Win 7 can't even boot up now [Solved]
11 min read
Please try the following:
For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.
Plug the flashdrive into the infected PC.
Enter System Recovery Options.
To enter System Recovery Options from the Advanced Boot Options:
- Restart the computer.
- As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
- Use the arrow keys to select the Repair your computer menu item.
- Choose your language settings, and then click Next.
- Select the operating system you want to repair, and then click Next.
- Select your user account and click Next.
- Insert the installation disc.
- Restart your computer.
- If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
- Click Repair your computer.
- Choose your language settings, and then click Next.
- Select the operating system you want to repair, and then click Next.
- Select your user account an click Next.
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
[*]Select Command Prompt
[*]In the command window type in notepad and press Enter.
[*]The notepad opens. Under File menu select Open.
[*]Select "Computer" and find your flash drive letter and close the notepad.
[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.
[*]When the tool opens click Yes to the disclaimer.
[*]Place a check next to List Drivers MD5 as well as the default check marks that are already there
[*]Press Scan button.
[*]type exit and reboot the computer normally
[*]FRST will make a log (FRST.txt) on the flash drive, please copy and paste the log in your reply.
Please do the following:
Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste). Save it on the flashdrive as fixlist.txt
start SubSystems: [Windows] ==> ZeroAccess cmd: bootrec /FixMbr TDL4: custom:26000022 end
NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system
Now please enter System Recovery Options then select Command Prompt
Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.
Now restart, let it boot normally and tell me how it went.
Thank you, that worked and I was able to boot back up successfully. Here is the fixlog:
Fix result of Farbar Recovery Scan Tool (FRST written by farbar) Version: 15-03-2012
Ran by [removed] at 2012-03-20 07:18:56 R:1
Running from F:\
==============================================
HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Session Manager\SubSystems\\Windows Value was restored.
========= bootrec /FixMbr =========
ÿþT h e o p e r a t i o n c o m p l e t e d s u c c e s s f u l l y .
========= End of CMD: =========
The operation completed successfully.
The operation completed successfully.
==== End of Fixlog ====
Sorry just to add to the results of the FRST64 above, I don't seem to get redirected in Google anymore. Nevertheless, here is an OTL for you:
OTL logfile created on: 3/20/2012 7:33:14 AM - Run 1
OTL by OldTimer - Version 3.2.39.1 Folder = C:\Users\gabcon\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.75 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 44.77% Memory free
7.49 Gb Paging File | 4.82 Gb Available in Paging File | 64.29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.83 Gb Total Space | 845.24 Gb Free Space | 92.19% Space Free | Partition Type: NTFS
Drive D: | 241.14 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 3.76 Gb Total Space | 0.85 Gb Free Space | 22.51% Space Free | Partition Type: FAT32
Computer Name: GABCON-PC | User Name: gabcon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\gabcon\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11f_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
PRC - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
PRC - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
PRC - C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe (Sensible Vision )
PRC - C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
PRC - c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe (Sensible Vision )
PRC - C:\Program Files (x86)\Multimedia Card Reader(6366)\ShwiconXP6366.exe (Alcor Micro Corp.)
PRC - C:\Program Files (x86)\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe (Hewlett-Packard Development Co. L.P.)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\a25e06e527720656434230d3ee420427\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\6954c7f14ea634672cdacf2cd793497e\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8435718626a24beaeefc98d45ae77127\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ff30db6905f8ec024fc808ed8779c0f3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\a09ee392fa90849f2e9313a1ebbe0279\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\c0508b05f5c28e37711f447a66368e75\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\585ac5899ab444221c8b41df13b194bc\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d49f4cb0755ccc34cd35ff96dc2ef9e3\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\15742b3597258ce67cbe219005c197e5\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\1f14b3e1ee0847f8662f513e67f92547\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\QtCore4.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\libumajin.dll ()
MOD - C:\Program Files (x86)\Dell Stage\Dell Stage\QtGui4.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\SftBRCCPiped.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STBRCCServCLR.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\libxml2.dll ()
MOD - C:\Windows\SysWOW64\FAIEExtension.dll ()
MOD - C:\Windows\SysWOW64\FAib.dll ()
MOD - C:\Windows\SysWOW64\FACrashRpt.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (mfevtp) – C:\Program Files\Common Files\mcafee\systemcore\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (McODS) – C:\Program Files\mcafee\virusscan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (McProxy) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McOobeSv) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (DellOSDservice) – C:\Program Files\Dell\OSD\DellOSDservice.exe (Microsoft)
SRV:64bit: - (wltrysvc) – C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (Dell Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ioloSystemService) – C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
SRV - (SupportDockService.exe) – C:\Program Files (x86)\iYogi Support Dock\Services\CommAgent\SupportDockService.exe (iYogi Technical Services)
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\615\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FAService) – c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe (Sensible Vision )
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe (WildTangent, Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfenlfk) – C:\Windows\SysNative\drivers\mfenlfk.sys (McAfee, Inc.)
DRV:64bit: - (cfwids) – C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) – c:\Program Files\Dell Support Center\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (nuviocir) – C:\Windows\SysNative\drivers\nuviocir_win7_x64.sys (Nuvoton Technology Corp.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie64.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BcmVWL) – C:\Windows\SysNative\drivers\bcmvwl64.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (ElRawDisk) – C:\Windows\SysNative\drivers\ElRawDsk.sys (EldoS Corporation)
DRV:64bit: - (FACAP) – C:\Windows\SysNative\drivers\facap.sys (Sensible Vision )
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (MpKslce43b409) – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{33A5EDBD-705D-4133-B07B-BC7BEDDB5F8E}\MpKslce43b409.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {545AFDF0-8E90-4A10-A2F5-2B3446ABCB31}
IE:64bit: - HKLM\..\SearchScopes\{545AFDF0-8E90-4A10-A2F5-2B3446ABCB31}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes,DefaultScope = {BE050599-7E7E-4E14-8F5F-F389AE02B2FD}
IE - HKLM\..\SearchScopes\{BE050599-7E7E-4E14-8F5F-F389AE02B2FD}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
IE - HKCU\..\SearchScopes,DefaultScope = {BE050599-7E7E-4E14-8F5F-F389AE02B2FD}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2011/04/15 10:40:08 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2011/04/15 10:40:08 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\gabcon\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\gabcon\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\gabcon\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\electronicarts.com/GameFacePlugin: C:\Users\gabcon\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/07/19 10:43:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/02/24 11:20:22 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/07/19 10:43:24 | 000,000,000 | —D | M]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\gabcon\AppData\Local\Google\Chrome\Application\17.0.963.79\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.250.6 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U25 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\gabcon\AppData\Local\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\gabcon\AppData\Local\Google\Chrome\Application\17.0.963.79\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\gabcon\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Game Face Plugin (Enabled) = C:\Users\gabcon\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~2\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\gabcon\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: Poppit = C:\Users\gabcon\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
O1 HOSTS File: ([2012/03/12 07:55:11 | 000,000,855 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 94.63.147.17 www.bing.com
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20120223202634.dll (McAfee, Inc.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20120223202634.dll (McAfee, Inc.)
O2 - BHO: (FAIESSOHelper Class) - {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll (Sensible Vision )
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RunDLLEntry_EptMon] C:\Windows\SysNative\EptMon64.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [RunDLLEntry_THXCfg] C:\Windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [FAStartup] File not found
O4 - HKLM..\Run: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
O4 - HKLM..\Run: [iolo Startup] C:\Program Files (x86)\iolo\Common\Lib\ioloLManager.exe (iolo technologies, LLC)
O4 - HKLM..\Run: [iYogi Support Dock] C:\Program Files (x86)\iYogi Support Dock\iYogiSupportDock.exe ()
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [ShwiconXP6366] c:\Program Files (x86)\Multimedia Card Reader(6366)\ShwiconXP6366.exe (Alcor Micro Corp.)
O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [THX Audio Control Panel] C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Facebook Update] C:\Users\gabcon\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Update] C:\Windows\SysWow64\config\systemprofile\AppData\Roaming\Adobe\Adobe\klzgc.dll (eMajix.com, Inc.)
O4 - HKLM..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe (Dell)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: rexplorer.net ([]* in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} http://support.rexplorer.net/iftw_install//iftwclix.cab (Reg Error: Key error.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1B27BA64-2B63-470A-B5B5-6EF887544C0A}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\cozi - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\615\G2AWinLogon_x64.dll) - C:\Program Files (x86)\Citrix\GoToAssist\615\g2awinlogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\FastAccess: DllName - (c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll) - c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll ()
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (autocheck smrgdf C:\Users\gabcon\AppData\Roaming\iolo\)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/03/20 07:34:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/03/20 07:32:10 | 000,594,432 | —- | C] (OldTimer Tools) – C:\Users\gabcon\Desktop\OTL.exe
[2012/03/19 19:08:33 | 000,000,000 | —D | C] – C:\FRST
[2012/03/17 13:13:55 | 000,000,000 | —D | C] – C:\Windows\Microsoft Antimalware
[2012/03/12 19:57:56 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\svchost.exe
[2012/03/02 07:45:20 | 000,000,000 | —D | C] – C:\Program Files\Google
[2012/03/02 07:44:06 | 000,000,000 | —D | C] – C:\ProgramData\Google
[2012/03/02 07:44:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2012/03/02 07:44:04 | 000,414,368 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/03/02 07:43:46 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2012/02/22 04:02:50 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/02/22 04:02:50 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/02/22 04:02:50 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2012/02/22 04:02:50 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2012/02/22 04:02:50 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2012/02/22 04:02:50 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2012/02/22 04:02:50 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2012/02/22 04:02:50 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2012/02/22 04:02:50 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2012/02/22 04:02:50 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2012/02/22 04:02:50 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2012/02/22 04:02:49 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2012/02/22 04:02:49 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/02/22 04:02:49 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2012/02/22 04:02:49 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2012/02/22 04:02:49 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/02/22 04:02:49 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2012/02/22 04:02:49 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2012/02/22 04:02:49 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2012/02/22 04:02:49 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2012/02/22 04:02:49 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/02/22 04:02:49 | 000,123,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2012/02/22 04:02:49 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2012/02/22 04:02:49 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2012/02/22 04:02:49 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2012/02/22 04:02:49 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2012/02/22 04:02:49 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/02/22 04:02:49 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2012/02/22 04:02:49 | 000,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2012/02/22 04:02:49 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2012/02/22 04:02:49 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2012/02/22 04:02:49 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2012/02/22 04:02:48 | 002,308,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/02/22 04:02:48 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/02/22 04:02:48 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2012/02/22 04:02:48 | 000,222,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2012/02/22 04:02:48 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2012/02/22 04:02:48 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/02/22 04:02:48 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2012/02/22 04:02:48 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2012/02/22 04:02:48 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2012/02/22 04:02:48 | 000,145,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2012/02/22 04:02:48 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2012/02/22 04:02:48 | 000,114,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2012/02/22 04:02:48 | 000,111,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2012/02/22 04:02:48 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2012/02/22 04:02:48 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2012/02/22 04:02:48 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2012/02/22 04:02:48 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2012/02/22 04:02:48 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2012/02/22 04:02:48 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2012/02/22 04:02:48 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2012/02/22 04:02:47 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2012/02/22 04:02:47 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/02/22 04:02:47 | 000,697,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/02/22 04:02:47 | 000,603,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/02/22 04:02:47 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2012/02/22 04:02:47 | 000,452,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2012/02/22 04:02:47 | 000,448,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2012/02/22 04:02:47 | 000,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2012/02/22 04:02:47 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/02/22 04:02:47 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/02/22 04:02:47 | 000,165,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2012/02/22 04:02:47 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2012/02/22 04:02:47 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2012/02/22 04:02:47 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/02/22 04:02:47 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2012/02/22 04:02:47 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2012/02/22 04:02:47 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2012/02/22 04:02:47 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2012/02/22 04:02:47 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2012/02/22 04:02:47 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2012/02/21 21:41:13 | 000,000,000 | —D | C] – C:\Windows\Sun
========== Files - Modified Within 30 Days ==========
[2012/03/20 07:42:46 | 000,000,422 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2012/03/20 07:31:48 | 000,594,432 | —- | M] (OldTimer Tools) – C:\Users\gabcon\Desktop\OTL.exe
[2012/03/20 07:31:17 | 000,733,968 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/03/20 07:31:17 | 000,629,204 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/03/20 07:31:17 | 000,108,420 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/03/20 07:27:33 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/20 07:27:33 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/20 07:23:57 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/20 07:20:12 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/03/20 07:19:51 | 3016,712,192 | -HS- | M] () – C:\hiberfil.sys
[2012/03/17 11:52:56 | 000,183,791 | —- | M] () – C:\Users\gabcon\AppData\Local\census.cache
[2012/03/17 11:52:45 | 000,104,595 | —- | M] () – C:\Users\gabcon\AppData\Local\ars.cache
[2012/03/17 09:34:24 | 000,000,036 | —- | M] () – C:\Users\gabcon\AppData\Local\housecall.guid.cache
[2012/03/12 20:02:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001UA.job
[2012/03/12 19:59:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/12 18:03:15 | 000,002,407 | —- | M] () – C:\Users\gabcon\Desktop\Google Chrome.lnk
[2012/03/12 17:09:00 | 000,000,932 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001UA.job
[2012/03/12 16:02:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001Core.job
[2012/03/12 07:55:11 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/03/11 20:09:00 | 000,000,910 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001Core.job
[2012/03/03 21:02:37 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2012/03/02 08:22:25 | 000,002,221 | —- | M] () – C:\Users\gabcon\Desktop\System Mechanic.lnk
[2012/03/02 07:44:04 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/02/29 22:04:34 | 000,001,111 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/23 16:00:06 | 000,746,910 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/02/22 07:03:27 | 000,001,439 | —- | M] () – C:\Users\gabcon\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/22 04:02:50 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/02/22 04:02:50 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/02/22 04:02:50 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2012/02/22 04:02:50 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2012/02/22 04:02:50 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2012/02/22 04:02:50 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2012/02/22 04:02:50 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2012/02/22 04:02:50 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2012/02/22 04:02:50 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2012/02/22 04:02:50 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2012/02/22 04:02:50 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2012/02/22 04:02:49 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2012/02/22 04:02:49 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/02/22 04:02:49 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2012/02/22 04:02:49 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2012/02/22 04:02:49 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/02/22 04:02:49 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2012/02/22 04:02:49 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2012/02/22 04:02:49 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2012/02/22 04:02:49 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2012/02/22 04:02:49 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/02/22 04:02:49 | 000,123,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2012/02/22 04:02:49 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2012/02/22 04:02:49 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2012/02/22 04:02:49 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2012/02/22 04:02:49 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2012/02/22 04:02:49 | 000,072,822 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2012/02/22 04:02:49 | 000,072,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/02/22 04:02:49 | 000,066,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2012/02/22 04:02:49 | 000,063,488 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2012/02/22 04:02:49 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2012/02/22 04:02:49 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2012/02/22 04:02:49 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2012/02/22 04:02:48 | 002,308,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/02/22 04:02:48 | 000,818,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/02/22 04:02:48 | 000,267,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2012/02/22 04:02:48 | 000,248,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/02/22 04:02:48 | 000,222,208 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2012/02/22 04:02:48 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2012/02/22 04:02:48 | 000,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/02/22 04:02:48 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2012/02/22 04:02:48 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2012/02/22 04:02:48 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2012/02/22 04:02:48 | 000,145,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2012/02/22 04:02:48 | 000,135,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2012/02/22 04:02:48 | 000,114,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2012/02/22 04:02:48 | 000,111,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2012/02/22 04:02:48 | 000,091,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2012/02/22 04:02:48 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2012/02/22 04:02:48 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2012/02/22 04:02:48 | 000,049,664 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2012/02/22 04:02:48 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2012/02/22 04:02:48 | 000,012,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2012/02/22 04:02:48 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2012/02/22 04:02:47 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2012/02/22 04:02:47 | 001,493,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/02/22 04:02:47 | 000,697,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/02/22 04:02:47 | 000,603,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/02/22 04:02:47 | 000,534,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2012/02/22 04:02:47 | 000,452,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2012/02/22 04:02:47 | 000,448,512 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2012/02/22 04:02:47 | 000,282,112 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2012/02/22 04:02:47 | 000,237,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/02/22 04:02:47 | 000,165,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2012/02/22 04:02:47 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2012/02/22 04:02:47 | 000,103,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2012/02/22 04:02:47 | 000,096,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/02/22 04:02:47 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2012/02/22 04:02:47 | 000,085,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2012/02/22 04:02:47 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2012/02/22 04:02:47 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2012/02/22 04:02:47 | 000,072,822 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2012/02/22 04:02:47 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2012/02/22 04:02:47 | 000,030,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
========== Files Created - No Company Name ==========
[2012/03/17 11:52:56 | 000,183,791 | —- | C] () – C:\Users\gabcon\AppData\Local\census.cache
[2012/03/17 11:52:45 | 000,104,595 | —- | C] () – C:\Users\gabcon\AppData\Local\ars.cache
[2012/03/17 09:34:24 | 000,000,036 | —- | C] () – C:\Users\gabcon\AppData\Local\housecall.guid.cache
[2012/03/02 07:44:51 | 000,000,898 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/02 07:44:49 | 000,000,894 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/28 06:18:45 | 000,001,111 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/22 04:02:49 | 000,072,822 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2012/02/22 04:02:47 | 000,072,822 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2011/12/04 15:27:21 | 000,746,910 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/11/18 13:00:53 | 000,074,703 | —- | C] () – C:\Windows\SysWow64\mfc45.dll
[2011/07/19 10:37:18 | 000,202,808 | —- | C] () – C:\Windows\hpoins18.dat
[2011/07/19 10:37:18 | 000,005,355 | —- | C] () – C:\Windows\hpomdl18.dat
[2011/04/15 12:31:43 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/04/15 11:06:28 | 000,001,264 | —- | C] () – C:\Windows\THXCfg_SP_APOIM.ini
[2011/04/15 11:06:28 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_HP_APOIM.ini
[2011/04/15 11:06:28 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_APOIM.ini
[2011/04/15 11:06:27 | 000,177,664 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2011/04/15 11:06:27 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2011/02/22 20:15:11 | 000,002,857 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
========== LOP Check ==========
[2011/12/27 18:41:44 | 000,000,000 | —D | M] – C:\Users\gabcon\AppData\Roaming\acccore
[2012/02/03 22:56:44 | 000,000,000 | —D | M] – C:\Users\gabcon\AppData\Roaming\Babylon
[2011/06/11 10:04:45 | 000,000,000 | —D | M] – C:\Users\gabcon\AppData\Roaming\Electronic Arts
[2011/11/18 13:07:12 | 000,000,000 | —D | M] – C:\Users\gabcon\AppData\Roaming\iolo
[2011/11/18 12:32:49 | 000,000,000 | —D | M] – C:\Users\gabcon\AppData\Roaming\iYogi
[2011/05/24 17:00:36 | 000,000,000 | —D | M] – C:\Users\gabcon\AppData\Roaming\PCDr
[2011/06/01 10:06:05 | 000,000,000 | —D | M] – C:\Users\gabcon\AppData\Roaming\WildTangent
[2012/03/11 20:09:00 | 000,000,910 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001Core.job
[2012/03/12 17:09:00 | 000,000,932 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-681966066-4204787335-1963788685-1001UA.job
[2012/03/03 21:02:37 | 000,000,564 | —- | M] () – C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2012/03/12 10:09:07 | 000,032,630 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/03/20 07:42:46 | 000,000,422 | —- | M] () – C:\Windows\Tasks\SystemToolsDailyTest.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/04/15 13:20:15 | 000,028,998 | RH– | M] () – C:\dell.sdr
[2012/03/20 07:19:51 | 3016,712,192 | -HS- | M] () – C:\hiberfil.sys
[2011/12/27 18:41:13 | 000,000,363 | -H– | M] () – C:\IPH.PH
[2012/03/20 07:20:14 | 4022,284,288 | -HS- | M] () – C:\pagefile.sys
[2012/02/03 22:56:56 | 000,001,492 | —- | M] () – C:\user.js
[2011/04/15 11:11:32 | 001,177,452 | —- | M] () – C:\vcredist_x86.log
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2009/07/10 13:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/22 07:03:27 | 000,000,221 | -HS- | M] () – C:\Users\gabcon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/03/20 07:31:48 | 000,594,432 | —- | M] (OldTimer Tools) – C:\Users\gabcon\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
———————————————————-
Here is the Extras:
OTL Extras logfile created on: 3/20/2012 7:33:14 AM - Run 1
OTL by OldTimer - Version 3.2.39.1 Folder = C:\Users\gabcon\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.75 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 44.77% Memory free
7.49 Gb Paging File | 4.82 Gb Available in Paging File | 64.29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.83 Gb Total Space | 845.24 Gb Free Space | 92.19% Space Free | Partition Type: NTFS
Drive D: | 241.14 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 3.76 Gb Total Space | 0.85 Gb Free Space | 22.51% Space Free | Partition Type: FAT32
Computer Name: GABCON-PC | User Name: gabcon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{08627866-B869-8C66-C375-14D64CFF448B}" = ccc-utility64
"{17016DA1-F040-4032-BD36-34DD317BC9D5}" = HP Photosmart All-In-One Driver Software 13.0 Rel. A
"{26A24AE4-039D-4CA4-87B4-2F86416023FF}" = Java™ 6 Update 23 (64-bit)
"{277C688D-1948-4CF2-8EFC-6328C6AE85BB}" = SetDisplayConfig
"{42738DB0-FC3E-4672-A99B-9372F5696E30}" = Microsoft Security Client
"{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}" = Bing Maps 3D
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{876F4556-6811-4341-A6D7-78C3F15420E2}" = FastAccess
"{89B91433-49FF-45E6-9B89-02E761A5ACB9}" = DellOSD
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9C98CA38-4C1A-4AC8-B55C-169497C8826B}" = Apple Mobile Device Support
"{9CD0F7D3-B67F-4BF8-8784-D73AD229FF1E}" = iTunes
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"Dell Support Center" = Dell Support Center
"DW WLAN Card Utility" = DW WLAN Card Utility
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Shop for HP Supplies" = Shop for HP Supplies
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{010A785B-F920-4350-821B-6309909C20BB}" = THX TruStudio PC
"{04DA0C9B-0BD8-835A-7BCB-58B4E2F57CED}" = ccc-core-static
"{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}" = Microsoft Visual C++ 2005 Redistributable
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0807242D-4BB5-4F6C-BEA8-EC9D75A51C51}" = Multimedia Card Reader
"{0D6ABC33-35FF-CBCA-595D-2B095BC35C5C}" = CCC Help Polish
"{0DCDDAAC-CB9D-27E5-ED83-CDD88DCCF85F}" = Skins
"{0DEF8C02-2EAB-4BFE-A7E0-7990665DF1A9}" = C6100
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1C1473A1-1A26-4C8F-9548-A52D03066CE7}" = Catalyst Control Center - Branding
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 25
"{27612481-2FDB-E7A6-F76C-68E60F582219}" = CCC Help Swedish
"{2A7EF808-14F3-4E93-BE3A-1675EE5332A4}" = AIO_CDA_ProductContext
"{2DA5F129-11AC-4F11-8188-B2F07EAAC20A}" = Cozi
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FAECEAF-0EBE-48FF-B60A-B4577C0EFDAB}" = CIR Tool Kit
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{309ECB18-F25E-F405-DF6C-8B1B4CEDD11B}" = Catalyst Control Center InstallProxy
"{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}" = Microsoft XNA Framework Redistributable 3.0
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{43CD1466-73DF-5CE8-2FF7-CB33A87CA754}" = CCC Help German
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45F26F68-35F6-12D5-A83D-DE5C39786BA6}" = Catalyst Control Center Graphics Previews Vista
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4AC7B4E7-59B7-4E48-A60D-263C486FC33A}_is1" = System Checkup 3.1
"{4BD5B5D2-406D-4bc5-BB10-2F0D1D367C95}" = c6100_Help
"{4DBA3785-6268-DEE0-BDE4-129776FAE34D}" = CCC Help Finnish
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{5467C8DB-D7D5-411A-B2C7-2639B68627EF}" = StickyNotes
"{55FD1D5A-7AEF-4DA3-8FAF-A71B2A52FFC7}_is1" = iolo technologies' System Mechanic
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5D965998-4756-C622-6785-B3C23BD4F8AC}" = CCC Help Japanese
"{61D7A655-D59B-1312-C69D-4D85082B8836}" = CCC Help Danish
"{624E54D0-E4F4-434F-9EF6-D4D066EE4348}" = Facebook Video Calling 1.1.1.1
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{66F07F97-D1F1-4633-9D0A-C6AD0DC864D9}" = Dell Touch Software Suite Games
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72BF1DA0-2B00-4794-9173-159722019B74}" = CyberLink YouPaint
"{76A65EED-98BF-83CD-2989-97546A94572D}" = CCC Help Spanish
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7FCAED3F-AA2D-7AE1-B367-61723135891D}" = CCC Help Chinese Traditional
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{820B6609-4C97-3A2B-B644-573B06A0F0CC}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89AD7D28-F70D-2F9D-EBB7-771127521063}" = CCC Help Dutch
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8B7B2D54-C5A4-07E0-D92E-462ECB95F352}" = CCC Help Chinese Standard
"{8FF90DB8-6DED-44A3-B182-244FEC09012F}" = Microsoft Touch Pack for Windows 7
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{903679E8-44C8-4C07-9600-05C92654FC50}" = QualxServ Service Agreement
"{92A9F8A5-1EC6-A1EC-18FE-47098D074CFE}" = CCC Help Hungarian
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{A639BD63-8CE6-11D5-B4CC-00105A07274A}" = REXplorer Component Upgrade
"{A65A5ADE-F093-4840-4A52-0E4510ABE00F}" = CCC Help Thai
"{A7AEE29F-839E-46B5-B347-6D430618129F}" = AIO_CDA_Software
"{A81F2341-5207-ADA5-127A-A96CE606BA17}" = CCC Help Turkish
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.2
"{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
"{B2F5F3EA-BB20-BF63-A070-4EFA017F14F0}" = CCC Help Russian
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CCFAD826-D8CA-C72B-52DD-B05167161515}" = CCC Help Italian
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D15718E4-CD90-A107-2FDB-AF770B9AAEA8}" = CCC Help French
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D770F4B4-C422-45D9-8CEE-1B4C66E68CA8}" = Dell Stage
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{DCA8B341-3DA6-7500-C145-4397E1447C4E}" = CCC Help Czech
"{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"{DCE3D214-E9B1-7AFD-85F7-79BA7612C859}" = CCC Help Portuguese
"{DE7B593E-8227-071D-A768-CA3077D225E2}" = CCC Help English
"{E0860139-60E3-FCD8-9081-157839572587}" = CCC Help Greek
"{E0C0979D-05BF-4B3E-0272-602BB817B249}" = Catalyst Control Center Localization All
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E4335E82-17B3-460F-9E70-39D9BC269DB3}" = Dell PhotoStage
"{E9486293-4A94-55A8-A389-B693CFE4E280}" = CCC Help Norwegian
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{EF85FEF4-EB92-4075-A6D2-5F519BB30A2C}" = Accidental Damage Services Agreement
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F161CEF1-E88E-5515-3AB1-F79A016B30AA}" = CCC Help Korean
"{F2B83C93-3F61-8971-7350-1FD2C6C310CC}" = Catalyst Control Center Graphics Previews Common
"{F336F89D-8C5A-432C-8EA9-DA19377AD591}" = Dell MusicStage
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"AIM_7" = AIM 7
"BabylonToolbar" = Babylon toolbar on IE
"Dell Webcam Central" = Dell Webcam Central
"GoToAssist" = GoToAssist Corporate
"InstallShield_{0807242D-4BB5-4F6C-BEA8-EC9D75A51C51}" = Multimedia Card Reader
"InstallShield_{72BF1DA0-2B00-4794-9173-159722019B74}" = CyberLink YouPaint
"InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"iYogi Support Dock" = iYogi Support Dock 5.5.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Mixxx (1.9.0)" = Mixxx 1.9.0
"MSC" = McAfee SecurityCenter
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"WildTangent dell Master Uninstall" = WildTangent Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"World of Warcraft" = World of Warcraft
"Yahoo! Companion" = Yahoo! Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"EA SPORTS Gameface Browser Plugin" = EA SPORTS Gameface Browser Plugin 1.3.1.0
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/20/2012 7:32:01 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 3028
Description =
Error - 3/20/2012 7:32:01 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 3058
Description =
Error - 3/20/2012 7:32:01 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 7010
Description =
Error - 3/20/2012 7:32:13 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 3057
Description =
Error - 3/20/2012 7:32:14 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 3029
Description =
Error - 3/20/2012 7:32:14 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 3028
Description =
Error - 3/20/2012 7:32:14 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 3058
Description =
Error - 3/20/2012 7:32:14 AM | Computer Name = gabcon-PC | Source = Windows Search Service | ID = 7010
Description =
Error - 3/20/2012 7:40:07 AM | Computer Name = gabcon-PC | Source = PC-Doctor | ID = 1
Description = (3200) Asapi: (07:40:07:0550)(3200) libAsapi.DynamicLoadedPlugin -
Error – 64 Unable to load library 'S3LogPusher.dll'
Error - 3/20/2012 7:40:07 AM | Computer Name = gabcon-PC | Source = PC-Doctor | ID = 1
Description = (3200) Asapi: (07:40:07:0860)(3200) Asapi.State - Error – 123 Plugin
S3LogPusher.dll failed to load.
[ Broadcom Wireless LAN Events ]
Error - 3/15/2012 5:09:59 AM | Computer Name = gabcon-PC | Source = WLAN-Tray | ID = 0
Description = 05:09:59, Thu, Mar 15, 12 Error - Unable to gain access to user store
[ Dell Events ]
Error - 5/24/2011 3:10:20 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.
Error - 5/24/2011 4:01:20 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.
Error - 5/24/2011 4:01:20 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.
Error - 6/23/2011 5:31:33 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.
Error - 6/23/2011 5:31:33 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.
Error - 7/7/2011 8:40:59 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.
Error - 7/7/2011 8:40:59 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.
Error - 8/25/2011 1:03:07 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.
Error - 8/25/2011 1:03:07 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.
Error - 11/6/2011 4:46:28 PM | Computer Name = gabcon-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.
[ System Events ]
Error - 3/20/2012 7:41:34 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7024
Description = The Windows Search service terminated with service-specific error
%%-2147218170.
Error - 3/20/2012 7:41:34 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7034
Description = The Windows Search service terminated unexpectedly. It has done this
28 time(s).
Error - 3/20/2012 7:41:36 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7024
Description = The Windows Search service terminated with service-specific error
%%-2147218170.
Error - 3/20/2012 7:41:36 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7034
Description = The Windows Search service terminated unexpectedly. It has done this
29 time(s).
Error - 3/20/2012 7:41:37 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7024
Description = The Windows Search service terminated with service-specific error
%%-2147218170.
Error - 3/20/2012 7:41:37 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7034
Description = The Windows Search service terminated unexpectedly. It has done this
30 time(s).
Error - 3/20/2012 7:41:39 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7024
Description = The Windows Search service terminated with service-specific error
%%-2147218170.
Error - 3/20/2012 7:41:39 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7034
Description = The Windows Search service terminated unexpectedly. It has done this
31 time(s).
Error - 3/20/2012 7:41:41 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7024
Description = The Windows Search service terminated with service-specific error
%%-2147218170.
Error - 3/20/2012 7:41:41 AM | Computer Name = gabcon-PC | Source = Service Control Manager | ID = 7034
Description = The Windows Search service terminated unexpectedly. It has done this
32 time(s).
< End of report >
Please run the following:
Refer to the ComboFix User's Guide
- Download ComboFix from one of these locations:
Link 1
Link 2
* IMPORTANT !!! Place ComboFix.exe on your Desktop
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
You can get help on disabling your protection programs here
- Double click on ComboFix.exe & follow the prompts.
- Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
- When finished, it shall produce a log for you. Post that log in your next reply
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
———————————————————————————————
- Ensure your AntiVirus and AntiSpyware applications are re-enabled.
———————————————————————————————
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
The log is indicting you have more than one AV installed:
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
please uninstall one of them, as having more than one AV can cause instability, conflicts and crashes.
Please do the following;
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
- They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')
http://forums.whatthetech.com/index.php?showtopic=122671 Collect:: c:\windows\system32\config\systemprofile\AppData\Roaming\Adobe\Adobe\klzgc.dll Registry:: [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Update"=- ClearJavaCache::
Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
- Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
- ComboFix may request an update; please allow it.
- ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
- When finished, it shall produce a log for you.
- Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
- Ensure you are connected to the internet and click OK on the message box.
NEXT
- Please open your MalwareBytes AntiMalware Program
- Click the Update Tab and search for updates
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select "Perform Quick Scan", then click Scan.
- The scan may take some time to finish, so please be patient.
- When the scan is complete, click OK, then Show Results to view the results.
- Make sure that everything is checked, and click Remove Selected. <– very important
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
- Copy&Paste the entire report in your next reply.
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
NEXT
Go here to run an online scanner from ESET.
- Turn off the real time scanner of any existing antivirus program while performing the online scan
- Tick the box next to YES, I accept the Terms of Use.
- Click Start
- When asked, allow the activeX control to install
- Click Start
- Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
- Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
- Click Scan
- Wait for the scan to finish
- When the scan completes, press the LIST OF THREATS FOUND button
- Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
- Include the contents of this report in your next reply.
- Press the BACK button.
- Press Finish
Go to Start > control panel > programs and features > navigate to the Babylon toolbar > remove
now navigate to the babylon folder
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar
right click and delete it
NEXT
Visit ADOBE and download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.
NEXT
[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
- Download the latest version of Java Runtime Environment (JRE) 6 and Save it to your Desktop.
- Scroll down to where it says Java SE 6 Update 31
- Click the Download button under JRE to the right.
- Read the License Agreement then select Accept License Agreement
- Click on the link to download Windows x86 Offline and save the file to your desktop.
- Close any programs you may have running - especially your web browser.
- Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
- Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
- Click the Remove or Change/Remove button.
- Repeat as many times as necessary to remove each Java versions.
- Reboot your computer once all Java components are removed.
- Then from your desktop double-click on jre-6u31-windows-i586.exe to install the newest version.
- After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
- On the General tab, under Temporary Internet Files, click the Settings button.
- Next, click on the Delete Files button
- There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
Trace and Log Files
- Click OK on Delete Temporary Files Window
Note: This deletes ALL the Downloaded Applications and Applets from the CACHE. - Click OK to leave the Temporary Files Window
- Click OK to leave the Java Control Panel.
NEXT
Please advise how the computer is running now and if there are any outstanding issues
we just need to clean up the tools now, please do the following:
You can delete the FRST logs and program from your desktop.
NEXT
Follow these steps to uninstall Combofix
- Make sure your security programs are totally disabled.
- Click START then RUN
- Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.
[external image: Posted Image]
If there are any logs/tools remaining on your desktop > right click and delete them.
NEXT
Below I have included a number of recommendations for how to protect your computer against malware infections.
- It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.
- Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.
- Make Internet Explorer more secure
- Click Start > Run
- Type Inetcpl.cpl & click OK
- Click on the Security tab
- Click Reset all zones to default level
- Make sure the Internet Zone is selected & Click Custom level
- In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
- Next Click OK, then Apply button and then OK to exit the Internet Properties page.
- Download TFC to your desktop
- Close any open windows.
- Double click the TFC icon to run the program
- TFC will close all open programs itself in order to run,
- Click the Start button to begin the process.
- Allow TFC to run uninterrupted.
- The program should not take long to finish it's job
- Once its finished it should automatically reboot your machine,
- if it doesn't, manually reboot to ensure a complete clean
- WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
- Green to go
- Yellow for caution
- Red to stop
- Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
- ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
- In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
PC Safety and Security–What Do I Need?.
Thank you for your patience, and performing all of the procedures requested.
Please respond one last time so we can consider the thread resolved and close it, thank-you.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI