This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

searchqu and searchnu406 removal [Solved]

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft Windows 7 Starter Boot Device: \Device\HarddiskVolume1 Install Date: 17/01/2011 09:57:42 System Uptime: 23/04/2012 23:50:51 (2 hours ago) . Motherboard: SAMSUNG ELECTRONICS CO., LTD. | | N145P/N250P/N260P Processor: Intel® Atom™ CPU N450 @ 1.66GHz | CPU 1 | 983/mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 88 GiB total, 56.043 GiB free. D: is FIXED (NTFS) - 130 GiB total, 70.365 GiB free. . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: Photosmart C6100 series Device ID: ROOT\MULTIFUNCTION\0001 Manufacturer: HP Name: Photosmart C6100 series PNP Device ID: ROOT\MULTIFUNCTION\0001 Service: . Class GUID: Description: Photosmart C6100 series Device ID: ROOT\MULTIFUNCTION\0000 Manufacturer: Name: Photosmart C6100 series PNP Device ID: ROOT\MULTIFUNCTION\0000 Service: . ==== System Restore Points =================== . RP271: 12/04/2012 10:44:30 - Windows Update RP272: 16/04/2012 14:20:31 - Windows Backup RP273: 22/04/2012 11:52:55 - Tweaking.com - Windows Repair RP274: 22/04/2012 19:01:10 - Windows Backup RP275: 24/04/2012 00:48:11 - Installed Java™ 7 Update 3 . ==== Installed Programs ====================== . 32 Bit HP CIO Components Installer 3Connect Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader X (10.1.3) AIO_CDA_ProductContext AIO_CDA_Software AIO_Scan Amazon MP3 Downloader 1.0.9 Apple Application Support Apple Mobile Device Support Apple Software Update Atheros Client Installation Program BatteryLifeExtender Bonjour Broadcom 802.11 Network Adapter BufferChm C6100 c6100_Help Copy CyberLink YouCam D3DX10 Destinations DeviceDiscovery DocProc Easy Content Share Easy Display Manager Easy Network Manager Easy Resolution Manager Easy SpeedUp Manager EasyBatteryManager EasyFileShare ERUNT 1.1j ESET Online Scanner v3 ETDWare PS/2-X86 8.0.7.0_WHQL Fast Start Fax FileZilla Client 3.4.0 Google Chrome Google Earth Google Update Helper GPBaseService2 HP Customer Participation Program 13.0 HP Imaging Device Functions 13.0 HP Photosmart All-In-One Driver Software 13.0 Rel. A HP Photosmart Essential 3.5 HP Smart Web Printing 4.60 HP Solution Center 13.0 HP Update HPPhotoGadget HPPhotoSmartDiscLabelContent1 HPPhotosmartEssential HPProductAssistant HPSSupply Huawei modem iLivid Intel® Graphics Media Accelerator Driver IrfanView (remove only) iTunes Java Auto Updater Java™ 6 Update 29 Java™ 7 Update 3 Malwarebytes Anti-Malware version 1.61.0.1400 MarketResearch Marvell Miniport Driver McAfee Virtual Technician Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Office Basic Edition 2003 Microsoft Office File Validation Add-In Microsoft Office Outlook Connector Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 MobileMe Control Panel Movie Color Enhancer Mozilla Firefox 12.0 (x86 en-US) Mozilla Maintenance Service MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Network OCR Software by I.R.I.S. 13.0 OpenOffice.org 3.3 PLAY ONLINE QuickTime Realtek High Definition Audio Driver REALTEK PCIE Wireless LAN Software Samsung AnyWeb Print Samsung Recovery Solution 5 Samsung Support Center 1.0 Samsung Universal Print Driver Samsung Universal Scan Driver Samsung Update Plus SamsungMovie Scan Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Shop for HP Supplies Skype™ 4.2 SmartWebPrinting Software Informer 1.1 SolutionCenter SRS Premium Sound Control Panel Status TeamViewer 6 Toolbox TrayApp TuneUp Utilities 2011 TuneUp Utilities Language Pack (en-US) Tweaking.com - Windows Repair (All in One) UnloadSupport Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) User Guide Vit Registry Fix 9.5.4 (remove only) WebReg Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Mesh ActiveX Control for Remote Connections Windows Live Messenger Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live Sync Windows Live UX Platform Windows Live UX Platform Language Pack WinZip 16.0 WinZipBar Toolbar Yahoo! BrowserPlus 2.9.8 Yahoo! Messenger Yahoo! Software Update . ==== Event Viewer Messages From Past Week ======== . 23/04/2012 23:51:31, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom 23/04/2012 17:02:59, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 23/04/2012 16:04:51, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly. 22/04/2012 20:07:08, Error: Service Control Manager [7034] - The Adobe Acrobat Update Service service terminated unexpectedly. It has done this 1 time(s). 22/04/2012 16:35:15, Error: Service Control Manager [7022] - The Windows Update service hung on starting. 22/04/2012 16:32:44, Error: Service Control Manager [7022] - The McAfee Network Agent service hung on starting. 22/04/2012 16:31:07, Error: Service Control Manager [7022] - The McAfee VirusScan Announcer service hung on starting. 22/04/2012 12:18:56, Error: Service Control Manager [7022] - The McAfee McShield service hung on starting. 21/04/2012 17:32:37, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the defragsvc service. . ==== End Of File ===========================
Hi,

Do you have the DDS.txt log that was created as well? If so post that too please.
———-

Please do the following:

Hold down the Windows key and press R to open a run box
type the following text into the run box

appwiz.cpl

This will open your Programs And Features. A list of installed programs will populate

Remove the following programs if still there:

iLivid
Java™ 6 Update 29

———-
I believe it is this one . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 1:52:32.92 on 24/04/2012 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.3.0 Microsoft Windows 7 Starter 6.1.7601.1.1252.44.1033.18.1013.143 [GMT 1:00] . SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\windows\system32\wininit.exe C:\windows\system32\lsm.exe C:\windows\system32\svchost.exe -k DcomLaunch C:\windows\system32\svchost.exe -k RPCSS C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\windows\system32\svchost.exe -k netsvcs C:\windows\system32\svchost.exe -k LocalService C:\windows\system32\svchost.exe -k NetworkService C:\windows\system32\svchost.exe -k LocalServiceNoNetwork C:\windows\System32\spoolsv.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\windows\system32\svchost.exe -k hpdevmgmt C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\windows\System32\svchost.exe -k HPZ12 C:\windows\System32\svchost.exe -k HPZ12 C:\windows\system32\svchost.exe -k imgsvc C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe C:\windows\system32\SearchIndexer.exe C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\windows\system32\svchost.exe -k HPService C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\windows\system32\taskhost.exe C:\windows\System32\rundll32.exe C:\windows\system32\Dwm.exe C:\windows\Explorer.EXE C:\Program Files\TeamViewer\Version6\TeamViewer.exe C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\windows\system32\igfxsrvc.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\windows\system32\taskeng.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel.exe C:\windows\system32\taskeng.exe C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe C:\windows\system32\igfxext.exe C:\windows\system32\igfxsrvc.exe C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe C:\windows\system32\svchost.exe -k SDRSVC C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\windows\system32\SearchProtocolHost.exe C:\windows\system32\SearchFilterHost.exe C:\Users\Christina\Downloads\dds.scr C:\windows\system32\conhost.exe C:\windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = uInternet Settings,ProxyOverride = *.local BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: W2PBrowser Class: {aa609d72-8482-4076-8991-8cdae5b93bcb} - c:\program files\samsung anyweb print\W2PBrowser.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" StartupFolder: c:\users\christ~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: {328ECD19-C167-40eb-A0C7-16FE7634105E} - {94BB0C4C-B957-479A-85E4-42F53B89F681} - c:\program files\samsung anyweb print\W2PBrowser.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\christ~1\appdata\roaming\mozilla\firefox\profiles\l3h69xx6.default\ FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\program files\mcafee\supportability\mvt\NPMVTPlugin.dll FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll FF - plugin: c:\users\christina\appdata\local\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll . —- FIREFOX POLICIES —- FF - user.js: general.useragent.extra.brc - FF - user.js: yahoo.ytff.general.dontshowhpoffer - true FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . ============= SERVICES / DRIVERS =============== . R1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\drivers\SABI.sys [2010-9-1 10752] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928] R2 BecHelperService;BecHelperService;c:\program files\3 mobile broadband\3connect\BecHelperService.exe [2011-10-14 1740696] R2 TeamViewer6;TeamViewer 6;c:\program files\teamviewer\version6\TeamViewer_Service.exe [2011-8-30 2337144] R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2011\TuneUpUtilitiesService32.exe [2011-2-18 1517376] R2 UI Assistant Service;UI Assistant Service;c:\program files\play online\AssistantServices.exe [2011-1-26 252784] R3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\drivers\ETD.sys [2010-9-2 94208] R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [2011-10-14 73216] R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2011\TuneUpUtilitiesDriver32.sys [2010-11-29 10064] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2010-7-8 322336] S2 0311831335121373mcinstcleanup;McAfee Application Installer Cleanup (0311831335121373);c:\users\christ~1\appdata\local\temp\031183~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service –> c:\users\christ~1\appdata\local\temp\031183~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-7-29 136176] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [2011-10-14 102784] S3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\drivers\ew_usbenumfilter.sys [2011-10-14 11136] S3 ewusbmbb;HUAWEI USB-WWAN miniport;c:\windows\system32\drivers\ewusbwwan.sys [2011-10-14 353280] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-7-29 136176] S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2011-1-26 9216] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-4-23 129976] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776] S3 Samsung UPD Service;Samsung UPD Service;c:\windows\system32\SUPDSvc.exe [2011-1-17 131888] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-25 52224] . =============== Created Last 30 ================ . 2012-04-24 00:40:50 ——– d—–w- c:\users\christ~1\appdata\local\{AB19881D-AE5D-4E25-8C08-1A14E631CAC0} 2012-04-24 00:40:25 ——– d—–w- c:\users\christ~1\appdata\local\{9AF1068E-65E6-455D-A5F9-732EEB637530} 2012-04-24 00:07:23 ——– d—–w- c:\users\christ~1\appdata\local\{84804CA1-E889-462B-805E-326AA920561D} 2012-04-24 00:07:00 ——– d—–w- c:\users\christ~1\appdata\local\{F08A658D-F235-49DC-AA6C-94F348BAB383} 2012-04-23 23:49:32 637848 —-a-w- c:\windows\system32\npdeployJava1.dll 2012-04-23 22:55:02 ——– d—–w- c:\users\christ~1\appdata\local\{CB4FE251-26EE-4EE9-8FC5-AD14900F962C} 2012-04-23 22:54:43 ——– d—–w- c:\users\christ~1\appdata\local\{99FA0E2B-F868-498E-9B5B-042774EE8013} 2012-04-23 20:19:30 ——– d—–w- c:\users\christ~1\appdata\local\{C52E985A-405B-4AC2-AAE3-FF8304F2DE3F} 2012-04-23 20:19:15 ——– d—–w- c:\users\christ~1\appdata\local\{68375F71-2413-428B-9BD5-DAA65E06FF1D} 2012-04-23 20:15:02 ——– d—–w- c:\program files\Mozilla Maintenance Service 2012-04-23 20:14:59 43960 —-a-w- c:\program files\mozilla firefox\mozglue.dll 2012-04-23 20:14:59 157352 —-a-w- c:\program files\mozilla firefox\maintenanceservice_installer.exe 2012-04-23 20:14:59 129976 —-a-w- c:\program files\mozilla firefox\maintenanceservice.exe 2012-04-23 20:14:58 588728 —-a-w- c:\program files\mozilla firefox\gkmedias.dll 2012-04-23 16:14:11 ——– d—–w- c:\users\christ~1\appdata\local\{E5FC0E25-F14E-48FC-A003-874F022E1698} 2012-04-23 16:13:42 ——– d—–w- c:\users\christ~1\appdata\local\{486161F1-98FF-43C4-A668-6EE23466B845} 2012-04-23 16:09:10 ——– d-sh–w- C:\$RECYCLE.BIN 2012-04-23 16:09:03 ——– d—–w- c:\users\christ~1\appdata\local\temp 2012-04-23 15:05:48 ——– d—–w- c:\users\christ~1\appdata\local\{0C258FC4-16B9-415A-BB57-31CD0F30F657} 2012-04-23 15:05:34 ——– d—–w- c:\users\christ~1\appdata\local\{320BC3A4-397E-4005-8381-3B8ADD6543C8} 2012-04-23 12:11:15 ——– d—–w- c:\users\christ~1\appdata\local\{2F869C4D-524F-4759-A2A1-531068A179B6} 2012-04-23 12:06:16 98816 —-a-w- c:\windows\sed.exe 2012-04-23 12:06:16 518144 —-a-w- c:\windows\SWREG.exe 2012-04-23 12:06:16 256000 —-a-w- c:\windows\PEV.exe 2012-04-23 12:06:16 208896 —-a-w- c:\windows\MBR.exe 2012-04-23 11:58:05 ——– d—–w- c:\users\christ~1\appdata\local\{39E49110-86E0-421C-869A-40D48463DF44} 2012-04-23 11:57:47 ——– d—–w- c:\users\christ~1\appdata\local\{A6EA1502-635B-4A0B-AC0B-12CBB6E13A13} 2012-04-22 19:12:44 ——– d—–w- c:\users\christ~1\appdata\local\{9163A833-59B4-43CB-9F12-9C4AED32AA82} 2012-04-22 19:12:33 ——– d—–w- c:\users\christ~1\appdata\local\{0B100FCF-19D4-4871-B7AF-EF172CA7F52D} 2012-04-22 15:28:18 ——– d—–w- c:\users\christ~1\appdata\local\{0B739743-C1F4-4FF4-BB0F-B213725C5B9F} 2012-04-22 15:28:04 ——– d—–w- c:\users\christ~1\appdata\local\{54820ACA-EF1C-4BB0-A299-0C925519D435} 2012-04-22 11:13:19 ——– d—–w- c:\users\christ~1\appdata\local\{DF13114C-5A3B-4441-A027-39C57758E653} 2012-04-22 11:12:51 ——– d—–w- c:\users\christ~1\appdata\local\{B98FBA63-DE18-49EF-9DA7-9BAB94561AAF} 2012-04-22 10:54:22 ——– d—–w- C:\Reg_Backup 2012-04-22 10:50:42 ——– d—–w- C:\Tweaking.com_Windows_Repair_Logs 2012-04-22 10:50:02 ——– d—–w- c:\program files\Tweaking.com 2012-04-22 09:58:17 ——– d—–w- c:\users\christ~1\appdata\local\{7DCBE4D7-9A7A-4217-87C2-06C9FEF79DEF} 2012-04-21 23:01:09 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-04-21 23:01:08 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-04-21 22:32:44 ——– d—–w- c:\program files\common files\Mcafee 2012-04-21 22:32:42 ——– d—–w- c:\program files\McAfee.com 2012-04-21 22:23:34 ——– d—–w- c:\users\christ~1\appdata\local\{333DF259-F04E-40A8-9ABB-9644FA6AEC50} 2012-04-21 22:23:18 ——– d—–w- c:\users\christ~1\appdata\local\{1B898735-5C13-4BDD-986A-69C48B5913E1} 2012-04-21 21:28:19 ——– d—–w- c:\users\christ~1\appdata\local\{6892558C-DC81-470A-85BE-2CCB18F6848A} 2012-04-21 21:27:56 ——– d—–w- c:\users\christ~1\appdata\local\{43456941-9D2C-4930-9C5D-C7EF74544F22} 2012-04-21 21:24:26 ——– d—–w- c:\users\christ~1\appdata\local\{6C7EEEC2-46C5-4033-93E8-5E78917F7BA1} 2012-04-21 21:24:13 ——– d—–w- c:\users\christ~1\appdata\local\{6DA76A72-FE63-4581-B6FA-128F659A8FF7} 2012-04-21 20:10:21 ——– d—–w- c:\users\christ~1\appdata\local\{18AECC58-EBBE-4908-A03B-353385D96D8C} 2012-04-21 20:09:56 ——– d—–w- c:\users\christ~1\appdata\local\{2A7B61D3-90AC-44AE-AFA2-87A5B611FB36} 2012-04-21 19:20:25 ——– d—–w- c:\users\christ~1\appdata\local\{BED26244-67A8-4E24-8B7A-694F692FE217} 2012-04-21 19:20:13 ——– d—–w- c:\users\christ~1\appdata\local\{7EF4FEFF-4195-4B90-B704-A4E234D13572} 2012-04-21 18:22:00 ——– d—–w- c:\users\christ~1\appdata\local\{8EBDDF4A-4447-4615-AA92-F4500A80104B} 2012-04-21 18:21:32 ——– d—–w- c:\users\christ~1\appdata\local\{BC3F252D-6AF7-48DA-931B-684B6A8003E1} 2012-04-21 18:06:54 ——– d—–w- c:\users\christ~1\appdata\local\{902EF019-219E-469A-AAAC-BEBF7FD6EAC0} 2012-04-21 18:06:32 ——– d—–w- c:\users\christ~1\appdata\local\{F4EAC8DD-3E7B-4214-93BB-A27CA4188D24} 2012-04-21 09:22:27 ——– d—–w- c:\users\christ~1\appdata\local\{975ADCD7-0732-4DA9-809A-6EE3F83DCF0D} 2012-04-21 09:21:50 ——– d—–w- c:\users\christ~1\appdata\local\{82B05528-BF3B-452E-9D0C-7D6D64575259} 2012-04-20 09:28:10 ——– d—–w- c:\users\christ~1\appdata\local\{B4DFE1EE-8C93-417E-830A-A2688023CD71} 2012-04-20 09:27:23 ——– d—–w- c:\users\christ~1\appdata\local\{0EC2CC3D-7F16-4E0F-90CB-47C1CD875FD1} 2012-04-19 21:34:00 ——– d—–w- c:\users\christ~1\appdata\local\{E507A3E1-A6ED-44D0-9596-51938B34B725} 2012-04-19 21:33:34 ——– d—–w- c:\users\christ~1\appdata\local\{36B4D4B9-2C41-4FAB-8A6C-C30BCDB366BC} 2012-04-19 14:37:42 ——– d—–w- c:\users\christ~1\appdata\local\{AB98BAE1-A861-4533-84D5-42955D09F691} 2012-04-19 14:37:26 ——– d—–w- c:\users\christ~1\appdata\local\{EE31A02C-91BB-4D10-953D-B9DAD1829B49} 2012-04-18 21:39:05 ——– d—–w- c:\users\christ~1\appdata\local\{63CBD3F4-81C8-457C-A409-4BF9820AEBA0} 2012-04-18 21:38:21 ——– d—–w- c:\users\christ~1\appdata\local\{07D573A2-C17C-4A2E-A407-2FBBE7275332} 2012-04-18 19:37:36 ——– d—–w- c:\users\christ~1\appdata\local\{F1F2B18B-8211-472B-B281-206711E4F087} 2012-04-18 19:37:20 ——– d—–w- c:\users\christ~1\appdata\local\{A6F03645-0AF1-453A-B1DE-F19DF91B51BF} 2012-04-18 12:35:39 ——– d—–w- c:\users\christ~1\appdata\local\{C385A2F8-6574-415B-8687-4A5447CAF2F4} 2012-04-18 12:35:07 ——– d—–w- c:\users\christ~1\appdata\local\{6E81434B-B1DF-4C8E-ABE9-39DC724B7289} 2012-04-18 07:34:23 ——– d—–w- c:\users\christ~1\appdata\local\{2F0B1D53-0213-4C14-A34A-CDC89784EC01} 2012-04-18 07:34:09 ——– d—–w- c:\users\christ~1\appdata\local\{8B722896-69DA-454C-A0F9-8B6BD59DE768} 2012-04-17 20:23:21 ——– d—–w- c:\program files\ESET 2012-04-17 18:57:35 ——– d—–w- c:\users\christ~1\appdata\local\{B8212108-20A6-45AA-97AE-3CCB797CC5D1} 2012-04-17 18:57:09 ——– d—–w- c:\users\christ~1\appdata\local\{661A33A4-0C5E-44A4-AEDB-4ECBC3C62EB9} 2012-04-17 18:28:37 ——– d—–w- c:\users\christ~1\appdata\roaming\Malwarebytes 2012-04-17 18:28:02 ——– d—–w- c:\progra~2\Malwarebytes 2012-04-17 18:04:58 ——– d—–w- c:\users\christ~1\appdata\local\{E5C485DF-08A9-4FE8-A53D-0BDC91F116B3} 2012-04-17 18:04:33 ——– d—–w- c:\users\christ~1\appdata\local\{3A278787-D700-401C-9966-9D34692F875A} 2012-04-17 18:00:47 ——– d—–w- C:\found.000 2012-04-17 11:19:42 ——– d—–w- c:\users\christ~1\appdata\local\{F35E964A-6FCD-4353-97ED-CA912EB1EB65} 2012-04-17 11:19:16 ——– d—–w- c:\users\christ~1\appdata\local\{35592A29-3846-48BF-AF27-211B2EAB1B42} 2012-04-17 10:30:44 ——– d—–w- C:\_OTL 2012-04-17 10:01:51 ——– d—–w- c:\users\christ~1\appdata\local\{B32618D4-D46F-437C-B795-815FDE4A6B35} 2012-04-17 10:01:29 ——– d—–w- c:\users\christ~1\appdata\local\{50120FB6-C762-462B-A028-D6399FF4C31A} 2012-04-16 18:53:19 ——– d—–w- c:\users\christ~1\appdata\local\{353ABB58-7BD4-4459-A2EB-C412D6EC8E18} 2012-04-16 18:52:48 ——– d—–w- c:\users\christ~1\appdata\local\{44ACE206-2C0F-4A88-9186-E39AADDA6FE7} 2012-04-14 19:59:07 ——– d—–w- c:\users\christ~1\appdata\local\{5347E02E-61C4-4A34-82A7-545D2641B3F3} 2012-04-14 19:58:39 ——– d—–w- c:\users\christ~1\appdata\local\{022A2F2D-9B12-4D06-B669-A9642629A139} 2012-04-14 10:21:42 ——– d—–w- c:\users\christ~1\appdata\local\{56C1D28E-2276-4DB1-9239-EA48F9749018} 2012-04-14 10:20:55 ——– d—–w- c:\users\christ~1\appdata\local\{302F11B4-7742-4911-AAB8-C4243746E438} 2012-04-12 12:10:10 ——– d—–w- c:\users\christ~1\appdata\local\{DEB12ACD-A165-40D6-B120-B90FF89CF18F} 2012-04-12 12:09:53 ——– d—–w- c:\users\christ~1\appdata\local\{8BEAEFC4-BC24-4E9C-A4BA-925BFC01E83B} 2012-04-12 09:42:36 ——– d—–w- c:\users\christ~1\appdata\local\{4E38B6BD-FC8A-41F2-92B3-321A33528DBC} 2012-04-12 09:42:18 ——– d—–w- c:\users\christ~1\appdata\local\{ADDEEC85-BDAB-4677-ADAC-96F49FBBEC9A} 2012-04-12 00:48:26 19824 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-04-12 00:48:25 5120 —-a-w- c:\windows\system32\wmi.dll 2012-04-12 00:48:25 172544 —-a-w- c:\windows\system32\wintrust.dll 2012-04-12 00:48:25 159232 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-12 00:26:11 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-12 00:26:07 3913072 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-04-12 00:13:14 ——– d—–w- c:\users\christ~1\appdata\local\{53F44410-0F49-4159-A9F7-59CC9BFFC840} 2012-04-12 00:00:33 ——– d—–w- c:\users\christ~1\appdata\local\{366BC4BB-E3D2-4779-8C3E-EF1ED4E083D1} 2012-04-11 23:59:22 ——– d—–w- c:\users\christ~1\appdata\local\{129F8187-BA00-4F56-9B40-E66F1178AA51} 2012-04-11 22:15:03 ——– d—–w- c:\users\christ~1\appdata\local\{CB62930E-E8B8-4025-A65D-E322529139F8} 2012-04-11 17:32:29 ——– d—–w- c:\progra~2\AVG Secure Search 2012-04-11 17:32:15 ——– d—–w- c:\program files\common files\AVG Secure Search 2012-04-11 17:32:07 ——– d—–w- c:\program files\AVG Secure Search 2012-04-11 17:26:16 ——– d—–w- C:\$AVG 2012-04-11 15:45:09 ——– d—–w- c:\program files\common files\SpeedyPC Software 2012-04-11 15:45:07 ——– d—–w- c:\program files\SpeedyPC Software 2012-04-10 20:42:54 ——– d—–w- c:\users\christ~1\appdata\local\{866CAD26-2E62-4941-BDEC-0923B602D05F} 2012-04-09 01:12:51 ——– d—–w- c:\users\christ~1\appdata\roaming\SpeedyPC Software 2012-04-09 01:12:02 ——– d—–w- c:\progra~2\SpeedyPC Software 2012-04-08 22:19:57 ——– d—–w- c:\users\christ~1\appdata\local\{76C924EA-6DD3-4D30-8A0B-48AE4858BCD8} 2012-04-04 05:53:56 182160 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll 2012-04-04 05:53:56 182160 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll 2012-04-03 20:36:56 ——– d—–w- c:\users\christ~1\appdata\local\WinZip 2012-04-03 19:12:03 ——– d—–w- c:\users\christ~1\appdata\local\{33EE76A0-7DA3-43AD-AA28-3D14011E35FA} 2012-04-03 19:11:27 ——– d—–w- c:\users\christ~1\appdata\local\{4F619680-21D9-4743-AA23-61D6AD6AFDFD} 2012-04-03 18:37:50 ——– d—–w- c:\users\christ~1\appdata\local\{6134C62C-6DBF-4C38-B968-D8951F6892BF} 2012-04-03 18:20:22 ——– d—–w- c:\users\christ~1\appdata\local\{BC049C4B-D462-49AA-8DBC-5E59C2640EAD} 2012-04-03 18:19:15 ——– d—–w- c:\users\christ~1\appdata\local\{78D44058-B568-47E9-A492-E82E66134CEA} 2012-03-29 19:41:09 ——– d—–w- c:\users\christ~1\appdata\local\{92341BC9-2B8A-4130-AF99-C38DF4ACE36A} 2012-03-29 18:37:48 ——– d—–w- c:\users\christ~1\appdata\local\{75351EA8-4AD7-4C50-89C7-E4901675B152} 2012-03-26 22:53:31 ——– d—–w- c:\users\christ~1\appdata\local\{54C4A35C-A82D-4C15-A4B6-0476397D1B3C} 2012-03-26 22:53:04 ——– d—–w- c:\users\christ~1\appdata\local\{47D1C48E-CA92-4A51-A53B-A29A2D6F0B0B} 2012-03-26 10:52:08 ——– d—–w- c:\users\christ~1\appdata\local\{5A15AD8D-6405-440F-801B-97CD9EC05AA2} 2012-03-26 10:51:43 ——– d—–w- c:\users\christ~1\appdata\local\{924EF17F-2F86-4D2B-BABC-EA55463BA947} . ==================== Find3M ==================== . 2012-04-23 23:49:04 567696 —-a-w- c:\windows\system32\deployJava1.dll 2012-03-02 11:37:03 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-28 01:18:55 1799168 —-a-w- c:\windows\system32\jscript9.dll 2012-02-28 01:11:21 1427456 —-a-w- c:\windows\system32\inetcpl.cpl 2012-02-28 01:11:07 1127424 —-a-w- c:\windows\system32\wininet.dll 2012-02-28 01:03:16 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-02-17 05:34:22 826880 —-a-w- c:\windows\system32\rdpcore.dll 2012-02-10 05:38:43 1077248 —-a-w- c:\windows\system32\DWrite.dll 2012-02-03 03:54:27 2343424 —-a-w- c:\windows\system32\win32k.sys 2012-01-25 05:32:35 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-01-25 05:32:34 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-01-25 05:27:51 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe . ============= FINISH: 1:53:52.59 ===============
Yep that was the one. :)

Be sure to turn your antivirus back on because it is just not showing in the log but otherwise it looks good.

If you were wanting two alternatives to McAfee you could choose either of the two below but be sure to choose just one…
Microsoft Security Essentials
Avast
———-

Providing there are no more malware related problems…

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :D SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :D

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
———-

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following text into the Run box as shown and click OK.
Combofix /Uninstall
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]
———-

Clean up with OTL:
  • Right-click and Run as Administrator OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
———-

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted using right-click > delete so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Enable Protected Mode in Internet Explorer. This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps:
  • Open Internet Explorer
  • Click on Tools > Internet Options
  • Press Security tab
  • Select Internet zone then place check next to Enable Protected Mode if not already done
  • Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
  • Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.
3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here. **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

6. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

7. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Hi Jeff After your last response I proceeded to restore my McAfee. In the course of the re-installation I was prompted to uninstall Malwarebytes due to incompatibility but I opted to keep it and to see what happens. Installation went ok but later on McA's icons faded away and it transpired that installation was ineffective. So I uninstalled it and tried to reinstall ab 20 times. I was forced to contact their tech supp. It must be somewhere in India because all my helpers have invariably Indian names. After taking control of my screen they messed up my registry: deleted temp files, interfered with my administrator's settings and many more which I am not even able to evaluate. For the reasons above I am asking you to indicate whether I should go on with your instructions or to do a scan showing the present state before carrying out your final instructions. Also, please tell me how to enter with my other laptop. Chris
Jeff I know it is a small matter to ask you about but dealing with this by myself means enormous loss of time.: I want to remove ask toolbar from my search engines and it is so-far difficult for me. I deleted it form my programmes but it still rules Firefox. I hate it because it provides no helpful information but directs to multiple tabs with the same guestion: " idem per idem". Is there any way I could restore to my normal homepage (Google) and links to sites ebay, amazon etc from my hotmail page, windows live, firefox and explorer.? ERUNT appears upon opening, can it be stopped appearing? Cheers Chris
Hi,

I was forced to contact their tech supp. It must be somewhere in India because all my helpers have invariably Indian names.
After taking control of my screen they messed up my registry: deleted temp files, interfered with my administrator's settings and many more which I am not even able to evaluate.
For the reasons above I am asking you to indicate whether I should go on with your instructions or to do a scan showing the present state before carrying out your final instructions.

Ok…since they took control of your system remotely it is hard to tell what it is that they did without getting new scans. They could have changed any number of things that we had already fixed and this includes putting the Ask Toolbar on your system again. This is the reason I recommend either Microsoft Security Essentials or Avast for an antivirus program. They are compatible with virtually everything. Anyway…run a new scan with OTL and I can see what they have done and hopefully put things back together.

As for ERUNT…keep the program but we will remove it from startup. Just remember to run it about once a week manually to back up your registry. :) Please do the following…

Go to Start >> in Start Search type Run >> when it populates above select Run. In the Run text bar type msconfig >> press OK >> select Startup tab >> remove checkmark from any ERUNT entries >> select Apply >> Ok >> reboot your system. :)
OTL logfile created on: 4/24/2012 7:42:09 PM - Run 7
OTL by OldTimer - Version 3.2.40.0 Folder = C:\Users\Christina\Downloads
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1013.30 Mb Total Physical Memory | 312.57 Mb Available Physical Memory | 30.85% Memory free
1.99 Gb Paging File | 1.24 Gb Available in Paging File | 62.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 88.00 Gb Total Space | 59.92 Gb Free Space | 68.10% Space Free | Partition Type: NTFS
Drive D: | 130.35 Gb Total Space | 70.37 Gb Free Space | 53.98% Space Free | Partition Type: NTFS

Computer Name: CHRISSAMSUNG | User Name: Christina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Christina\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe (SAMSUNG Electronics)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files\Online Armor\OAReg.exe (Emsi Software GmbH)
PRC - C:\Program Files\Online Armor\oacat.exe (Emsi Software GmbH)
PRC - C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe (SRS Labs, Inc.)
PRC - C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe (Samsung Electronics)
PRC - C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (SEC)
PRC - C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\PLAY ONLINE\AssistantServices.exe ()
PRC - C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\Samsung\Movie Color Enhancer\WinCRT.dll ()
MOD - C:\Program Files\Samsung\Samsung Recovery Solution 5\Resdll.dll ()
MOD - C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll ()


========== Win32 Services (SafeList) ==========

SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe File not found
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TeamViewer6) – C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (SvcOnlineArmor) – C:\Program Files\Online Armor\oasrv.exe (Emsi Software GmbH)
SRV - (OAcat) – C:\Program Files\Online Armor\oacat.exe (Emsi Software GmbH)
SRV - (BecHelperService) – C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (Samsung UPD Service) – C:\Windows\System32\SUPDSvc.exe (Samsung Electronics CO., LTD.)
SRV - (UI Assistant Service) – C:\Program Files\PLAY ONLINE\AssistantServices.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (catchme) – C:\Users\CHRIST~1\AppData\Local\Temp\catchme.sys File not found
DRV - (oahlpXX) – C:\Windows\System32\drivers\oahlp32.sys ()
DRV - (OADevice) – C:\Windows\System32\drivers\OADriver.sys ()
DRV - (OAmon) – C:\Windows\System32\drivers\OAmon.sys (Emsisoft)
DRV - (mdvrmng) – C:\Windows\System32\drivers\mdvrmng.sys ()
DRV - (ewusbmbb) – C:\Windows\System32\drivers\ewusbwwan.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_hwusbdev) – C:\Windows\System32\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (huawei_enumerator) – C:\Windows\System32\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_usbenumfilter) – C:\Windows\System32\drivers\ew_usbenumfilter.sys (Huawei Technologies Co., Ltd.)
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (rtport) – C:\Windows\System32\drivers\rtport.sys (Windows ® 2003 DDK 3790 provider)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 65 4E 19 3B 02 22 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll File not found
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Christina\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/11 23:37:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/04/23 21:15:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/24 00:49:32 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/11 23:37:25 | 000,000,000 | —D | M]

[2011/10/04 01:13:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Christina\AppData\Roaming\Mozilla\Extensions
[2012/04/23 21:15:10 | 000,000,000 | —D | M] (No name found) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions
[2012/04/11 23:40:38 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/04/11 23:40:37 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]
[2012/04/23 21:15:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/04/23 21:15:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\distribution\extensions
[2012/04/18 04:07:26 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/04/11 18:32:03 | 000,003,747 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/04/18 04:06:17 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/18 04:06:17 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://search.avg.com/?d=4e4480f1&v;=7….q={searchTerms}
CHR - default_search_provider: suggest_url = http://suggestqueries.google.com/complete/…q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Christina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Users\Christina\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: SiteAdvisor = C:\Users\Christina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\

O1 HOSTS File: ([2012/04/23 17:02:51 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (W2PBrowser Class) - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Online Armor\oaui.exe (Emsi Software GmbH)
O4 - Startup: C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.3.0)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CA189E4A-4A04-4742-880D-62407F0217CC}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D82A697F-63A7-4A2B-9CD7-D1CBBF0B567D}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-mfe-ipt - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsi Software GmbH)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/04/24 19:35:38 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{AC5DCCF2-6D30-46B1-A8F8-4A40E666D9FD}
[2012/04/24 19:35:26 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5BBF0D47-40EF-44CF-9A91-8A409E9F4098}
[2012/04/24 11:47:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{AEE52324-1E24-4D1E-9D60-E65CA43007BC}
[2012/04/24 11:47:04 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{39ED5D2F-D1FE-4688-8E91-FB477351C801}
[2012/04/24 10:34:21 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F7EF0085-D988-4BB0-9B6A-E65877A5FF3F}
[2012/04/24 10:34:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{D6945D0A-CEAE-475F-9232-D4A246E9D64B}
[2012/04/24 03:10:55 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{62B7DC70-8BD7-43E8-8F54-4E3AC10E7FD5}
[2012/04/24 03:10:38 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{69F4A9D3-FB95-479E-BF28-8F127E71C17E}
[2012/04/24 03:05:36 | 000,000,000 | R-SD | C] – C:\Users\Christina\Documents\McAfee Vaults
[2012/04/24 02:49:08 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{11AE4FA2-5961-4B6A-861B-FC9428679320}
[2012/04/24 02:48:47 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{05837DFF-C69D-40CF-8EB8-B80C8FD8227F}
[2012/04/24 02:19:55 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\OnlineArmor
[2012/04/24 02:19:55 | 000,000,000 | —D | C] – C:\ProgramData\OnlineArmor
[2012/04/24 02:17:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Armor
[2012/04/24 02:17:01 | 000,025,192 | —- | C] (Emsisoft) – C:\windows\System32\drivers\OAmon.sys
[2012/04/24 02:16:50 | 000,000,000 | —D | C] – C:\Program Files\Online Armor
[2012/04/24 02:07:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{67B86495-09C0-4D56-9122-D346217C6D15}
[2012/04/24 02:07:25 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2B1C6F43-6C1B-4BB1-9648-75CCC520B237}
[2012/04/24 01:56:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{817A36E0-5C87-4390-8BFC-A195B140E7E5}
[2012/04/24 01:56:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{7B0867E3-271F-491A-8EE3-6C703F84591C}
[2012/04/24 01:40:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{AB19881D-AE5D-4E25-8C08-1A14E631CAC0}
[2012/04/24 01:40:25 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{9AF1068E-65E6-455D-A5F9-732EEB637530}
[2012/04/24 01:07:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{84804CA1-E889-462B-805E-326AA920561D}
[2012/04/24 01:07:00 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F08A658D-F235-49DC-AA6C-94F348BAB383}
[2012/04/24 00:50:05 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/04/24 00:49:32 | 000,637,848 | —- | C] (Oracle Corporation) – C:\windows\System32\npdeployJava1.dll
[2012/04/24 00:49:32 | 000,224,136 | —- | C] (Oracle Corporation) – C:\windows\System32\javaws.exe
[2012/04/24 00:49:32 | 000,173,960 | —- | C] (Oracle Corporation) – C:\windows\System32\javaw.exe
[2012/04/24 00:49:32 | 000,173,960 | —- | C] (Oracle Corporation) – C:\windows\System32\java.exe
[2012/04/23 23:55:02 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{CB4FE251-26EE-4EE9-8FC5-AD14900F962C}
[2012/04/23 23:54:43 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{99FA0E2B-F868-498E-9B5B-042774EE8013}
[2012/04/23 21:19:30 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{C52E985A-405B-4AC2-AAE3-FF8304F2DE3F}
[2012/04/23 21:19:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{68375F71-2413-428B-9BD5-DAA65E06FF1D}
[2012/04/23 21:15:02 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/04/23 21:15:02 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2012/04/23 17:14:11 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{E5FC0E25-F14E-48FC-A003-874F022E1698}
[2012/04/23 17:13:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{486161F1-98FF-43C4-A668-6EE23466B845}
[2012/04/23 17:09:10 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/04/23 17:09:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\temp
[2012/04/23 16:05:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0C258FC4-16B9-415A-BB57-31CD0F30F657}
[2012/04/23 16:05:34 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{320BC3A4-397E-4005-8381-3B8ADD6543C8}
[2012/04/23 13:11:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2F869C4D-524F-4759-A2A1-531068A179B6}
[2012/04/23 12:58:05 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{39E49110-86E0-421C-869A-40D48463DF44}
[2012/04/23 12:57:47 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{A6EA1502-635B-4A0B-AC0B-12CBB6E13A13}
[2012/04/22 20:12:44 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{9163A833-59B4-43CB-9F12-9C4AED32AA82}
[2012/04/22 20:12:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0B100FCF-19D4-4871-B7AF-EF172CA7F52D}
[2012/04/22 16:28:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0B739743-C1F4-4FF4-BB0F-B213725C5B9F}
[2012/04/22 16:28:04 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{54820ACA-EF1C-4BB0-A299-0C925519D435}
[2012/04/22 12:13:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{DF13114C-5A3B-4441-A027-39C57758E653}
[2012/04/22 12:12:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B98FBA63-DE18-49EF-9DA7-9BAB94561AAF}
[2012/04/22 11:54:22 | 000,000,000 | —D | C] – C:\Reg_Backup
[2012/04/22 11:54:18 | 000,181,064 | —- | C] (Sysinternals) – C:\windows\PSEXESVC.EXE
[2012/04/22 11:50:42 | 000,000,000 | —D | C] – C:\Tweaking.com_Windows_Repair_Logs
[2012/04/22 11:50:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
[2012/04/22 11:50:02 | 000,000,000 | —D | C] – C:\Program Files\Tweaking.com
[2012/04/22 10:58:17 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{7DCBE4D7-9A7A-4217-87C2-06C9FEF79DEF}
[2012/04/22 00:32:11 | 000,000,000 | —D | C] – C:\Users\Christina\Desktop\Play
[2012/04/21 23:32:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2012/04/21 23:23:34 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{333DF259-F04E-40A8-9ABB-9644FA6AEC50}
[2012/04/21 23:23:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{1B898735-5C13-4BDD-986A-69C48B5913E1}
[2012/04/21 22:57:07 | 000,000,000 | —D | C] – C:\Users\Christina\Desktop\lucid
[2012/04/21 22:28:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6892558C-DC81-470A-85BE-2CCB18F6848A}
[2012/04/21 22:27:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{43456941-9D2C-4930-9C5D-C7EF74544F22}
[2012/04/21 22:24:26 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6C7EEEC2-46C5-4033-93E8-5E78917F7BA1}
[2012/04/21 22:24:13 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6DA76A72-FE63-4581-B6FA-128F659A8FF7}
[2012/04/21 21:10:21 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{18AECC58-EBBE-4908-A03B-353385D96D8C}
[2012/04/21 21:09:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2A7B61D3-90AC-44AE-AFA2-87A5B611FB36}
[2012/04/21 20:20:25 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BED26244-67A8-4E24-8B7A-694F692FE217}
[2012/04/21 20:20:13 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{7EF4FEFF-4195-4B90-B704-A4E234D13572}
[2012/04/21 19:22:00 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8EBDDF4A-4447-4615-AA92-F4500A80104B}
[2012/04/21 19:21:32 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BC3F252D-6AF7-48DA-931B-684B6A8003E1}
[2012/04/21 19:06:54 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{902EF019-219E-469A-AAAC-BEBF7FD6EAC0}
[2012/04/21 19:06:32 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F4EAC8DD-3E7B-4214-93BB-A27CA4188D24}
[2012/04/21 10:22:27 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{975ADCD7-0732-4DA9-809A-6EE3F83DCF0D}
[2012/04/21 10:21:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{82B05528-BF3B-452E-9D0C-7D6D64575259}
[2012/04/20 10:28:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B4DFE1EE-8C93-417E-830A-A2688023CD71}
[2012/04/20 10:27:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0EC2CC3D-7F16-4E0F-90CB-47C1CD875FD1}
[2012/04/19 22:34:00 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{E507A3E1-A6ED-44D0-9596-51938B34B725}
[2012/04/19 22:33:34 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{36B4D4B9-2C41-4FAB-8A6C-C30BCDB366BC}
[2012/04/19 15:37:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{AB98BAE1-A861-4533-84D5-42955D09F691}
[2012/04/19 15:37:26 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{EE31A02C-91BB-4D10-953D-B9DAD1829B49}
[2012/04/18 22:39:05 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{63CBD3F4-81C8-457C-A409-4BF9820AEBA0}
[2012/04/18 22:38:21 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{07D573A2-C17C-4A2E-A407-2FBBE7275332}
[2012/04/18 20:37:36 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F1F2B18B-8211-472B-B281-206711E4F087}
[2012/04/18 20:37:20 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{A6F03645-0AF1-453A-B1DE-F19DF91B51BF}
[2012/04/18 13:35:39 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{C385A2F8-6574-415B-8687-4A5447CAF2F4}
[2012/04/18 13:35:07 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6E81434B-B1DF-4C8E-ABE9-39DC724B7289}
[2012/04/18 08:34:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2F0B1D53-0213-4C14-A34A-CDC89784EC01}
[2012/04/18 08:34:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8B722896-69DA-454C-A0F9-8B6BD59DE768}
[2012/04/17 21:23:21 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/04/17 19:57:35 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B8212108-20A6-45AA-97AE-3CCB797CC5D1}
[2012/04/17 19:57:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{661A33A4-0C5E-44A4-AEDB-4ECBC3C62EB9}
[2012/04/17 19:28:37 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\Malwarebytes
[2012/04/17 19:28:02 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/04/17 19:04:58 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{E5C485DF-08A9-4FE8-A53D-0BDC91F116B3}
[2012/04/17 19:04:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{3A278787-D700-401C-9966-9D34692F875A}
[2012/04/17 19:00:47 | 000,000,000 | —D | C] – C:\found.000
[2012/04/17 12:19:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F35E964A-6FCD-4353-97ED-CA912EB1EB65}
[2012/04/17 12:19:16 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{35592A29-3846-48BF-AF27-211B2EAB1B42}
[2012/04/17 11:30:44 | 000,000,000 | —D | C] – C:\_OTL
[2012/04/17 11:01:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B32618D4-D46F-437C-B795-815FDE4A6B35}
[2012/04/17 11:01:29 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{50120FB6-C762-462B-A028-D6399FF4C31A}
[2012/04/17 00:48:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/04/17 00:48:08 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012/04/16 23:32:49 | 000,000,000 | —D | C] – C:\Users\Christina\Desktop\whatthetech navigation
[2012/04/16 19:53:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{353ABB58-7BD4-4459-A2EB-C412D6EC8E18}
[2012/04/16 19:52:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{44ACE206-2C0F-4A88-9186-E39AADDA6FE7}
[2012/04/14 20:59:07 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5347E02E-61C4-4A34-82A7-545D2641B3F3}
[2012/04/14 20:58:39 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{022A2F2D-9B12-4D06-B669-A9642629A139}
[2012/04/14 11:21:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{56C1D28E-2276-4DB1-9239-EA48F9749018}
[2012/04/14 11:20:55 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{302F11B4-7742-4911-AAB8-C4243746E438}
[2012/04/12 13:10:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{DEB12ACD-A165-40D6-B120-B90FF89CF18F}
[2012/04/12 13:09:53 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8BEAEFC4-BC24-4E9C-A4BA-925BFC01E83B}
[2012/04/12 10:42:36 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{4E38B6BD-FC8A-41F2-92B3-321A33528DBC}
[2012/04/12 10:42:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{ADDEEC85-BDAB-4677-ADAC-96F49FBBEC9A}
[2012/04/12 01:26:11 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntkrnlpa.exe
[2012/04/12 01:26:07 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntoskrnl.exe
[2012/04/12 01:13:14 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{53F44410-0F49-4159-A9F7-59CC9BFFC840}
[2012/04/12 01:00:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{366BC4BB-E3D2-4779-8C3E-EF1ED4E083D1}
[2012/04/12 00:59:22 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{129F8187-BA00-4F56-9B40-E66F1178AA51}
[2012/04/11 23:15:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{CB62930E-E8B8-4025-A65D-E322529139F8}
[2012/04/11 19:53:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2012/04/11 18:33:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/04/11 18:32:29 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2012/04/11 18:32:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2012/04/11 18:32:07 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2012/04/11 18:26:16 | 000,000,000 | —D | C] – C:\$AVG
[2012/04/11 16:45:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SpeedyPC Software
[2012/04/11 16:45:07 | 000,000,000 | —D | C] – C:\Program Files\SpeedyPC Software
[2012/04/10 21:42:54 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{866CAD26-2E62-4941-BDEC-0923B602D05F}
[2012/04/09 02:12:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\SpeedyPC Software
[2012/04/09 02:12:02 | 000,000,000 | —D | C] – C:\ProgramData\SpeedyPC Software
[2012/04/08 23:19:57 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{76C924EA-6DD3-4D30-8A0B-48AE4858BCD8}
[2012/04/03 21:36:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\WinZip
[2012/04/03 20:12:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{33EE76A0-7DA3-43AD-AA28-3D14011E35FA}
[2012/04/03 20:11:27 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{4F619680-21D9-4743-AA23-61D6AD6AFDFD}
[2012/04/03 19:37:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6134C62C-6DBF-4C38-B968-D8951F6892BF}
[2012/04/03 19:20:22 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BC049C4B-D462-49AA-8DBC-5E59C2640EAD}
[2012/04/03 19:19:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{78D44058-B568-47E9-A492-E82E66134CEA}
[2012/03/29 20:41:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{92341BC9-2B8A-4130-AF99-C38DF4ACE36A}
[2012/03/29 19:37:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{75351EA8-4AD7-4C50-89C7-E4901675B152}
[2012/03/26 23:53:31 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{54C4A35C-A82D-4C15-A4B6-0476397D1B3C}
[2012/03/26 23:53:04 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{47D1C48E-CA92-4A51-A53B-A29A2D6F0B0B}
[2012/03/26 11:52:08 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5A15AD8D-6405-440F-801B-97CD9EC05AA2}
[2012/03/26 11:51:43 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{924EF17F-2F86-4D2B-BABC-EA55463BA947}

========== Files - Modified Within 30 Days ==========

[2012/04/24 19:39:45 | 000,010,592 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/24 19:39:45 | 000,010,592 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/24 19:34:51 | 000,000,888 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/24 19:34:14 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/04/24 19:34:09 | 1062,518,784 | -HS- | M] () – C:\hiberfil.sys
[2012/04/24 12:22:05 | 000,000,892 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/24 04:19:00 | 000,103,784 | —- | M] () – C:\Users\Christina\GoToAssistDownloadHelper.exe
[2012/04/24 00:49:05 | 000,637,848 | —- | M] (Oracle Corporation) – C:\windows\System32\npdeployJava1.dll
[2012/04/24 00:49:05 | 000,224,136 | —- | M] (Oracle Corporation) – C:\windows\System32\javaws.exe
[2012/04/24 00:49:05 | 000,173,960 | —- | M] (Oracle Corporation) – C:\windows\System32\javaw.exe
[2012/04/24 00:49:05 | 000,173,960 | —- | M] (Oracle Corporation) – C:\windows\System32\java.exe
[2012/04/24 00:49:04 | 000,567,696 | —- | M] (Oracle Corporation) – C:\windows\System32\deployJava1.dll
[2012/04/23 21:15:03 | 000,001,011 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/23 17:02:51 | 000,000,027 | —- | M] () – C:\windows\System32\drivers\etc\hosts
[2012/04/23 14:20:38 | 000,001,173 | —- | M] () – C:\Users\Christina\Desktop\ComboFix - Shortcut.lnk
[2012/04/23 13:46:21 | 000,014,519 | —- | M] () – C:\Combofix.text
[2012/04/22 20:16:06 | 000,649,584 | —- | M] () – C:\windows\System32\perfh009.dat
[2012/04/22 20:16:06 | 000,120,746 | —- | M] () – C:\windows\System32\perfc009.dat
[2012/04/22 12:06:51 | 000,181,064 | —- | M] (Sysinternals) – C:\windows\PSEXESVC.EXE
[2012/04/22 12:06:51 | 000,000,042 | —- | M] () – C:\repairs_running.dat
[2012/04/17 00:48:37 | 000,001,078 | —- | M] () – C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/04/16 14:54:34 | 000,002,290 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/04/11 01:35:17 | 000,392,875 | —- | M] () – C:\Users\Christina\Desktop\fru_7steps.pdf

========== Files Created - No Company Name ==========

[2012/04/24 04:18:59 | 000,103,784 | —- | C] () – C:\Users\Christina\GoToAssistDownloadHelper.exe
[2012/04/24 02:17:01 | 000,205,864 | —- | C] () – C:\windows\System32\drivers\OADriver.sys
[2012/04/24 02:17:01 | 000,039,048 | —- | C] () – C:\windows\System32\drivers\oahlp32.sys
[2012/04/23 14:20:38 | 000,001,173 | —- | C] () – C:\Users\Christina\Desktop\ComboFix - Shortcut.lnk
[2012/04/23 13:46:20 | 000,014,519 | —- | C] () – C:\Combofix.text
[2012/04/22 12:01:08 | 000,000,042 | —- | C] () – C:\repairs_running.dat
[2012/04/17 00:48:37 | 000,001,078 | —- | C] () – C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/04/11 01:35:17 | 000,392,875 | —- | C] () – C:\Users\Christina\Desktop\fru_7steps.pdf
[2011/10/14 11:06:49 | 000,067,156 | —- | C] () – C:\windows\Huawei ModemsUninstall.exe
[2011/10/14 11:06:43 | 000,010,240 | —- | C] () – C:\windows\System32\drivers\mdvrmng.sys
[2011/08/20 00:52:46 | 000,023,128 | —- | C] () – C:\windows\hpqins15.dat
[2011/07/03 20:40:27 | 000,202,283 | —- | C] () – C:\windows\hpoins18.dat
[2011/07/03 20:40:27 | 000,005,355 | —- | C] () – C:\windows\hpomdl18.dat
[2011/06/25 16:30:02 | 000,202,516 | —- | C] () – C:\windows\hpoins18.dat.temp
[2011/06/25 16:30:02 | 000,005,355 | —- | C] () – C:\windows\hpomdl18.dat.temp
[2011/06/04 20:34:36 | 000,000,376 | —- | C] () – C:\windows\ODBC.INI
[2011/01/19 08:42:30 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/01/19 08:07:17 | 000,000,000 | —- | C] () – C:\windows\nsreg.dat
[2011/01/17 11:01:21 | 000,120,688 | —- | C] () – C:\windows\Wiainst.exe
[2011/01/17 11:00:36 | 000,552,960 | —- | C] () – C:\windows\System32\SnMinDrv.dll
[2011/01/17 11:00:36 | 000,154,112 | —- | C] () – C:\windows\System32\SNWIAUI.dll
[2011/01/17 11:00:36 | 000,135,168 | —- | C] () – C:\windows\System32\SnImgFlt.dll
[2011/01/17 11:00:36 | 000,094,208 | —- | C] () – C:\windows\System32\SnErHdlr.dll
[2011/01/17 11:00:16 | 000,484,656 | —- | C] () – C:\windows\ssndii.exe
[2011/01/17 10:59:30 | 000,259,888 | —- | C] () – C:\windows\SUPDRun.exe
[2011/01/17 10:59:30 | 000,151,552 | —- | C] () – C:\windows\System32\spd__ci.exe
[2011/01/17 10:59:29 | 000,283,136 | —- | C] () – C:\windows\System32\DscPnt.dll
[2011/01/17 10:59:29 | 000,026,624 | —- | C] () – C:\windows\System32\spd__l.dll
[2010/09/01 11:06:37 | 000,001,064 | —- | C] () – C:\windows\HotFixList.ini
[2010/09/01 10:49:40 | 000,006,656 | —- | C] () – C:\windows\System32\bcmwlrc.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:B63300D1
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:D1B5B4F1

< End of report >
Hi,

So the Ask Toolbar is only in Firefox? Be sure to update to Internet Explorer 9 as well. You can find that here

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Right-click and Run as Administrator SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    ask
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
SystemLook 30.07.11 by jpshortstuff Log created at 21:14 on 24/04/2012 by Christina Administrator - Elevation successful No Context: CODE ========== filefind ========== Searching for "ask" No files found. -= EOF =- In anger I had uninstalled Ask from programs but it survived and stayed in taskbars.
Hi,

I had uninstalled Ask from programs but it survived and stayed in taskbars.

What browsers are you still seeing it in? It is not showing in the logs?

In Firefox click on Tools >> Add-ons >> if that toolbar is still there remove it.

In Chrome click on the "Wrench" >> Tools >> Extensions >> if it is still there as well remove it.
It is in Mozila F It says Ask.com Search Engine- Better Web Search Below: ASK Search Well, I suppose this should not disturb me so much.
Hi Jeff It works great. Thank you very much, it was a pleasure to work under your guidance. Please let me know if this terminates the matter. I shall be grateful for your indication which of the programs, if at all, I could use for cleaning my registry and repairing in the future. I know of some contraindications but not all of them were warned against instructing repair. I acknowledge you final advice and shall implement some of that. Chris

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI