computerwannabe
Topic Starter
I have been having problems with the internet being slow to load pages for about a week. I have run a kaspersky scan, an mbam scan, a bitdefender quickscan (I have never had that program find anything, does it really work?) and an ESET scan, (one thing was found by eset and fixed, but the problem really didn't go away). The challenge is that it isn't consistent. It comes and goes throughout the day. Right now it seems great, but yesterday it was slow, and saturday it was a nightmare. I am assuming I have some kind of infection that isn't being picked up, as when it hangs, it says it is waiting for a different site than the one I am on (usually an ad site) before it goes to the actual site. Usually, it is not a site that has an ad on the page I am visiting. That is why I ran Mbam, because I thought I had picked up adware, but it didn't find anything.
Anyway, here are the results:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:13:18 AM, on 4/30/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\jtmeserole\Downloads\HijackThis(1).exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\6.2.0.9\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\6.2.0.9\IPS\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll (file missing)
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MI1933~1\Office14\URLREDIR.DLL
O2 - BHO: Norton Safety Minder BHO - {B8E07826-0971-4f16-B133-047B88034E89} - C:\Program Files\Norton Online\AddOns\Norton Safety Minder\Engine\2.3.0.18\coIEPlg.dll
O2 - BHO: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.2.0.9\coIEPlg.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "c:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windstream Service Agent.exe] "C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe" /AUTORUN
O4 - HKLM\..\Run: [DiagnosticTools.exe] "C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe" /AUTORUN
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-21-3496540520-3972749145-994392144-1001\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'safe kids')
O4 - HKUS\S-1-5-21-3496540520-3972749145-994392144-1001\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW,SYSTRAY (User 'safe kids')
O4 - HKUS\S-1-5-21-3496540520-3972749145-994392144-1001\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (User 'safe kids')
O4 - HKUS\S-1-5-21-3496540520-3972749145-994392144-1001\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User 'safe kids')
O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~1\MI1933~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} (BitDefender QuickScan Control) - http://quickscan.bitdefender.com/qsax/qsax.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/…can8/oscan8.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HsdService - Windstream - C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
O23 - Service: Norton Online (NOF) - Symantec Corporation - C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
O23 - Service: Norton PC Checkup Application Launcher - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
O23 - Service: ServicepointService - Radialpoint SafeCare Inc. - C:\Program Files\Windstream\Service Agent\ServicepointService.exe
O23 - Service: Application Virtualization Client (sftlist) - Unknown owner - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (file missing)
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
–
End of file - 12435 bytes
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 8:59:36.36 on Mon 04/30/2012
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.932 [GMT -5:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe
C:\Program Files\Windstream\Service Agent\ServicepointService.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\system32\rundll32.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
C:\Windows\Explorer.EXE
C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe
C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Users\safe kids\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LULnchr.exe
C:\Users\safe kids\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LogitechUpdate.exe
C:\Program Files\Chocolatier - Decadence by Design\chocolatier-decadence.exe
C:\Windows\helppane.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\system32\NOTEPAD.EXE
c:\Users\jtmeserole\Downloads\OTL.exe
C:\Windows\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\jtmeserole\Downloads\dds(1).scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\6.2.0.9\coIEPlg.dll
BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\6.2.0.9\ips\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\wi371a~1\datamngr\toolbar\searchqudtx.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mi1933~1\office14\URLREDIR.DLL
BHO: Norton Safety Minder BHO: {b8e07826-0971-4f16-b133-047b88034e89} - c:\program files\norton online\addons\norton safety minder\engine\2.3.0.18\coIEPlg.dll
BHO: Free Download Manager: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\6.2.0.9\coIEPlg.dll
TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\wi371a~1\datamngr\toolbar\searchqudtx.dll
TB: {C2DB4FE6-8409-45CE-8010-189A7B5CCE86} - No File
TB: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Free Download Manager] "c:\program files\free download manager\fdm.exe" -autorun
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [UpdatePDIRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\cyberlink dvd suite deluxe\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\cyberlink dvd suite deluxe" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Windstream Service Agent.exe] "c:\program files\windstream\service agent\Windstream Service Agent.exe" /AUTORUN
mRun: [DiagnosticTools.exe] "c:\program files\windstream\diagnostic tools\DiagnosticTools.exe" /AUTORUN
StartupFolder: c:\users\jtmese~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office14\ONENOTEM.EXE
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\mi1933~1\office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\mi1933~1\office14\ONBttnIE.dll/105
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
LSP: c:\windows\system32\wpclsp.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jtmese~1\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\
FF - prefs.js: browser.search.defaulturl - Bing
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.ldsscripturemastery.net/
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid;=113&systemid;=406&sr;=0&q;=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\progra~1\mi1933~1\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\mi1933~1\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\musicnotes\npmusicn.dll
FF - plugin: c:\program files\musicnotes\NPSibelius.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\program files\windstream\service agent\nprpspa.dll
FF - plugin: c:\users\jtmeserole\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\jtmeserole\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\extensions\{000f1ea4-5e08-4564-a29b-29076f63a37a}\plugins\npsoe.dll
FF - plugin: c:\users\jtmeserole\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
.
—- FIREFOX POLICIES —-
FF - user.js: extentions.y2layers.installId - 1132a82e-f3dd-43a0-b9bf-af81c9d2c769
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0602000.009\symds.sys [2012-4-23 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0602000.009\symefa.sys [2012-4-23 905336]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.0.1.2\definitions\bashdefs\20120413.001\BHDrvx86.sys [2012-4-19 821880]
R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\n360\0602000.009\ccsetx86.sys [2012-4-23 132744]
R1 ccSet_NOF;Norton Online Settings Manager;c:\windows\system32\drivers\nof\0203000.007\ccsetx86.sys [2012-2-9 132744]
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\rsdrv.sys [2011-9-7 22312]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.0.1.2\definitions\ipsdefs\20120427.001\IDSvix86.sys [2012-4-27 368248]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0602000.009\ironx86.sys [2012-4-23 149624]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0602000.009\symtdiv.sys [2012-4-23 345208]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 N360;Norton 360;c:\program files\norton 360\engine\6.2.0.9\ccsvchst.exe [2012-4-23 138232]
R2 NOF;Norton Online;c:\program files\norton online\engine\2.3.0.7\ccsvchst.exe [2012-2-9 138248]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\norton pc checkup\engine\2.0.12.27\SymcPCCULaunchSvc.exe [2011-9-30 135608]
R2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\norton pc checkup\engine\2.0.12.27\ccSvcHst.exe [2011-9-30 126392]
R2 ServicepointService;ServicepointService;c:\program files\windstream\service agent\ServicepointService.exe [2012-1-17 10315064]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-2-4 106104]
R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2011-10-1 579944]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2011-10-1 194408]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2011-10-1 19304]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\microsoft application virtualization client\sftvsa.exe [2011-10-1 219496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2012-1-4 822624]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-10 136176]
S2 HsdService;HsdService;c:\program files\windstream\diagnostic tools\HsdService.exe [2012-1-17 1393976]
S2 sftlist;Application Virtualization Client;"c:\program files\microsoft application virtualization client\sftlist.exe" –> c:\program files\microsoft application virtualization client\sftlist.exe [?]
S2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-8-19 450848]
S3 dsiarhwprog;dsiarhwprog;c:\windows\system32\drivers\dsiarhwprog.sys [2011-8-14 29184]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2011-1-26 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-10 136176]
S3 MHIKEY10;MHIKEY10;c:\windows\system32\drivers\MHIKEY10.sys [2008-5-27 50560]
S3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2011-10-1 21864]
S3 SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A};Symantec Redirector - Norton Safety Minder;c:\windows\system32\drivers\nsm\0203000.012\symrdr.sys [2012-3-15 197624]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-04-23 23:02:47 905336 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symefa.sys
2012-04-23 23:02:47 574072 —-a-w- c:\windows\system32\drivers\n360\0602000.009\srtsp.sys
2012-04-23 23:02:47 345208 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symtdiv.sys
2012-04-23 23:02:47 340088 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symds.sys
2012-04-23 23:02:47 32888 —-a-w- c:\windows\system32\drivers\n360\0602000.009\srtspx.sys
2012-04-23 23:02:47 318584 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symnets.sys
2012-04-23 23:02:46 149624 —-a-r- c:\windows\system32\drivers\n360\0602000.009\ironx86.sys
2012-04-23 23:02:46 132744 —-a-r- c:\windows\system32\drivers\n360\0602000.009\ccsetx86.sys
2012-04-23 23:02:35 4782 —-a-w- c:\windows\system32\drivers\n360\0602000.009\symvtcer.dat
2012-04-23 23:02:35 ——– d—–w- c:\windows\system32\drivers\n360\0602000.009
2012-04-11 08:14:19 5120 —-a-w- c:\windows\system32\wmi.dll
2012-04-11 08:14:19 172032 —-a-w- c:\windows\system32\wintrust.dll
2012-04-11 08:14:19 157696 —-a-w- c:\windows\system32\imagehlp.dll
2012-04-11 08:14:19 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-11 08:13:51 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-04-11 08:13:50 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-11 06:39:16 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2012-04-07 14:36:55 ——– d—–w- c:\program files\Celestia
.
==================== Find3M ====================
.
2012-03-26 15:22:17 35113704 —-a-w- c:\program files\common files\directx_9c_redist.exe
2012-03-01 22:53:35 1576 —-a-w- c:\windows\system32\DeletedKey21.reg
2012-03-01 22:51:30 348722 —-a-w- c:\windows\system32\DeletedKey20.reg
2012-03-01 22:50:15 83578 —-a-w- c:\windows\system32\DeletedKey19.reg
2012-03-01 21:54:12 565410 —-a-w- c:\windows\system32\uninstallkey01.reg
2012-03-01 21:51:28 318 —-a-w- c:\windows\system32\DeletedKey18.reg
2012-03-01 21:51:03 318 —-a-w- c:\windows\system32\DeletedKey17.reg
2012-03-01 21:50:45 318 —-a-w- c:\windows\system32\DeletedKey16.reg
2012-03-01 21:50:21 3518 —-a-w- c:\windows\system32\DeletedKey15.reg
2012-03-01 21:50:05 8856 —-a-w- c:\windows\system32\DeletedKey14.reg
2012-03-01 21:48:55 1668 —-a-w- c:\windows\system32\DeletedKey13.reg
2012-03-01 21:48:36 270 —-a-w- c:\windows\system32\DeletedKey12.reg
2012-03-01 21:48:16 732 —-a-w- c:\windows\system32\DeletedKey11.reg
2012-03-01 21:47:09 2956 —-a-w- c:\windows\system32\DeletedKey10.reg
2012-03-01 21:45:38 7152 —-a-w- c:\windows\system32\DeletedKey09.reg
2012-03-01 21:45:17 34560 —-a-w- c:\windows\system32\DeletedKey08.reg
2012-03-01 21:44:13 404 —-a-w- c:\windows\system32\DeletedKey07.reg
2012-03-01 21:43:56 404 —-a-w- c:\windows\system32\DeletedKey06.reg
2012-03-01 21:43:37 404 —-a-w- c:\windows\system32\DeletedKey05.reg
2012-03-01 21:41:28 2178 —-a-w- c:\windows\system32\DeletedKey04.reg
2012-03-01 21:40:42 13288 —-a-w- c:\windows\system32\DeletedKey03.reg
2012-03-01 21:39:57 3462 —-a-w- c:\windows\system32\DeletedKey02.reg
2012-03-01 21:10:53 1240 —-a-w- c:\windows\system32\DeletedKey01.reg
2012-02-29 15:32:50 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-28 01:18:55 1799168 —-a-w- c:\windows\system32\jscript9.dll
2012-02-28 01:11:21 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
2012-02-28 01:11:07 1127424 —-a-w- c:\windows\system32\wininet.dll
2012-02-28 01:03:16 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-02-14 17:09:44 1070352 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2012-02-14 15:45:30 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-02-14 15:45:30 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-02-13 14:12:08 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-02-13 13:47:57 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-02-13 13:44:40 1068544 —-a-w- c:\windows\system32\DWrite.dll
2012-02-02 15:16:25 2044416 —-a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 9:00:34.52 ===============
OTL logfile created on: 4/29/2012 8:45:32 PM - Run 4
OTL by OldTimer - Version 3.2.26.5 Folder = c:\Users\jtmeserole\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 1.18 Gb Available Physical Memory | 41.04% Memory free
5.95 Gb Paging File | 3.51 Gb Available in Paging File | 58.93% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.80 Gb Total Space | 152.20 Gb Free Space | 53.07% Space Free | Partition Type: NTFS
Drive D: | 11.28 Gb Total Space | 1.59 Gb Free Space | 14.08% Space Free | Partition Type: NTFS
Drive F: | 298.02 Gb Total Space | 163.62 Gb Free Space | 54.90% Space Free | Partition Type: FAT32
Computer Name: JTMESEROLE-PC | User Name: jtmeserole | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files\Norton 360\Engine\6.2.0.9\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Norton Online\Engine\2.3.0.7\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Windstream\Service Agent\Windstream Service AgentComHandler.exe (Radialpoint SafeCare Inc.)
PRC - C:\Program Files\Windstream\Service Agent\ServicepointService.exe (Radialpoint SafeCare Inc.)
PRC - C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe (Windstream)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\bfgclient\bfggameservices.exe ()
PRC - c:\Users\jtmeserole\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Users\safe kids\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LogitechUpdate.exe (Logitech, Inc.)
PRC - C:\Users\safe kids\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LULnchr.exe (Logitech, Inc.)
PRC - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe (Windstream)
PRC - C:\Program Files\Chocolatier - Decadence by Design\chocolatier-decadence.exe ()
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\HelpPane.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Norton Online\AddOns\Norton Safety Minder\Engine\2.3.0.18\wincfi39.dll ()
========== Win32 Services (SafeList) ==========
SRV - (sftlist) – File not found
SRV - (N360) – C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe (Symantec Corporation)
SRV - (Norton PC Checkup Application Launcher) – C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (NOF) – C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe (Symantec Corporation)
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (ServicepointService) – C:\Program Files\Windstream\Service Agent\ServicepointService.exe (Radialpoint SafeCare Inc.)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (UMVPFSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (PCCUJobMgr) – C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
SRV - (HsdService) – C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe (Windstream)
SRV - (GameConsoleService) – C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\Definitions\BASHDefs\20120413.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\N360\0602000.009\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\N360\0602000.009\SRTSPX.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\Definitions\IPSDefs\20120427.001\IDSvix86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\Definitions\VirusDefs\20120428.016\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\Definitions\VirusDefs\20120428.016\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\N360\0602000.009\SYMEFA.SYS (Symantec Corporation)
DRV - (SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}) – C:\Windows\System32\Drivers\NSM\0203000.012\SymRdr.SYS (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\System32\Drivers\N360\0602000.009\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\N360\0602000.009\Ironx86.SYS (Symantec Corporation)
DRV - (ccSet_N360) – C:\Windows\system32\drivers\N360\0602000.009\ccSetx86.sys (Symantec Corporation)
DRV - (ccSet_NOF) – C:\Windows\system32\drivers\NOF\0203000.007\ccSetx86.sys (Symantec Corporation)
DRV - (Sftvol) – C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (LVUVC) Logitech Webcam 250(UVC) – C:\Windows\System32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (SymDS) – C:\Windows\system32\drivers\N360\0602000.009\SYMDS.SYS (Symantec Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corporation)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (ElRawDisk) – C:\Windows\System32\drivers\rsdrv.sys (EldoS Corporation)
DRV - (nvrd32) – C:\Windows\system32\drivers\nvrd32.sys (NVIDIA Corporation)
DRV - (nvstor32) – C:\Windows\system32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (MHIKEY10) – C:\Windows\System32\drivers\MHIKEY10.sys (Generic USB smartcard reader)
DRV - (nvsmu) – C:\Windows\system32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (irsir) – C:\Windows\System32\drivers\irsir.sys (Microsoft Corporation)
DRV - (dsiarhwprog) – C:\Windows\System32\drivers\dsiarhwprog.sys (Thesycon GmbH, Germany)
DRV - (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM) – C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.ldsscripturemastery.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 98 7D 03 02 CE 6E E2 4D 9F 26 81 EE 65 AF 76 3D [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "www.google.com"
FF - prefs.js..browser.search.defaulturl: "Bing"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.ldsscripturemastery.net/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:5.0.1
FF - prefs.js..extensions.enabledItems: [removed]:2.3
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {000F1EA4-5E08-4564-A29B-29076F63A37A}:[removed]
FF - prefs.js..extensions.enabledItems: {6D5C8FC4-DE46-41bf-9092-93F0F78E9115}:2.1.0.51
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=113&systemid;=406&sr;=0&q;="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MI1933~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MI1933~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.18.9: C:\Program Files\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files\Windstream\Service Agent\nprpspa.dll (Windstream)
FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=6.2.0.88: C:\Program Files\Musicnotes\npsibelius.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll ()
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\jtmeserole\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\IPSFFPlgn\ [2012/02/29 16:11:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\coFFPlgn\ [2012/04/26 10:42:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}: C:\ProgramData\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.2.0.28\coFFFw\ [2012/04/26 10:42:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/03/28 10:30:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/19 06:38:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/09 21:25:10 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/03/28 10:30:49 | 000,000,000 | —D | M]
[2011/11/09 11:14:59 | 000,000,000 | —D | M] (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Extensions
[2012/04/25 18:38:57 | 000,000,000 | —D | M] (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions
[2011/02/19 18:48:33 | 000,000,000 | —D | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
[2010/09/27 21:35:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/04/21 18:35:30 | 000,000,000 | —D | M] (Bitdefender QuickScan) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/09/27 21:35:19 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2010/09/20 15:59:14 | 000,000,000 | —D | M] (KidZui) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2011/12/24 23:14:40 | 000,002,578 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\askcom.xml
[2011/09/07 18:07:40 | 000,001,945 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\bing-zugo.xml
[2010/12/01 18:51:50 | 000,000,927 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\conduit.xml
[2011/05/03 11:52:57 | 000,002,469 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\safesearch.xml
[2011/11/08 22:40:03 | 000,002,519 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\SearchResults.xml
[2012/01/13 17:53:52 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
[2012/02/29 16:11:43 | 000,000,000 | —D | M] (Norton Vulnerability Protection) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\IPSFFPLGN
[2012/04/26 10:42:15 | 000,000,000 | —D | M] (Norton Safety Minder) – C:\PROGRAMDATA\NORTON\{78CA3BF0-9C3B-40E1-B46D-38C877EF059A}\NSM_2.2.0.28\COFFFW
() (No name found) – C:\USERS\JTMESEROLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TKUCY2AP.DEFAULT\EXTENSIONS\{EF4E370E-D9F0-4E00-B93E-A4F274CFDD5A}.XPI
() (No name found) – C:\USERS\JTMESEROLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TKUCY2AP.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\JTMESEROLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TKUCY2AP.DEFAULT\EXTENSIONS\[removed]
[2012/03/19 06:38:43 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/09/29 16:30:47 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2011/07/13 16:52:56 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/03 06:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/07/13 16:52:58 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2010/03/31 11:09:22 | 010,437,264 | —- | M] (PDFTron Systems Inc.) – C:\Program Files\mozilla firefox\plugins\PDFNetC.dll
[2010/04/08 13:36:02 | 000,107,760 | —- | M] () – C:\Program Files\mozilla firefox\plugins\ScorchPDFWrapper.dll
[2011/08/01 23:22:34 | 000,002,226 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012/02/14 13:51:54 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/08/12 01:58:47 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml.old
[2011/11/08 22:40:03 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml
[2012/02/14 13:51:54 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/08/23 18:24:55 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\6.2.0.9\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\6.2.0.9\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Norton Safety Minder BHO) - {B8E07826-0971-4f16-B133-047B88034E89} - C:\Program Files\Norton Online\AddOns\Norton Safety Minder\Engine\2.3.0.18\coieplg.dll (Symantec Corporation)
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.2.0.9\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.2.0.9\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DiagnosticTools.exe] C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe (Windstream)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [UpdateLBPShortCut] c:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windstream Service Agent.exe] C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe (Windstream)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
O4 - Startup: C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Cabo.JPG
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Cabo.JPG
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/06/27 10:31:18 | 000,000,000 | —D | M] - F:\autorun – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: aux - wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi - wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - midimap.dll (Microsoft Corporation)
Drivers32: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32: MSVideo - vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - VfWWDM32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - lvcodec2.dll (Logitech Inc.)
Drivers32: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YUY2 - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - msyuv.dll (Microsoft Corporation)
Drivers32: wave - wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/04/20 15:26:11 | 000,000,000 | —D | C] – C:\Users\jtmeserole\Documents\OneNote Notebooks
[2012/04/11 03:16:53 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/04/11 03:16:52 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/04/11 03:16:51 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/04/11 03:16:51 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/04/11 03:16:51 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/04/11 03:16:50 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/04/11 03:13:51 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/04/11 03:13:50 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/04/07 09:37:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Celestia
[2012/04/07 09:36:55 | 000,000,000 | —D | C] – C:\Program Files\Celestia
[2012/03/26 10:22:17 | 035,113,704 | —- | C] (Microsoft Corporation) – C:\Program Files\Common Files\directx_9c_redist.exe
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\jtmeserole\Desktop\*.tmp files -> C:\Users\jtmeserole\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/04/29 20:42:39 | 000,003,616 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/29 20:42:39 | 000,003,616 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/29 18:55:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/29 18:00:00 | 000,000,452 | —- | M] () – C:\Windows\tasks\ParetoLogic Registration.job
[2012/04/29 11:55:00 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/26 10:48:05 | 000,604,708 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/04/26 10:48:05 | 000,104,150 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/04/26 10:41:54 | 000,065,536 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2012/04/26 10:41:34 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/04/25 13:48:41 | 000,002,045 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2012/04/25 13:48:11 | 002,188,162 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\Cat.DB
[2012/04/25 13:47:32 | 000,008,942 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\VT20120410.034
[2012/04/25 13:45:06 | 000,000,912 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/20 15:51:42 | 000,431,713 | —- | M] () – C:\Users\jtmeserole\Desktop\additional work experience.rtf
[2012/04/20 15:26:17 | 000,001,103 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2012/04/18 22:48:26 | 000,000,172 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\isolate.ini
[2012/04/16 20:17:58 | 000,001,977 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/04/07 09:37:00 | 000,000,810 | —- | M] () – C:\Users\jtmeserole\Desktop\Celestia.lnk
[2012/04/06 16:07:42 | 000,000,000 | —- | M] () – C:\Windows\System32\drivers\lvuvc.hs
[2012/04/04 18:44:36 | 000,029,234 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\wklnhst.dat
[2012/04/04 15:56:40 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2012/04/04 11:23:33 | 000,011,208 | —- | M] () – C:\Users\jtmeserole\Documents\stop it.jpg
[2012/04/04 10:42:41 | 000,110,898 | —- | M] () – C:\Users\jtmeserole\Documents\Cookbook for Missionary.pdf
[2012/04/03 20:43:49 | 000,007,454 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\srtspx.cat
[2012/04/03 20:43:49 | 000,007,450 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\srtsp.cat
[2012/04/03 20:43:49 | 000,001,388 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\srtspx.inf
[2012/04/03 20:43:49 | 000,001,388 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\srtsp.inf
[2012/04/01 21:55:54 | 000,003,021 | —- | M] () – C:\Users\jtmeserole\Documents\brisingr sword.jpg
[2012/03/31 13:54:49 | 000,002,570 | —- | M] () – C:\Users\jtmeserole\Documents\banana.jpg
[2012/03/31 13:53:36 | 000,000,536 | —- | M] () – C:\Users\jtmeserole\Desktop\httpwww.google.comimgresq=banana+avatar&um;=1&hl;=en&safe;=active&client;=firefox-a&rls;=org.mozillaen-USofficial&biw;=595&bih;=100.URL
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\jtmeserole\Desktop\*.tmp files -> C:\Users\jtmeserole\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/04/20 15:51:42 | 000,431,713 | —- | C] () – C:\Users\jtmeserole\Desktop\additional work experience.rtf
[2012/04/20 15:26:17 | 000,001,103 | —- | C] () – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2012/04/07 09:37:00 | 000,000,810 | —- | C] () – C:\Users\jtmeserole\Desktop\Celestia.lnk
[2012/04/04 11:23:32 | 000,011,208 | —- | C] () – C:\Users\jtmeserole\Documents\stop it.jpg
[2012/04/04 10:42:40 | 000,110,898 | —- | C] () – C:\Users\jtmeserole\Documents\Cookbook for Missionary.pdf
[2012/04/01 21:55:53 | 000,003,021 | —- | C] () – C:\Users\jtmeserole\Documents\brisingr sword.jpg
[2012/03/31 13:54:45 | 000,002,570 | —- | C] () – C:\Users\jtmeserole\Documents\banana.jpg
[2012/03/31 13:53:36 | 000,000,536 | —- | C] () – C:\Users\jtmeserole\Desktop\httpwww.google.comimgresq=banana+avatar&um;=1&hl;=en&safe;=active&client;=firefox-a&rls;=org.mozillaen-USofficial&biw;=595&bih;=100.URL
[2012/02/29 10:51:38 | 000,000,022 | —- | C] () – C:\Windows\WinInit.Ini
[2012/02/29 10:51:28 | 000,168,207 | —- | C] () – C:\Windows\System32\Unstall.exe
[2011/08/20 16:04:22 | 000,150,004 | —- | C] () – C:\Windows\System32\mlfcache.dat
[2011/08/19 04:26:20 | 010,898,456 | —- | C] () – C:\Windows\System32\LogiDPP.dll
[2011/08/19 04:26:20 | 000,336,408 | —- | C] () – C:\Windows\System32\DevManagerCore.dll
[2011/08/19 04:26:20 | 000,104,472 | —- | C] () – C:\Windows\System32\LogiDPPApp.exe
[2011/08/12 13:20:14 | 000,015,896 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2011/07/26 01:48:54 | 000,028,418 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2011/05/22 17:10:50 | 000,069,632 | —- | C] () – C:\Windows\System32\MobOlExt.dll
[2011/05/15 19:27:51 | 000,000,092 | -HS- | C] () – C:\Windows\WSYS049.SYS
[2011/05/15 19:26:24 | 000,199,297 | —- | C] () – C:\Windows\Photo Pos Pro Uninstaller.exe
[2011/03/28 10:52:04 | 000,171,321 | —- | C] () – C:\Windows\hpwins27.dat.temp
[2011/03/28 10:52:04 | 000,000,385 | —- | C] () – C:\Windows\hpwmdl27.dat.temp
[2011/03/28 10:20:22 | 000,170,596 | —- | C] () – C:\Windows\hpwins27.dat
[2011/02/12 22:26:46 | 000,000,048 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/01/11 20:33:13 | 000,262,144 | —- | C] () – C:\Windows\System32\lame_enc.dll
[2010/09/25 19:46:40 | 000,054,784 | —- | C] () – C:\Users\jtmeserole\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/24 12:10:20 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/09/24 12:10:20 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/09/22 23:41:23 | 000,029,234 | —- | C] () – C:\Users\jtmeserole\AppData\Roaming\wklnhst.dat
[2010/09/20 13:18:13 | 000,001,356 | —- | C] () – C:\Users\jtmeserole\AppData\Local\d3d9caps.dat
[2010/04/06 05:10:15 | 000,225,411 | —- | C] () – C:\Windows\System32\PosPrKpLib.dll
[2010/04/06 05:10:07 | 000,020,480 | —- | C] () – C:\Windows\System32\PosTickerLib.dll
[2009/08/18 11:11:03 | 000,000,385 | —- | C] () – C:\Windows\hpwmdl27.dat
[2009/05/18 15:36:28 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/05/18 15:06:49 | 000,354,816 | —- | C] () – C:\Windows\System32\pythoncom26.dll
[2009/05/18 15:06:49 | 000,108,032 | —- | C] () – C:\Windows\System32\pywintypes26.dll
[2009/01/05 16:44:10 | 000,053,248 | —- | C] () – C:\Windows\bdoscandel.exe
[2009/01/05 16:44:10 | 000,000,453 | —- | C] () – C:\Windows\bdoscandellang.ini
[2006/11/02 07:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,381,240 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,604,708 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,104,150 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 05:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2005/09/23 06:52:14 | 000,078,848 | —- | C] () – C:\Windows\System32\OneWay.dll
[2002/06/02 09:05:40 | 000,038,912 | —- | C] () – C:\Windows\System32\1Way.dll
========== LOP Check ==========
[2011/09/23 11:48:03 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\.t4k_common
[2011/03/02 20:50:37 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\2monkeys
[2012/03/25 18:22:23 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Audacity
[2011/09/29 16:30:47 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Catalina Marketing Corp
[2011/05/30 17:30:34 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Chessmaster Challenge
[2011/04/10 14:35:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Farm Mania 2.1
[2012/04/11 08:16:45 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Free Download Manager
[2011/01/24 21:48:39 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\freshgames
[2011/09/07 18:15:19 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Guitar Pro 6
[2011/10/17 22:06:00 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\KidZui
[2011/12/11 17:31:28 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Leadertech
[2011/03/03 13:06:46 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Mean Hamster
[2011/03/01 11:52:31 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MSNInstaller
[2010/10/15 17:58:10 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MusE
[2010/11/05 18:54:16 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MusicNet
[2011/02/12 12:24:20 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\NCH Swift Sound
[2010/12/15 14:38:17 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Oberon Games
[2010/09/20 13:12:56 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\PictureMover
[2011/12/04 21:38:09 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\PlayFirst
[2012/04/25 15:30:42 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\QuickScan
[2012/04/17 01:24:17 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Radialpoint
[2012/02/27 16:38:58 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\School Zone Preferences
[2010/10/19 11:23:24 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Skunk Studios
[2012/02/28 11:30:52 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\SoftGrid Client
[2012/03/26 09:53:35 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Stellarium
[2012/03/08 13:16:04 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Super-Cow
[2011/01/25 21:26:00 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Supermarket Mania 2
[2010/09/22 23:41:24 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Template
[2011/09/30 18:21:20 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Tific
[2012/03/01 18:12:26 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\TP
[2012/02/10 16:33:14 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\tuxmath
[2010/09/27 15:17:15 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Unity
[2010/10/18 07:10:46 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\WildTangent
[2012/01/17 21:37:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Windstream
[2010/10/15 20:20:28 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\YoudaGames
[2012/04/29 18:00:00 | 000,000,452 | —- | M] () – C:\Windows\Tasks\ParetoLogic Registration.job
[2012/04/25 22:31:07 | 000,032,594 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/05/18 15:28:11 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2011/08/23 18:27:33 | 000,013,301 | —- | M] () – C:\ComboFix.txt
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/09/07 12:57:44 | 000,000,000 | —- | M] () – C:\FileRecovery.log
[2012/02/28 13:03:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/02/28 13:03:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/04/26 10:41:17 | 3399,237,632 | -HS- | M] () – C:\pagefile.sys
[2011/10/02 13:04:55 | 000,000,414 | —- | M] () – C:\TDSSKiller.2.5.15.0_02.10.2011_13.04.45_log.txt
[2011/08/17 20:34:46 | 000,065,814 | —- | M] () – C:\TDSSKiller.2.5.15.0_17.08.2011_20.33.13_log.txt
[2011/10/02 13:07:17 | 000,076,732 | —- | M] () – C:\TDSSKiller.2.6.2.0_02.10.2011_13.05.34_log.txt
[2009/05/18 15:31:49 | 000,000,349 | —- | M] () – C:\updatedatfix.log
[2008/08/26 07:37:52 | 000,000,458 | —- | M] () – C:\Windows Sidebar
< %systemroot%\Fonts\*.com >
[2006/11/02 07:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/12/21 12:24:56 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/04/20 12:23:48 | 000,315,904 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpfpp70w.dll
[2008/01/20 21:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 07:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 21:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 22:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 22:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 22:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/20 08:09:26 | 000,000,351 | -HS- | M] () – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/08/17 20:23:28 | 001,404,720 | —- | M] (Kaspersky Lab ZAO) – C:\Users\jtmeserole\Desktop\12345.com.exe
[2011/08/20 15:55:47 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\jtmeserole\Desktop\ATF_Cleaner.exe
[2011/09/23 11:35:12 | 021,091,562 | —- | M] () – C:\Users\jtmeserole\Desktop\tuxmath-2.0.3-win32-installer.exe
[1 C:\Users\jtmeserole\Desktop\*.tmp files -> C:\Users\jtmeserole\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
[2012/03/26 10:22:17 | 035,113,704 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\directx_9c_redist.exe
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-04-11 08:17:22
========== Alternate Data Streams ==========
@Alternate Data Stream - 249 bytes -> C:\ProgramData\Temp:EAEE7554
@Alternate Data Stream - 241 bytes -> C:\ProgramData\Temp:05F547A9
@Alternate Data Stream - 235 bytes -> C:\ProgramData\Temp:4B244549
@Alternate Data Stream - 232 bytes -> C:\ProgramData\Temp:76466F4C
@Alternate Data Stream - 228 bytes -> C:\ProgramData\Temp:E5F8E280
@Alternate Data Stream - 228 bytes -> C:\ProgramData\Temp:453190EC
@Alternate Data Stream - 226 bytes -> C:\ProgramData\Temp:2C678471
@Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:CFF6B3FF
@Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:217A2A36
@Alternate Data Stream - 223 bytes -> C:\ProgramData\Temp:162E02F7
@Alternate Data Stream - 221 bytes -> C:\ProgramData\Temp:ED9B661E
@Alternate Data Stream - 215 bytes -> C:\ProgramData\Temp:CF61CE5A
@Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:966CEAE7
@Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:90015502
@Alternate Data Stream - 213 bytes -> C:\ProgramData\Temp:6677D85A
@Alternate Data Stream - 213 bytes -> C:\ProgramData\Temp:517B507A
@Alternate Data Stream - 208 bytes -> C:\ProgramData\Temp:FEEEFFAD
@Alternate Data Stream - 208 bytes -> C:\ProgramData\Temp:969C0C96
@Alternate Data Stream - 207 bytes -> C:\ProgramData\Temp:C60FAC5D
@Alternate Data Stream - 207 bytes -> C:\ProgramData\Temp:10D98D98
@Alternate Data Stream - 206 bytes -> C:\ProgramData\Temp:1663E41B
@Alternate Data Stream - 195 bytes -> C:\ProgramData\Temp:A1D3FEF0
@Alternate Data Stream - 158 bytes -> C:\ProgramData\Temp:6B708944
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:DE6EED8B
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:9D03192E
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:A1023D41
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:4149A170
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:C9B27A06
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:8CCDAB14
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:93B0BB6F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:EC2E1DEC
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:00811B66
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:A4BF246C
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:02A78DF6
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:073139EC
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:8DD36B71
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:08801FDB
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:A00BCDEF
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:D1B5B4F1
@Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:FBFC061F
@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:E73B14E2
< End of report >
thanks!
Anyway, here are the results:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:13:18 AM, on 4/30/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\jtmeserole\Downloads\HijackThis(1).exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\6.2.0.9\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\6.2.0.9\IPS\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll (file missing)
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MI1933~1\Office14\URLREDIR.DLL
O2 - BHO: Norton Safety Minder BHO - {B8E07826-0971-4f16-B133-047B88034E89} - C:\Program Files\Norton Online\AddOns\Norton Safety Minder\Engine\2.3.0.18\coIEPlg.dll
O2 - BHO: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.2.0.9\coIEPlg.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "c:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windstream Service Agent.exe] "C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe" /AUTORUN
O4 - HKLM\..\Run: [DiagnosticTools.exe] "C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe" /AUTORUN
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-21-3496540520-3972749145-994392144-1001\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'safe kids')
O4 - HKUS\S-1-5-21-3496540520-3972749145-994392144-1001\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW,SYSTRAY (User 'safe kids')
O4 - HKUS\S-1-5-21-3496540520-3972749145-994392144-1001\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (User 'safe kids')
O4 - HKUS\S-1-5-21-3496540520-3972749145-994392144-1001\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User 'safe kids')
O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~1\MI1933~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} (BitDefender QuickScan Control) - http://quickscan.bitdefender.com/qsax/qsax.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/…can8/oscan8.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HsdService - Windstream - C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
O23 - Service: Norton Online (NOF) - Symantec Corporation - C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
O23 - Service: Norton PC Checkup Application Launcher - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
O23 - Service: ServicepointService - Radialpoint SafeCare Inc. - C:\Program Files\Windstream\Service Agent\ServicepointService.exe
O23 - Service: Application Virtualization Client (sftlist) - Unknown owner - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (file missing)
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
–
End of file - 12435 bytes
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 8:59:36.36 on Mon 04/30/2012
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.932 [GMT -5:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe
C:\Program Files\Windstream\Service Agent\ServicepointService.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\system32\rundll32.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
C:\Windows\Explorer.EXE
C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe
C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Users\safe kids\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LULnchr.exe
C:\Users\safe kids\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LogitechUpdate.exe
C:\Program Files\Chocolatier - Decadence by Design\chocolatier-decadence.exe
C:\Windows\helppane.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\system32\NOTEPAD.EXE
c:\Users\jtmeserole\Downloads\OTL.exe
C:\Windows\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\jtmeserole\Downloads\dds(1).scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\6.2.0.9\coIEPlg.dll
BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\6.2.0.9\ips\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\wi371a~1\datamngr\toolbar\searchqudtx.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mi1933~1\office14\URLREDIR.DLL
BHO: Norton Safety Minder BHO: {b8e07826-0971-4f16-b133-047b88034e89} - c:\program files\norton online\addons\norton safety minder\engine\2.3.0.18\coIEPlg.dll
BHO: Free Download Manager: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\6.2.0.9\coIEPlg.dll
TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\wi371a~1\datamngr\toolbar\searchqudtx.dll
TB: {C2DB4FE6-8409-45CE-8010-189A7B5CCE86} - No File
TB: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Free Download Manager] "c:\program files\free download manager\fdm.exe" -autorun
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [UpdatePDIRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\cyberlink dvd suite deluxe\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\cyberlink dvd suite deluxe" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Windstream Service Agent.exe] "c:\program files\windstream\service agent\Windstream Service Agent.exe" /AUTORUN
mRun: [DiagnosticTools.exe] "c:\program files\windstream\diagnostic tools\DiagnosticTools.exe" /AUTORUN
StartupFolder: c:\users\jtmese~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office14\ONENOTEM.EXE
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\mi1933~1\office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\mi1933~1\office14\ONBttnIE.dll/105
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
LSP: c:\windows\system32\wpclsp.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jtmese~1\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\
FF - prefs.js: browser.search.defaulturl - Bing
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.ldsscripturemastery.net/
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid;=113&systemid;=406&sr;=0&q;=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\progra~1\mi1933~1\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\mi1933~1\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\musicnotes\npmusicn.dll
FF - plugin: c:\program files\musicnotes\NPSibelius.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\program files\windstream\service agent\nprpspa.dll
FF - plugin: c:\users\jtmeserole\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\jtmeserole\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\extensions\{000f1ea4-5e08-4564-a29b-29076f63a37a}\plugins\npsoe.dll
FF - plugin: c:\users\jtmeserole\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
.
—- FIREFOX POLICIES —-
FF - user.js: extentions.y2layers.installId - 1132a82e-f3dd-43a0-b9bf-af81c9d2c769
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0602000.009\symds.sys [2012-4-23 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0602000.009\symefa.sys [2012-4-23 905336]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.0.1.2\definitions\bashdefs\20120413.001\BHDrvx86.sys [2012-4-19 821880]
R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\n360\0602000.009\ccsetx86.sys [2012-4-23 132744]
R1 ccSet_NOF;Norton Online Settings Manager;c:\windows\system32\drivers\nof\0203000.007\ccsetx86.sys [2012-2-9 132744]
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\rsdrv.sys [2011-9-7 22312]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.0.1.2\definitions\ipsdefs\20120427.001\IDSvix86.sys [2012-4-27 368248]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0602000.009\ironx86.sys [2012-4-23 149624]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0602000.009\symtdiv.sys [2012-4-23 345208]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 N360;Norton 360;c:\program files\norton 360\engine\6.2.0.9\ccsvchst.exe [2012-4-23 138232]
R2 NOF;Norton Online;c:\program files\norton online\engine\2.3.0.7\ccsvchst.exe [2012-2-9 138248]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\norton pc checkup\engine\2.0.12.27\SymcPCCULaunchSvc.exe [2011-9-30 135608]
R2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\norton pc checkup\engine\2.0.12.27\ccSvcHst.exe [2011-9-30 126392]
R2 ServicepointService;ServicepointService;c:\program files\windstream\service agent\ServicepointService.exe [2012-1-17 10315064]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-2-4 106104]
R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2011-10-1 579944]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2011-10-1 194408]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2011-10-1 19304]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\microsoft application virtualization client\sftvsa.exe [2011-10-1 219496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2012-1-4 822624]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-10 136176]
S2 HsdService;HsdService;c:\program files\windstream\diagnostic tools\HsdService.exe [2012-1-17 1393976]
S2 sftlist;Application Virtualization Client;"c:\program files\microsoft application virtualization client\sftlist.exe" –> c:\program files\microsoft application virtualization client\sftlist.exe [?]
S2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-8-19 450848]
S3 dsiarhwprog;dsiarhwprog;c:\windows\system32\drivers\dsiarhwprog.sys [2011-8-14 29184]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2011-1-26 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-10 136176]
S3 MHIKEY10;MHIKEY10;c:\windows\system32\drivers\MHIKEY10.sys [2008-5-27 50560]
S3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2011-10-1 21864]
S3 SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A};Symantec Redirector - Norton Safety Minder;c:\windows\system32\drivers\nsm\0203000.012\symrdr.sys [2012-3-15 197624]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-04-23 23:02:47 905336 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symefa.sys
2012-04-23 23:02:47 574072 —-a-w- c:\windows\system32\drivers\n360\0602000.009\srtsp.sys
2012-04-23 23:02:47 345208 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symtdiv.sys
2012-04-23 23:02:47 340088 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symds.sys
2012-04-23 23:02:47 32888 —-a-w- c:\windows\system32\drivers\n360\0602000.009\srtspx.sys
2012-04-23 23:02:47 318584 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symnets.sys
2012-04-23 23:02:46 149624 —-a-r- c:\windows\system32\drivers\n360\0602000.009\ironx86.sys
2012-04-23 23:02:46 132744 —-a-r- c:\windows\system32\drivers\n360\0602000.009\ccsetx86.sys
2012-04-23 23:02:35 4782 —-a-w- c:\windows\system32\drivers\n360\0602000.009\symvtcer.dat
2012-04-23 23:02:35 ——– d—–w- c:\windows\system32\drivers\n360\0602000.009
2012-04-11 08:14:19 5120 —-a-w- c:\windows\system32\wmi.dll
2012-04-11 08:14:19 172032 —-a-w- c:\windows\system32\wintrust.dll
2012-04-11 08:14:19 157696 —-a-w- c:\windows\system32\imagehlp.dll
2012-04-11 08:14:19 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-11 08:13:51 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-04-11 08:13:50 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-11 06:39:16 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2012-04-07 14:36:55 ——– d—–w- c:\program files\Celestia
.
==================== Find3M ====================
.
2012-03-26 15:22:17 35113704 —-a-w- c:\program files\common files\directx_9c_redist.exe
2012-03-01 22:53:35 1576 —-a-w- c:\windows\system32\DeletedKey21.reg
2012-03-01 22:51:30 348722 —-a-w- c:\windows\system32\DeletedKey20.reg
2012-03-01 22:50:15 83578 —-a-w- c:\windows\system32\DeletedKey19.reg
2012-03-01 21:54:12 565410 —-a-w- c:\windows\system32\uninstallkey01.reg
2012-03-01 21:51:28 318 —-a-w- c:\windows\system32\DeletedKey18.reg
2012-03-01 21:51:03 318 —-a-w- c:\windows\system32\DeletedKey17.reg
2012-03-01 21:50:45 318 —-a-w- c:\windows\system32\DeletedKey16.reg
2012-03-01 21:50:21 3518 —-a-w- c:\windows\system32\DeletedKey15.reg
2012-03-01 21:50:05 8856 —-a-w- c:\windows\system32\DeletedKey14.reg
2012-03-01 21:48:55 1668 —-a-w- c:\windows\system32\DeletedKey13.reg
2012-03-01 21:48:36 270 —-a-w- c:\windows\system32\DeletedKey12.reg
2012-03-01 21:48:16 732 —-a-w- c:\windows\system32\DeletedKey11.reg
2012-03-01 21:47:09 2956 —-a-w- c:\windows\system32\DeletedKey10.reg
2012-03-01 21:45:38 7152 —-a-w- c:\windows\system32\DeletedKey09.reg
2012-03-01 21:45:17 34560 —-a-w- c:\windows\system32\DeletedKey08.reg
2012-03-01 21:44:13 404 —-a-w- c:\windows\system32\DeletedKey07.reg
2012-03-01 21:43:56 404 —-a-w- c:\windows\system32\DeletedKey06.reg
2012-03-01 21:43:37 404 —-a-w- c:\windows\system32\DeletedKey05.reg
2012-03-01 21:41:28 2178 —-a-w- c:\windows\system32\DeletedKey04.reg
2012-03-01 21:40:42 13288 —-a-w- c:\windows\system32\DeletedKey03.reg
2012-03-01 21:39:57 3462 —-a-w- c:\windows\system32\DeletedKey02.reg
2012-03-01 21:10:53 1240 —-a-w- c:\windows\system32\DeletedKey01.reg
2012-02-29 15:32:50 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-28 01:18:55 1799168 —-a-w- c:\windows\system32\jscript9.dll
2012-02-28 01:11:21 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
2012-02-28 01:11:07 1127424 —-a-w- c:\windows\system32\wininet.dll
2012-02-28 01:03:16 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-02-14 17:09:44 1070352 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2012-02-14 15:45:30 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-02-14 15:45:30 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-02-13 14:12:08 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-02-13 13:47:57 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-02-13 13:44:40 1068544 —-a-w- c:\windows\system32\DWrite.dll
2012-02-02 15:16:25 2044416 —-a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 9:00:34.52 ===============
OTL logfile created on: 4/29/2012 8:45:32 PM - Run 4
OTL by OldTimer - Version 3.2.26.5 Folder = c:\Users\jtmeserole\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 1.18 Gb Available Physical Memory | 41.04% Memory free
5.95 Gb Paging File | 3.51 Gb Available in Paging File | 58.93% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.80 Gb Total Space | 152.20 Gb Free Space | 53.07% Space Free | Partition Type: NTFS
Drive D: | 11.28 Gb Total Space | 1.59 Gb Free Space | 14.08% Space Free | Partition Type: NTFS
Drive F: | 298.02 Gb Total Space | 163.62 Gb Free Space | 54.90% Space Free | Partition Type: FAT32
Computer Name: JTMESEROLE-PC | User Name: jtmeserole | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files\Norton 360\Engine\6.2.0.9\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Norton Online\Engine\2.3.0.7\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Windstream\Service Agent\Windstream Service AgentComHandler.exe (Radialpoint SafeCare Inc.)
PRC - C:\Program Files\Windstream\Service Agent\ServicepointService.exe (Radialpoint SafeCare Inc.)
PRC - C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe (Windstream)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\bfgclient\bfggameservices.exe ()
PRC - c:\Users\jtmeserole\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Users\safe kids\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LogitechUpdate.exe (Logitech, Inc.)
PRC - C:\Users\safe kids\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LULnchr.exe (Logitech, Inc.)
PRC - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe (Windstream)
PRC - C:\Program Files\Chocolatier - Decadence by Design\chocolatier-decadence.exe ()
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\HelpPane.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Norton Online\AddOns\Norton Safety Minder\Engine\2.3.0.18\wincfi39.dll ()
========== Win32 Services (SafeList) ==========
SRV - (sftlist) – File not found
SRV - (N360) – C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe (Symantec Corporation)
SRV - (Norton PC Checkup Application Launcher) – C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (NOF) – C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe (Symantec Corporation)
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (ServicepointService) – C:\Program Files\Windstream\Service Agent\ServicepointService.exe (Radialpoint SafeCare Inc.)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (UMVPFSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (PCCUJobMgr) – C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
SRV - (HsdService) – C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe (Windstream)
SRV - (GameConsoleService) – C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\Definitions\BASHDefs\20120413.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\N360\0602000.009\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\N360\0602000.009\SRTSPX.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\Definitions\IPSDefs\20120427.001\IDSvix86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\Definitions\VirusDefs\20120428.016\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\Definitions\VirusDefs\20120428.016\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\N360\0602000.009\SYMEFA.SYS (Symantec Corporation)
DRV - (SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}) – C:\Windows\System32\Drivers\NSM\0203000.012\SymRdr.SYS (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\System32\Drivers\N360\0602000.009\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\N360\0602000.009\Ironx86.SYS (Symantec Corporation)
DRV - (ccSet_N360) – C:\Windows\system32\drivers\N360\0602000.009\ccSetx86.sys (Symantec Corporation)
DRV - (ccSet_NOF) – C:\Windows\system32\drivers\NOF\0203000.007\ccSetx86.sys (Symantec Corporation)
DRV - (Sftvol) – C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (LVUVC) Logitech Webcam 250(UVC) – C:\Windows\System32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (SymDS) – C:\Windows\system32\drivers\N360\0602000.009\SYMDS.SYS (Symantec Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corporation)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (ElRawDisk) – C:\Windows\System32\drivers\rsdrv.sys (EldoS Corporation)
DRV - (nvrd32) – C:\Windows\system32\drivers\nvrd32.sys (NVIDIA Corporation)
DRV - (nvstor32) – C:\Windows\system32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (MHIKEY10) – C:\Windows\System32\drivers\MHIKEY10.sys (Generic USB smartcard reader)
DRV - (nvsmu) – C:\Windows\system32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (irsir) – C:\Windows\System32\drivers\irsir.sys (Microsoft Corporation)
DRV - (dsiarhwprog) – C:\Windows\System32\drivers\dsiarhwprog.sys (Thesycon GmbH, Germany)
DRV - (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM) – C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.ldsscripturemastery.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 98 7D 03 02 CE 6E E2 4D 9F 26 81 EE 65 AF 76 3D [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "www.google.com"
FF - prefs.js..browser.search.defaulturl: "Bing"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.ldsscripturemastery.net/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:5.0.1
FF - prefs.js..extensions.enabledItems: [removed]:2.3
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {000F1EA4-5E08-4564-A29B-29076F63A37A}:[removed]
FF - prefs.js..extensions.enabledItems: {6D5C8FC4-DE46-41bf-9092-93F0F78E9115}:2.1.0.51
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=113&systemid;=406&sr;=0&q;="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MI1933~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MI1933~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.18.9: C:\Program Files\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files\Windstream\Service Agent\nprpspa.dll (Windstream)
FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=6.2.0.88: C:\Program Files\Musicnotes\npsibelius.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll ()
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\jtmeserole\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\IPSFFPlgn\ [2012/02/29 16:11:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\coFFPlgn\ [2012/04/26 10:42:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}: C:\ProgramData\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.2.0.28\coFFFw\ [2012/04/26 10:42:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/03/28 10:30:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/19 06:38:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/09 21:25:10 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/03/28 10:30:49 | 000,000,000 | —D | M]
[2011/11/09 11:14:59 | 000,000,000 | —D | M] (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Extensions
[2012/04/25 18:38:57 | 000,000,000 | —D | M] (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions
[2011/02/19 18:48:33 | 000,000,000 | —D | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
[2010/09/27 21:35:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/04/21 18:35:30 | 000,000,000 | —D | M] (Bitdefender QuickScan) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/09/27 21:35:19 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2010/09/20 15:59:14 | 000,000,000 | —D | M] (KidZui) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2011/12/24 23:14:40 | 000,002,578 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\askcom.xml
[2011/09/07 18:07:40 | 000,001,945 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\bing-zugo.xml
[2010/12/01 18:51:50 | 000,000,927 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\conduit.xml
[2011/05/03 11:52:57 | 000,002,469 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\safesearch.xml
[2011/11/08 22:40:03 | 000,002,519 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\SearchResults.xml
[2012/01/13 17:53:52 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
[2012/02/29 16:11:43 | 000,000,000 | —D | M] (Norton Vulnerability Protection) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\IPSFFPLGN
[2012/04/26 10:42:15 | 000,000,000 | —D | M] (Norton Safety Minder) – C:\PROGRAMDATA\NORTON\{78CA3BF0-9C3B-40E1-B46D-38C877EF059A}\NSM_2.2.0.28\COFFFW
() (No name found) – C:\USERS\JTMESEROLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TKUCY2AP.DEFAULT\EXTENSIONS\{EF4E370E-D9F0-4E00-B93E-A4F274CFDD5A}.XPI
() (No name found) – C:\USERS\JTMESEROLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TKUCY2AP.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\JTMESEROLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TKUCY2AP.DEFAULT\EXTENSIONS\[removed]
[2012/03/19 06:38:43 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/09/29 16:30:47 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2011/07/13 16:52:56 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/03 06:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/07/13 16:52:58 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2010/03/31 11:09:22 | 010,437,264 | —- | M] (PDFTron Systems Inc.) – C:\Program Files\mozilla firefox\plugins\PDFNetC.dll
[2010/04/08 13:36:02 | 000,107,760 | —- | M] () – C:\Program Files\mozilla firefox\plugins\ScorchPDFWrapper.dll
[2011/08/01 23:22:34 | 000,002,226 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012/02/14 13:51:54 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/08/12 01:58:47 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml.old
[2011/11/08 22:40:03 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml
[2012/02/14 13:51:54 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/08/23 18:24:55 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\6.2.0.9\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\6.2.0.9\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Norton Safety Minder BHO) - {B8E07826-0971-4f16-B133-047B88034E89} - C:\Program Files\Norton Online\AddOns\Norton Safety Minder\Engine\2.3.0.18\coieplg.dll (Symantec Corporation)
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.2.0.9\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.2.0.9\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DiagnosticTools.exe] C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe (Windstream)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [UpdateLBPShortCut] c:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windstream Service Agent.exe] C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe (Windstream)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
O4 - Startup: C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Cabo.JPG
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Cabo.JPG
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/06/27 10:31:18 | 000,000,000 | —D | M] - F:\autorun – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: aux - wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi - wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - midimap.dll (Microsoft Corporation)
Drivers32: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32: MSVideo - vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - VfWWDM32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - lvcodec2.dll (Logitech Inc.)
Drivers32: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YUY2 - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - msyuv.dll (Microsoft Corporation)
Drivers32: wave - wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/04/20 15:26:11 | 000,000,000 | —D | C] – C:\Users\jtmeserole\Documents\OneNote Notebooks
[2012/04/11 03:16:53 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/04/11 03:16:52 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/04/11 03:16:51 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/04/11 03:16:51 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/04/11 03:16:51 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/04/11 03:16:50 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/04/11 03:13:51 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/04/11 03:13:50 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/04/07 09:37:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Celestia
[2012/04/07 09:36:55 | 000,000,000 | —D | C] – C:\Program Files\Celestia
[2012/03/26 10:22:17 | 035,113,704 | —- | C] (Microsoft Corporation) – C:\Program Files\Common Files\directx_9c_redist.exe
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\jtmeserole\Desktop\*.tmp files -> C:\Users\jtmeserole\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/04/29 20:42:39 | 000,003,616 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/29 20:42:39 | 000,003,616 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/29 18:55:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/29 18:00:00 | 000,000,452 | —- | M] () – C:\Windows\tasks\ParetoLogic Registration.job
[2012/04/29 11:55:00 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/26 10:48:05 | 000,604,708 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/04/26 10:48:05 | 000,104,150 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/04/26 10:41:54 | 000,065,536 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2012/04/26 10:41:34 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/04/25 13:48:41 | 000,002,045 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2012/04/25 13:48:11 | 002,188,162 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\Cat.DB
[2012/04/25 13:47:32 | 000,008,942 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\VT20120410.034
[2012/04/25 13:45:06 | 000,000,912 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/20 15:51:42 | 000,431,713 | —- | M] () – C:\Users\jtmeserole\Desktop\additional work experience.rtf
[2012/04/20 15:26:17 | 000,001,103 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2012/04/18 22:48:26 | 000,000,172 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\isolate.ini
[2012/04/16 20:17:58 | 000,001,977 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/04/07 09:37:00 | 000,000,810 | —- | M] () – C:\Users\jtmeserole\Desktop\Celestia.lnk
[2012/04/06 16:07:42 | 000,000,000 | —- | M] () – C:\Windows\System32\drivers\lvuvc.hs
[2012/04/04 18:44:36 | 000,029,234 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\wklnhst.dat
[2012/04/04 15:56:40 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2012/04/04 11:23:33 | 000,011,208 | —- | M] () – C:\Users\jtmeserole\Documents\stop it.jpg
[2012/04/04 10:42:41 | 000,110,898 | —- | M] () – C:\Users\jtmeserole\Documents\Cookbook for Missionary.pdf
[2012/04/03 20:43:49 | 000,007,454 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\srtspx.cat
[2012/04/03 20:43:49 | 000,007,450 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\srtsp.cat
[2012/04/03 20:43:49 | 000,001,388 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\srtspx.inf
[2012/04/03 20:43:49 | 000,001,388 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\srtsp.inf
[2012/04/01 21:55:54 | 000,003,021 | —- | M] () – C:\Users\jtmeserole\Documents\brisingr sword.jpg
[2012/03/31 13:54:49 | 000,002,570 | —- | M] () – C:\Users\jtmeserole\Documents\banana.jpg
[2012/03/31 13:53:36 | 000,000,536 | —- | M] () – C:\Users\jtmeserole\Desktop\httpwww.google.comimgresq=banana+avatar&um;=1&hl;=en&safe;=active&client;=firefox-a&rls;=org.mozillaen-USofficial&biw;=595&bih;=100.URL
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\jtmeserole\Desktop\*.tmp files -> C:\Users\jtmeserole\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/04/20 15:51:42 | 000,431,713 | —- | C] () – C:\Users\jtmeserole\Desktop\additional work experience.rtf
[2012/04/20 15:26:17 | 000,001,103 | —- | C] () – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2012/04/07 09:37:00 | 000,000,810 | —- | C] () – C:\Users\jtmeserole\Desktop\Celestia.lnk
[2012/04/04 11:23:32 | 000,011,208 | —- | C] () – C:\Users\jtmeserole\Documents\stop it.jpg
[2012/04/04 10:42:40 | 000,110,898 | —- | C] () – C:\Users\jtmeserole\Documents\Cookbook for Missionary.pdf
[2012/04/01 21:55:53 | 000,003,021 | —- | C] () – C:\Users\jtmeserole\Documents\brisingr sword.jpg
[2012/03/31 13:54:45 | 000,002,570 | —- | C] () – C:\Users\jtmeserole\Documents\banana.jpg
[2012/03/31 13:53:36 | 000,000,536 | —- | C] () – C:\Users\jtmeserole\Desktop\httpwww.google.comimgresq=banana+avatar&um;=1&hl;=en&safe;=active&client;=firefox-a&rls;=org.mozillaen-USofficial&biw;=595&bih;=100.URL
[2012/02/29 10:51:38 | 000,000,022 | —- | C] () – C:\Windows\WinInit.Ini
[2012/02/29 10:51:28 | 000,168,207 | —- | C] () – C:\Windows\System32\Unstall.exe
[2011/08/20 16:04:22 | 000,150,004 | —- | C] () – C:\Windows\System32\mlfcache.dat
[2011/08/19 04:26:20 | 010,898,456 | —- | C] () – C:\Windows\System32\LogiDPP.dll
[2011/08/19 04:26:20 | 000,336,408 | —- | C] () – C:\Windows\System32\DevManagerCore.dll
[2011/08/19 04:26:20 | 000,104,472 | —- | C] () – C:\Windows\System32\LogiDPPApp.exe
[2011/08/12 13:20:14 | 000,015,896 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2011/07/26 01:48:54 | 000,028,418 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2011/05/22 17:10:50 | 000,069,632 | —- | C] () – C:\Windows\System32\MobOlExt.dll
[2011/05/15 19:27:51 | 000,000,092 | -HS- | C] () – C:\Windows\WSYS049.SYS
[2011/05/15 19:26:24 | 000,199,297 | —- | C] () – C:\Windows\Photo Pos Pro Uninstaller.exe
[2011/03/28 10:52:04 | 000,171,321 | —- | C] () – C:\Windows\hpwins27.dat.temp
[2011/03/28 10:52:04 | 000,000,385 | —- | C] () – C:\Windows\hpwmdl27.dat.temp
[2011/03/28 10:20:22 | 000,170,596 | —- | C] () – C:\Windows\hpwins27.dat
[2011/02/12 22:26:46 | 000,000,048 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/01/11 20:33:13 | 000,262,144 | —- | C] () – C:\Windows\System32\lame_enc.dll
[2010/09/25 19:46:40 | 000,054,784 | —- | C] () – C:\Users\jtmeserole\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/24 12:10:20 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/09/24 12:10:20 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/09/22 23:41:23 | 000,029,234 | —- | C] () – C:\Users\jtmeserole\AppData\Roaming\wklnhst.dat
[2010/09/20 13:18:13 | 000,001,356 | —- | C] () – C:\Users\jtmeserole\AppData\Local\d3d9caps.dat
[2010/04/06 05:10:15 | 000,225,411 | —- | C] () – C:\Windows\System32\PosPrKpLib.dll
[2010/04/06 05:10:07 | 000,020,480 | —- | C] () – C:\Windows\System32\PosTickerLib.dll
[2009/08/18 11:11:03 | 000,000,385 | —- | C] () – C:\Windows\hpwmdl27.dat
[2009/05/18 15:36:28 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/05/18 15:06:49 | 000,354,816 | —- | C] () – C:\Windows\System32\pythoncom26.dll
[2009/05/18 15:06:49 | 000,108,032 | —- | C] () – C:\Windows\System32\pywintypes26.dll
[2009/01/05 16:44:10 | 000,053,248 | —- | C] () – C:\Windows\bdoscandel.exe
[2009/01/05 16:44:10 | 000,000,453 | —- | C] () – C:\Windows\bdoscandellang.ini
[2006/11/02 07:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,381,240 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,604,708 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,104,150 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 05:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2005/09/23 06:52:14 | 000,078,848 | —- | C] () – C:\Windows\System32\OneWay.dll
[2002/06/02 09:05:40 | 000,038,912 | —- | C] () – C:\Windows\System32\1Way.dll
========== LOP Check ==========
[2011/09/23 11:48:03 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\.t4k_common
[2011/03/02 20:50:37 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\2monkeys
[2012/03/25 18:22:23 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Audacity
[2011/09/29 16:30:47 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Catalina Marketing Corp
[2011/05/30 17:30:34 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Chessmaster Challenge
[2011/04/10 14:35:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Farm Mania 2.1
[2012/04/11 08:16:45 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Free Download Manager
[2011/01/24 21:48:39 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\freshgames
[2011/09/07 18:15:19 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Guitar Pro 6
[2011/10/17 22:06:00 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\KidZui
[2011/12/11 17:31:28 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Leadertech
[2011/03/03 13:06:46 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Mean Hamster
[2011/03/01 11:52:31 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MSNInstaller
[2010/10/15 17:58:10 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MusE
[2010/11/05 18:54:16 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MusicNet
[2011/02/12 12:24:20 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\NCH Swift Sound
[2010/12/15 14:38:17 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Oberon Games
[2010/09/20 13:12:56 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\PictureMover
[2011/12/04 21:38:09 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\PlayFirst
[2012/04/25 15:30:42 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\QuickScan
[2012/04/17 01:24:17 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Radialpoint
[2012/02/27 16:38:58 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\School Zone Preferences
[2010/10/19 11:23:24 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Skunk Studios
[2012/02/28 11:30:52 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\SoftGrid Client
[2012/03/26 09:53:35 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Stellarium
[2012/03/08 13:16:04 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Super-Cow
[2011/01/25 21:26:00 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Supermarket Mania 2
[2010/09/22 23:41:24 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Template
[2011/09/30 18:21:20 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Tific
[2012/03/01 18:12:26 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\TP
[2012/02/10 16:33:14 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\tuxmath
[2010/09/27 15:17:15 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Unity
[2010/10/18 07:10:46 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\WildTangent
[2012/01/17 21:37:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Windstream
[2010/10/15 20:20:28 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\YoudaGames
[2012/04/29 18:00:00 | 000,000,452 | —- | M] () – C:\Windows\Tasks\ParetoLogic Registration.job
[2012/04/25 22:31:07 | 000,032,594 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/05/18 15:28:11 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2011/08/23 18:27:33 | 000,013,301 | —- | M] () – C:\ComboFix.txt
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/09/07 12:57:44 | 000,000,000 | —- | M] () – C:\FileRecovery.log
[2012/02/28 13:03:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/02/28 13:03:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/04/26 10:41:17 | 3399,237,632 | -HS- | M] () – C:\pagefile.sys
[2011/10/02 13:04:55 | 000,000,414 | —- | M] () – C:\TDSSKiller.2.5.15.0_02.10.2011_13.04.45_log.txt
[2011/08/17 20:34:46 | 000,065,814 | —- | M] () – C:\TDSSKiller.2.5.15.0_17.08.2011_20.33.13_log.txt
[2011/10/02 13:07:17 | 000,076,732 | —- | M] () – C:\TDSSKiller.2.6.2.0_02.10.2011_13.05.34_log.txt
[2009/05/18 15:31:49 | 000,000,349 | —- | M] () – C:\updatedatfix.log
[2008/08/26 07:37:52 | 000,000,458 | —- | M] () – C:\Windows Sidebar
< %systemroot%\Fonts\*.com >
[2006/11/02 07:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/12/21 12:24:56 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/04/20 12:23:48 | 000,315,904 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpfpp70w.dll
[2008/01/20 21:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 07:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 21:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 22:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 22:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 22:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/20 08:09:26 | 000,000,351 | -HS- | M] () – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/08/17 20:23:28 | 001,404,720 | —- | M] (Kaspersky Lab ZAO) – C:\Users\jtmeserole\Desktop\12345.com.exe
[2011/08/20 15:55:47 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\jtmeserole\Desktop\ATF_Cleaner.exe
[2011/09/23 11:35:12 | 021,091,562 | —- | M] () – C:\Users\jtmeserole\Desktop\tuxmath-2.0.3-win32-installer.exe
[1 C:\Users\jtmeserole\Desktop\*.tmp files -> C:\Users\jtmeserole\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
[2012/03/26 10:22:17 | 035,113,704 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\directx_9c_redist.exe
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-04-11 08:17:22
========== Alternate Data Streams ==========
@Alternate Data Stream - 249 bytes -> C:\ProgramData\Temp:EAEE7554
@Alternate Data Stream - 241 bytes -> C:\ProgramData\Temp:05F547A9
@Alternate Data Stream - 235 bytes -> C:\ProgramData\Temp:4B244549
@Alternate Data Stream - 232 bytes -> C:\ProgramData\Temp:76466F4C
@Alternate Data Stream - 228 bytes -> C:\ProgramData\Temp:E5F8E280
@Alternate Data Stream - 228 bytes -> C:\ProgramData\Temp:453190EC
@Alternate Data Stream - 226 bytes -> C:\ProgramData\Temp:2C678471
@Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:CFF6B3FF
@Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:217A2A36
@Alternate Data Stream - 223 bytes -> C:\ProgramData\Temp:162E02F7
@Alternate Data Stream - 221 bytes -> C:\ProgramData\Temp:ED9B661E
@Alternate Data Stream - 215 bytes -> C:\ProgramData\Temp:CF61CE5A
@Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:966CEAE7
@Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:90015502
@Alternate Data Stream - 213 bytes -> C:\ProgramData\Temp:6677D85A
@Alternate Data Stream - 213 bytes -> C:\ProgramData\Temp:517B507A
@Alternate Data Stream - 208 bytes -> C:\ProgramData\Temp:FEEEFFAD
@Alternate Data Stream - 208 bytes -> C:\ProgramData\Temp:969C0C96
@Alternate Data Stream - 207 bytes -> C:\ProgramData\Temp:C60FAC5D
@Alternate Data Stream - 207 bytes -> C:\ProgramData\Temp:10D98D98
@Alternate Data Stream - 206 bytes -> C:\ProgramData\Temp:1663E41B
@Alternate Data Stream - 195 bytes -> C:\ProgramData\Temp:A1D3FEF0
@Alternate Data Stream - 158 bytes -> C:\ProgramData\Temp:6B708944
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:DE6EED8B
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:9D03192E
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:A1023D41
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:4149A170
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:C9B27A06
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:8CCDAB14
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:93B0BB6F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:EC2E1DEC
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:00811B66
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:A4BF246C
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:02A78DF6
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:073139EC
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:8DD36B71
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:08801FDB
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:A00BCDEF
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:D1B5B4F1
@Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:FBFC061F
@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:E73B14E2
< End of report >
thanks!