This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow internet [Solved]

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been having problems with the internet being slow to load pages for about a week. I have run a kaspersky scan, an mbam scan, a bitdefender quickscan (I have never had that program find anything, does it really work?) and an ESET scan, (one thing was found by eset and fixed, but the problem really didn't go away). The challenge is that it isn't consistent. It comes and goes throughout the day. Right now it seems great, but yesterday it was slow, and saturday it was a nightmare. I am assuming I have some kind of infection that isn't being picked up, as when it hangs, it says it is waiting for a different site than the one I am on (usually an ad site) before it goes to the actual site. Usually, it is not a site that has an ad on the page I am visiting. That is why I ran Mbam, because I thought I had picked up adware, but it didn't find anything.

Anyway, here are the results:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:13:18 AM, on 4/30/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\jtmeserole\Downloads\HijackThis(1).exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\6.2.0.9\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\6.2.0.9\IPS\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll (file missing)
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MI1933~1\Office14\URLREDIR.DLL
O2 - BHO: Norton Safety Minder BHO - {B8E07826-0971-4f16-B133-047B88034E89} - C:\Program Files\Norton Online\AddOns\Norton Safety Minder\Engine\2.3.0.18\coIEPlg.dll
O2 - BHO: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.2.0.9\coIEPlg.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "c:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windstream Service Agent.exe] "C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe" /AUTORUN
O4 - HKLM\..\Run: [DiagnosticTools.exe] "C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe" /AUTORUN
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-21-3496540520-3972749145-994392144-1001\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'safe kids')
O4 - HKUS\S-1-5-21-3496540520-3972749145-994392144-1001\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW,SYSTRAY (User 'safe kids')
O4 - HKUS\S-1-5-21-3496540520-3972749145-994392144-1001\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (User 'safe kids')
O4 - HKUS\S-1-5-21-3496540520-3972749145-994392144-1001\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User 'safe kids')
O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~1\MI1933~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} (BitDefender QuickScan Control) - http://quickscan.bitdefender.com/qsax/qsax.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/…can8/oscan8.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HsdService - Windstream - C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
O23 - Service: Norton Online (NOF) - Symantec Corporation - C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
O23 - Service: Norton PC Checkup Application Launcher - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
O23 - Service: ServicepointService - Radialpoint SafeCare Inc. - C:\Program Files\Windstream\Service Agent\ServicepointService.exe
O23 - Service: Application Virtualization Client (sftlist) - Unknown owner - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (file missing)
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe

–
End of file - 12435 bytes

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 8:59:36.36 on Mon 04/30/2012
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.932 [GMT -5:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe
C:\Program Files\Windstream\Service Agent\ServicepointService.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\system32\rundll32.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe
C:\Windows\Explorer.EXE
C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe
C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Users\safe kids\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LULnchr.exe
C:\Users\safe kids\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LogitechUpdate.exe
C:\Program Files\Chocolatier - Decadence by Design\chocolatier-decadence.exe
C:\Windows\helppane.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\system32\NOTEPAD.EXE
c:\Users\jtmeserole\Downloads\OTL.exe
C:\Windows\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\jtmeserole\Downloads\dds(1).scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\6.2.0.9\coIEPlg.dll
BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\6.2.0.9\ips\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\wi371a~1\datamngr\toolbar\searchqudtx.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mi1933~1\office14\URLREDIR.DLL
BHO: Norton Safety Minder BHO: {b8e07826-0971-4f16-b133-047b88034e89} - c:\program files\norton online\addons\norton safety minder\engine\2.3.0.18\coIEPlg.dll
BHO: Free Download Manager: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\6.2.0.9\coIEPlg.dll
TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\wi371a~1\datamngr\toolbar\searchqudtx.dll
TB: {C2DB4FE6-8409-45CE-8010-189A7B5CCE86} - No File
TB: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Free Download Manager] "c:\program files\free download manager\fdm.exe" -autorun
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [UpdatePDIRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\cyberlink dvd suite deluxe\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\cyberlink dvd suite deluxe" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Windstream Service Agent.exe] "c:\program files\windstream\service agent\Windstream Service Agent.exe" /AUTORUN
mRun: [DiagnosticTools.exe] "c:\program files\windstream\diagnostic tools\DiagnosticTools.exe" /AUTORUN
StartupFolder: c:\users\jtmese~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office14\ONENOTEM.EXE
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\mi1933~1\office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\mi1933~1\office14\ONBttnIE.dll/105
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
LSP: c:\windows\system32\wpclsp.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jtmese~1\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\
FF - prefs.js: browser.search.defaulturl - Bing
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.ldsscripturemastery.net/
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid;=113&systemid;=406&sr;=0&q;=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\progra~1\mi1933~1\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\mi1933~1\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\musicnotes\npmusicn.dll
FF - plugin: c:\program files\musicnotes\NPSibelius.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\program files\windstream\service agent\nprpspa.dll
FF - plugin: c:\users\jtmeserole\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\jtmeserole\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\extensions\{000f1ea4-5e08-4564-a29b-29076f63a37a}\plugins\npsoe.dll
FF - plugin: c:\users\jtmeserole\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
.
—- FIREFOX POLICIES —-
FF - user.js: extentions.y2layers.installId - 1132a82e-f3dd-43a0-b9bf-af81c9d2c769
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0602000.009\symds.sys [2012-4-23 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0602000.009\symefa.sys [2012-4-23 905336]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.0.1.2\definitions\bashdefs\20120413.001\BHDrvx86.sys [2012-4-19 821880]
R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\n360\0602000.009\ccsetx86.sys [2012-4-23 132744]
R1 ccSet_NOF;Norton Online Settings Manager;c:\windows\system32\drivers\nof\0203000.007\ccsetx86.sys [2012-2-9 132744]
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\rsdrv.sys [2011-9-7 22312]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.0.1.2\definitions\ipsdefs\20120427.001\IDSvix86.sys [2012-4-27 368248]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0602000.009\ironx86.sys [2012-4-23 149624]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0602000.009\symtdiv.sys [2012-4-23 345208]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 N360;Norton 360;c:\program files\norton 360\engine\6.2.0.9\ccsvchst.exe [2012-4-23 138232]
R2 NOF;Norton Online;c:\program files\norton online\engine\2.3.0.7\ccsvchst.exe [2012-2-9 138248]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\norton pc checkup\engine\2.0.12.27\SymcPCCULaunchSvc.exe [2011-9-30 135608]
R2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\norton pc checkup\engine\2.0.12.27\ccSvcHst.exe [2011-9-30 126392]
R2 ServicepointService;ServicepointService;c:\program files\windstream\service agent\ServicepointService.exe [2012-1-17 10315064]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-2-4 106104]
R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2011-10-1 579944]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2011-10-1 194408]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2011-10-1 19304]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\microsoft application virtualization client\sftvsa.exe [2011-10-1 219496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2012-1-4 822624]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-10 136176]
S2 HsdService;HsdService;c:\program files\windstream\diagnostic tools\HsdService.exe [2012-1-17 1393976]
S2 sftlist;Application Virtualization Client;"c:\program files\microsoft application virtualization client\sftlist.exe" –> c:\program files\microsoft application virtualization client\sftlist.exe [?]
S2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-8-19 450848]
S3 dsiarhwprog;dsiarhwprog;c:\windows\system32\drivers\dsiarhwprog.sys [2011-8-14 29184]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2011-1-26 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-10 136176]
S3 MHIKEY10;MHIKEY10;c:\windows\system32\drivers\MHIKEY10.sys [2008-5-27 50560]
S3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2011-10-1 21864]
S3 SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A};Symantec Redirector - Norton Safety Minder;c:\windows\system32\drivers\nsm\0203000.012\symrdr.sys [2012-3-15 197624]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-04-23 23:02:47 905336 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symefa.sys
2012-04-23 23:02:47 574072 —-a-w- c:\windows\system32\drivers\n360\0602000.009\srtsp.sys
2012-04-23 23:02:47 345208 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symtdiv.sys
2012-04-23 23:02:47 340088 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symds.sys
2012-04-23 23:02:47 32888 —-a-w- c:\windows\system32\drivers\n360\0602000.009\srtspx.sys
2012-04-23 23:02:47 318584 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symnets.sys
2012-04-23 23:02:46 149624 —-a-r- c:\windows\system32\drivers\n360\0602000.009\ironx86.sys
2012-04-23 23:02:46 132744 —-a-r- c:\windows\system32\drivers\n360\0602000.009\ccsetx86.sys
2012-04-23 23:02:35 4782 —-a-w- c:\windows\system32\drivers\n360\0602000.009\symvtcer.dat
2012-04-23 23:02:35 ——– d—–w- c:\windows\system32\drivers\n360\0602000.009
2012-04-11 08:14:19 5120 —-a-w- c:\windows\system32\wmi.dll
2012-04-11 08:14:19 172032 —-a-w- c:\windows\system32\wintrust.dll
2012-04-11 08:14:19 157696 —-a-w- c:\windows\system32\imagehlp.dll
2012-04-11 08:14:19 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-11 08:13:51 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-04-11 08:13:50 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-11 06:39:16 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2012-04-07 14:36:55 ——– d—–w- c:\program files\Celestia
.
==================== Find3M ====================
.
2012-03-26 15:22:17 35113704 —-a-w- c:\program files\common files\directx_9c_redist.exe
2012-03-01 22:53:35 1576 —-a-w- c:\windows\system32\DeletedKey21.reg
2012-03-01 22:51:30 348722 —-a-w- c:\windows\system32\DeletedKey20.reg
2012-03-01 22:50:15 83578 —-a-w- c:\windows\system32\DeletedKey19.reg
2012-03-01 21:54:12 565410 —-a-w- c:\windows\system32\uninstallkey01.reg
2012-03-01 21:51:28 318 —-a-w- c:\windows\system32\DeletedKey18.reg
2012-03-01 21:51:03 318 —-a-w- c:\windows\system32\DeletedKey17.reg
2012-03-01 21:50:45 318 —-a-w- c:\windows\system32\DeletedKey16.reg
2012-03-01 21:50:21 3518 —-a-w- c:\windows\system32\DeletedKey15.reg
2012-03-01 21:50:05 8856 —-a-w- c:\windows\system32\DeletedKey14.reg
2012-03-01 21:48:55 1668 —-a-w- c:\windows\system32\DeletedKey13.reg
2012-03-01 21:48:36 270 —-a-w- c:\windows\system32\DeletedKey12.reg
2012-03-01 21:48:16 732 —-a-w- c:\windows\system32\DeletedKey11.reg
2012-03-01 21:47:09 2956 —-a-w- c:\windows\system32\DeletedKey10.reg
2012-03-01 21:45:38 7152 —-a-w- c:\windows\system32\DeletedKey09.reg
2012-03-01 21:45:17 34560 —-a-w- c:\windows\system32\DeletedKey08.reg
2012-03-01 21:44:13 404 —-a-w- c:\windows\system32\DeletedKey07.reg
2012-03-01 21:43:56 404 —-a-w- c:\windows\system32\DeletedKey06.reg
2012-03-01 21:43:37 404 —-a-w- c:\windows\system32\DeletedKey05.reg
2012-03-01 21:41:28 2178 —-a-w- c:\windows\system32\DeletedKey04.reg
2012-03-01 21:40:42 13288 —-a-w- c:\windows\system32\DeletedKey03.reg
2012-03-01 21:39:57 3462 —-a-w- c:\windows\system32\DeletedKey02.reg
2012-03-01 21:10:53 1240 —-a-w- c:\windows\system32\DeletedKey01.reg
2012-02-29 15:32:50 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-28 01:18:55 1799168 —-a-w- c:\windows\system32\jscript9.dll
2012-02-28 01:11:21 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
2012-02-28 01:11:07 1127424 —-a-w- c:\windows\system32\wininet.dll
2012-02-28 01:03:16 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-02-14 17:09:44 1070352 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2012-02-14 15:45:30 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-02-14 15:45:30 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-02-13 14:12:08 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-02-13 13:47:57 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-02-13 13:44:40 1068544 —-a-w- c:\windows\system32\DWrite.dll
2012-02-02 15:16:25 2044416 —-a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 9:00:34.52 ===============

OTL logfile created on: 4/29/2012 8:45:32 PM - Run 4
OTL by OldTimer - Version 3.2.26.5 Folder = c:\Users\jtmeserole\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.18 Gb Available Physical Memory | 41.04% Memory free
5.95 Gb Paging File | 3.51 Gb Available in Paging File | 58.93% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.80 Gb Total Space | 152.20 Gb Free Space | 53.07% Space Free | Partition Type: NTFS
Drive D: | 11.28 Gb Total Space | 1.59 Gb Free Space | 14.08% Space Free | Partition Type: NTFS
Drive F: | 298.02 Gb Total Space | 163.62 Gb Free Space | 54.90% Space Free | Partition Type: FAT32

Computer Name: JTMESEROLE-PC | User Name: jtmeserole | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Norton 360\Engine\6.2.0.9\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Norton Online\Engine\2.3.0.7\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Windstream\Service Agent\Windstream Service AgentComHandler.exe (Radialpoint SafeCare Inc.)
PRC - C:\Program Files\Windstream\Service Agent\ServicepointService.exe (Radialpoint SafeCare Inc.)
PRC - C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe (Windstream)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\bfgclient\bfggameservices.exe ()
PRC - c:\Users\jtmeserole\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Users\safe kids\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LogitechUpdate.exe (Logitech, Inc.)
PRC - C:\Users\safe kids\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LULnchr.exe (Logitech, Inc.)
PRC - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe (Windstream)
PRC - C:\Program Files\Chocolatier - Decadence by Design\chocolatier-decadence.exe ()
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\HelpPane.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Norton Online\AddOns\Norton Safety Minder\Engine\2.3.0.18\wincfi39.dll ()


========== Win32 Services (SafeList) ==========

SRV - (sftlist) – File not found
SRV - (N360) – C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe (Symantec Corporation)
SRV - (Norton PC Checkup Application Launcher) – C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (NOF) – C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe (Symantec Corporation)
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (ServicepointService) – C:\Program Files\Windstream\Service Agent\ServicepointService.exe (Radialpoint SafeCare Inc.)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (UMVPFSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (PCCUJobMgr) – C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
SRV - (HsdService) – C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe (Windstream)
SRV - (GameConsoleService) – C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\Definitions\BASHDefs\20120413.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\N360\0602000.009\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\N360\0602000.009\SRTSPX.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\Definitions\IPSDefs\20120427.001\IDSvix86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\Definitions\VirusDefs\20120428.016\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\Definitions\VirusDefs\20120428.016\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\N360\0602000.009\SYMEFA.SYS (Symantec Corporation)
DRV - (SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}) – C:\Windows\System32\Drivers\NSM\0203000.012\SymRdr.SYS (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\System32\Drivers\N360\0602000.009\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\N360\0602000.009\Ironx86.SYS (Symantec Corporation)
DRV - (ccSet_N360) – C:\Windows\system32\drivers\N360\0602000.009\ccSetx86.sys (Symantec Corporation)
DRV - (ccSet_NOF) – C:\Windows\system32\drivers\NOF\0203000.007\ccSetx86.sys (Symantec Corporation)
DRV - (Sftvol) – C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (LVUVC) Logitech Webcam 250(UVC) – C:\Windows\System32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (SymDS) – C:\Windows\system32\drivers\N360\0602000.009\SYMDS.SYS (Symantec Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corporation)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (ElRawDisk) – C:\Windows\System32\drivers\rsdrv.sys (EldoS Corporation)
DRV - (nvrd32) – C:\Windows\system32\drivers\nvrd32.sys (NVIDIA Corporation)
DRV - (nvstor32) – C:\Windows\system32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (MHIKEY10) – C:\Windows\System32\drivers\MHIKEY10.sys (Generic USB smartcard reader)
DRV - (nvsmu) – C:\Windows\system32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (irsir) – C:\Windows\System32\drivers\irsir.sys (Microsoft Corporation)
DRV - (dsiarhwprog) – C:\Windows\System32\drivers\dsiarhwprog.sys (Thesycon GmbH, Germany)
DRV - (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM) – C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.ldsscripturemastery.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 98 7D 03 02 CE 6E E2 4D 9F 26 81 EE 65 AF 76 3D [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "www.google.com"
FF - prefs.js..browser.search.defaulturl: "Bing"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.ldsscripturemastery.net/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:5.0.1
FF - prefs.js..extensions.enabledItems: [removed]:2.3
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {000F1EA4-5E08-4564-A29B-29076F63A37A}:[removed]
FF - prefs.js..extensions.enabledItems: {6D5C8FC4-DE46-41bf-9092-93F0F78E9115}:2.1.0.51
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=113&systemid;=406&sr;=0&q;="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MI1933~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MI1933~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.18.9: C:\Program Files\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files\Windstream\Service Agent\nprpspa.dll (Windstream)
FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=6.2.0.88: C:\Program Files\Musicnotes\npsibelius.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll ()
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\jtmeserole\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\IPSFFPlgn\ [2012/02/29 16:11:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\coFFPlgn\ [2012/04/26 10:42:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}: C:\ProgramData\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.2.0.28\coFFFw\ [2012/04/26 10:42:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/03/28 10:30:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/19 06:38:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/09 21:25:10 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/03/28 10:30:49 | 000,000,000 | —D | M]

[2011/11/09 11:14:59 | 000,000,000 | —D | M] (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Extensions
[2012/04/25 18:38:57 | 000,000,000 | —D | M] (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions
[2011/02/19 18:48:33 | 000,000,000 | —D | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
[2010/09/27 21:35:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/04/21 18:35:30 | 000,000,000 | —D | M] (Bitdefender QuickScan) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/09/27 21:35:19 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2010/09/20 15:59:14 | 000,000,000 | —D | M] (KidZui) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2011/12/24 23:14:40 | 000,002,578 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\askcom.xml
[2011/09/07 18:07:40 | 000,001,945 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\bing-zugo.xml
[2010/12/01 18:51:50 | 000,000,927 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\conduit.xml
[2011/05/03 11:52:57 | 000,002,469 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\safesearch.xml
[2011/11/08 22:40:03 | 000,002,519 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\SearchResults.xml
[2012/01/13 17:53:52 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
[2012/02/29 16:11:43 | 000,000,000 | —D | M] (Norton Vulnerability Protection) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.1.2\IPSFFPLGN
[2012/04/26 10:42:15 | 000,000,000 | —D | M] (Norton Safety Minder) – C:\PROGRAMDATA\NORTON\{78CA3BF0-9C3B-40E1-B46D-38C877EF059A}\NSM_2.2.0.28\COFFFW
() (No name found) – C:\USERS\JTMESEROLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TKUCY2AP.DEFAULT\EXTENSIONS\{EF4E370E-D9F0-4E00-B93E-A4F274CFDD5A}.XPI
() (No name found) – C:\USERS\JTMESEROLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TKUCY2AP.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\JTMESEROLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TKUCY2AP.DEFAULT\EXTENSIONS\[removed]
[2012/03/19 06:38:43 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/09/29 16:30:47 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2011/07/13 16:52:56 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/03 06:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/07/13 16:52:58 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2010/03/31 11:09:22 | 010,437,264 | —- | M] (PDFTron Systems Inc.) – C:\Program Files\mozilla firefox\plugins\PDFNetC.dll
[2010/04/08 13:36:02 | 000,107,760 | —- | M] () – C:\Program Files\mozilla firefox\plugins\ScorchPDFWrapper.dll
[2011/08/01 23:22:34 | 000,002,226 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012/02/14 13:51:54 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/08/12 01:58:47 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml.old
[2011/11/08 22:40:03 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml
[2012/02/14 13:51:54 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2011/08/23 18:24:55 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\6.2.0.9\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\6.2.0.9\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Norton Safety Minder BHO) - {B8E07826-0971-4f16-B133-047B88034E89} - C:\Program Files\Norton Online\AddOns\Norton Safety Minder\Engine\2.3.0.18\coieplg.dll (Symantec Corporation)
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.2.0.9\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.2.0.9\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DiagnosticTools.exe] C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe (Windstream)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [UpdateLBPShortCut] c:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windstream Service Agent.exe] C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe (Windstream)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
O4 - Startup: C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Cabo.JPG
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Cabo.JPG
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/06/27 10:31:18 | 000,000,000 | —D | M] - F:\autorun – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: aux - wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi - wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - midimap.dll (Microsoft Corporation)
Drivers32: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32: MSVideo - vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - VfWWDM32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - lvcodec2.dll (Logitech Inc.)
Drivers32: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YUY2 - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - msyuv.dll (Microsoft Corporation)
Drivers32: wave - wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/04/20 15:26:11 | 000,000,000 | —D | C] – C:\Users\jtmeserole\Documents\OneNote Notebooks
[2012/04/11 03:16:53 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/04/11 03:16:52 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/04/11 03:16:51 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/04/11 03:16:51 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/04/11 03:16:51 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/04/11 03:16:50 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/04/11 03:13:51 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/04/11 03:13:50 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/04/07 09:37:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Celestia
[2012/04/07 09:36:55 | 000,000,000 | —D | C] – C:\Program Files\Celestia
[2012/03/26 10:22:17 | 035,113,704 | —- | C] (Microsoft Corporation) – C:\Program Files\Common Files\directx_9c_redist.exe
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\jtmeserole\Desktop\*.tmp files -> C:\Users\jtmeserole\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/04/29 20:42:39 | 000,003,616 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/29 20:42:39 | 000,003,616 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/29 18:55:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/29 18:00:00 | 000,000,452 | —- | M] () – C:\Windows\tasks\ParetoLogic Registration.job
[2012/04/29 11:55:00 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/26 10:48:05 | 000,604,708 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/04/26 10:48:05 | 000,104,150 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/04/26 10:41:54 | 000,065,536 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2012/04/26 10:41:34 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/04/25 13:48:41 | 000,002,045 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2012/04/25 13:48:11 | 002,188,162 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\Cat.DB
[2012/04/25 13:47:32 | 000,008,942 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\VT20120410.034
[2012/04/25 13:45:06 | 000,000,912 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/20 15:51:42 | 000,431,713 | —- | M] () – C:\Users\jtmeserole\Desktop\additional work experience.rtf
[2012/04/20 15:26:17 | 000,001,103 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2012/04/18 22:48:26 | 000,000,172 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\isolate.ini
[2012/04/16 20:17:58 | 000,001,977 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/04/07 09:37:00 | 000,000,810 | —- | M] () – C:\Users\jtmeserole\Desktop\Celestia.lnk
[2012/04/06 16:07:42 | 000,000,000 | —- | M] () – C:\Windows\System32\drivers\lvuvc.hs
[2012/04/04 18:44:36 | 000,029,234 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\wklnhst.dat
[2012/04/04 15:56:40 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2012/04/04 11:23:33 | 000,011,208 | —- | M] () – C:\Users\jtmeserole\Documents\stop it.jpg
[2012/04/04 10:42:41 | 000,110,898 | —- | M] () – C:\Users\jtmeserole\Documents\Cookbook for Missionary.pdf
[2012/04/03 20:43:49 | 000,007,454 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\srtspx.cat
[2012/04/03 20:43:49 | 000,007,450 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\srtsp.cat
[2012/04/03 20:43:49 | 000,001,388 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\srtspx.inf
[2012/04/03 20:43:49 | 000,001,388 | —- | M] () – C:\Windows\System32\drivers\N360\0602000.009\srtsp.inf
[2012/04/01 21:55:54 | 000,003,021 | —- | M] () – C:\Users\jtmeserole\Documents\brisingr sword.jpg
[2012/03/31 13:54:49 | 000,002,570 | —- | M] () – C:\Users\jtmeserole\Documents\banana.jpg
[2012/03/31 13:53:36 | 000,000,536 | —- | M] () – C:\Users\jtmeserole\Desktop\httpwww.google.comimgresq=banana+avatar&um;=1&hl;=en&safe;=active&client;=firefox-a&rls;=org.mozillaen-USofficial&biw;=595&bih;=100.URL
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\jtmeserole\Desktop\*.tmp files -> C:\Users\jtmeserole\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/04/20 15:51:42 | 000,431,713 | —- | C] () – C:\Users\jtmeserole\Desktop\additional work experience.rtf
[2012/04/20 15:26:17 | 000,001,103 | —- | C] () – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2012/04/07 09:37:00 | 000,000,810 | —- | C] () – C:\Users\jtmeserole\Desktop\Celestia.lnk
[2012/04/04 11:23:32 | 000,011,208 | —- | C] () – C:\Users\jtmeserole\Documents\stop it.jpg
[2012/04/04 10:42:40 | 000,110,898 | —- | C] () – C:\Users\jtmeserole\Documents\Cookbook for Missionary.pdf
[2012/04/01 21:55:53 | 000,003,021 | —- | C] () – C:\Users\jtmeserole\Documents\brisingr sword.jpg
[2012/03/31 13:54:45 | 000,002,570 | —- | C] () – C:\Users\jtmeserole\Documents\banana.jpg
[2012/03/31 13:53:36 | 000,000,536 | —- | C] () – C:\Users\jtmeserole\Desktop\httpwww.google.comimgresq=banana+avatar&um;=1&hl;=en&safe;=active&client;=firefox-a&rls;=org.mozillaen-USofficial&biw;=595&bih;=100.URL
[2012/02/29 10:51:38 | 000,000,022 | —- | C] () – C:\Windows\WinInit.Ini
[2012/02/29 10:51:28 | 000,168,207 | —- | C] () – C:\Windows\System32\Unstall.exe
[2011/08/20 16:04:22 | 000,150,004 | —- | C] () – C:\Windows\System32\mlfcache.dat
[2011/08/19 04:26:20 | 010,898,456 | —- | C] () – C:\Windows\System32\LogiDPP.dll
[2011/08/19 04:26:20 | 000,336,408 | —- | C] () – C:\Windows\System32\DevManagerCore.dll
[2011/08/19 04:26:20 | 000,104,472 | —- | C] () – C:\Windows\System32\LogiDPPApp.exe
[2011/08/12 13:20:14 | 000,015,896 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2011/07/26 01:48:54 | 000,028,418 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2011/05/22 17:10:50 | 000,069,632 | —- | C] () – C:\Windows\System32\MobOlExt.dll
[2011/05/15 19:27:51 | 000,000,092 | -HS- | C] () – C:\Windows\WSYS049.SYS
[2011/05/15 19:26:24 | 000,199,297 | —- | C] () – C:\Windows\Photo Pos Pro Uninstaller.exe
[2011/03/28 10:52:04 | 000,171,321 | —- | C] () – C:\Windows\hpwins27.dat.temp
[2011/03/28 10:52:04 | 000,000,385 | —- | C] () – C:\Windows\hpwmdl27.dat.temp
[2011/03/28 10:20:22 | 000,170,596 | —- | C] () – C:\Windows\hpwins27.dat
[2011/02/12 22:26:46 | 000,000,048 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/01/11 20:33:13 | 000,262,144 | —- | C] () – C:\Windows\System32\lame_enc.dll
[2010/09/25 19:46:40 | 000,054,784 | —- | C] () – C:\Users\jtmeserole\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/24 12:10:20 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/09/24 12:10:20 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/09/22 23:41:23 | 000,029,234 | —- | C] () – C:\Users\jtmeserole\AppData\Roaming\wklnhst.dat
[2010/09/20 13:18:13 | 000,001,356 | —- | C] () – C:\Users\jtmeserole\AppData\Local\d3d9caps.dat
[2010/04/06 05:10:15 | 000,225,411 | —- | C] () – C:\Windows\System32\PosPrKpLib.dll
[2010/04/06 05:10:07 | 000,020,480 | —- | C] () – C:\Windows\System32\PosTickerLib.dll
[2009/08/18 11:11:03 | 000,000,385 | —- | C] () – C:\Windows\hpwmdl27.dat
[2009/05/18 15:36:28 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/05/18 15:06:49 | 000,354,816 | —- | C] () – C:\Windows\System32\pythoncom26.dll
[2009/05/18 15:06:49 | 000,108,032 | —- | C] () – C:\Windows\System32\pywintypes26.dll
[2009/01/05 16:44:10 | 000,053,248 | —- | C] () – C:\Windows\bdoscandel.exe
[2009/01/05 16:44:10 | 000,000,453 | —- | C] () – C:\Windows\bdoscandellang.ini
[2006/11/02 07:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,381,240 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,604,708 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,104,150 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 05:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2005/09/23 06:52:14 | 000,078,848 | —- | C] () – C:\Windows\System32\OneWay.dll
[2002/06/02 09:05:40 | 000,038,912 | —- | C] () – C:\Windows\System32\1Way.dll

========== LOP Check ==========

[2011/09/23 11:48:03 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\.t4k_common
[2011/03/02 20:50:37 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\2monkeys
[2012/03/25 18:22:23 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Audacity
[2011/09/29 16:30:47 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Catalina Marketing Corp
[2011/05/30 17:30:34 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Chessmaster Challenge
[2011/04/10 14:35:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Farm Mania 2.1
[2012/04/11 08:16:45 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Free Download Manager
[2011/01/24 21:48:39 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\freshgames
[2011/09/07 18:15:19 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Guitar Pro 6
[2011/10/17 22:06:00 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\KidZui
[2011/12/11 17:31:28 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Leadertech
[2011/03/03 13:06:46 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Mean Hamster
[2011/03/01 11:52:31 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MSNInstaller
[2010/10/15 17:58:10 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MusE
[2010/11/05 18:54:16 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MusicNet
[2011/02/12 12:24:20 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\NCH Swift Sound
[2010/12/15 14:38:17 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Oberon Games
[2010/09/20 13:12:56 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\PictureMover
[2011/12/04 21:38:09 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\PlayFirst
[2012/04/25 15:30:42 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\QuickScan
[2012/04/17 01:24:17 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Radialpoint
[2012/02/27 16:38:58 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\School Zone Preferences
[2010/10/19 11:23:24 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Skunk Studios
[2012/02/28 11:30:52 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\SoftGrid Client
[2012/03/26 09:53:35 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Stellarium
[2012/03/08 13:16:04 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Super-Cow
[2011/01/25 21:26:00 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Supermarket Mania 2
[2010/09/22 23:41:24 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Template
[2011/09/30 18:21:20 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Tific
[2012/03/01 18:12:26 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\TP
[2012/02/10 16:33:14 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\tuxmath
[2010/09/27 15:17:15 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Unity
[2010/10/18 07:10:46 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\WildTangent
[2012/01/17 21:37:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Windstream
[2010/10/15 20:20:28 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\YoudaGames
[2012/04/29 18:00:00 | 000,000,452 | —- | M] () – C:\Windows\Tasks\ParetoLogic Registration.job
[2012/04/25 22:31:07 | 000,032,594 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/05/18 15:28:11 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2011/08/23 18:27:33 | 000,013,301 | —- | M] () – C:\ComboFix.txt
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/09/07 12:57:44 | 000,000,000 | —- | M] () – C:\FileRecovery.log
[2012/02/28 13:03:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/02/28 13:03:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/04/26 10:41:17 | 3399,237,632 | -HS- | M] () – C:\pagefile.sys
[2011/10/02 13:04:55 | 000,000,414 | —- | M] () – C:\TDSSKiller.2.5.15.0_02.10.2011_13.04.45_log.txt
[2011/08/17 20:34:46 | 000,065,814 | —- | M] () – C:\TDSSKiller.2.5.15.0_17.08.2011_20.33.13_log.txt
[2011/10/02 13:07:17 | 000,076,732 | —- | M] () – C:\TDSSKiller.2.6.2.0_02.10.2011_13.05.34_log.txt
[2009/05/18 15:31:49 | 000,000,349 | —- | M] () – C:\updatedatfix.log
[2008/08/26 07:37:52 | 000,000,458 | —- | M] () – C:\Windows Sidebar

< %systemroot%\Fonts\*.com >
[2006/11/02 07:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/12/21 12:24:56 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/04/20 12:23:48 | 000,315,904 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpfpp70w.dll
[2008/01/20 21:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 07:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 21:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 22:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 22:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 22:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/20 08:09:26 | 000,000,351 | -HS- | M] () – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/08/17 20:23:28 | 001,404,720 | —- | M] (Kaspersky Lab ZAO) – C:\Users\jtmeserole\Desktop\12345.com.exe
[2011/08/20 15:55:47 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\jtmeserole\Desktop\ATF_Cleaner.exe
[2011/09/23 11:35:12 | 021,091,562 | —- | M] () – C:\Users\jtmeserole\Desktop\tuxmath-2.0.3-win32-installer.exe
[1 C:\Users\jtmeserole\Desktop\*.tmp files -> C:\Users\jtmeserole\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >
[2012/03/26 10:22:17 | 035,113,704 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\directx_9c_redist.exe

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-04-11 08:17:22

========== Alternate Data Streams ==========

@Alternate Data Stream - 249 bytes -> C:\ProgramData\Temp:EAEE7554
@Alternate Data Stream - 241 bytes -> C:\ProgramData\Temp:05F547A9
@Alternate Data Stream - 235 bytes -> C:\ProgramData\Temp:4B244549
@Alternate Data Stream - 232 bytes -> C:\ProgramData\Temp:76466F4C
@Alternate Data Stream - 228 bytes -> C:\ProgramData\Temp:E5F8E280
@Alternate Data Stream - 228 bytes -> C:\ProgramData\Temp:453190EC
@Alternate Data Stream - 226 bytes -> C:\ProgramData\Temp:2C678471
@Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:CFF6B3FF
@Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:217A2A36
@Alternate Data Stream - 223 bytes -> C:\ProgramData\Temp:162E02F7
@Alternate Data Stream - 221 bytes -> C:\ProgramData\Temp:ED9B661E
@Alternate Data Stream - 215 bytes -> C:\ProgramData\Temp:CF61CE5A
@Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:966CEAE7
@Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:90015502
@Alternate Data Stream - 213 bytes -> C:\ProgramData\Temp:6677D85A
@Alternate Data Stream - 213 bytes -> C:\ProgramData\Temp:517B507A
@Alternate Data Stream - 208 bytes -> C:\ProgramData\Temp:FEEEFFAD
@Alternate Data Stream - 208 bytes -> C:\ProgramData\Temp:969C0C96
@Alternate Data Stream - 207 bytes -> C:\ProgramData\Temp:C60FAC5D
@Alternate Data Stream - 207 bytes -> C:\ProgramData\Temp:10D98D98
@Alternate Data Stream - 206 bytes -> C:\ProgramData\Temp:1663E41B
@Alternate Data Stream - 195 bytes -> C:\ProgramData\Temp:A1D3FEF0
@Alternate Data Stream - 158 bytes -> C:\ProgramData\Temp:6B708944
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:DE6EED8B
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:9D03192E
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:A1023D41
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:4149A170
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:C9B27A06
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:8CCDAB14
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:93B0BB6F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:EC2E1DEC
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:00811B66
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:A4BF246C
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:02A78DF6
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:073139EC
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:8DD36B71
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:08801FDB
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:A00BCDEF
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:D1B5B4F1
@Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:FBFC061F
@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:E73B14E2

< End of report >

thanks!

Attachments:

Hi computerwannabe,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

It looks like you've picked up a searchqu infection. Let's rip it out of there…

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes

:OTL
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=113&systemid=406&sr=0&q="
[2010/12/01 18:51:50 | 000,000,927 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\conduit.xml
[2011/11/08 22:40:03 | 000,002,519 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\SearchResults.xml
[2011/09/29 16:30:47 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2011/07/13 16:52:56 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/07/13 16:52:58 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/08/01 23:22:34 | 000,002,226 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011/11/08 22:40:03 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
@Alternate Data Stream - 249 bytes -> C:\ProgramData\Temp:EAEE7554
@Alternate Data Stream - 241 bytes -> C:\ProgramData\Temp:05F547A9
@Alternate Data Stream - 235 bytes -> C:\ProgramData\Temp:4B244549
@Alternate Data Stream - 232 bytes -> C:\ProgramData\Temp:76466F4C
@Alternate Data Stream - 228 bytes -> C:\ProgramData\Temp:E5F8E280
@Alternate Data Stream - 228 bytes -> C:\ProgramData\Temp:453190EC
@Alternate Data Stream - 226 bytes -> C:\ProgramData\Temp:2C678471
@Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:CFF6B3FF
@Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:217A2A36
@Alternate Data Stream - 223 bytes -> C:\ProgramData\Temp:162E02F7
@Alternate Data Stream - 221 bytes -> C:\ProgramData\Temp:ED9B661E
@Alternate Data Stream - 215 bytes -> C:\ProgramData\Temp:CF61CE5A
@Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:966CEAE7
@Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:90015502
@Alternate Data Stream - 213 bytes -> C:\ProgramData\Temp:6677D85A
@Alternate Data Stream - 213 bytes -> C:\ProgramData\Temp:517B507A
@Alternate Data Stream - 208 bytes -> C:\ProgramData\Temp:FEEEFFAD
@Alternate Data Stream - 208 bytes -> C:\ProgramData\Temp:969C0C96
@Alternate Data Stream - 207 bytes -> C:\ProgramData\Temp:C60FAC5D
@Alternate Data Stream - 207 bytes -> C:\ProgramData\Temp:10D98D98
@Alternate Data Stream - 206 bytes -> C:\ProgramData\Temp:1663E41B
@Alternate Data Stream - 195 bytes -> C:\ProgramData\Temp:A1D3FEF0
@Alternate Data Stream - 158 bytes -> C:\ProgramData\Temp:6B708944
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:DE6EED8B
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:9D03192E
@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:A1023D41
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:4149A170
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:C9B27A06
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:8CCDAB14
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:93B0BB6F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:EC2E1DEC
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:00811B66
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:A4BF246C
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:02A78DF6
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:073139EC
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:8DD36B71
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:08801FDB
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:A00BCDEF
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:D1B5B4F1
@Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:FBFC061F
@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:E73B14E2

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.
Thank you! Here is the log of the OTL fix: All processes killed ========== PROCESSES ========== ========== OTL ========== Prefs.js: "http://dts.search-results.com/sr?src=ffb&appid=113&systemid=406&sr=0&q=" removed from keyword.URL C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\conduit.xml moved successfully. C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\SearchResults.xml moved successfully. C:\Program Files\Mozilla Firefox\plugins\NPcol400.dll moved successfully. C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll moved successfully. C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll moved successfully. C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml moved successfully. C:\Program Files\Mozilla Firefox\searchplugins\SearchResults.xml moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found. ADS C:\ProgramData\Temp:EAEE7554 deleted successfully. ADS C:\ProgramData\Temp:05F547A9 deleted successfully. ADS C:\ProgramData\Temp:4B244549 deleted successfully. ADS C:\ProgramData\Temp:76466F4C deleted successfully. ADS C:\ProgramData\Temp:E5F8E280 deleted successfully. ADS C:\ProgramData\Temp:453190EC deleted successfully. ADS C:\ProgramData\Temp:2C678471 deleted successfully. ADS C:\ProgramData\Temp:CFF6B3FF deleted successfully. ADS C:\ProgramData\Temp:217A2A36 deleted successfully. ADS C:\ProgramData\Temp:162E02F7 deleted successfully. ADS C:\ProgramData\Temp:ED9B661E deleted successfully. ADS C:\ProgramData\Temp:CF61CE5A deleted successfully. ADS C:\ProgramData\Temp:966CEAE7 deleted successfully. ADS C:\ProgramData\Temp:90015502 deleted successfully. ADS C:\ProgramData\Temp:6677D85A deleted successfully. ADS C:\ProgramData\Temp:517B507A deleted successfully. ADS C:\ProgramData\Temp:FEEEFFAD deleted successfully. ADS C:\ProgramData\Temp:969C0C96 deleted successfully. ADS C:\ProgramData\Temp:C60FAC5D deleted successfully. ADS C:\ProgramData\Temp:10D98D98 deleted successfully. ADS C:\ProgramData\Temp:1663E41B deleted successfully. ADS C:\ProgramData\Temp:A1D3FEF0 deleted successfully. ADS C:\ProgramData\Temp:6B708944 deleted successfully. ADS C:\ProgramData\Temp:DE6EED8B deleted successfully. ADS C:\ProgramData\Temp:9D03192E deleted successfully. ADS C:\ProgramData\Temp:A1023D41 deleted successfully. ADS C:\ProgramData\Temp:4149A170 deleted successfully. ADS C:\ProgramData\Temp:C9B27A06 deleted successfully. ADS C:\ProgramData\Temp:8CCDAB14 deleted successfully. ADS C:\ProgramData\Temp:93B0BB6F deleted successfully. ADS C:\ProgramData\Temp:EC2E1DEC deleted successfully. ADS C:\ProgramData\Temp:00811B66 deleted successfully. ADS C:\ProgramData\Temp:A4BF246C deleted successfully. ADS C:\ProgramData\Temp:02A78DF6 deleted successfully. ADS C:\ProgramData\Temp:073139EC deleted successfully. ADS C:\ProgramData\Temp:8DD36B71 deleted successfully. ADS C:\ProgramData\Temp:08801FDB deleted successfully. ADS C:\ProgramData\Temp:A00BCDEF deleted successfully. ADS C:\ProgramData\Temp:D1B5B4F1 deleted successfully. ADS C:\ProgramData\Temp:FBFC061F deleted successfully. ADS C:\ProgramData\Temp:E73B14E2 deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56504 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: jtmeserole ->Temp folder emptied: 4975772 bytes ->Temporary Internet Files folder emptied: 769759 bytes ->Java cache emptied: 3014720 bytes ->FireFox cache emptied: 181159084 bytes ->Google Chrome cache emptied: 419171446 bytes ->Apple Safari cache emptied: 3732480 bytes ->Flash cache emptied: 2878587 bytes User: Nice ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 47845531 bytes ->FireFox cache emptied: 28711603 bytes ->Flash cache emptied: 59686 bytes User: Public User: s ->Temp folder emptied: 362945 bytes ->Temporary Internet Files folder emptied: 3663321 bytes ->FireFox cache emptied: 103041736 bytes ->Flash cache emptied: 58513 bytes User: safe kids ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 938 bytes ->Java cache emptied: 346854 bytes ->FireFox cache emptied: 49241378 bytes ->Google Chrome cache emptied: 14360263 bytes ->Flash cache emptied: 245164 bytes User: seminary ->Temp folder emptied: 33280 bytes ->Temporary Internet Files folder emptied: 871 bytes ->Java cache emptied: 572161 bytes ->FireFox cache emptied: 427296892 bytes ->Google Chrome cache emptied: 14247518 bytes ->Flash cache emptied: 72936 bytes User: What ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 4102848 bytes ->FireFox cache emptied: 66393288 bytes ->Flash cache emptied: 59479 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 1183 bytes %systemroot%\System32 .tmp files removed: 26624 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2239 bytes RecycleBin emptied: 128011429 bytes Total Files Cleaned = 1,435.00 mb OTL by OldTimer - Version 3.2.26.5 log created on 05042012_093748 Files\Folders moved on Reboot… File\Folder C:\Windows\temp\NSM-{F71C8917-4589-4C45-BB24-C1944D0908B8}.dat not found! Registry entries deleted on Reboot…
Good. Now let's do this.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Right click on ComboFix.exe & select "Run as Administrator"
  • Follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 12-05-04.03 - jtmeserole 05/04/2012 15:29:50.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1243 [GMT -5:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\jtmeserole\AppData\Roaming\Microsoft\Windows\Recent\httpwww.google.comimgresq=banana+avatar&um=1&hl=en&safe=active&client=firefox-a&rls=org.mozillaen-USofficial&biw=595&bih=100.URL
c:\users\seminary\lame_enc_en.dll
c:\users\seminary\lametritonus_en.dll
F:\setup.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-04-04 to 2012-05-04 )))))))))))))))))))))))))))))))
.
.
2012-05-04 20:38 . 2012-05-04 20:38 ——– d—–w- c:\users\safe kids\AppData\Local\temp
2012-05-04 20:38 . 2012-05-04 20:38 ——– d—–w- c:\users\What\AppData\Local\temp
2012-05-01 00:58 . 2012-05-01 00:58 ——– d—–w- c:\windows\system32\drivers\NSM\0203000.013
2012-04-23 23:02 . 2012-04-25 18:47 ——– d—–w- c:\windows\system32\drivers\N360\0602000.009
2012-04-11 08:14 . 2012-02-29 15:11 5120 —-a-w- c:\windows\system32\wmi.dll
2012-04-11 08:14 . 2012-02-29 15:11 172032 —-a-w- c:\windows\system32\wintrust.dll
2012-04-11 08:14 . 2012-02-29 15:09 157696 —-a-w- c:\windows\system32\imagehlp.dll
2012-04-11 08:14 . 2012-02-29 13:32 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-11 08:13 . 2012-03-06 06:39 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-04-11 08:13 . 2012-03-06 06:39 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-11 06:39 . 2012-03-01 11:01 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-04-07 14:36 . 2012-04-07 14:37 ——– d—–w- c:\program files\Celestia
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-04 20:56 . 2010-11-26 20:52 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-03-26 15:22 . 2012-03-26 15:22 35113704 —-a-w- c:\program files\Common Files\directx_9c_redist.exe
2012-03-23 18:42 . 2010-09-22 16:15 141944 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-03-01 22:53 . 2012-03-01 22:53 1576 —-a-w- c:\windows\system32\DeletedKey21.reg
2012-03-01 22:51 . 2012-03-01 22:51 348722 —-a-w- c:\windows\system32\DeletedKey20.reg
2012-03-01 22:50 . 2012-03-01 22:50 83578 —-a-w- c:\windows\system32\DeletedKey19.reg
2012-03-01 21:54 . 2012-03-01 21:54 565410 —-a-w- c:\windows\system32\uninstallkey01.reg
2012-03-01 21:51 . 2012-03-01 21:51 318 —-a-w- c:\windows\system32\DeletedKey18.reg
2012-03-01 21:51 . 2012-03-01 21:51 318 —-a-w- c:\windows\system32\DeletedKey17.reg
2012-03-01 21:50 . 2012-03-01 21:50 318 —-a-w- c:\windows\system32\DeletedKey16.reg
2012-03-01 21:50 . 2012-03-01 21:50 3518 —-a-w- c:\windows\system32\DeletedKey15.reg
2012-03-01 21:50 . 2012-03-01 21:50 8856 —-a-w- c:\windows\system32\DeletedKey14.reg
2012-03-01 21:48 . 2012-03-01 21:48 1668 —-a-w- c:\windows\system32\DeletedKey13.reg
2012-03-01 21:48 . 2012-03-01 21:48 270 —-a-w- c:\windows\system32\DeletedKey12.reg
2012-03-01 21:48 . 2012-03-01 21:48 732 —-a-w- c:\windows\system32\DeletedKey11.reg
2012-03-01 21:47 . 2012-03-01 21:47 2956 —-a-w- c:\windows\system32\DeletedKey10.reg
2012-03-01 21:45 . 2012-03-01 21:45 7152 —-a-w- c:\windows\system32\DeletedKey09.reg
2012-03-01 21:45 . 2012-03-01 21:45 34560 —-a-w- c:\windows\system32\DeletedKey08.reg
2012-03-01 21:44 . 2012-03-01 21:44 404 —-a-w- c:\windows\system32\DeletedKey07.reg
2012-03-01 21:43 . 2012-03-01 21:43 404 —-a-w- c:\windows\system32\DeletedKey06.reg
2012-03-01 21:43 . 2012-03-01 21:43 404 —-a-w- c:\windows\system32\DeletedKey05.reg
2012-03-01 21:41 . 2012-03-01 21:41 2178 —-a-w- c:\windows\system32\DeletedKey04.reg
2012-03-01 21:40 . 2012-03-01 21:40 13288 —-a-w- c:\windows\system32\DeletedKey03.reg
2012-03-01 21:39 . 2012-03-01 21:39 3462 —-a-w- c:\windows\system32\DeletedKey02.reg
2012-03-01 21:10 . 2012-03-01 21:10 1240 —-a-w- c:\windows\system32\DeletedKey01.reg
2012-02-29 15:32 . 2011-06-30 17:17 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-20 09:02 . 2012-02-20 09:02 86528 —-a-w- c:\windows\system32\iesysprep.dll
2012-02-20 09:02 . 2012-02-20 09:02 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-02-20 09:02 . 2012-02-20 09:02 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-02-20 09:02 . 2012-02-20 09:02 63488 —-a-w- c:\windows\system32\tdc.ocx
2012-02-20 09:02 . 2012-02-20 09:02 48640 —-a-w- c:\windows\system32\mshtmler.dll
2012-02-20 09:02 . 2012-02-20 09:02 367104 —-a-w- c:\windows\system32\html.iec
2012-02-20 09:02 . 2012-02-20 09:02 161792 —-a-w- c:\windows\system32\msls31.dll
2012-02-20 09:02 . 2012-02-20 09:02 74752 —-a-w- c:\windows\system32\iesetup.dll
2012-02-20 09:02 . 2012-02-20 09:02 420864 —-a-w- c:\windows\system32\vbscript.dll
2012-02-20 09:02 . 2012-02-20 09:02 23552 —-a-w- c:\windows\system32\licmgr10.dll
2012-02-20 09:02 . 2012-02-20 09:02 152064 —-a-w- c:\windows\system32\wextract.exe
2012-02-20 09:02 . 2012-02-20 09:02 150528 —-a-w- c:\windows\system32\iexpress.exe
2012-02-20 09:02 . 2012-02-20 09:02 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-02-20 09:02 . 2012-02-20 09:02 11776 —-a-w- c:\windows\system32\mshta.exe
2012-02-20 09:02 . 2012-02-20 09:02 101888 —-a-w- c:\windows\system32\admparse.dll
2012-02-20 09:02 . 2012-02-20 09:02 35840 —-a-w- c:\windows\system32\imgutil.dll
2012-02-20 09:02 . 2012-02-20 09:02 110592 —-a-w- c:\windows\system32\IEAdvpack.dll
2012-02-14 17:09 . 2012-02-14 17:09 1070352 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2012-02-14 15:45 . 2012-03-14 00:40 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-02-14 15:45 . 2012-03-14 00:40 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-02-13 14:12 . 2012-03-14 00:40 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-02-13 13:47 . 2012-03-14 00:40 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-02-13 13:44 . 2012-03-14 00:40 1068544 —-a-w- c:\windows\system32\DWrite.dll
2010-03-31 16:09 . 2010-03-31 16:09 10437264 —-a-w- c:\program files\mozilla firefox\plugins\PDFNetC.dll
2010-04-08 18:36 . 2010-04-08 18:36 107760 —-a-w- c:\program files\mozilla firefox\plugins\ScorchPDFWrapper.dll
2012-03-19 11:38 . 2011-03-24 15:54 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2011-12-28 6148096]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-08 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-08 92704]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-12-04 218408]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-12-04 218408]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-12-04 218408]
"UpdatePSTShortCut"="c:\program files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" [2009-02-02 210216]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-08-12 205336]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-12-08 421736]
"Windstream Service Agent.exe"="c:\program files\Windstream\Service Agent\Windstream Service Agent.exe" [2011-10-14 10204472]
"DiagnosticTools.exe"="c:\program files\Windstream\Diagnostic Tools\DiagnosticTools.exe" [2011-04-25 2037048]
.
c:\users\seminary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [N/A]
.
c:\users\jtmeserole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HsdService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\prwntdrv]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ServicepointService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-11 01:23]
.
2012-05-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-11 01:23]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MI1933~1\Office14\ONBttnIE.dll/105
LSP: c:\windows\system32\wpclsp.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.254.254
FF - ProfilePath - c:\users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\
FF - prefs.js: browser.search.defaulturl - Bing
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.ldsscripturemastery.net/
FF - prefs.js: network.proxy.type - 0
FF - user.js: extentions.y2layers.installId - 1132a82e-f3dd-43a0-b9bf-af81c9d2c769
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
WebBrowser-{C2DB4FE6-8409-45CE-8010-189A7B5CCE86} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
AddRemove-BFG-Wedding Dash - Ready, Aim, Love - c:\program files\Wedding Dash - Ready
AddRemove-FoxTab Music Converter - c:\program files\FoxTabMusicConverter\Uninstall\Uninstall.exe
AddRemove-RadialpointServicepointDashboardExtensions_is1 - c:\users\JTMESE~1\AppData\Local\Temp\is-BREE3.tmp\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-05-04 15:38
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\6.2.0.9\diMaster.dll\" /prefetch:1"
–
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NOF]
"ImagePath"="\"c:\program files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe\" /s \"NOF\" /m \"c:\program files\Norton Online\Engine\2.3.0.7\diMaster.dll\" /prefetch:1"
–
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCCUJobMgr]
"ImagePath"="\"c:\program files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files\Norton PC Checkup\Engine\2.0.12.27\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2012-05-04 15:40:23
ComboFix-quarantined-files.txt 2012-05-04 20:40
ComboFix2.txt 2011-08-23 23:27
.
Pre-Run: 166,508,482,560 bytes free
Post-Run: 165,924,020,224 bytes free
.
- - End Of File - - AEDFDFEF1686E6E5FBBD0E90A91B8BA6
Looking good.

Let's get an online scan.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
It didn't give me an option to save a logfile, only to export the threat info to a .txt file. This is what it contained: F:\MEESHAMESERO-PC\Backup Set 2010-12-21 183027\Backup Files 2010-12-21 183027\Backup files 18.zip multiple threats
Still slow. Websites are slow to load. When I click on a link it takes longer than it used to for the page to change and will often hang with a blank screen until it is able to load. It happens with Google Chrome, Firefox, and IE, and it often leads to the browser "not responding" . It will unfreeze when the page loads.
This time it ran much faster than last time. I did look around a little bit more in Norton 360 and found more things to turn off before running it, so maybe that is why it took such little time (like 1 minute or less.) to scan. DDS (Ver_2011-06-23.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29 Run by [removed] at 7:24:03 on 2012-05-08 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1511 [GMT -5:00] . AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\LSI SoftModem\agrsmsvc.exe C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Windstream\Service Agent\ServicepointService.exe C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe C:\Program Files\Norton Online\Engine\2.3.0.7\ccSvcHst.exe C:\Program Files\Norton 360\Engine\6.2.0.9\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\rundll32.exe C:\Windows\System32\wpcumi.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Free Download Manager\fdm.exe C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\ehome\ehmsas.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\iPod\bin\iPodService.exe C:\Users\jtmeserole\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LULnchr.exe C:\Users\jtmeserole\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LogitechUpdate.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.co.uk/ BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\6.2.0.9\coIEPlg.dll BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\6.2.0.9\ips\IPSBHO.DLL BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mi1933~1\office14\URLREDIR.DLL BHO: Norton Safety Minder BHO: {b8e07826-0971-4f16-b133-047b88034e89} - c:\program files\norton online\addons\norton safety minder\engine\2.3.0.19\coIEPlg.dll BHO: Free Download Manager: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\6.2.0.9\coIEPlg.dll EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Free Download Manager] "c:\program files\free download manager\fdm.exe" -autorun uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0" mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5" mRun: [UpdatePDIRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0" mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\cyberlink dvd suite deluxe\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\cyberlink dvd suite deluxe" updatewithcreateonce "software\cyberlink\PowerStarter" mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Windstream Service Agent.exe] "c:\program files\windstream\service agent\Windstream Service Agent.exe" /AUTORUN mRun: [DiagnosticTools.exe] "c:\program files\windstream\diagnostic tools\DiagnosticTools.exe" /AUTORUN StartupFolder: c:\users\jtmese~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office14\ONENOTEM.EXE mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\mi1933~1\office14\ONBttnIE.dll/105 IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll LSP: c:\windows\system32\wpclsp.dll Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab TCP: DhcpNameServer = 192.168.254.254 TCP: Interfaces\{DC2E7865-5ADB-466A-9527-0EFA9B7FF184} : DhcpNameServer = 192.168.254.254 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\jtmeserole\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\ FF - prefs.js: browser.search.defaulturl - Bing FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.ldsscripturemastery.net/ FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\progra~1\mi1933~1\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\mi1933~1\office14\NPSPWRAP.DLL FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\musicnotes\npmusicn.dll FF - plugin: c:\program files\musicnotes\NPSibelius.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\program files\windstream\service agent\nprpspa.dll FF - plugin: c:\users\jtmeserole\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\users\jtmeserole\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\extensions\{000f1ea4-5e08-4564-a29b-29076f63a37a}\plugins\npsoe.dll FF - plugin: c:\users\jtmeserole\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll . —- FIREFOX POLICIES —- FF - user.js: extentions.y2layers.installId - 1132a82e-f3dd-43a0-b9bf-af81c9d2c769 . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0602000.009\symds.sys [2012-4-23 340088] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0602000.009\symefa.sys [2012-4-23 905336] R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.0.1.2\definitions\bashdefs\20120413.001\BHDrvx86.sys [2012-4-19 821880] R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\n360\0602000.009\ccsetx86.sys [2012-4-23 132744] R1 ccSet_NOF;Norton Online Settings Manager;c:\windows\system32\drivers\nof\0203000.007\ccsetx86.sys [2012-2-9 132744] R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\rsdrv.sys [2011-9-7 22312] R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.0.1.2\definitions\ipsdefs\20120507.001\IDSvix86.sys [2012-5-7 368248] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0602000.009\ironx86.sys [2012-4-23 149624] R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0602000.009\symtdiv.sys [2012-4-23 345208] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 HsdService;HsdService;c:\program files\windstream\diagnostic tools\HsdService.exe [2012-1-17 1393976] R2 N360;Norton 360;c:\program files\norton 360\engine\6.2.0.9\ccsvchst.exe [2012-4-23 138232] R2 NOF;Norton Online;c:\program files\norton online\engine\2.3.0.7\ccsvchst.exe [2012-2-9 138248] R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\norton pc checkup\engine\2.0.12.27\SymcPCCULaunchSvc.exe [2011-9-30 135608] R2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\norton pc checkup\engine\2.0.12.27\ccSvcHst.exe [2011-9-30 126392] R2 ServicepointService;ServicepointService;c:\program files\windstream\service agent\ServicepointService.exe [2012-1-17 10315064] R2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-8-19 450848] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-5-4 106104] R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2011-10-1 579944] R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2011-10-1 194408] R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2011-10-1 19304] R3 sftvsa;Application Virtualization Service Agent;c:\program files\microsoft application virtualization client\sftvsa.exe [2011-10-1 219496] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2012-1-4 822624] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-10 136176] S2 sftlist;Application Virtualization Client;"c:\program files\microsoft application virtualization client\sftlist.exe" –> c:\program files\microsoft application virtualization client\sftlist.exe [?] S3 dsiarhwprog;dsiarhwprog;c:\windows\system32\drivers\dsiarhwprog.sys [2011-8-14 29184] S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2011-1-26 39272] S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-10 136176] S3 MHIKEY10;MHIKEY10;c:\windows\system32\drivers\MHIKEY10.sys [2008-5-27 50560] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-6 129976] S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] S3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2011-10-1 21864] S3 SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A};Symantec Redirector - Norton Safety Minder;c:\windows\system32\drivers\nsm\0203000.013\symrdr.sys [2012-4-30 197624] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2012-05-06 19:34:09 ——– d—–w- c:\program files\Mozilla Maintenance Service 2012-05-06 19:34:06 157352 —-a-w- c:\program files\mozilla firefox\maintenanceservice_installer.exe 2012-05-06 19:34:06 129976 —-a-w- c:\program files\mozilla firefox\maintenanceservice.exe 2012-05-04 20:40:28 ——– d-sh–w- C:\$RECYCLE.BIN 2012-05-04 20:27:05 98816 —-a-w- c:\windows\sed.exe 2012-05-04 20:27:05 518144 —-a-w- c:\windows\SWREG.exe 2012-05-04 20:27:05 256000 —-a-w- c:\windows\PEV.exe 2012-05-04 20:27:05 208896 —-a-w- c:\windows\MBR.exe 2012-05-01 00:58:49 197624 —-a-w- c:\windows\system32\drivers\nsm\0203000.013\symrdr.sys 2012-05-01 00:58:49 177272 —-a-w- c:\windows\system32\drivers\nsm\0203000.013\symrdrs.sys 2012-05-01 00:58:48 ——– d—–w- c:\windows\system32\drivers\nsm\0203000.013 2012-04-23 23:02:47 905336 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symefa.sys 2012-04-23 23:02:47 574072 —-a-w- c:\windows\system32\drivers\n360\0602000.009\srtsp.sys 2012-04-23 23:02:47 345208 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symtdiv.sys 2012-04-23 23:02:47 340088 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symds.sys 2012-04-23 23:02:47 32888 —-a-w- c:\windows\system32\drivers\n360\0602000.009\srtspx.sys 2012-04-23 23:02:47 318584 —-a-r- c:\windows\system32\drivers\n360\0602000.009\symnets.sys 2012-04-23 23:02:46 149624 —-a-r- c:\windows\system32\drivers\n360\0602000.009\ironx86.sys 2012-04-23 23:02:46 132744 —-a-r- c:\windows\system32\drivers\n360\0602000.009\ccsetx86.sys 2012-04-23 23:02:35 4782 —-a-w- c:\windows\system32\drivers\n360\0602000.009\symvtcer.dat 2012-04-23 23:02:35 ——– d—–w- c:\windows\system32\drivers\n360\0602000.009 2012-04-11 08:14:19 5120 —-a-w- c:\windows\system32\wmi.dll 2012-04-11 08:14:19 172032 —-a-w- c:\windows\system32\wintrust.dll 2012-04-11 08:14:19 157696 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-11 08:14:19 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-04-11 08:13:51 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-04-11 08:13:50 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-11 06:39:16 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat . ==================== Find3M ==================== . 2012-04-04 20:56:40 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-03-26 15:22:17 35113704 —-a-w- c:\program files\common files\directx_9c_redist.exe 2012-03-23 18:42:09 141944 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2012-03-01 22:53:35 1576 —-a-w- c:\windows\system32\DeletedKey21.reg 2012-03-01 22:51:30 348722 —-a-w- c:\windows\system32\DeletedKey20.reg 2012-03-01 22:50:15 83578 —-a-w- c:\windows\system32\DeletedKey19.reg 2012-03-01 21:54:12 565410 —-a-w- c:\windows\system32\uninstallkey01.reg 2012-03-01 21:51:28 318 —-a-w- c:\windows\system32\DeletedKey18.reg 2012-03-01 21:51:03 318 —-a-w- c:\windows\system32\DeletedKey17.reg 2012-03-01 21:50:45 318 —-a-w- c:\windows\system32\DeletedKey16.reg 2012-03-01 21:50:21 3518 —-a-w- c:\windows\system32\DeletedKey15.reg 2012-03-01 21:50:05 8856 —-a-w- c:\windows\system32\DeletedKey14.reg 2012-03-01 21:48:55 1668 —-a-w- c:\windows\system32\DeletedKey13.reg 2012-03-01 21:48:36 270 —-a-w- c:\windows\system32\DeletedKey12.reg 2012-03-01 21:48:16 732 —-a-w- c:\windows\system32\DeletedKey11.reg 2012-03-01 21:47:09 2956 —-a-w- c:\windows\system32\DeletedKey10.reg 2012-03-01 21:45:38 7152 —-a-w- c:\windows\system32\DeletedKey09.reg 2012-03-01 21:45:17 34560 —-a-w- c:\windows\system32\DeletedKey08.reg 2012-03-01 21:44:13 404 —-a-w- c:\windows\system32\DeletedKey07.reg 2012-03-01 21:43:56 404 —-a-w- c:\windows\system32\DeletedKey06.reg 2012-03-01 21:43:37 404 —-a-w- c:\windows\system32\DeletedKey05.reg 2012-03-01 21:41:28 2178 —-a-w- c:\windows\system32\DeletedKey04.reg 2012-03-01 21:40:42 13288 —-a-w- c:\windows\system32\DeletedKey03.reg 2012-03-01 21:39:57 3462 —-a-w- c:\windows\system32\DeletedKey02.reg 2012-03-01 21:10:53 1240 —-a-w- c:\windows\system32\DeletedKey01.reg 2012-02-29 15:32:50 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-28 01:18:55 1799168 —-a-w- c:\windows\system32\jscript9.dll 2012-02-28 01:11:21 1427456 —-a-w- c:\windows\system32\inetcpl.cpl 2012-02-28 01:11:07 1127424 —-a-w- c:\windows\system32\wininet.dll 2012-02-28 01:03:16 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-02-14 17:09:44 1070352 —-a-w- c:\windows\system32\MSCOMCTL.OCX 2012-02-14 15:45:30 219648 —-a-w- c:\windows\system32\d3d10_1core.dll 2012-02-14 15:45:30 160768 —-a-w- c:\windows\system32\d3d10_1.dll 2012-02-13 14:12:08 1172480 —-a-w- c:\windows\system32\d3d10warp.dll 2012-02-13 13:47:57 683008 —-a-w- c:\windows\system32\d2d1.dll 2012-02-13 13:44:40 1068544 —-a-w- c:\windows\system32\DWrite.dll . ============= FINISH: 7:24:19.82 ===============

Attachments:

Please give this a try: Right click on the task bar and select Task Manager. click on the process tab and look for APSDaemon. Select it and then stop it from running. Now exit out of the task manager and let me know if things speed up for you.
It's not running. I usually stop that and all apple related processes when I start the computer. I have a list of processes that I know are not necessary that I stop. In anticipation of the question I will try to remember them all for you: All apple related such as ipod service, apple push, apple mobile device, bonjour service. I also stop lws.exe and all logitech processes, as they are associated with my logitech camera and not necessary since I rarely use it. I stop jusched.exe and hsdservice.exe, servicepointservice.exe, and fdm.exe. I occasionally will adjust the start programs list so I don't have to keep doing this, but every time I install a new program, new unnecessary programs pop up or some are pretty stubborn and keep reappearing with updates, like the apple ones. I am only having this problem with the internet. The other programs on my computer have no problem running, which is why I thought it was a virus of some kind. One more thing, a day or two ago I was looking at task manager and found a service running I hadn't seen before. It appeared then went away pretty quick, so I didn't catch it exactly, I know it had security and logic in the name. I googled it but didn't find anything to help me know what it was. Does this process sound familiar?
I only had you look for that process because it can be an issue… and I'm not seeing anything else in your logs to explain your slowness. I don't know what that process could have been. Can you be a little more specific?
I'm sorry if I offended you. I was only clarifying things, I didn't mean to be rude. I wish I could be more specific about the process, it was literally only there for a few seconds after I looked at the list of running processes. Too fast for me. I only asked in case it rang a bell, I hoped there was a virus with a similar name or something. I will let you know if it shows up again. In the meantime, I am not sure what to do. Yesterday, the slowness was consistent. So far this morning it isn't bad at all. It may be that it gets worse throughout the day. It makes sense, although I am not on the computer enough lately to know for sure.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI