This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win 7 can't even boot up now [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a Dell Inspiron One all-in-one LCD/PC that was apparently infected with malware. Ran Malwarebytes and MS Essentials and no matter what I did the infection kept coming back. I remember it mentioning it found Alureon? Now I can't even boot up properly. Windows keeps going to Startup Repair and when I run it it says it can't fix the problem. Tried boot to Win 7 System Recovery partition too, ran CHKDSK and it's fine, ran Startup Repair and didn't work. Not even Safe Mode works. Don't know what to do. Did this infection cause my entire OS to go corrupt?
Hi

Please try the following:


For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to the disclaimer.

[*]Place a check next to List Drivers MD5 as well as the default check marks that are already there

[*]Press Scan button.

[*]type exit and reboot the computer normally

[*]FRST will make a log (FRST.txt) on the flash drive, please copy and paste the log in your reply.

Thanks CatByte, here is the FRST log: Scan result of Farbar Recovery Scan Tool Version: 15-03-2012 Ran by [removed] at 19-03-2012 18:08:45 Running from F:\ Windows 7 Home Premium (X64) OS Language: English(US) The current controlset is ControlSet001 ========================== Registry (Whitelisted) ============= HKLM\…\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10920552 2010-06-22] (Realtek Semiconductor) HKLM\…\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5712896 2010-02-02] (Dell Inc.) HKLM\…\Run: [RunDLLEntry_THXCfg] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 [17920 2009-10-15] (Creative Technology Ltd.) HKLM\…\Run: [RunDLLEntry_EptMon] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\EptMon64.dll,RunDLLEntry EptMon64 [21504 2009-10-15] (Creative Technology Ltd.) HKLM\…\Run: [DellStage] "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" –startup [207350 2011-01-25] () HKLM\…\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1436736 2011-06-15] (Microsoft Corporation) HKLM-x32\…\Run: [ShwiconXP6366] c:\Program Files (x86)\Multimedia Card Reader(6366)\ShwiconXP6366.exe [237568 2009-07-16] (Alcor Micro Corp.) HKLM-x32\…\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-09-21] (Advanced Micro Devices, Inc.) HKLM-x32\…\Run: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe [95560 2010-02-22] (Sensible Vision ) HKLM-x32\…\Run: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r [963584 2009-12-01] (Creative Technology Ltd) HKLM-x32\…\Run: [FAStartup] [x] HKLM-x32\…\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey [1675160 2011-11-22] (McAfee, Inc.) HKLM-x32\…\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM-x32\…\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKLM-x32\…\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-10-09] (Apple Inc.) HKLM-x32\…\Run: [iYogi Support Dock] "C:\Program Files (x86)\iYogi Support Dock\iYogiSupportDock.exe" [1576176 2011-08-30] () HKLM-x32\…\Run: [iolo Startup] "C:\Program Files (x86)\iolo\Common\Lib\ioloLManager.exe" [606904 2012-01-06] (iolo technologies, LLC) HKLM-x32\…\Run: [devicexml] C:\ProgramData\devicexml.exe [68632 2012-03-12] () HKLM-x32\…\Run: [utilsrv] C:\Windows\system32\config\systemprofile\AppData\Roaming\utilsrv.exe [x] HKU\Finn\…\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [3883856 2009-07-26] (Microsoft Corporation) HKU\Finn\…\Policies\system: [LogonHoursAction] 2 HKU\Finn\…\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\gabcon\…\Run: [Google Update] "C:\Users\gabcon\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-05-28] (Google Inc.) HKU\gabcon\…\Run: [Facebook Update] "C:\Users\gabcon\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [137536 2011-12-31] (Facebook Inc.) HKU\gabcon\…\Run: [devicexml] C:\ProgramData\devicexml.exe [68632 2012-03-12] () HKU\gabcon\…\Run: [utilsrv] C:\Users\gabcon\AppData\Roaming\utilsrv.exe [68632 2012-03-12] () HKU\gabcon\…\Run: [Update] rundll32.exe "C:\Windows\system32\config\systemprofile\AppData\Roaming\Adobe\Adobe\klzgc.dll",DllRegisterServer [x] HKU\gabcon\…\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [3883856 2009-07-26] (Microsoft Corporation) HKU\gabcon\…\Policies\system: [LogonHoursAction] 2 HKU\gabcon\…\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKLM\…\RunOnce: [*Restore] C:\Windows\system32\rstrui.exe /RUNONCE [296960 2009-07-13] (Microsoft Corporation) HKLM-x32\…\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [560128 2011-09-18] (Dell) HKLM-x32\…\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe [165184 2011-01-13] (Softthinks) HKLM-x32\…\RunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript [1081416 2012-01-13] (Malwarebytes Corporation) Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\615\G2AWinLogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.) Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76 Lsa: [Notification Packages] scecli FAPassSync ==================== Services (Whitelisted) ====== 2 Bonjour Service; "C:\Program Files\Bonjour\mDNSResponder.exe" [462184 2011-08-30] (Apple Inc.) 2 ioloSystemService; "C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe" [722616 2012-01-06] (iolo technologies, LLC) 2 McMPFSvc; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [249936 2011-01-27] (McAfee, Inc.) 2 mcmscsvc; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [249936 2011-01-27] (McAfee, Inc.) 2 McNaiAnn; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [249936 2011-01-27] (McAfee, Inc.) 2 McNASvc; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [249936 2011-01-27] (McAfee, Inc.) 3 McODS; "C:\Program Files\mcafee\VirusScan\mcods.exe" [501768 2011-03-17] (McAfee, Inc.) 4 McOobeSv; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [249936 2011-01-27] (McAfee, Inc.) 2 McProxy; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [249936 2011-01-27] (McAfee, Inc.) 2 McShield; "C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe" [199272 2011-10-18] (McAfee, Inc.) 2 mfefire; "C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe" [208536 2011-10-18] (McAfee, Inc.) 2 mfevtp; "C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe" [161168 2011-10-18] (McAfee, Inc.) 2 SupportDockService.exe; "C:\Program Files (x86)\iYogi Support Dock\Services\CommAgent\SupportDockService.exe" [73728 2011-08-30] (iYogi Technical Services) 2 FAService; "c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe" [x] 2 MsMpSvc; "c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe" [x] 3 NisSrv; "c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe" [x] ========================== Drivers (Whitelisted) ============= 3 cfwids; C:\Windows\System32\Drivers\cfwids.sys [65264 2011-10-15] (McAfee, Inc.) 1 ElRawDisk; \??\C:\Windows\system32\drivers\ElRawDsk.sys [23464 2008-12-09] (EldoS Corporation) 3 mfeapfk; C:\Windows\System32\Drivers\mfeapfk.sys [160280 2011-10-15] (McAfee, Inc.) 3 mfeavfk; C:\Windows\System32\Drivers\mfeavfk.sys [229528 2011-10-15] (McAfee, Inc.) 3 mfefirek; C:\Windows\System32\Drivers\mfefirek.sys [481768 2011-10-15] (McAfee, Inc.) 0 mfehidk; C:\Windows\System32\Drivers\mfehidk.sys [647080 2011-10-15] (McAfee, Inc.) 1 mfenlfk; C:\Windows\System32\Drivers\mfenlfk.sys [75808 2011-10-15] (McAfee, Inc.) 3 mferkdet; C:\Windows\System32\Drivers\mferkdet.sys [100912 2011-10-15] (McAfee, Inc.) 0 mfewfpk; C:\Windows\System32\Drivers\mfewfpk.sys [284648 2011-10-15] (McAfee, Inc.) 1 MpKslce43b409; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{33A5EDBD-705D-4133-B07B-BC7BEDDB5F8E}\MpKslce43b409.sys [35664 2012-03-12] (Microsoft Corporation) 3 StillCam; C:\Windows\System32\DRIVERS\serscan.sys [12288 2009-07-13] (Microsoft Corporation) 3 mfeavfk01; [x] 3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0; \??\c:\program files\dell support center\pcdsrvc_x64.pkms [x] ========================== NetSvcs (Whitelisted) =========== ============ One Month Created Files and Folders ============== 2012-03-17 12:13 - 2012-03-19 14:41 - 0000000 ____D C:\Windows\Microsoft Antimalware 2012-03-17 10:57 - 2012-03-17 10:57 - 0000316 ____A C:\Users\gabcon\Downloads\RootKitBusterDebug20120317_00.log 2012-03-17 10:52 - 2012-03-17 10:52 - 0183791 ____A C:\Users\gabcon\Local Settings\census.cache 2012-03-17 10:52 - 2012-03-17 10:52 - 0183791 ____A C:\Users\gabcon\Local Settings\Application Data\census.cache 2012-03-17 10:52 - 2012-03-17 10:52 - 0183791 ____A C:\Users\gabcon\AppData\Local\census.cache 2012-03-17 10:52 - 2012-03-17 10:52 - 0104595 ____A C:\Users\gabcon\Local Settings\ars.cache 2012-03-17 10:52 - 2012-03-17 10:52 - 0104595 ____A C:\Users\gabcon\Local Settings\Application Data\ars.cache 2012-03-17 10:52 - 2012-03-17 10:52 - 0104595 ____A C:\Users\gabcon\AppData\Local\ars.cache 2012-03-17 08:34 - 2012-03-17 08:34 - 0000036 ____A C:\Users\gabcon\Local Settings\housecall.guid.cache 2012-03-17 08:34 - 2012-03-17 08:34 - 0000036 ____A C:\Users\gabcon\Local Settings\Application Data\housecall.guid.cache 2012-03-17 08:34 - 2012-03-17 08:34 - 0000036 ____A C:\Users\gabcon\AppData\Local\housecall.guid.cache 2012-03-12 18:57 - 2009-07-13 20:14 - 0020480 ____A (Microsoft Corporation) C:\Windows\svchost.exe 2012-03-12 08:54 - 2012-03-12 07:38 - 0068632 ____A C:\Users\gabcon\Application Data\utilsrv.exe 2012-03-12 08:54 - 2012-03-12 07:38 - 0068632 ____A C:\Users\gabcon\AppData\Roaming\utilsrv.exe 2012-03-12 08:26 - 2012-03-12 08:26 - 0782720 ____A (Microsoft Corporation) C:\Users\gabcon\Downloads\mssstool64 (1).exe 2012-03-12 08:25 - 2012-03-12 08:25 - 0782720 ____A (Microsoft Corporation) C:\Users\gabcon\Downloads\mssstool64.exe 2012-03-12 07:38 - 2012-03-12 07:38 - 0068632 ____A C:\Users\All Users\devicexml.exe 2012-03-12 07:38 - 2012-03-12 07:38 - 0068632 ____A C:\Users\All Users\Application Data\devicexml.exe 2012-03-12 07:38 - 2012-03-12 07:38 - 0068632 ____A C:\ProgramData\devicexml.exe 2012-03-02 06:45 - 2012-03-02 06:45 - 0000000 ____D C:\Program Files\Google 2012-03-02 06:44 - 2012-03-12 18:59 - 0000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2012-03-02 06:44 - 2012-03-12 11:49 - 0000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2012-03-02 06:44 - 2012-03-02 06:45 - 0000000 ____D C:\Users\All Users\Google 2012-03-02 06:44 - 2012-03-02 06:45 - 0000000 ____D C:\Users\All Users\Application Data\Google 2012-03-02 06:44 - 2012-03-02 06:45 - 0000000 ____D C:\ProgramData\Google 2012-03-02 06:44 - 2012-03-02 06:45 - 0000000 ____D C:\Program Files (x86)\Google 2012-03-02 06:44 - 2012-03-02 06:44 - 0414368 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-03-02 06:43 - 2012-03-02 06:43 - 0000000 ____D C:\Windows\System32\Macromed 2012-02-29 20:57 - 2012-02-29 20:57 - 0065536 __ASH C:\Windows\System32\config\components{65a45370-5cf0-11e1-bcdf-842b2b8535fb}.TxR.blf 2012-02-28 19:47 - 2012-02-28 19:47 - 0016822 ____A C:\Users\gabcon\My Documents\Finn Conle2.docx 2012-02-28 19:47 - 2012-02-28 19:47 - 0016822 ____A C:\Users\gabcon\Documents\Finn Conle2.docx 2012-02-28 05:18 - 2012-02-29 21:04 - 0001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-02-28 05:18 - 2012-02-29 21:04 - 0001111 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk 2012-02-26 18:55 - 2012-02-27 11:14 - 0021879 ____A C:\Users\gabcon\My Documents\Balloon.docx 2012-02-26 18:55 - 2012-02-27 11:14 - 0021879 ____A C:\Users\gabcon\Documents\Balloon.docx 2012-02-22 03:02 - 2012-02-22 03:02 - 9705472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 3695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2012-02-22 03:02 - 2012-02-22 03:02 - 3695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2012-02-22 03:02 - 2012-02-22 03:02 - 2382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-02-22 03:02 - 2012-02-22 03:02 - 2382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-02-22 03:02 - 2012-02-22 03:02 - 2308096 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 2144256 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 1798656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 1792000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 17790464 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 1493504 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-02-22 03:02 - 2012-02-22 03:02 - 1427456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-02-22 03:02 - 2012-02-22 03:02 - 1390080 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 1345536 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 12282368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 1127424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 1103360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 10887168 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0697344 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0603648 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0580608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0534528 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0452608 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0448512 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2012-02-22 03:02 - 2012-02-22 03:02 - 0434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0403248 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2012-02-22 03:02 - 2012-02-22 03:02 - 0353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0282112 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0267776 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0249344 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0222208 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0165888 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0160256 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0160256 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0145920 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0135168 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0114176 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0111616 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0103936 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0096256 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0091648 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0089088 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0089088 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0085504 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0082432 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0076800 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2012-02-22 03:02 - 2012-02-22 03:02 - 0074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0072822 ____A C:\Windows\SysWOW64\ieuinit.inf 2012-02-22 03:02 - 2012-02-22 03:02 - 0072822 ____A C:\Windows\System32\ieuinit.inf 2012-02-22 03:02 - 2012-02-22 03:02 - 0072704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0065024 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2012-02-22 03:02 - 2012-02-22 03:02 - 0055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0049664 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0030720 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0012288 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2012-02-22 03:00 - 2012-02-22 03:03 - 0003900 ____A C:\Windows\IE9_main.log 2012-02-21 20:41 - 2012-02-21 20:41 - 0000000 ____D C:\Windows\Sun ============ 3 Months Modified Files and Folders ============= 2012-03-19 18:09 - 2012-03-19 18:08 - 0000000 ____D C:\FRST 2012-03-19 14:42 - 2011-05-24 21:29 - 0000000 ____D C:\users\Finn 2012-03-19 14:42 - 2011-05-24 13:50 - 0000000 ____D C:\users\gabcon 2012-03-19 14:42 - 2009-07-13 22:20 - 0000000 ___HD C:\Windows\System32\GroupPolicy 2012-03-19 14:42 - 2009-07-13 22:20 - 0000000 ____D C:\Windows\AppCompat 2012-03-19 14:41 - 2012-03-17 12:13 - 0000000 ____D C:\Windows\Microsoft Antimalware 2012-03-19 14:41 - 2011-12-04 14:26 - 0000000 ____D C:\Program Files\Microsoft Security Client 2012-03-19 14:41 - 2011-11-18 11:24 - 0000000 ____D C:\Users\All Users\Malwarebytes 2012-03-19 14:41 - 2011-11-18 11:24 - 0000000 ____D C:\Users\All Users\Application Data\Malwarebytes 2012-03-19 14:41 - 2011-11-18 11:24 - 0000000 ____D C:\ProgramData\Malwarebytes 2012-03-19 14:41 - 2011-11-18 11:24 - 0000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-03-19 14:41 - 2011-07-19 09:14 - 0000000 ____D C:\Users\All Users\HP 2012-03-19 14:41 - 2011-07-19 09:14 - 0000000 ____D C:\Users\All Users\Application Data\HP 2012-03-19 14:41 - 2011-07-19 09:14 - 0000000 ____D C:\ProgramData\HP 2012-03-19 14:41 - 2009-07-13 22:20 - 0000000 ____D C:\Windows\registration 2012-03-19 14:36 - 2011-12-04 14:27 - 0000000 ____D C:\Program Files (x86)\Microsoft Security Client 2012-03-19 14:36 - 2011-04-15 10:00 - 0000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup 2012-03-17 10:57 - 2012-03-17 10:57 - 0000316 ____A C:\Users\gabcon\Downloads\RootKitBusterDebug20120317_00.log 2012-03-17 10:52 - 2012-03-17 10:52 - 0183791 ____A C:\Users\gabcon\Local Settings\census.cache 2012-03-17 10:52 - 2012-03-17 10:52 - 0183791 ____A C:\Users\gabcon\Local Settings\Application Data\census.cache 2012-03-17 10:52 - 2012-03-17 10:52 - 0183791 ____A C:\Users\gabcon\AppData\Local\census.cache 2012-03-17 10:52 - 2012-03-17 10:52 - 0104595 ____A C:\Users\gabcon\Local Settings\ars.cache 2012-03-17 10:52 - 2012-03-17 10:52 - 0104595 ____A C:\Users\gabcon\Local Settings\Application Data\ars.cache 2012-03-17 10:52 - 2012-03-17 10:52 - 0104595 ____A C:\Users\gabcon\AppData\Local\ars.cache 2012-03-17 10:37 - 2011-05-24 13:50 - 0000000 ____D C:\Users\gabcon\Local Settings\SoftThinks 2012-03-17 10:37 - 2011-05-24 13:50 - 0000000 ____D C:\Users\gabcon\Local Settings\Application Data\SoftThinks 2012-03-17 10:37 - 2011-05-24 13:50 - 0000000 ____D C:\Users\gabcon\AppData\Local\SoftThinks 2012-03-17 08:42 - 2011-04-15 11:29 - 3016712192 __ASH C:\hiberfil.sys 2012-03-17 08:34 - 2012-03-17 08:34 - 0000036 ____A C:\Users\gabcon\Local Settings\housecall.guid.cache 2012-03-17 08:34 - 2012-03-17 08:34 - 0000036 ____A C:\Users\gabcon\Local Settings\Application Data\housecall.guid.cache 2012-03-17 08:34 - 2012-03-17 08:34 - 0000036 ____A C:\Users\gabcon\AppData\Local\housecall.guid.cache 2012-03-16 18:32 - 2011-12-13 18:32 - 0000000 ____D C:\Windows\Minidump 2012-03-15 20:57 - 2011-06-07 17:44 - 0000000 ____D C:\Users\gabcon\Tracing 2012-03-14 02:20 - 2009-07-13 23:51 - 0031119 ____A C:\Windows\setupact.log 2012-03-12 19:08 - 2009-07-14 00:10 - 1136004 ____A C:\Windows\WindowsUpdate.log 2012-03-12 19:04 - 2009-07-13 23:45 - 0014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-03-12 19:04 - 2009-07-13 23:45 - 0014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-03-12 19:02 - 2011-05-28 09:24 - 0000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001UA.job 2012-03-12 19:01 - 2009-07-14 00:13 - 0733968 ____A C:\Windows\System32\PerfStringBackup.INI 2012-03-12 18:59 - 2012-03-02 06:44 - 0000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2012-03-12 18:56 - 2009-07-14 00:08 - 0000006 ___AH C:\Windows\Tasks\SA.DAT 2012-03-12 18:56 - 2009-07-13 23:51 - 0031007 ____A C:\Windows\setupact(36).log 2012-03-12 17:03 - 2011-05-28 09:24 - 0002407 ____A C:\Users\gabcon\Desktop\Google Chrome.lnk 2012-03-12 16:09 - 2011-12-31 20:04 - 0000932 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001UA.job 2012-03-12 16:02 - 2011-05-24 13:53 - 0000422 ____A C:\Windows\Tasks\SystemToolsDailyTest.job 2012-03-12 15:02 - 2011-05-28 09:24 - 0000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001Core.job 2012-03-12 11:49 - 2012-03-02 06:44 - 0000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2012-03-12 09:09 - 2009-07-14 00:08 - 0032630 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2012-03-12 08:26 - 2012-03-12 08:26 - 0782720 ____A (Microsoft Corporation) C:\Users\gabcon\Downloads\mssstool64 (1).exe 2012-03-12 08:25 - 2012-03-12 08:25 - 0782720 ____A (Microsoft Corporation) C:\Users\gabcon\Downloads\mssstool64.exe 2012-03-12 07:38 - 2012-03-12 08:54 - 0068632 ____A C:\Users\gabcon\Application Data\utilsrv.exe 2012-03-12 07:38 - 2012-03-12 08:54 - 0068632 ____A C:\Users\gabcon\AppData\Roaming\utilsrv.exe 2012-03-12 07:38 - 2012-03-12 07:38 - 0068632 ____A C:\Users\All Users\devicexml.exe 2012-03-12 07:38 - 2012-03-12 07:38 - 0068632 ____A C:\Users\All Users\Application Data\devicexml.exe 2012-03-12 07:38 - 2012-03-12 07:38 - 0068632 ____A C:\ProgramData\devicexml.exe 2012-03-12 06:55 - 2009-07-13 21:34 - 0000855 ____A C:\Windows\System32\Drivers\etc\hosts 2012-03-12 06:42 - 2011-04-15 11:29 - 0083020 ____A C:\Windows\PFRO.log 2012-03-11 19:09 - 2011-12-31 20:04 - 0000910 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001Core.job 2012-03-04 10:48 - 2011-06-08 06:46 - 0000000 ____D C:\Users\gabcon\Local Settings\ElevatedDiagnostics 2012-03-04 10:48 - 2011-06-08 06:46 - 0000000 ____D C:\Users\gabcon\Local Settings\Application Data\ElevatedDiagnostics 2012-03-04 10:48 - 2011-06-08 06:46 - 0000000 ____D C:\Users\gabcon\AppData\Local\ElevatedDiagnostics 2012-03-03 20:02 - 2011-05-24 13:53 - 0000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job 2012-03-02 07:35 - 2011-11-18 11:17 - 0000000 ____D C:\Users\All Users\iolo 2012-03-02 07:35 - 2011-11-18 11:17 - 0000000 ____D C:\Users\All Users\Application Data\iolo 2012-03-02 07:35 - 2011-11-18 11:17 - 0000000 ____D C:\ProgramData\iolo 2012-03-02 07:22 - 2011-11-18 12:02 - 0002221 ____A C:\Users\gabcon\Desktop\System Mechanic.lnk 2012-03-02 06:45 - 2012-03-02 06:45 - 0000000 ____D C:\Program Files\Google 2012-03-02 06:45 - 2012-03-02 06:44 - 0000000 ____D C:\Users\All Users\Google 2012-03-02 06:45 - 2012-03-02 06:44 - 0000000 ____D C:\Users\All Users\Application Data\Google 2012-03-02 06:45 - 2012-03-02 06:44 - 0000000 ____D C:\ProgramData\Google 2012-03-02 06:45 - 2012-03-02 06:44 - 0000000 ____D C:\Program Files (x86)\Google 2012-03-02 06:44 - 2012-03-02 06:44 - 0414368 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-03-02 06:43 - 2012-03-02 06:43 - 0000000 ____D C:\Windows\System32\Macromed 2012-03-02 06:39 - 2009-07-13 22:20 - 0000000 ____D C:\Windows\System32\config\TxR 2012-03-02 05:15 - 2009-07-14 02:44 - 0000000 ___RD C:\Users\Public\Recorded TV 2012-03-02 05:14 - 2011-05-24 15:14 - 0000000 __RHD C:\MSOCache 2012-02-29 21:04 - 2012-02-28 05:18 - 0001111 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-02-29 21:04 - 2012-02-28 05:18 - 0001111 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk 2012-02-29 20:57 - 2012-02-29 20:57 - 0065536 __ASH C:\Windows\System32\config\components{65a45370-5cf0-11e1-bcdf-842b2b8535fb}.TxR.blf 2012-02-29 20:22 - 2012-02-03 21:58 - 0000000 ____D C:\Users\gabcon\Local Settings\Mixxx 2012-02-29 20:22 - 2012-02-03 21:58 - 0000000 ____D C:\Users\gabcon\Local Settings\Application Data\Mixxx 2012-02-29 20:22 - 2012-02-03 21:58 - 0000000 ____D C:\Users\gabcon\AppData\Local\Mixxx 2012-02-28 19:47 - 2012-02-28 19:47 - 0016822 ____A C:\Users\gabcon\My Documents\Finn Conle2.docx 2012-02-28 19:47 - 2012-02-28 19:47 - 0016822 ____A C:\Users\gabcon\Documents\Finn Conle2.docx 2012-02-27 11:14 - 2012-02-26 18:55 - 0021879 ____A C:\Users\gabcon\My Documents\Balloon.docx 2012-02-27 11:14 - 2012-02-26 18:55 - 0021879 ____A C:\Users\gabcon\Documents\Balloon.docx 2012-02-23 15:00 - 2011-12-04 14:27 - 0746910 ____A C:\Windows\SysWOW64\PerfStringBackup.INI 2012-02-22 04:19 - 2009-07-13 22:20 - 0000000 ____D C:\Windows\rescache 2012-02-22 03:05 - 2009-07-13 22:20 - 0000000 ____D C:\Windows\PolicyDefinitions 2012-02-22 03:03 - 2012-02-22 03:00 - 0003900 ____A C:\Windows\IE9_main.log 2012-02-22 03:02 - 2012-02-22 03:02 - 9705472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 3695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2012-02-22 03:02 - 2012-02-22 03:02 - 3695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2012-02-22 03:02 - 2012-02-22 03:02 - 2382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-02-22 03:02 - 2012-02-22 03:02 - 2382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-02-22 03:02 - 2012-02-22 03:02 - 2308096 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 2144256 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 1798656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 1792000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 17790464 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 1493504 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-02-22 03:02 - 2012-02-22 03:02 - 1427456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-02-22 03:02 - 2012-02-22 03:02 - 1390080 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 1345536 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 12282368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 1127424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 1103360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 10887168 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0697344 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0603648 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0580608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0534528 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0452608 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0448512 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2012-02-22 03:02 - 2012-02-22 03:02 - 0434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0403248 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2012-02-22 03:02 - 2012-02-22 03:02 - 0353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0282112 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0267776 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0249344 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0222208 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0165888 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0160256 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0160256 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0145920 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0135168 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0114176 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0111616 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0103936 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0096256 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0091648 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0089088 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0089088 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0085504 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0082432 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0076800 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2012-02-22 03:02 - 2012-02-22 03:02 - 0074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0072822 ____A C:\Windows\SysWOW64\ieuinit.inf 2012-02-22 03:02 - 2012-02-22 03:02 - 0072822 ____A C:\Windows\System32\ieuinit.inf 2012-02-22 03:02 - 2012-02-22 03:02 - 0072704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0065024 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2012-02-22 03:02 - 2012-02-22 03:02 - 0055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0049664 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0030720 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2012-02-22 03:02 - 2012-02-22 03:02 - 0012288 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2012-02-22 03:02 - 2012-02-22 03:02 - 0010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2012-02-21 20:41 - 2012-02-21 20:41 - 0000000 ____D C:\Windows\Sun 2012-02-16 06:47 - 2011-04-15 10:05 - 0000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2012-02-16 06:46 - 2009-07-13 22:20 - 0000000 ____D C:\Windows\System32\sysprep 2012-02-15 17:49 - 2012-02-15 17:49 - 0026249 ____A C:\Users\gabcon\My Documents\lab.docx 2012-02-15 17:49 - 2012-02-15 17:49 - 0026249 ____A C:\Users\gabcon\Documents\lab.docx 2012-02-15 15:42 - 2011-05-24 13:53 - 0000402 __ASH C:\Users\gabcon\My Documents\desktop.ini 2012-02-15 15:42 - 2011-05-24 13:53 - 0000174 ___SH C:\Users\gabcon\Start Menu\Programs\Startup\desktop.ini 2012-02-15 15:42 - 2011-05-24 13:53 - 0000174 ___SH C:\Users\gabcon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini 2012-02-15 03:27 - 2009-07-13 23:45 - 0416792 ____A C:\Windows\System32\FNTCACHE.DAT 2012-02-15 03:08 - 2011-05-24 15:14 - 0000000 ____D C:\Users\All Users\Microsoft Help 2012-02-15 03:08 - 2011-05-24 15:14 - 0000000 ____D C:\Users\All Users\Application Data\Microsoft Help 2012-02-15 03:08 - 2011-05-24 15:14 - 0000000 ____D C:\ProgramData\Microsoft Help 2012-02-13 08:20 - 2011-06-23 17:15 - 0000000 ____D C:\Users\gabcon\Local Settings\Microsoft Games 2012-02-13 08:20 - 2011-06-23 17:15 - 0000000 ____D C:\Users\gabcon\Local Settings\Application Data\Microsoft Games 2012-02-13 08:20 - 2011-06-23 17:15 - 0000000 ____D C:\Users\gabcon\AppData\Local\Microsoft Games 2012-02-12 11:30 - 2012-02-12 11:30 - 0023884 ____A C:\Users\gabcon\My Documents\isolationism.docx 2012-02-12 11:30 - 2012-02-12 11:30 - 0023884 ____A C:\Users\gabcon\Documents\isolationism.docx 2012-02-12 11:28 - 2012-02-12 11:28 - 0022821 ____A C:\Users\gabcon\My Documents\question #8 notes.docx 2012-02-12 11:28 - 2012-02-12 11:28 - 0022821 ____A C:\Users\gabcon\Documents\question #8 notes.docx 2012-02-11 10:41 - 2009-07-13 22:20 - 0000000 ____D C:\Windows\System32\NDF 2012-02-10 16:16 - 2011-12-15 07:30 - 0000000 ____D C:\Program Files (x86)\World of Warcraft 2012-02-03 22:06 - 2011-05-24 13:50 - 0000000 ____D C:\Users\gabcon\AppData\LocalLow 2012-02-03 21:57 - 2012-02-03 21:57 - 0001831 ____A C:\Users\Public\Desktop\Mixxx.lnk 2012-02-03 21:57 - 2012-02-03 21:57 - 0001831 ____A C:\Users\All Users\Desktop\Mixxx.lnk 2012-02-03 21:57 - 2012-02-03 21:57 - 0000000 ____D C:\Program Files (x86)\Mixxx 2012-02-03 21:56 - 2012-02-03 21:56 - 0002408 ____A C:\Users\Public\Desktop\Babylon.lnk 2012-02-03 21:56 - 2012-02-03 21:56 - 0002408 ____A C:\Users\All Users\Desktop\Babylon.lnk 2012-02-03 21:56 - 2012-02-03 21:56 - 0001492 ____A C:\user.js 2012-02-03 21:56 - 2012-02-03 21:56 - 0000000 ____D C:\Users\gabcon\Local Settings\I Want This 2012-02-03 21:56 - 2012-02-03 21:56 - 0000000 ____D C:\Users\gabcon\Local Settings\Babylon 2012-02-03 21:56 - 2012-02-03 21:56 - 0000000 ____D C:\Users\gabcon\Local Settings\Application Data\I Want This 2012-02-03 21:56 - 2012-02-03 21:56 - 0000000 ____D C:\Users\gabcon\Local Settings\Application Data\Babylon 2012-02-03 21:56 - 2012-02-03 21:56 - 0000000 ____D C:\Users\gabcon\Application Data\Babylon 2012-02-03 21:56 - 2012-02-03 21:56 - 0000000 ____D C:\Users\gabcon\AppData\Roaming\Babylon 2012-02-03 21:56 - 2012-02-03 21:56 - 0000000 ____D C:\Users\gabcon\AppData\Local\I Want This 2012-02-03 21:56 - 2012-02-03 21:56 - 0000000 ____D C:\Users\gabcon\AppData\Local\Babylon 2012-02-03 21:56 - 2012-02-03 21:56 - 0000000 ____D C:\Users\All Users\Babylon 2012-02-03 21:56 - 2012-02-03 21:56 - 0000000 ____D C:\Users\All Users\Application Data\Babylon 2012-02-03 21:56 - 2012-02-03 21:56 - 0000000 ____D C:\ProgramData\Babylon 2012-02-03 21:56 - 2012-02-03 21:56 - 0000000 ____D C:\Program Files (x86)\BabylonToolbar 2012-01-31 07:44 - 2011-12-04 14:34 - 0279656 ____A (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe 2012-01-24 21:31 - 2011-05-25 13:06 - 0000000 ____D C:\Users\gabcon\My Documents\Outlook Files 2012-01-24 21:31 - 2011-05-25 13:06 - 0000000 ____D C:\Users\gabcon\Documents\Outlook Files 2012-01-23 21:10 - 2012-01-23 21:10 - 0018272 ____A C:\Users\gabcon\My Documents\dedication.docx 2012-01-23 21:10 - 2012-01-23 21:10 - 0018272 ____A C:\Users\gabcon\Documents\dedication.docx 2012-01-23 20:47 - 2012-01-23 20:47 - 0018431 ____A C:\Users\gabcon\My Documents\Introduction.docx 2012-01-23 20:47 - 2012-01-23 20:47 - 0018431 ____A C:\Users\gabcon\Documents\Introduction.docx 2012-01-23 18:13 - 2011-12-07 17:11 - 0026266 ____A C:\Users\gabcon\My Documents\Family Tradition.docx 2012-01-23 18:13 - 2011-12-07 17:11 - 0026266 ____A C:\Users\gabcon\Documents\Family Tradition.docx 2012-01-23 18:04 - 2011-11-30 19:13 - 0026924 ____A C:\Users\gabcon\My Documents\Family Bio #1.docx 2012-01-23 18:04 - 2011-11-30 19:13 - 0026924 ____A C:\Users\gabcon\Documents\Family Bio #1.docx 2012-01-23 09:15 - 2012-01-23 09:15 - 0014889 ____A C:\Users\gabcon\My Documents\Finn Conle1.docx 2012-01-23 09:15 - 2012-01-23 09:15 - 0014889 ____A C:\Users\gabcon\Documents\Finn Conle1.docx 2012-01-22 11:45 - 2011-07-29 19:03 - 0000000 ____D C:\Users\Finn\Tracing 2012-01-22 11:42 - 2011-12-20 07:14 - 0021275 ____A C:\Users\gabcon\My Documents\crest.docx 2012-01-22 11:42 - 2011-12-20 07:14 - 0021275 ____A C:\Users\gabcon\Documents\crest.docx 2012-01-22 11:38 - 2012-01-04 22:59 - 0027174 ____A C:\Users\gabcon\My Documents\Family Bio #2 Dad.docx 2012-01-22 11:38 - 2012-01-04 22:59 - 0027174 ____A C:\Users\gabcon\Documents\Family Bio #2 Dad.docx 2012-01-22 11:24 - 2011-12-31 11:13 - 0026350 ____A C:\Users\gabcon\My Documents\all about me.docx 2012-01-22 11:24 - 2011-12-31 11:13 - 0026350 ____A C:\Users\gabcon\Documents\all about me.docx 2012-01-17 20:06 - 2012-01-17 20:06 - 0784431 ____A C:\Users\gabcon\My Documents\theme.docx 2012-01-17 20:06 - 2012-01-17 20:06 - 0784431 ____A C:\Users\gabcon\Documents\theme.docx 2012-01-16 14:01 - 2012-01-16 14:01 - 0062395 ____A C:\Users\gabcon\My Documents\Nuclear Energy.docx 2012-01-16 14:01 - 2012-01-16 14:01 - 0062395 ____A C:\Users\gabcon\Documents\Nuclear Energy.docx 2012-01-13 23:02 - 2012-02-14 21:53 - 3143168 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-01-12 16:16 - 2012-01-05 21:04 - 0023583 ____A C:\Users\gabcon\My Documents\Two Were Left.docx 2012-01-12 16:16 - 2012-01-05 21:04 - 0023583 ____A C:\Users\gabcon\Documents\Two Were Left.docx 2012-01-06 11:51 - 2011-11-18 12:02 - 0045568 ____A (iolo technologies, LLC) C:\Windows\System32\iolobtdfg.exe 2012-01-06 11:51 - 2011-11-18 12:02 - 0014848 ____A (iolo technologies, LLC) C:\Windows\System32\smrgdf.exe 2012-01-06 11:29 - 2011-11-18 12:02 - 2141832 ____A (iolo technologies, LLC) C:\Windows\System32\Incinerator64.dll 2012-01-06 11:29 - 2011-11-18 12:02 - 2083464 ____A (iolo technologies, LLC) C:\Windows\SysWOW64\Incinerator32.dll 2012-01-04 18:22 - 2012-01-04 18:22 - 0015190 ____A C:\Users\gabcon\My Documents\Doc2.docx 2012-01-04 18:22 - 2012-01-04 18:22 - 0015190 ____A C:\Users\gabcon\Documents\Doc2.docx 2012-01-04 04:59 - 2012-02-14 21:55 - 14164480 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2012-01-04 04:58 - 2012-02-14 21:55 - 0509952 ____A (Microsoft Corporation) C:\Windows\System32\ntshrui.dll 2012-01-04 04:03 - 2012-02-14 21:55 - 12868096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2012-01-04 04:03 - 2012-02-14 21:53 - 0442880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll 2012-01-03 01:24 - 2012-02-14 21:53 - 0515584 ____A (Microsoft Corporation) C:\Windows\System32\timedate.cpl 2012-01-03 00:44 - 2012-02-14 21:53 - 0478208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl 2011-12-31 20:04 - 2011-12-31 20:04 - 0000000 ____D C:\Users\gabcon\Local Settings\Facebook 2011-12-31 20:04 - 2011-12-31 20:04 - 0000000 ____D C:\Users\gabcon\Local Settings\Application Data\Facebook 2011-12-31 20:04 - 2011-12-31 20:04 - 0000000 ____D C:\Users\gabcon\AppData\Local\Facebook 2011-12-27 22:59 - 2012-02-14 21:53 - 0499200 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\afd.sys 2011-12-27 18:00 - 2011-05-30 16:27 - 0000000 ____D C:\Users\gabcon\Application Data\Skype 2011-12-27 18:00 - 2011-05-30 16:27 - 0000000 ____D C:\Users\gabcon\AppData\Roaming\Skype 2011-12-27 17:41 - 2011-12-27 17:41 - 0000000 ____D C:\Users\gabcon\Local Settings\Application Data\AOL 2011-12-27 17:41 - 2011-12-27 17:41 - 0000000 ____D C:\Users\gabcon\Local Settings\Application Data\AIM 2011-12-27 17:41 - 2011-12-27 17:41 - 0000000 ____D C:\Users\gabcon\Local Settings\AOL 2011-12-27 17:41 - 2011-12-27 17:41 - 0000000 ____D C:\Users\gabcon\Local Settings\AIM 2011-12-27 17:41 - 2011-12-27 17:41 - 0000000 ____D C:\Users\gabcon\Application Data\acccore 2011-12-27 17:41 - 2011-12-27 17:41 - 0000000 ____D C:\Users\gabcon\AppData\Roaming\acccore 2011-12-27 17:41 - 2011-12-27 17:41 - 0000000 ____D C:\Users\gabcon\AppData\Local\AOL 2011-12-27 17:41 - 2011-12-27 17:41 - 0000000 ____D C:\Users\gabcon\AppData\Local\AIM 2011-12-27 17:41 - 2011-12-27 17:41 - 0000000 ____D C:\Users\All Users\Application Data\AIM 2011-12-27 17:41 - 2011-12-27 17:41 - 0000000 ____D C:\Users\All Users\AIM 2011-12-27 17:41 - 2011-12-27 17:41 - 0000000 ____D C:\ProgramData\AIM 2011-12-27 17:41 - 2011-12-27 17:41 - 0000000 ____D C:\Program Files (x86)\AIM 2011-12-27 17:41 - 2011-12-27 17:40 - 0000363 ___AH C:\IPH.PH ========================= Known DLLs (Whitelisted) ============ ========================= Bamital & volsnap Check ============ C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ========================= Memory info ====================== Percentage of memory in use: 14% Total physical RAM: 3835.95 MB Available physical RAM: 3263.38 MB Total Pagefile: 3834.1 MB Available Pagefile: 3248.4 MB Total Virtual: 8192 MB Available Virtual: 8191.9 MB ======================= Partitions ========================= 1 Drive c: (OS) (Fixed) (Total:916.83 GB) (Free:845.55 GB) NTFS 2 Drive d: (MSSS_Media64) (CDROM) (Total:0.24 GB) (Free:0 GB) UDF 3 Drive e: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:6.67 GB) NTFS ==>[System with boot components (obtained from reading drive)] 4 Drive f: (LUZER) (Removable) (Total:3.76 GB) (Free:0.85 GB) FAT32 5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Disk ### Status Size Free Dyn Gpt ——– ————- ——- ——- — — Disk 0 Online 931 GB 0 B Disk 1 Online 3853 MB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 OEM 39 MB 31 KB Partition 2 Primary 14 GB 39 MB Partition 3 Primary 916 GB 14 GB ================================================================================ ====================== Disk: 0 Partition 1 Type : DE Hidden: Yes Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 4 FAT Partition 39 MB Healthy Hidden ================================================================================ ====================== Disk: 0 Partition 2 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 E RECOVERY NTFS Partition 14 GB Healthy ================================================================================ ====================== Disk: 0 Partition 3 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 C OS NTFS Partition 916 GB Healthy ================================================================================ ====================== Partitions of Disk 1: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 3853 MB 31 KB ================================================================================ ====================== Disk: 1 Partition 1 Type : 0C Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 F LUZER FAT32 Removable 3853 MB Healthy ================================================================================ ====================== ========================================================== TDL4: custom:26000022 ========================================================== Last Boot: 2012-03-02 10:18 ======================= End Of Log ==========================
Hi

Please do the following:


Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste). Save it on the flashdrive as fixlist.txt

start
SubSystems: [Windows] ==> ZeroAccess
cmd: bootrec /FixMbr
TDL4: custom:26000022
end

NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system

Now please enter System Recovery Options then select Command Prompt

Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Now restart, let it boot normally and tell me how it went.
Thank you, that worked and I was able to boot back up successfully. Here is the fixlog: Fix result of Farbar Recovery Scan Tool (FRST written by farbar) Version: 15-03-2012 Ran by [removed] at 2012-03-20 07:18:56 R:1 Running from F:\ ============================================== HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Session Manager\SubSystems\\Windows Value was restored. ========= bootrec /FixMbr ========= ÿþT h e o p e r a t i o n c o m p l e t e d s u c c e s s f u l l y . ========= End of CMD: ========= The operation completed successfully. The operation completed successfully. ==== End of Fixlog ====

Thank you, that worked and I was able to boot back up successfully. Here is the fixlog:

Fix result of Farbar Recovery Scan Tool (FRST written by farbar) Version: 15-03-2012
Ran by [removed] at 2012-03-20 07:18:56 R:1
Running from F:\

==============================================

HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Session Manager\SubSystems\\Windows Value was restored.

========= bootrec /FixMbr =========

ÿþT h e o p e r a t i o n c o m p l e t e d s u c c e s s f u l l y .

========= End of CMD: =========


The operation completed successfully.
The operation completed successfully.

==== End of Fixlog ====


Sorry just to add to the results of the FRST64 above, I don't seem to get redirected in Google anymore. Nevertheless, here is an OTL for you:

OTL logfile created on: 3/20/2012 7:33:14 AM - Run 1
OTL by OldTimer - Version 3.2.39.1 Folder = C:\Users\gabcon\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 44.77% Memory free
7.49 Gb Paging File | 4.82 Gb Available in Paging File | 64.29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.83 Gb Total Space | 845.24 Gb Free Space | 92.19% Space Free | Partition Type: NTFS
Drive D: | 241.14 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 3.76 Gb Total Space | 0.85 Gb Free Space | 22.51% Space Free | Partition Type: FAT32

Computer Name: GABCON-PC | User Name: gabcon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\gabcon\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11f_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
PRC - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
PRC - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
PRC - C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe (Sensible Vision )
PRC - C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
PRC - c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe (Sensible Vision )
PRC - C:\Program Files (x86)\Multimedia Card Reader(6366)\ShwiconXP6366.exe (Alcor Micro Corp.)
PRC - C:\Program Files (x86)\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe (Hewlett-Packard Development Co. L.P.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\a25e06e527720656434230d3ee420427\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\6954c7f14ea634672cdacf2cd793497e\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8435718626a24beaeefc98d45ae77127\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ff30db6905f8ec024fc808ed8779c0f3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\a09ee392fa90849f2e9313a1ebbe0279\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\c0508b05f5c28e37711f447a66368e75\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\585ac5899ab444221c8b41df13b194bc\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d49f4cb0755ccc34cd35ff96dc2ef9e3\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\15742b3597258ce67cbe219005c197e5\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\1f14b3e1ee0847f8662f513e67f92547\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\QtCore4.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\libumajin.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\QtGui4.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\SftBRCCPiped.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STBRCCServCLR.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\libxml2.dll ()
MOD - C:\Windows\SysWOW64\FAIEExtension.dll ()
MOD - C:\Windows\SysWOW64\FAib.dll ()
MOD - C:\Windows\SysWOW64\FACrashRpt.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (mfevtp) – C:\Program Files\Common Files\mcafee\systemcore\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (McODS) – C:\Program Files\mcafee\virusscan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (McProxy) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McOobeSv) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (DellOSDservice) – C:\Program Files\Dell\OSD\DellOSDservice.exe (Microsoft)
SRV:64bit: - (wltrysvc) – C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (Dell Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ioloSystemService) – C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
SRV - (SupportDockService.exe) – C:\Program Files (x86)\iYogi Support Dock\Services\CommAgent\SupportDockService.exe (iYogi Technical Services)
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\615\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FAService) – c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe (Sensible Vision )
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe (WildTangent, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfenlfk) – C:\Windows\SysNative\drivers\mfenlfk.sys (McAfee, Inc.)
DRV:64bit: - (cfwids) – C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) – c:\Program Files\Dell Support Center\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (nuviocir) – C:\Windows\SysNative\drivers\nuviocir_win7_x64.sys (Nuvoton Technology Corp.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie64.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BcmVWL) – C:\Windows\SysNative\drivers\bcmvwl64.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (ElRawDisk) – C:\Windows\SysNative\drivers\ElRawDsk.sys (EldoS Corporation)
DRV:64bit: - (FACAP) – C:\Windows\SysNative\drivers\facap.sys (Sensible Vision )
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (MpKslce43b409) – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{33A5EDBD-705D-4133-B07B-BC7BEDDB5F8E}\MpKslce43b409.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {545AFDF0-8E90-4A10-A2F5-2B3446ABCB31}
IE:64bit: - HKLM\..\SearchScopes\{545AFDF0-8E90-4A10-A2F5-2B3446ABCB31}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes,DefaultScope = {BE050599-7E7E-4E14-8F5F-F389AE02B2FD}
IE - HKLM\..\SearchScopes\{BE050599-7E7E-4E14-8F5F-F389AE02B2FD}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
IE - HKCU\..\SearchScopes,DefaultScope = {BE050599-7E7E-4E14-8F5F-F389AE02B2FD}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2011/04/15 10:40:08 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2011/04/15 10:40:08 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\gabcon\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\gabcon\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\gabcon\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\electronicarts.com/GameFacePlugin: C:\Users\gabcon\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/07/19 10:43:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/02/24 11:20:22 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/07/19 10:43:24 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\gabcon\AppData\Local\Google\Chrome\Application\17.0.963.79\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.250.6 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U25 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\gabcon\AppData\Local\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\gabcon\AppData\Local\Google\Chrome\Application\17.0.963.79\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\gabcon\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Game Face Plugin (Enabled) = C:\Users\gabcon\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~2\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\gabcon\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: Poppit = C:\Users\gabcon\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\

O1 HOSTS File: ([2012/03/12 07:55:11 | 000,000,855 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 94.63.147.17 www.bing.com
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20120223202634.dll (McAfee, Inc.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20120223202634.dll (McAfee, Inc.)
O2 - BHO: (FAIESSOHelper Class) - {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll (Sensible Vision )
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RunDLLEntry_EptMon] C:\Windows\SysNative\EptMon64.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [RunDLLEntry_THXCfg] C:\Windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [FAStartup] File not found
O4 - HKLM..\Run: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
O4 - HKLM..\Run: [iolo Startup] C:\Program Files (x86)\iolo\Common\Lib\ioloLManager.exe (iolo technologies, LLC)
O4 - HKLM..\Run: [iYogi Support Dock] C:\Program Files (x86)\iYogi Support Dock\iYogiSupportDock.exe ()
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [ShwiconXP6366] c:\Program Files (x86)\Multimedia Card Reader(6366)\ShwiconXP6366.exe (Alcor Micro Corp.)
O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [THX Audio Control Panel] C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Facebook Update] C:\Users\gabcon\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Update] C:\Windows\SysWow64\config\systemprofile\AppData\Roaming\Adobe\Adobe\klzgc.dll (eMajix.com, Inc.)
O4 - HKLM..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe (Dell)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: rexplorer.net ([]* in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} http://support.rexplorer.net/iftw_install//iftwclix.cab (Reg Error: Key error.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1B27BA64-2B63-470A-B5B5-6EF887544C0A}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\cozi - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\615\G2AWinLogon_x64.dll) - C:\Program Files (x86)\Citrix\GoToAssist\615\g2awinlogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\FastAccess: DllName - (c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll) - c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll ()
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (autocheck smrgdf C:\Users\gabcon\AppData\Roaming\iolo\)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/03/20 07:34:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/03/20 07:32:10 | 000,594,432 | —- | C] (OldTimer Tools) – C:\Users\gabcon\Desktop\OTL.exe
[2012/03/19 19:08:33 | 000,000,000 | —D | C] – C:\FRST
[2012/03/17 13:13:55 | 000,000,000 | —D | C] – C:\Windows\Microsoft Antimalware
[2012/03/12 19:57:56 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\svchost.exe
[2012/03/02 07:45:20 | 000,000,000 | —D | C] – C:\Program Files\Google
[2012/03/02 07:44:06 | 000,000,000 | —D | C] – C:\ProgramData\Google
[2012/03/02 07:44:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2012/03/02 07:44:04 | 000,414,368 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/03/02 07:43:46 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2012/02/22 04:02:50 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/02/22 04:02:50 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/02/22 04:02:50 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2012/02/22 04:02:50 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2012/02/22 04:02:50 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2012/02/22 04:02:50 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2012/02/22 04:02:50 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2012/02/22 04:02:50 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2012/02/22 04:02:50 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2012/02/22 04:02:50 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2012/02/22 04:02:50 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2012/02/22 04:02:49 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2012/02/22 04:02:49 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/02/22 04:02:49 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2012/02/22 04:02:49 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2012/02/22 04:02:49 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/02/22 04:02:49 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2012/02/22 04:02:49 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2012/02/22 04:02:49 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2012/02/22 04:02:49 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2012/02/22 04:02:49 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/02/22 04:02:49 | 000,123,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2012/02/22 04:02:49 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2012/02/22 04:02:49 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2012/02/22 04:02:49 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2012/02/22 04:02:49 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2012/02/22 04:02:49 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/02/22 04:02:49 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2012/02/22 04:02:49 | 000,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2012/02/22 04:02:49 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2012/02/22 04:02:49 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2012/02/22 04:02:49 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2012/02/22 04:02:48 | 002,308,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/02/22 04:02:48 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/02/22 04:02:48 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2012/02/22 04:02:48 | 000,222,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2012/02/22 04:02:48 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2012/02/22 04:02:48 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/02/22 04:02:48 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2012/02/22 04:02:48 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2012/02/22 04:02:48 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2012/02/22 04:02:48 | 000,145,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2012/02/22 04:02:48 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2012/02/22 04:02:48 | 000,114,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2012/02/22 04:02:48 | 000,111,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2012/02/22 04:02:48 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2012/02/22 04:02:48 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2012/02/22 04:02:48 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2012/02/22 04:02:48 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2012/02/22 04:02:48 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2012/02/22 04:02:48 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2012/02/22 04:02:48 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2012/02/22 04:02:47 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2012/02/22 04:02:47 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/02/22 04:02:47 | 000,697,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/02/22 04:02:47 | 000,603,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/02/22 04:02:47 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2012/02/22 04:02:47 | 000,452,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2012/02/22 04:02:47 | 000,448,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2012/02/22 04:02:47 | 000,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2012/02/22 04:02:47 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/02/22 04:02:47 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/02/22 04:02:47 | 000,165,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2012/02/22 04:02:47 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2012/02/22 04:02:47 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2012/02/22 04:02:47 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/02/22 04:02:47 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2012/02/22 04:02:47 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2012/02/22 04:02:47 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2012/02/22 04:02:47 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2012/02/22 04:02:47 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2012/02/22 04:02:47 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2012/02/21 21:41:13 | 000,000,000 | —D | C] – C:\Windows\Sun

========== Files - Modified Within 30 Days ==========

[2012/03/20 07:42:46 | 000,000,422 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2012/03/20 07:31:48 | 000,594,432 | —- | M] (OldTimer Tools) – C:\Users\gabcon\Desktop\OTL.exe
[2012/03/20 07:31:17 | 000,733,968 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/03/20 07:31:17 | 000,629,204 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/03/20 07:31:17 | 000,108,420 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/03/20 07:27:33 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/20 07:27:33 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/20 07:23:57 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/20 07:20:12 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/03/20 07:19:51 | 3016,712,192 | -HS- | M] () – C:\hiberfil.sys
[2012/03/17 11:52:56 | 000,183,791 | —- | M] () – C:\Users\gabcon\AppData\Local\census.cache
[2012/03/17 11:52:45 | 000,104,595 | —- | M] () – C:\Users\gabcon\AppData\Local\ars.cache
[2012/03/17 09:34:24 | 000,000,036 | —- | M] () – C:\Users\gabcon\AppData\Local\housecall.guid.cache
[2012/03/12 20:02:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001UA.job
[2012/03/12 19:59:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/12 18:03:15 | 000,002,407 | —- | M] () – C:\Users\gabcon\Desktop\Google Chrome.lnk
[2012/03/12 17:09:00 | 000,000,932 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001UA.job
[2012/03/12 16:02:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001Core.job
[2012/03/12 07:55:11 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/03/11 20:09:00 | 000,000,910 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001Core.job
[2012/03/03 21:02:37 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2012/03/02 08:22:25 | 000,002,221 | —- | M] () – C:\Users\gabcon\Desktop\System Mechanic.lnk
[2012/03/02 07:44:04 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/02/29 22:04:34 | 000,001,111 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/23 16:00:06 | 000,746,910 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/02/22 07:03:27 | 000,001,439 | —- | M] () – C:\Users\gabcon\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/22 04:02:50 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/02/22 04:02:50 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/02/22 04:02:50 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2012/02/22 04:02:50 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2012/02/22 04:02:50 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2012/02/22 04:02:50 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2012/02/22 04:02:50 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2012/02/22 04:02:50 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2012/02/22 04:02:50 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2012/02/22 04:02:50 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2012/02/22 04:02:50 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2012/02/22 04:02:49 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2012/02/22 04:02:49 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/02/22 04:02:49 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2012/02/22 04:02:49 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2012/02/22 04:02:49 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/02/22 04:02:49 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2012/02/22 04:02:49 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2012/02/22 04:02:49 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2012/02/22 04:02:49 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2012/02/22 04:02:49 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/02/22 04:02:49 | 000,123,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2012/02/22 04:02:49 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2012/02/22 04:02:49 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2012/02/22 04:02:49 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2012/02/22 04:02:49 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2012/02/22 04:02:49 | 000,072,822 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2012/02/22 04:02:49 | 000,072,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/02/22 04:02:49 | 000,066,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2012/02/22 04:02:49 | 000,063,488 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2012/02/22 04:02:49 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2012/02/22 04:02:49 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2012/02/22 04:02:49 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2012/02/22 04:02:48 | 002,308,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/02/22 04:02:48 | 000,818,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/02/22 04:02:48 | 000,267,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2012/02/22 04:02:48 | 000,248,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/02/22 04:02:48 | 000,222,208 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2012/02/22 04:02:48 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2012/02/22 04:02:48 | 000,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/02/22 04:02:48 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2012/02/22 04:02:48 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2012/02/22 04:02:48 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2012/02/22 04:02:48 | 000,145,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2012/02/22 04:02:48 | 000,135,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2012/02/22 04:02:48 | 000,114,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2012/02/22 04:02:48 | 000,111,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2012/02/22 04:02:48 | 000,091,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2012/02/22 04:02:48 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2012/02/22 04:02:48 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2012/02/22 04:02:48 | 000,049,664 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2012/02/22 04:02:48 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2012/02/22 04:02:48 | 000,012,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2012/02/22 04:02:48 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2012/02/22 04:02:47 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2012/02/22 04:02:47 | 001,493,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/02/22 04:02:47 | 000,697,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/02/22 04:02:47 | 000,603,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/02/22 04:02:47 | 000,534,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2012/02/22 04:02:47 | 000,452,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2012/02/22 04:02:47 | 000,448,512 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2012/02/22 04:02:47 | 000,282,112 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2012/02/22 04:02:47 | 000,237,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/02/22 04:02:47 | 000,165,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2012/02/22 04:02:47 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2012/02/22 04:02:47 | 000,103,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2012/02/22 04:02:47 | 000,096,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/02/22 04:02:47 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2012/02/22 04:02:47 | 000,085,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2012/02/22 04:02:47 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2012/02/22 04:02:47 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2012/02/22 04:02:47 | 000,072,822 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2012/02/22 04:02:47 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2012/02/22 04:02:47 | 000,030,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll

========== Files Created - No Company Name ==========

[2012/03/17 11:52:56 | 000,183,791 | —- | C] () – C:\Users\gabcon\AppData\Local\census.cache
[2012/03/17 11:52:45 | 000,104,595 | —- | C] () – C:\Users\gabcon\AppData\Local\ars.cache
[2012/03/17 09:34:24 | 000,000,036 | —- | C] () – C:\Users\gabcon\AppData\Local\housecall.guid.cache
[2012/03/02 07:44:51 | 000,000,898 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/02 07:44:49 | 000,000,894 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/28 06:18:45 | 000,001,111 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/22 04:02:49 | 000,072,822 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2012/02/22 04:02:47 | 000,072,822 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2011/12/04 15:27:21 | 000,746,910 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/11/18 13:00:53 | 000,074,703 | —- | C] () – C:\Windows\SysWow64\mfc45.dll
[2011/07/19 10:37:18 | 000,202,808 | —- | C] () – C:\Windows\hpoins18.dat
[2011/07/19 10:37:18 | 000,005,355 | —- | C] () – C:\Windows\hpomdl18.dat
[2011/04/15 12:31:43 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/04/15 11:06:28 | 000,001,264 | —- | C] () – C:\Windows\THXCfg_SP_APOIM.ini
[2011/04/15 11:06:28 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_HP_APOIM.ini
[2011/04/15 11:06:28 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_APOIM.ini
[2011/04/15 11:06:27 | 000,177,664 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2011/04/15 11:06:27 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2011/02/22 20:15:11 | 000,002,857 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== LOP Check ==========

[2011/12/27 18:41:44 | 000,000,000 | —D | M] – C:\Users\gabcon\AppData\Roaming\acccore
[2012/02/03 22:56:44 | 000,000,000 | —D | M] – C:\Users\gabcon\AppData\Roaming\Babylon
[2011/06/11 10:04:45 | 000,000,000 | —D | M] – C:\Users\gabcon\AppData\Roaming\Electronic Arts
[2011/11/18 13:07:12 | 000,000,000 | —D | M] – C:\Users\gabcon\AppData\Roaming\iolo
[2011/11/18 12:32:49 | 000,000,000 | —D | M] – C:\Users\gabcon\AppData\Roaming\iYogi
[2011/05/24 17:00:36 | 000,000,000 | —D | M] – C:\Users\gabcon\AppData\Roaming\PCDr
[2011/06/01 10:06:05 | 000,000,000 | —D | M] – C:\Users\gabcon\AppData\Roaming\WildTangent
[2012/03/11 20:09:00 | 000,000,910 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001Core.job
[2012/03/12 17:09:00 | 000,000,932 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001UA.job
[2012/03/03 21:02:37 | 000,000,564 | —- | M] () – C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2012/03/12 10:09:07 | 000,032,630 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/03/20 07:42:46 | 000,000,422 | —- | M] () – C:\Windows\Tasks\SystemToolsDailyTest.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2011/04/15 13:20:15 | 000,028,998 | RH– | M] () – C:\dell.sdr
[2012/03/20 07:19:51 | 3016,712,192 | -HS- | M] () – C:\hiberfil.sys
[2011/12/27 18:41:13 | 000,000,363 | -H– | M] () – C:\IPH.PH
[2012/03/20 07:20:14 | 4022,284,288 | -HS- | M] () – C:\pagefile.sys
[2012/02/03 22:56:56 | 000,001,492 | —- | M] () – C:\user.js
[2011/04/15 11:11:32 | 001,177,452 | —- | M] () – C:\vcredist_x86.log

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 13:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/22 07:03:27 | 000,000,221 | -HS- | M] () – C:\Users\gabcon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/03/20 07:31:48 | 000,594,432 | —- | M] (OldTimer Tools) – C:\Users\gabcon\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >

———————————————————-

Here is the Extras:

OTL Extras logfile created on: 3/20/2012 7:33:14 AM - Run 1
OTL by OldTimer - Version 3.2.39.1 Folder = C:\Users\gabcon\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 44.77% Memory free
7.49 Gb Paging File | 4.82 Gb Available in Paging File | 64.29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.83 Gb Total Space | 845.24 Gb Free Space | 92.19% Space Free | Partition Type: NTFS
Drive D: | 241.14 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 3.76 Gb Total Space | 0.85 Gb Free Space | 22.51% Space Free | Partition Type: FAT32

Computer Name: GABCON-PC | User Name: gabcon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{08627866-B869-8C66-C375-14D64CFF448B}" = ccc-utility64
"{17016DA1-F040-4032-BD36-34DD317BC9D5}" = HP Photosmart All-In-One Driver Software 13.0 Rel. A
"{26A24AE4-039D-4CA4-87B4-2F86416023FF}" = Java™ 6 Update 23 (64-bit)
"{277C688D-1948-4CF2-8EFC-6328C6AE85BB}" = SetDisplayConfig
"{42738DB0-FC3E-4672-A99B-9372F5696E30}" = Microsoft Security Client
"{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}" = Bing Maps 3D
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{876F4556-6811-4341-A6D7-78C3F15420E2}" = FastAccess
"{89B91433-49FF-45E6-9B89-02E761A5ACB9}" = DellOSD
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9C98CA38-4C1A-4AC8-B55C-169497C8826B}" = Apple Mobile Device Support
"{9CD0F7D3-B67F-4BF8-8784-D73AD229FF1E}" = iTunes
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"Dell Support Center" = Dell Support Center
"DW WLAN Card Utility" = DW WLAN Card Utility
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Shop for HP Supplies" = Shop for HP Supplies

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{010A785B-F920-4350-821B-6309909C20BB}" = THX TruStudio PC
"{04DA0C9B-0BD8-835A-7BCB-58B4E2F57CED}" = ccc-core-static
"{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}" = Microsoft Visual C++ 2005 Redistributable
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0807242D-4BB5-4F6C-BEA8-EC9D75A51C51}" = Multimedia Card Reader
"{0D6ABC33-35FF-CBCA-595D-2B095BC35C5C}" = CCC Help Polish
"{0DCDDAAC-CB9D-27E5-ED83-CDD88DCCF85F}" = Skins
"{0DEF8C02-2EAB-4BFE-A7E0-7990665DF1A9}" = C6100
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1C1473A1-1A26-4C8F-9548-A52D03066CE7}" = Catalyst Control Center - Branding
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 25
"{27612481-2FDB-E7A6-F76C-68E60F582219}" = CCC Help Swedish
"{2A7EF808-14F3-4E93-BE3A-1675EE5332A4}" = AIO_CDA_ProductContext
"{2DA5F129-11AC-4F11-8188-B2F07EAAC20A}" = Cozi
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FAECEAF-0EBE-48FF-B60A-B4577C0EFDAB}" = CIR Tool Kit
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{309ECB18-F25E-F405-DF6C-8B1B4CEDD11B}" = Catalyst Control Center InstallProxy
"{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}" = Microsoft XNA Framework Redistributable 3.0
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{43CD1466-73DF-5CE8-2FF7-CB33A87CA754}" = CCC Help German
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45F26F68-35F6-12D5-A83D-DE5C39786BA6}" = Catalyst Control Center Graphics Previews Vista
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4AC7B4E7-59B7-4E48-A60D-263C486FC33A}_is1" = System Checkup 3.1
"{4BD5B5D2-406D-4bc5-BB10-2F0D1D367C95}" = c6100_Help
"{4DBA3785-6268-DEE0-BDE4-129776FAE34D}" = CCC Help Finnish
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{5467C8DB-D7D5-411A-B2C7-2639B68627EF}" = StickyNotes
"{55FD1D5A-7AEF-4DA3-8FAF-A71B2A52FFC7}_is1" = iolo technologies' System Mechanic
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5D965998-4756-C622-6785-B3C23BD4F8AC}" = CCC Help Japanese
"{61D7A655-D59B-1312-C69D-4D85082B8836}" = CCC Help Danish
"{624E54D0-E4F4-434F-9EF6-D4D066EE4348}" = Facebook Video Calling 1.1.1.1
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{66F07F97-D1F1-4633-9D0A-C6AD0DC864D9}" = Dell Touch Software Suite Games
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72BF1DA0-2B00-4794-9173-159722019B74}" = CyberLink YouPaint
"{76A65EED-98BF-83CD-2989-97546A94572D}" = CCC Help Spanish
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7FCAED3F-AA2D-7AE1-B367-61723135891D}" = CCC Help Chinese Traditional
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{820B6609-4C97-3A2B-B644-573B06A0F0CC}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89AD7D28-F70D-2F9D-EBB7-771127521063}" = CCC Help Dutch
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8B7B2D54-C5A4-07E0-D92E-462ECB95F352}" = CCC Help Chinese Standard
"{8FF90DB8-6DED-44A3-B182-244FEC09012F}" = Microsoft Touch Pack for Windows 7
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{903679E8-44C8-4C07-9600-05C92654FC50}" = QualxServ Service Agreement
"{92A9F8A5-1EC6-A1EC-18FE-47098D074CFE}" = CCC Help Hungarian
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{A639BD63-8CE6-11D5-B4CC-00105A07274A}" = REXplorer Component Upgrade
"{A65A5ADE-F093-4840-4A52-0E4510ABE00F}" = CCC Help Thai
"{A7AEE29F-839E-46B5-B347-6D430618129F}" = AIO_CDA_Software
"{A81F2341-5207-ADA5-127A-A96CE606BA17}" = CCC Help Turkish
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.2
"{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
"{B2F5F3EA-BB20-BF63-A070-4EFA017F14F0}" = CCC Help Russian
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CCFAD826-D8CA-C72B-52DD-B05167161515}" = CCC Help Italian
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D15718E4-CD90-A107-2FDB-AF770B9AAEA8}" = CCC Help French
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D770F4B4-C422-45D9-8CEE-1B4C66E68CA8}" = Dell Stage
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{DCA8B341-3DA6-7500-C145-4397E1447C4E}" = CCC Help Czech
"{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"{DCE3D214-E9B1-7AFD-85F7-79BA7612C859}" = CCC Help Portuguese
"{DE7B593E-8227-071D-A768-CA3077D225E2}" = CCC Help English
"{E0860139-60E3-FCD8-9081-157839572587}" = CCC Help Greek
"{E0C0979D-05BF-4B3E-0272-602BB817B249}" = Catalyst Control Center Localization All
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E4335E82-17B3-460F-9E70-39D9BC269DB3}" = Dell PhotoStage
"{E9486293-4A94-55A8-A389-B693CFE4E280}" = CCC Help Norwegian
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{EF85FEF4-EB92-4075-A6D2-5F519BB30A2C}" = Accidental Damage Services Agreement
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F161CEF1-E88E-5515-3AB1-F79A016B30AA}" = CCC Help Korean
"{F2B83C93-3F61-8971-7350-1FD2C6C310CC}" = Catalyst Control Center Graphics Previews Common
"{F336F89D-8C5A-432C-8EA9-DA19377AD591}" = Dell MusicStage
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"AIM_7" = AIM 7
"BabylonToolbar" = Babylon toolbar on IE
"Dell Webcam Central" = Dell Webcam Central
"GoToAssist" = GoToAssist Corporate
"InstallShield_{0807242D-4BB5-4F6C-BEA8-EC9D75A51C51}" = Multimedia Card Reader
"InstallShield_{72BF1DA0-2B00-4794-9173-159722019B74}" = CyberLink YouPaint
"InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"iYogi Support Dock" = iYogi Support Dock 5.5.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Mixxx (1.9.0)" = Mixxx 1.9.0
"MSC" = McAfee SecurityCenter
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"WildTangent dell Master Uninstall" = WildTangent Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"World of Warcraft" = World of Warcraft
"Yahoo! Companion" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"EA SPORTS Gameface Browser Plugin" = EA SPORTS Gameface Browser Plugin 1.3.1.0
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/20/2012 7:32:01 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 3028
Description =

Error - 3/20/2012 7:32:01 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 3058
Description =

Error - 3/20/2012 7:32:01 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 7010
Description =

Error - 3/20/2012 7:32:13 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 3057
Description =

Error - 3/20/2012 7:32:14 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 3029
Description =

Error - 3/20/2012 7:32:14 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 3028
Description =

Error - 3/20/2012 7:32:14 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 3058
Description =

Error - 3/20/2012 7:32:14 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 7010
Description =

Error - 3/20/2012 7:40:07 AM | Computer Name = gabcon-PC | Source = PC-Doctor | ID = 1
Description = (3200) Asapi: (07:40:07:0550)(3200) libAsapi.DynamicLoadedPlugin -
Error – 64 Unable to load library 'S3LogPusher.dll'

Error - 3/20/2012 7:40:07 AM | Computer Name = gabcon-PC | Source = PC-Doctor | ID = 1
Description = (3200) Asapi: (07:40:07:0860)(3200) Asapi.State - Error – 123 Plugin
S3LogPusher.dll failed to load.

[ Broadcom Wireless LAN Events ]
Error - 3/15/2012 5:09:59 AM | Computer Name = gabcon-PC | Source = WLAN-Tray | ID = 0
Description = 05:09:59, Thu, Mar 15, 12 Error - Unable to gain access to user store


[ Dell Events ]
Error - 5/24/2011 3:10:20 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 5/24/2011 4:01:20 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 5/24/2011 4:01:20 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 6/23/2011 5:31:33 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 6/23/2011 5:31:33 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 7/7/2011 8:40:59 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 7/7/2011 8:40:59 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 8/25/2011 1:03:07 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 8/25/2011 1:03:07 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 11/6/2011 4:46:28 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

[ System Events ]
Error - 3/20/2012 7:41:34 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7024
Description = The Windows Search service terminated with service-specific error
%%-2147218170.

Error - 3/20/2012 7:41:34 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7034
Description = The Windows Search service terminated unexpectedly. It has done this
28 time(s).

Error - 3/20/2012 7:41:36 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7024
Description = The Windows Search service terminated with service-specific error
%%-2147218170.

Error - 3/20/2012 7:41:36 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7034
Description = The Windows Search service terminated unexpectedly. It has done this
29 time(s).

Error - 3/20/2012 7:41:37 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7024
Description = The Windows Search service terminated with service-specific error
%%-2147218170.

Error - 3/20/2012 7:41:37 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7034
Description = The Windows Search service terminated unexpectedly. It has done this
30 time(s).

Error - 3/20/2012 7:41:39 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7024
Description = The Windows Search service terminated with service-specific error
%%-2147218170.

Error - 3/20/2012 7:41:39 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7034
Description = The Windows Search service terminated unexpectedly. It has done this
31 time(s).

Error - 3/20/2012 7:41:41 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7024
Description = The Windows Search service terminated with service-specific error
%%-2147218170.

Error - 3/20/2012 7:41:41 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7034
Description = The Windows Search service terminated unexpectedly. It has done this
32 time(s).


< End of report >
:thumbup:

Please run the following:

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Here is the Combofix log: ComboFix 12-03-18.04 - gabcon 03/20/2012 9:40.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3836.2291 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\gabcon\GoToAssistDownloadHelper.exe c:\windows\system32\config\systemprofile\AppData\Roaming\Adobe\Adobe\klzgc.dll . . ((((((((((((((((((((((((( Files Created from 2012-02-20 to 2012-03-20 ))))))))))))))))))))))))))))))) . . 2012-03-20 11:30 . 2012-02-11 15:51 927800 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2F54A36F-7AA0-4E49-A8B8-A0F09FB09A1B}\gapaengine.dll 2012-03-20 11:29 . 2012-02-08 03:14 8643640 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0DF9519A-8D34-4118-B161-2D78886212CC}\mpengine.dll 2012-03-19 23:08 . 2012-03-19 23:09 ——– d—–w- C:\FRST 2012-03-17 17:13 . 2012-03-19 19:41 ——– d—–w- c:\windows\Microsoft Antimalware 2012-03-12 23:57 . 2009-07-14 01:14 20480 —-a-w- c:\windows\svchost.exe 2012-03-02 11:45 . 2012-03-02 11:45 ——– d—–w- c:\program files\Google 2012-03-02 11:44 . 2012-03-02 11:45 ——– d—–w- c:\program files (x86)\Google 2012-03-02 11:44 . 2012-03-02 11:44 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-03-02 11:43 . 2012-03-02 11:43 ——– d—–w- c:\windows\system32\Macromed 2012-02-22 01:41 . 2012-02-22 01:41 ——– d—–w- c:\windows\Sun . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-02-11 15:51 . 2012-02-11 15:52 927800 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2012-02-08 07:13 . 2011-12-05 20:27 8643640 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-01-31 12:44 . 2011-12-04 19:34 279656 ——w- c:\windows\system32\MpSigStub.exe 2012-01-14 04:02 . 2012-02-15 02:53 3143168 —-a-w- c:\windows\system32\win32k.sys 2012-01-06 16:51 . 2011-11-18 17:02 45568 —-a-w- c:\windows\system32\iolobtdfg.exe 2012-01-06 16:51 . 2011-11-18 17:02 14848 —-a-w- c:\windows\system32\smrgdf.exe 2012-01-06 16:29 . 2011-11-18 17:02 2141832 —-a-w- c:\windows\system32\Incinerator64.dll 2012-01-06 16:29 . 2011-11-18 17:02 2083464 —-a-w- c:\windows\SysWow64\Incinerator32.dll 2012-01-04 09:58 . 2012-02-15 02:55 509952 —-a-w- c:\windows\system32\ntshrui.dll 2012-01-04 09:03 . 2012-02-15 02:53 442880 —-a-w- c:\windows\SysWow64\ntshrui.dll 2012-01-03 06:24 . 2012-02-15 02:53 515584 —-a-w- c:\windows\system32\timedate.cpl 2012-01-03 05:44 . 2012-02-15 02:53 478208 —-a-w- c:\windows\SysWow64\timedate.cpl 2011-12-28 03:59 . 2012-02-15 02:53 499200 —-a-w- c:\windows\system32\drivers\afd.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072] "Facebook Update"="c:\users\gabcon\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-01-01 137536] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ShwiconXP6366"="c:\program files (x86)\Multimedia Card Reader(6366)\ShwiconXP6366.exe" [2009-07-17 237568] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-22 98304] "FATrayAlert"="c:\program files (x86)\Sensible Vision\Fast Access\FATrayMon.exe" [2010-02-22 95560] "THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" [2009-12-01 963584] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-11-22 1675160] "hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736] "iYogi Support Dock"="c:\program files (x86)\iYogi Support Dock\iYogiSupportDock.exe" [2011-08-30 1576176] "iolo Startup"="c:\program files (x86)\iolo\Common\Lib\ioloLManager.exe" [2012-01-06 606904] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-09-18 560128] "Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe" [2011-01-13 165184] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Update"="c:\windows\system32\config\systemprofile\AppData\Roaming\Adobe\Adobe\klzgc.dll" [2012-03-12 312832] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FastAccess] 2010-02-22 20:24 144712 —-a-w- c:\program files (x86)\Sensible Vision\Fast Access\FALogNot.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck smrgdf c:\users\gabcon\AppData\Roaming\iolo\ . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli FAPassSync . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-02 136176] R2 SupportDockService.exe;Support Dock Service;c:\program files (x86)\iYogi Support Dock\Services\CommAgent\SupportDockService.exe [2011-08-30 73728] R3 FACAP;facap, FastAccess Video Capture;c:\windows\system32\DRIVERS\facap.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-02 136176] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2010-07-30 25072] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys [x] S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 DellOSDservice;DellOSDservice;c:\program files\Dell\OSD\DellOSDservice.exe [2010-07-06 7168] S2 FAService;FAService;c:\program files (x86)\Sensible Vision\Fast Access\FAService.exe [2010-02-22 2409800] S2 ioloSystemService;iolo System Service;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2012-01-06 722616] S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936] S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-10-18 208536] S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2011-10-18 161168] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-01-13 705856] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 BcmVWL;Broadcom Virtual Wireless;c:\windows\system32\DRIVERS\bcmvwl64.sys [x] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x] S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x] S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272] S3 nuviocir;Nuvoton W836x7HG CIR Device Driver;c:\windows\system32\DRIVERS\nuviocir_win7_x64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL *Deregistered* - mfeavfk01 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2012-03-12 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001Core.job - c:\users\gabcon\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-01 01:04] . 2012-03-20 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001UA.job - c:\users\gabcon\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-01 01:04] . 2012-03-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-02 11:44] . 2012-03-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-02 11:44] . 2012-03-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001Core.job - c:\users\gabcon\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-28 14:24] . 2012-03-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001UA.job - c:\users\gabcon\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-28 14:24] . 2012-03-04 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job - c:\program files\Dell Support Center\uaclauncher.exe [2010-08-05 07:47] . 2012-03-20 c:\windows\Tasks\SystemToolsDailyTest.job - c:\program files\Dell Support Center\pcdrcui.exe [2010-08-05 07:47] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-22 10920552] "Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2010-02-02 5712896] "RunDLLEntry_THXCfg"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568] "RunDLLEntry_EptMon"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568] "DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-01-25 1802472] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uInternet Settings,ProxyOverride = *.local Trusted Zone: rexplorer.net TCP: DhcpNameServer = 192.168.0.1 . . ——- File Associations ——- . JSEFile=NOTEPAD.EXE %1 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run-FAStartup - (no file) Wow6432Node-HKU-Default-Run-dplaysvr - c:\windows\system32\config\systemprofile\AppData\Local\dplaysvr.exe Toolbar-Locked - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020101}_0] "ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe c:\program files (x86)\Dell DataSafe Local Backup\Toaster.exe . ************************************************************************** . Completion time: 2012-03-20 09:53:48 - machine was rebooted ComboFix-quarantined-files.txt 2012-03-20 13:53 . Pre-Run: 906,875,785,216 bytes free Post-Run: 908,185,366,528 bytes free . - - End Of File - - CD4CB537DD52BD90F39AE2D44CCA2D61
Hi,

The log is indicting you have more than one AV installed:

AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}

please uninstall one of them, as having more than one AV can cause instability, conflicts and crashes.

Please do the following;

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/index.php?showtopic=122671

Collect::
c:\windows\system32\config\systemprofile\AppData\Roaming\Adobe\Adobe\klzgc.dll

Registry::
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Update"=-
ClearJavaCache::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
I uninstalled both MS Essentials and McAfee. Here is the Combofix after your script: ComboFix 12-03-20.01 - gabcon 03/20/2012 11:46:54.2.2 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3836.2375 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\gabcon\Desktop\CFScript.txt SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\svchost.exe . . ((((((((((((((((((((((((( Files Created from 2012-02-20 to 2012-03-20 ))))))))))))))))))))))))))))))) . . 2012-03-20 15:51 . 2012-03-20 15:51 ——– d—–w- c:\users\Finn\AppData\Local\temp 2012-03-20 15:51 . 2012-03-20 15:51 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-03-19 23:08 . 2012-03-19 23:09 ——– d—–w- C:\FRST 2012-03-17 17:13 . 2012-03-19 19:41 ——– d—–w- c:\windows\Microsoft Antimalware 2012-03-02 11:45 . 2012-03-02 11:45 ——– d—–w- c:\program files\Google 2012-03-02 11:44 . 2012-03-02 11:45 ——– d—–w- c:\program files (x86)\Google 2012-03-02 11:44 . 2012-03-02 11:44 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-03-02 11:43 . 2012-03-02 11:43 ——– d—–w- c:\windows\system32\Macromed 2012-02-22 01:41 . 2012-02-22 01:41 ——– d—–w- c:\windows\Sun . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-01-31 12:44 . 2011-12-04 19:34 279656 ——w- c:\windows\system32\MpSigStub.exe 2012-01-14 04:02 . 2012-02-15 02:53 3143168 —-a-w- c:\windows\system32\win32k.sys 2012-01-06 16:51 . 2011-11-18 17:02 45568 —-a-w- c:\windows\system32\iolobtdfg.exe 2012-01-06 16:51 . 2011-11-18 17:02 14848 —-a-w- c:\windows\system32\smrgdf.exe 2012-01-06 16:29 . 2011-11-18 17:02 2141832 —-a-w- c:\windows\system32\Incinerator64.dll 2012-01-06 16:29 . 2011-11-18 17:02 2083464 —-a-w- c:\windows\SysWow64\Incinerator32.dll 2012-01-04 09:58 . 2012-02-15 02:55 509952 —-a-w- c:\windows\system32\ntshrui.dll 2012-01-04 09:03 . 2012-02-15 02:53 442880 —-a-w- c:\windows\SysWow64\ntshrui.dll 2012-01-03 06:24 . 2012-02-15 02:53 515584 —-a-w- c:\windows\system32\timedate.cpl 2012-01-03 05:44 . 2012-02-15 02:53 478208 —-a-w- c:\windows\SysWow64\timedate.cpl 2011-12-28 03:59 . 2012-02-15 02:53 499200 —-a-w- c:\windows\system32\drivers\afd.sys . . ((((((((((((((((((((((((((((( SnapShot@2012-03-20_13.49.27 ))))))))))))))))))))))))))))))))))))))))) . + 2011-04-15 14:40 . 2012-03-20 15:38 44996 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-03-20 15:38 36112 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-05-24 18:52 . 2012-03-20 15:31 12732 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-681966066-4204787335-1963788685-1001_UserData.bin - 2011-05-24 17:58 . 2012-03-20 11:33 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-05-24 17:58 . 2012-03-20 15:19 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-05-24 17:58 . 2012-03-20 11:33 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2011-05-24 17:58 . 2012-03-20 15:19 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-03-20 11:33 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-03-20 15:19 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:46 . 2012-03-20 13:57 79024 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat + 2012-03-20 15:52 . 2012-03-20 15:52 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2012-03-20 13:48 . 2012-03-20 13:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-03-20 15:52 . 2012-03-20 15:52 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-03-20 13:48 . 2012-03-20 13:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-07-14 04:54 . 2012-03-20 15:29 491520 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2012-03-20 11:20 491520 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 02:36 . 2012-03-20 15:40 627104 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2012-03-20 15:40 107420 c:\windows\system32\perfc009.dat + 2009-07-14 05:01 . 2012-03-20 15:52 387160 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2012-03-20 13:47 387160 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2012-02-24 15:18 . 2012-03-20 13:47 644750 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-681966066-4204787335-1963788685-1001-12288.dat + 2012-02-24 15:18 . 2012-03-20 15:34 644750 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-681966066-4204787335-1963788685-1001-12288.dat + 2009-07-14 04:54 . 2012-03-20 15:29 8060928 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-03-20 11:20 8060928 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2012-02-24 15:18 . 2012-03-20 15:52 1350132 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-681966066-4204787335-1963788685-1001-8192.dat + 2012-02-24 15:18 . 2012-03-20 15:52 6931128 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-681966066-4204787335-1963788685-1001-4096.dat - 2012-02-24 15:18 . 2012-03-20 13:47 6931128 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-681966066-4204787335-1963788685-1001-4096.dat + 2009-07-14 04:54 . 2012-03-20 15:29 16187392 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2012-03-20 11:20 16187392 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072] "Facebook Update"="c:\users\gabcon\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-01-01 137536] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ShwiconXP6366"="c:\program files (x86)\Multimedia Card Reader(6366)\ShwiconXP6366.exe" [2009-07-17 237568] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-22 98304] "FATrayAlert"="c:\program files (x86)\Sensible Vision\Fast Access\FATrayMon.exe" [2010-02-22 95560] "THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" [2009-12-01 963584] "hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736] "iYogi Support Dock"="c:\program files (x86)\iYogi Support Dock\iYogiSupportDock.exe" [2011-08-30 1576176] "iolo Startup"="c:\program files (x86)\iolo\Common\Lib\ioloLManager.exe" [2012-01-06 606904] "FAStartup"="" [BU] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-09-18 560128] "Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe" [2011-01-13 165184] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FastAccess] 2010-02-22 20:24 144712 —-a-w- c:\program files (x86)\Sensible Vision\Fast Access\FALogNot.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli FAPassSync . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-02 136176] R2 SupportDockService.exe;Support Dock Service;c:\program files (x86)\iYogi Support Dock\Services\CommAgent\SupportDockService.exe [2011-08-30 73728] R3 FACAP;facap, FastAccess Video Capture;c:\windows\system32\DRIVERS\facap.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-02 136176] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2010-07-30 25072] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 DellOSDservice;DellOSDservice;c:\program files\Dell\OSD\DellOSDservice.exe [2010-07-06 7168] S2 FAService;FAService;c:\program files (x86)\Sensible Vision\Fast Access\FAService.exe [2010-02-22 2409800] S2 ioloSystemService;iolo System Service;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe [2012-01-06 722616] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-01-13 705856] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 BcmVWL;Broadcom Virtual Wireless;c:\windows\system32\DRIVERS\bcmvwl64.sys [x] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x] S3 nuviocir;Nuvoton W836x7HG CIR Device Driver;c:\windows\system32\DRIVERS\nuviocir_win7_x64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2012-03-12 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001Core.job - c:\users\gabcon\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-01 01:04] . 2012-03-20 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001UA.job - c:\users\gabcon\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-01 01:04] . 2012-03-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-02 11:44] . 2012-03-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-02 11:44] . 2012-03-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001Core.job - c:\users\gabcon\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-28 14:24] . 2012-03-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001UA.job - c:\users\gabcon\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-28 14:24] . 2012-03-04 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job - c:\program files\Dell Support Center\uaclauncher.exe [2010-08-05 07:47] . 2012-03-20 c:\windows\Tasks\SystemToolsDailyTest.job - c:\program files\Dell Support Center\pcdrcui.exe [2010-08-05 07:47] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-22 10920552] "Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2010-02-02 5712896] "RunDLLEntry_THXCfg"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568] "RunDLLEntry_EptMon"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568] "DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-01-25 1802472] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uInternet Settings,ProxyOverride = *.local Trusted Zone: rexplorer.net TCP: DhcpNameServer = 192.168.0.1 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020101}_0] "ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe c:\program files (x86)\Dell DataSafe Local Backup\Toaster.exe . ************************************************************************** . Completion time: 2012-03-20 11:56:41 - machine was rebooted ComboFix-quarantined-files.txt 2012-03-20 15:56 . Pre-Run: 907,910,729,728 bytes free Post-Run: 907,566,428,160 bytes free . - - End Of File - - 0B29365FBFC2EFDA323296BA516D1053 ————————————————————————————————————————————————— Here is the Malwarebytes log: Malwarebytes Anti-Malware 1.60.1.1000 www.malwarebytes.org Database version: v2012.03.20.06 Windows 7 x64 NTFS Internet Explorer 9.0.8112.16421 gabcon :: GABCON-PC [administrator] 3/20/2012 12:04:02 PM mbam-log-2012-03-20 (12-04-02).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 213329 Time elapsed: 3 minute(s), 40 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) —————————————————————————————————————– Here is the ESET log: C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarApp.dll a variant of Win32/Toolbar.Babylon application C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarEng.dll Win32/Toolbar.Babylon application C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarsrv.exe probably a variant of Win32/Toolbar.Babylon application C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll Win32/Toolbar.Babylon application C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll Win32/Toolbar.Babylon application C:\Program Files (x86)\Dell DataSafe Local Backup\hstart.exe a variant of Win32/HiddenStart.A application C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe a variant of Win32/HiddenStart.A application C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\UpdateWorkingDirectory\DSL\hstart.exe a variant of Win32/HiddenStart.A application C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\UpdateWorkingDirectory\DSL\Components\DSUpdate\hstart.exe a variant of Win32/HiddenStart.A application Operating memory Win32/Toolbar.Babylon application
Hi

Go to Start > control panel > programs and features > navigate to the Babylon toolbar > remove

now navigate to the babylon folder

C:\Program Files (x86)\BabylonToolbar\BabylonToolbar

right click and delete it

NEXT


Visit ADOBE and download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 6 and Save it to your Desktop.
  • Scroll down to where it says Java SE 6 Update 31
  • Click the Download button under JRE to the right.
  • Read the License Agreement then select Accept License Agreement
  • Click on the link to download Windows x86 Offline and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u31-windows-i586.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT


Please advise how the computer is running now and if there are any outstanding issues
Worked like a charm, I think the machine is back to normal now. Should I run Combofix /uninstall? Or just delete it from the Desktop now? I am also going to install Avast Home Edition instead along with Spywareblaster and SpywareGuard.
that's good to hear :)

we just need to clean up the tools now, please do the following:


You can delete the FRST logs and program from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI