Spyware / Malware / Virus Removal
searchqu and searchnu406 removal [Solved]
30 min read
Chris1701
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Starter
Boot Device: \Device\HarddiskVolume1
Install Date: 17/01/2011 09:57:42
System Uptime: 23/04/2012 23:50:51 (2 hours ago)
.
Motherboard: SAMSUNG ELECTRONICS CO., LTD. | | N145P/N250P/N260P
Processor: Intel® Atom™ CPU N450 @ 1.66GHz | CPU 1 | 983/mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 88 GiB total, 56.043 GiB free.
D: is FIXED (NTFS) - 130 GiB total, 70.365 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
Description: Photosmart C6100 series
Device ID: ROOT\MULTIFUNCTION\0001
Manufacturer: HP
Name: Photosmart C6100 series
PNP Device ID: ROOT\MULTIFUNCTION\0001
Service:
.
Class GUID:
Description: Photosmart C6100 series
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer:
Name: Photosmart C6100 series
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service:
.
==== System Restore Points ===================
.
RP271: 12/04/2012 10:44:30 - Windows Update
RP272: 16/04/2012 14:20:31 - Windows Backup
RP273: 22/04/2012 11:52:55 - Tweaking.com - Windows Repair
RP274: 22/04/2012 19:01:10 - Windows Backup
RP275: 24/04/2012 00:48:11 - Installed Java™ 7 Update 3
.
==== Installed Programs ======================
.
32 Bit HP CIO Components Installer
3Connect
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.3)
AIO_CDA_ProductContext
AIO_CDA_Software
AIO_Scan
Amazon MP3 Downloader 1.0.9
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Atheros Client Installation Program
BatteryLifeExtender
Bonjour
Broadcom 802.11 Network Adapter
BufferChm
C6100
c6100_Help
Copy
CyberLink YouCam
D3DX10
Destinations
DeviceDiscovery
DocProc
Easy Content Share
Easy Display Manager
Easy Network Manager
Easy Resolution Manager
Easy SpeedUp Manager
EasyBatteryManager
EasyFileShare
ERUNT 1.1j
ESET Online Scanner v3
ETDWare PS/2-X86 8.0.7.0_WHQL
Fast Start
Fax
FileZilla Client 3.4.0
Google Chrome
Google Earth
Google Update Helper
GPBaseService2
HP Customer Participation Program 13.0
HP Imaging Device Functions 13.0
HP Photosmart All-In-One Driver Software 13.0 Rel. A
HP Photosmart Essential 3.5
HP Smart Web Printing 4.60
HP Solution Center 13.0
HP Update
HPPhotoGadget
HPPhotoSmartDiscLabelContent1
HPPhotosmartEssential
HPProductAssistant
HPSSupply
Huawei modem
iLivid
Intel® Graphics Media Accelerator Driver
IrfanView (remove only)
iTunes
Java Auto Updater
Java™ 6 Update 29
Java™ 7 Update 3
Malwarebytes Anti-Malware version 1.61.0.1400
MarketResearch
Marvell Miniport Driver
McAfee Virtual Technician
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office Basic Edition 2003
Microsoft Office File Validation Add-In
Microsoft Office Outlook Connector
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MobileMe Control Panel
Movie Color Enhancer
Mozilla Firefox 12.0 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Network
OCR Software by I.R.I.S. 13.0
OpenOffice.org 3.3
PLAY ONLINE
QuickTime
Realtek High Definition Audio Driver
REALTEK PCIE Wireless LAN Software
Samsung AnyWeb Print
Samsung Recovery Solution 5
Samsung Support Center 1.0
Samsung Universal Print Driver
Samsung Universal Scan Driver
Samsung Update Plus
SamsungMovie
Scan
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Shop for HP Supplies
Skype™ 4.2
SmartWebPrinting
Software Informer 1.1
SolutionCenter
SRS Premium Sound Control Panel
Status
TeamViewer 6
Toolbox
TrayApp
TuneUp Utilities 2011
TuneUp Utilities Language Pack (en-US)
Tweaking.com - Windows Repair (All in One)
UnloadSupport
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
User Guide
Vit Registry Fix 9.5.4 (remove only)
WebReg
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
WinZip 16.0
WinZipBar Toolbar
Yahoo! BrowserPlus 2.9.8
Yahoo! Messenger
Yahoo! Software Update
.
==== Event Viewer Messages From Past Week ========
.
23/04/2012 23:51:31, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom
23/04/2012 17:02:59, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
23/04/2012 16:04:51, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
22/04/2012 20:07:08, Error: Service Control Manager [7034] - The Adobe Acrobat Update Service service terminated unexpectedly. It has done this 1 time(s).
22/04/2012 16:35:15, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
22/04/2012 16:32:44, Error: Service Control Manager [7022] - The McAfee Network Agent service hung on starting.
22/04/2012 16:31:07, Error: Service Control Manager [7022] - The McAfee VirusScan Announcer service hung on starting.
22/04/2012 12:18:56, Error: Service Control Manager [7022] - The McAfee McShield service hung on starting.
21/04/2012 17:32:37, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the defragsvc service.
.
==== End Of File ===========================
jeffce
Hi,
Do you have the DDS.txt log that was created as well? If so post that too please.
———-
Please do the following:
Hold down the Windows key and press R to open a run box
type the following text into the run box
appwiz.cpl
This will open your Programs And Features. A list of installed programs will populate
Remove the following programs if still there:
iLivid
Java™ 6 Update 29
———-
Do you have the DDS.txt log that was created as well? If so post that too please.
———-
Please do the following:
Hold down the Windows key and press R to open a run box
type the following text into the run box
appwiz.cpl
This will open your Programs And Features. A list of installed programs will populate
Remove the following programs if still there:
iLivid
Java™ 6 Update 29
———-
Chris1701
I believe it is this one
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 1:52:32.92 on 24/04/2012
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.3.0
Microsoft Windows 7 Starter 6.1.7601.1.1252.44.1033.18.1013.143 [GMT 1:00]
.
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\windows\System32\svchost.exe -k HPZ12
C:\windows\System32\svchost.exe -k HPZ12
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\windows\system32\svchost.exe -k HPService
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\taskhost.exe
C:\windows\System32\rundll32.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\TeamViewer\Version6\TeamViewer.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel.exe
C:\windows\system32\taskeng.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\windows\system32\igfxext.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe
C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
C:\windows\system32\svchost.exe -k SDRSVC
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\Users\Christina\Downloads\dds.scr
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page =
uInternet Settings,ProxyOverride = *.local
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: W2PBrowser Class: {aa609d72-8482-4076-8991-8cdae5b93bcb} - c:\program files\samsung anyweb print\W2PBrowser.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\christ~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {328ECD19-C167-40eb-A0C7-16FE7634105E} - {94BB0C4C-B957-479A-85E4-42F53B89F681} - c:\program files\samsung anyweb print\W2PBrowser.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\christ~1\appdata\roaming\mozilla\firefox\profiles\l3h69xx6.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\mcafee\supportability\mvt\NPMVTPlugin.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: c:\users\christina\appdata\local\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll
.
—- FIREFOX POLICIES —-
FF - user.js: general.useragent.extra.brc -
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
============= SERVICES / DRIVERS ===============
.
R1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\drivers\SABI.sys [2010-9-1 10752]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]
R2 BecHelperService;BecHelperService;c:\program files\3 mobile broadband\3connect\BecHelperService.exe [2011-10-14 1740696]
R2 TeamViewer6;TeamViewer 6;c:\program files\teamviewer\version6\TeamViewer_Service.exe [2011-8-30 2337144]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2011\TuneUpUtilitiesService32.exe [2011-2-18 1517376]
R2 UI Assistant Service;UI Assistant Service;c:\program files\play online\AssistantServices.exe [2011-1-26 252784]
R3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\drivers\ETD.sys [2010-9-2 94208]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [2011-10-14 73216]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2011\TuneUpUtilitiesDriver32.sys [2010-11-29 10064]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2010-7-8 322336]
S2 0311831335121373mcinstcleanup;McAfee Application Installer Cleanup (0311831335121373);c:\users\christ~1\appdata\local\temp\031183~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service –> c:\users\christ~1\appdata\local\temp\031183~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-7-29 136176]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [2011-10-14 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\drivers\ew_usbenumfilter.sys [2011-10-14 11136]
S3 ewusbmbb;HUAWEI USB-WWAN miniport;c:\windows\system32\drivers\ewusbwwan.sys [2011-10-14 353280]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-7-29 136176]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2011-1-26 9216]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-4-23 129976]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]
S3 Samsung UPD Service;Samsung UPD Service;c:\windows\system32\SUPDSvc.exe [2011-1-17 131888]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-25 52224]
.
=============== Created Last 30 ================
.
2012-04-24 00:40:50 ——– d—–w- c:\users\christ~1\appdata\local\{AB19881D-AE5D-4E25-8C08-1A14E631CAC0}
2012-04-24 00:40:25 ——– d—–w- c:\users\christ~1\appdata\local\{9AF1068E-65E6-455D-A5F9-732EEB637530}
2012-04-24 00:07:23 ——– d—–w- c:\users\christ~1\appdata\local\{84804CA1-E889-462B-805E-326AA920561D}
2012-04-24 00:07:00 ——– d—–w- c:\users\christ~1\appdata\local\{F08A658D-F235-49DC-AA6C-94F348BAB383}
2012-04-23 23:49:32 637848 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-04-23 22:55:02 ——– d—–w- c:\users\christ~1\appdata\local\{CB4FE251-26EE-4EE9-8FC5-AD14900F962C}
2012-04-23 22:54:43 ——– d—–w- c:\users\christ~1\appdata\local\{99FA0E2B-F868-498E-9B5B-042774EE8013}
2012-04-23 20:19:30 ——– d—–w- c:\users\christ~1\appdata\local\{C52E985A-405B-4AC2-AAE3-FF8304F2DE3F}
2012-04-23 20:19:15 ——– d—–w- c:\users\christ~1\appdata\local\{68375F71-2413-428B-9BD5-DAA65E06FF1D}
2012-04-23 20:15:02 ——– d—–w- c:\program files\Mozilla Maintenance Service
2012-04-23 20:14:59 43960 —-a-w- c:\program files\mozilla firefox\mozglue.dll
2012-04-23 20:14:59 157352 —-a-w- c:\program files\mozilla firefox\maintenanceservice_installer.exe
2012-04-23 20:14:59 129976 —-a-w- c:\program files\mozilla firefox\maintenanceservice.exe
2012-04-23 20:14:58 588728 —-a-w- c:\program files\mozilla firefox\gkmedias.dll
2012-04-23 16:14:11 ——– d—–w- c:\users\christ~1\appdata\local\{E5FC0E25-F14E-48FC-A003-874F022E1698}
2012-04-23 16:13:42 ——– d—–w- c:\users\christ~1\appdata\local\{486161F1-98FF-43C4-A668-6EE23466B845}
2012-04-23 16:09:10 ——– d-sh–w- C:\$RECYCLE.BIN
2012-04-23 16:09:03 ——– d—–w- c:\users\christ~1\appdata\local\temp
2012-04-23 15:05:48 ——– d—–w- c:\users\christ~1\appdata\local\{0C258FC4-16B9-415A-BB57-31CD0F30F657}
2012-04-23 15:05:34 ——– d—–w- c:\users\christ~1\appdata\local\{320BC3A4-397E-4005-8381-3B8ADD6543C8}
2012-04-23 12:11:15 ——– d—–w- c:\users\christ~1\appdata\local\{2F869C4D-524F-4759-A2A1-531068A179B6}
2012-04-23 12:06:16 98816 —-a-w- c:\windows\sed.exe
2012-04-23 12:06:16 518144 —-a-w- c:\windows\SWREG.exe
2012-04-23 12:06:16 256000 —-a-w- c:\windows\PEV.exe
2012-04-23 12:06:16 208896 —-a-w- c:\windows\MBR.exe
2012-04-23 11:58:05 ——– d—–w- c:\users\christ~1\appdata\local\{39E49110-86E0-421C-869A-40D48463DF44}
2012-04-23 11:57:47 ——– d—–w- c:\users\christ~1\appdata\local\{A6EA1502-635B-4A0B-AC0B-12CBB6E13A13}
2012-04-22 19:12:44 ——– d—–w- c:\users\christ~1\appdata\local\{9163A833-59B4-43CB-9F12-9C4AED32AA82}
2012-04-22 19:12:33 ——– d—–w- c:\users\christ~1\appdata\local\{0B100FCF-19D4-4871-B7AF-EF172CA7F52D}
2012-04-22 15:28:18 ——– d—–w- c:\users\christ~1\appdata\local\{0B739743-C1F4-4FF4-BB0F-B213725C5B9F}
2012-04-22 15:28:04 ——– d—–w- c:\users\christ~1\appdata\local\{54820ACA-EF1C-4BB0-A299-0C925519D435}
2012-04-22 11:13:19 ——– d—–w- c:\users\christ~1\appdata\local\{DF13114C-5A3B-4441-A027-39C57758E653}
2012-04-22 11:12:51 ——– d—–w- c:\users\christ~1\appdata\local\{B98FBA63-DE18-49EF-9DA7-9BAB94561AAF}
2012-04-22 10:54:22 ——– d—–w- C:\Reg_Backup
2012-04-22 10:50:42 ——– d—–w- C:\Tweaking.com_Windows_Repair_Logs
2012-04-22 10:50:02 ——– d—–w- c:\program files\Tweaking.com
2012-04-22 09:58:17 ——– d—–w- c:\users\christ~1\appdata\local\{7DCBE4D7-9A7A-4217-87C2-06C9FEF79DEF}
2012-04-21 23:01:09 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-04-21 23:01:08 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-04-21 22:32:44 ——– d—–w- c:\program files\common files\Mcafee
2012-04-21 22:32:42 ——– d—–w- c:\program files\McAfee.com
2012-04-21 22:23:34 ——– d—–w- c:\users\christ~1\appdata\local\{333DF259-F04E-40A8-9ABB-9644FA6AEC50}
2012-04-21 22:23:18 ——– d—–w- c:\users\christ~1\appdata\local\{1B898735-5C13-4BDD-986A-69C48B5913E1}
2012-04-21 21:28:19 ——– d—–w- c:\users\christ~1\appdata\local\{6892558C-DC81-470A-85BE-2CCB18F6848A}
2012-04-21 21:27:56 ——– d—–w- c:\users\christ~1\appdata\local\{43456941-9D2C-4930-9C5D-C7EF74544F22}
2012-04-21 21:24:26 ——– d—–w- c:\users\christ~1\appdata\local\{6C7EEEC2-46C5-4033-93E8-5E78917F7BA1}
2012-04-21 21:24:13 ——– d—–w- c:\users\christ~1\appdata\local\{6DA76A72-FE63-4581-B6FA-128F659A8FF7}
2012-04-21 20:10:21 ——– d—–w- c:\users\christ~1\appdata\local\{18AECC58-EBBE-4908-A03B-353385D96D8C}
2012-04-21 20:09:56 ——– d—–w- c:\users\christ~1\appdata\local\{2A7B61D3-90AC-44AE-AFA2-87A5B611FB36}
2012-04-21 19:20:25 ——– d—–w- c:\users\christ~1\appdata\local\{BED26244-67A8-4E24-8B7A-694F692FE217}
2012-04-21 19:20:13 ——– d—–w- c:\users\christ~1\appdata\local\{7EF4FEFF-4195-4B90-B704-A4E234D13572}
2012-04-21 18:22:00 ——– d—–w- c:\users\christ~1\appdata\local\{8EBDDF4A-4447-4615-AA92-F4500A80104B}
2012-04-21 18:21:32 ——– d—–w- c:\users\christ~1\appdata\local\{BC3F252D-6AF7-48DA-931B-684B6A8003E1}
2012-04-21 18:06:54 ——– d—–w- c:\users\christ~1\appdata\local\{902EF019-219E-469A-AAAC-BEBF7FD6EAC0}
2012-04-21 18:06:32 ——– d—–w- c:\users\christ~1\appdata\local\{F4EAC8DD-3E7B-4214-93BB-A27CA4188D24}
2012-04-21 09:22:27 ——– d—–w- c:\users\christ~1\appdata\local\{975ADCD7-0732-4DA9-809A-6EE3F83DCF0D}
2012-04-21 09:21:50 ——– d—–w- c:\users\christ~1\appdata\local\{82B05528-BF3B-452E-9D0C-7D6D64575259}
2012-04-20 09:28:10 ——– d—–w- c:\users\christ~1\appdata\local\{B4DFE1EE-8C93-417E-830A-A2688023CD71}
2012-04-20 09:27:23 ——– d—–w- c:\users\christ~1\appdata\local\{0EC2CC3D-7F16-4E0F-90CB-47C1CD875FD1}
2012-04-19 21:34:00 ——– d—–w- c:\users\christ~1\appdata\local\{E507A3E1-A6ED-44D0-9596-51938B34B725}
2012-04-19 21:33:34 ——– d—–w- c:\users\christ~1\appdata\local\{36B4D4B9-2C41-4FAB-8A6C-C30BCDB366BC}
2012-04-19 14:37:42 ——– d—–w- c:\users\christ~1\appdata\local\{AB98BAE1-A861-4533-84D5-42955D09F691}
2012-04-19 14:37:26 ——– d—–w- c:\users\christ~1\appdata\local\{EE31A02C-91BB-4D10-953D-B9DAD1829B49}
2012-04-18 21:39:05 ——– d—–w- c:\users\christ~1\appdata\local\{63CBD3F4-81C8-457C-A409-4BF9820AEBA0}
2012-04-18 21:38:21 ——– d—–w- c:\users\christ~1\appdata\local\{07D573A2-C17C-4A2E-A407-2FBBE7275332}
2012-04-18 19:37:36 ——– d—–w- c:\users\christ~1\appdata\local\{F1F2B18B-8211-472B-B281-206711E4F087}
2012-04-18 19:37:20 ——– d—–w- c:\users\christ~1\appdata\local\{A6F03645-0AF1-453A-B1DE-F19DF91B51BF}
2012-04-18 12:35:39 ——– d—–w- c:\users\christ~1\appdata\local\{C385A2F8-6574-415B-8687-4A5447CAF2F4}
2012-04-18 12:35:07 ——– d—–w- c:\users\christ~1\appdata\local\{6E81434B-B1DF-4C8E-ABE9-39DC724B7289}
2012-04-18 07:34:23 ——– d—–w- c:\users\christ~1\appdata\local\{2F0B1D53-0213-4C14-A34A-CDC89784EC01}
2012-04-18 07:34:09 ——– d—–w- c:\users\christ~1\appdata\local\{8B722896-69DA-454C-A0F9-8B6BD59DE768}
2012-04-17 20:23:21 ——– d—–w- c:\program files\ESET
2012-04-17 18:57:35 ——– d—–w- c:\users\christ~1\appdata\local\{B8212108-20A6-45AA-97AE-3CCB797CC5D1}
2012-04-17 18:57:09 ——– d—–w- c:\users\christ~1\appdata\local\{661A33A4-0C5E-44A4-AEDB-4ECBC3C62EB9}
2012-04-17 18:28:37 ——– d—–w- c:\users\christ~1\appdata\roaming\Malwarebytes
2012-04-17 18:28:02 ——– d—–w- c:\progra~2\Malwarebytes
2012-04-17 18:04:58 ——– d—–w- c:\users\christ~1\appdata\local\{E5C485DF-08A9-4FE8-A53D-0BDC91F116B3}
2012-04-17 18:04:33 ——– d—–w- c:\users\christ~1\appdata\local\{3A278787-D700-401C-9966-9D34692F875A}
2012-04-17 18:00:47 ——– d—–w- C:\found.000
2012-04-17 11:19:42 ——– d—–w- c:\users\christ~1\appdata\local\{F35E964A-6FCD-4353-97ED-CA912EB1EB65}
2012-04-17 11:19:16 ——– d—–w- c:\users\christ~1\appdata\local\{35592A29-3846-48BF-AF27-211B2EAB1B42}
2012-04-17 10:30:44 ——– d—–w- C:\_OTL
2012-04-17 10:01:51 ——– d—–w- c:\users\christ~1\appdata\local\{B32618D4-D46F-437C-B795-815FDE4A6B35}
2012-04-17 10:01:29 ——– d—–w- c:\users\christ~1\appdata\local\{50120FB6-C762-462B-A028-D6399FF4C31A}
2012-04-16 18:53:19 ——– d—–w- c:\users\christ~1\appdata\local\{353ABB58-7BD4-4459-A2EB-C412D6EC8E18}
2012-04-16 18:52:48 ——– d—–w- c:\users\christ~1\appdata\local\{44ACE206-2C0F-4A88-9186-E39AADDA6FE7}
2012-04-14 19:59:07 ——– d—–w- c:\users\christ~1\appdata\local\{5347E02E-61C4-4A34-82A7-545D2641B3F3}
2012-04-14 19:58:39 ——– d—–w- c:\users\christ~1\appdata\local\{022A2F2D-9B12-4D06-B669-A9642629A139}
2012-04-14 10:21:42 ——– d—–w- c:\users\christ~1\appdata\local\{56C1D28E-2276-4DB1-9239-EA48F9749018}
2012-04-14 10:20:55 ——– d—–w- c:\users\christ~1\appdata\local\{302F11B4-7742-4911-AAB8-C4243746E438}
2012-04-12 12:10:10 ——– d—–w- c:\users\christ~1\appdata\local\{DEB12ACD-A165-40D6-B120-B90FF89CF18F}
2012-04-12 12:09:53 ——– d—–w- c:\users\christ~1\appdata\local\{8BEAEFC4-BC24-4E9C-A4BA-925BFC01E83B}
2012-04-12 09:42:36 ——– d—–w- c:\users\christ~1\appdata\local\{4E38B6BD-FC8A-41F2-92B3-321A33528DBC}
2012-04-12 09:42:18 ——– d—–w- c:\users\christ~1\appdata\local\{ADDEEC85-BDAB-4677-ADAC-96F49FBBEC9A}
2012-04-12 00:48:26 19824 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-12 00:48:25 5120 —-a-w- c:\windows\system32\wmi.dll
2012-04-12 00:48:25 172544 —-a-w- c:\windows\system32\wintrust.dll
2012-04-12 00:48:25 159232 —-a-w- c:\windows\system32\imagehlp.dll
2012-04-12 00:26:11 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-12 00:26:07 3913072 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-04-12 00:13:14 ——– d—–w- c:\users\christ~1\appdata\local\{53F44410-0F49-4159-A9F7-59CC9BFFC840}
2012-04-12 00:00:33 ——– d—–w- c:\users\christ~1\appdata\local\{366BC4BB-E3D2-4779-8C3E-EF1ED4E083D1}
2012-04-11 23:59:22 ——– d—–w- c:\users\christ~1\appdata\local\{129F8187-BA00-4F56-9B40-E66F1178AA51}
2012-04-11 22:15:03 ——– d—–w- c:\users\christ~1\appdata\local\{CB62930E-E8B8-4025-A65D-E322529139F8}
2012-04-11 17:32:29 ——– d—–w- c:\progra~2\AVG Secure Search
2012-04-11 17:32:15 ——– d—–w- c:\program files\common files\AVG Secure Search
2012-04-11 17:32:07 ——– d—–w- c:\program files\AVG Secure Search
2012-04-11 17:26:16 ——– d—–w- C:\$AVG
2012-04-11 15:45:09 ——– d—–w- c:\program files\common files\SpeedyPC Software
2012-04-11 15:45:07 ——– d—–w- c:\program files\SpeedyPC Software
2012-04-10 20:42:54 ——– d—–w- c:\users\christ~1\appdata\local\{866CAD26-2E62-4941-BDEC-0923B602D05F}
2012-04-09 01:12:51 ——– d—–w- c:\users\christ~1\appdata\roaming\SpeedyPC Software
2012-04-09 01:12:02 ——– d—–w- c:\progra~2\SpeedyPC Software
2012-04-08 22:19:57 ——– d—–w- c:\users\christ~1\appdata\local\{76C924EA-6DD3-4D30-8A0B-48AE4858BCD8}
2012-04-04 05:53:56 182160 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2012-04-04 05:53:56 182160 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2012-04-03 20:36:56 ——– d—–w- c:\users\christ~1\appdata\local\WinZip
2012-04-03 19:12:03 ——– d—–w- c:\users\christ~1\appdata\local\{33EE76A0-7DA3-43AD-AA28-3D14011E35FA}
2012-04-03 19:11:27 ——– d—–w- c:\users\christ~1\appdata\local\{4F619680-21D9-4743-AA23-61D6AD6AFDFD}
2012-04-03 18:37:50 ——– d—–w- c:\users\christ~1\appdata\local\{6134C62C-6DBF-4C38-B968-D8951F6892BF}
2012-04-03 18:20:22 ——– d—–w- c:\users\christ~1\appdata\local\{BC049C4B-D462-49AA-8DBC-5E59C2640EAD}
2012-04-03 18:19:15 ——– d—–w- c:\users\christ~1\appdata\local\{78D44058-B568-47E9-A492-E82E66134CEA}
2012-03-29 19:41:09 ——– d—–w- c:\users\christ~1\appdata\local\{92341BC9-2B8A-4130-AF99-C38DF4ACE36A}
2012-03-29 18:37:48 ——– d—–w- c:\users\christ~1\appdata\local\{75351EA8-4AD7-4C50-89C7-E4901675B152}
2012-03-26 22:53:31 ——– d—–w- c:\users\christ~1\appdata\local\{54C4A35C-A82D-4C15-A4B6-0476397D1B3C}
2012-03-26 22:53:04 ——– d—–w- c:\users\christ~1\appdata\local\{47D1C48E-CA92-4A51-A53B-A29A2D6F0B0B}
2012-03-26 10:52:08 ——– d—–w- c:\users\christ~1\appdata\local\{5A15AD8D-6405-440F-801B-97CD9EC05AA2}
2012-03-26 10:51:43 ——– d—–w- c:\users\christ~1\appdata\local\{924EF17F-2F86-4D2B-BABC-EA55463BA947}
.
==================== Find3M ====================
.
2012-04-23 23:49:04 567696 —-a-w- c:\windows\system32\deployJava1.dll
2012-03-02 11:37:03 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-28 01:18:55 1799168 —-a-w- c:\windows\system32\jscript9.dll
2012-02-28 01:11:21 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
2012-02-28 01:11:07 1127424 —-a-w- c:\windows\system32\wininet.dll
2012-02-28 01:03:16 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-02-17 05:34:22 826880 —-a-w- c:\windows\system32\rdpcore.dll
2012-02-10 05:38:43 1077248 —-a-w- c:\windows\system32\DWrite.dll
2012-02-03 03:54:27 2343424 —-a-w- c:\windows\system32\win32k.sys
2012-01-25 05:32:35 58880 —-a-w- c:\windows\system32\rdpwsx.dll
2012-01-25 05:32:34 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll
2012-01-25 05:27:51 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe
.
============= FINISH: 1:53:52.59 ===============
jeffce
Yep that was the one. 
Be sure to turn your antivirus back on because it is just not showing in the log but otherwise it looks good.
If you were wanting two alternatives to McAfee you could choose either of the two below but be sure to choose just one…
Microsoft Security Essentials
Avast
———-
Providing there are no more malware related problems…
IT APPEARS THAT YOUR LOGS ARE NOW CLEAN
SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! 
This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
———-
The following will implement some cleanup procedures as well as reset System Restore points:
Click Start > Run and copy/paste the following text into the Run box as shown and click OK.
Combofix /Uninstall
(Note: There is a space between the ..X and the /U that needs to be there.)
[external image: Posted Image]
———-
Clean up with OTL:
Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted using right-click > delete so they aren't cluttering up your desktop.
Here are some tips to reduce the potential for spyware infection in the future:
1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here. **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free
5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.
6. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.
7. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?
Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Be sure to turn your antivirus back on because it is just not showing in the log but otherwise it looks good.
If you were wanting two alternatives to McAfee you could choose either of the two below but be sure to choose just one…
Microsoft Security Essentials
Avast
———-
Providing there are no more malware related problems…
IT APPEARS THAT YOUR LOGS ARE NOW CLEAN
This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
———-
The following will implement some cleanup procedures as well as reset System Restore points:
Click Start > Run and copy/paste the following text into the Run box as shown and click OK.
Combofix /Uninstall
(Note: There is a space between the ..X and the /U that needs to be there.)
[external image: Posted Image]
———-
Clean up with OTL:
- Right-click and Run as Administrator OTL.exe to start the program.
- Close all other programs apart from OTL as this step will require a reboot
- On the OTL main screen, press the CLEANUP button
- Say Yes to the prompt and then allow the program to reboot your computer.
Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted using right-click > delete so they aren't cluttering up your desktop.
Here are some tips to reduce the potential for spyware infection in the future:
1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
- From within Internet Explorer click on the Tools menu and then click on Options.
- Click once on the Security tab
- Click once on the Internet icon so it becomes highlighted.
- Click once on the Custom Level button.
- Change the Download signed ActiveX controls to Prompt
- Change the Download unsigned ActiveX controls to Disable
- Change the Initialize and script ActiveX controls not marked as safe to Disable
- Change the Installation of desktop items to Prompt
- Change the Launching programs and files in an IFRAME to Prompt
- Change the Navigate sub-frames across different domains to Prompt
- When all these settings have been made, click on the OK button.
- If it prompts you as to whether or not you want to save the settings, press the Yes button.
- Next press the Apply button and then the OK to exit the Internet Properties page.
- Open Internet Explorer
- Click on Tools > Internet Options
- Press Security tab
- Select Internet zone then place check next to Enable Protected Mode if not already done
- Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
- Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.
4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here. **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free
5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.
6. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.
7. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?
Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Chris1701
Hi Jeff
After your last response I proceeded to restore my McAfee. In the course of the re-installation I was prompted to uninstall Malwarebytes due to incompatibility but I opted to keep it and to see what happens. Installation went ok but later on McA's icons faded away and it transpired that installation was ineffective. So I uninstalled it and tried to reinstall ab 20 times. I was forced to contact their tech supp. It must be somewhere in India because all my helpers have invariably Indian names.
After taking control of my screen they messed up my registry: deleted temp files, interfered with my administrator's settings and many more which I am not even able to evaluate.
For the reasons above I am asking you to indicate whether I should go on with your instructions or to do a scan showing the present state before carrying out your final instructions.
Also, please tell me how to enter with my other laptop.
Chris
Chris1701
Jeff
I know it is a small matter to ask you about but dealing with this by myself means enormous loss of time.:
I want to remove ask toolbar from my search engines and it is so-far difficult for me. I deleted it form my programmes but it still rules Firefox. I hate it because it provides no helpful information but directs to multiple tabs with the same guestion: " idem per idem". Is there any way I could restore to my normal homepage (Google) and links to sites ebay, amazon etc from my hotmail page, windows live, firefox and explorer.?
ERUNT appears upon opening, can it be stopped appearing?
Cheers
Chris
jeffce
Hi,
As for ERUNT…keep the program but we will remove it from startup. Just remember to run it about once a week manually to back up your registry.
Please do the following…
Go to Start >> in Start Search type Run >> when it populates above select Run. In the Run text bar type msconfig >> press OK >> select Startup tab >> remove checkmark from any ERUNT entries >> select Apply >> Ok >> reboot your system.
Ok…since they took control of your system remotely it is hard to tell what it is that they did without getting new scans. They could have changed any number of things that we had already fixed and this includes putting the Ask Toolbar on your system again. This is the reason I recommend either Microsoft Security Essentials or Avast for an antivirus program. They are compatible with virtually everything. Anyway…run a new scan with OTL and I can see what they have done and hopefully put things back together.I was forced to contact their tech supp. It must be somewhere in India because all my helpers have invariably Indian names.
After taking control of my screen they messed up my registry: deleted temp files, interfered with my administrator's settings and many more which I am not even able to evaluate.
For the reasons above I am asking you to indicate whether I should go on with your instructions or to do a scan showing the present state before carrying out your final instructions.
As for ERUNT…keep the program but we will remove it from startup. Just remember to run it about once a week manually to back up your registry.
Go to Start >> in Start Search type Run >> when it populates above select Run. In the Run text bar type msconfig >> press OK >> select Startup tab >> remove checkmark from any ERUNT entries >> select Apply >> Ok >> reboot your system.
Chris1701
OTL logfile created on: 4/24/2012 7:42:09 PM - Run 7
OTL by OldTimer - Version 3.2.40.0 Folder = C:\Users\Christina\Downloads
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1013.30 Mb Total Physical Memory | 312.57 Mb Available Physical Memory | 30.85% Memory free
1.99 Gb Paging File | 1.24 Gb Available in Paging File | 62.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 88.00 Gb Total Space | 59.92 Gb Free Space | 68.10% Space Free | Partition Type: NTFS
Drive D: | 130.35 Gb Total Space | 70.37 Gb Free Space | 53.98% Space Free | Partition Type: NTFS
Computer Name: CHRISSAMSUNG | User Name: Christina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Christina\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe (SAMSUNG Electronics)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files\Online Armor\OAReg.exe (Emsi Software GmbH)
PRC - C:\Program Files\Online Armor\oacat.exe (Emsi Software GmbH)
PRC - C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe (SRS Labs, Inc.)
PRC - C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe (Samsung Electronics)
PRC - C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (SEC)
PRC - C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\PLAY ONLINE\AssistantServices.exe ()
PRC - C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\Samsung\Movie Color Enhancer\WinCRT.dll ()
MOD - C:\Program Files\Samsung\Samsung Recovery Solution 5\Resdll.dll ()
MOD - C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll ()
========== Win32 Services (SafeList) ==========
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe File not found
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TeamViewer6) – C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (SvcOnlineArmor) – C:\Program Files\Online Armor\oasrv.exe (Emsi Software GmbH)
SRV - (OAcat) – C:\Program Files\Online Armor\oacat.exe (Emsi Software GmbH)
SRV - (BecHelperService) – C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (Samsung UPD Service) – C:\Windows\System32\SUPDSvc.exe (Samsung Electronics CO., LTD.)
SRV - (UI Assistant Service) – C:\Program Files\PLAY ONLINE\AssistantServices.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (catchme) – C:\Users\CHRIST~1\AppData\Local\Temp\catchme.sys File not found
DRV - (oahlpXX) – C:\Windows\System32\drivers\oahlp32.sys ()
DRV - (OADevice) – C:\Windows\System32\drivers\OADriver.sys ()
DRV - (OAmon) – C:\Windows\System32\drivers\OAmon.sys (Emsisoft)
DRV - (mdvrmng) – C:\Windows\System32\drivers\mdvrmng.sys ()
DRV - (ewusbmbb) – C:\Windows\System32\drivers\ewusbwwan.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_hwusbdev) – C:\Windows\System32\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (huawei_enumerator) – C:\Windows\System32\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_usbenumfilter) – C:\Windows\System32\drivers\ew_usbenumfilter.sys (Huawei Technologies Co., Ltd.)
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (rtport) – C:\Windows\System32\drivers\rtport.sys (Windows ® 2003 DDK 3790 provider)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 65 4E 19 3B 02 22 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll File not found
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Christina\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/11 23:37:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/04/23 21:15:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/24 00:49:32 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/11 23:37:25 | 000,000,000 | —D | M]
[2011/10/04 01:13:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Christina\AppData\Roaming\Mozilla\Extensions
[2012/04/23 21:15:10 | 000,000,000 | —D | M] (No name found) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions
[2012/04/11 23:40:38 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/04/11 23:40:37 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]
[2012/04/23 21:15:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/04/23 21:15:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\distribution\extensions
[2012/04/18 04:07:26 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/04/11 18:32:03 | 000,003,747 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/04/18 04:06:17 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/18 04:06:17 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://search.avg.com/?d=4e4480f1&v;=7….q={searchTerms}
CHR - default_search_provider: suggest_url = http://suggestqueries.google.com/complete/…q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Christina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Users\Christina\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: SiteAdvisor = C:\Users\Christina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\
O1 HOSTS File: ([2012/04/23 17:02:51 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (W2PBrowser Class) - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Online Armor\oaui.exe (Emsi Software GmbH)
O4 - Startup: C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.3.0)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CA189E4A-4A04-4742-880D-62407F0217CC}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D82A697F-63A7-4A2B-9CD7-D1CBBF0B567D}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-mfe-ipt - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsi Software GmbH)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/04/24 19:35:38 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{AC5DCCF2-6D30-46B1-A8F8-4A40E666D9FD}
[2012/04/24 19:35:26 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5BBF0D47-40EF-44CF-9A91-8A409E9F4098}
[2012/04/24 11:47:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{AEE52324-1E24-4D1E-9D60-E65CA43007BC}
[2012/04/24 11:47:04 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{39ED5D2F-D1FE-4688-8E91-FB477351C801}
[2012/04/24 10:34:21 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F7EF0085-D988-4BB0-9B6A-E65877A5FF3F}
[2012/04/24 10:34:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{D6945D0A-CEAE-475F-9232-D4A246E9D64B}
[2012/04/24 03:10:55 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{62B7DC70-8BD7-43E8-8F54-4E3AC10E7FD5}
[2012/04/24 03:10:38 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{69F4A9D3-FB95-479E-BF28-8F127E71C17E}
[2012/04/24 03:05:36 | 000,000,000 | R-SD | C] – C:\Users\Christina\Documents\McAfee Vaults
[2012/04/24 02:49:08 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{11AE4FA2-5961-4B6A-861B-FC9428679320}
[2012/04/24 02:48:47 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{05837DFF-C69D-40CF-8EB8-B80C8FD8227F}
[2012/04/24 02:19:55 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\OnlineArmor
[2012/04/24 02:19:55 | 000,000,000 | —D | C] – C:\ProgramData\OnlineArmor
[2012/04/24 02:17:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Armor
[2012/04/24 02:17:01 | 000,025,192 | —- | C] (Emsisoft) – C:\windows\System32\drivers\OAmon.sys
[2012/04/24 02:16:50 | 000,000,000 | —D | C] – C:\Program Files\Online Armor
[2012/04/24 02:07:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{67B86495-09C0-4D56-9122-D346217C6D15}
[2012/04/24 02:07:25 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2B1C6F43-6C1B-4BB1-9648-75CCC520B237}
[2012/04/24 01:56:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{817A36E0-5C87-4390-8BFC-A195B140E7E5}
[2012/04/24 01:56:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{7B0867E3-271F-491A-8EE3-6C703F84591C}
[2012/04/24 01:40:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{AB19881D-AE5D-4E25-8C08-1A14E631CAC0}
[2012/04/24 01:40:25 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{9AF1068E-65E6-455D-A5F9-732EEB637530}
[2012/04/24 01:07:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{84804CA1-E889-462B-805E-326AA920561D}
[2012/04/24 01:07:00 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F08A658D-F235-49DC-AA6C-94F348BAB383}
[2012/04/24 00:50:05 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/04/24 00:49:32 | 000,637,848 | —- | C] (Oracle Corporation) – C:\windows\System32\npdeployJava1.dll
[2012/04/24 00:49:32 | 000,224,136 | —- | C] (Oracle Corporation) – C:\windows\System32\javaws.exe
[2012/04/24 00:49:32 | 000,173,960 | —- | C] (Oracle Corporation) – C:\windows\System32\javaw.exe
[2012/04/24 00:49:32 | 000,173,960 | —- | C] (Oracle Corporation) – C:\windows\System32\java.exe
[2012/04/23 23:55:02 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{CB4FE251-26EE-4EE9-8FC5-AD14900F962C}
[2012/04/23 23:54:43 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{99FA0E2B-F868-498E-9B5B-042774EE8013}
[2012/04/23 21:19:30 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{C52E985A-405B-4AC2-AAE3-FF8304F2DE3F}
[2012/04/23 21:19:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{68375F71-2413-428B-9BD5-DAA65E06FF1D}
[2012/04/23 21:15:02 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/04/23 21:15:02 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2012/04/23 17:14:11 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{E5FC0E25-F14E-48FC-A003-874F022E1698}
[2012/04/23 17:13:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{486161F1-98FF-43C4-A668-6EE23466B845}
[2012/04/23 17:09:10 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/04/23 17:09:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\temp
[2012/04/23 16:05:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0C258FC4-16B9-415A-BB57-31CD0F30F657}
[2012/04/23 16:05:34 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{320BC3A4-397E-4005-8381-3B8ADD6543C8}
[2012/04/23 13:11:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2F869C4D-524F-4759-A2A1-531068A179B6}
[2012/04/23 12:58:05 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{39E49110-86E0-421C-869A-40D48463DF44}
[2012/04/23 12:57:47 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{A6EA1502-635B-4A0B-AC0B-12CBB6E13A13}
[2012/04/22 20:12:44 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{9163A833-59B4-43CB-9F12-9C4AED32AA82}
[2012/04/22 20:12:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0B100FCF-19D4-4871-B7AF-EF172CA7F52D}
[2012/04/22 16:28:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0B739743-C1F4-4FF4-BB0F-B213725C5B9F}
[2012/04/22 16:28:04 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{54820ACA-EF1C-4BB0-A299-0C925519D435}
[2012/04/22 12:13:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{DF13114C-5A3B-4441-A027-39C57758E653}
[2012/04/22 12:12:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B98FBA63-DE18-49EF-9DA7-9BAB94561AAF}
[2012/04/22 11:54:22 | 000,000,000 | —D | C] – C:\Reg_Backup
[2012/04/22 11:54:18 | 000,181,064 | —- | C] (Sysinternals) – C:\windows\PSEXESVC.EXE
[2012/04/22 11:50:42 | 000,000,000 | —D | C] – C:\Tweaking.com_Windows_Repair_Logs
[2012/04/22 11:50:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
[2012/04/22 11:50:02 | 000,000,000 | —D | C] – C:\Program Files\Tweaking.com
[2012/04/22 10:58:17 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{7DCBE4D7-9A7A-4217-87C2-06C9FEF79DEF}
[2012/04/22 00:32:11 | 000,000,000 | —D | C] – C:\Users\Christina\Desktop\Play
[2012/04/21 23:32:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2012/04/21 23:23:34 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{333DF259-F04E-40A8-9ABB-9644FA6AEC50}
[2012/04/21 23:23:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{1B898735-5C13-4BDD-986A-69C48B5913E1}
[2012/04/21 22:57:07 | 000,000,000 | —D | C] – C:\Users\Christina\Desktop\lucid
[2012/04/21 22:28:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6892558C-DC81-470A-85BE-2CCB18F6848A}
[2012/04/21 22:27:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{43456941-9D2C-4930-9C5D-C7EF74544F22}
[2012/04/21 22:24:26 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6C7EEEC2-46C5-4033-93E8-5E78917F7BA1}
[2012/04/21 22:24:13 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6DA76A72-FE63-4581-B6FA-128F659A8FF7}
[2012/04/21 21:10:21 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{18AECC58-EBBE-4908-A03B-353385D96D8C}
[2012/04/21 21:09:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2A7B61D3-90AC-44AE-AFA2-87A5B611FB36}
[2012/04/21 20:20:25 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BED26244-67A8-4E24-8B7A-694F692FE217}
[2012/04/21 20:20:13 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{7EF4FEFF-4195-4B90-B704-A4E234D13572}
[2012/04/21 19:22:00 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8EBDDF4A-4447-4615-AA92-F4500A80104B}
[2012/04/21 19:21:32 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BC3F252D-6AF7-48DA-931B-684B6A8003E1}
[2012/04/21 19:06:54 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{902EF019-219E-469A-AAAC-BEBF7FD6EAC0}
[2012/04/21 19:06:32 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F4EAC8DD-3E7B-4214-93BB-A27CA4188D24}
[2012/04/21 10:22:27 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{975ADCD7-0732-4DA9-809A-6EE3F83DCF0D}
[2012/04/21 10:21:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{82B05528-BF3B-452E-9D0C-7D6D64575259}
[2012/04/20 10:28:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B4DFE1EE-8C93-417E-830A-A2688023CD71}
[2012/04/20 10:27:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0EC2CC3D-7F16-4E0F-90CB-47C1CD875FD1}
[2012/04/19 22:34:00 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{E507A3E1-A6ED-44D0-9596-51938B34B725}
[2012/04/19 22:33:34 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{36B4D4B9-2C41-4FAB-8A6C-C30BCDB366BC}
[2012/04/19 15:37:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{AB98BAE1-A861-4533-84D5-42955D09F691}
[2012/04/19 15:37:26 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{EE31A02C-91BB-4D10-953D-B9DAD1829B49}
[2012/04/18 22:39:05 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{63CBD3F4-81C8-457C-A409-4BF9820AEBA0}
[2012/04/18 22:38:21 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{07D573A2-C17C-4A2E-A407-2FBBE7275332}
[2012/04/18 20:37:36 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F1F2B18B-8211-472B-B281-206711E4F087}
[2012/04/18 20:37:20 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{A6F03645-0AF1-453A-B1DE-F19DF91B51BF}
[2012/04/18 13:35:39 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{C385A2F8-6574-415B-8687-4A5447CAF2F4}
[2012/04/18 13:35:07 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6E81434B-B1DF-4C8E-ABE9-39DC724B7289}
[2012/04/18 08:34:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2F0B1D53-0213-4C14-A34A-CDC89784EC01}
[2012/04/18 08:34:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8B722896-69DA-454C-A0F9-8B6BD59DE768}
[2012/04/17 21:23:21 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/04/17 19:57:35 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B8212108-20A6-45AA-97AE-3CCB797CC5D1}
[2012/04/17 19:57:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{661A33A4-0C5E-44A4-AEDB-4ECBC3C62EB9}
[2012/04/17 19:28:37 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\Malwarebytes
[2012/04/17 19:28:02 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/04/17 19:04:58 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{E5C485DF-08A9-4FE8-A53D-0BDC91F116B3}
[2012/04/17 19:04:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{3A278787-D700-401C-9966-9D34692F875A}
[2012/04/17 19:00:47 | 000,000,000 | —D | C] – C:\found.000
[2012/04/17 12:19:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F35E964A-6FCD-4353-97ED-CA912EB1EB65}
[2012/04/17 12:19:16 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{35592A29-3846-48BF-AF27-211B2EAB1B42}
[2012/04/17 11:30:44 | 000,000,000 | —D | C] – C:\_OTL
[2012/04/17 11:01:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B32618D4-D46F-437C-B795-815FDE4A6B35}
[2012/04/17 11:01:29 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{50120FB6-C762-462B-A028-D6399FF4C31A}
[2012/04/17 00:48:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/04/17 00:48:08 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012/04/16 23:32:49 | 000,000,000 | —D | C] – C:\Users\Christina\Desktop\whatthetech navigation
[2012/04/16 19:53:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{353ABB58-7BD4-4459-A2EB-C412D6EC8E18}
[2012/04/16 19:52:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{44ACE206-2C0F-4A88-9186-E39AADDA6FE7}
[2012/04/14 20:59:07 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5347E02E-61C4-4A34-82A7-545D2641B3F3}
[2012/04/14 20:58:39 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{022A2F2D-9B12-4D06-B669-A9642629A139}
[2012/04/14 11:21:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{56C1D28E-2276-4DB1-9239-EA48F9749018}
[2012/04/14 11:20:55 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{302F11B4-7742-4911-AAB8-C4243746E438}
[2012/04/12 13:10:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{DEB12ACD-A165-40D6-B120-B90FF89CF18F}
[2012/04/12 13:09:53 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8BEAEFC4-BC24-4E9C-A4BA-925BFC01E83B}
[2012/04/12 10:42:36 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{4E38B6BD-FC8A-41F2-92B3-321A33528DBC}
[2012/04/12 10:42:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{ADDEEC85-BDAB-4677-ADAC-96F49FBBEC9A}
[2012/04/12 01:26:11 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntkrnlpa.exe
[2012/04/12 01:26:07 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntoskrnl.exe
[2012/04/12 01:13:14 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{53F44410-0F49-4159-A9F7-59CC9BFFC840}
[2012/04/12 01:00:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{366BC4BB-E3D2-4779-8C3E-EF1ED4E083D1}
[2012/04/12 00:59:22 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{129F8187-BA00-4F56-9B40-E66F1178AA51}
[2012/04/11 23:15:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{CB62930E-E8B8-4025-A65D-E322529139F8}
[2012/04/11 19:53:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2012/04/11 18:33:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/04/11 18:32:29 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2012/04/11 18:32:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2012/04/11 18:32:07 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2012/04/11 18:26:16 | 000,000,000 | —D | C] – C:\$AVG
[2012/04/11 16:45:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SpeedyPC Software
[2012/04/11 16:45:07 | 000,000,000 | —D | C] – C:\Program Files\SpeedyPC Software
[2012/04/10 21:42:54 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{866CAD26-2E62-4941-BDEC-0923B602D05F}
[2012/04/09 02:12:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\SpeedyPC Software
[2012/04/09 02:12:02 | 000,000,000 | —D | C] – C:\ProgramData\SpeedyPC Software
[2012/04/08 23:19:57 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{76C924EA-6DD3-4D30-8A0B-48AE4858BCD8}
[2012/04/03 21:36:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\WinZip
[2012/04/03 20:12:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{33EE76A0-7DA3-43AD-AA28-3D14011E35FA}
[2012/04/03 20:11:27 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{4F619680-21D9-4743-AA23-61D6AD6AFDFD}
[2012/04/03 19:37:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6134C62C-6DBF-4C38-B968-D8951F6892BF}
[2012/04/03 19:20:22 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BC049C4B-D462-49AA-8DBC-5E59C2640EAD}
[2012/04/03 19:19:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{78D44058-B568-47E9-A492-E82E66134CEA}
[2012/03/29 20:41:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{92341BC9-2B8A-4130-AF99-C38DF4ACE36A}
[2012/03/29 19:37:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{75351EA8-4AD7-4C50-89C7-E4901675B152}
[2012/03/26 23:53:31 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{54C4A35C-A82D-4C15-A4B6-0476397D1B3C}
[2012/03/26 23:53:04 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{47D1C48E-CA92-4A51-A53B-A29A2D6F0B0B}
[2012/03/26 11:52:08 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5A15AD8D-6405-440F-801B-97CD9EC05AA2}
[2012/03/26 11:51:43 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{924EF17F-2F86-4D2B-BABC-EA55463BA947}
========== Files - Modified Within 30 Days ==========
[2012/04/24 19:39:45 | 000,010,592 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/24 19:39:45 | 000,010,592 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/24 19:34:51 | 000,000,888 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/24 19:34:14 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/04/24 19:34:09 | 1062,518,784 | -HS- | M] () – C:\hiberfil.sys
[2012/04/24 12:22:05 | 000,000,892 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/24 04:19:00 | 000,103,784 | —- | M] () – C:\Users\Christina\GoToAssistDownloadHelper.exe
[2012/04/24 00:49:05 | 000,637,848 | —- | M] (Oracle Corporation) – C:\windows\System32\npdeployJava1.dll
[2012/04/24 00:49:05 | 000,224,136 | —- | M] (Oracle Corporation) – C:\windows\System32\javaws.exe
[2012/04/24 00:49:05 | 000,173,960 | —- | M] (Oracle Corporation) – C:\windows\System32\javaw.exe
[2012/04/24 00:49:05 | 000,173,960 | —- | M] (Oracle Corporation) – C:\windows\System32\java.exe
[2012/04/24 00:49:04 | 000,567,696 | —- | M] (Oracle Corporation) – C:\windows\System32\deployJava1.dll
[2012/04/23 21:15:03 | 000,001,011 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/23 17:02:51 | 000,000,027 | —- | M] () – C:\windows\System32\drivers\etc\hosts
[2012/04/23 14:20:38 | 000,001,173 | —- | M] () – C:\Users\Christina\Desktop\ComboFix - Shortcut.lnk
[2012/04/23 13:46:21 | 000,014,519 | —- | M] () – C:\Combofix.text
[2012/04/22 20:16:06 | 000,649,584 | —- | M] () – C:\windows\System32\perfh009.dat
[2012/04/22 20:16:06 | 000,120,746 | —- | M] () – C:\windows\System32\perfc009.dat
[2012/04/22 12:06:51 | 000,181,064 | —- | M] (Sysinternals) – C:\windows\PSEXESVC.EXE
[2012/04/22 12:06:51 | 000,000,042 | —- | M] () – C:\repairs_running.dat
[2012/04/17 00:48:37 | 000,001,078 | —- | M] () – C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/04/16 14:54:34 | 000,002,290 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/04/11 01:35:17 | 000,392,875 | —- | M] () – C:\Users\Christina\Desktop\fru_7steps.pdf
========== Files Created - No Company Name ==========
[2012/04/24 04:18:59 | 000,103,784 | —- | C] () – C:\Users\Christina\GoToAssistDownloadHelper.exe
[2012/04/24 02:17:01 | 000,205,864 | —- | C] () – C:\windows\System32\drivers\OADriver.sys
[2012/04/24 02:17:01 | 000,039,048 | —- | C] () – C:\windows\System32\drivers\oahlp32.sys
[2012/04/23 14:20:38 | 000,001,173 | —- | C] () – C:\Users\Christina\Desktop\ComboFix - Shortcut.lnk
[2012/04/23 13:46:20 | 000,014,519 | —- | C] () – C:\Combofix.text
[2012/04/22 12:01:08 | 000,000,042 | —- | C] () – C:\repairs_running.dat
[2012/04/17 00:48:37 | 000,001,078 | —- | C] () – C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/04/11 01:35:17 | 000,392,875 | —- | C] () – C:\Users\Christina\Desktop\fru_7steps.pdf
[2011/10/14 11:06:49 | 000,067,156 | —- | C] () – C:\windows\Huawei ModemsUninstall.exe
[2011/10/14 11:06:43 | 000,010,240 | —- | C] () – C:\windows\System32\drivers\mdvrmng.sys
[2011/08/20 00:52:46 | 000,023,128 | —- | C] () – C:\windows\hpqins15.dat
[2011/07/03 20:40:27 | 000,202,283 | —- | C] () – C:\windows\hpoins18.dat
[2011/07/03 20:40:27 | 000,005,355 | —- | C] () – C:\windows\hpomdl18.dat
[2011/06/25 16:30:02 | 000,202,516 | —- | C] () – C:\windows\hpoins18.dat.temp
[2011/06/25 16:30:02 | 000,005,355 | —- | C] () – C:\windows\hpomdl18.dat.temp
[2011/06/04 20:34:36 | 000,000,376 | —- | C] () – C:\windows\ODBC.INI
[2011/01/19 08:42:30 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/01/19 08:07:17 | 000,000,000 | —- | C] () – C:\windows\nsreg.dat
[2011/01/17 11:01:21 | 000,120,688 | —- | C] () – C:\windows\Wiainst.exe
[2011/01/17 11:00:36 | 000,552,960 | —- | C] () – C:\windows\System32\SnMinDrv.dll
[2011/01/17 11:00:36 | 000,154,112 | —- | C] () – C:\windows\System32\SNWIAUI.dll
[2011/01/17 11:00:36 | 000,135,168 | —- | C] () – C:\windows\System32\SnImgFlt.dll
[2011/01/17 11:00:36 | 000,094,208 | —- | C] () – C:\windows\System32\SnErHdlr.dll
[2011/01/17 11:00:16 | 000,484,656 | —- | C] () – C:\windows\ssndii.exe
[2011/01/17 10:59:30 | 000,259,888 | —- | C] () – C:\windows\SUPDRun.exe
[2011/01/17 10:59:30 | 000,151,552 | —- | C] () – C:\windows\System32\spd__ci.exe
[2011/01/17 10:59:29 | 000,283,136 | —- | C] () – C:\windows\System32\DscPnt.dll
[2011/01/17 10:59:29 | 000,026,624 | —- | C] () – C:\windows\System32\spd__l.dll
[2010/09/01 11:06:37 | 000,001,064 | —- | C] () – C:\windows\HotFixList.ini
[2010/09/01 10:49:40 | 000,006,656 | —- | C] () – C:\windows\System32\bcmwlrc.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:B63300D1
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:D1B5B4F1
< End of report >
OTL by OldTimer - Version 3.2.40.0 Folder = C:\Users\Christina\Downloads
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1013.30 Mb Total Physical Memory | 312.57 Mb Available Physical Memory | 30.85% Memory free
1.99 Gb Paging File | 1.24 Gb Available in Paging File | 62.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 88.00 Gb Total Space | 59.92 Gb Free Space | 68.10% Space Free | Partition Type: NTFS
Drive D: | 130.35 Gb Total Space | 70.37 Gb Free Space | 53.98% Space Free | Partition Type: NTFS
Computer Name: CHRISSAMSUNG | User Name: Christina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Christina\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe (SAMSUNG Electronics)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files\Online Armor\OAReg.exe (Emsi Software GmbH)
PRC - C:\Program Files\Online Armor\oacat.exe (Emsi Software GmbH)
PRC - C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe (SRS Labs, Inc.)
PRC - C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe (Samsung Electronics)
PRC - C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (SEC)
PRC - C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\PLAY ONLINE\AssistantServices.exe ()
PRC - C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\Samsung\Movie Color Enhancer\WinCRT.dll ()
MOD - C:\Program Files\Samsung\Samsung Recovery Solution 5\Resdll.dll ()
MOD - C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll ()
========== Win32 Services (SafeList) ==========
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe File not found
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TeamViewer6) – C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (SvcOnlineArmor) – C:\Program Files\Online Armor\oasrv.exe (Emsi Software GmbH)
SRV - (OAcat) – C:\Program Files\Online Armor\oacat.exe (Emsi Software GmbH)
SRV - (BecHelperService) – C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (Samsung UPD Service) – C:\Windows\System32\SUPDSvc.exe (Samsung Electronics CO., LTD.)
SRV - (UI Assistant Service) – C:\Program Files\PLAY ONLINE\AssistantServices.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (catchme) – C:\Users\CHRIST~1\AppData\Local\Temp\catchme.sys File not found
DRV - (oahlpXX) – C:\Windows\System32\drivers\oahlp32.sys ()
DRV - (OADevice) – C:\Windows\System32\drivers\OADriver.sys ()
DRV - (OAmon) – C:\Windows\System32\drivers\OAmon.sys (Emsisoft)
DRV - (mdvrmng) – C:\Windows\System32\drivers\mdvrmng.sys ()
DRV - (ewusbmbb) – C:\Windows\System32\drivers\ewusbwwan.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_hwusbdev) – C:\Windows\System32\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (huawei_enumerator) – C:\Windows\System32\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_usbenumfilter) – C:\Windows\System32\drivers\ew_usbenumfilter.sys (Huawei Technologies Co., Ltd.)
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (rtport) – C:\Windows\System32\drivers\rtport.sys (Windows ® 2003 DDK 3790 provider)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 65 4E 19 3B 02 22 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll File not found
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Christina\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/11 23:37:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/04/23 21:15:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/24 00:49:32 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/11 23:37:25 | 000,000,000 | —D | M]
[2011/10/04 01:13:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Christina\AppData\Roaming\Mozilla\Extensions
[2012/04/23 21:15:10 | 000,000,000 | —D | M] (No name found) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions
[2012/04/11 23:40:38 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/04/11 23:40:37 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]
[2012/04/23 21:15:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/04/23 21:15:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\distribution\extensions
[2012/04/18 04:07:26 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/04/11 18:32:03 | 000,003,747 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/04/18 04:06:17 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/18 04:06:17 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://search.avg.com/?d=4e4480f1&v;=7….q={searchTerms}
CHR - default_search_provider: suggest_url = http://suggestqueries.google.com/complete/…q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Christina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Users\Christina\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: SiteAdvisor = C:\Users\Christina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\
O1 HOSTS File: ([2012/04/23 17:02:51 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (W2PBrowser Class) - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Online Armor\oaui.exe (Emsi Software GmbH)
O4 - Startup: C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.3.0)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CA189E4A-4A04-4742-880D-62407F0217CC}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D82A697F-63A7-4A2B-9CD7-D1CBBF0B567D}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-mfe-ipt - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsi Software GmbH)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/04/24 19:35:38 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{AC5DCCF2-6D30-46B1-A8F8-4A40E666D9FD}
[2012/04/24 19:35:26 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5BBF0D47-40EF-44CF-9A91-8A409E9F4098}
[2012/04/24 11:47:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{AEE52324-1E24-4D1E-9D60-E65CA43007BC}
[2012/04/24 11:47:04 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{39ED5D2F-D1FE-4688-8E91-FB477351C801}
[2012/04/24 10:34:21 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F7EF0085-D988-4BB0-9B6A-E65877A5FF3F}
[2012/04/24 10:34:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{D6945D0A-CEAE-475F-9232-D4A246E9D64B}
[2012/04/24 03:10:55 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{62B7DC70-8BD7-43E8-8F54-4E3AC10E7FD5}
[2012/04/24 03:10:38 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{69F4A9D3-FB95-479E-BF28-8F127E71C17E}
[2012/04/24 03:05:36 | 000,000,000 | R-SD | C] – C:\Users\Christina\Documents\McAfee Vaults
[2012/04/24 02:49:08 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{11AE4FA2-5961-4B6A-861B-FC9428679320}
[2012/04/24 02:48:47 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{05837DFF-C69D-40CF-8EB8-B80C8FD8227F}
[2012/04/24 02:19:55 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\OnlineArmor
[2012/04/24 02:19:55 | 000,000,000 | —D | C] – C:\ProgramData\OnlineArmor
[2012/04/24 02:17:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Armor
[2012/04/24 02:17:01 | 000,025,192 | —- | C] (Emsisoft) – C:\windows\System32\drivers\OAmon.sys
[2012/04/24 02:16:50 | 000,000,000 | —D | C] – C:\Program Files\Online Armor
[2012/04/24 02:07:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{67B86495-09C0-4D56-9122-D346217C6D15}
[2012/04/24 02:07:25 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2B1C6F43-6C1B-4BB1-9648-75CCC520B237}
[2012/04/24 01:56:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{817A36E0-5C87-4390-8BFC-A195B140E7E5}
[2012/04/24 01:56:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{7B0867E3-271F-491A-8EE3-6C703F84591C}
[2012/04/24 01:40:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{AB19881D-AE5D-4E25-8C08-1A14E631CAC0}
[2012/04/24 01:40:25 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{9AF1068E-65E6-455D-A5F9-732EEB637530}
[2012/04/24 01:07:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{84804CA1-E889-462B-805E-326AA920561D}
[2012/04/24 01:07:00 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F08A658D-F235-49DC-AA6C-94F348BAB383}
[2012/04/24 00:50:05 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/04/24 00:49:32 | 000,637,848 | —- | C] (Oracle Corporation) – C:\windows\System32\npdeployJava1.dll
[2012/04/24 00:49:32 | 000,224,136 | —- | C] (Oracle Corporation) – C:\windows\System32\javaws.exe
[2012/04/24 00:49:32 | 000,173,960 | —- | C] (Oracle Corporation) – C:\windows\System32\javaw.exe
[2012/04/24 00:49:32 | 000,173,960 | —- | C] (Oracle Corporation) – C:\windows\System32\java.exe
[2012/04/23 23:55:02 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{CB4FE251-26EE-4EE9-8FC5-AD14900F962C}
[2012/04/23 23:54:43 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{99FA0E2B-F868-498E-9B5B-042774EE8013}
[2012/04/23 21:19:30 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{C52E985A-405B-4AC2-AAE3-FF8304F2DE3F}
[2012/04/23 21:19:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{68375F71-2413-428B-9BD5-DAA65E06FF1D}
[2012/04/23 21:15:02 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/04/23 21:15:02 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2012/04/23 17:14:11 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{E5FC0E25-F14E-48FC-A003-874F022E1698}
[2012/04/23 17:13:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{486161F1-98FF-43C4-A668-6EE23466B845}
[2012/04/23 17:09:10 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/04/23 17:09:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\temp
[2012/04/23 16:05:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0C258FC4-16B9-415A-BB57-31CD0F30F657}
[2012/04/23 16:05:34 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{320BC3A4-397E-4005-8381-3B8ADD6543C8}
[2012/04/23 13:11:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2F869C4D-524F-4759-A2A1-531068A179B6}
[2012/04/23 12:58:05 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{39E49110-86E0-421C-869A-40D48463DF44}
[2012/04/23 12:57:47 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{A6EA1502-635B-4A0B-AC0B-12CBB6E13A13}
[2012/04/22 20:12:44 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{9163A833-59B4-43CB-9F12-9C4AED32AA82}
[2012/04/22 20:12:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0B100FCF-19D4-4871-B7AF-EF172CA7F52D}
[2012/04/22 16:28:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0B739743-C1F4-4FF4-BB0F-B213725C5B9F}
[2012/04/22 16:28:04 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{54820ACA-EF1C-4BB0-A299-0C925519D435}
[2012/04/22 12:13:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{DF13114C-5A3B-4441-A027-39C57758E653}
[2012/04/22 12:12:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B98FBA63-DE18-49EF-9DA7-9BAB94561AAF}
[2012/04/22 11:54:22 | 000,000,000 | —D | C] – C:\Reg_Backup
[2012/04/22 11:54:18 | 000,181,064 | —- | C] (Sysinternals) – C:\windows\PSEXESVC.EXE
[2012/04/22 11:50:42 | 000,000,000 | —D | C] – C:\Tweaking.com_Windows_Repair_Logs
[2012/04/22 11:50:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
[2012/04/22 11:50:02 | 000,000,000 | —D | C] – C:\Program Files\Tweaking.com
[2012/04/22 10:58:17 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{7DCBE4D7-9A7A-4217-87C2-06C9FEF79DEF}
[2012/04/22 00:32:11 | 000,000,000 | —D | C] – C:\Users\Christina\Desktop\Play
[2012/04/21 23:32:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2012/04/21 23:23:34 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{333DF259-F04E-40A8-9ABB-9644FA6AEC50}
[2012/04/21 23:23:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{1B898735-5C13-4BDD-986A-69C48B5913E1}
[2012/04/21 22:57:07 | 000,000,000 | —D | C] – C:\Users\Christina\Desktop\lucid
[2012/04/21 22:28:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6892558C-DC81-470A-85BE-2CCB18F6848A}
[2012/04/21 22:27:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{43456941-9D2C-4930-9C5D-C7EF74544F22}
[2012/04/21 22:24:26 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6C7EEEC2-46C5-4033-93E8-5E78917F7BA1}
[2012/04/21 22:24:13 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6DA76A72-FE63-4581-B6FA-128F659A8FF7}
[2012/04/21 21:10:21 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{18AECC58-EBBE-4908-A03B-353385D96D8C}
[2012/04/21 21:09:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2A7B61D3-90AC-44AE-AFA2-87A5B611FB36}
[2012/04/21 20:20:25 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BED26244-67A8-4E24-8B7A-694F692FE217}
[2012/04/21 20:20:13 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{7EF4FEFF-4195-4B90-B704-A4E234D13572}
[2012/04/21 19:22:00 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8EBDDF4A-4447-4615-AA92-F4500A80104B}
[2012/04/21 19:21:32 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BC3F252D-6AF7-48DA-931B-684B6A8003E1}
[2012/04/21 19:06:54 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{902EF019-219E-469A-AAAC-BEBF7FD6EAC0}
[2012/04/21 19:06:32 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F4EAC8DD-3E7B-4214-93BB-A27CA4188D24}
[2012/04/21 10:22:27 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{975ADCD7-0732-4DA9-809A-6EE3F83DCF0D}
[2012/04/21 10:21:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{82B05528-BF3B-452E-9D0C-7D6D64575259}
[2012/04/20 10:28:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B4DFE1EE-8C93-417E-830A-A2688023CD71}
[2012/04/20 10:27:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0EC2CC3D-7F16-4E0F-90CB-47C1CD875FD1}
[2012/04/19 22:34:00 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{E507A3E1-A6ED-44D0-9596-51938B34B725}
[2012/04/19 22:33:34 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{36B4D4B9-2C41-4FAB-8A6C-C30BCDB366BC}
[2012/04/19 15:37:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{AB98BAE1-A861-4533-84D5-42955D09F691}
[2012/04/19 15:37:26 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{EE31A02C-91BB-4D10-953D-B9DAD1829B49}
[2012/04/18 22:39:05 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{63CBD3F4-81C8-457C-A409-4BF9820AEBA0}
[2012/04/18 22:38:21 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{07D573A2-C17C-4A2E-A407-2FBBE7275332}
[2012/04/18 20:37:36 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F1F2B18B-8211-472B-B281-206711E4F087}
[2012/04/18 20:37:20 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{A6F03645-0AF1-453A-B1DE-F19DF91B51BF}
[2012/04/18 13:35:39 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{C385A2F8-6574-415B-8687-4A5447CAF2F4}
[2012/04/18 13:35:07 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6E81434B-B1DF-4C8E-ABE9-39DC724B7289}
[2012/04/18 08:34:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2F0B1D53-0213-4C14-A34A-CDC89784EC01}
[2012/04/18 08:34:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8B722896-69DA-454C-A0F9-8B6BD59DE768}
[2012/04/17 21:23:21 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/04/17 19:57:35 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B8212108-20A6-45AA-97AE-3CCB797CC5D1}
[2012/04/17 19:57:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{661A33A4-0C5E-44A4-AEDB-4ECBC3C62EB9}
[2012/04/17 19:28:37 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\Malwarebytes
[2012/04/17 19:28:02 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/04/17 19:04:58 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{E5C485DF-08A9-4FE8-A53D-0BDC91F116B3}
[2012/04/17 19:04:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{3A278787-D700-401C-9966-9D34692F875A}
[2012/04/17 19:00:47 | 000,000,000 | —D | C] – C:\found.000
[2012/04/17 12:19:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F35E964A-6FCD-4353-97ED-CA912EB1EB65}
[2012/04/17 12:19:16 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{35592A29-3846-48BF-AF27-211B2EAB1B42}
[2012/04/17 11:30:44 | 000,000,000 | —D | C] – C:\_OTL
[2012/04/17 11:01:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B32618D4-D46F-437C-B795-815FDE4A6B35}
[2012/04/17 11:01:29 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{50120FB6-C762-462B-A028-D6399FF4C31A}
[2012/04/17 00:48:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/04/17 00:48:08 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012/04/16 23:32:49 | 000,000,000 | —D | C] – C:\Users\Christina\Desktop\whatthetech navigation
[2012/04/16 19:53:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{353ABB58-7BD4-4459-A2EB-C412D6EC8E18}
[2012/04/16 19:52:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{44ACE206-2C0F-4A88-9186-E39AADDA6FE7}
[2012/04/14 20:59:07 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5347E02E-61C4-4A34-82A7-545D2641B3F3}
[2012/04/14 20:58:39 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{022A2F2D-9B12-4D06-B669-A9642629A139}
[2012/04/14 11:21:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{56C1D28E-2276-4DB1-9239-EA48F9749018}
[2012/04/14 11:20:55 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{302F11B4-7742-4911-AAB8-C4243746E438}
[2012/04/12 13:10:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{DEB12ACD-A165-40D6-B120-B90FF89CF18F}
[2012/04/12 13:09:53 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8BEAEFC4-BC24-4E9C-A4BA-925BFC01E83B}
[2012/04/12 10:42:36 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{4E38B6BD-FC8A-41F2-92B3-321A33528DBC}
[2012/04/12 10:42:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{ADDEEC85-BDAB-4677-ADAC-96F49FBBEC9A}
[2012/04/12 01:26:11 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntkrnlpa.exe
[2012/04/12 01:26:07 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntoskrnl.exe
[2012/04/12 01:13:14 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{53F44410-0F49-4159-A9F7-59CC9BFFC840}
[2012/04/12 01:00:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{366BC4BB-E3D2-4779-8C3E-EF1ED4E083D1}
[2012/04/12 00:59:22 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{129F8187-BA00-4F56-9B40-E66F1178AA51}
[2012/04/11 23:15:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{CB62930E-E8B8-4025-A65D-E322529139F8}
[2012/04/11 19:53:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2012/04/11 18:33:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/04/11 18:32:29 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2012/04/11 18:32:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2012/04/11 18:32:07 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2012/04/11 18:26:16 | 000,000,000 | —D | C] – C:\$AVG
[2012/04/11 16:45:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SpeedyPC Software
[2012/04/11 16:45:07 | 000,000,000 | —D | C] – C:\Program Files\SpeedyPC Software
[2012/04/10 21:42:54 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{866CAD26-2E62-4941-BDEC-0923B602D05F}
[2012/04/09 02:12:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\SpeedyPC Software
[2012/04/09 02:12:02 | 000,000,000 | —D | C] – C:\ProgramData\SpeedyPC Software
[2012/04/08 23:19:57 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{76C924EA-6DD3-4D30-8A0B-48AE4858BCD8}
[2012/04/03 21:36:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\WinZip
[2012/04/03 20:12:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{33EE76A0-7DA3-43AD-AA28-3D14011E35FA}
[2012/04/03 20:11:27 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{4F619680-21D9-4743-AA23-61D6AD6AFDFD}
[2012/04/03 19:37:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6134C62C-6DBF-4C38-B968-D8951F6892BF}
[2012/04/03 19:20:22 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BC049C4B-D462-49AA-8DBC-5E59C2640EAD}
[2012/04/03 19:19:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{78D44058-B568-47E9-A492-E82E66134CEA}
[2012/03/29 20:41:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{92341BC9-2B8A-4130-AF99-C38DF4ACE36A}
[2012/03/29 19:37:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{75351EA8-4AD7-4C50-89C7-E4901675B152}
[2012/03/26 23:53:31 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{54C4A35C-A82D-4C15-A4B6-0476397D1B3C}
[2012/03/26 23:53:04 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{47D1C48E-CA92-4A51-A53B-A29A2D6F0B0B}
[2012/03/26 11:52:08 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5A15AD8D-6405-440F-801B-97CD9EC05AA2}
[2012/03/26 11:51:43 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{924EF17F-2F86-4D2B-BABC-EA55463BA947}
========== Files - Modified Within 30 Days ==========
[2012/04/24 19:39:45 | 000,010,592 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/24 19:39:45 | 000,010,592 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/24 19:34:51 | 000,000,888 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/24 19:34:14 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/04/24 19:34:09 | 1062,518,784 | -HS- | M] () – C:\hiberfil.sys
[2012/04/24 12:22:05 | 000,000,892 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/24 04:19:00 | 000,103,784 | —- | M] () – C:\Users\Christina\GoToAssistDownloadHelper.exe
[2012/04/24 00:49:05 | 000,637,848 | —- | M] (Oracle Corporation) – C:\windows\System32\npdeployJava1.dll
[2012/04/24 00:49:05 | 000,224,136 | —- | M] (Oracle Corporation) – C:\windows\System32\javaws.exe
[2012/04/24 00:49:05 | 000,173,960 | —- | M] (Oracle Corporation) – C:\windows\System32\javaw.exe
[2012/04/24 00:49:05 | 000,173,960 | —- | M] (Oracle Corporation) – C:\windows\System32\java.exe
[2012/04/24 00:49:04 | 000,567,696 | —- | M] (Oracle Corporation) – C:\windows\System32\deployJava1.dll
[2012/04/23 21:15:03 | 000,001,011 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/23 17:02:51 | 000,000,027 | —- | M] () – C:\windows\System32\drivers\etc\hosts
[2012/04/23 14:20:38 | 000,001,173 | —- | M] () – C:\Users\Christina\Desktop\ComboFix - Shortcut.lnk
[2012/04/23 13:46:21 | 000,014,519 | —- | M] () – C:\Combofix.text
[2012/04/22 20:16:06 | 000,649,584 | —- | M] () – C:\windows\System32\perfh009.dat
[2012/04/22 20:16:06 | 000,120,746 | —- | M] () – C:\windows\System32\perfc009.dat
[2012/04/22 12:06:51 | 000,181,064 | —- | M] (Sysinternals) – C:\windows\PSEXESVC.EXE
[2012/04/22 12:06:51 | 000,000,042 | —- | M] () – C:\repairs_running.dat
[2012/04/17 00:48:37 | 000,001,078 | —- | M] () – C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/04/16 14:54:34 | 000,002,290 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/04/11 01:35:17 | 000,392,875 | —- | M] () – C:\Users\Christina\Desktop\fru_7steps.pdf
========== Files Created - No Company Name ==========
[2012/04/24 04:18:59 | 000,103,784 | —- | C] () – C:\Users\Christina\GoToAssistDownloadHelper.exe
[2012/04/24 02:17:01 | 000,205,864 | —- | C] () – C:\windows\System32\drivers\OADriver.sys
[2012/04/24 02:17:01 | 000,039,048 | —- | C] () – C:\windows\System32\drivers\oahlp32.sys
[2012/04/23 14:20:38 | 000,001,173 | —- | C] () – C:\Users\Christina\Desktop\ComboFix - Shortcut.lnk
[2012/04/23 13:46:20 | 000,014,519 | —- | C] () – C:\Combofix.text
[2012/04/22 12:01:08 | 000,000,042 | —- | C] () – C:\repairs_running.dat
[2012/04/17 00:48:37 | 000,001,078 | —- | C] () – C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/04/11 01:35:17 | 000,392,875 | —- | C] () – C:\Users\Christina\Desktop\fru_7steps.pdf
[2011/10/14 11:06:49 | 000,067,156 | —- | C] () – C:\windows\Huawei ModemsUninstall.exe
[2011/10/14 11:06:43 | 000,010,240 | —- | C] () – C:\windows\System32\drivers\mdvrmng.sys
[2011/08/20 00:52:46 | 000,023,128 | —- | C] () – C:\windows\hpqins15.dat
[2011/07/03 20:40:27 | 000,202,283 | —- | C] () – C:\windows\hpoins18.dat
[2011/07/03 20:40:27 | 000,005,355 | —- | C] () – C:\windows\hpomdl18.dat
[2011/06/25 16:30:02 | 000,202,516 | —- | C] () – C:\windows\hpoins18.dat.temp
[2011/06/25 16:30:02 | 000,005,355 | —- | C] () – C:\windows\hpomdl18.dat.temp
[2011/06/04 20:34:36 | 000,000,376 | —- | C] () – C:\windows\ODBC.INI
[2011/01/19 08:42:30 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/01/19 08:07:17 | 000,000,000 | —- | C] () – C:\windows\nsreg.dat
[2011/01/17 11:01:21 | 000,120,688 | —- | C] () – C:\windows\Wiainst.exe
[2011/01/17 11:00:36 | 000,552,960 | —- | C] () – C:\windows\System32\SnMinDrv.dll
[2011/01/17 11:00:36 | 000,154,112 | —- | C] () – C:\windows\System32\SNWIAUI.dll
[2011/01/17 11:00:36 | 000,135,168 | —- | C] () – C:\windows\System32\SnImgFlt.dll
[2011/01/17 11:00:36 | 000,094,208 | —- | C] () – C:\windows\System32\SnErHdlr.dll
[2011/01/17 11:00:16 | 000,484,656 | —- | C] () – C:\windows\ssndii.exe
[2011/01/17 10:59:30 | 000,259,888 | —- | C] () – C:\windows\SUPDRun.exe
[2011/01/17 10:59:30 | 000,151,552 | —- | C] () – C:\windows\System32\spd__ci.exe
[2011/01/17 10:59:29 | 000,283,136 | —- | C] () – C:\windows\System32\DscPnt.dll
[2011/01/17 10:59:29 | 000,026,624 | —- | C] () – C:\windows\System32\spd__l.dll
[2010/09/01 11:06:37 | 000,001,064 | —- | C] () – C:\windows\HotFixList.ini
[2010/09/01 10:49:40 | 000,006,656 | —- | C] () – C:\windows\System32\bcmwlrc.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:B63300D1
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:D1B5B4F1
< End of report >
jeffce
Hi,
So the Ask Toolbar is only in Firefox? Be sure to update to Internet Explorer 9 as well. You can find that here
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
So the Ask Toolbar is only in Firefox? Be sure to update to Internet Explorer 9 as well. You can find that here
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
- Right-click and Run as Administrator SystemLook.exe to run it.
- Copy the content of the following codebox into the main textfield:
:filefind ask
- Click the Look button to start the scan.
- When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Chris1701
SystemLook 30.07.11 by jpshortstuff
Log created at 21:14 on 24/04/2012 by Christina
Administrator - Elevation successful
No Context: CODE
========== filefind ==========
Searching for "ask"
No files found.
-= EOF =-
In anger I had uninstalled Ask from programs but it survived and stayed in taskbars.
jeffce
Hi,
In Firefox click on Tools >> Add-ons >> if that toolbar is still there remove it.
In Chrome click on the "Wrench" >> Tools >> Extensions >> if it is still there as well remove it.
What browsers are you still seeing it in? It is not showing in the logs?I had uninstalled Ask from programs but it survived and stayed in taskbars.
In Firefox click on Tools >> Add-ons >> if that toolbar is still there remove it.
In Chrome click on the "Wrench" >> Tools >> Extensions >> if it is still there as well remove it.
Chris1701
It is in Mozila F
It says Ask.com Search Engine- Better Web Search
Below: ASK Search
Well, I suppose this should not disturb me so much.
Chris1701
I shall now start to work through your final instructions.

jeffce
Sounds good. Let me know how it works out. 
Chris1701
Hi Jeff
It works great. Thank you very much, it was a pleasure to work under your guidance. Please let me know if this terminates the matter.
I shall be grateful for your indication which of the programs, if at all, I could use for cleaning my registry and repairing in the future. I know of some contraindications but not all of them were warned against instructing repair. I acknowledge you final advice and shall implement some of that.
Chris
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI