doojob
Topic Starter
All my browsers on the computer have been going to searchnu.com Just want to get rid of it
HAve attached the OTL.txt file
Thank you in advance
OTL logfile created on: 05/04/2012 8:56:08 PM - Run 2
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Amish\Downloads
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.87 Gb Total Physical Memory | 1.59 Gb Available Physical Memory | 55.19% Memory free
5.95 Gb Paging File | 4.62 Gb Available in Paging File | 77.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 456.91 Gb Total Space | 46.39 Gb Free Space | 10.15% Space Free | Partition Type: NTFS
Drive D: | 8.85 Gb Total Space | 1.21 Gb Free Space | 13.64% Space Free | Partition Type: NTFS
Drive F: | 1863.01 Gb Total Space | 839.07 Gb Free Space | 45.04% Space Free | Partition Type: NTFS
Drive T: | 931.51 Gb Total Space | 0.65 Gb Free Space | 0.07% Space Free | Partition Type: NTFS
Computer Name: DAD | User Name: Amish | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Amish\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
PRC - C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
PRC - C:\Users\Public\Documents\Symantec\NortonProtectionMemo.exe (Symantec Corporation)
PRC - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe ()
PRC - C:\Program Files\Common Files\X-Rite\InstrumentService\colormunki\ColorMunki.exe ()
PRC - C:\Program Files\Common Files\X-Rite\InstrumentService\wnoted.exe ()
PRC - C:\Program Files\Photodex\ProShowProducer\scsiaccess.exe ()
PRC - C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe ()
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
PRC - C:\Windows\System32\schtasks.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Acronis\TrueImageHome\fox.dll ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe ()
MOD - C:\Program Files\Common Files\X-Rite\InstrumentService\colormunki\ColorMunki.exe ()
MOD - C:\Program Files\Common Files\X-Rite\InstrumentService\colormunki\colormunki.dll ()
MOD - C:\Program Files\Common Files\X-Rite\InstrumentService\colormunki\XRiteDevice.dll ()
MOD - C:\Program Files\Common Files\X-Rite\InstrumentService\wnoted.exe ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\QtGui4.dll ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\QtCore4.dll ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\imageformats\qtiff4.dll ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe ()
========== Win32 Services (SafeList) ==========
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (ScsiAccess) – C:\Program Files\Photodex\ProShowProducer\scsiaccess.exe ()
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ISPwdSvc) – c:\Program Files\Norton Internet Security\isPwdSvc.exe (Symantec Corporation)
SRV - (comHost) – c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (LiveUpdate Notice Ex) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SymAppCore) – c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (timounter) – C:\Windows\System32\drivers\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\Windows\System32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman) – C:\Windows\System32\drivers\snapman.sys (Acronis)
DRV - (tdrpman) – C:\Windows\System32\drivers\tdrpman.sys (Acronis)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSvix86) – C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20080208.001\IDSvix86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20071210.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20071210.002\NAVENG.SYS (Symantec Corporation)
DRV - (colormunki) – C:\Windows\System32\drivers\colormunki.sys (Thesycon GmbH, Germany)
DRV - (nvstor32) – C:\Windows\System32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\drivers\symtdi.sys (Symantec Corporation)
DRV - (SYMFW) – C:\Windows\System32\drivers\symfw.sys (Symantec Corporation)
DRV - (SYMIDS) – C:\Windows\System32\drivers\symids.sys (Symantec Corporation)
DRV - (SYMNDISV) – C:\Windows\System32\drivers\symndisv.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\drivers\symredrv.sys (Symantec Corporation)
DRV - (SYMDNS) – C:\Windows\System32\drivers\symdns.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\Windows\System32\drivers\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (PdiPorts) – C:\Windows\System32\drivers\PdiPorts.sys (Portrait Displays, Inc.)
DRV - (WSDPrintDevice) – C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (WSDScan) – C:\Windows\System32\drivers\WSDScan.sys (Microsoft Corporation)
DRV - (Ps2) – C:\Windows\System32\drivers\PS2.sys (Hewlett-Packard Company)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{2A17C834-32F5-4A4F-8D13-9EE1899F5364}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HVDCS7
IE - HKLM\..\SearchScopes\{828E4B64-759B-4F32-A907-4FE331004BD4}: "URL" = http://www.ask.com/web?q={searchTerms}&l=dis&o=cahpd
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}: "URL" = http://search.imesh.com/web?src=ieb&sy…q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2801948
IE - HKLM\..\SearchScopes\{D0BDB87D-C866-450A-989C-A28A5866DC64}: "URL" = http://ca.search.yahoo.com/search?p={searc…&fr=hp-pvdt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {37483b40-c254-4a72-bda4-22ee90182c1e} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKCU\..\SearchScopes\{2A17C834-32F5-4A4F-8D13-9EE1899F5364}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HVDCS7
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…soft:{language}
IE - HKCU\..\SearchScopes\{828E4B64-759B-4F32-A907-4FE331004BD4}: "URL" = http://www.ask.com/web?q={searchTerms}&l=dis&o=cahpd
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}: "URL" = http://search.imesh.com/web?src=ieb&sy…q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2801948
IE - HKCU\..\SearchScopes\{D0BDB87D-C866-450A-989C-A28A5866DC64}: "URL" = http://ca.search.yahoo.com/search?p={searc…&fr=hp-pvdt
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.17\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/01/23 20:49:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.17\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2011/03/07 09:56:27 | 000,000,000 | —D | M]
[2012/03/28 17:38:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Amish\AppData\Roaming\Mozilla\Extensions
[2011/07/18 10:13:35 | 000,000,000 | —D | M] (No name found) – C:\Users\Amish\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/08/12 04:21:14 | 000,002,486 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\iMeshWebSearch.xml
[2012/01/29 16:18:07 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Reg Error: Value error.) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBHO.dll (Symantec Corporation)
O2 - BHO: (UrlHelper Class) - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\IEBHO.dll File not found
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll File not found
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {37483B40-C254-4A72-BDA4-22EE90182C1E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ccApp] c:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup File not found
O4 - HKLM..\Run: [SunJavaUpdateReg] C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [wnoted] C:\Program Files\Common Files\X-Rite\InstrumentService\wnoted.exe ()
O4 - HKCU..\Run: [NCH Swift Sound] C:\Users\Amish\AppData\Roaming\975DAD.exe (Provtech Limited)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Launcher] C:\Windows\SMINST\Launcher.exe (soft thinks)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{762A9203-78A2-4D67-B599-AEB6871A31F2}: DhcpNameServer = [removed]
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O30 - LSA: Authentication Packages - (relog_ap) - C:\Windows\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/23 23:40:52 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{158a4bd8-dc66-11dc-bb47-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O33 - MountPoints2\{5897d8fc-7080-11dd-8ee9-001d60c20cf8}\Shell\AutoRun\command - "" = F:\ – File not found
O33 - MountPoints2\{5897d8fc-7080-11dd-8ee9-001d60c20cf8}\Shell\explore\Command - "" = F:\RECYCLER\INFO.exe
O33 - MountPoints2\{5897d8fc-7080-11dd-8ee9-001d60c20cf8}\Shell\open\Command - "" = F:\RECYCLER\INFO.exe
O33 - MountPoints2\{65af461b-cda4-11dd-be1e-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O33 - MountPoints2\{e3e98251-57e8-11de-861f-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O33 - MountPoints2\{eccede6f-7cd8-11de-b2b6-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O33 - MountPoints2\{efd80d14-a8f1-11e0-80c2-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/03/28 15:42:30 | 000,000,000 | —D | C] – C:\Program Files\Image Finder
[2012/03/28 15:36:14 | 000,000,000 | —D | C] – C:\Users\Amish\Desktop\DHARA
========== Files - Modified Within 30 Days ==========
[2012/04/05 21:00:00 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{6ED5FB7D-A7C0-4A74-AAD6-796CE0857E7B}.job
[2012/04/05 20:53:50 | 000,622,906 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/04/05 20:53:50 | 000,108,122 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/04/05 20:51:39 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{C605F679-9461-4FE7-895D-46EB09FD9008}.job
[2012/04/05 20:47:28 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/05 20:47:28 | 000,000,378 | —- | M] () – C:\Windows\tasks\Registry Reviver-Amish-Startup.job
[2012/04/05 20:47:19 | 000,003,456 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/05 20:47:19 | 000,003,456 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/05 20:47:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/03/28 17:26:23 | 000,002,255 | —- | M] () – C:\Users\Amish\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2012/03/28 17:09:23 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/28 15:42:30 | 000,000,794 | —- | M] () – C:\Users\Public\Desktop\Image Finder.lnk
[2012/03/26 21:34:58 | 000,000,546 | —- | M] () – C:\Windows\tasks\Norton Internet Security - Run Full System Scan - Amish.job
========== Files Created - No Company Name ==========
[2012/03/28 15:42:30 | 000,000,806 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Finder.lnk
[2012/03/28 15:42:30 | 000,000,794 | —- | C] () – C:\Users\Public\Desktop\Image Finder.lnk
[2012/02/11 14:32:13 | 000,002,048 | —- | C] () – C:\Users\Amish\AppData\Roaming\Photobook Designer Prefs
[2012/02/01 13:38:13 | 000,001,152 | —- | C] () – C:\Windows\System32\windrv.sys
[2011/01/13 18:34:54 | 000,102,400 | —- | C] () – C:\Windows\RegBootClean.exe
[2011/01/13 17:54:36 | 000,000,036 | —- | C] () – C:\Users\Amish\AppData\Local\housecall.guid.cache
========== LOP Check ==========
[2007/12/29 17:21:18 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\.BitTornado
[2007/12/14 01:41:19 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Anthropics
[2011/03/07 09:56:25 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\InterTrust
[2010/12/13 16:38:32 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\MusicNet
[2008/08/29 03:48:15 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\MyPublisher
[2010/12/14 17:28:15 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\NCH Swift Sound
[2008/05/20 14:57:13 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Netscape
[2008/09/12 15:07:40 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Nikon
[2012/02/11 14:31:44 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Photobook Designer
[2008/05/20 14:56:39 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Photodex
[2010/12/14 01:39:14 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Recordpad
[2009/07/12 12:20:44 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\SiteBuilder.1092AF29A5D2D6F129EC9E969ADB342C4F09EC7B.1
[2007/12/10 21:53:55 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Snapfish
[2011/01/13 18:34:47 | 000,000,000 | -HSD | M] – C:\Users\Amish\AppData\Roaming\SystemProc
[2011/07/18 10:13:34 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Thunderbird
[2008/07/27 09:10:57 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Vso
[2012/04/05 20:47:28 | 000,000,378 | —- | M] () – C:\Windows\Tasks\Registry Reviver-Amish-Startup.job
[2012/03/28 17:41:36 | 000,032,608 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/04/05 21:00:00 | 000,000,420 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{6ED5FB7D-A7C0-4A74-AAD6-796CE0857E7B}.job
[2012/04/05 20:51:39 | 000,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{C605F679-9461-4FE7-895D-46EB09FD9008}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 216 bytes -> C:\ProgramData\TEMP:1957F8A9
< End of report >
HAve attached the OTL.txt file
Thank you in advance
OTL logfile created on: 05/04/2012 8:56:08 PM - Run 2
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Amish\Downloads
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.87 Gb Total Physical Memory | 1.59 Gb Available Physical Memory | 55.19% Memory free
5.95 Gb Paging File | 4.62 Gb Available in Paging File | 77.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 456.91 Gb Total Space | 46.39 Gb Free Space | 10.15% Space Free | Partition Type: NTFS
Drive D: | 8.85 Gb Total Space | 1.21 Gb Free Space | 13.64% Space Free | Partition Type: NTFS
Drive F: | 1863.01 Gb Total Space | 839.07 Gb Free Space | 45.04% Space Free | Partition Type: NTFS
Drive T: | 931.51 Gb Total Space | 0.65 Gb Free Space | 0.07% Space Free | Partition Type: NTFS
Computer Name: DAD | User Name: Amish | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Amish\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
PRC - C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
PRC - C:\Users\Public\Documents\Symantec\NortonProtectionMemo.exe (Symantec Corporation)
PRC - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe ()
PRC - C:\Program Files\Common Files\X-Rite\InstrumentService\colormunki\ColorMunki.exe ()
PRC - C:\Program Files\Common Files\X-Rite\InstrumentService\wnoted.exe ()
PRC - C:\Program Files\Photodex\ProShowProducer\scsiaccess.exe ()
PRC - C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe ()
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
PRC - C:\Windows\System32\schtasks.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Acronis\TrueImageHome\fox.dll ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe ()
MOD - C:\Program Files\Common Files\X-Rite\InstrumentService\colormunki\ColorMunki.exe ()
MOD - C:\Program Files\Common Files\X-Rite\InstrumentService\colormunki\colormunki.dll ()
MOD - C:\Program Files\Common Files\X-Rite\InstrumentService\colormunki\XRiteDevice.dll ()
MOD - C:\Program Files\Common Files\X-Rite\InstrumentService\wnoted.exe ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\QtGui4.dll ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\QtCore4.dll ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\imageformats\qtiff4.dll ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe ()
========== Win32 Services (SafeList) ==========
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (ScsiAccess) – C:\Program Files\Photodex\ProShowProducer\scsiaccess.exe ()
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ISPwdSvc) – c:\Program Files\Norton Internet Security\isPwdSvc.exe (Symantec Corporation)
SRV - (comHost) – c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (LiveUpdate Notice Ex) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SymAppCore) – c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (timounter) – C:\Windows\System32\drivers\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\Windows\System32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman) – C:\Windows\System32\drivers\snapman.sys (Acronis)
DRV - (tdrpman) – C:\Windows\System32\drivers\tdrpman.sys (Acronis)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSvix86) – C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20080208.001\IDSvix86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20071210.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20071210.002\NAVENG.SYS (Symantec Corporation)
DRV - (colormunki) – C:\Windows\System32\drivers\colormunki.sys (Thesycon GmbH, Germany)
DRV - (nvstor32) – C:\Windows\System32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\drivers\symtdi.sys (Symantec Corporation)
DRV - (SYMFW) – C:\Windows\System32\drivers\symfw.sys (Symantec Corporation)
DRV - (SYMIDS) – C:\Windows\System32\drivers\symids.sys (Symantec Corporation)
DRV - (SYMNDISV) – C:\Windows\System32\drivers\symndisv.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\drivers\symredrv.sys (Symantec Corporation)
DRV - (SYMDNS) – C:\Windows\System32\drivers\symdns.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\Windows\System32\drivers\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (PdiPorts) – C:\Windows\System32\drivers\PdiPorts.sys (Portrait Displays, Inc.)
DRV - (WSDPrintDevice) – C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (WSDScan) – C:\Windows\System32\drivers\WSDScan.sys (Microsoft Corporation)
DRV - (Ps2) – C:\Windows\System32\drivers\PS2.sys (Hewlett-Packard Company)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{2A17C834-32F5-4A4F-8D13-9EE1899F5364}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HVDCS7
IE - HKLM\..\SearchScopes\{828E4B64-759B-4F32-A907-4FE331004BD4}: "URL" = http://www.ask.com/web?q={searchTerms}&l=dis&o=cahpd
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}: "URL" = http://search.imesh.com/web?src=ieb&sy…q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2801948
IE - HKLM\..\SearchScopes\{D0BDB87D-C866-450A-989C-A28A5866DC64}: "URL" = http://ca.search.yahoo.com/search?p={searc…&fr=hp-pvdt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {37483b40-c254-4a72-bda4-22ee90182c1e} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKCU\..\SearchScopes\{2A17C834-32F5-4A4F-8D13-9EE1899F5364}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HVDCS7
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…soft:{language}
IE - HKCU\..\SearchScopes\{828E4B64-759B-4F32-A907-4FE331004BD4}: "URL" = http://www.ask.com/web?q={searchTerms}&l=dis&o=cahpd
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}: "URL" = http://search.imesh.com/web?src=ieb&sy…q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2801948
IE - HKCU\..\SearchScopes\{D0BDB87D-C866-450A-989C-A28A5866DC64}: "URL" = http://ca.search.yahoo.com/search?p={searc…&fr=hp-pvdt
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.17\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/01/23 20:49:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.17\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2011/03/07 09:56:27 | 000,000,000 | —D | M]
[2012/03/28 17:38:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Amish\AppData\Roaming\Mozilla\Extensions
[2011/07/18 10:13:35 | 000,000,000 | —D | M] (No name found) – C:\Users\Amish\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/08/12 04:21:14 | 000,002,486 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\iMeshWebSearch.xml
[2012/01/29 16:18:07 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Reg Error: Value error.) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBHO.dll (Symantec Corporation)
O2 - BHO: (UrlHelper Class) - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\IEBHO.dll File not found
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll File not found
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {37483B40-C254-4A72-BDA4-22EE90182C1E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ccApp] c:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup File not found
O4 - HKLM..\Run: [SunJavaUpdateReg] C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [wnoted] C:\Program Files\Common Files\X-Rite\InstrumentService\wnoted.exe ()
O4 - HKCU..\Run: [NCH Swift Sound] C:\Users\Amish\AppData\Roaming\975DAD.exe (Provtech Limited)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Launcher] C:\Windows\SMINST\Launcher.exe (soft thinks)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{762A9203-78A2-4D67-B599-AEB6871A31F2}: DhcpNameServer = [removed]
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O30 - LSA: Authentication Packages - (relog_ap) - C:\Windows\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/23 23:40:52 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{158a4bd8-dc66-11dc-bb47-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O33 - MountPoints2\{5897d8fc-7080-11dd-8ee9-001d60c20cf8}\Shell\AutoRun\command - "" = F:\ – File not found
O33 - MountPoints2\{5897d8fc-7080-11dd-8ee9-001d60c20cf8}\Shell\explore\Command - "" = F:\RECYCLER\INFO.exe
O33 - MountPoints2\{5897d8fc-7080-11dd-8ee9-001d60c20cf8}\Shell\open\Command - "" = F:\RECYCLER\INFO.exe
O33 - MountPoints2\{65af461b-cda4-11dd-be1e-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O33 - MountPoints2\{e3e98251-57e8-11de-861f-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O33 - MountPoints2\{eccede6f-7cd8-11de-b2b6-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O33 - MountPoints2\{efd80d14-a8f1-11e0-80c2-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/03/28 15:42:30 | 000,000,000 | —D | C] – C:\Program Files\Image Finder
[2012/03/28 15:36:14 | 000,000,000 | —D | C] – C:\Users\Amish\Desktop\DHARA
========== Files - Modified Within 30 Days ==========
[2012/04/05 21:00:00 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{6ED5FB7D-A7C0-4A74-AAD6-796CE0857E7B}.job
[2012/04/05 20:53:50 | 000,622,906 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/04/05 20:53:50 | 000,108,122 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/04/05 20:51:39 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{C605F679-9461-4FE7-895D-46EB09FD9008}.job
[2012/04/05 20:47:28 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/05 20:47:28 | 000,000,378 | —- | M] () – C:\Windows\tasks\Registry Reviver-Amish-Startup.job
[2012/04/05 20:47:19 | 000,003,456 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/05 20:47:19 | 000,003,456 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/05 20:47:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/03/28 17:26:23 | 000,002,255 | —- | M] () – C:\Users\Amish\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2012/03/28 17:09:23 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/28 15:42:30 | 000,000,794 | —- | M] () – C:\Users\Public\Desktop\Image Finder.lnk
[2012/03/26 21:34:58 | 000,000,546 | —- | M] () – C:\Windows\tasks\Norton Internet Security - Run Full System Scan - Amish.job
========== Files Created - No Company Name ==========
[2012/03/28 15:42:30 | 000,000,806 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Finder.lnk
[2012/03/28 15:42:30 | 000,000,794 | —- | C] () – C:\Users\Public\Desktop\Image Finder.lnk
[2012/02/11 14:32:13 | 000,002,048 | —- | C] () – C:\Users\Amish\AppData\Roaming\Photobook Designer Prefs
[2012/02/01 13:38:13 | 000,001,152 | —- | C] () – C:\Windows\System32\windrv.sys
[2011/01/13 18:34:54 | 000,102,400 | —- | C] () – C:\Windows\RegBootClean.exe
[2011/01/13 17:54:36 | 000,000,036 | —- | C] () – C:\Users\Amish\AppData\Local\housecall.guid.cache
========== LOP Check ==========
[2007/12/29 17:21:18 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\.BitTornado
[2007/12/14 01:41:19 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Anthropics
[2011/03/07 09:56:25 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\InterTrust
[2010/12/13 16:38:32 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\MusicNet
[2008/08/29 03:48:15 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\MyPublisher
[2010/12/14 17:28:15 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\NCH Swift Sound
[2008/05/20 14:57:13 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Netscape
[2008/09/12 15:07:40 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Nikon
[2012/02/11 14:31:44 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Photobook Designer
[2008/05/20 14:56:39 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Photodex
[2010/12/14 01:39:14 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Recordpad
[2009/07/12 12:20:44 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\SiteBuilder.1092AF29A5D2D6F129EC9E969ADB342C4F09EC7B.1
[2007/12/10 21:53:55 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Snapfish
[2011/01/13 18:34:47 | 000,000,000 | -HSD | M] – C:\Users\Amish\AppData\Roaming\SystemProc
[2011/07/18 10:13:34 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Thunderbird
[2008/07/27 09:10:57 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Vso
[2012/04/05 20:47:28 | 000,000,378 | —- | M] () – C:\Windows\Tasks\Registry Reviver-Amish-Startup.job
[2012/03/28 17:41:36 | 000,032,608 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/04/05 21:00:00 | 000,000,420 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{6ED5FB7D-A7C0-4A74-AAD6-796CE0857E7B}.job
[2012/04/05 20:51:39 | 000,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{C605F679-9461-4FE7-895D-46EB09FD9008}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 216 bytes -> C:\ProgramData\TEMP:1957F8A9
< End of report >