This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Search engine redirects [Solved]

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
OTL logfile created on: 6/8/2012 2:00:54 PM - Run 1
OTL by OldTimer - Version 3.2.47.0 Folder = C:\Documents and Settings\jzipkin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.49 Gb Total Physical Memory | 2.83 Gb Available Physical Memory | 81.05% Memory free
5.32 Gb Paging File | 4.42 Gb Available in Paging File | 83.01% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.99 Gb Total Space | 108.81 Gb Free Space | 73.03% Space Free | Partition Type: NTFS
Drive U: | 246.92 Gb Total Space | 108.81 Gb Free Space | 44.07% Space Free | Partition Type: NTFS
Drive W: | 246.92 Gb Total Space | 108.81 Gb Free Space | 44.07% Space Free | Partition Type: NTFS
Drive X: | 246.92 Gb Total Space | 108.81 Gb Free Space | 44.07% Space Free | Partition Type: NTFS
Drive Y: | 246.92 Gb Total Space | 108.81 Gb Free Space | 44.07% Space Free | Partition Type: NTFS
Drive Z: | 246.92 Gb Total Space | 108.81 Gb Free Space | 44.07% Space Free | Partition Type: NTFS

Computer Name: C4LHXH1 | User Name: jzipkin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\jzipkin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Documents and Settings\jzipkin\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
PRC - C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfeann.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\HPSIsvc.exe (HP)
PRC - C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - c:\drivers\audio\R267815\payload\WDM\stacsv.exe (IDT, Inc.)
PRC - C:\WINDOWS\system32\AESTFltr.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\OA001Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Yahoo!\Common\YMailAdvisor.exe (Yahoo! Inc.)
PRC - C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe (Sage Software, Inc.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe (Dell Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe (Dell Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe (Dell Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
PRC - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
PRC - C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Genghis\4ec6587ba23030fa1c14ef684a18351e\Genghis.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\62e34cfb5a8b233667c7c5a47a32ad93\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\3c272cad7afb127e2a2bdb8a5a808512\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IsdiInterop\733a109cdd12f97bbfff91e63924bea8\IsdiInterop.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\90b90e700e59d73d6d692cf74e1ba16e\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IAStorUtil\ef89196608b35dfab2f5b31b878730ac\IAStorUtil.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IAStorDataMgr\5441b605b1d8c2cf5ccbab0573811e3f\IAStorDataMgr.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IAStorDataMgrSvc\3c352231fca566d7612b47ba71bf6afa\IAStorDataMgrSvc.ni.exe ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Windows.#\15a297b280cef43a5f9a9477c59564f2\Act.Shared.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Win32\70f279b356c2e26601831c764a83517b\Act.Shared.Win32.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Utilities\7526aa275aa0f9e11e2f2c1c57ad812c\Act.Shared.Utilities.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.LicProvi#\40e614dcbf0dca144f00ab72a1b18e85\Act.Shared.LicProvider.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Images\2e21ec6a78917b8706761e73a6ea1e87\Act.Shared.Images.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Licensing\828a2ff08f117ccb30871bd2ab5d9a32\Act.Shared.Licensing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Diagnost#\db44282e964afaec6efe510148054c6e\Act.Shared.Diagnostics.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Config\8f3349920ebd24120eb3b88fa49cf26e\Act.Shared.Config.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Shared.Collecti#\79892a316118891749163853e5f946ab\Act.Shared.Collections.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Framework\3157390a3579a9cef986e6ab0331c0e9\Act.Framework.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Data.Resources\7e585554b28d9b7c9aa299b105c09f66\Act.Data.Resources.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Data.ActDb\0f66bf416f375b7e90f50bb07f832445\Act.Data.ActDb.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Act.Data\e81ea38cd416b481949046a57d5fd181\Act.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\1adc4ae51a5ac63e896a1402749ca495\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\WINDOWS\system32\HP1100LM.DLL ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\HP1100PP.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Outlook.Service.Shared\11.1.183.0__ebf6b2ff4d0a08aa\Act.Outlook.Service.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Outlook.Service.Desktop\11.1.183.0__ebf6b2ff4d0a08aa\Act.Outlook.Service.Desktop.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\Act.Outlook.Message.Reader\11.1.183.0__ebf6b2ff4d0a08aa\Act.Outlook.Message.Reader.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Outlook.Service.AppCommon\11.1.183.0__ebf6b2ff4d0a08aa\Act.Outlook.Service.AppCommon.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Act.Outlook.Service.Interfaces\11.1.183.0__ebf6b2ff4d0a08aa\Act.Outlook.Service.Interfaces.dll ()
MOD - C:\Program Files\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll ()
MOD - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AcroTray.DEU ()
MOD - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AcroTray.FRA ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\UCMPlugin\SmithMicro.Common.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMProfileManager.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.SharedUI.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMMessages.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SmithMicro.AsyncOperations.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\VpnWrapper.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SmithMicro.VpnController.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SmithMicro.Application.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SmithMicro.Message.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SmithMicro.Common.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\Dell.DcpPlugin.dll ()
MOD - C:\Program Files\Dell\Dell ControlPoint\SmithMicro.Common.dll ()
MOD - C:\WINDOWS\system32\btwicons.dll ()
MOD - C:\WINDOWS\system32\Wavx_ESC_Logging.dll ()
MOD - C:\WINDOWS\system32\wxvault.dll ()
MOD - C:\Program Files\ACT\Act for Windows\PSIClient.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\TspPopup_ENU.dll ()


========== Win32 Services (SafeList) ==========

SRV - (slee_503_service) – %systemroot%\system32\AMDPCI.dll File not found
SRV - (pavprsrv) – %systemroot%\system32\rasacd.dll File not found
SRV - (nwcworkstation) – %systemroot%\system32\yats32.dll File not found
SRV - (idebusdr) – %systemroot%\system32\dlbu_device.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (JavaQuickStarterService) – C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
SRV - (RumorServer) – C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe (McAfee, Inc.)
SRV - (myAgtSvc) – C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Enterprise Service) – C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe (McAfee, Inc.)
SRV - (HPSIService) – C:\WINDOWS\system32\HPSIsvc.exe (HP)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (XobniService) – C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
SRV - (LBTServ) – C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (STacSV) – c:\drivers\audio\R267815\payload\WDM\stacsv.exe (IDT, Inc.)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (ACT! Scheduler) – C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe (Sage Software, Inc.)
SRV - (Credential Vault Host Storage) – C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
SRV - (Credential Vault Host Control Service) – C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
SRV - (dcpsysmgrsvc) – C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe (Dell Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (SMManager) – C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe (Smith Micro Software, Inc.)
SRV - (buttonsvc32) – C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe (Dell Inc.)
SRV - (TdmService) – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
SRV - (SecureStorageService) – C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe (Wave Systems Corp.)
SRV - (tcsd_win32.exe) – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe ()
SRV - (PSI_SVC_2) – C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (ASFAgent) – C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (WinDriver6) – system32\drivers\windrvr6.sys File not found
DRV - (WDICA) – File not found
DRV - (TRMUSB5K) – system32\drivers\TRMUSB5K.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mfeavfk01) – File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\jzipkin\LOCALS~1\Temp\catchme.sys File not found
DRV - (RsFx0105) – C:\WINDOWS\system32\drivers\RsFx0105.sys (Microsoft Corporation)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (MfeAVFK) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (MfeBOPK) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (SMSIVZAM5) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMSIVZAM5.sys (Smith Micro Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (IDT, Inc.)
DRV - (AESTAud) – C:\WINDOWS\system32\drivers\AESTAud.sys (Andrea Electronics Corporation)
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (OA001Vid) – C:\WINDOWS\system32\drivers\OA001Vid.sys (Creative Technology Ltd.)
DRV - (NWUSBCDFIL) – C:\WINDOWS\system32\drivers\NwUsbCdFil.sys (Novatel Wireless Inc.)
DRV - (NWADI) – C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBPort2) – C:\WINDOWS\system32\drivers\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort) – C:\WINDOWS\system32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) – C:\WINDOWS\system32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (mfetdik) – C:\WINDOWS\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (MfeRKDK) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (NAL) – C:\WINDOWS\system32\drivers\iqvw32.sys (Intel Corporation )
DRV - (e1yexpress) Intel® – C:\WINDOWS\system32\drivers\e1y5132.sys (Intel Corporation)
DRV - (OA001Afx) – C:\WINDOWS\system32\drivers\OA001Afx.sys (Creative Technology Ltd.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (OA001Ufd) – C:\WINDOWS\system32\drivers\OA001Ufd.sys (Creative Technology Ltd.)
DRV - (cvusbdrv) – C:\WINDOWS\system32\drivers\cvusbdrv.sys (Broadcom Corporation)
DRV - (USBCCID) – C:\WINDOWS\system32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (CCIDFILTER) – C:\WINDOWS\system32\drivers\ccidflt.sys (Broadcom Corporation)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (WavxDMgr) – C:\WINDOWS\system32\drivers\WavxDMgr.sys (Wave Systems Corp.)
DRV - (PBADRV) – C:\WINDOWS\system32\drivers\PBADRV.sys (Dell Inc)
DRV - (USA19H) – C:\WINDOWS\system32\drivers\USA19H2k.sys (Keyspan)
DRV - (USA19H2KP) – C:\WINDOWS\system32\drivers\USA19H2kp.sys (Keyspan)
DRV - (TrmbTS) – C:\WINDOWS\system32\drivers\TrmbTS.sys (Trimble AB, Sweden)
DRV - (PCASp50) – C:\WINDOWS\system32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (Sentinel) – C:\WINDOWS\system32\drivers\sentinel.sys (Rainbow Technologies, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Help_Page = http://support.dell.com/support/index.aspx…;l=en&s=gen
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {1866F458-8483-4815-BAD5-D7640059E447}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{1866F458-8483-4815-BAD5-D7640059E447}: "URL" = http://www.google.com/search?q={searchTerm…utputEncoding?}
IE - HKCU\..\SearchScopes\{7AB1F9F9-BDC2-46CC-9008-2CB7C62AB53E}: "URL" = http://search.yahoo.com/search?p={searchTe…ge?}&fr=ie8
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.652: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.652: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\jzipkin\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\jzipkin\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Documents and Settings\jzipkin\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/06/29 11:23:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor Enterprise\ [2011/08/23 13:10:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2011/09/19 20:00:24 | 000,000,000 | —D | M]


O1 HOSTS File: ([2012/06/07 09:47:14 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110919093418.dll (McAfee, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Act! Preloader] C:\Program Files\ACT\Act for Windows\ActSage.exe (Sage Software, Inc.)
O4 - HKLM..\Run: [Act.Outlook.Service] C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe (Sage Software, Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AESTFltr] C:\WINDOWS\System32\AESTFltr.exe (Andrea Electronics Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [DCPstrApp] C:\Program Files\Dell\Dell ControlPoint\Security Manager\SecurityDeviceInfoSetRegistryString.exe (Broadcom Corporation)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [DellConnectionManager] C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe (Smith Micro Software, Inc.)
O4 - HKLM..\Run: [DellControlPoint] C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell, Inc.)
O4 - HKLM..\Run: [EmbassySecurityCheck] C:\Program Files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [OA001Mon] C:\WINDOWS\OA001Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [YMailAdvisor] C:\Program Files\Yahoo!\Common\YMailAdvisor.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Facebook Update] C:\Documents and Settings\jzipkin\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell ControlPoint System Manager.lnk = C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe (Dell Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: //about.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Exclude.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //LanguageSelection.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Message.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryCmd.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryNag.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyNotification.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //NOCLessUpdate.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //quarantine.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //ScanNow.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //strings.vbs/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Template.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Update.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //VirFound.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*]http in Trusted sites)

O15 - HKLM\..Trusted Domains: mcafee.com ([*]https in Trusted sites)

O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] https in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1307550125529 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-31-0.cab (EPUImageControl Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.11
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = waypoint.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3EC90BA7-13DA-43D8-B7BC-EF802309F89E}: DhcpNameServer = 10.0.0.11
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\myrm {4D034FC3-013F-4b95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt5.0.0.811.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\jzipkin\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\jzipkin\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 17:29:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - %systemroot%\system32\yats32.dll File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: pavprsrv - %systemroot%\system32\rasacd.dll File not found
NetSvcs: slee_503_service - %systemroot%\system32\AMDPCI.dll File not found
NetSvcs: idebusdr - %systemroot%\system32\dlbu_device.dll File not found
NetSvcs: slimsvc - File not found
NetSvcs: nwcworkstation - %systemroot%\system32\yats32.dll File not found
NetSvcs: PAC7302 - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: SENTINEL - C:\WINDOWS\System32\snti386.dll (Rainbow Technologies, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/06/08 13:46:58 | 000,595,456 | —- | C] (OldTimer Tools) – C:\Documents and Settings\jzipkin\Desktop\OTL.exe
[2012/06/08 09:44:27 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\jzipkin\Desktop\aswMBR.exe
[2012/06/07 13:38:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/07 13:38:15 | 000,022,344 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/06/07 12:17:15 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/06/07 12:14:22 | 010,063,000 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\jzipkin\Desktop\mbam-setup-1.61.0.1400.exe
[2012/06/07 12:13:21 | 000,446,464 | —- | C] (OldTimer Tools) – C:\Documents and Settings\jzipkin\Desktop\TFC.exe
[2012/06/06 11:08:44 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2012/06/06 11:08:44 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2012/06/06 11:08:44 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2012/06/06 11:08:44 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2012/06/06 11:08:27 | 000,000,000 | —D | C] – C:\Qoobox
[2012/06/06 11:02:08 | 000,000,000 | —D | C] – C:\Documents and Settings\jzipkin\Desktop\tdsskiller
[2012/06/06 11:01:32 | 004,538,022 | R— | C] (Swearware) – C:\Documents and Settings\jzipkin\Desktop\ComboFix.exe
[2012/06/05 09:30:09 | 000,000,000 | —D | C] – C:\Documents and Settings\jzipkin\Desktop\JZpersonal
[2012/05/25 11:49:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Free Audio Pack
[2012/05/25 11:47:49 | 000,000,000 | —D | C] – C:\Documents and Settings\jzipkin\AppData
[2012/05/25 11:47:48 | 000,000,000 | —D | C] – C:\Documents and Settings\jzipkin\Application Data\searchquband
[2012/05/25 11:47:12 | 000,164,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\COMCT232.OCX
[2012/05/25 11:47:05 | 001,212,416 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\AudioInfos.dll
[2012/05/25 11:47:05 | 000,479,232 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\AudioVisu.dll
[2012/05/25 11:47:05 | 000,458,752 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\AudPlayer.dll
[2012/05/25 11:47:05 | 000,454,656 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\AudioRecord.dll
[2012/05/25 11:47:05 | 000,348,160 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\WMAFile.dll
[2012/05/25 11:47:04 | 001,986,560 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\AudFile.dll
[2012/05/25 11:47:04 | 000,417,792 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\AudDisplay.dll
[2012/05/25 11:47:03 | 002,084,864 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\AudDesign.dll
[2012/05/25 11:47:03 | 000,119,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\VB6FR.DLL
[2012/05/25 11:47:03 | 000,115,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msinet.OCX
[2012/05/25 11:47:03 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\VB6STKIT.DLL
[2012/05/25 11:47:03 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\TABCTFR.DLL
[2012/05/25 11:47:03 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\inetfr.DLL
[2012/05/25 11:47:02 | 000,141,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MSCMCFR.DLL
[2012/05/25 11:47:02 | 000,059,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Mscc2fr.dll
[2012/05/25 11:47:02 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CMDLGFR.DLL
[2012/05/25 11:47:01 | 000,000,000 | —D | C] – C:\Documents and Settings\jzipkin\Application Data\FreeAudioPack
[2012/05/25 11:47:01 | 000,000,000 | —D | C] – C:\Program Files\Free mp3 Wma Converter
[2012/05/25 11:28:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2012/05/25 11:28:36 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2012/05/25 11:27:10 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/05/25 11:27:02 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/05/25 11:27:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/05/25 11:26:39 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2012/05/25 11:26:31 | 004,547,944 | —- | C] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll
[2012/05/25 11:20:22 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2012/05/14 16:49:54 | 000,000,000 | —D | C] – C:\Documents and Settings\jzipkin\Application Data\Unity
[2012/05/14 15:48:09 | 000,000,000 | —D | C] – C:\Documents and Settings\jzipkin\Local Settings\Application Data\Unity
[2012/05/11 11:48:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2012/05/11 11:47:47 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2012/05/11 11:47:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2012/05/09 15:47:53 | 011,870,298 | —- | C] (IDT, Inc.) – C:\WINDOWS\System32\idtsg.cpl
[2012/05/09 15:47:53 | 003,354,624 | —- | C] (IDT, Inc.) – C:\WINDOWS\System32\stlang.dll
[2012/05/09 15:47:53 | 000,253,952 | —- | C] (Andrea Electronics Corporation) – C:\WINDOWS\System32\AESTCtrl.cpl

========== Files - Modified Within 30 Days ==========

[2012/06/08 14:00:11 | 000,000,290 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-308600077-3542235570-3293604796-1145.job
[2012/06/08 14:00:11 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-308600077-3542235570-3293604796-1145.job
[2012/06/08 13:51:00 | 000,001,006 | —- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-308600077-3542235570-3293604796-1145UA.job
[2012/06/08 13:51:00 | 000,000,984 | —- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-308600077-3542235570-3293604796-1145Core.job
[2012/06/08 13:46:58 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Documents and Settings\jzipkin\Desktop\OTL.exe
[2012/06/08 13:27:00 | 000,000,888 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/08 13:24:15 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/06/08 13:12:20 | 000,001,890 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2012/06/08 11:22:20 | 000,002,539 | —- | M] () – C:\Documents and Settings\jzipkin\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook 2007.lnk
[2012/06/08 11:01:34 | 000,560,798 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/06/08 11:01:34 | 000,117,144 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/06/08 10:58:16 | 000,000,000 | —- | M] () – C:\Documents and Settings\jzipkin\Local Settings\Application Data\WavXMapDrive.bat
[2012/06/08 10:58:06 | 000,243,584 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2012/06/08 10:58:04 | 000,203,657 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2012/06/08 10:57:39 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/06/08 10:57:17 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/08 10:55:33 | 000,000,316 | —- | M] () – C:\WINDOWS\tasks\geipcppjz.job
[2012/06/08 10:55:14 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/06/08 10:55:04 | 3745,406,976 | -HS- | M] () – C:\hiberfil.sys
[2012/06/08 10:53:34 | 000,058,520 | —- | M] () – C:\Documents and Settings\jzipkin\Desktop\all
[2012/06/08 10:14:38 | 000,000,559 | —- | M] () – C:\Documents and Settings\jzipkin\Desktop\MBR.zip
[2012/06/08 10:13:51 | 000,000,512 | —- | M] () – C:\Documents and Settings\jzipkin\Desktop\MBR.dat
[2012/06/08 09:44:40 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\jzipkin\Desktop\aswMBR.exe
[2012/06/07 13:38:18 | 000,000,788 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/07 12:14:28 | 010,063,000 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\jzipkin\Desktop\mbam-setup-1.61.0.1400.exe
[2012/06/07 12:13:21 | 000,446,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\jzipkin\Desktop\TFC.exe
[2012/06/07 10:03:04 | 000,000,008 | RHS- | M] () – C:\Documents and Settings\All Users\Application Data\8615B8621C.sys
[2012/06/07 09:47:14 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/06/07 09:36:05 | 004,538,022 | R— | M] (Swearware) – C:\Documents and Settings\jzipkin\Desktop\ComboFix.exe
[2012/06/06 11:01:04 | 002,108,959 | —- | M] () – C:\Documents and Settings\jzipkin\Desktop\tdsskiller.zip
[2012/06/05 14:15:54 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\jzipkin\Desktop\HiJackThis.exe
[2012/06/05 12:59:21 | 000,006,144 | —- | M] () – C:\Documents and Settings\jzipkin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/06/04 11:01:15 | 000,163,840 | RHS- | M] () – C:\WINDOWS\System32\c_1257I.dll
[2012/05/18 14:30:16 | 000,000,781 | —- | M] () – C:\Documents and Settings\jzipkin\Application Data\Microsoft\Internet Explorer\Quick Launch\MGIS Product Catalog.lnk
[2012/05/15 15:50:55 | 000,000,143 | —- | M] () – C:\WINDOWS\TRIMSURV.INI

========== Files Created - No Company Name ==========

[2012/06/08 10:53:32 | 000,058,520 | —- | C] () – C:\Documents and Settings\jzipkin\Desktop\all
[2012/06/08 10:14:38 | 000,000,559 | —- | C] () – C:\Documents and Settings\jzipkin\Desktop\MBR.zip
[2012/06/08 10:13:51 | 000,000,512 | —- | C] () – C:\Documents and Settings\jzipkin\Desktop\MBR.dat
[2012/06/07 13:38:18 | 000,000,788 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/07 10:03:04 | 000,000,008 | RHS- | C] () – C:\Documents and Settings\All Users\Application Data\8615B8621C.sys
[2012/06/06 11:08:44 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/06/06 11:08:44 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/06/06 11:08:44 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/06/06 11:08:44 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/06/06 11:08:44 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/06/06 11:00:57 | 002,108,959 | —- | C] () – C:\Documents and Settings\jzipkin\Desktop\tdsskiller.zip
[2012/06/04 11:01:15 | 000,163,840 | RHS- | C] () – C:\WINDOWS\System32\c_1257I.dll
[2012/06/04 11:01:15 | 000,000,316 | —- | C] () – C:\WINDOWS\tasks\geipcppjz.job
[2012/05/25 11:49:01 | 000,484,352 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2012/05/25 11:47:05 | 000,116,296 | —- | C] () – C:\WINDOWS\System32\NCTWMAProfiles.prx
[2012/05/15 10:31:44 | 000,018,203 | —- | C] () – C:\Documents and Settings\jzipkin\Desktop\2241-2TSConfig.tcf
[2012/05/15 10:30:57 | 000,021,488 | —- | C] () – C:\Documents and Settings\jzipkin\Desktop\2241-2 Config.tcf
[2012/03/21 09:57:40 | 000,270,848 | —- | C] () – C:\WINDOWS\System32\unwise32.exe
[2011/12/29 16:47:18 | 001,511,424 | —- | C] () – C:\WINDOWS\System32\HP1100SM.EXE
[2011/12/29 16:47:18 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\HP1100LM.DLL
[2011/12/29 16:46:46 | 000,284,160 | —- | C] () – C:\WINDOWS\System32\mvhlewsi.DLL
[2011/12/29 16:46:38 | 000,047,104 | —- | C] () – C:\WINDOWS\System32\HP1100SMs.dll
[2011/11/04 16:18:01 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/10/25 12:36:01 | 000,000,133 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/07/29 09:26:25 | 000,015,188 | -HS- | C] () – C:\Documents and Settings\jzipkin\Local Settings\Application Data\4jt08j3453lv6eerv3ryh58wlpwkbx274umkyc5s2batk27
[2011/07/29 09:26:25 | 000,015,188 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\4jt08j3453lv6eerv3ryh58wlpwkbx274umkyc5s2batk27
[2011/04/19 14:30:22 | 000,000,041 | —- | C] () – C:\WINDOWS\ArcPad.INI
[2010/11/29 15:01:51 | 000,006,144 | —- | C] () – C:\Documents and Settings\jzipkin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/08 12:33:15 | 000,000,000 | —- | C] () – C:\WINDOWS\SSFEdit.INI
[2010/09/08 10:54:16 | 000,000,000 | —- | C] () – C:\WINDOWS\Check.INI
[2010/08/27 12:08:29 | 000,009,136 | —- | C] () – C:\WINDOWS\System32\INETWH16.DLL
[2010/08/13 15:56:37 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\k19hinst.dll
[2010/07/28 13:01:55 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2010/07/27 22:06:32 | 000,000,000 | —- | C] () – C:\WINDOWS\Export.INI
[2010/07/27 09:29:43 | 000,002,528 | —- | C] () – C:\Documents and Settings\jzipkin\Application Data\$_hpcst$.hpc
[2010/07/26 14:14:03 | 000,001,890 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2010/07/26 11:28:09 | 000,000,143 | —- | C] () – C:\WINDOWS\TRIMSURV.INI
[2010/07/23 14:20:07 | 000,000,000 | —- | C] () – C:\Documents and Settings\jzipkin\Local Settings\Application Data\WavXMapDrive.bat
[2010/07/22 13:24:24 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2010/07/22 13:11:54 | 000,279,888 | —- | C] () – C:\WINDOWS\System32\brcmbsp.dll
[2010/07/22 13:11:47 | 000,080,368 | —- | C] () – C:\WINDOWS\System32\pbadrvdll.dll
[2010/07/22 13:03:29 | 000,203,657 | —- | C] () – C:\WINDOWS\System32\nvModes.dat
[2010/07/22 12:48:45 | 000,064,200 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/07/21 17:27:17 | 001,584,326 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2010/07/21 17:25:26 | 000,077,824 | —- | C] () – C:\WINDOWS\setpwr32.exe
[2010/07/21 17:23:40 | 000,001,156 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI

========== Custom Scans ==========

< >

< %SYSTEMDRIVE%\*.* >
[2012/01/04 17:27:56 | 000,000,268 | —- | M] () – C:\ab_1.gif
[2011/01/10 11:59:49 | 000,000,042 | —- | M] () – C:\alrt_204.data
[2011/07/27 15:40:50 | 000,065,484 | —- | M] () – C:\ASLog.txt
[2008/04/25 17:29:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/07/22 13:31:21 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/07/25 10:37:27 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2012/06/07 09:48:44 | 000,020,929 | —- | M] () – C:\ComboFix.txt
[2008/04/25 17:29:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/07/21 17:27:48 | 000,006,172 | R— | M] () – C:\dell.sdr
[2012/01/04 17:27:57 | 000,000,103 | —- | M] () – C:\del_1.gif
[2012/01/04 17:27:56 | 000,000,304 | —- | M] () – C:\dir.bmp
[2012/01/04 17:27:56 | 000,000,380 | —- | M] () – C:\edu.bmp
[2008/04/11 11:07:18 | 000,003,820 | —- | M] () – C:\eula.1028.txt
[2008/04/11 11:07:18 | 000,015,428 | —- | M] () – C:\eula.1031.txt
[2008/04/11 11:07:18 | 000,010,058 | —- | M] () – C:\eula.1033.txt
[2008/04/11 11:07:18 | 000,012,246 | —- | M] () – C:\eula.1036.txt
[2008/04/11 11:07:18 | 000,013,912 | —- | M] () – C:\eula.1040.txt
[2008/04/11 11:07:18 | 000,005,868 | —- | M] () – C:\eula.1041.txt
[2008/04/11 11:07:18 | 000,005,970 | —- | M] () – C:\eula.1042.txt
[2008/04/11 11:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2008/04/11 11:07:18 | 000,003,814 | —- | M] () – C:\eula.2052.txt
[2008/04/11 11:07:18 | 000,012,936 | —- | M] () – C:\eula.3082.txt
[2012/01/04 17:27:57 | 000,000,138 | —- | M] () – C:\flk2.gif
[2008/04/11 11:07:18 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/06/08 10:55:04 | 3745,406,976 | -HS- | M] () – C:\hiberfil.sys
[2012/04/26 13:04:32 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\HiJackThis.exe
[2012/04/26 13:06:46 | 000,017,645 | —- | M] () – C:\hijackthis.log
[2012/01/04 17:27:56 | 000,000,279 | —- | M] () – C:\hj_1.gif
[2008/04/11 11:07:18 | 000,000,843 | —- | M] () – C:\install.ini
[2008/04/11 09:03:48 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2008/04/11 09:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2008/04/11 09:03:48 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2008/04/11 09:03:48 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2008/04/11 09:03:48 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2008/04/11 09:03:48 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2008/04/11 09:03:48 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 11:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2008/04/11 09:03:48 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2008/04/11 09:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2008/04/25 17:29:32 | 000,000,000 | —- | M] () – C:\IO.SYS
[2012/01/04 17:27:57 | 000,000,277 | —- | M] () – C:\mov_1.gif
[2008/04/25 17:29:32 | 000,000,000 | —- | M] () – C:\MSDOS.SYS
[2010/07/21 17:28:03 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/07/21 17:28:03 | 000,250,048 | RHS- | M] () – C:\ntldr
[2009/12/15 05:31:08 | 047,582,528 | —- | M] (NVIDIA Corporation ) – C:\NvCplSetupInt.exe
[2012/06/08 10:55:01 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2012/01/04 17:27:55 | 000,000,235 | —- | M] () – C:\srch_1.gif
[2012/01/04 17:27:56 | 000,000,265 | —- | M] () – C:\srch_ans_1.gif
[2012/01/04 17:27:56 | 000,000,113 | —- | M] () – C:\srch_aud_1.gif
[2012/01/04 17:27:56 | 000,000,112 | —- | M] () – C:\srch_img_1.gif
[2012/01/04 17:27:56 | 000,000,131 | —- | M] () – C:\srch_loc_1.gif
[2012/01/04 17:27:57 | 000,000,284 | —- | M] () – C:\srch_map_1.gif
[2012/01/04 17:27:56 | 000,000,121 | —- | M] () – C:\srch_nws_1.gif
[2012/01/04 17:27:56 | 000,000,123 | —- | M] () – C:\srch_sh_1.gif
[2012/01/04 17:27:57 | 000,000,240 | —- | M] () – C:\srch_site_1.gif
[2012/01/04 17:27:57 | 000,000,273 | —- | M] () – C:\srch_stk_1.gif
[2012/01/04 17:27:56 | 000,000,112 | —- | M] () – C:\srch_vid_1.gif
[2012/04/26 22:52:53 | 000,122,974 | —- | M] () – C:\TDSSKiller.2.7.33.0_26.04.2012_22.46.51_log.txt
[2012/05/09 12:02:01 | 000,109,446 | —- | M] () – C:\TDSSKiller.2.7.34.0_09.05.2012_11.58.50_log.txt
[2012/06/06 11:05:45 | 000,111,840 | —- | M] () – C:\TDSSKiller.2.7.36.0_06.06.2012_11.02.27_log.txt
[2012/06/06 11:06:36 | 000,111,758 | —- | M] () – C:\TDSSKiller.2.7.36.0_06.06.2012_11.05.57_log.txt
[2012/06/07 09:32:51 | 000,112,632 | —- | M] () – C:\TDSSKiller.2.7.36.0_07.06.2012_09.32.14_log.txt
[2011/03/03 15:10:35 | 000,000,258 | —- | M] () – C:\TerraSync.ini
[2012/01/04 17:27:57 | 000,000,274 | —- | M] () – C:\trav_1.gif
[2008/04/11 11:07:18 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2008/04/11 11:09:38 | 003,797,292 | —- | M] () – C:\VC_RED.cab
[2008/04/11 11:11:40 | 000,233,472 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/04/18 23:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 22:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 23:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 22:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/04/25 17:29:00 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/05/21 21:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD95.DLL
[2007/05/21 21:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP95.DLL
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2011/04/02 17:03:22 | 000,069,632 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\HP1100PP.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/04/25 05:21:09 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/04/25 05:21:09 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/04/25 05:21:09 | 000,905,216 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2010/07/22 13:15:05 | 000,000,837 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\wave_license.txt

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/12/01 11:16:57 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\jzipkin\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/12/01 11:16:12 | 000,000,079 | —- | M] () – C:\Documents and Settings\jzipkin\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2012/06/08 09:44:40 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\jzipkin\Desktop\aswMBR.exe
[2012/06/07 09:36:05 | 004,538,022 | R— | M] (Swearware) – C:\Documents and Settings\jzipkin\Desktop\ComboFix.exe
[2012/06/05 14:15:54 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\jzipkin\Desktop\HiJackThis.exe
[2012/06/07 12:14:28 | 010,063,000 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\jzipkin\Desktop\mbam-setup-1.61.0.1400.exe
[2012/06/08 13:46:58 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Documents and Settings\jzipkin\Desktop\OTL.exe
[2012/06/07 12:13:21 | 000,446,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\jzipkin\Desktop\TFC.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoUpdate" = 0
"AUOptions" = 4
"RescheduleWaitTimeEnabled" = 1
"RescheduleWaitTime" = 1
"RebootWarningTimeoutEnabled" = 1
"RebootWarningTimeout" = 5
"RebootRelaunchTimeoutEnabled" = 1
"RebootRelaunchTimeout" = 10
"DetectionFrequencyEnabled" = 1
"DetectionFrequency" = 1
"AutoInstallMinorUpdates" = 1
"UseWUServer" = 1
"NoAutoRebootWithLoggedOnUsers" = 0
"ScheduledInstallDay" = 0
"ScheduledInstallTime" = 3

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-16 14:31:18

< End of report >
OTL Extras logfile created on: 6/8/2012 2:00:54 PM - Run 1
OTL by OldTimer - Version 3.2.47.0 Folder = C:\Documents and Settings\jzipkin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.49 Gb Total Physical Memory | 2.83 Gb Available Physical Memory | 81.05% Memory free
5.32 Gb Paging File | 4.42 Gb Available in Paging File | 83.01% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.99 Gb Total Space | 108.81 Gb Free Space | 73.03% Space Free | Partition Type: NTFS
Drive U: | 246.92 Gb Total Space | 108.81 Gb Free Space | 44.07% Space Free | Partition Type: NTFS
Drive W: | 246.92 Gb Total Space | 108.81 Gb Free Space | 44.07% Space Free | Partition Type: NTFS
Drive X: | 246.92 Gb Total Space | 108.81 Gb Free Space | 44.07% Space Free | Partition Type: NTFS
Drive Y: | 246.92 Gb Total Space | 108.81 Gb Free Space | 44.07% Space Free | Partition Type: NTFS
Drive Z: | 246.92 Gb Total Space | 108.81 Gb Free Space | 44.07% Space Free | Partition Type: NTFS

Computer Name: C4LHXH1 | User Name: jzipkin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications]
"Enabled" = 1
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts]
"Enabled" = 1
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts\List]
"135:TCP:*:Enabled:Offer Remote Assistance - Port" = 135:TCP:*:Enabled:Offer Remote Assistance - Port

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint]
"Enabled" = 1
"RemoteAddresses" = LocalSubnet

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop]
"Enabled" = 1
"RemoteAddresses" = *

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\AuthorizedApplications]
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\GloballyOpenPorts]
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:TCP" = 1900:TCP:LocalSubNet:Enabled:UDP 1900

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe" = C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe:*:Enabled:Managed Services Agent – (McAfee, Inc.)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\ACT\Act for Windows\ActSage.exe" = C:\Program Files\ACT\Act for Windows\ActSage.exe:*:Enabled:ACT! by Sage – (Sage Software, Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\SOTI\Pocket Controller-Pro\PocketController.exe" = C:\Program Files\SOTI\Pocket Controller-Pro\PocketController.exe:*:Enabled:Pocket Controller Professional – (SOTI Inc.)
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – (Google)
"\\sbs01\employee\Waypoint Documents\Rentals\Rental Software\rmfull_210_exe.exe" = \\sbs01\employee\Waypoint Documents\Rentals\Rental Software\rmfull_210_exe.exe:*:Enabled:CNET Download.com Installer
"C:\Documents and Settings\jzipkin\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe" = C:\Documents and Settings\jzipkin\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin – (Skype Limited)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe" = C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe:*:Enabled:Managed Services Agent – (McAfee, Inc.)
"C:\Program Files\ACT\Act for Windows\ActSage.exe" = C:\Program Files\ACT\Act for Windows\ActSage.exe:*:Enabled:ACT! by Sage – (Sage Software, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048633AA-0FD0-4B69-84B7-D286BD0BDBEF}" = TerraSync 4.12 for Windows Mobile
"{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"{0B291E8C-673A-4549-9745-9109DFD19873}" = Trimble Access Installation Manager
"{0E433CFD-B6FF-4D4E-A081-BB1A680D19A1}" = Verizon Wireless MiFi-2200 Firmware Updates
"{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0
"{15C77FC3-8137-4A5E-8F81-F559045DD6B0}" = Shipping Assistant 3.8
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{2220CF3A-EBD6-4070-94D0-0C7337B537A7}" = All Day Battery Life Configuration
"{228510C9-5C64-4A94-AB46-C730B770B625}" = TerraSync 4.02 for Windows Mobile
"{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes
"{24A494F3-5B5F-4183-9F7D-9CE82812C1FC}" = tsp patch
"{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java™ 7 Update 4
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (ACT7)
"{2D594814-6E68-4245-81AF-84864D43B695}" = TerraSync 3.30 Windows Mobile 2003
"{2E97DE76-851A-48AA-A0D6-665860FAD9CA}" = Keyspan USB Serial Adapter
"{32821558-2C36-4FD0-A891-CA65360B0EC7}" = DesignPro 5
"{3296BD36-4CF1-4684-BEE2-E1D9A6C45560}" = GPS Controller Windows Mobile
"{3393CDDB-27F0-4869-BED4-BE478598F0FF}" = Dell Control Point
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{396CE0B5-DC06-46D2-A870-47798143AE85}" = ACT! by Sage Premium 2009 (11.0)
"{39716D9C-41B8-4689-82F8-8BF86D059451}" = TerraSync 4.13 for Windows Mobile
"{3A6BE9F4-5FC8-44BB-BE7B-32A29607FEF6}" = Preboot Manager
"{3A8FE746-19BA-4168-8D01-D45897C7310E}" = VZAccess Manager
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{4112625F-2D38-49EF-924F-48511BC5CD34}" = Microsoft SQL Server 2008 Database Engine Services
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{476A5FC4-2C37-4978-ABF8-C22ADF47E508}" = RentMaster
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{4850B023-A9C0-4D15-8DE6-326028CAB499}" = Visual C++ 8.0 x86 Runtime Setup Package
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{4D523D94-C637-4C49-89FD-5B8FFB071D76}" = Dell ControlPoint Connection Manager
"{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{558B86E5-CFAC-447C-99EE-5BB1C068706D}" = NTRU TCG Software Stack
"{55FC6992-6B28-48A8-AF73-097011C80B8C}" = Grid Factory
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5C807402-F8BD-4BE8-9AA3-619C71A922FA}" = TerraSync 5.02 for Windows Mobile
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{5E760D2E-7572-4B0D-8C2B-1D0D31C39381}" = TerraSync 5.20 for Windows Mobile
"{6EA8A52B-8EA1-4A59-85AB-48132299061A}" = Intel® PRO Alerting Agent
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}" = Microsoft SQL Server Native Client
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{791CAF6C-90A3-11D4-8306-00D0B72E1DB9}" = Sentinel System Driver
"{7B18E7E2-AFCA-4CBE-8CD5-3613315AB262}" = ArcGIS Explorer
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{7EA69B5E-EE96-44A1-BDD6-F9C193CDDAF9}" = Wave Infrastructure Installer
"{7F67A6AE-414C-11D4-9F71-00C04F6BDDB9}" = VBA (3821b)
"{7F67A6AF-414C-11D4-9F71-00C04F6BDDB9}" = VBA (3821b)
"{81EBF3DA-65FD-4862-AE33-964CAF246BBD}" = TerraSync 5.10 for Windows Mobile
"{8215AC14-BFC2-4ECC-96D6-1030202F8BDF}" = Visual C++ 8.0 x86 Runtime Setup Package
"{83298573-A6B6-42AB-A234-FE91CA2859C0}" = Microsoft SQL Server 2008 Native Client
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DC069E7-893C-41E1-9442-DE89FEC33371}" = Xobni Core
"{8EF68CB3-CFC2-462D-B494-07918005FE20}" = TerraSync 4.12 for Windows Mobile 2003
"{8F72E2D4-1E48-4534-8DB8-1E8E012899C6}" = Microsoft SQL Server 2008 Setup Support Files
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91FC12AD-EC98-4A7D-BB14-D5FFFE42867F}" = TerraSync 3.30 Windows Mobile
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9593C6E5-205E-45C3-B785-05CF146CA76A}" = biolsp patch
"{96963F83-7F17-4941-B16C-1E790455E93A}" = McAfee SiteAdvisor Enterprise Plus
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A093D83F-429A-4AB2-A0CD-1F7E9C7B764A}" = Trusted Drive Manager
"{A2E0B024-AC3B-41D3-A7DE-FB39D467CCFF}" = TerraSync 5.01 for Windows Mobile
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A719C89B-201A-4FD9-AA68-C033E2C30D90}" = WinFlash
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{ABBA2EA4-740E-4052-902B-9CA70B081E3F}" = Dell Embassy Trust Suite by Wave Systems
"{AC2BA148-EE9C-4F1A-AFCE-F38C2C71D29B}" = Mobile Broadband Generic Drivers
"{AC76BA86-1033-F400-BA7E-000000000004}" = Adobe Acrobat 9 Standard - English, Français, Deutsch
"{AC76BA86-1033-F400-BA7E-000000000004}_951" = Adobe Acrobat 9.5.1 - CPSID_83708
"{AC76BA86-1033-F400-BA7E-000000000004}{AC76BA86-1033-F400-BA7E-000000000004}" = Adobe Acrobat 9 Standard - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{AF7E4468-E364-4991-BC2A-6E8293E1055B}" = BioAPI Framework
"{B0FC00C7-7EA6-4EAF-978B-7705016E395E}" = Trimble RealWorks Viewer 6.5
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B20179BA-2872-432F-8D88-B8F44AED359B}" = Broadcom USH Host Components
"{B389D381-CCD0-4509-A892-84C546B99F4C}" = TerraSync Desktop
"{B5D99D31-3C2B-48A1-99A5-653BF9CA55C5}" = WinFLASH
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{B8E9F8A1-9F4D-43D5-ABD6-1DF067FAA469}" = Microsoft SQL Server 2008 Database Engine Services
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BBF3D0F7-7661-4508-B45C-CF58EF26888E}" = GPS Controller Windows Mobile
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C19B3EB6-B54C-3204-A4DF-88432E0C79F7}" = Microsoft ReportViewer 2010 Redistributable
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC753DD0-8554-4018-B6C8-B2A571A1E4B3}" = GeoExplorer CE Loader
"{CC9EA2BC-BCFA-4DEA-8F5F-1E1032567673}" = SOTI Pocket Controller-Pro
"{CCC68887-6E07-4438-A035-7C22EFBDC15E}" = Intel® Network Connections [removed]
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}" = Secure Update
"{D2D40BAE-7B66-11D3-882B-00105A64914B}" = Trimble Data Transfer
"{D84DBC4E-D804-4E8D-A008-3266E2B21F79}" = GPS Configurator
"{DF2035BE-5820-4965-BD97-7FAF8D4A7879}" = Microsoft_VC90_CRT_x86
"{DF38C72B-8A86-4727-99D2-FA7CC5E17A24}" = Microsoft SQL Server 2008 RsFx Driver
"{E27D856D-664C-49F3-95A3-E6B639BB2AC1}" = GPS Pathfinder Office
"{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"{ED3F245C-9E61-4B3F-8C5D-B8FA6586D4A6}" = TerraSync 5.30 for Windows Mobile
"{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"{EF05BA0F-AC15-4D12-AC5C-276225F5E751}" = Gemalto
"{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F202C04C-042D-48EC-BECE-9E071DC8E5EF}" = GPScorrect 2.41 Windows Mobile
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F4487649-7368-4217-AEA3-1E04DB3E2C5C}" = Dell ControlPoint Security Manager
"{F44F0A3A-2110-4705-B5EC-D5B6371F53C1}" = Visual C++ 8.0 x86 Runtime Setup Package
"{F74B95DF-A68C-4A99-98AA-E98698341F21}" = Dell ControlPoint System Manager
"{FD9FF4D5-A220-49F1-ABE8-91C18B348E5B}" = GPScorrect 3.15 for Windows Mobile
"{FF1DDCF4-3A28-4F7F-96D8-E3F4BD1C1702}" = Dell Security Device Driver Pack
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"9D57DE505B6D8C710EF3B74BE638DBB936EED8A3" = Windows Driver Package - Dell Inc. PBADRV System (01/07/2008 1.0.1.5)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ArcGIS Explorer" = ArcGIS Explorer
"Corpscon" = Corpscon 6.0.1
"Creative OA001" = Integrated Webcam Driver (1.08.01.0129)
"Dell Webcam Central" = Dell Webcam Central
"ESRI ArcPad 6.0.3" = ESRI ArcPad 6.0.3
"ESRI ArcPad 7.1.1" = ESRI ArcPad 7.1.1
"Free Internet Window Washer" = Free Internet Window Washer
"Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 2.2
"HP LaserJet Professional P1100-P1560-P1600 Series" = HP LaserJet Professional P1100-P1560-P1600 Series
"ie8" = Windows Internet Explorer 8
"InstallShield_{048633AA-0FD0-4B69-84B7-D286BD0BDBEF}" = TerraSync 4.12 for Windows Mobile
"InstallShield_{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"InstallShield_{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"InstallShield_{228510C9-5C64-4A94-AB46-C730B770B625}" = TerraSync 4.02 for Windows Mobile
"InstallShield_{2D594814-6E68-4245-81AF-84864D43B695}" = TerraSync 3.30 Windows Mobile 2003
"InstallShield_{32821558-2C36-4FD0-A891-CA65360B0EC7}" = DesignPro 5
"InstallShield_{3296BD36-4CF1-4684-BEE2-E1D9A6C45560}" = GPS Controller Windows Mobile
"InstallShield_{396CE0B5-DC06-46D2-A870-47798143AE85}" = ACT! by Sage Premium 2009 (11.0)
"InstallShield_{39716D9C-41B8-4689-82F8-8BF86D059451}" = TerraSync 4.13 for Windows Mobile
"InstallShield_{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"InstallShield_{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"InstallShield_{5C807402-F8BD-4BE8-9AA3-619C71A922FA}" = TerraSync 5.02 for Windows Mobile
"InstallShield_{5E760D2E-7572-4B0D-8C2B-1D0D31C39381}" = TerraSync 5.20 for Windows Mobile
"InstallShield_{81EBF3DA-65FD-4862-AE33-964CAF246BBD}" = TerraSync 5.10 for Windows Mobile
"InstallShield_{8EF68CB3-CFC2-462D-B494-07918005FE20}" = TerraSync 4.12 for Windows Mobile 2003
"InstallShield_{91FC12AD-EC98-4A7D-BB14-D5FFFE42867F}" = TerraSync 3.30 Windows Mobile
"InstallShield_{A2E0B024-AC3B-41D3-A7DE-FB39D467CCFF}" = TerraSync 5.01 for Windows Mobile
"InstallShield_{B389D381-CCD0-4509-A892-84C546B99F4C}" = TerraSync Desktop
"InstallShield_{BBF3D0F7-7661-4508-B45C-CF58EF26888E}" = GPS Controller Windows Mobile
"InstallShield_{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}" = Secure Update
"InstallShield_{E27D856D-664C-49F3-95A3-E6B639BB2AC1}" = GPS Pathfinder Office
"InstallShield_{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"InstallShield_{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"InstallShield_{ED3F245C-9E61-4B3F-8C5D-B8FA6586D4A6}" = TerraSync 5.30 for Windows Mobile
"InstallShield_{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"InstallShield_{F202C04C-042D-48EC-BECE-9E071DC8E5EF}" = GPScorrect 2.41 Windows Mobile
"InstallShield_{FD9FF4D5-A220-49F1-ABE8-91C18B348E5B}" = GPScorrect 3.15 for Windows Mobile
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"McAfeeBrowserProtection" = McAfee Browser Protection Service
"MGIS Product Catalog_is1" = MGIS Product Catalog 2.006
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mobile Broadband Generic Drivers" = Mobile Broadband Generic Drivers
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"PROHYBRIDR" = 2007 Microsoft Office system
"QuickXpenseV1.61" = QuickXpense 1.61
"RealPlayer 12.0" = RealPlayer
"SP6" = Logitech SetPoint 6.15
"Survey Digital Price Book_is1" = Survey Digital Price Book
"Trimble General Survey Update Office Software" = Trimble General Survey v1.70 Update Office Software
"Trimble Survey Controller Update Office Software" = Trimble Survey Controller v12.45 Update Office Software
"VLC media player" = VLC media player 1.1.11
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XobniMain" = Xobni
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Mail Advisor" = Yahoo! Mail Advisor
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/7/2012 5:58:20 PM | Computer Name = C4LHXH1 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3632719

Error - 6/7/2012 5:58:36 PM | Computer Name = C4LHXH1 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 6/7/2012 5:58:36 PM | Computer Name = C4LHXH1 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3648453

Error - 6/7/2012 5:58:36 PM | Computer Name = C4LHXH1 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3648453

Error - 6/8/2012 9:29:52 AM | Computer Name = C4LHXH1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (A socket operation was attempted to an unreachable host. ). Group Policy
processing aborted.

Error - 6/8/2012 9:29:56 AM | Computer Name = C4LHXH1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (A socket operation was attempted to an unreachable host. ). Group Policy
processing aborted.

Error - 6/8/2012 9:30:02 AM | Computer Name = C4LHXH1 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 6/8/2012 9:30:02 AM | Computer Name = C4LHXH1 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 59534110

Error - 6/8/2012 9:30:02 AM | Computer Name = C4LHXH1 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 59534110

Error - 6/8/2012 10:55:37 AM | Computer Name = C4LHXH1 | Source = ACT! Scheduler | ID = 0
Description = Service cannot be started. System.Exception: Unable to start scheduler
service. Missing server configuration information. at Act.Scheduler.SchedulerService.OnStart(String[]
args) at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

[ OSession Events ]
Error - 9/16/2010 1:11:01 PM | Computer Name = C4LHXH1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 99401
seconds with 4140 seconds of active time. This session ended with a crash.

Error - 10/20/2010 5:00:46 PM | Computer Name = C4LHXH1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 610070
seconds with 1860 seconds of active time. This session ended with a crash.

Error - 3/3/2011 5:54:42 PM | Computer Name = C4LHXH1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 112506
seconds with 2220 seconds of active time. This session ended with a crash.

Error - 4/28/2011 9:34:44 AM | Computer Name = C4LHXH1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 64986
seconds with 180 seconds of active time. This session ended with a crash.

Error - 4/28/2011 11:13:59 AM | Computer Name = C4LHXH1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 263252
seconds with 2160 seconds of active time. This session ended with a crash.

Error - 9/25/2011 8:05:14 AM | Computer Name = C4LHXH1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 253335
seconds with 3900 seconds of active time. This session ended with a crash.

Error - 2/29/2012 5:58:12 PM | Computer Name = C4LHXH1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 8, Application Name: Microsoft Office Publisher, Application Version:
12.0.6652.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 22273
seconds with 120 seconds of active time. This session ended with a crash.

Error - 3/20/2012 3:38:43 PM | Computer Name = C4LHXH1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 8, Application Name: Microsoft Office Publisher, Application Version:
12.0.6652.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1431
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 6/7/2012 12:20:50 PM | Computer Name = C4LHXH1 | Source = Service Control Manager | ID = 7023
Description = The Oraclewebassistant service terminated with the following error:
%%126

Error - 6/7/2012 12:20:52 PM | Computer Name = C4LHXH1 | Source = Service Control Manager | ID = 7023
Description = The SeaPort service terminated with the following error: %%126

Error - 6/7/2012 5:58:09 PM | Computer Name = C4LHXH1 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time-a.nist.gov,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: No such service is known. The service cannot
be found in the specified name space. (0x8007277C)

Error - 6/7/2012 5:58:10 PM | Computer Name = C4LHXH1 | Source = SCardSvr | ID = 610
Description = Smart Card Reader 'Broadcom Corp Contacted SmartCard 0' rejected IOCTL
GET_STATE: The device has been removed.

Error - 6/8/2012 10:54:07 AM | Computer Name = C4LHXH1 | Source = Service Control Manager | ID = 7034
Description = The Dell ControlPoint Button Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 6/8/2012 10:54:07 AM | Computer Name = C4LHXH1 | Source = Service Control Manager | ID = 7034
Description = The Dell ControlPoint System Manager service terminated unexpectedly.
It has done this 1 time(s).

Error - 6/8/2012 10:55:45 AM | Computer Name = C4LHXH1 | Source = Service Control Manager | ID = 7023
Description = The ASNDIS5 service terminated with the following error: %%126

Error - 6/8/2012 10:55:54 AM | Computer Name = C4LHXH1 | Source = Service Control Manager | ID = 7023
Description = The Lxdj_device service terminated with the following error: %%126

Error - 6/8/2012 10:55:54 AM | Computer Name = C4LHXH1 | Source = Service Control Manager | ID = 7023
Description = The Oraclewebassistant service terminated with the following error:
%%126

Error - 6/8/2012 10:55:55 AM | Computer Name = C4LHXH1 | Source = Service Control Manager | ID = 7023
Description = The SeaPort service terminated with the following error: %%126


< End of report >
Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

File::
C:\Documents and Settings\jzipkin\Local Settings\temp\SetupDataMngr_Searchqu.exe
C:\Documents and Settings\All Users\Application Data\8615B8621C.sys
C:\WINDOWS\tasks\geipcppjz.job

Folder::
C:\Documents and Settings\jzipkin\Local Settings\temp\nsj9FF
C:\Documents and Settings\jzipkin\Local Settings\temp\nst9F1

ClearJavaCache::


In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

When finished, it shall produce a log for you. Please post that log, C:\ComboFix.txt, in your next reply.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]
Sorry for the delay, was off-grid for the weekend.
Here's the combofix log.

ComboFix 12-06-10.01 - jzipkin 06/11/2012 9:47.13.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3572.3008 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\jzipkin\Desktop\CFScript.txt
AV: McAfee® Security-as-a-Service Anti-virus *Disabled/Updated* {8C354827-2F54-4E28-90DC-AD391E77808C}
.
FILE ::
"c:\documents and settings\All Users\Application Data\8615B8621C.sys"
"c:\documents and settings\jzipkin\Local Settings\temp\SetupDataMngr_Searchqu.exe"
"c:\windows\tasks\geipcppjz.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\8615B8621C.sys
.
.
((((((((((((((((((((((((( Files Created from 2012-05-11 to 2012-06-11 )))))))))))))))))))))))))))))))
.
.
2012-06-07 17:38 . 2012-04-04 19:56 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-06-04 15:01 . 2012-06-04 15:01 163840 –sha-r- c:\windows\system32\c_1257I.dll
2012-05-25 15:49 . 2011-09-29 18:20 484352 —-a-w- c:\windows\system32\lame_enc.dll
2012-05-25 15:28 . 2009-05-18 17:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-05-25 15:28 . 2008-04-17 16:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2012-05-25 15:27 . 2012-05-25 15:27 ——– d—–w- c:\program files\iPod
2012-05-25 15:27 . 2012-05-25 15:28 ——– d—–w- c:\program files\iTunes
2012-05-25 15:27 . 2012-05-25 15:28 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2012-05-25 15:26 . 2012-05-25 15:26 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2012-05-25 15:26 . 2012-02-15 15:01 4547944 —-a-w- c:\windows\system32\usbaaplrc.dll
2012-05-25 15:26 . 2012-02-15 15:01 43520 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2012-05-25 15:20 . 2012-05-25 15:20 ——– d—–w- c:\program files\Bonjour
2012-05-14 20:49 . 2012-05-14 20:49 ——– d—–w- c:\documents and settings\JZipkin\Application Data\Unity
2012-05-14 19:48 . 2012-05-14 19:48 ——– d—–w- c:\documents and settings\JZipkin\Local Settings\Application Data\Unity
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-11 13:18 . 2010-07-26 18:14 1890 –sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2012-06-11 13:16 . 2010-07-23 18:20 0 —-a-w- c:\documents and settings\JZipkin\Local Settings\Application Data\WavXMapDrive.bat
2012-05-09 16:25 . 2012-04-25 13:45 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-09 16:25 . 2011-06-29 15:20 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-27 02:53 . 2008-04-25 16:16 75264 —-a-w- c:\windows\system32\drivers\ipsec.sys
2012-04-26 17:04 . 2012-04-26 17:05 388608 —-a-w- C:\HiJackThis.exe
2012-04-04 22:47 . 2012-04-30 15:32 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-04-04 22:47 . 2012-04-30 15:32 772504 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-04-04 22:47 . 2010-07-22 17:11 687504 —-a-w- c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-06-06_15.19.58 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-06-11 13:13 . 2012-06-11 13:13 16384 c:\windows\Temp\Perflib_Perfdata_9b8.dat
+ 2012-06-11 13:13 . 2012-06-11 13:13 16384 c:\windows\Temp\Perflib_Perfdata_79c.dat
+ 2008-04-25 16:16 . 2012-06-11 13:19 560798 c:\windows\system32\perfh009.dat
- 2008-04-25 16:16 . 2012-06-04 17:56 560798 c:\windows\system32\perfh009.dat
+ 2008-04-25 16:16 . 2012-06-11 13:19 117144 c:\windows\system32\perfc009.dat
- 2008-04-25 16:16 . 2012-06-04 17:56 117144 c:\windows\system32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn0\yt.dll" [2012-03-21 1523512]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay]
@="{022F2F51-CDDA-4873-8A29-72C66C808A3F}"
[HKEY_CLASSES_ROOT\CLSID\{022F2F51-CDDA-4873-8A29-72C66C808A3F}]
2009-11-07 05:07 297808 ——w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{661963C1-99A1-44e7-A671-1CF3768AE9D4}"
[HKEY_CLASSES_ROOT\CLSID\{661963C1-99A1-44e7-A671-1CF3768AE9D4}]
2009-11-07 05:07 297808 ——w- c:\windows\system32\mscoree.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"Facebook Update"="c:\documents and settings\jzipkin\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" [2011-10-21 137536]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-02-17 278528]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2010-04-05 737280]
"nwiz"="nwiz.exe" [2009-12-15 1657448]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-12-15 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-12-15 13770752]
"NVHotkey"="nvHotkey.dll" [2009-12-15 86016]
"OA001Mon"="c:\windows\OA001Mon.exe" [2010-01-28 24576]
"IAStorIcon"="c:\program files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
"ChangeTPMAuth"="c:\program files\Wave Systems Corp\Common\ChangeTPMAuth.exe" [2008-05-30 180224]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2008-05-14 105472]
"SecureUpgrade"="c:\program files\Wave Systems Corp\SecureUpgrade.exe" [2008-06-24 243000]
"EmbassySecurityCheck"="c:\program files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe" [2008-06-24 79160]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2008-08-18 598016]
"DCPstrApp"="c:\program files\Dell\Dell ControlPoint\Security Manager\SecurityDeviceInfoSetRegistryString.exe" [2008-08-04 6656]
"DellConnectionManager"="c:\program files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe" [2008-10-01 1454080]
"MVS Splash"="c:\program files\McAfee\Managed VirusScan\DesktopUI\XTray.exe" [2011-08-25 476480]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-06-26 1311312]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"Act.Outlook.Service"="c:\program files\ACT\Act for Windows\Act.Outlook.Service.exe" [2009-02-24 28672]
"Act! Preloader"="c:\program files\ACT\Act for Windows\ActSage.exe" [2009-02-24 393216]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2012-03-27 40376]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2012-03-26 640440]
"YMailAdvisor"="c:\program files\Yahoo!\Common\YMailAdvisor.exe" [2009-05-08 174424]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143360]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-10-17 442536]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-06-29 273544]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2010-04-05 495708]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-10-24 421888]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
.
c:\documents and settings\McAfeeMVSUser\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [N/A]
.
c:\documents and settings\ataylor.WAYPOINT.000\Start Menu\Programs\Startup\
Logitech . Product Registration.lnk - c:\program files\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 517384]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-8-15 604776]
Dell ControlPoint System Manager.lnk - c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe [2008-11-11 950048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-05-06 09:29 64592 —-a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\ACT\\Act for Windows\\ActSage.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [8/12/2010 2:55 PM 89624]
R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [4/19/2007 6:56 AM 133968]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\Dell\Dell ControlPoint\DCPButtonSvc.exe [9/4/2008 6:28 PM 406808]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [11/11/2008 5:35 PM 808296]
R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [11/11/2008 5:35 PM 20840]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe [11/11/2008 4:00 PM 451872]
R2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [12/29/2011 4:47 PM 99896]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [7/22/2010 1:13 PM 13336]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [7/26/2010 11:19 AM 10448]
R2 McAfee SiteAdvisor Enterprise Service;McAfee SiteAdvisor Enterprise Service;c:\program files\McAfee\SiteAdvisor Enterprise\McSACore.exe [5/12/2011 11:48 AM 324928]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [11/16/2010 10:37 AM 148520]
R2 MSSQL$ACT7;SQL Server (ACT7);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [12/10/2010 6:29 PM 29293408]
R2 myAgtSvc;McAfee Virus and Spyware Protection Service;c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe [8/23/2011 9:50 AM 291064]
R2 RumorServer;McAfee Peer Distribution Service;c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe [8/23/2011 9:50 AM 291064]
R2 SMManager;Smith Micro Connection Manager Service;c:\program files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe [10/1/2008 5:28 AM 90112]
R2 XobniService;XobniService;c:\program files\Xobni\XobniService.exe [5/20/2010 1:46 PM 55016]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [7/21/2010 5:25 PM 113664]
R3 CCIDFILTER;Broadcom Smart Card Reader Filter Driver;c:\windows\system32\drivers\ccidflt.sys [7/22/2010 1:11 PM 12840]
R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [7/21/2010 5:27 PM 32808]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [7/21/2010 5:25 PM 240344]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [7/21/2010 5:25 PM 133632]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [7/21/2010 5:25 PM 281472]
S2 ACT! Scheduler;ACT! Scheduler;c:\program files\ACT\Act for Windows\Act.Scheduler.exe [2/24/2009 2:08 PM 81920]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/26/2010 11:43 AM 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/25/2012 9:45 AM 257696]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/26/2010 11:43 AM 136176]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [8/12/2010 2:55 PM 87808]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [12/18/2009 12:13 PM 20480]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [12/18/2009 12:12 PM 174720]
S3 OA001Afx;Provides a software interface to control audio effects of OA001 camera.;c:\windows\system32\drivers\OA001Afx.sys [7/21/2010 5:25 PM 134144]
S3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [4/14/2010 8:29 PM 32408]
S3 TrmbTS;TrmbTS;c:\windows\system32\drivers\TrmbTS.sys [8/26/2010 12:49 PM 29184]
S3 TRMUSB5K;Trimble USB GPS Driver;c:\windows\system32\drivers\TRMUSB5K.sys –> c:\windows\system32\drivers\TRMUSB5K.sys [?]
S3 USA19H;USA19H;c:\windows\system32\drivers\USA19H2k.sys [8/13/2010 3:56 PM 704000]
S3 USA19H2KP;Keyspan USB Serial Port Driver;c:\windows\system32\drivers\USA19H2kp.sys [8/13/2010 3:56 PM 24192]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/25/2008 12:16 PM 14336]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/22/2009 11:08 PM 47128]
S4 RsFx0105;RsFx0105 Driver;c:\windows\system32\drivers\RsFx0105.sys [9/22/2011 6:10 PM 238696]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [9/22/2011 6:17 PM 370024]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
pavprsrv
slee_503_service
idebusdr
slimsvc
PAC7302
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-25 16:25]
.
2011-10-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2012-06-08 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-308600077-3542235570-3293604796-1145Core.job
- c:\documents and settings\jzipkin\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-21 17:46]
.
2012-06-08 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-308600077-3542235570-3293604796-1145UA.job
- c:\documents and settings\jzipkin\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-21 17:46]
.
2012-06-11 c:\windows\Tasks\geipcppjz.job
- c:\windows\system32\c_1257I.dll [2012-06-04 15:01]
.
2012-06-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-26 15:43]
.
2012-06-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-26 15:43]
.
2012-06-11 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-308600077-3542235570-3293604796-1145.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
2012-06-11 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-308600077-3542235570-3293604796-1145.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
TCP: DhcpNameServer = 10.0.0.11
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-06-11 09:53
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(624)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
.
Completion time: 2012-06-11 09:55:05
ComboFix-quarantined-files.txt 2012-06-11 13:55
ComboFix2.txt 2012-06-07 13:48
ComboFix3.txt 2012-06-06 15:21
ComboFix4.txt 2012-05-10 16:31
.
Pre-Run: 116,664,573,952 bytes free
Post-Run: 116,897,067,008 bytes free
.
- - End Of File - - 0C4D42C12894F9C31EF8217EF1417506
Just checking, you still having redirects. Am I right?

Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)

Please go to one of the below sites to scan the following files:
Virus Total (Recommended)
jotti.org
VirScan


click on Browse, and upload the following file for analysis:
c:\windows\system32\c_1257I.dll
c:\windows\system32\drivers\ipsec.sys


Then click Submit. Allow the file to be scanned, and then please copy and paste the results link(for Virus Total) here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.
odd. i was still getting redirects on Friday, but not now…and i haven't touched this computer all weekend. will continue to monitor for redirects and will do this scan a little later and post results. thx again.
scanned both. both needed 'reanalyze'…but don't see the 'results link' you mention. not sure how to interpret the results. what should i post?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI