:01 | 000,105,014 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 04:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 04:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 02:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 02:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 01:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/03/09 16:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll

========== LOP Check ==========

[2010/09/18 08:40:59 | 000,000,000 | —D | M] – C:\Users\Duane\AppData\Roaming\Canon
[2012/01/13 12:19:08 | 000,000,000 | —D | M] – C:\Users\Duane\AppData\Roaming\Uniblue
[2012/01/13 12:19:21 | 000,000,332 | —- | M] () – C:\Windows\Tasks\RegistryBooster.job
[2012/01/13 11:37:07 | 000,032,598 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 00:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/12/19 19:48:32 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2012/01/13 11:38:55 | 1072,283,648 | -HS- | M] () – C:\hiberfil.sys
[2010/01/11 15:25:16 | 000,000,349 | -H– | M] () – C:\IPH.PH
[2012/01/13 11:38:54 | 1386,082,304 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/11/02 06:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/09/17 19:03:50 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/05/21 23:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPD91.DLL
[2007/05/21 23:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPP91.DLL
[2008/01/18 22:34:30 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 06:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2010/09/12 13:47:14 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 04:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/12/29 11:46:46 | 000,000,547 | -HS- | M] () – C:\Users\Duane\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/09/18 06:54:45 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Duane\Desktop\ATF-Cleaner.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-12 01:12:46

< End of report >

OTL Extras logfile created on: 1/13/2012 12:39:15 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Duane\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1021.87 Mb Total Physical Memory | 201.50 Mb Available Physical Memory | 19.72% Memory free
2.26 Gb Paging File | 0.79 Gb Available in Paging File | 35.22% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 204.21 Gb Free Space | 68.51% Space Free | Partition Type: NTFS

Computer Name: SHANNONOCONNER | User Name: Duane | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.bat [@ = batfile] – Reg Error: Key error. File not found
.cmd [@ = cmdfile] – Reg Error: Key error. File not found
.com [@ = comfile] – Reg Error: Key error. File not found
.exe [@ = exefile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1BE1AF03-D816-4807-98AC-2DB11D6B93CA}" = rport=137 | protocol=17 | dir=out | app=system |
"{21302A75-EDDC-4E8B-B910-CB2A4B1AEDF8}" = lport=138 | protocol=17 | dir=in | app=system |
"{21E7897C-3043-4708-A1D6-90AB5D565EEE}" = lport=139 | protocol=6 | dir=in | app=system |
"{2EE996EF-9717-44A6-A8BD-1CC2CBF48326}" = rport=138 | protocol=17 | dir=out | app=system |
"{2EF90D85-5B86-4F80-B415-82FD636C96C2}" = lport=137 | protocol=17 | dir=in | app=system |
"{44AFB042-5C3F-4E6F-A6A9-98219D8A6A64}" = rport=139 | protocol=6 | dir=out | app=system |
"{4822F8A4-EA13-49C5-AB09-7135D0AA76F5}" = lport=445 | protocol=6 | dir=in | app=system |
"{64C990DD-F2CB-4F9D-90A5-E3C85EA0239B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe |
"{6E49CEF3-185B-4FA1-9AFA-A7378567C46F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=file and printer sharing (spooler service - rpc-epmap) |
"{E6DD69B4-C281-4AA0-877F-334AF7D380A2}" = rport=445 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0D14F5BA-63C8-4701-93AC-1824F01C9B31}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{14AC5A94-7BD9-429E-BFB7-6CED04AAAFD1}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{305CED5F-4C7F-4475-A5F2-ADAB5DEB8244}" = protocol=1 | dir=in | name=file and printer sharing (echo request - icmpv4-in) |
"{7A6325AF-4DDC-4DB1-AD9B-C6A45143BC64}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7B49D2B3-8EEC-4086-995C-AA01967EC590}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{8A22F7FF-CDF1-44E6-8ED8-DA22CD021E86}" = protocol=58 | dir=in | name=file and printer sharing (echo request - icmpv6-in) |
"{989B7E54-EB26-43ED-9FF6-043E5209AC29}" = protocol=58 | dir=out | name=file and printer sharing (echo request - icmpv6-out) |
"{9DCC21E5-FB96-445E-AE92-DE6A826FA955}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{AD0C7DEC-0370-458C-ABCC-87997330D087}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B34AC80C-C2EB-4668-9A61-CDAAFF1C4008}" = protocol=1 | dir=out | name=file and printer sharing (echo request - icmpv4-out) |
"{EC001DD3-6049-42FB-9AE4-ADE79A28D80E}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"TCP Query User{5F8F37A1-98AC-4CB5-8137-0577B0443573}C:\program files\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files\skype\phone\skype.exe |
"TCP Query User{9282021A-FEE3-41C8-BF9C-CAE8ECF1F877}C:\users\duane\appdata\local\temp\g2_626\g2viewer.exe" = protocol=6 | dir=in | app=c:\users\duane\appdata\local\temp\g2_626\g2viewer.exe |
"UDP Query User{90F25616-32BE-4B18-AF45-CBC0976DC472}C:\users\duane\appdata\local\temp\g2_626\g2viewer.exe" = protocol=17 | dir=in | app=c:\users\duane\appdata\local\temp\g2_626\g2viewer.exe |
"UDP Query User{DAEBDEDC-1899-4B2F-8DFB-13BC7F43DC4A}C:\program files\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP970_series" = Canon MP970 series
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 30
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.7
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2F3DBD9-A9D2-4838-B45D-C917DAB32BC3}" = ScanSoft OmniPage SE 4
"{B7DBF6E8-0D17-4BE4-853B-ACD6EFBD4A1F}" = iTunes
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BB}" = WinZip 14.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F5CC2EF8-20A4-4366-A681-3FE849E65809}" = RICOH Media Driver
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Canon MP970 series User Registration" = Canon MP970 series User Registration
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"ESET Online Scanner" = ESET Online Scanner v3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"N360" = Norton 360
"NVIDIA Drivers" = NVIDIA Drivers
"PROR" = Microsoft Office Professional 2007
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TomTom HOME" = TomTom HOME 2.7.3.1894
"Uniblue RegistryBooster" = Uniblue RegistryBooster
"WinLiveSuite" = Windows Live Essentials

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/26/2011 1:15:02 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 3/26/2011 1:15:02 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 9782

Error - 3/26/2011 1:15:02 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 9782

Error - 3/26/2011 1:15:03 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 3/26/2011 1:15:03 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 10796

Error - 3/26/2011 1:15:03 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 10796

Error - 3/26/2011 1:15:04 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 3/26/2011 1:15:04 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 11794

Error - 3/26/2011 1:15:04 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 11794

Error - 3/26/2011 1:15:05 PM | Computer Name = ShannonOConner | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

[ Media Center Events ]
Error - 11/1/2010 9:45:58 PM | Computer Name = ShannonOConner | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 6/19/2011 2:01:28 AM | Computer Name = ShannonOConner | Source = MCUpdate | ID = 0
Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed
due to an abandoned mutex.'.

[ System Events ]
Error - 1/2/2012 2:44:42 PM | Computer Name = ShannonOConner | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.10.105 for the Network Card with network
address 001A73143DA0 has been denied by the DHCP server 192.168.10.1 (The DHCP
Server sent a DHCPNACK message).

Error - 1/5/2012 10:40:36 AM | Computer Name = ShannonOConner | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:35:39 AM on 1/5/2012 was unexpected.

Error - 1/5/2012 8:53:38 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7011
Description =

Error - 1/10/2012 8:53:02 AM | Computer Name = ShannonOConner | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:31:48 PM on 1/9/2012 was unexpected.

Error - 1/10/2012 2:28:46 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7011
Description =

Error - 1/11/2012 12:59:02 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7031
Description =

Error - 1/11/2012 1:26:16 PM | Computer Name = ShannonOConner | Source = EventLog | ID = 6008
Description = The previous system shutdown at 11:23:38 AM on 1/11/2012 was unexpected.

Error - 1/11/2012 8:29:31 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7011
Description =

Error - 1/12/2012 1:51:55 PM | Computer Name = ShannonOConner | Source = EventLog | ID = 6008
Description = The previous system shutdown at 11:49:19 AM on 1/12/2012 was unexpected.

Error - 1/12/2012 8:32:59 PM | Computer Name = ShannonOConner | Source = Service Control Manager | ID = 7011
Description =


< End of report >

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:50:42 PM, on 1/13/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\wpcumi.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Duane\Downloads\HiJackThis.exe
C:\Users\Duane\Downloads\technical software\whatthetech files\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20614.www2.hp.com/ediags/gmd/Insta…hpdetect118.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8795 bytes

DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 13:53:20.76 on Fri 01/13/2012
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1022.153 [GMT -6:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\wpcumi.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Duane\Downloads\HiJackThis.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Duane\Downloads\technical software\whatthetech files\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://att.my.yahoo.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\5.1.0.29\ips\IPSBHO.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [RegistryBooster] "c:\program files\uniblue\registrybooster\launcher.exe" delay 20000
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe"
mRun: [IJNetworkScanUtility] c:\program files\canon\canon ij network scan utility\CNMNSUT.EXE
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\windows\system32\wpclsp.dll
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect118.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys [2012-1-1 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys [2012-1-1 744568]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\bashdefs\20111223.001\BHDrvx86.sys [2011-11-30 820344]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\ipsdefs\20120112.002\IDSvix86.sys [2012-1-12 368248]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys [2012-1-1 136312]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0501000.01d\symtdiv.sys [2012-1-1 331384]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2010-9-12 21504]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-12-27 106104]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-9-12 20464]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\drivers\R5U870FLx86.sys [2006-12-18 73472]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\drivers\R5U870FUx86.sys [2006-12-18 43904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-12-14 136176]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-20 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-22 1493352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-12-14 136176]
.
=============== Created Last 30 ================
.
2012-01-13 18:19:08 ——– d—–w- c:\users\duane\appdata\roaming\Uniblue
2012-01-13 18:18:55 ——– dc-h–w- c:\progra~2\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
2012-01-13 18:18:54 ——– d—–w- c:\program files\Uniblue
2012-01-13 18:18:09 ——– d—–w- c:\users\duane\appdata\local\PackageAware
2012-01-13 13:01:43 ——– d—–w- c:\users\duane\appdata\local\Adobe
2012-01-12 01:04:31 9728 —-a-w- c:\windows\system32\lsass.exe
2012-01-12 01:04:31 72704 —-a-w- c:\windows\system32\secur32.dll
2012-01-12 01:04:31 440192 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-12 01:04:31 377344 —-a-w- c:\windows\system32\winhttp.dll
2012-01-12 01:04:31 278528 —-a-w- c:\windows\system32\schannel.dll
2012-01-12 01:04:31 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2012-01-12 00:44:42 ——– d—–w- c:\users\duane\appdata\local\NPE
2012-01-11 12:14:40 23552 —-a-w- c:\windows\system32\mciseq.dll
2012-01-11 12:14:40 189952 —-a-w- c:\windows\system32\winmm.dll
2012-01-11 12:14:36 1205064 —-a-w- c:\windows\system32\ntdll.dll
2012-01-11 12:14:31 66560 —-a-w- c:\windows\system32\packager.dll
2012-01-11 12:14:27 376320 —-a-w- c:\windows\system32\winsrv.dll
2012-01-11 12:14:21 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2012-01-11 12:14:16 1314816 —-a-w- c:\windows\system32\quartz.dll
2012-01-11 12:14:15 497152 —-a-w- c:\windows\system32\qdvd.dll
2012-01-05 14:26:09 ——– d—–w- C:\bf6cf6c4002208f661226346e13c06b4
2012-01-02 05:00:11 ——– d—–w- c:\users\duane\appdata\local\CrashDumps
2012-01-02 04:34:59 ——– d—–w- c:\program files\iPod
2012-01-02 04:34:32 ——– d—–w- c:\program files\iTunes
2012-01-02 04:16:27 ——– d—–w- c:\program files\Bonjour
2012-01-01 23:13:16 27888 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-01-01 23:12:09 331384 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\symtdiv.sys
2012-01-01 23:12:09 296568 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\symnets.sys
2012-01-01 23:12:08 744568 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys
2012-01-01 23:12:08 516216 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\srtsp.sys
2012-01-01 23:12:08 50168 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\srtspx.sys
2012-01-01 23:12:08 340088 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys
2012-01-01 23:12:08 136312 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys
2012-01-01 23:11:39 ——– d—–w- c:\windows\system32\drivers\n360\0501000.01D
2012-01-01 21:12:38 ——– d—–w- c:\program files\HP
2011-12-28 03:15:53 106928 —-a-w- c:\windows\system32\GEARAspi.dll
2011-12-28 03:15:45 126584 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-12-28 03:15:35 ——– d—–w- c:\program files\Symantec
2011-12-28 03:15:35 ——– d—–w- c:\program files\common files\Symantec Shared
2011-12-28 03:14:36 ——– d—–w- c:\windows\system32\drivers\N360
2011-12-28 03:14:32 ——– d—–w- c:\program files\Norton 360
2011-12-28 03:14:18 ——– d—–w- c:\program files\NortonInstaller
2011-12-28 03:14:18 ——– d—–w- c:\progra~2\NortonInstaller
2011-12-28 01:27:11 114688 —-a-w- c:\windows\system32\RicohMediadriverVer.dll
2011-12-28 01:27:10 90112 —-a-w- c:\windows\system32\snymsico.dll
2011-12-28 01:27:10 48128 —-a-w- c:\windows\system32\drivers\rimmptsk.sys
2011-12-28 01:27:10 44544 —-a-w- c:\windows\system32\drivers\rimsptsk.sys
2011-12-28 01:27:10 38400 —-a-w- c:\windows\system32\drivers\rixdptsk.sys
2011-12-28 01:27:09 172032 —-a-w- c:\windows\system32\rixdicon.dll
2011-12-28 00:51:26 ——– d—–w- c:\users\duane\appdata\local\ElevatedDiagnostics
2011-12-27 23:58:22 ——– d—–w- c:\progra~2\Norton
2011-12-27 21:22:10 6823496 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{7579a660-a0ec-4a5b-8cc3-67ad7ce68772}\mpengine.dll
2011-12-19 14:42:19 1393736 —-a-w- c:\users\duane\gotomypc_626.exe
2011-12-17 00:01:03 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-15 02:30:23 ——– d—–w- c:\users\duane\appdata\local\Apps
2011-12-15 02:30:22 ——– d—–w- c:\users\duane\appdata\local\Deployment
2011-12-14 22:58:08 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-14 22:58:07 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-12-14 22:58:04 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax
2011-12-14 22:58:04 57856 —-a-w- c:\windows\system32\MSDvbNP.ax
2011-12-14 22:58:04 293376 —-a-w- c:\windows\system32\psisdecd.dll
2011-12-14 22:58:04 217088 —-a-w- c:\windows\system32\psisrndr.ax
2011-12-14 22:57:57 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-12-14 22:57:56 79872 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-12-14 22:57:56 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-12-14 22:57:54 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-12-14 22:57:53 6144 —-a-w- c:\program files\internet explorer\iecompat.dll
2011-12-14 22:57:24 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-12-14 22:57:00 2043904 —-a-w- c:\windows\system32\win32k.sys
2011-12-14 22:56:54 49152 —-a-w- c:\windows\system32\csrsrv.dll
2011-12-14 22:56:47 2048 —-a-w- c:\windows\system32\tzres.dll
2011-12-14 22:56:21 563712 —-a-w- c:\windows\system32\oleaut32.dll
2011-12-14 22:56:21 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2011-12-14 22:56:21 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2011-12-14 22:56:21 238080 —-a-w- c:\windows\system32\oleacc.dll
2011-12-14 22:54:25 707584 —-a-w- c:\program files\common files\system\wab32.dll
.
==================== Find3M ====================
.
2011-11-15 20:29:56 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-11-10 11:54:13 472808 —-a-w- c:\windows\system32\deployJava1.dll
.
============= FINISH: 13:58:59.50 ===============

Attachments:

Hi

I received your PM, that all is OK now.
There are no obvious signs of malware in the logs, but it wouldn't hurt to run a couple of scans just to be certain, please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Here's the logs. Malwarebytes Anti-Malware (Trial) 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.13.05 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Duane :: SHANNONOCONNER [administrator] Protection: Enabled 1/14/2012 12:42:26 PM mbam-log-2012-01-14 (12-42-26).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 217352 Time elapsed: 9 minute(s), 46 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) C:\Users\Caledonia\AppData\Roaming\Mozilla\Firefox\Profiles\xjja1d66.default\extensions\{060f1156-c2eb-4a64-9b23-0aecae8dfffe}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan C:\Users\Caledonia\AppData\Roaming\Mozilla\Firefox\Profiles\xjja1d66.default\extensions\{060f1156-c2eb-4a64-9b23-0aecae8dfffe}\chrome\xulcache.jar JS/Agent.NDB trojan C:\Users\Duane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QXPNGG6I\registrybooster.exe Win32/RegistryBooster application C:\Users\Duane\AppData\Local\temp\mia3ADE.tmp\data\OFFLINE\7F895C1F\DE39FC21\Launcher.exe Win32/RegistryBooster application C:\Users\Duane\AppData\Local\temp\mia3ADE.tmp\data\OFFLINE\7F895C1F\DE39FC21\rbmonitor.exe Win32/RegistryBooster application C:\Users\Duane\AppData\Local\temp\mia3ADE.tmp\data\OFFLINE\7F895C1F\DE39FC21\rbnotifier.exe Win32/RegistryBooster application C:\Users\Duane\AppData\Local\temp\mia3ADE.tmp\data\OFFLINE\7F895C1F\DE39FC21\rb_move_serial.exe Win32/RegistryBooster application C:\Users\Duane\AppData\Local\temp\mia3ADE.tmp\data\OFFLINE\7F895C1F\DE39FC21\rb_ubm.exe Win32/RegistryBooster application C:\Users\Duane\AppData\Local\temp\mia3ADE.tmp\data\OFFLINE\7F895C1F\DE39FC21\registrybooster.exe Win32/RegistryBooster application C:\Users\Shannon O'Conner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\2cc07e61-4246687b a variant of Java/TrojanDownloader.OpenStream.NCE trojan C:\Users\Shannon O'Conner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\51d1c3f7-5d204d43 a variant of Java/TrojanDownloader.OpenStream.NCE trojan C:\Users\Shannon O'Conner\AppData\Roaming\Mozilla\Firefox\Profiles\1x3aw1l4.default\extensions\{060f1156-c2eb-4a64-9b23-0aecae8dfffe}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan C:\Users\Shannon O'Conner\AppData\Roaming\Mozilla\Firefox\Profiles\1x3aw1l4.default\extensions\{060f1156-c2eb-4a64-9b23-0aecae8dfffe}\chrome\xulcache.jar JS/Agent.NDB trojan
Hi

Update Adobe and clear all your temp files and browser history

Visit ADOBE and download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.


Download TFC to your desktop
Mirror
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean


Let me know how the computer is running now and if there are any outstanding issues
OK, good

I'll give you my usual clean up speech and keep the thread open a day or too in case new issues develop.

Just some clean up to do now:

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
OK Catbyte, I've done all of the recommendations. However, there was a glitch loading WOT and I am waiting for a response from them regarding the debug. Let me know how you want to proceed.
Sorry for the delay. WOT responded that although there were error messages during installation and the exclamation point was showing on the toolbar, the software installed correctly and simply opening up the rating window would clear the exclamation point. I did that and it cleared. Everything else appears to be working fine. Thanks for everything.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI