This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Redirect Virus [Closed]

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I ran the steps in the Google Redirect forum. None of the fixes worked. Therefore I could really use some more help. I started from scratch from the "Getting Started" forum. Here are the results from OTL. This first one is from the OTL.txt, the second is from Extras.txt.

OTL logfile created on: 5/10/2012 9:15:21 PM - Run 1
OTL by OldTimer - Version 3.2.42.3 Folder = C:\Users\hillmd\Desktop
Enterprise Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.92 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 48.84% Memory free
5.83 Gb Paging File | 4.39 Gb Available in Paging File | 75.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.74 Gb Total Space | 379.56 Gb Free Space | 81.50% Space Free | Partition Type: NTFS

Computer Name: 31296STD | User Name: HillMD | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\hillmd\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\Windows\System32\SProtector.exe (Sophos Plc)
PRC - C:\Windows\System32\SimonPro.exe (Sophos Plc)
PRC - C:\Windows\System32\Simba.exe (Sophos Plc)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)
PRC - C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation)
PRC - C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Symantec\NetBackup DLO\DLO\dloclientu.exe (Symantec Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
PRC - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
PRC - C:\Windows\System32\SASrv.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\Program Files\Symantec\NetBackup DLO\DLO\DLOChangeLogSvcu.exe (Symantec Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
PRC - C:\Windows\System32\CxAudMsg32.exe (Conexant Systems Inc.)
PRC - C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\RightFax\Client\FAXCTRL.exe (Captaris, Inc.)
PRC - C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Lenovo Group Limited)
PRC - C:\Program Files\CONEXANT\ForteConfig\fmapp.exe ()
PRC - C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNAuthServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Windows\System32\BEDevCtl.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Windows\System32\BEFCSvcn.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNMaster.exe (Utimaco Safeware AG - a member of the Sophos Group)
PRC - C:\Users\hillmd\AppData\Roaming\CognosRCP\rcp\cognosrcp.exe (IBM Cognos ULC)
PRC - C:\Program Files\iPass\iPassConnect Crowe Connect\iPassPeriodicUpdateService.exe (iPass, Inc.)
PRC - C:\Program Files\iPass\iPassConnect Crowe Connect\iPassPeriodicUpdateApp.exe (iPass, Inc.)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\ManageSoft\Schedule Agent\ndtask.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Launcher\ndserv.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Schedule Agent\ndschedag.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Launcher\ndlaunch.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Schedule Agent\ndinit.exe (ManageSoft Corp)
PRC - C:\Program Files\ManageSoft\Security Agent\mgssecsvc.exe (ManageSoft Corp)
PRC - C:\Program Files\Brother\DSmobileSCAN II\DSmobileSCAN.exe (Brother International)
PRC - C:\Program Files\Integrated Camera Driver\RCIMGDIR.exe (Ricoh co.,Ltd.)
PRC - C:\Program Files\Citrix\ICA Client\ssonsvr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\lotus\notes\nsl.exe (IBM Corp)
PRC - C:\Program Files\lotus\notes\nslsvice.exe (IBM Corp)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll ()
MOD - C:\Windows\System32\IccLibDll.dll ()
MOD - C:\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll ()
MOD - C:\Program Files\CONEXANT\ForteConfig\fmapp.exe ()
MOD - C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNBELinkern.dll ()
MOD - C:\Windows\System32\sptbasen.dll ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()


========== Win32 Services (SafeList) ==========

SRV - (oracle_load_balancer_60_client-forms6i) – %systemroot%\system32\atimpab.dll File not found
SRV - (nvstor64) – %systemroot%\system32\vxsvc.dll File not found
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (mfevtp) – C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (SophosSGPPS) – C:\Windows\System32\SProtector.exe (Sophos Plc)
SRV - (SDBAgent) – C:\Program Files\Sophos\SafeGuard PortProtector Client\SDBAgent.exe (Sophos Plc)
SRV - (McAfee SiteAdvisor Enterprise Service) – C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe (McAfee, Inc.)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (hips) – C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe (McAfee, Inc.)
SRV - (enterceptAgent) – C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe (McAfee, Inc.)
SRV - (Diskeeper) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
SRV - (SAService) – C:\Windows\System32\SASrv.exe (Conexant Systems, Inc.)
SRV - (DLOChangeJournalSvc) – C:\Program Files\Symantec\NetBackup DLO\DLO\DLOChangeLogSvcu.exe (Symantec Corporation)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (McTaskManager) – C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
SRV - (CxAudMsg) – C:\Windows\System32\CxAudMsg32.exe (Conexant Systems Inc.)
SRV - (TPHKLOAD) – C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Lenovo Group Limited)
SRV - (TPHKSVC) – C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
SRV - (LENOVO.MICMUTE) – C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
SRV - (SGNAuthService) – C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNAuthServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (BEDevCtl) SafeGuard® – C:\Windows\System32\BEDevCtl.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (BEFCSvcn) SafeGuard® – C:\Windows\System32\BEFCSvcn.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (SGN_Trans) SafeGuard® – C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (SGN_Sem) SafeGuard® – C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (SGN_LogSystem) SafeGuard® – C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (SGN_BEService) SafeGuard® – C:\Windows\System32\SGN_MasterServicen.exe (Utimaco Safeware AG - a member of the Sophos Group)
SRV - (iPassConnectEngine) – C:\Program Files\iPass\iPassConnect Crowe Connect\iPassConnectEngine.exe (iPass, Inc.)
SRV - (iPassPeriodicUpdateService) – C:\Program Files\iPass\iPassConnect Crowe Connect\iPassPeriodicUpdateService.exe (iPass, Inc.)
SRV - (iPassPeriodicUpdateApp) – C:\Program Files\iPass\iPassConnect Crowe Connect\iPassPeriodicUpdateApp.exe (iPass, Inc.)
SRV - (CVPND) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (ndGlobalLauncher) – C:\Program Files\ManageSoft\Launcher\ndserv.exe (ManageSoft Corp)
SRV - (ndinit) – C:\Program Files\ManageSoft\Schedule Agent\ndinit.exe (ManageSoft Corp)
SRV - (mgssecsvc) – C:\Program Files\ManageSoft\Security Agent\mgssecsvc.exe (ManageSoft Corp)
SRV - (mgsdl) – C:\Program Files\ManageSoft\Launcher\mgsdl.exe (ManageSoft Corp)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PWSSvc) – C:\Program Files\Colligo Networks\Colligo Workgroup Edition\PWSSvc.exe ()
SRV - (Lotus Notes Single Logon) – C:\Program Files\lotus\notes\nslsvice.exe (IBM Corp)


========== Driver Services (SafeList) ==========

DRV - (VGPU) – System32\drivers\rdvgkmd.sys File not found
DRV - (PnSson) – File not found
DRV - (mfeavfk01) – File not found
DRV - (ehdrv) – system32\DRIVERS\ehdrv.sys File not found
DRV - (Avgtdix) – system32\DRIVERS\avgtdix.sys File not found
DRV - (Avgrkx86) – system32\DRIVERS\avgrkx86.sys File not found
DRV - (AVGIDSShim) – system32\DRIVERS\avgidsshimx.sys File not found
DRV - (AVGIDSHX) – system32\DRIVERS\avgidshx.sys File not found
DRV - (AVGIDSFilter) – system32\DRIVERS\avgidsfilterx.sys File not found
DRV - (AVGIDSDriver) – system32\DRIVERS\avgidsdriverx.sys File not found
DRV - (mfewfpk) – C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (Spfd) – C:\Windows\System32\drivers\Spfd.sys (Safend Ltd.)
DRV - (Sidney) – C:\Windows\System32\drivers\Sidney.sys (Sophos Plc)
DRV - (SofiaMp) – C:\Windows\System32\drivers\Sofia.sys (Sophos Plc)
DRV - (Sofia) – C:\Windows\System32\drivers\Sofia.sys (Sophos Plc)
DRV - (Sofy) – C:\Windows\System32\drivers\Sofy.sys (Sophos Plc)
DRV - (Shandy) – C:\Windows\System32\drivers\Shandy.sys (Sophos Plc)
DRV - (Scarlet) – C:\Windows\System32\drivers\Scarlet.sys (Sophos Plc)
DRV - (Shlos) – C:\Windows\System32\drivers\Shlos.sys (Sophos Plc)
DRV - (Sahara) – C:\Windows\System32\drivers\Sahara.sys (Sophos Plc)
DRV - (Salvador) – C:\Windows\System32\drivers\Salvador.sys (Sophos Plc)
DRV - (Santa) – C:\Windows\System32\drivers\Santa.sys (Sophos Plc)
DRV - (Diego) – C:\Windows\System32\drivers\Diego.sys (Sophos Plc)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (nvkflt) – C:\Windows\System32\drivers\nvkflt.sys (NVIDIA Corporation)
DRV - (nvpciflt) – C:\Windows\System32\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV - (BeFlt) – C:\Windows\System32\drivers\BEFLT.SYS (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (HIPK) – C:\Windows\System32\drivers\HIPK.sys (McAfee, Inc.)
DRV - (mfetdik) – C:\Windows\System32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (HIPPSK) – C:\Windows\System32\drivers\HIPPSK.sys (McAfee, Inc.)
DRV - (HIPQK) – C:\Windows\System32\drivers\HIPQK.sys (McAfee, Inc.)
DRV - (firelm01) – C:\Windows\System32\drivers\firelm01.sys (McAfee, Inc.)
DRV - (FireTDI) – C:\Windows\System32\drivers\FireTDI.sys (McAfee, Inc.)
DRV - (FirePM) – C:\Windows\System32\drivers\FirePM.sys (McAfee, Inc.)
DRV - (risdxc) – C:\Windows\System32\drivers\risdxc86.sys (REDC)
DRV - (5U877) – C:\Windows\System32\drivers\5U877.sys (Ricoh co.,Ltd.)
DRV - (DKRtWrt) – C:\Windows\System32\drivers\DKRtWrt.sys (Diskeeper Corporation)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (Shockprf) – C:\Windows\System32\drivers\ApsX86.sys (Lenovo.)
DRV - (TPDIGIMN) – C:\Windows\System32\drivers\ApsHM86.sys (Lenovo.)
DRV - (NETwNs32) ___ Intel® – C:\Windows\System32\drivers\NETwNs32.sys (Intel Corporation)
DRV - (e1cexpress) Intel® – C:\Windows\System32\drivers\e1c6232.sys (Intel Corporation)
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (tsusbhub) – C:\Windows\System32\drivers\tsusbhub.sys (Microsoft Corporation)
DRV - (Synth3dVsc) – C:\Windows\System32\drivers\Synth3dVsc.sys (Microsoft Corporation)
DRV - (dmvsc) – C:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbGD) – C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (terminpt) – C:\Windows\System32\drivers\terminpt.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (MEI) Intel® – C:\Windows\System32\drivers\HECI.sys (Intel Corporation)
DRV - (BE_FLTI) – C:\Windows\System32\drivers\be_fltim.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEAES2M) – C:\Windows\System32\drivers\cegaes2m.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEAESM) – C:\Windows\System32\drivers\cegaesm.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (SGSTDRVM) – C:\Windows\System32\drivers\SGStDrvm.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEEIDEM) – C:\Windows\System32\drivers\ceeidem.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEIDEM) – C:\Windows\System32\drivers\ceidem.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEDESM) – C:\Windows\System32\drivers\cedesm.sys ()
DRV - (CEDES3M) – C:\Windows\System32\drivers\cedes3m.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CEHMACM) – C:\Windows\System32\drivers\cehmacm.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CESHAM) – C:\Windows\System32\drivers\cesham.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (CERNDM) – C:\Windows\System32\drivers\cerndm.sys (Utimaco Safeware AG - a member of the Sophos Group)
DRV - (lenovo.smi) – C:\Windows\System32\drivers\smiif32.sys (Lenovo Group Limited)
DRV - (SpfdBus) – C:\Windows\System32\drivers\SpfdBus.sys (Safend Ltd.)
DRV - (CVPNDRVA) – C:\Windows\System32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (TVTI2C) – C:\Windows\System32\drivers\tvti2c.sys (Lenovo (United States) Inc.)
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (TPM) – C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (psadd) – C:\Windows\System32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (DNE) – C:\Windows\System32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (FirehkMP) – C:\Windows\System32\drivers\firehk.sys (McAfee, Inc.)
DRV - (Firehk) – C:\Windows\System32\drivers\firehk.sys (McAfee, Inc.)
DRV - (CVirtA) – C:\Windows\System32\drivers\CVirtA.sys (Cisco Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\NPMVTPlugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\ManageSoft\Usage Agent\mgsusageagent\ [2011/08/10 03:48:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/03/02 08:39:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor Enterprise\ [2011/11/29 09:15:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/05/10 20:53:55 | 000,000,000 | —D | M]

[2011/07/21 13:09:28 | 000,032,040 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll

O1 HOSTS File: ([2009/06/10 16:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (ManageSoft Web Application Tracker) - {30A22EC9-42D0-4D46-A2F7-7516419F943D} - C:\Program Files\ManageSoft\Usage Agent\mgsiebho.dll ()
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111209122843.dll (McAfee, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Communicator] C:\Program Files\Microsoft Lync\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ForteConfig] C:\Program Files\CONEXANT\ForteConfig\fmapp.exe ()
O4 - HKLM..\Run: [McAfee Host Intrusion Prevention Tray] C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RightFAX Print-to-Fax Driver] C:\Program Files\RightFax\Client\FAXCTRL.exe (Captaris, Inc.)
O4 - HKLM..\Run: [RotateImage] C:\Program Files\Integrated Camera Driver\RCIMGDIR.exe (Ricoh co.,Ltd.)
O4 - HKLM..\Run: [RunSimba] C:\Windows\System32\Simba.exe (Sophos Plc)
O4 - HKLM..\Run: [SchedulingAgent_nDG] C:\Program Files\ManageSoft\Schedule Agent\ndschedag.exe (ManageSoft Corp)
O4 - HKLM..\Run: [ScrewDrivers RDP Plugin] C:\Program Files\triCerat\Simplify Printing\ScrewDrivers Client v4\install_rdp.exe ()
O4 - HKLM..\Run: [SGNMasterApplication] C:\Program Files\Sophos\SafeGuard Enterprise\Client\SGNMaster.exe (Utimaco Safeware AG - a member of the Sophos Group)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe (Conexant systems, Inc.)
O4 - HKLM..\Run: [STFWebFormApp] "C:\Program Files\Common Files\STF Services Shared\WebFormApp.exe" -start File not found
O4 - HKCU..\Run: [Google] C:\Users\hillmd\AppData\Local\javasharedresources\Google\wimpud.dll (MainConcept GmbH)
O4 - Startup: C:\Users\hillmd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSmobileSCAN II.lnk = C:\Program Files\Brother\DSmobileSCAN II\DSmobileSCAN.exe (Brother International)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoComputersNearMe = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ConfirmFileDelete = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowCpl = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceRunOnStartMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 2 = nusrmgr.cpl
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 3 = wscui.cpl (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 4 = wuaucpl.cpl
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 5 = Microsoft.ActionCenter
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 6 = Microsoft.BitlockerDriveEncryption
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 7 = Microsoft.WindowsDefender
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll File not found
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (Bitdefender QuickScan Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = crowe-chizek.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5124753B-F203-43E3-9BE8-9C547CC546DE}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\cw {774E529C-2458-48A2-8F57-3ED3105D8612} - C:\Program Files\Caseware 2011\cwproto.dll (CaseWare International Inc.)
O18 - Protocol\Handler\cwt {774E529C-2458-48A2-8F57-3ED3105D8612} - C:\Program Files\Caseware 2011\cwproto.dll (CaseWare International Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\Windows\system32\nvinit.dll) - C:\Windows\System32\nvinit.dll (NVIDIA Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\aSinadin: DllName - (Sinadin.dll) - C:\Windows\System32\Sinadin.dll (Sophos Plc)
O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O30 - LSA: Authentication Packages - (sesami) - C:\Windows\System32\sesami.dll (Sophos Plc)
O30 - LSA: Security Packages - (sesami) - C:\Windows\System32\sesami.dll (Sophos Plc)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: nvstor64 - %systemroot%\system32\vxsvc.dll File not found
NetSvcs: oracle_load_balancer_60_client-forms6i - %systemroot%\system32\atimpab.dll File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/05/10 21:13:58 | 000,595,456 | —- | C] (OldTimer Tools) – C:\Users\hillmd\Desktop\OTL.exe
[2012/05/10 21:10:56 | 000,000,000 | —D | C] – C:\ProgramData\ESET
[2012/05/10 21:10:56 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/05/10 19:47:20 | 000,000,000 | —D | C] – C:\Users\hillmd\AppData\Roaming\Malwarebytes
[2012/05/10 19:46:46 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/05/10 19:38:28 | 000,000,000 | —D | C] – C:\Users\hillmd\AppData\Roaming\QuickScan
[2012/05/10 19:27:08 | 000,040,328 | —- | C] (McAfee, Inc.) – C:\Windows\System32\HIPIS0e011b8.dll
[2012/05/10 18:47:48 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2012/05/10 18:44:29 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2012/05/10 18:44:28 | 000,000,000 | —D | C] – C:\Users\hillmd\AppData\Local\Conduit
[2012/05/10 15:49:41 | 000,000,000 | —D | C] – C:\ProgramData\Roaming
[2012/05/09 15:26:52 | 000,000,000 | —D | C] – C:\Users\hillmd\Desktop\INSTEC
[2012/05/04 11:34:06 | 000,000,000 | —D | C] – C:\Users\hillmd\Desktop\Performance
[2012/05/03 10:44:44 | 000,000,000 | —D | C] – C:\Users\hillmd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ACL 9
[2012/05/03 10:44:43 | 000,000,000 | —D | C] – C:\ACL Data
[2012/05/03 10:43:00 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2012/04/18 07:35:18 | 000,000,000 | —D | C] – C:\ProgramData\Hewlett-Packard
[2012/04/15 22:51:50 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2012/04/15 22:45:18 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2012/04/15 22:43:20 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2012/04/15 22:26:23 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2012/04/15 22:11:29 | 000,000,000 | —D | C] – C:\ProgramData\B7E858A70004254C00079FC2B4EB238B

========== Files - Modified Within 30 Days ==========

[2012/05/10 21:14:11 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\hillmd\Desktop\OTL.exe
[2012/05/10 21:01:04 | 000,023,808 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/10 21:01:04 | 000,023,808 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/10 20:54:34 | 000,001,118 | —- | M] () – C:\Users\hillmd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSmobileSCAN II.lnk
[2012/05/10 20:54:12 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/10 20:53:49 | 000,127,577 | —- | M] () – C:\Windows\System32\api_hook_list.dat
[2012/05/10 20:53:39 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/05/10 20:53:31 | 2347,663,360 | -HS- | M] () – C:\hiberfil.sys
[2012/05/10 20:29:08 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/10 15:47:59 | 000,000,544 | —- | M] () – C:\Windows\ODBC.INI
[2012/05/10 11:32:51 | 000,389,760 | —- | M] () – C:\Users\hillmd\Desktop\QCSA #3.pdf
[2012/05/10 11:32:39 | 000,385,903 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-139.pdf
[2012/05/09 15:24:19 | 000,063,559 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-138.pdf
[2012/05/09 10:28:43 | 000,333,690 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-137.pdf
[2012/05/04 13:44:16 | 000,414,800 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/05/03 10:44:44 | 000,002,077 | —- | M] () – C:\Users\hillmd\Desktop\ACL 9.lnk
[2012/05/03 00:17:08 | 000,143,008 | —- | M] (McAfee, Inc.) – C:\Windows\System32\KevlarSigs.dll
[2012/04/30 16:27:35 | 000,032,832 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-136.pdf
[2012/04/30 16:25:25 | 000,032,975 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-135.pdf
[2012/04/27 16:01:24 | 000,043,298 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-134.pdf
[2012/04/27 07:01:07 | 000,017,441 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-133.pdf
[2012/04/27 06:56:19 | 000,017,619 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-132.pdf
[2012/04/25 11:31:19 | 000,688,486 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/04/25 11:31:19 | 000,129,136 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/04/19 08:09:27 | 000,029,733 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-131.pdf
[2012/04/19 08:08:31 | 000,028,504 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-130.pdf
[2012/04/17 12:32:38 | 000,048,329 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-129.pdf
[2012/04/17 12:29:04 | 000,055,814 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-128.pdf
[2012/04/17 12:24:15 | 000,054,694 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-127.pdf
[2012/04/16 15:16:01 | 000,060,987 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-126.pdf
[2012/04/16 07:45:38 | 000,035,648 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-125.pdf
[2012/04/16 07:44:26 | 000,303,744 | —- | M] () – C:\Users\hillmd\Documents\DSmobileSCAN-124.pdf
[2012/04/16 05:04:28 | 000,017,407 | —- | M] () – C:\Users\hillmd\AppData\Local\dt.dat
[2012/04/15 22:11:52 | 000,000,000 | -HS- | M] () – C:\Windows\System32\dds_trash_log.cmd

========== Files Created - No Company Name ==========

[2012/05/10 20:53:49 | 000,127,577 | —- | C] () – C:\Windows\System32\api_hook_list.dat
[2012/05/10 11:32:51 | 000,389,760 | —- | C] () – C:\Users\hillmd\Desktop\QCSA #3.pdf
[2012/05/10 11:32:39 | 000,385,903 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-139.pdf
[2012/05/09 15:24:19 | 000,063,559 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-138.pdf
[2012/05/09 10:28:43 | 000,333,690 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-137.pdf
[2012/05/03 10:44:44 | 000,002,077 | —- | C] () – C:\Users\hillmd\Desktop\ACL 9.lnk
[2012/04/30 16:27:35 | 000,032,832 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-136.pdf
[2012/04/30 16:25:25 | 000,032,975 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-135.pdf
[2012/04/27 16:01:24 | 000,043,298 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-134.pdf
[2012/04/27 07:01:07 | 000,017,441 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-133.pdf
[2012/04/27 06:56:19 | 000,017,619 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-132.pdf
[2012/04/19 08:09:27 | 000,029,733 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-131.pdf
[2012/04/19 08:08:31 | 000,028,504 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-130.pdf
[2012/04/17 12:32:38 | 000,048,329 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-129.pdf
[2012/04/17 12:29:04 | 000,055,814 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-128.pdf
[2012/04/17 12:24:15 | 000,054,694 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-127.pdf
[2012/04/16 15:16:01 | 000,060,987 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-126.pdf
[2012/04/16 07:45:38 | 000,035,648 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-125.pdf
[2012/04/16 07:44:26 | 000,303,744 | —- | C] () – C:\Users\hillmd\Documents\DSmobileSCAN-124.pdf
[2012/04/16 05:04:28 | 000,017,407 | —- | C] () – C:\Users\hillmd\AppData\Local\dt.dat
[2012/04/15 22:11:52 | 000,000,000 | -HS- | C] () – C:\Windows\System32\dds_trash_log.cmd
[2011/09/26 18:05:46 | 000,222,488 | —- | C] () – C:\Windows\System32\SPHook.dll
[2011/09/12 07:21:08 | 000,009,886 | —- | C] () – C:\Users\hillmd\AppData\Roaming\connector.dotm
[2011/08/30 15:06:10 | 000,002,080 | —- | C] () – C:\Windows\System32\drivers\SamSfPa.dat
[2011/08/30 11:48:31 | 000,000,544 | —- | C] () – C:\Windows\ODBC.INI
[2011/08/30 11:48:23 | 000,000,608 | —- | C] () – C:\Windows\tenkey.ini
[2011/08/09 16:38:36 | 000,002,658 | —- | C] () – C:\Windows\INSTAREA.DAT
[2011/08/09 16:16:38 | 000,039,472 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/03/06 19:45:44 | 000,213,332 | —- | C] () – C:\Windows\System32\igfcg600m.bin
[2011/03/06 19:45:44 | 000,145,804 | —- | C] () – C:\Windows\System32\igcompkrng600.bin
[2011/03/06 19:45:42 | 000,963,116 | —- | C] () – C:\Windows\System32\igkrng600.bin
[2011/03/06 19:13:20 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll
[2011/03/06 19:11:06 | 000,000,151 | —- | C] () – C:\Windows\System32\GfxUI.exe.config
[2011/03/06 19:07:58 | 000,094,208 | —- | C] () – C:\Windows\System32\IccLibDll.dll
[2011/02/02 23:29:52 | 001,816,324 | —- | C] () – C:\Windows\System32\nvcoproc.bin
[2011/01/18 10:35:42 | 000,030,893 | —- | C] () – C:\Windows\System32\drivers\Mixer.ini
[2010/11/20 16:29:34 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2010/11/20 16:29:26 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2010/10/28 12:27:48 | 000,001,816 | —- | C] () – C:\Windows\System32\drivers\Altmixer.ini
[2010/10/15 06:58:42 | 067,108,864 | —- | C] () – C:\Windows\SGBEKERNEL.BIN
[2010/10/15 06:58:42 | 000,000,512 | R— | C] () – C:\Windows\KrnlPatt.bin
[2010/10/15 01:28:02 | 000,000,512 | —- | C] () – C:\Windows\SGBEMBR.BIN
[2010/10/14 21:11:02 | 000,167,936 | —- | C] () – C:\Windows\System32\sptbasen.dll
[2010/10/14 17:40:00 | 000,118,784 | R— | C] () – C:\Windows\System32\SGNP11RSAn.dll
[2010/10/14 15:37:04 | 000,019,712 | —- | C] () – C:\Windows\System32\drivers\cedesm.sys
[2010/10/01 14:39:56 | 000,001,372 | —- | C] () – C:\Windows\System32\VoipUpdate.ini

========== LOP Check ==========

[2011/09/19 15:11:08 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\CognosRCP
[2011/08/30 12:01:09 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\Colligo Networks
[2012/01/15 15:35:09 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\Leadertech
[2011/08/30 11:44:57 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\ManageSoft Corp
[2011/08/30 14:27:28 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\MessageOne
[2012/05/10 19:38:32 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\QuickScan
[2012/01/02 21:37:44 | 000,000,000 | —D | M] – C:\Users\hillmd\AppData\Roaming\Tacori Bridal Collection
[2009/07/13 23:53:46 | 000,029,670 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2009/06/10 16:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/11/20 16:29:06 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/08/10 07:18:57 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 16:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2012/05/09 15:39:20 | 000,000,000 | —- | M] () – C:\dataset.log
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/05/10 20:53:31 | 2347,663,360 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2011/08/30 12:19:21 | 000,067,049 | —- | M] () – C:\MGSPostWork.log
[2011/09/12 12:35:40 | 000,013,176 | —- | M] () – C:\Open Items Summary Report.xls
[2012/05/10 20:53:30 | 3130,220,544 | -HS- | M] () – C:\pagefile.sys
[2012/02/23 17:26:17 | 000,000,312 | —- | M] () – C:\Ping.txt
[2011/08/09 16:44:38 | 000,000,211 | —- | M] () – C:\setup.log
[2012/05/10 21:03:24 | 000,040,324 | —- | M] () – C:\TDSSKiller.2.7.34.0_10.05.2012_21.03.12_log.txt
[2012/05/10 21:05:17 | 000,077,580 | —- | M] () – C:\TDSSKiller.2.7.34.0_10.05.2012_21.04.59_log.txt
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/13 23:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 20:15:26 | 000,280,064 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpzppw71.dll
[2009/07/13 20:15:26 | 000,090,624 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPWN7.DLL
[2009/07/13 20:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2011/02/05 12:25:34 | 000,082,184 | —- | M] (Microsoft Corporation.) – C:\Windows\system32\spool\prtprocs\w32x86\lmdippr8.dll
[2010/11/03 17:45:10 | 000,016,896 | —- | M] (Captaris, Inc.) – C:\Windows\system32\spool\prtprocs\w32x86\rfprint.dll
[2010/11/20 16:29:21 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >
[2008/05/22 10:35:34 | 000,299,324 | —- | M] () – C:\Windows\Crowe Wallpaper 1 1280x1024.jpg
[2008/05/22 10:33:48 | 000,299,480 | —- | M] () – C:\Windows\Crowe Wallpaper 1 1400x990.jpg
[2008/05/22 10:32:36 | 000,124,577 | —- | M] () – C:\Windows\Crowe Wallpaper 1.jpg
[2008/05/22 10:30:08 | 000,326,220 | —- | M] () – C:\Windows\Crowe Wallpaper 2 1280x1024.jpg
[2008/05/22 10:28:12 | 000,295,571 | —- | M] () – C:\Windows\Crowe Wallpaper 2 1400x990.jpg
[2008/05/22 10:27:30 | 000,141,897 | —- | M] () – C:\Windows\Crowe Wallpaper 2.jpg
[2008/05/22 10:23:36 | 000,430,497 | —- | M] () – C:\Windows\Crowe Wallpaper 3 1280x1024.jpg
[2008/05/22 10:22:34 | 000,403,300 | —- | M] () – C:\Windows\Crowe Wallpaper 3 1400x990.jpg
[2008/05/22 10:21:32 | 000,366,234 | —- | M] () – C:\Windows\Crowe Wallpaper 3.jpg
[2008/05/22 10:20:26 | 000,210,931 | —- | M] () – C:\Windows\Crowe Wallpaper 4.jpg
[2006/02/28 12:41:04 | 000,031,565 | —- | M] () – C:\Windows\Unique2Big4.JPG
[2008/05/22 10:43:44 | 000,091,442 | —- | M] () – C:\Windows\Unique2Big4Crowe.JPG

< %systemroot%\*.png >
[2008/05/22 10:45:20 | 000,006,569 | —- | M] () – C:\Windows\Crowe_2c_White_Small.png
[2008/05/22 10:46:30 | 000,148,091 | —- | M] () – C:\Windows\Unique2Big4Crowe.PNG

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/01/04 08:42:08 | 000,000,221 | -HS- | M] () – C:\Users\hillmd\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/05/10 21:14:11 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\hillmd\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAUShutdownOption" = 1
"NoAutoUpdate" = 1

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\$NtUninstallKB20529$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:502D809E

< End of report >


Here is the report from Extras.Txt

OTL Extras logfile created on: 5/10/2012 9:15:21 PM - Run 1
OTL by OldTimer - Version 3.2.42.3 Folder = C:\Users\hillmd\Desktop
Enterprise Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.92 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 48.84% Memory free
5.83 Gb Paging File | 4.39 Gb Available in Paging File | 75.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.74 Gb Total Space | 379.56 Gb Free Space | 81.50% Space Free | Partition Type: NTFS

Computer Name: 31296STD | User Name: HillMD | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"AntiVirusDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallDisableNotify" = 0
"FirewallOverride" = 1
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{3A273A4B-7E8C-4F16-8B50-060367B3135D}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{B6D68FF2-5B6F-4570-B65B-6D0F4A31A067}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{18FF6F66-51DB-4292-8668-F92B3A1ADF67}" = dir=in | app=c:\program files\microsoft lync\ucmapi.exe |
"{23315F50-6557-49A4-B9D8-290F06FA98D0}" = protocol=6 | dir=in | app=c:\program files\microsoft lync\communicator.exe |
"{273FADB2-C640-42AF-88DA-76D7B7BB5054}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{2D443245-1CC4-41EC-B966-7B257939E0E4}" = protocol=17 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{3EDBA95D-0C14-46DB-9B19-9DE48FE8ACC6}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{40446D02-B013-4F2E-84D7-1F45091199AE}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{4CD225EE-ADC8-4871-BD82-BFED6CE09209}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5CB3D8B8-9674-4313-9A96-71DC2C85C7EA}" = dir=in | app=c:\program files\microsoft lync\communicator.exe |
"{5D6F1B84-D5FC-422A-B1D6-C1DC0DAAC3B1}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{5EC0DB8E-5C3C-4A46-A2BA-6278C27AFDD6}" = dir=in | app=c:\program files\colligo networks\colligo workgroup edition\colligo.exe |
"{680F3BCF-DE69-49FE-A1CE-D0DD81DF7926}" = protocol=17 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{6ADB6757-1A99-496B-8C71-57724809D4BA}" = protocol=17 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{71B98DBA-2899-419D-B5F5-376F304B1529}" = protocol=17 | dir=in | app=c:\program files\microsoft lync\communicator.exe |
"{71D7CD66-ABC4-46C9-8F64-D54C5AA0B4A4}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{7B1DEDEF-2193-47D2-933A-E607753C81CA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8D0F57C7-3264-4096-84B7-284E368D0F5C}" = protocol=17 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{B3C09CC4-C96C-43AE-A571-7847FCCC0FE0}" = protocol=6 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{B726BA07-0EC2-4165-9B22-D93C17C490A9}" = protocol=6 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{CE08BEF9-2C30-4EC9-BFD1-2F385AB00B66}" = protocol=6 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{D64D9E2A-4C86-40A2-8F8F-325ED96831C7}" = protocol=17 | dir=in | app=c:\program files\microsoft office\live meeting 8\console\pwconsole.exe |
"{DECC7D06-1820-40BB-88F5-1D6E68022CB3}" = protocol=6 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{E87FF355-F7EF-46D4-8EF7-A75556B87CEE}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{EAAB60CC-E615-4E13-96D6-130FDA2780C2}" = protocol=6 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{F100AF2C-6A14-4138-BDAA-5EC9A981C454}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00FC3F65-86EB-475E-881F-A5B1CF731320}" = McAfee SiteAdvisor Enterprise Plus
"{05227385-5073-46ED-9035-B1910E2613CC}" = DSmobileSCAN II
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{121634B0-2F4A-11D3-ADA3-00C04F52DD53}" = Windows Installer Clean Up
"{134774E3-4A0B-4139-815B-A7171CFA0B9C}" = Caseware Master Library 4.18.2011.00
"{17CBC505-D1AE-459D-B445-3D2000A85842}" = ThinkPad UltraNav Utility
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{23D79730-EC1A-435E-83F8-AAEBFE5237B0}" = Adobe Flash Player 11 ActiveX
"{2624B680-02BC-4CBC-839C-DA20DF6EF6EC}" = Citrix Presentation Server Client
"{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java™ 6 Update 30
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{2BB9B2F5-79E7-4220-B903-22E849100547}" = Microsoft Conferencing Add-in for Microsoft Office Outlook
"{2C2EA2C8-1B0F-4FEC-88E2-2B104E0507F3}" = Outlook Space On Demand
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage Active Protection System
"{51D359FF-91CA-467B-967D-DEEDA013628A}" = Colligo Workgroup Edition
"{5395ACBD-D72C-4ECB-0AAC-1821D15D049A}" = SafeGuard PortProtector Client
"{55D1BF8E-EA8F-4969-82B9-B577010CFBCD}" = Microsoft Baseline Security Analyzer 2.1
"{56BD1B37-3934-4FA4-AE71-91DDB176C032}" = ACL 9
"{6267109C-50D2-4667-9FF6-03FB9A94A771}" = Sophos SafeGuard 5.50.8 Client
"{65545E0A-8288-43CF-8A68-E2F6CC8B469E}" = ManageSoft for managed devices
"{65E9B2E4-555F-441C-A8F7-B754FB1A010E}" = iPassConnect Crowe Connect
"{6A4F975D-EC09-4CF4-8452-A357CDF14D9C}" = Sage Fixed Assets - Depreciation
"{6FED6E57-AA25-4597-9ED5-C66C02992066}" = Symantec NetBackup Desktop Agent
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{774391DB-E12D-47AE-B4D2-46F7EB4ABDDC}" = McAfee Virtual Technician
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{81BE0B17-563B-45D4-B198-5721E6C665CD}" = Microsoft Lync 2010
"{846A8F6B-BEE5-4E94-9356-99B51E4D6F54}" = IBM Cognos Contributor Client
"{84BDCF3F-9FDE-4526-BBB4-3077CB8515EC}" = CaseWare Connector 2011
"{89DFC26C-9CB3-44E3-A799-80BCE8CE0BEB}" = Monarch 10.00
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B39A4EA-6E2C-4298-97AA-D8CDB0D91E7A}" = Outlook Secure Option
"{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components
"{90120000-00D1-0409-0000-0000000FF1CE}" = Microsoft Office Access database engine 2007 (English)
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{1E6AE8C5-CAC6-49B2-953B-3A4C8CDC1AD2}" =
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00D1-0409-0000-0000000FF1CE}" = Microsoft Access database engine 2010 (English)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90C65E91-03C5-47B9-9EBF-72AAB0E7FDF3}" = ePO-MVT
"{94FB0978-D094-40C7-91D7-834D39220D4A}" = Crystal Reports XI Release 2 for Sage
"{9A235AC3-FA85-42D6-9B93-78A45E23596F}" = ScrewDrivers Client v4
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CA0DEE4-E84B-466F-9B96-FC255F3A929F}" = Integrated Camera TWAIN
"{9FCD6918-3DB5-45F2-B89F-654BB3233483}" = Sophos SafeGuard 5.50.0 Client Configuration
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A0E54EC6-EA51-4088-A6EE-BEF1D1D128AB}" = Lotus Notes 7.0.2
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-F400-BA7E-000000000005}" = Adobe Acrobat X Standard - English, Français, Deutsch
"{B0BF7057-6869-4E4B-920C-EA2A58DA07F0}" = Cisco Systems VPN Client 5.0.07.0290
"{B2CA6F37-1602-4823-81B5-0384B6888AA6}" = Integrated Camera Driver Installer Package Ver.1.1.0.1147
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Display Control Panel
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 280.26
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.0.21
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver [removed]
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B332732A-4958-41DD-B439-DDA2D32753C5}" = McAfee Host Intrusion Prevention
"{B60C695C-EF2F-4826-9106-417ED7A68658}" = RightFax Product Suite - Client
"{B72B06E0-0C54-495F-896F-E3ED2905624A}" = Microsoft Junk E-mail Reporting Add-in
"{B87E6D2C-1365-4507-AA4F-15D007A64D1A}" = Dell Outlook Addin (x86)
"{C184AAA4-DFD6-44DF-B1E1-B2B9CC19EAA7}" = CaseWare Working Papers 2011
"{CDBAAE82-1725-4BDF-9770-69EA174318F1}" = Sophos SafeGuard Preinstall 5.50.0
"{CE15D1B6-19B6-4D4D-8F43-CF5D2C3356FF}" = McAfee VirusScan Enterprise
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D79036E3-A83E-41CD-9776-28853C258940}" = DSmobile 600
"{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"{DE91C193-2611-4BD3-A9F9-DF589C572565}" = McAfee Agent
"{E117B4A1-5C43-4ED8-8DE8-B45B58940191}" = Diskeeper 2011 Professional
"{E2C29C93-171B-40CF-949E-B27E3E6F9EDE}" = Becker's CPA Exam Review and PassMaster - 2011 Edition
"{E60146B0-C083-47BE-BD6B-EFA57AC8D9B1}" = RightFax Product Suite - Client
"{EA710A0A-BF5D-433C-8EB5-D17DC54CC298}" = Microsoft Office Live Meeting 2007
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F30B17C3-F398-4832-9176-6B2B52D9682A}" = IBM Cognos 8 Planning 8.4 Client Framework
"{F7797694-3F06-41C7-B9A0-C4BEF21ACE7A}" = Judy's TenKey ™ Installer
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe PDF IFilter 6.0" = Adobe PDF IFilter 6.0
"B2A - Windows Active X Files [Common] (ManageSoft)" = B2A - Windows Active X Files [Common] (via ManageSoft)
"CNXT_AUDIO_HDA" = Conexant 20672 SmartAudio HD
"Crowe Utilities [Common] (ManageSoft)" = Crowe Utilties [Common] (via ManageSoft)
"DTE Remote 2004" = DTE Remote 2004
"HP OfficeJet 100 Printer Drivers [Common] (ManageSoft)" = HP OfficeJet 100 Printer Drivers [Common] (via ManageSoft)
"HP450 [Common] (ManageSoft)" = HP450 Print Drivers [Common] (via ManageSoft)
"HP470 [Common] (ManageSoft)" = HP470 Print Drivers [Common] (via ManageSoft)
"InstallShield_{6A4F975D-EC09-4CF4-8452-A357CDF14D9C}" = Sage Fixed Assets - Depreciation
"LENOVO.SMIIF" = Lenovo System Interface Driver
"McAfee GetSusp Malware Scanner [Common] (ManageSoft)" = McAfee GetSusp Malware Scanner [Common] (via ManageSoft)
"McAfee Stinger - Standard [Common] (ManageSoft)" = McAfee Stinger - Standard [Common] (via ManageSoft)
"MGS Config [Common] (ManageSoft)" = MGS Config [Common] (via ManageSoft)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Office 2010 Help Guides [Common] (ManageSoft)" = Microsoft Office 2010 Help Guides [Common] (via ManageSoft)
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Nvidia Config [Common] (ManageSoft)" = Nvidia Config [Common] (via ManageSoft)
"Office Update Inventory Tool [Common] (ManageSoft)" = Office Update Inventory Tool [Common] (via ManageSoft)
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"OnScreenDisplay" = On Screen Display
"PaperPort Viewer [Common] (ManageSoft)" = PaperPort Viewer [Common] (via ManageSoft)
"Power Management Driver" = ThinkPad Power Management Driver
"Security Patch Settings for Microsoft Office [Common] (ManageSoft)" = Security Patch Settings for Microsoft Office [Common] (via ManageSoft)
"Security Patch Settings for Microsoft Windows [Common] (ManageSoft)" = Security Patch Settings for Microsoft Windows [Common] (via ManageSoft)
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"WinZip" = WinZip
"WinZip [Common] (ManageSoft)" = WinZip 9.0 SR1 [Common] (via ManageSoft)
"Wireless Profiles Config [Common] (ManageSoft)" = Wireless Profiles Config [Common] (via ManageSoft)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ACL Update [HillMD] (ManageSoft)" = ACL Update [HillMD] (via ManageSoft)
"AOL Toolbar" = AOL Toolbar
"FAS 2012.1 DLL Patch [hillmd] (ManageSoft)" = FAS 2012.1 DLL Patch [hillmd] (via ManageSoft)
"Interactive Forms 2011 [HillMD] (ManageSoft)" = Interactive Forms 2011 [HillMD] (via ManageSoft)
"Lotus Notes Configuration [hillmd] (ManageSoft)" = Lotus Notes Configuration [HillMD] (via ManageSoft)
"MGS User Config [hillmd] (ManageSoft)" = MGS User Config [hillmd] (via ManageSoft)
"Microsoft Windows Desktop Shortcuts [HillMD] (ManageSoft)" = Microsoft Windows Desktop Shortcuts [HillMD] (via ManageSoft)
"Personalization_2 [hillmd] (ManageSoft)" = Personalization_2 [hillmd] (via ManageSoft)
"Symantec NetBackup Configuration Changes [hillmd] (ManageSoft)" = Symantec NetBackup Configuration Changes [HillMD] (via ManageSoft)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/12/2012 2:08:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/12/2012 2:08:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 998

Error - 2/12/2012 2:08:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 998

Error - 2/12/2012 6:17:37 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Application Hang | ID = 1002
Description = The program vpngui.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 27ac Start Time:
01cce803bba98cad Termination Time: 120 Application Path: C:\Program Files\Cisco Systems\VPN
Client\vpngui.exe Report Id: 5d0bc9be-55c7-11e1-864e-c80953cf97d0

Error - 2/13/2012 10:55:39 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Application Hang | ID = 1002
Description = The program Acrobat.exe version 10.1.0.534 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 2694 Start
Time: 01ccea5e9a381ee4 Termination Time: 6 Application Path: C:\Program Files\Adobe\Acrobat
10.0\Acrobat\Acrobat.exe Report Id: c98b5480-5652-11e1-864e-c80953cf97d0

Error - 2/13/2012 10:57:34 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Application Hang | ID = 1002
Description = The program Acrobat.exe version 10.1.0.534 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1698 Start
Time: 01ccea5f915db115 Termination Time: 0 Application Path: C:\Program Files\Adobe\Acrobat
10.0\Acrobat\Acrobat.exe Report Id: 0e1873a3-5653-11e1-864e-c80953cf97d0

Error - 2/13/2012 10:59:17 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Application Hang | ID = 1002
Description = The program Acrobat.exe version 10.1.0.534 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 2044 Start
Time: 01ccea5fd2ff48de Termination Time: 0 Application Path: C:\Program Files\Adobe\Acrobat
10.0\Acrobat\Acrobat.exe Report Id: 4bc82321-5653-11e1-864e-c80953cf97d0

Error - 2/14/2012 12:57:47 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/14/2012 12:57:47 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 15569

Error - 2/14/2012 12:57:47 AM | Computer Name = 31296STD.crowe-chizek.com | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 15569

[ ManageSoft Events ]
Error - 5/10/2012 9:26:07 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Policy Agent | ID = 65537
Description = ERROR: The specified domain either does not exist or could not be
contacted. ERROR: Unable to translate NT4-style account name CROWE-CHIZEK\31296STD$
to a distinguished name ERROR: Cannot generate merged deployment policy Program exited
with code 1

Error - 5/10/2012 9:26:11 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T202611] Failed to run "Apply Machine Policy" - Program did
not execute successfully

Error - 5/10/2012 10:02:03 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Policy Agent | ID = 65537
Description = ERROR: The specified domain either does not exist or could not be
contacted. ERROR: Unable to translate NT4-style account name CROWE-CHIZEK\31296STD$
to a distinguished name ERROR: Cannot generate merged deployment policy Program exited
with code 1

Error - 5/10/2012 10:02:07 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T210207] Failed to run "Update Schedule" - Program did not
execute successfully

Error - 5/10/2012 10:08:02 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Policy Agent | ID = 65537
Description = ERROR: The specified domain either does not exist or could not be
contacted. ERROR: Unable to translate NT4-style account name CROWE-CHIZEK\31296STD$
to a distinguished name ERROR: Cannot generate merged deployment policy Program exited
with code 1

Error - 5/10/2012 10:08:06 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T210806] Failed to run "Apply Machine Policy" - Program did
not execute successfully

Error - 5/10/2012 10:12:03 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Policy Agent | ID = 65537
Description = ERROR: The specified domain either does not exist or could not be
contacted. ERROR: Unable to translate NT4-style account name CROWE-CHIZEK\31296STD$
to a distinguished name ERROR: Cannot generate merged deployment policy Program exited
with code 1

Error - 5/10/2012 10:12:07 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T211207] Failed to run "Apply Machine Policy" - Program did
not execute successfully

Error - 5/10/2012 10:15:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Installation Agent | ID = 65537
Description =

Error - 5/10/2012 10:15:42 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Schedule Agent | ID = 65537
Description = [20120510T211542] Failed to run "Update Client Settings" - Program
did not execute successfully

[ System Events ]
Error - 5/10/2012 9:53:45 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7023
Description = The Cercsr6 service terminated with the following error: %%126

Error - 5/10/2012 9:53:45 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7023
Description = The Nidomainservice service terminated with the following error: %%126

Error - 5/10/2012 9:53:45 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7003
Description = The IPsec Policy Agent service depends the following service: BFE.
This service might not be installed.

Error - 5/10/2012 9:53:47 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.

Error - 5/10/2012 9:53:51 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
luafv

Error - 5/10/2012 9:53:53 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.

Error - 5/10/2012 9:54:13 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.

Error - 5/10/2012 9:54:16 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.

Error - 5/10/2012 10:11:01 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7030
Description = The ESET Service service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 5/10/2012 10:11:30 PM | Computer Name = 31296STD.crowe-chizek.com | Source = Service Control Manager | ID = 7003
Description = The epfwwfpr service depends the following service: BFE. This service
might not be installed.


< End of report >
Hi,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
Thank you for your help. I couldn't get the DDS downloads to work. Here is the error message I got. Unable to download dds.scr from download.bleepingcomputer.com. Unale to open this Internet site. The requested site is either unavailable or cannot be found. Please try again later. The following is the aswMBR.exe scan results. aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-05-10 23:43:15 —————————– 23:43:15.046 OS Version: Windows 6.1.7601 Service Pack 1 23:43:15.046 Number of processors: 4 586 0x2A07 23:43:15.046 ComputerName: 31296STD UserName: HillMD 23:43:22.269 Initialize success 23:45:11.713 AVAST engine defs: 12051001 23:45:17.329 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 23:45:17.329 Disk 0 Vendor: ST950042 0003 Size: 476940MB BusType: 3 23:45:17.345 Disk 0 MBR read successfully 23:45:17.345 Disk 0 MBR scan 23:45:17.376 Disk 0 Windows 7 default MBR code found via API 23:45:17.392 Disk 0 unknown MBR code 23:45:17.392 Disk 0 MBR hidden 23:45:17.407 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS CRYPT 476913 MB offset 32130 23:45:17.548 Disk 0 scanning sectors +976752000 23:45:17.610 Disk 0 MBR [possible unknown bootkit@MBR] **ROOTKIT** 23:45:17.626 Disk 0 trace - called modules: 23:45:17.641 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll Sidney.sys iaStor.sys 23:45:17.641 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x888ed328] 23:45:17.657 3 CLASSPNP.SYS[8c08359e] -> nt!IofCallDriver -> [0x8693f838] 23:45:17.657 5 ACPI.sys[83efe3d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x868df028] 23:45:21.604 AVAST engine scan C:\Windows 23:45:21.619 AVAST engine scan C:\Windows\system32 23:45:21.635 AVAST engine scan C:\Windows\system32\drivers 23:45:21.650 AVAST engine scan C:\Users\hillmd 23:45:21.650 AVAST engine scan C:\ProgramData 23:45:21.666 Scan finished successfully 23:45:47.437 Disk 0 MBR has been saved successfully to "C:\Users\hillmd\Desktop\MBR.dat" 23:45:47.453 The log file has been saved successfully to "C:\Users\hillmd\Desktop\aswMBR.txt"

Attachments:

Hi michaeldhill8,

No problem :). That's fine.

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
06:57:27.0176 7936 TDSS rootkit removing tool 2.7.34.0 May 2 2012 09:59:18 06:57:27.0566 7936 ============================================================ 06:57:27.0566 7936 Current date / time: 2012/05/11 06:57:27.0566 06:57:27.0566 7936 SystemInfo: 06:57:27.0566 7936 06:57:27.0566 7936 OS Version: 6.1.7601 ServicePack: 1.0 06:57:27.0566 7936 Product type: Workstation 06:57:27.0566 7936 ComputerName: 31296STD 06:57:27.0566 7936 UserName: HillMD 06:57:27.0566 7936 Windows directory: C:\Windows 06:57:27.0566 7936 System windows directory: C:\Windows 06:57:27.0566 7936 Processor architecture: Intel x86 06:57:27.0566 7936 Number of processors: 4 06:57:27.0566 7936 Page size: 0x1000 06:57:27.0566 7936 Boot type: Normal boot 06:57:27.0566 7936 ============================================================ 06:57:29.0890 7936 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 06:57:29.0890 7936 ============================================================ 06:57:29.0890 7936 \Device\Harddisk0\DR0: 06:57:29.0906 7936 MBR partitions: 06:57:29.0906 7936 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x7D82, BlocksNum 0x3A378FFE 06:57:29.0906 7936 ============================================================ 06:57:29.0906 7936 Initialize success 06:57:29.0906 7936 ============================================================ 06:57:31.0403 7976 ============================================================ 06:57:31.0403 7976 Scan started 06:57:31.0403 7976 Mode: Manual; 06:57:31.0403 7976 ============================================================ 06:57:31.0700 7976 1394ohci - ok 06:57:31.0715 7976 5U877 - ok 06:57:31.0731 7976 ACPI - ok 06:57:31.0731 7976 AcpiPmi - ok 06:57:31.0747 7976 adp94xx - ok 06:57:31.0747 7976 adpahci - ok 06:57:31.0762 7976 adpu320 - ok 06:57:31.0762 7976 AeLookupSvc - ok 06:57:31.0778 7976 AFD - ok 06:57:31.0778 7976 agp440 - ok 06:57:31.0778 7976 aic78xx - ok 06:57:31.0778 7976 ALG - ok 06:57:31.0793 7976 aliide - ok 06:57:31.0793 7976 amdagp - ok 06:57:31.0793 7976 amdide - ok 06:57:31.0793 7976 AmdK8 - ok 06:57:31.0793 7976 AmdPPM - ok 06:57:31.0793 7976 amdsata - ok 06:57:31.0809 7976 amdsbs - ok 06:57:31.0809 7976 amdxata - ok 06:57:31.0809 7976 AppID - ok 06:57:31.0825 7976 AppIDSvc - ok 06:57:31.0856 7976 Appinfo - ok 06:57:31.0856 7976 Apple Mobile Device - ok 06:57:31.0871 7976 AppMgmt - ok 06:57:31.0887 7976 arc - ok 06:57:31.0887 7976 arcsas - ok 06:57:31.0934 7976 aspnet_state - ok 06:57:31.0934 7976 AsyncMac - ok 06:57:31.0934 7976 atapi - ok 06:57:31.0949 7976 AudioEndpointBuilder - ok 06:57:31.0949 7976 Audiosrv - ok 06:57:31.0981 7976 AxInstSV - ok 06:57:31.0996 7976 b06bdrv - ok 06:57:31.0996 7976 b57nd60x - ok 06:57:32.0012 7976 Bcim - ok 06:57:32.0027 7976 BDESVC - ok 06:57:32.0027 7976 BEDevCtl - ok 06:57:32.0027 7976 Beep - ok 06:57:32.0027 7976 BEFCSvcn - ok 06:57:32.0027 7976 BeFlt - ok 06:57:32.0043 7976 BE_FLTI - ok 06:57:32.0043 7976 BITS - ok 06:57:32.0043 7976 blbdrive - ok 06:57:32.0059 7976 Bonjour Service - ok 06:57:32.0074 7976 bowser - ok 06:57:32.0074 7976 BrFiltLo - ok 06:57:32.0074 7976 BrFiltUp - ok 06:57:32.0074 7976 Browser - ok 06:57:32.0074 7976 Brserid - ok 06:57:32.0074 7976 BrSerWdm - ok 06:57:32.0090 7976 BrUsbMdm - ok 06:57:32.0090 7976 BrUsbSer - ok 06:57:32.0105 7976 BthEnum - ok 06:57:32.0105 7976 BTHMODEM - ok 06:57:32.0105 7976 BthPan - ok 06:57:32.0105 7976 BTHPORT - ok 06:57:32.0121 7976 bthserv - ok 06:57:32.0121 7976 BTHUSB - ok 06:57:32.0121 7976 cdfs - ok 06:57:32.0121 7976 cdrom - ok 06:57:32.0121 7976 CEAES2M - ok 06:57:32.0137 7976 CEAESM - ok 06:57:32.0137 7976 CEDES3M - ok 06:57:32.0137 7976 CEDESM - ok 06:57:32.0137 7976 CEEIDEM - ok 06:57:32.0137 7976 CEHMACM - ok 06:57:32.0137 7976 CEIDEM - ok 06:57:32.0152 7976 CERNDM - ok 06:57:32.0168 7976 CertPropSvc - ok 06:57:32.0168 7976 CESHAM - ok 06:57:32.0183 7976 circlass - ok 06:57:32.0183 7976 CLFS - ok 06:57:32.0183 7976 clr_optimization_v2.0.50727_32 - ok 06:57:32.0215 7976 clr_optimization_v4.0.30319_32 - ok 06:57:32.0215 7976 CmBatt - ok 06:57:32.0215 7976 cmdide - ok 06:57:32.0215 7976 CNG - ok 06:57:32.0215 7976 CnxtHdAudService - ok 06:57:32.0230 7976 Compbatt - ok 06:57:32.0230 7976 CompositeBus - ok 06:57:32.0230 7976 COMSysApp - ok 06:57:32.0230 7976 crcdisk - ok 06:57:32.0246 7976 CryptSvc - ok 06:57:32.0246 7976 CSC - ok 06:57:32.0246 7976 CscService - ok 06:57:32.0261 7976 CVirtA - ok 06:57:32.0261 7976 CVPND - ok 06:57:32.0277 7976 CVPNDRVA - ok 06:57:32.0277 7976 CxAudMsg - ok 06:57:32.0277 7976 DcomLaunch - ok 06:57:32.0277 7976 defragsvc - ok 06:57:32.0277 7976 DfsC - ok 06:57:32.0293 7976 Dhcp - ok 06:57:32.0293 7976 Diego - ok 06:57:32.0293 7976 discache - ok 06:57:32.0293 7976 Disk - ok 06:57:32.0308 7976 Diskeeper - ok 06:57:32.0308 7976 DKRtWrt - ok 06:57:32.0324 7976 DLOChangeJournalSvc - ok 06:57:32.0324 7976 dmvsc - ok 06:57:32.0324 7976 DNE - ok 06:57:32.0324 7976 Dnscache - ok 06:57:32.0324 7976 dot3svc - ok 06:57:32.0339 7976 dot4 - ok 06:57:32.0339 7976 Dot4Print - ok 06:57:32.0339 7976 dot4usb - ok 06:57:32.0339 7976 DPS - ok 06:57:32.0355 7976 drmkaud - ok 06:57:32.0355 7976 DXGKrnl - ok 06:57:32.0355 7976 e1cexpress - ok 06:57:32.0355 7976 EapHost - ok 06:57:32.0371 7976 ebdrv - ok 06:57:32.0371 7976 EFS - ok 06:57:32.0371 7976 ehRecvr - ok 06:57:32.0371 7976 ehSched - ok 06:57:32.0371 7976 elxstor - ok 06:57:32.0386 7976 enterceptAgent - ok 06:57:32.0386 7976 ErrDev - ok 06:57:32.0386 7976 EventSystem - ok 06:57:32.0386 7976 exfat - ok 06:57:32.0402 7976 fastfat - ok 06:57:32.0402 7976 Fax - ok 06:57:32.0402 7976 fdc - ok 06:57:32.0402 7976 fdPHost - ok 06:57:32.0402 7976 FDResPub - ok 06:57:32.0402 7976 FileInfo - ok 06:57:32.0417 7976 Filetrace - ok 06:57:32.0417 7976 Firehk - ok 06:57:32.0417 7976 FirehkMP - ok 06:57:32.0417 7976 firelm01 - ok 06:57:32.0417 7976 FirePM - ok 06:57:32.0433 7976 FireTDI - ok 06:57:32.0433 7976 flpydisk - ok 06:57:32.0433 7976 FltMgr - ok 06:57:32.0433 7976 FontCache - ok 06:57:32.0433 7976 FontCache3.0.0.0 - ok 06:57:32.0433 7976 FsDepends - ok 06:57:32.0449 7976 Fs_Rec - ok 06:57:32.0449 7976 fvevol - ok 06:57:32.0449 7976 gagp30kx - ok 06:57:32.0449 7976 GEARAspiWDM - ok 06:57:32.0449 7976 gpsvc - ok 06:57:32.0464 7976 gupdate - ok 06:57:32.0480 7976 gupdatem - ok 06:57:32.0480 7976 hcw85cir - ok 06:57:32.0480 7976 HdAudAddService - ok 06:57:32.0480 7976 HDAudBus - ok 06:57:32.0480 7976 HidBatt - ok 06:57:32.0480 7976 HidBth - ok 06:57:32.0495 7976 HidIr - ok 06:57:32.0495 7976 hidserv - ok 06:57:32.0495 7976 HidUsb - ok 06:57:32.0495 7976 HIPK - ok 06:57:32.0495 7976 HIPPSK - ok 06:57:32.0495 7976 HIPQK - ok 06:57:32.0511 7976 hips - ok 06:57:32.0511 7976 hkmsvc - ok 06:57:32.0511 7976 HomeGroupListener - ok 06:57:32.0511 7976 HomeGroupProvider - ok 06:57:32.0511 7976 HpSAMD - ok 06:57:32.0527 7976 HTTP - ok 06:57:32.0527 7976 hwpolicy - ok 06:57:32.0527 7976 i8042prt - ok 06:57:32.0527 7976 iaStor - ok 06:57:32.0527 7976 iaStorV - ok 06:57:32.0542 7976 IBMPMDRV - ok 06:57:32.0542 7976 IBMPMSVC - ok 06:57:32.0542 7976 idsvc - ok 06:57:32.0542 7976 igfx - ok 06:57:32.0542 7976 iirsp - ok 06:57:32.0558 7976 IKEEXT - ok 06:57:32.0558 7976 intelide - ok 06:57:32.0558 7976 intelppm - ok 06:57:32.0558 7976 iPassConnectEngine - ok 06:57:32.0558 7976 iPassPeriodicUpdateApp - ok 06:57:32.0573 7976 iPassPeriodicUpdateService - ok 06:57:32.0573 7976 IPBusEnum - ok 06:57:32.0573 7976 IpFilterDriver - ok 06:57:32.0573 7976 IPMIDRV - ok 06:57:32.0573 7976 IPNAT - ok 06:57:32.0573 7976 iPod Service - ok 06:57:32.0589 7976 IRENUM - ok 06:57:32.0589 7976 isapnp - ok 06:57:32.0589 7976 iScsiPrt - ok 06:57:32.0605 7976 kbdclass - ok 06:57:32.0605 7976 kbdhid - ok 06:57:32.0605 7976 KeyIso - ok 06:57:32.0605 7976 KSecDD - ok 06:57:32.0620 7976 KSecPkg - ok 06:57:32.0620 7976 KtmRm - ok 06:57:32.0620 7976 LanmanServer - ok 06:57:32.0620 7976 LanmanWorkstation - ok 06:57:32.0620 7976 LENOVO.MICMUTE - ok 06:57:32.0636 7976 lenovo.smi - ok 06:57:32.0636 7976 lltdio - ok 06:57:32.0636 7976 lltdsvc - ok 06:57:32.0636 7976 lmhosts - ok 06:57:32.0636 7976 Lotus Notes Single Logon - ok 06:57:32.0651 7976 LSI_FC - ok 06:57:32.0651 7976 LSI_SAS - ok 06:57:32.0651 7976 LSI_SAS2 - ok 06:57:32.0667 7976 LSI_SCSI - ok 06:57:32.0667 7976 luafv - ok 06:57:32.0683 7976 McAfee SiteAdvisor Enterprise Service - ok 06:57:32.0698 7976 McAfeeFramework - ok 06:57:32.0698 7976 McShield - ok 06:57:32.0698 7976 McTaskManager - ok 06:57:32.0714 7976 Mcx2Svc - ok 06:57:32.0714 7976 megasas - ok 06:57:32.0714 7976 MegaSR - ok 06:57:32.0714 7976 MEI - ok 06:57:32.0729 7976 mfeapfk - ok 06:57:32.0729 7976 mfeavfk - ok 06:57:32.0745 7976 mfeavfk01 - ok 06:57:32.0745 7976 mfebopk - ok 06:57:32.0745 7976 mfehidk - ok 06:57:32.0745 7976 mferkdet - ok 06:57:32.0761 7976 mfetdik - ok 06:57:32.0761 7976 mfevtp - ok 06:57:32.0761 7976 mfewfpk - ok 06:57:32.0776 7976 mgsdl - ok 06:57:32.0776 7976 mgssecsvc - ok 06:57:32.0776 7976 Microsoft SharePoint Workspace Audit Service - ok 06:57:32.0776 7976 MMCSS - ok 06:57:32.0792 7976 Modem - ok 06:57:32.0792 7976 monitor - ok 06:57:32.0792 7976 mouclass - ok 06:57:32.0792 7976 mouhid - ok 06:57:32.0807 7976 mountmgr - ok 06:57:32.0807 7976 mpio - ok 06:57:32.0807 7976 mpsdrv - ok 06:57:32.0807 7976 MRxDAV - ok 06:57:32.0807 7976 mrxsmb - ok 06:57:32.0823 7976 mrxsmb10 - ok 06:57:32.0823 7976 mrxsmb20 - ok 06:57:32.0823 7976 msahci - ok 06:57:32.0823 7976 msdsm - ok 06:57:32.0823 7976 MSDTC - ok 06:57:32.0839 7976 Msfs - ok 06:57:32.0839 7976 mshidkmdf - ok 06:57:32.0839 7976 msisadrv - ok 06:57:32.0839 7976 MSiSCSI - ok 06:57:32.0839 7976 msiserver - ok 06:57:32.0854 7976 MSKSSRV - ok 06:57:32.0854 7976 MSPCLOCK - ok 06:57:32.0854 7976 MSPQM - ok 06:57:32.0854 7976 MsRPC - ok 06:57:32.0870 7976 mssmbios - ok 06:57:32.0870 7976 MSTEE - ok 06:57:32.0870 7976 MTConfig - ok 06:57:32.0870 7976 Mup - ok 06:57:32.0870 7976 napagent - ok 06:57:32.0885 7976 NativeWifiP - ok 06:57:32.0885 7976 ndGlobalLauncher - ok 06:57:32.0885 7976 ndinit - ok 06:57:32.0885 7976 NDIS - ok 06:57:32.0885 7976 NdisCap - ok 06:57:32.0901 7976 NdisTapi - ok 06:57:32.0901 7976 Ndisuio - ok 06:57:32.0901 7976 NdisWan - ok 06:57:32.0901 7976 NDProxy - ok 06:57:32.0901 7976 NetBIOS - ok 06:57:32.0901 7976 NetBT - ok 06:57:32.0917 7976 Netlogon - ok 06:57:32.0932 7976 Netman - ok 06:57:32.0932 7976 NetMsmqActivator - ok 06:57:32.0932 7976 NetPipeActivator - ok 06:57:32.0932 7976 netprofm - ok 06:57:32.0948 7976 NetTcpActivator - ok 06:57:32.0948 7976 NetTcpPortSharing - ok 06:57:32.0948 7976 NETwNs32 - ok 06:57:32.0948 7976 nfrd960 - ok 06:57:32.0963 7976 NlaSvc - ok 06:57:32.0963 7976 Npfs - ok 06:57:32.0963 7976 nsausvc - ok 06:57:32.0979 7976 nsi - ok 06:57:32.0979 7976 nsiproxy - ok 06:57:32.0979 7976 Ntfs - ok 06:57:32.0979 7976 Null - ok 06:57:32.0995 7976 nvkflt - ok 06:57:32.0995 7976 nvlddmkm - ok 06:57:32.0995 7976 nvpciflt - ok 06:57:32.0995 7976 nvraid - ok 06:57:33.0010 7976 nvstor - ok 06:57:33.0010 7976 nvstor64 - ok 06:57:33.0010 7976 NVSvc - ok 06:57:33.0010 7976 nvUpdatusService - ok 06:57:33.0010 7976 nv_agp - ok 06:57:33.0026 7976 ohci1394 - ok 06:57:33.0026 7976 oracle_load_balancer_60_client-forms6i - ok 06:57:33.0026 7976 ose - ok 06:57:33.0026 7976 osppsvc - ok 06:57:33.0041 7976 p2pimsvc - ok 06:57:33.0041 7976 p2psvc - ok 06:57:33.0041 7976 Parport - ok 06:57:33.0041 7976 partmgr - ok 06:57:33.0041 7976 Parvdm - ok 06:57:33.0041 7976 PcaSvc - ok 06:57:33.0057 7976 pci - ok 06:57:33.0057 7976 pciide - ok 06:57:33.0057 7976 pcmcia - ok 06:57:33.0057 7976 pcw - ok 06:57:33.0057 7976 PEAUTH - ok 06:57:33.0073 7976 PeerDistSvc - ok 06:57:33.0073 7976 pla - ok 06:57:33.0073 7976 PlugPlay - ok 06:57:33.0088 7976 Pml Driver HPZ12 - ok 06:57:33.0088 7976 PNRPAutoReg - ok 06:57:33.0088 7976 PNRPsvc - ok 06:57:33.0088 7976 PolicyAgent - ok 06:57:33.0104 7976 Power - ok 06:57:33.0104 7976 PptpMiniport - ok 06:57:33.0104 7976 Processor - ok 06:57:33.0119 7976 ProfSvc - ok 06:57:33.0119 7976 ProtectedStorage - ok 06:57:33.0119 7976 psadd - ok 06:57:33.0119 7976 Psched - ok 06:57:33.0135 7976 PWSSvc - ok 06:57:33.0135 7976 ql2300 - ok 06:57:33.0151 7976 ql40xx - ok 06:57:33.0151 7976 QWAVE - ok 06:57:33.0151 7976 QWAVEdrv - ok 06:57:33.0166 7976 RasAcd - ok 06:57:33.0166 7976 RasAgileVpn - ok 06:57:33.0166 7976 RasAuto - ok 06:57:33.0166 7976 Rasl2tp - ok 06:57:33.0166 7976 RasMan - ok 06:57:33.0182 7976 RasPppoe - ok 06:57:33.0182 7976 RasSstp - ok 06:57:33.0182 7976 rdbss - ok 06:57:33.0197 7976 RDID1007 - ok 06:57:33.0197 7976 rdpbus - ok 06:57:33.0213 7976 RDPCDD - ok 06:57:33.0213 7976 RDPDR - ok 06:57:33.0213 7976 RDPENCDD - ok 06:57:33.0213 7976 RDPREFMP - ok 06:57:33.0229 7976 RdpVideoMiniport - ok 06:57:33.0229 7976 RDPWD - ok 06:57:33.0229 7976 rdyboost - ok 06:57:33.0229 7976 RemoteAccess - ok 06:57:33.0244 7976 RemoteRegistry - ok 06:57:33.0244 7976 RFCOMM - ok 06:57:33.0244 7976 risdxc - ok 06:57:33.0244 7976 RpcEptMapper - ok 06:57:33.0260 7976 RpcLocator - ok 06:57:33.0260 7976 RpcSs - ok 06:57:33.0260 7976 rspndr - ok 06:57:33.0260 7976 s3cap - ok 06:57:33.0275 7976 Sahara - ok 06:57:33.0275 7976 Salvador - ok 06:57:33.0275 7976 SamSs - ok 06:57:33.0275 7976 Santa - ok 06:57:33.0275 7976 SAService - ok 06:57:33.0291 7976 sbp2port - ok 06:57:33.0291 7976 SCardSvr - ok 06:57:33.0291 7976 Scarlet - ok 06:57:33.0291 7976 scfilter - ok 06:57:33.0307 7976 Schedule - ok 06:57:33.0307 7976 SCPolicySvc - ok 06:57:33.0307 7976 SDBAgent - ok 06:57:33.0307 7976 SDRSVC - ok 06:57:33.0307 7976 secdrv - ok 06:57:33.0322 7976 seclogon - ok 06:57:33.0322 7976 SENS - ok 06:57:33.0322 7976 SensrSvc - ok 06:57:33.0322 7976 Serenum - ok 06:57:33.0322 7976 Serial - ok 06:57:33.0338 7976 sermouse - ok 06:57:33.0338 7976 SessionEnv - ok 06:57:33.0338 7976 sffdisk - ok 06:57:33.0353 7976 sffp_mmc - ok 06:57:33.0353 7976 sffp_sd - ok 06:57:33.0353 7976 sfloppy - ok 06:57:33.0353 7976 SGNAuthService - ok 06:57:33.0353 7976 SGN_BEService - ok 06:57:33.0369 7976 SGN_LogSystem - ok 06:57:33.0369 7976 SGN_Sem - ok 06:57:33.0369 7976 SGN_Trans - ok 06:57:33.0369 7976 SGSTDRVM - ok 06:57:33.0369 7976 Shandy - ok 06:57:33.0385 7976 SharedAccess - ok 06:57:33.0385 7976 ShellHWDetection - ok 06:57:33.0385 7976 Shlos - ok 06:57:33.0385 7976 Shockprf - ok 06:57:33.0400 7976 Sidney - ok 06:57:33.0400 7976 sisagp - ok 06:57:33.0400 7976 SiSRaid2 - ok 06:57:33.0400 7976 SiSRaid4 - ok 06:57:33.0400 7976 SkypeUpdate - ok 06:57:33.0416 7976 Smb - ok 06:57:33.0416 7976 SNMPTRAP - ok 06:57:33.0416 7976 Sofia - ok 06:57:33.0431 7976 SofiaMp - ok 06:57:33.0431 7976 Sofy - ok 06:57:33.0431 7976 SophosSGPPS - ok 06:57:33.0431 7976 Spfd - ok 06:57:33.0447 7976 SpfdBus - ok 06:57:33.0447 7976 spldr - ok 06:57:33.0447 7976 Spooler - ok 06:57:33.0447 7976 sppsvc - ok 06:57:33.0463 7976 sppuinotify - ok 06:57:33.0463 7976 srv - ok 06:57:33.0463 7976 srv2 - ok 06:57:33.0463 7976 srvnet - ok 06:57:33.0463 7976 SSDPSRV - ok 06:57:33.0478 7976 SstpSvc - ok 06:57:33.0478 7976 stexstor - ok 06:57:33.0478 7976 StiSvc - ok 06:57:33.0478 7976 storflt - ok 06:57:33.0494 7976 StorSvc - ok 06:57:33.0494 7976 storvsc - ok 06:57:33.0494 7976 swenum - ok 06:57:33.0494 7976 swprv - ok 06:57:33.0494 7976 Synth3dVsc - ok 06:57:33.0509 7976 SynTP - ok 06:57:33.0509 7976 SysMain - ok 06:57:33.0509 7976 TabletInputService - ok 06:57:33.0509 7976 TapiSrv - ok 06:57:33.0525 7976 TBS - ok 06:57:33.0525 7976 Tcpip - ok 06:57:33.0525 7976 TCPIP6 - ok 06:57:33.0525 7976 tcpipreg - ok 06:57:33.0541 7976 TDPIPE - ok 06:57:33.0541 7976 TDTCP - ok 06:57:33.0541 7976 tdx - ok 06:57:33.0541 7976 TermDD - ok 06:57:33.0541 7976 terminpt - ok 06:57:33.0556 7976 TermService - ok 06:57:33.0556 7976 Themes - ok 06:57:33.0556 7976 THREADORDER - ok 06:57:33.0556 7976 TPDIGIMN - ok 06:57:33.0572 7976 TPHDEXLGSVC - ok 06:57:33.0572 7976 TPHKLOAD - ok 06:57:33.0572 7976 TPHKSVC - ok 06:57:33.0572 7976 TPM - ok 06:57:33.0587 7976 TrkWks - ok 06:57:33.0587 7976 TrustedInstaller - ok 06:57:33.0587 7976 tssecsrv - ok 06:57:33.0587 7976 TsUsbFlt - ok 06:57:33.0603 7976 TsUsbGD - ok 06:57:33.0603 7976 tsusbhub - ok 06:57:33.0603 7976 tunnel - ok 06:57:33.0619 7976 TVTI2C - ok 06:57:33.0619 7976 uagp35 - ok 06:57:33.0619 7976 udfs - ok 06:57:33.0634 7976 UI0Detect - ok 06:57:33.0634 7976 uliagpkx - ok 06:57:33.0634 7976 umbus - ok 06:57:33.0634 7976 UmPass - ok 06:57:33.0650 7976 UmRdpService - ok 06:57:33.0650 7976 upnphost - ok 06:57:33.0650 7976 USBAAPL - ok 06:57:33.0650 7976 usbccgp - ok 06:57:33.0665 7976 usbcir - ok 06:57:33.0665 7976 usbehci - ok 06:57:33.0665 7976 usbhub - ok 06:57:33.0665 7976 usbohci - ok 06:57:33.0681 7976 usbprint - ok 06:57:33.0681 7976 usbscan - ok 06:57:33.0681 7976 USBSTOR - ok 06:57:33.0681 7976 usbuhci - ok 06:57:33.0681 7976 usbvideo - ok 06:57:33.0697 7976 UxSms - ok 06:57:33.0697 7976 VaultSvc - ok 06:57:33.0697 7976 vdrvroot - ok 06:57:33.0697 7976 vds - ok 06:57:33.0712 7976 vga - ok 06:57:33.0712 7976 VgaSave - ok 06:57:33.0712 7976 VGPU - ok 06:57:33.0712 7976 vhdmp - ok 06:57:33.0728 7976 viaagp - ok 06:57:33.0728 7976 ViaC7 - ok 06:57:33.0728 7976 viaide - ok 06:57:33.0728 7976 vmbus - ok 06:57:33.0728 7976 VMBusHID - ok 06:57:33.0743 7976 volmgr - ok 06:57:33.0743 7976 volmgrx - ok 06:57:33.0743 7976 volsnap - ok 06:57:33.0743 7976 vsmraid - ok 06:57:33.0759 7976 VSS - ok 06:57:33.0759 7976 vwifibus - ok 06:57:33.0759 7976 vwififlt - ok 06:57:33.0759 7976 W32Time - ok 06:57:33.0775 7976 WacomPen - ok 06:57:33.0775 7976 WANARP - ok 06:57:33.0775 7976 Wanarpv6 - ok 06:57:33.0775 7976 wbengine - ok 06:57:33.0790 7976 WbioSrvc - ok 06:57:33.0790 7976 wcncsvc - ok 06:57:33.0790 7976 WcsPlugInService - ok 06:57:33.0790 7976 Wd - ok 06:57:33.0806 7976 Wdf01000 - ok 06:57:33.0806 7976 WdiServiceHost - ok 06:57:33.0806 7976 WdiSystemHost - ok 06:57:33.0806 7976 WebClient - ok 06:57:33.0821 7976 Wecsvc - ok 06:57:33.0821 7976 wercplsupport - ok 06:57:33.0821 7976 WerSvc - ok 06:57:33.0821 7976 WfpLwf - ok 06:57:33.0837 7976 WIMMount - ok 06:57:33.0837 7976 WinHttpAutoProxySvc - ok 06:57:33.0837 7976 Winmgmt - ok 06:57:33.0853 7976 WinRM - ok 06:57:33.0853 7976 WinUsb - ok 06:57:33.0868 7976 Wlansvc - ok 06:57:33.0868 7976 WmiAcpi - ok 06:57:33.0868 7976 wmiApSrv - ok 06:57:33.0884 7976 WMPNetworkSvc - ok 06:57:33.0884 7976 WPCSvc - ok 06:57:33.0884 7976 WPDBusEnum - ok 06:57:33.0884 7976 ws2ifsl - ok 06:57:33.0884 7976 WSearch - ok 06:57:33.0899 7976 wuauserv - ok 06:57:33.0899 7976 WudfPf - ok 06:57:33.0899 7976 WUDFRd - ok 06:57:33.0899 7976 wudfsvc - ok 06:57:33.0915 7976 WwanSvc - ok 06:57:33.0946 7976 {eda5f5d3-9e0f-4f4d-8a13-1d1cf469c9cc} - ok 06:57:33.0962 7976 MBR (0x1B8) (c8a06e6344251a5a6d1ffbbda3bf40f1) \Device\Harddisk0\DR0 06:57:34.0040 7976 \Device\Harddisk0\DR0 - ok 06:57:34.0055 7976 Boot (0x1200) (a288ded9fe758244423362cb51d0a424) \Device\Harddisk0\DR0\Partition0 06:57:34.0055 7976 \Device\Harddisk0\DR0\Partition0 - ok 06:57:34.0055 7976 ============================================================ 06:57:34.0055 7976 Scan finished 06:57:34.0055 7976 ============================================================ 06:57:34.0087 7968 Detected object count: 0 06:57:34.0087 7968 Actual detected object count: 0
Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI