Spyware / Malware / Virus Removal
searchqu and searchnu406 removal [Solved]
30 min read
Chris1701
Topic Starter
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Starter
Boot Device: \Device\HarddiskVolume1
Install Date: 17/01/2011 09:57:42
System Uptime: 12/04/2012 13:07:27 (0 hours ago)
.
Motherboard: SAMSUNG ELECTRONICS CO., LTD. | | N145P/N250P/N260P
Processor: Intel® Atom™ CPU N450 @ 1.66GHz | CPU 1 | 1667/mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 88 GiB total, 53.715 GiB free.
D: is FIXED (NTFS) - 130 GiB total, 76.686 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: Photosmart C6100 series
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer:
Name: Photosmart C6100 series
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service:
.
Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
Description: Photosmart C6100 series
Device ID: ROOT\MULTIFUNCTION\0001
Manufacturer: HP
Name: Photosmart C6100 series
PNP Device ID: ROOT\MULTIFUNCTION\0001
Service:
.
==== System Restore Points ===================
.
RP258: 08/04/2012 19:05:51 - Windows Backup
RP259: 08/04/2012 22:51:56 - Installed STOPzilla. Available with Windows Installer version 1.2 and later.
RP261: 08/04/2012 23:22:49 - StopZILLA! Restore Point.
RP262: 09/04/2012 01:12:02 - Removed STOPzilla. Available with Windows Installer version 1.2 and later.
RP263: 11/04/2012 18:14:50 - Installed AVG 2012
RP264: 11/04/2012 18:21:27 - Installed AVG 2012
RP265: 11/04/2012 20:07:07 - Removed TuneUp Utilities 2011
RP266: 11/04/2012 20:15:50 - Removed TuneUp Utilities 2011
RP267: 11/04/2012 20:25:54 - Removed TuneUp Utilities Language Pack (en-US)
RP268: 11/04/2012 23:27:13 - Restore Operation
RP269: 12/04/2012 01:19:52 - Windows Update
RP270: 12/04/2012 01:31:05 - Windows Backup
RP271: 12/04/2012 10:44:30 - Windows Update
.
==== Installed Programs ======================
.
32 Bit HP CIO Components Installer
3Connect
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.2)
AIO_CDA_ProductContext
AIO_CDA_Software
AIO_Scan
Amazon MP3 Downloader 1.0.9
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Atheros Client Installation Program
BatteryLifeExtender
Bonjour
Broadcom 802.11 Network Adapter
BufferChm
C6100
c6100_Help
Copy
CyberLink YouCam
D3DX10
Destinations
DeviceDiscovery
DocProc
Easy Content Share
Easy Display Manager
Easy Network Manager
Easy Resolution Manager
Easy SpeedUp Manager
EasyBatteryManager
EasyFileShare
ETDWare PS/2-X86 8.0.7.0_WHQL
Fast Start
Fax
FileZilla Client 3.4.0
Google Chrome
Google Earth
Google Update Helper
GPBaseService2
HP Customer Participation Program 13.0
HP Imaging Device Functions 13.0
HP Photosmart All-In-One Driver Software 13.0 Rel. A
HP Photosmart Essential 3.5
HP Smart Web Printing 4.60
HP Solution Center 13.0
HP Update
HPPhotoGadget
HPPhotoSmartDiscLabelContent1
HPPhotosmartEssential
HPProductAssistant
HPSSupply
Huawei modem
iLivid
Intel® Graphics Media Accelerator Driver
IrfanView (remove only)
iTunes
Java Auto Updater
Java™ 6 Update 29
MarketResearch
Marvell Miniport Driver
McAfee Total Protection
McAfee Virtual Technician
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office Basic Edition 2003
Microsoft Office File Validation Add-In
Microsoft Office Outlook Connector
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MobileMe Control Panel
Movie Color Enhancer
Mozilla Firefox 10.0.2 (x86 en-US)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Network
OCR Software by I.R.I.S. 13.0
OpenOffice.org 3.3
PLAY ONLINE
QuickTime
Realtek High Definition Audio Driver
REALTEK PCIE Wireless LAN Software
Samsung AnyWeb Print
Samsung Recovery Solution 5
Samsung Support Center 1.0
Samsung Universal Print Driver
Samsung Universal Scan Driver
Samsung Update Plus
SamsungMovie
Scan
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Shop for HP Supplies
Skype™ 4.2
SmartWebPrinting
Software Informer 1.1
SolutionCenter
SRS Premium Sound Control Panel
Status
TeamViewer 6
Toolbox
TrayApp
TuneUp Utilities 2011
TuneUp Utilities Language Pack (en-US)
UnloadSupport
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
User Guide
Vit Registry Fix 9.5.4 (remove only)
WebReg
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
WinZip 16.0
WinZipBar Toolbar
Yahoo! BrowserPlus 2.9.8
Yahoo! Messenger
Yahoo! Software Update
.
==== Event Viewer Messages From Past Week ========
.
12/04/2012 13:08:25, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom
12/04/2012 01:15:13, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
12/04/2012 01:10:20, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TeamViewer6 service.
12/04/2012 01:07:42, Error: Service Control Manager [7043] - The McAfee McShield service did not shut down properly after receiving a preshutdown control.
12/04/2012 00:58:37, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate) service to connect.
12/04/2012 00:58:37, Error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/04/2012 00:57:32, Error: volsnap [6] - The shadow copy of volume C: could not create a new paged heap. The system may be low on virtual memory.
12/04/2012 00:55:42, Error: Service Control Manager [7024] - The Windows Firewall service terminated with service-specific error Access is denied..
11/04/2012 23:19:00, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service MCODS with arguments "" in order to run the server: {C98F04D7-CD30-4BB0-B7D7-8DD7448520F2}
11/04/2012 23:18:38, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the McAfee Scanner service to connect.
11/04/2012 23:18:38, Error: Service Control Manager [7000] - The McAfee Scanner service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
11/04/2012 23:18:08, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: After starting, the service hung in a start-pending state.
11/04/2012 23:18:08, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
11/04/2012 23:18:07, Error: Service Control Manager [7022] - The Function Discovery Resource Publication service hung on starting.
11/04/2012 23:10:23, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avgwd service.
11/04/2012 22:49:32, Error: Service Control Manager [7023] - The Windows Modules Installer service terminated with the following error: The process cannot access the file because it is being used by another process.
11/04/2012 17:46:14, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
.
==== End Of File ===========================
jeffce
Hi and Welcome!!
My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.
Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
———-
Please download aswMBR to your desktop.
[external image: Posted Image]
Click the image to enlarge it
———-
When you ran DDS there should have been a log named DDS.txt created…could you post that along with the log created by aswMBR into your next reply?
- I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
- Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
- The fixes are specific to your problem and should only be used for the issues on this machine.
- Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
- It's often worth reading through these instructions and printing them for ease of reference.
- If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
- Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.
Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
———-
Please download aswMBR to your desktop.
- Double click the aswMBR icon to run it.
- Click the Scan button to start scan.
- When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
[external image: Posted Image]
Click the image to enlarge it
———-
When you ran DDS there should have been a log named DDS.txt created…could you post that along with the log created by aswMBR into your next reply?
Chris1701
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
- I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
- Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
- The fixes are specific to your problem and should only be used for the issues on this machine.
- Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
- It's often worth reading through these instructions and printing them for ease of reference.
- If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
- Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.
Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
———-
Please download aswMBR to your desktop.
- Double click the aswMBR icon to run it.
- Click the Scan button to start scan.
- When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
[external image: Posted Image]
Click the image to enlarge it
———-
When you ran DDS there should have been a log named DDS.txt created…could you post that along with the log created by aswMBR into your next reply? :)
Chris1701
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-04-16 21:46:37
—————————–
21:46:37.170 OS Version: Windows 6.1.7601 Service Pack 1
21:46:37.170 Number of processors: 2 586 0x1C0A
21:46:37.170 ComputerName: CHRISSAMSUNG UserName: Christina
21:46:37.700 Initialize success
21:46:59.135 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
21:46:59.151 Disk 0 Vendor: SAMSUNG_HM250HI 2AC101C4 Size: 238475MB BusType: 11
21:46:59.166 Disk 0 MBR read successfully
21:46:59.182 Disk 0 MBR scan
21:46:59.182 Disk 0 unknown MBR code
21:46:59.213 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
21:46:59.229 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 90112 MB offset 206848
21:46:59.229 Disk 0 Partition - 00 0F Extended LBA 133480 MB offset 184756224
21:46:59.275 Disk 0 Partition 3 00 27 Hidden NTFS WinRE NTFS 14780 MB offset 458123264
21:46:59.322 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 133479 MB offset 184758272
21:46:59.338 Disk 0 scanning sectors +488392704
21:46:59.431 Disk 0 scanning C:\windows\system32\drivers
21:47:08.403 Service scanning
21:47:26.328 Modules scanning
21:47:37.655 Disk 0 trace - called modules:
21:47:37.686
21:47:37.686 Scan finished successfully
21:48:28.107 Disk 0 MBR has been saved successfully to "C:\Users\Christina\Desktop\MBR.dat"
21:48:28.279 The log file has been saved successfully to "C:\Users\Christina\Desktop\aswMBR.txt"
Dear Jeffce,
Do you wish me to post OTL Text and EXTRAS? which I prepared before but could not find the way to answer. I hope this answer will reach you. In my efforts I answered my own topic!
Best regards.
Chris1701
jeffce
Hi,
Yes please post the OTL logs as well. That would be great! 
Chris1701
OTL logfile created on: 4/16/2012 8:52:54 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Christina\Downloads
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1013.30 Mb Total Physical Memory | 216.36 Mb Available Physical Memory | 21.35% Memory free
1.99 Gb Paging File | 0.65 Gb Available in Paging File | 32.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 88.00 Gb Total Space | 56.24 Gb Free Space | 63.91% Space Free | Partition Type: NTFS
Drive D: | 130.35 Gb Total Space | 69.34 Gb Free Space | 53.19% Space Free | Partition Type: NTFS
Computer Name: CHRISSAMSUNG | User Name: Christina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Christina\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - c:\Program Files\McAfee\SiteAdvisor\saUI.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe (SAMSUNG Electronics)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files\McAfee\MAT\McPvTray.exe (McAfee, Inc.)
PRC - C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe (SRS Labs, Inc.)
PRC - C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe (Samsung Electronics)
PRC - C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (SEC)
PRC - C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\PLAY ONLINE\AssistantServices.exe ()
PRC - C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\Samsung\Movie Color Enhancer\WinCRT.dll ()
MOD - C:\Program Files\Samsung\Samsung Recovery Solution 5\Resdll.dll ()
MOD - C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll ()
========== Win32 Services (SafeList) ==========
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (mfevtp) – C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (TeamViewer6) – C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (BecHelperService) – C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (Samsung UPD Service) – C:\Windows\System32\SUPDSvc.exe (Samsung Electronics CO., LTD.)
SRV - (UI Assistant Service) – C:\Program Files\PLAY ONLINE\AssistantServices.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (mfeavfk01) – File not found
DRV - (mfehidk) – C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfewfpk) – C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfenlfk) – C:\Windows\System32\drivers\mfenlfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\Windows\System32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (McPvDrv) – C:\Windows\System32\drivers\McPvDrv.sys (McAfee, Inc.)
DRV - (mdvrmng) – C:\Windows\System32\drivers\mdvrmng.sys ()
DRV - (ewusbmbb) – C:\Windows\System32\drivers\ewusbwwan.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_hwusbdev) – C:\Windows\System32\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (huawei_enumerator) – C:\Windows\System32\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_usbenumfilter) – C:\Windows\System32\drivers\ew_usbenumfilter.sys (Huawei Technologies Co., Ltd.)
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (rtport) – C:\Windows\System32\drivers\rtport.sys (Windows ® 2003 DDK 3790 provider)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - C:\Program Files\WinZipBar\prxtbWinZ.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 04 71 BF 8D 1F D4 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - No CLSID value found
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}: "URL" = http://uk.search.yahoo.com/search?p={searc…209,16938,0,8,0
IE - HKCU\..\SearchScopes\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}: "URL" = http://search.avg.com/route/?d=4e448571&am;…y=&ychte;=us
IE - HKCU\..\SearchScopes\{BBEB043B-0987-45CA-8610-4DA635C9E113}: "URL" = http://websearch.ask.com/redirect?client=i…ppid%3D101%3Auc
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Christina\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/11 23:37:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/04/11 23:48:16 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/04/16 19:57:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/04/11 23:48:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/11 23:48:19 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/11 23:37:25 | 000,000,000 | —D | M]
[2011/10/04 01:13:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Christina\AppData\Roaming\Mozilla\Extensions
[2012/04/11 23:40:38 | 000,000,000 | —D | M] (No name found) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions
[2012/04/11 23:40:38 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/04/11 23:40:37 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]
[2012/04/11 23:40:38 | 000,000,000 | —D | M] (Ask Toolbar) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]
[2012/02/13 16:17:18 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/03/12 11:45:36 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 06:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/04/11 18:32:03 | 000,003,747 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/02/08 18:12:58 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/08 18:12:58 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://search.avg.com/?d=4e4480f1&v;=7….q={searchTerms}
CHR - default_search_provider: suggest_url = http://suggestqueries.google.com/complete/…q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Christina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Users\Christina\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: SiteAdvisor = C:\Users\Christina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\
O1 HOSTS File: ([2011/06/20 12:20:47 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (WinZipBar Toolbar) - {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - C:\Program Files\WinZipBar\prxtbWinZ.dll (Conduit Ltd.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20111230205812.dll (McAfee, Inc.)
O2 - BHO: (W2PBrowser Class) - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (WinZipBar Toolbar) - {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - C:\Program Files\WinZipBar\prxtbWinZ.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [McPvTray_exe] C:\Program Files\McAfee\MAT\McPvTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CA189E4A-4A04-4742-880D-62407F0217CC}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D82A697F-63A7-4A2B-9CD7-D1CBBF0B567D}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/04/16 19:53:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{353ABB58-7BD4-4459-A2EB-C412D6EC8E18}
[2012/04/16 19:52:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{44ACE206-2C0F-4A88-9186-E39AADDA6FE7}
[2012/04/14 20:59:07 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5347E02E-61C4-4A34-82A7-545D2641B3F3}
[2012/04/14 20:58:39 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{022A2F2D-9B12-4D06-B669-A9642629A139}
[2012/04/14 11:21:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{56C1D28E-2276-4DB1-9239-EA48F9749018}
[2012/04/14 11:20:55 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{302F11B4-7742-4911-AAB8-C4243746E438}
[2012/04/12 13:10:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{DEB12ACD-A165-40D6-B120-B90FF89CF18F}
[2012/04/12 13:09:53 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8BEAEFC4-BC24-4E9C-A4BA-925BFC01E83B}
[2012/04/12 10:42:36 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{4E38B6BD-FC8A-41F2-92B3-321A33528DBC}
[2012/04/12 10:42:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{ADDEEC85-BDAB-4677-ADAC-96F49FBBEC9A}
[2012/04/12 02:13:16 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2012/04/12 02:13:11 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\windows\System32\jscript9.dll
[2012/04/12 02:13:08 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\windows\System32\jsproxy.dll
[2012/04/12 02:13:06 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\windows\System32\url.dll
[2012/04/12 02:13:05 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2012/04/12 02:13:03 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\windows\System32\inetcpl.cpl
[2012/04/12 01:26:11 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntkrnlpa.exe
[2012/04/12 01:26:07 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntoskrnl.exe
[2012/04/12 01:13:14 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{53F44410-0F49-4159-A9F7-59CC9BFFC840}
[2012/04/12 01:00:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{366BC4BB-E3D2-4779-8C3E-EF1ED4E083D1}
[2012/04/12 00:59:22 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{129F8187-BA00-4F56-9B40-E66F1178AA51}
[2012/04/11 23:15:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{CB62930E-E8B8-4025-A65D-E322529139F8}
[2012/04/11 19:53:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2012/04/11 18:33:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/04/11 18:32:29 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2012/04/11 18:32:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2012/04/11 18:32:07 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2012/04/11 18:26:16 | 000,000,000 | -H-D | C] – C:\$AVG
[2012/04/11 18:26:15 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2012/04/11 16:45:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SpeedyPC Software
[2012/04/11 16:45:07 | 000,000,000 | —D | C] – C:\Program Files\SpeedyPC Software
[2012/04/10 21:42:54 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{866CAD26-2E62-4941-BDEC-0923B602D05F}
[2012/04/09 02:12:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\SpeedyPC Software
[2012/04/09 02:12:02 | 000,000,000 | —D | C] – C:\ProgramData\SpeedyPC Software
[2012/04/08 23:19:57 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{76C924EA-6DD3-4D30-8A0B-48AE4858BCD8}
[2012/04/03 21:36:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\WinZip
[2012/04/03 20:12:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{33EE76A0-7DA3-43AD-AA28-3D14011E35FA}
[2012/04/03 20:11:27 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{4F619680-21D9-4743-AA23-61D6AD6AFDFD}
[2012/04/03 19:37:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6134C62C-6DBF-4C38-B968-D8951F6892BF}
[2012/04/03 19:20:22 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BC049C4B-D462-49AA-8DBC-5E59C2640EAD}
[2012/04/03 19:19:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{78D44058-B568-47E9-A492-E82E66134CEA}
[2012/03/29 20:41:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{92341BC9-2B8A-4130-AF99-C38DF4ACE36A}
[2012/03/29 19:37:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{75351EA8-4AD7-4C50-89C7-E4901675B152}
[2012/03/26 23:53:31 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{54C4A35C-A82D-4C15-A4B6-0476397D1B3C}
[2012/03/26 23:53:04 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{47D1C48E-CA92-4A51-A53B-A29A2D6F0B0B}
[2012/03/26 11:52:08 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5A15AD8D-6405-440F-801B-97CD9EC05AA2}
[2012/03/26 11:51:43 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{924EF17F-2F86-4D2B-BABC-EA55463BA947}
[2012/03/19 13:17:11 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{D2533852-26D0-434C-A9FE-3001ADF7D953}
[2012/03/19 13:16:47 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{72C3C9BA-ED60-471F-B99E-A965E9805036}
[2012/03/18 14:20:58 | 000,031,552 | —- | C] (TuneUp Software) – C:\windows\System32\TURegOpt.exe
[2012/03/18 14:20:48 | 000,029,504 | —- | C] (TuneUp Software) – C:\windows\System32\uxtuneup.dll
[2012/03/18 14:20:47 | 000,021,312 | —- | C] (TuneUp Software) – C:\windows\System32\authuitu.dll
[2012/03/18 14:20:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2011
[2012/03/18 13:50:29 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{37F74A13-1B75-4C8B-AD1F-4700595BA27D}
[2012/03/18 13:50:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{ACA7B989-880E-45CA-B8F0-A7FDD5A2C211}
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/04/16 20:22:05 | 000,000,892 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/16 19:58:42 | 000,010,592 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/16 19:58:42 | 000,010,592 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/16 19:51:54 | 000,000,888 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/16 19:50:31 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/04/16 19:50:27 | 1062,518,784 | -HS- | M] () – C:\hiberfil.sys
[2012/04/16 14:54:34 | 000,002,290 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/04/14 12:32:14 | 000,649,584 | —- | M] () – C:\windows\System32\perfh009.dat
[2012/04/14 12:32:14 | 000,120,746 | —- | M] () – C:\windows\System32\perfc009.dat
[2012/04/12 13:18:51 | 000,625,664 | —- | M] () – C:\Users\Christina\Desktop\dds.scr
[2012/04/11 01:35:17 | 000,392,875 | —- | M] () – C:\Users\Christina\Desktop\fru_7steps.pdf
[2012/03/18 14:20:31 | 000,002,159 | —- | M] () – C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
[2012/03/18 14:20:30 | 000,002,141 | —- | M] () – C:\Users\Public\Desktop\TuneUp Utilities 2011.lnk
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/04/12 13:18:23 | 000,625,664 | —- | C] () – C:\Users\Christina\Desktop\dds.scr
[2012/04/11 01:35:17 | 000,392,875 | —- | C] () – C:\Users\Christina\Desktop\fru_7steps.pdf
[2012/03/18 14:20:31 | 000,002,159 | —- | C] () – C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
[2012/03/18 14:20:30 | 000,002,141 | —- | C] () – C:\Users\Public\Desktop\TuneUp Utilities 2011.lnk
[2012/03/18 14:20:22 | 000,002,153 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2011.lnk
[2011/11/02 10:40:35 | 000,003,584 | —- | C] () – C:\Users\Christina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/14 11:06:49 | 000,067,156 | —- | C] () – C:\windows\Huawei ModemsUninstall.exe
[2011/10/14 11:06:43 | 000,010,240 | —- | C] () – C:\windows\System32\drivers\mdvrmng.sys
[2011/08/20 00:52:46 | 000,023,128 | —- | C] () – C:\windows\hpqins15.dat
[2011/07/03 20:40:27 | 000,202,283 | —- | C] () – C:\windows\hpoins18.dat
[2011/07/03 20:40:27 | 000,005,355 | —- | C] () – C:\windows\hpomdl18.dat
[2011/06/25 16:30:02 | 000,202,516 | —- | C] () – C:\windows\hpoins18.dat.temp
[2011/06/25 16:30:02 | 000,005,355 | —- | C] () – C:\windows\hpomdl18.dat.temp
[2011/06/19 20:00:48 | 000,012,164 | -HS- | C] () – C:\Users\Christina\AppData\Local\ux28k8k70xg6ehd13ev2e
[2011/06/19 20:00:48 | 000,012,164 | -HS- | C] () – C:\ProgramData\ux28k8k70xg6ehd13ev2e
[2011/06/04 20:34:36 | 000,000,376 | —- | C] () – C:\windows\ODBC.INI
[2011/01/19 08:42:30 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/01/19 08:07:17 | 000,000,000 | —- | C] () – C:\windows\nsreg.dat
[2011/01/17 11:01:21 | 000,120,688 | —- | C] () – C:\windows\Wiainst.exe
[2011/01/17 11:00:36 | 000,552,960 | —- | C] () – C:\windows\System32\SnMinDrv.dll
[2011/01/17 11:00:36 | 000,154,112 | —- | C] () – C:\windows\System32\SNWIAUI.dll
[2011/01/17 11:00:36 | 000,135,168 | —- | C] () – C:\windows\System32\SnImgFlt.dll
[2011/01/17 11:00:36 | 000,094,208 | —- | C] () – C:\windows\System32\SnErHdlr.dll
[2011/01/17 11:00:16 | 000,484,656 | —- | C] () – C:\windows\ssndii.exe
[2011/01/17 10:59:30 | 000,259,888 | —- | C] () – C:\windows\SUPDRun.exe
[2011/01/17 10:59:30 | 000,151,552 | —- | C] () – C:\windows\System32\spd__ci.exe
[2011/01/17 10:59:29 | 000,283,136 | —- | C] () – C:\windows\System32\DscPnt.dll
[2011/01/17 10:59:29 | 000,026,624 | —- | C] () – C:\windows\System32\spd__l.dll
[2010/09/01 11:06:37 | 000,001,064 | —- | C] () – C:\windows\HotFixList.ini
[2010/09/01 10:49:40 | 000,006,656 | —- | C] () – C:\windows\System32\bcmwlrc.dll
========== LOP Check ==========
[2012/04/11 21:08:20 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\AVG
[2012/04/11 23:40:32 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\AVG10
[2012/04/11 23:40:32 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\Birdstep Technology
[2012/04/11 23:40:32 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\CompuClever
[2012/04/09 02:12:51 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\DriverCure
[2011/05/20 15:57:07 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\FileZilla
[2012/04/11 23:50:04 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\IrfanView
[2012/04/11 23:40:33 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\KompoZer
[2012/04/11 23:40:38 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\OpenOffice.org
[2011/04/09 13:32:03 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\ParetoLogic
[2011/02/23 05:08:34 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\RegistryKeys
[2011/01/17 10:59:15 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\Samsung
[2012/04/11 23:40:39 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\SoftGrid Client
[2012/04/11 23:40:39 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\Software Informer
[2012/04/09 02:12:51 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\SpeedyPC Software
[2011/11/07 14:53:21 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\Systweak
[2011/04/21 13:32:55 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\TP
[2011/08/13 13:52:16 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\TuneUp Software
[2011/02/23 04:10:35 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\Uniblue
[2011/02/01 12:49:37 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\Windows Live Writer
[2011/04/16 11:59:31 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\{90140011-0066-0409-0000-0000000FF1CE}
[2012/02/23 17:43:31 | 000,032,608 | —- | M] () – C:\windows\Tasks\SCHEDLGU.TXT
[2012/01/05 02:25:30 | 000,000,410 | —- | M] () – C:\windows\Tasks\vtscheduletask.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:B63300D1
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:D1B5B4F1
< End of report >
OTL Extras.Txt
OTL Extras logfile created on: 4/16/2012 8:52:54 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Christina\Downloads
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1013.30 Mb Total Physical Memory | 216.36 Mb Available Physical Memory | 21.35% Memory free
1.99 Gb Paging File | 0.65 Gb Available in Paging File | 32.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 88.00 Gb Total Space | 56.24 Gb Free Space | 63.91% Space Free | Partition Type: NTFS
Drive D: | 130.35 Gb Total Space | 69.34 Gb Free Space | 53.19% Space Free | Partition Type: NTFS
Computer Name: CHRISSAMSUNG | User Name: Christina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0DEF8C02-2EAB-4BFE-A7E0-7990665DF1A9}" = C6100
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{142D8CA7-2C6F-45A7-83E3-099AAFD99133}" = Samsung Update Plus
"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution 5
"{17016DA1-F040-4032-BD36-34DD317BC9D5}" = HP Photosmart All-In-One Driver Software 13.0 Rel. A
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{18AA278D-E0B9-4F99-ACCC-070978A38453}" = Easy Resolution Manager
"{1DF9729D-2A51-4CA1-B4CE-2B432D7ABA7C}" = Samsung AnyWeb Print
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{23BE4DF2-293D-4077-82F4-1FD8C269277C}" = TuneUp Utilities Language Pack (en-US)
"{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 29
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2998191E-A35E-47E2-BE38-7702C731D722}" = SRS Premium Sound Control Panel
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2A7EF808-14F3-4E93-BE3A-1675EE5332A4}" = AIO_CDA_ProductContext
"{2DDC70C1-C77A-4D08-89D2-9AB648504533}" = Easy Content Share
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{318DBE01-1E6B-4243-84B0-210391FE789A}" = Samsung AnyWeb Print
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4BD5B5D2-406D-4bc5-BB10-2F0D1D367C95}" = c6100_Help
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{559D1FDB-6D5C-4EF3-8F63-5E1E93A0A244}" = Easy Network Manager
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{607DA1C8-34EC-4D7A-AD83-F8E5C70736DF}" = EasyBatteryManager
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{75247E38-5C9B-45D6-ADF8-E11CB56B4990}" = Network
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{77F45ECD-FAFC-45A8-8896-CFFB139DAAA3}" = Fast Start
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7F6F62F0-7884-4CFB-B86C-597A4A6D9C4D}" = Movie Color Enhancer
"{82AF3E91-57E1-4754-84D0-40A46E2479AB}" = OpenOffice.org 3.3
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}" = iLivid
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007F-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A5C8BFF2-0044-4500-8BB5-BEB0D2335885}" = REALTEK PCIE Wireless LAN Software
"{A7AEE29F-839E-46B5-B347-6D430618129F}" = AIO_CDA_Software
"{A899DA1F-D626-401C-8651-F2921E3B4CB3}" = 3Connect
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}" = PLAY ONLINE
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C4582EED-A3FB-4358-8F3F-8C994460DF28}" = EasyFileShare
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240CA}" = WinZip 16.0
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D1434266-0486-4469-B338-A60082CC04E1}" = Atheros Client Installation Program
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E308B555-8434-4AF8-B66F-729897C75F93}" = BatteryLifeExtender
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager
"{EFA6EF6A-9E0D-4CF0-91DD-B55D8632F65A}" = SamsungMovie
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F687E657-F636-44DF-8125-9FEEA2C362F5}" = Samsung Support Center 1.0
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.9
"Broadcom 802.11 Network Adapter" = Broadcom 802.11 Network Adapter
"Elantech" = ETDWare PS/2-X86 8.0.7.0_WHQL
"FileZilla Client" = FileZilla Client 3.4.0
"Google Chrome" = Google Chrome
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Huawei Modems" = Huawei modem
"iLivid" = iLivid
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"IrfanView" = IrfanView (remove only)
"Marvell Miniport Driver" = Marvell Miniport Driver
"McAfee Virtual Technician" = McAfee Virtual Technician
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US)
"MSC" = McAfee Total Protection
"Samsung Universal Print Driver" = Samsung Universal Print Driver
"Samsung Universal Scan Driver" = Samsung Universal Scan Driver
"Shop for HP Supplies" = Shop for HP Supplies
"Software Informer_is1" = Software Informer 1.1
"TeamViewer 6" = TeamViewer 6
"TuneUp Utilities 2011" = TuneUp Utilities 2011
"Vit Registry Fix" = Vit Registry Fix 9.5.4 (remove only)
"WinLiveSuite" = Windows Live Essentials
"WinZipBar Toolbar" = WinZipBar Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/14/2012 6:29:03 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 4/14/2012 6:29:03 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 251832
Error - 4/14/2012 6:29:03 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 251832
Error - 4/14/2012 6:29:04 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 4/14/2012 6:29:04 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 252846
Error - 4/14/2012 6:29:04 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 252846
Error - 4/14/2012 6:29:05 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 4/14/2012 6:29:05 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 253860
Error - 4/14/2012 6:29:05 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 253860
Error - 4/14/2012 6:29:06 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
[ System Events ]
Error - 4/12/2012 5:39:27 AM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom
Error - 4/12/2012 8:08:25 AM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom
Error - 4/14/2012 6:18:31 AM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom
Error - 4/14/2012 6:19:08 AM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the TeamViewer6 service.
Error - 4/14/2012 11:16:04 AM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom
Error - 4/14/2012 11:21:42 AM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7022
Description = The Windows Update service hung on starting.
Error - 4/14/2012 3:56:33 PM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom
Error - 4/16/2012 9:15:55 AM | Computer Name = ChrisSamsung | Source = DCOM | ID = 10010
Description =
Error - 4/16/2012 11:38:08 AM | Computer Name = ChrisSamsung | Source = DCOM | ID = 10010
Description =
Error - 4/16/2012 2:51:02 PM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom
< End of report >
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Christina\Downloads
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1013.30 Mb Total Physical Memory | 216.36 Mb Available Physical Memory | 21.35% Memory free
1.99 Gb Paging File | 0.65 Gb Available in Paging File | 32.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 88.00 Gb Total Space | 56.24 Gb Free Space | 63.91% Space Free | Partition Type: NTFS
Drive D: | 130.35 Gb Total Space | 69.34 Gb Free Space | 53.19% Space Free | Partition Type: NTFS
Computer Name: CHRISSAMSUNG | User Name: Christina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Christina\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - c:\Program Files\McAfee\SiteAdvisor\saUI.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe (SAMSUNG Electronics)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files\McAfee\MAT\McPvTray.exe (McAfee, Inc.)
PRC - C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe (SRS Labs, Inc.)
PRC - C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe (Samsung Electronics)
PRC - C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (SEC)
PRC - C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\PLAY ONLINE\AssistantServices.exe ()
PRC - C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\Samsung\Movie Color Enhancer\WinCRT.dll ()
MOD - C:\Program Files\Samsung\Samsung Recovery Solution 5\Resdll.dll ()
MOD - C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll ()
========== Win32 Services (SafeList) ==========
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (mfevtp) – C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (TeamViewer6) – C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (BecHelperService) – C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (Samsung UPD Service) – C:\Windows\System32\SUPDSvc.exe (Samsung Electronics CO., LTD.)
SRV - (UI Assistant Service) – C:\Program Files\PLAY ONLINE\AssistantServices.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (mfeavfk01) – File not found
DRV - (mfehidk) – C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfewfpk) – C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfenlfk) – C:\Windows\System32\drivers\mfenlfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\Windows\System32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (McPvDrv) – C:\Windows\System32\drivers\McPvDrv.sys (McAfee, Inc.)
DRV - (mdvrmng) – C:\Windows\System32\drivers\mdvrmng.sys ()
DRV - (ewusbmbb) – C:\Windows\System32\drivers\ewusbwwan.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_hwusbdev) – C:\Windows\System32\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (huawei_enumerator) – C:\Windows\System32\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_usbenumfilter) – C:\Windows\System32\drivers\ew_usbenumfilter.sys (Huawei Technologies Co., Ltd.)
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (rtport) – C:\Windows\System32\drivers\rtport.sys (Windows ® 2003 DDK 3790 provider)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - C:\Program Files\WinZipBar\prxtbWinZ.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 04 71 BF 8D 1F D4 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - No CLSID value found
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}: "URL" = http://uk.search.yahoo.com/search?p={searc…209,16938,0,8,0
IE - HKCU\..\SearchScopes\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}: "URL" = http://search.avg.com/route/?d=4e448571&am;…y=&ychte;=us
IE - HKCU\..\SearchScopes\{BBEB043B-0987-45CA-8610-4DA635C9E113}: "URL" = http://websearch.ask.com/redirect?client=i…ppid%3D101%3Auc
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Christina\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/11 23:37:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/04/11 23:48:16 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/04/16 19:57:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/04/11 23:48:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/11 23:48:19 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/11 23:37:25 | 000,000,000 | —D | M]
[2011/10/04 01:13:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Christina\AppData\Roaming\Mozilla\Extensions
[2012/04/11 23:40:38 | 000,000,000 | —D | M] (No name found) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions
[2012/04/11 23:40:38 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/04/11 23:40:37 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]
[2012/04/11 23:40:38 | 000,000,000 | —D | M] (Ask Toolbar) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]
[2012/02/13 16:17:18 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/03/12 11:45:36 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 06:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/04/11 18:32:03 | 000,003,747 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/02/08 18:12:58 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/08 18:12:58 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://search.avg.com/?d=4e4480f1&v;=7….q={searchTerms}
CHR - default_search_provider: suggest_url = http://suggestqueries.google.com/complete/…q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Christina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Users\Christina\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: SiteAdvisor = C:\Users\Christina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\
O1 HOSTS File: ([2011/06/20 12:20:47 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (WinZipBar Toolbar) - {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - C:\Program Files\WinZipBar\prxtbWinZ.dll (Conduit Ltd.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20111230205812.dll (McAfee, Inc.)
O2 - BHO: (W2PBrowser Class) - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (WinZipBar Toolbar) - {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - C:\Program Files\WinZipBar\prxtbWinZ.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [McPvTray_exe] C:\Program Files\McAfee\MAT\McPvTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CA189E4A-4A04-4742-880D-62407F0217CC}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D82A697F-63A7-4A2B-9CD7-D1CBBF0B567D}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/04/16 19:53:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{353ABB58-7BD4-4459-A2EB-C412D6EC8E18}
[2012/04/16 19:52:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{44ACE206-2C0F-4A88-9186-E39AADDA6FE7}
[2012/04/14 20:59:07 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5347E02E-61C4-4A34-82A7-545D2641B3F3}
[2012/04/14 20:58:39 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{022A2F2D-9B12-4D06-B669-A9642629A139}
[2012/04/14 11:21:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{56C1D28E-2276-4DB1-9239-EA48F9749018}
[2012/04/14 11:20:55 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{302F11B4-7742-4911-AAB8-C4243746E438}
[2012/04/12 13:10:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{DEB12ACD-A165-40D6-B120-B90FF89CF18F}
[2012/04/12 13:09:53 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8BEAEFC4-BC24-4E9C-A4BA-925BFC01E83B}
[2012/04/12 10:42:36 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{4E38B6BD-FC8A-41F2-92B3-321A33528DBC}
[2012/04/12 10:42:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{ADDEEC85-BDAB-4677-ADAC-96F49FBBEC9A}
[2012/04/12 02:13:16 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2012/04/12 02:13:11 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\windows\System32\jscript9.dll
[2012/04/12 02:13:08 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\windows\System32\jsproxy.dll
[2012/04/12 02:13:06 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\windows\System32\url.dll
[2012/04/12 02:13:05 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2012/04/12 02:13:03 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\windows\System32\inetcpl.cpl
[2012/04/12 01:26:11 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntkrnlpa.exe
[2012/04/12 01:26:07 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntoskrnl.exe
[2012/04/12 01:13:14 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{53F44410-0F49-4159-A9F7-59CC9BFFC840}
[2012/04/12 01:00:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{366BC4BB-E3D2-4779-8C3E-EF1ED4E083D1}
[2012/04/12 00:59:22 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{129F8187-BA00-4F56-9B40-E66F1178AA51}
[2012/04/11 23:15:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{CB62930E-E8B8-4025-A65D-E322529139F8}
[2012/04/11 19:53:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2012/04/11 18:33:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/04/11 18:32:29 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2012/04/11 18:32:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2012/04/11 18:32:07 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2012/04/11 18:26:16 | 000,000,000 | -H-D | C] – C:\$AVG
[2012/04/11 18:26:15 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2012/04/11 16:45:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SpeedyPC Software
[2012/04/11 16:45:07 | 000,000,000 | —D | C] – C:\Program Files\SpeedyPC Software
[2012/04/10 21:42:54 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{866CAD26-2E62-4941-BDEC-0923B602D05F}
[2012/04/09 02:12:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\SpeedyPC Software
[2012/04/09 02:12:02 | 000,000,000 | —D | C] – C:\ProgramData\SpeedyPC Software
[2012/04/08 23:19:57 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{76C924EA-6DD3-4D30-8A0B-48AE4858BCD8}
[2012/04/03 21:36:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\WinZip
[2012/04/03 20:12:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{33EE76A0-7DA3-43AD-AA28-3D14011E35FA}
[2012/04/03 20:11:27 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{4F619680-21D9-4743-AA23-61D6AD6AFDFD}
[2012/04/03 19:37:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6134C62C-6DBF-4C38-B968-D8951F6892BF}
[2012/04/03 19:20:22 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BC049C4B-D462-49AA-8DBC-5E59C2640EAD}
[2012/04/03 19:19:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{78D44058-B568-47E9-A492-E82E66134CEA}
[2012/03/29 20:41:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{92341BC9-2B8A-4130-AF99-C38DF4ACE36A}
[2012/03/29 19:37:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{75351EA8-4AD7-4C50-89C7-E4901675B152}
[2012/03/26 23:53:31 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{54C4A35C-A82D-4C15-A4B6-0476397D1B3C}
[2012/03/26 23:53:04 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{47D1C48E-CA92-4A51-A53B-A29A2D6F0B0B}
[2012/03/26 11:52:08 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5A15AD8D-6405-440F-801B-97CD9EC05AA2}
[2012/03/26 11:51:43 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{924EF17F-2F86-4D2B-BABC-EA55463BA947}
[2012/03/19 13:17:11 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{D2533852-26D0-434C-A9FE-3001ADF7D953}
[2012/03/19 13:16:47 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{72C3C9BA-ED60-471F-B99E-A965E9805036}
[2012/03/18 14:20:58 | 000,031,552 | —- | C] (TuneUp Software) – C:\windows\System32\TURegOpt.exe
[2012/03/18 14:20:48 | 000,029,504 | —- | C] (TuneUp Software) – C:\windows\System32\uxtuneup.dll
[2012/03/18 14:20:47 | 000,021,312 | —- | C] (TuneUp Software) – C:\windows\System32\authuitu.dll
[2012/03/18 14:20:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2011
[2012/03/18 13:50:29 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{37F74A13-1B75-4C8B-AD1F-4700595BA27D}
[2012/03/18 13:50:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{ACA7B989-880E-45CA-B8F0-A7FDD5A2C211}
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/04/16 20:22:05 | 000,000,892 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/16 19:58:42 | 000,010,592 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/16 19:58:42 | 000,010,592 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/16 19:51:54 | 000,000,888 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/16 19:50:31 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/04/16 19:50:27 | 1062,518,784 | -HS- | M] () – C:\hiberfil.sys
[2012/04/16 14:54:34 | 000,002,290 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/04/14 12:32:14 | 000,649,584 | —- | M] () – C:\windows\System32\perfh009.dat
[2012/04/14 12:32:14 | 000,120,746 | —- | M] () – C:\windows\System32\perfc009.dat
[2012/04/12 13:18:51 | 000,625,664 | —- | M] () – C:\Users\Christina\Desktop\dds.scr
[2012/04/11 01:35:17 | 000,392,875 | —- | M] () – C:\Users\Christina\Desktop\fru_7steps.pdf
[2012/03/18 14:20:31 | 000,002,159 | —- | M] () – C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
[2012/03/18 14:20:30 | 000,002,141 | —- | M] () – C:\Users\Public\Desktop\TuneUp Utilities 2011.lnk
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/04/12 13:18:23 | 000,625,664 | —- | C] () – C:\Users\Christina\Desktop\dds.scr
[2012/04/11 01:35:17 | 000,392,875 | —- | C] () – C:\Users\Christina\Desktop\fru_7steps.pdf
[2012/03/18 14:20:31 | 000,002,159 | —- | C] () – C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
[2012/03/18 14:20:30 | 000,002,141 | —- | C] () – C:\Users\Public\Desktop\TuneUp Utilities 2011.lnk
[2012/03/18 14:20:22 | 000,002,153 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2011.lnk
[2011/11/02 10:40:35 | 000,003,584 | —- | C] () – C:\Users\Christina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/14 11:06:49 | 000,067,156 | —- | C] () – C:\windows\Huawei ModemsUninstall.exe
[2011/10/14 11:06:43 | 000,010,240 | —- | C] () – C:\windows\System32\drivers\mdvrmng.sys
[2011/08/20 00:52:46 | 000,023,128 | —- | C] () – C:\windows\hpqins15.dat
[2011/07/03 20:40:27 | 000,202,283 | —- | C] () – C:\windows\hpoins18.dat
[2011/07/03 20:40:27 | 000,005,355 | —- | C] () – C:\windows\hpomdl18.dat
[2011/06/25 16:30:02 | 000,202,516 | —- | C] () – C:\windows\hpoins18.dat.temp
[2011/06/25 16:30:02 | 000,005,355 | —- | C] () – C:\windows\hpomdl18.dat.temp
[2011/06/19 20:00:48 | 000,012,164 | -HS- | C] () – C:\Users\Christina\AppData\Local\ux28k8k70xg6ehd13ev2e
[2011/06/19 20:00:48 | 000,012,164 | -HS- | C] () – C:\ProgramData\ux28k8k70xg6ehd13ev2e
[2011/06/04 20:34:36 | 000,000,376 | —- | C] () – C:\windows\ODBC.INI
[2011/01/19 08:42:30 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/01/19 08:07:17 | 000,000,000 | —- | C] () – C:\windows\nsreg.dat
[2011/01/17 11:01:21 | 000,120,688 | —- | C] () – C:\windows\Wiainst.exe
[2011/01/17 11:00:36 | 000,552,960 | —- | C] () – C:\windows\System32\SnMinDrv.dll
[2011/01/17 11:00:36 | 000,154,112 | —- | C] () – C:\windows\System32\SNWIAUI.dll
[2011/01/17 11:00:36 | 000,135,168 | —- | C] () – C:\windows\System32\SnImgFlt.dll
[2011/01/17 11:00:36 | 000,094,208 | —- | C] () – C:\windows\System32\SnErHdlr.dll
[2011/01/17 11:00:16 | 000,484,656 | —- | C] () – C:\windows\ssndii.exe
[2011/01/17 10:59:30 | 000,259,888 | —- | C] () – C:\windows\SUPDRun.exe
[2011/01/17 10:59:30 | 000,151,552 | —- | C] () – C:\windows\System32\spd__ci.exe
[2011/01/17 10:59:29 | 000,283,136 | —- | C] () – C:\windows\System32\DscPnt.dll
[2011/01/17 10:59:29 | 000,026,624 | —- | C] () – C:\windows\System32\spd__l.dll
[2010/09/01 11:06:37 | 000,001,064 | —- | C] () – C:\windows\HotFixList.ini
[2010/09/01 10:49:40 | 000,006,656 | —- | C] () – C:\windows\System32\bcmwlrc.dll
========== LOP Check ==========
[2012/04/11 21:08:20 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\AVG
[2012/04/11 23:40:32 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\AVG10
[2012/04/11 23:40:32 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\Birdstep Technology
[2012/04/11 23:40:32 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\CompuClever
[2012/04/09 02:12:51 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\DriverCure
[2011/05/20 15:57:07 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\FileZilla
[2012/04/11 23:50:04 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\IrfanView
[2012/04/11 23:40:33 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\KompoZer
[2012/04/11 23:40:38 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\OpenOffice.org
[2011/04/09 13:32:03 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\ParetoLogic
[2011/02/23 05:08:34 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\RegistryKeys
[2011/01/17 10:59:15 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\Samsung
[2012/04/11 23:40:39 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\SoftGrid Client
[2012/04/11 23:40:39 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\Software Informer
[2012/04/09 02:12:51 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\SpeedyPC Software
[2011/11/07 14:53:21 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\Systweak
[2011/04/21 13:32:55 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\TP
[2011/08/13 13:52:16 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\TuneUp Software
[2011/02/23 04:10:35 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\Uniblue
[2011/02/01 12:49:37 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\Windows Live Writer
[2011/04/16 11:59:31 | 000,000,000 | —D | M] – C:\Users\Christina\AppData\Roaming\{90140011-0066-0409-0000-0000000FF1CE}
[2012/02/23 17:43:31 | 000,032,608 | —- | M] () – C:\windows\Tasks\SCHEDLGU.TXT
[2012/01/05 02:25:30 | 000,000,410 | —- | M] () – C:\windows\Tasks\vtscheduletask.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:B63300D1
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:D1B5B4F1
< End of report >
OTL Extras.Txt
OTL Extras logfile created on: 4/16/2012 8:52:54 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Christina\Downloads
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1013.30 Mb Total Physical Memory | 216.36 Mb Available Physical Memory | 21.35% Memory free
1.99 Gb Paging File | 0.65 Gb Available in Paging File | 32.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 88.00 Gb Total Space | 56.24 Gb Free Space | 63.91% Space Free | Partition Type: NTFS
Drive D: | 130.35 Gb Total Space | 69.34 Gb Free Space | 53.19% Space Free | Partition Type: NTFS
Computer Name: CHRISSAMSUNG | User Name: Christina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0DEF8C02-2EAB-4BFE-A7E0-7990665DF1A9}" = C6100
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{142D8CA7-2C6F-45A7-83E3-099AAFD99133}" = Samsung Update Plus
"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution 5
"{17016DA1-F040-4032-BD36-34DD317BC9D5}" = HP Photosmart All-In-One Driver Software 13.0 Rel. A
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{18AA278D-E0B9-4F99-ACCC-070978A38453}" = Easy Resolution Manager
"{1DF9729D-2A51-4CA1-B4CE-2B432D7ABA7C}" = Samsung AnyWeb Print
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{23BE4DF2-293D-4077-82F4-1FD8C269277C}" = TuneUp Utilities Language Pack (en-US)
"{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 29
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2998191E-A35E-47E2-BE38-7702C731D722}" = SRS Premium Sound Control Panel
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2A7EF808-14F3-4E93-BE3A-1675EE5332A4}" = AIO_CDA_ProductContext
"{2DDC70C1-C77A-4D08-89D2-9AB648504533}" = Easy Content Share
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{318DBE01-1E6B-4243-84B0-210391FE789A}" = Samsung AnyWeb Print
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4BD5B5D2-406D-4bc5-BB10-2F0D1D367C95}" = c6100_Help
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{559D1FDB-6D5C-4EF3-8F63-5E1E93A0A244}" = Easy Network Manager
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{607DA1C8-34EC-4D7A-AD83-F8E5C70736DF}" = EasyBatteryManager
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{75247E38-5C9B-45D6-ADF8-E11CB56B4990}" = Network
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{77F45ECD-FAFC-45A8-8896-CFFB139DAAA3}" = Fast Start
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7F6F62F0-7884-4CFB-B86C-597A4A6D9C4D}" = Movie Color Enhancer
"{82AF3E91-57E1-4754-84D0-40A46E2479AB}" = OpenOffice.org 3.3
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}" = iLivid
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007F-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A5C8BFF2-0044-4500-8BB5-BEB0D2335885}" = REALTEK PCIE Wireless LAN Software
"{A7AEE29F-839E-46B5-B347-6D430618129F}" = AIO_CDA_Software
"{A899DA1F-D626-401C-8651-F2921E3B4CB3}" = 3Connect
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}" = PLAY ONLINE
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C4582EED-A3FB-4358-8F3F-8C994460DF28}" = EasyFileShare
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240CA}" = WinZip 16.0
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D1434266-0486-4469-B338-A60082CC04E1}" = Atheros Client Installation Program
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E308B555-8434-4AF8-B66F-729897C75F93}" = BatteryLifeExtender
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager
"{EFA6EF6A-9E0D-4CF0-91DD-B55D8632F65A}" = SamsungMovie
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F687E657-F636-44DF-8125-9FEEA2C362F5}" = Samsung Support Center 1.0
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.9
"Broadcom 802.11 Network Adapter" = Broadcom 802.11 Network Adapter
"Elantech" = ETDWare PS/2-X86 8.0.7.0_WHQL
"FileZilla Client" = FileZilla Client 3.4.0
"Google Chrome" = Google Chrome
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Huawei Modems" = Huawei modem
"iLivid" = iLivid
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"IrfanView" = IrfanView (remove only)
"Marvell Miniport Driver" = Marvell Miniport Driver
"McAfee Virtual Technician" = McAfee Virtual Technician
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US)
"MSC" = McAfee Total Protection
"Samsung Universal Print Driver" = Samsung Universal Print Driver
"Samsung Universal Scan Driver" = Samsung Universal Scan Driver
"Shop for HP Supplies" = Shop for HP Supplies
"Software Informer_is1" = Software Informer 1.1
"TeamViewer 6" = TeamViewer 6
"TuneUp Utilities 2011" = TuneUp Utilities 2011
"Vit Registry Fix" = Vit Registry Fix 9.5.4 (remove only)
"WinLiveSuite" = Windows Live Essentials
"WinZipBar Toolbar" = WinZipBar Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/14/2012 6:29:03 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 4/14/2012 6:29:03 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 251832
Error - 4/14/2012 6:29:03 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 251832
Error - 4/14/2012 6:29:04 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 4/14/2012 6:29:04 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 252846
Error - 4/14/2012 6:29:04 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 252846
Error - 4/14/2012 6:29:05 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 4/14/2012 6:29:05 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 253860
Error - 4/14/2012 6:29:05 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 253860
Error - 4/14/2012 6:29:06 AM | Computer Name = ChrisSamsung | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
[ System Events ]
Error - 4/12/2012 5:39:27 AM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom
Error - 4/12/2012 8:08:25 AM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom
Error - 4/14/2012 6:18:31 AM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom
Error - 4/14/2012 6:19:08 AM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the TeamViewer6 service.
Error - 4/14/2012 11:16:04 AM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom
Error - 4/14/2012 11:21:42 AM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7022
Description = The Windows Update service hung on starting.
Error - 4/14/2012 3:56:33 PM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom
Error - 4/16/2012 9:15:55 AM | Computer Name = ChrisSamsung | Source = DCOM | ID = 10010
Description =
Error - 4/16/2012 11:38:08 AM | Computer Name = ChrisSamsung | Source = DCOM | ID = 10010
Description =
Error - 4/16/2012 2:51:02 PM | Computer Name = ChrisSamsung | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom
< End of report >
jeffce
Hi,
Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-
Run OTL.exe
Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-
Run OTL.exe
- Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL
:Services :OTL IE - HKLM\..\URLSearchHook: {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - C:\Program Files\WinZipBar\prxtbWinZ.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406 IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - No CLSID value found IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\..\SearchScopes\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}: "URL" = http://uk.search.yahoo.com/search?p={searc…209,16938,0,8,0 IE - HKCU\..\SearchScopes\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}: "URL" = http://search.avg.com/route/?d=4e448571&am…y=&ychte=us IE - HKCU\..\SearchScopes\{BBEB043B-0987-45CA-8610-4DA635C9E113}: "URL" = http://websearch.ask.com/redirect?client=i…ppid%3D101%3Auc [2012/04/11 23:40:38 | 000,000,000 | —D | M] (Ask Toolbar) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed] O2 - BHO: (WinZipBar Toolbar) - {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - C:\Program Files\WinZipBar\prxtbWinZ.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (WinZipBar Toolbar) - {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - C:\Program Files\WinZipBar\prxtbWinZ.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites) O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites) O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites) [2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ] [2011/11/02 10:40:35 | 000,003,584 | —- | C] () – C:\Users\Christina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/06/19 20:00:48 | 000,012,164 | -HS- | C] () – C:\Users\Christina\AppData\Local\ux28k8k70xg6ehd13ev2e [2011/06/19 20:00:48 | 000,012,164 | -HS- | C] () – C:\ProgramData\ux28k8k70xg6ehd13ev2e :Files ipconfig /flushdns /c :Commands [purity] [emptytemp] [start explorer] [Reboot] - Then click the Run Fix button at the top
- Let the program run unhindered, reboot when it is done
- Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Chris1701
Could you please give a link to OTL.exe. I lost it , can't find in program files nor downloads. Many say on forums how difficult it is to find uncorrupted OTL download so I am cautious to load from anywhere.
I struggle to write because my cursor is jumping about and I have to watch every letter.y as
I shall do as you say asap.
LDTate
http://oldtimer.geekstogo.com/OTL.exe
jeffce
Thanks for getting that for me while I was out LDTate. 
LDTate
Thanks for getting that for me while I was out LDTate.
Chris1701
Tried to copy but OTL opens without paste facility. I shall try to figure out how to do it.
Its 2am in London. Hope you are in the US. I shall continue tomorrow. Thank you very much for your patience and help.
Chris.
jeffce
You are not able to cut/paste into the Custom Scans/Fix portion of OTL?
Chris1701
Hi
Thanks to your influence I learned 3 other ways to paste. so-far I have been using 1. After rebooting following RunFix I found the following Notepad:
All processes killed
Error: Unable to interpret
Thanks to your influence I learned 3 other ways to paste. so-far I have been using 1. After rebooting following RunFix I found the following Notepad:
All processes killed
Error: Unable to interpret
in the current context!
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ deleted successfully.
C:\Program Files\WinZipBar\prxtbWinZ.dll moved successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\searchplugins folder moved successfully.
C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\logs folder moved successfully.
C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\defaults\preferences folder moved successfully.
C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\defaults folder moved successfully.
C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\datastore folder moved successfully.
C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\chrome\temp\ff-config.Tue-04-Oct-2011-00-20-57-GMT folder moved successfully.
C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\chrome\temp folder moved successfully.
C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\chrome\skin folder moved successfully.
C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\chrome\content folder moved successfully.
C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\chrome folder moved successfully.
C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed] folder moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internet\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
C:\Program Files\GUME262.tmp\GoogleCrashHandler.exe deleted successfully.
C:\Program Files\GUME262.tmp\GoogleCrashHandler64.exe deleted successfully.
C:\Program Files\GUME262.tmp\GoogleUpdate.exe deleted successfully.
C:\Program Files\GUME262.tmp\GoogleUpdateBroker.exe deleted successfully.
C:\Program Files\GUME262.tmp\GoogleUpdateHelper.msi deleted successfully.
C:\Program Files\GUME262.tmp\GoogleUpdateOnDemand.exe deleted successfully.
C:\Program Files\GUME262.tmp\GoogleUpdateSetup.exe deleted successfully.
C:\Program Files\GUME262.tmp\goopdate.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_am.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_ar.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_bg.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_bn.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_ca.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_cs.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_da.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_de.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_el.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_en-GB.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_en.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_es-419.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_es.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_et.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_fa.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_fi.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_fil.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_fr.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_gu.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_hi.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_hr.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_hu.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_id.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_is.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_it.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_iw.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_ja.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_kn.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_ko.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_lt.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_lv.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_ml.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_mr.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_ms.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_nl.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_no.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_pl.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_pt-BR.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_pt-PT.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_ro.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_ru.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_sk.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_sl.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_sr.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_sv.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_sw.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_ta.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_te.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_th.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_tr.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_uk.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_ur.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_vi.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_zh-CN.dll deleted successfully.
C:\Program Files\GUME262.tmp\goopdateres_zh-TW.dll deleted successfully.
C:\Program Files\GUME262.tmp\npGoogleUpdate3.dll deleted successfully.
C:\Program Files\GUME262.tmp\psmachine.dll deleted successfully.
C:\Program Files\GUME262.tmp\psuser.dll deleted successfully.
C:\Program Files\GUME262.tmp folder deleted successfully.
C:\Program Files\GUTE282.tmp deleted successfully.
C:\Users\Christina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
C:\Users\Christina\AppData\Local\ux28k8k70xg6ehd13ev2e moved successfully.
C:\ProgramData\ux28k8k70xg6ehd13ev2e moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Christina\Desktop\cmd.bat deleted successfully.
C:\Users\Christina\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 43676140 bytes
->Temporary Internet Files folder emptied: 174271388 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 55653052 bytes
->Google Chrome cache emptied: 141418695 bytes
->Flash cache emptied: 35825 bytes
User: All Users
User: Christina
->Temp folder emptied: 16791829 bytes
->Temporary Internet Files folder emptied: 58476047 bytes
->Java cache emptied: 97084 bytes
->FireFox cache emptied: 285592525 bytes
->Google Chrome cache emptied: 321485052 bytes
->Flash cache emptied: 949 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 10815180 bytes
RecycleBin emptied: 650980 bytes
Total Files Cleaned = 1,058.00 mb
Error: Unable to interpret <[Reboot]CODE> in the current context!
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Folder C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internet\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
File C:\Users\Christina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini not found.
File C:\Users\Christina\AppData\Local\ux28k8k70xg6ehd13ev2e not found.
File C:\ProgramData\ux28k8k70xg6ehd13ev2e not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Christina\Desktop\cmd.bat deleted successfully.
C:\Users\Christina\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Christina
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 5561908 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3630 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 5.00 mb
Error: Unable to interpret <[Reboot]CODE> in the current context!
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Folder C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internet\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
File C:\Users\Christina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini not found.
File C:\Users\Christina\AppData\Local\ux28k8k70xg6ehd13ev2e not found.
File C:\ProgramData\ux28k8k70xg6ehd13ev2e not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Christina\Desktop\cmd.bat deleted successfully.
C:\Users\Christina\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Christina
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 5540231 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3630 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 5.00 mb
Error: Unable to interpret <[Reboot]CODE> in the current context!
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Folder C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internet\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
File C:\Users\Christina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini not found.
File C:\Users\Christina\AppData\Local\ux28k8k70xg6ehd13ev2e not found.
File C:\ProgramData\ux28k8k70xg6ehd13ev2e not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Christina\Desktop\cmd.bat deleted successfully.
C:\Users\Christina\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Christina
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 5540231 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 456 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3630 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 5.00 mb
Error: Unable to interpret <[Reboot]CODE> in the current context!
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Folder C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internet\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
File C:\Users\Christina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini not found.
File C:\Users\Christina\AppData\Local\ux28k8k70xg6ehd13ev2e not found.
File C:\ProgramData\ux28k8k70xg6ehd13ev2e not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Christina\Desktop\cmd.bat deleted successfully.
C:\Users\Christina\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Christina
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 5817324 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3630 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 6.00 mb
Error: Unable to interpret <[Reboot]CODE> in the current context!
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Folder C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internet\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
File C:\Users\Christina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini not found.
File C:\Users\Christina\AppData\Local\ux28k8k70xg6ehd13ev2e not found.
File C:\ProgramData\ux28k8k70xg6ehd13ev2e not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Christina\Desktop\cmd.bat deleted successfully.
C:\Users\Christina\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Christina
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 5540134 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3630 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 5.00 mb
Error: Unable to interpret <[Reboot]CODE> in the current context!
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Folder C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internet\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
File C:\Users\Christina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini not found.
File C:\Users\Christina\AppData\Local\ux28k8k70xg6ehd13ev2e not found.
File C:\ProgramData\ux28k8k70xg6ehd13ev2e not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Christina\Desktop\cmd.bat deleted successfully.
C:\Users\Christina\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Christina
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 5540134 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3630 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 5.00 mb
Error: Unable to interpret <[Reboot]CODE> in the current context!
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Folder C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internet\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
File C:\Users\Christina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini not found.
File C:\Users\Christina\AppData\Local\ux28k8k70xg6ehd13ev2e not found.
File C:\ProgramData\ux28k8k70xg6ehd13ev2e not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Christina\Desktop\cmd.bat deleted successfully.
C:\Users\Christina\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Christina
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 5540134 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3630 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 5.00 mb
Error: Unable to interpret <[Reboot]CODE> in the current context!
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E8FDD38-C333-4A38-8719-AAB8F0EB9979}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2ECE0016-D353-4C15-8B6D-45C2329BA74E}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBEB043B-0987-45CA-8610-4DA635C9E113}\ not found.
Folder C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internet\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee.com\ not found.
File C:\Users\Christina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini not found.
File C:\Users\Christina\AppData\Local\ux28k8k70xg6ehd13ev2e not found.
File C:\ProgramData\ux28k8k70xg6ehd13ev2e not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Christina\Desktop\cmd.bat deleted successfully.
C:\Users\Christina\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Christina
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 5540134 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3630 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 5.00 mb
Error: Unable to interpret <[Reboot]CODE> in the current context!
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}\ not found.
File C:\Program Files\WinZipBar\prxtbWinZ.dll not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} not found.
If this is as good as new scan log, pls let me know.
Chris
jeffce
Hi,
Great job getting that ran. Please run a new scan with OTL and post that to your next reply. 
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI