This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

too long to boot - set up screen appears [Solved]

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:pullhair:

HI

My name is Darlene and I have a new problem. I think it's a coincidence, but I'll start from the beginning.

The other night my laptop downloaded and installed 9 updates, the tower did it as well, and so did all the pc's at work. All but my laptop are fine.

After the updates were installed, a box appeared that it wanted to reboot. I just shut it down, and at 5:30 am, I booted up. It took forever. The desk top finally appeared, with no icons, but a small box in the upper left corner said it was updating my personal settings. Finally it completed and all the icons appeared. Watching a youtube video this morning and for days prior, Adobe flash player crashed many times. so this morning, a box appeared to install updates. I clicked on it to resolve this issue. Later a box appeared saying it failed, to try again later. It was time to go to work, so I shut down.

when I came home from work today, I booted up the laptop. The screen was black and it said F2 Setup. OK. I pressed F2, it took 15 minutes or longer, finally a set up screen appeared, I just pressed Escape and after another long wait, the desktop and icons appeared and it seemed to run.

Trend Micro pops up this alert: : TROJAN HORSE PROGRAM DELETED - PLEASE RESTART COMPUTER TROJ_SIREFEF.GF - the box displays this link:

http://about-threats.trendmicro.com/Malwarโ€ฆTROJ_SIREFEF.GF

the box also says "A Trojan Horse program has been removed to prevent it from attacking you. Please restart your computer now to remove any remaining traces of this threat."

My Trend Micro is still scanning at this time. I am not going to distrupt the full system scan to reboot. I have included screen shots of the alerts I have seen tonight.

I'm not sure if I have posted this note in the correct place - please correct me if I have done it wrong.

I have downloaded the 3 programs in your help screen, but I have not run them, as you also state not to do so until instructed.

I am in Pittsburgh, PA, Eastern Standard Time.

Any help would be greatly appreciated!

If I need to tell you more information, please let me now. I thank you for all your help!

Darlene
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK
โ€”โ€”โ€”
OTL
  • Download OTL to your desktop.
  • Right-click and Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in

    netsvcs
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
โ€”โ€”โ€”-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If asked whether you would like to update the Avast virus database please do.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
โ€”โ€”โ€”-

In your next reply please post the logs made by OTL and aswMBR. :)
HI Jeff!

I followed your instructions, all folders are visable.

I loaded OTL and ran the report. I'm ready for my next command! Darlene

Here is OTL.txt

OTL logfile created on: 7/13/2012 10:06:54 PM - Run 6
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\DARLENE'S\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.68 Gb Total Physical Memory | 1.72 Gb Available Physical Memory | 46.77% Memory free
7.36 Gb Paging File | 5.11 Gb Available in Paging File | 69.54% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453.66 Gb Total Space | 43.29 Gb Free Space | 9.54% Space Free | Partition Type: NTFS

Computer Name: DARLENES-PC | User Name: DARLENE'S | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\DARLENE'S\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe (IncrediMail, Ltd.)
PRC - C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe (IncrediMail, Ltd.)
PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Web Assistant\ExtensionUpdaterService.exe ()
PRC - C:\Program Files\Wajam\Updater\WajamUpdater.exe (Wajam)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intelยฎ Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intelยฎ Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
PRC - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\IncrediMail\Bin\ImLookExU.dll ()
MOD - C:\Program Files (x86)\IncrediMail\Bin\wlessfp1.dll ()
MOD - C:\Program Files (x86)\IncrediMail\Bin\ImComUtlU.dll ()
MOD - C:\Program Files (x86)\IncrediMail\Bin\IMHttpComm.dll ()
MOD - C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\39624\RapportMS.dll ()
MOD - C:\Program Files (x86)\IncrediMail\Bin\ImAppRU.dll ()
MOD - C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll ()
MOD - C:\Program Files (x86)\IncrediMail\Bin\PMC.dll ()
MOD - \\?\globalroot\systemroot\syswow64\mswsock.DLL ()
MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (!SASCORE) โ€“ C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SRV:64bit: - (Web Assistant Updater) โ€“ C:\Program Files\Web Assistant\ExtensionUpdaterService.exe ()
SRV:64bit: - (WajamUpdater) โ€“ C:\Program Files\Wajam\Updater\WajamUpdater.exe (Wajam)
SRV:64bit: - (SfCtlCom) โ€“ C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV:64bit: - (wlcrasvc) โ€“ C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (TmProxy) โ€“ C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV:64bit: - (TMBMServer) โ€“ C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV:64bit: - (TurboBoost) โ€“ C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intelยฎ Corporation)
SRV:64bit: - (ePowerSvc) โ€“ C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (Updater Service) โ€“ C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
SRV - (AdobeFlashPlayerUpdateSvc) โ€“ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) โ€“ C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (RapportMgmtService) โ€“ C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (AdobeARMservice) โ€“ C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Kodak AiO Network Discovery Service) โ€“ C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
SRV - (BBSvc) โ€“ C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) โ€“ C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (NTI IScheduleSvc) โ€“ C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (clr_optimization_v4.0.30319_32) โ€“ C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) โ€“ C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (IAANTMON) Intelยฎ โ€“ C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (UNS) Intelยฎ โ€“ C:\Program Files (x86)\Intel\Intelยฎ Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intelยฎ โ€“ C:\Program Files (x86)\Intel\Intelยฎ Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Greg_Service) โ€“ C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) โ€“ C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (HsfXAudioService) โ€“ C:\Windows\SysWOW64\XAudio64.dll (Conexant Systems, Inc.)
SRV - (YahooAUService) โ€“ C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (RapportKE64) โ€“ C:\Windows\SysNative\drivers\RapportKE64.sys (Trusteer Ltd.)
DRV:64bit: - (fssfltr) โ€“ C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) โ€“ C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (iPodDrv) โ€“ C:\Windows\SysNative\drivers\iPodDrv.sys (Windows ยฎ Codename Longhorn DDK provider)
DRV:64bit: - (tmxpflt) โ€“ C:\Windows\SysNative\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV:64bit: - (tmpreflt) โ€“ C:\Windows\SysNative\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV:64bit: - (vsapint) โ€“ C:\Windows\SysNative\drivers\vsapint.sys (Trend Micro Inc.)
DRV:64bit: - (amdsata) โ€“ C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) โ€“ C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) โ€“ C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) โ€“ C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (igfx) โ€“ C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (tmtdi) โ€“ C:\Windows\SysNative\drivers\tmtdi.sys (Trend Micro Inc.)
DRV:64bit: - (athr) โ€“ C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (TurboB) โ€“ C:\Windows\SysNative\drivers\TurboB.sys ()
DRV:64bit: - (IntcDAud) Intelยฎ โ€“ C:\Windows\SysNative\drivers\IntcDAud.sys (Intelยฎ Corporation)
DRV:64bit: - (Impcd) โ€“ C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (SynTP) โ€“ C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (iaStor) โ€“ C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (HECIx64) Intelยฎ โ€“ C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) โ€“ C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (k57nd60a) Broadcom NetLink โ„ข โ€“ C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (amdsbs) โ€“ C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) โ€“ C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) โ€“ C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (atikmdag) โ€“ C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (PxHlpa64) โ€“ C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (VX3000) โ€“ C:\Windows\SysNative\drivers\VX3000.sys (Microsoft Corporation)
DRV:64bit: - (RTHDMIAzAudService) โ€“ C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (SrvHsfV92) โ€“ C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) โ€“ C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) โ€“ C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (ebdrv) โ€“ C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) โ€“ C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) โ€“ C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) โ€“ C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (grmnusb) โ€“ C:\Windows\SysNative\drivers\grmnusb.sys (GARMIN Corp.)
DRV:64bit: - (NTIDrvr) โ€“ C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) โ€“ C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (XAudio) โ€“ C:\Windows\SysNative\drivers\XAudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DPV) โ€“ C:\Windows\SysNative\drivers\CAX_DPV.sys (Conexant Systems, Inc.)
DRV:64bit: - (CAXHWAZL) โ€“ C:\Windows\SysNative\drivers\CAXHWAZL.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) โ€“ C:\Windows\SysNative\drivers\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (USBModem) โ€“ C:\Windows\SysNative\drivers\lgx64modem.sys (LG Electronics Inc.)
DRV:64bit: - (UsbDiag) โ€“ C:\Windows\SysNative\drivers\lgx64diag.sys (LG Electronics Inc.)
DRV:64bit: - (usbbus) โ€“ C:\Windows\SysNative\drivers\lgx64bus.sys (LG Electronics Inc.)
DRV:64bit: - (mdmxsdk) โ€“ C:\Windows\SysNative\drivers\mdmxsdk.sys (Conexant)
DRV - (RapportCerberus_34302) โ€“ C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_34302.sys ()
DRV - (RapportEI64) โ€“ C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys (Trusteer Ltd.)
DRV - (RapportPG64) โ€“ C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys (Trusteer Ltd.)
DRV - (MREMP50) โ€“ C:\Program Files (x86)\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) โ€“ C:\Program Files (x86)\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (RSUSBSTOR) โ€“ C:\Windows\SysWOW64\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (WIMMount) โ€“ C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (DKbFltr) Dritek Keyboard Filter Driver (64-bit) โ€“ C:\Windows\SysWOW64\drivers\DKbFltr.sys (Dritek System Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACGโ€ฆ54z105a4482y249
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACGโ€ฆ54z105a4482y249
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTermโ€ฆmp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACGโ€ฆ54z105a4482y249
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACGโ€ฆ54z105a4482y249
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&โ€ฆamp;rlz=1I7ACGW
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTermโ€ฆmp;sourceid=ie7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/mb57?a=DgVbUgHIqP
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTNavAssist.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}โ€ฆamp;FORM=IE8SRC
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&โ€ฆGW_enUS372US372
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTermโ€ฆGW_enUS372US372
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{8B63A8D6-BBED-4341-8867-790E5F524C96}: "URL" = http://mystart.incredimail.com/?search={seโ€ฆ;loc=search_box
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}: "URL" = browseforchange/search/redirect/?type=default&user;_id=fc386360-1883-468b-b65f-0f72af09d09e&query;={searchTerms}
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={A72286Fโ€ฆmp;d=2012-05-15 05:44:51&v;=11.0.0.9&sap;=dsp&q;={searchTerms}
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{BE81E2ED-2E2A-9BB0-8041-CF4B1D205A72}: "URL" = http://int.ask.com/ar?siteid=10000946&โ€ฆferrer:source?}
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com/?search={seโ€ฆbox_im2_test_v2
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://mystart.incredimail.com/mb57?a=DgVbUgHIqP"
FF - prefs.js..extensions.enabledItems: morningCoffee@shaneliesegang:1.33
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7Be4dcb1dd-7e64-4ac9-a5b3-74f0e7ab7eb8%7Dโˆฃ=469dad1e907047d0b4bea113f0f38de2-99689a59add06bdedde022257a874a8682ddc4d9&ds;=od011&v;=11.0.0.9โŸจ=enโ‰บ=sa&d;=2012-05-15%2005%3A44%3A51&sap;=ku&q;="
FF - prefs.js..network.proxy.type: 0


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files (x86)\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@doubletwist.com/NPPodcast: C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll (doubleTwist Corporation)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\DARLENE'S\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\DARLENE'S\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX [2012/05/20 21:15:26 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/06/25 23:13:20 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2012/05/20 21:15:26 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/17 19:19:03 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/25 20:45:07 | 000,000,000 | โ€”D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/17 19:19:03 | 000,000,000 | โ€”D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/25 20:45:07 | 000,000,000 | โ€”D | M]

[2010/08/04 19:50:45 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Extensions
[2012/03/31 22:46:31 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\.BackupManager\extensions
[2012/03/31 22:46:31 | 000,000,000 | โ€”D | M] (Browse For Change) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\.BackupManager\extensions\[removed]
[2012/07/09 17:55:36 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions
[2012/05/14 17:02:28 | 000,000,000 | -H-D | M] (No name found) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\.BackupManager
[2012/05/14 17:01:17 | 000,000,000 | โ€”D | M] (Garmin Communicator) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/07/02 17:03:06 | 000,000,000 | โ€”D | M] (AddThis) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2012/05/14 17:00:46 | 000,000,000 | โ€”D | M] (Browse For Change) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]
[2012/07/02 17:01:33 | 000,000,000 | โ€”D | M] ("I Want This") โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]
[2011/09/11 14:53:52 | 000,000,000 | โ€”D | M] (ShopAtHome.com Intelligent Shopping Toolbar) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]
[2011/03/29 17:57:23 | 000,002,183 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\searchplugins\MyStart Search.xml
[2012/03/19 05:50:04 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/05/20 21:15:26 | 000,000,000 | โ€”D | M] (Web Assistant) โ€“ C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
[1832/11/29 00:58:45 | 000,004,819 | โ€”- | M] () (No name found) โ€“ C:\USERS\DARLENE'S\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RS6A0NLK.DEFAULT\EXTENSIONS\[removed]
[2011/05/15 07:02:15 | 000,107,019 | โ€”- | M] () (No name found) โ€“ C:\USERS\DARLENE'S\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RS6A0NLK.DEFAULT\EXTENSIONS\[removed]
[2011/12/31 11:18:41 | 000,330,316 | โ€”- | M] () (No name found) โ€“ C:\USERS\DARLENE'S\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RS6A0NLK.DEFAULT\EXTENSIONS\[removed]
[2012/06/17 19:19:03 | 000,085,472 | โ€”- | M] (Mozilla Foundation) โ€“ C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/05/19 17:31:43 | 000,466,944 | โ€”- | M] (Catalina Marketing Corporation) โ€“ C:\Program Files (x86)\mozilla firefox\plugins\NPcol400.dll
[2011/05/19 17:31:43 | 000,466,944 | โ€”- | M] (Catalina Marketing Corporation) โ€“ C:\Program Files (x86)\mozilla firefox\plugins\NPcol500.dll
[2011/03/18 14:32:12 | 000,091,552 | โ€”- | M] (Coupons, Inc.) โ€“ C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2012/03/03 08:31:08 | 000,476,904 | โ€”- | M] (Sun Microsystems, Inc.) โ€“ C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 14:32:14 | 000,091,552 | โ€”- | M] (Coupons, Inc.) โ€“ C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/05/15 05:44:27 | 000,003,749 | โ€”- | M] () โ€“ C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/02/13 06:47:31 | 000,002,252 | โ€”- | M] () โ€“ C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/02/13 06:47:31 | 000,002,040 | โ€”- | M] () โ€“ C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://mystart.incredimail.com/mb57?a=DgVbUgHIqP

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | โ€”- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension64.dll ()
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (PodcastBHO Class) - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files (x86)\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files (x86)\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (Javaโ„ข Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\wajam.dll (Wajam)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (ShopAtHomeIEHelper Class) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files (x86)\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome.com)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {06C7AD57-B655-418D-9AB8-9526A6D2E052} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (ShopAtHome.com Toolbar) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files (x86)\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3:64bit: - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [DriverAccess] C:\Program Files (x86)\Driver Assure Corp\DriverAccess\DriverAccess.exe -tray File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Conime] %windir%\system32\conime.exe File not found
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-717187791-2577701650-807877497-1001..\Run: [Applications] C:\Users\DARLENE'S\AppData\Local\assembly\Applications\gqqpr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-717187791-2577701650-807877497-1001..\Run: [IncrediMail] C:\Program Files (x86)\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy Software Installer.lnk = File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy Software Installer.lnk = File not found
O4 - Startup: C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy Software Installer.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: &Add; animation to IncrediMail Style Box - C:\Program Files (x86)\IncrediMail\Bin\resources\WebMenuImg.htm ()
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint Preview - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: &Add; animation to IncrediMail Style Box - C:\Program Files (x86)\IncrediMail\Bin\resources\WebMenuImg.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5โ€ฆheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2FF8D282-F78A-4A33-ABC2-49E72A341482} http://riteaid.storefront.com/images/globaโ€ฆeUpload1_10.CAB (SFImageUpload1_10.ImageUpload)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWireโ€ฆloadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialoโ€ฆosoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shocโ€ฆash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0โ€ฆinAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CF79823C-E338-4FCB-AD89-F2024E306D53}: DhcpNameServer = 192.168.1.1 [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (C:\Windows\DCEBoot64.exe)
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (ngsโ€ฆ)
O34 - HKLM BootExecute: (ountPoints2\F\Shell)
O34 - HKLM BootExecute: (nts2\E\Shell)
O34 - HKLM BootExecute: (hel)
O35:64bit: - HKLM\..comfile [open] โ€“ "%1" %*
O35:64bit: - HKLM\..exefile [open] โ€“ "%1" %*
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37:64bit: - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37:64bit: - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/13 17:34:23 | 000,000,000 | -HSD | C] โ€“ C:\Windows\SysWow64\%APPDATA%
[2012/07/13 17:00:02 | 000,000,000 | -H-D | C] โ€“ C:\Users\DARLENE'S\Desktop\.BackupManager
[2012/07/13 06:06:46 | 000,000,000 | Rโ€“D | C] โ€“ C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 8
[2012/07/12 21:11:51 | 000,000,000 | โ€”D | C] โ€“ C:\Windows\pss
[2012/07/12 20:38:28 | 000,256,904 | โ€”- | C] (Trend Micro Inc.) โ€“ C:\Windows\SysWow64\drivers\tmcomm.sys
[2012/07/12 20:37:13 | 002,002,944 | โ€”- | C] (Trend Micro Inc.) โ€“ C:\Users\DARLENE'S\Desktop\HousecallLauncher.exe
[2012/07/12 19:34:19 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\Desktop\JULY PROBLEM
[2012/07/12 19:20:29 | 000,388,608 | โ€”- | C] (Trend Micro Inc.) โ€“ C:\Users\DARLENE'S\Desktop\HiJackThis.exe
[2012/07/12 19:20:08 | 000,596,480 | โ€”- | C] (OldTimer Tools) โ€“ C:\Users\DARLENE'S\Desktop\OTL.exe
[2012/07/12 07:04:20 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{139A6829-F1F7-41E6-A681-E7FDF1431EC0}
[2012/07/12 07:03:58 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{7BBC262B-889F-4FE4-AFD5-DF54E23F8639}
[2012/07/11 19:02:44 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{AA275D44-BB3E-45C1-AEB0-0CD2015B901A}
[2012/07/11 19:02:21 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{52090F60-850B-46E8-9AE8-FC6005F5DF28}
[2012/07/11 07:01:24 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{95216132-7E02-4BD3-AC34-105B937858CC}
[2012/07/11 07:01:03 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{F11B5F0A-6C67-4CE4-88D1-CF34B8F37866}
[2012/07/10 18:59:00 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{31492FF8-E7ED-4A77-BB9A-E9DBBC5DD560}
[2012/07/10 18:58:39 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{A1F0F47B-35BA-49D7-B3BF-E8021C0773E5}
[2012/07/10 06:26:18 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{0D5A58A6-4597-4598-8CBD-BD29BCCF3F2E}
[2012/07/10 06:25:56 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{1D981AB9-111E-418E-BFE5-D1AE5B842000}
[2012/07/09 18:24:57 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{ABB3A7CE-E804-4A10-9B3A-7F5AB06962C1}
[2012/07/09 18:24:33 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{7E111857-3D9B-4E39-B814-702FE047058B}
[2012/07/09 06:23:36 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{EED5E5AB-6D80-4861-8883-78AE6B39DDD3}
[2012/07/09 06:23:14 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{7E660141-CFE3-42EC-A2FA-D8A0E60AC2D0}
[2012/07/08 18:22:11 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{3B4C8DAE-9DE3-46E9-876B-2A3CC79B2F6C}
[2012/07/08 18:21:49 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{C44EA1D3-1F19-4403-AEDB-C22BD8FDB513}
[2012/07/08 06:19:29 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{7EE27FA6-B2DC-497E-9E6E-F751EAB956BB}
[2012/07/08 06:19:02 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{A83A6CA8-6D37-41DE-A70D-5C75AC52EE51}
[2012/07/07 15:51:35 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{8BE945D5-3E0D-4E03-A34A-A7A8FDDDB349}
[2012/07/07 15:51:02 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{3261F800-A2FA-4891-AB3D-5C78861F43BB}
[2012/07/07 05:48:26 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{6A498AC1-E11B-4497-8E27-7977C4BF3E2F}
[2012/07/06 17:18:09 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{36D9D348-281D-4931-BA74-BF97AECC8803}
[2012/07/06 17:17:40 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{4F4CC4EF-B03B-405C-AF12-F357ECC07CB2}
[2012/07/06 06:23:34 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{022F52A5-A2DF-4F8C-B32F-AE789598BC86}
[2012/07/05 17:37:34 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{4B6DF989-E67A-4BAE-A3B5-DF3F6914E4F5}
[2012/07/05 17:37:11 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{81CA895D-B46E-41AC-BA85-AB4D51BA29E4}
[2012/07/04 22:08:27 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{7F07EEC5-2861-4EB7-BE31-719D6E2260D6}
[2012/07/04 22:08:16 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{C91E45DF-1874-45F6-9CA9-9E8242357B6F}
[2012/07/04 17:26:21 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{965F5248-D96E-4D87-8888-76ED539A899B}
[2012/07/03 20:25:44 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{5B39F650-B109-44FE-84EF-4991496B1283}
[2012/07/03 20:25:22 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{E7823B6E-6BE3-4BA5-BD83-AD4BB2695144}
[2012/07/03 08:24:25 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{36E0CA8E-F6EF-47FB-B2E2-FFA96C171FC6}
[2012/07/03 08:24:03 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{E5446C28-14B9-4CCF-A09B-AED25292D7F4}
[2012/07/02 20:23:02 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{5967C27C-BD6B-412E-AD25-A8571E7F6089}
[2012/07/02 20:22:39 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{8701F7FC-6FB7-482F-9495-B73C1E834E77}
[2012/07/02 08:21:59 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{B0593EB0-F1C4-476E-A3ED-F396F96EF8C4}
[2012/07/02 08:21:38 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{5494C62E-D09A-4BB4-8C79-DDDC25A9849A}
[2012/07/01 20:20:40 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{4E21C335-F594-491A-9B0C-6A40C6B8E3F0}
[2012/07/01 20:20:18 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{DC303853-A8A9-4170-8ECB-4595ED9322F8}
[2012/07/01 08:19:23 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{618AB4B1-3DAF-4209-B9C8-263D700381C1}
[2012/07/01 08:19:02 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{F3C73D18-FE3E-4AF0-942A-1AE3A903BE23}
[2012/06/30 20:17:14 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{A0710D1F-1209-4CD5-811A-9D9EAEB4AF5E}
[2012/06/30 20:16:37 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{850F8AD1-C754-46D6-A9E2-AFA9F96C835B}
[2012/06/30 08:15:12 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{22768A20-770E-4FAD-A29C-1A366922C6B0}
[2012/06/30 08:14:50 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{33BBAF33-97FD-4271-A406-BB66C60EB731}
[2012/06/29 20:12:55 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{337C97E8-75D9-4D05-AFAE-5387D1015D69}
[2012/06/29 20:12:18 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{AF38A96C-7F3D-41F7-BB8D-BECEFC19B22F}
[2012/06/29 07:33:25 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{6F6D880B-87B2-469D-97AA-3C6C54050E42}
[2012/06/29 07:33:03 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{EFB9539C-BECF-4950-95BB-C82F5ABE0B3D}
[2012/06/28 19:32:10 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{14581703-DEE8-4FDB-8BB7-C8C5E1DEED1F}
[2012/06/28 19:31:48 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{3177E9EB-D3F0-4130-9DE4-5171BD7B6E92}
[2012/06/28 07:30:53 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{32C5C6DD-F581-47C0-AF51-823C60E3F7BC}
[2012/06/28 07:30:31 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{06DBDBE1-7B3A-4127-B8BF-B5A6BD19F8E9}
[2012/06/27 19:29:37 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{FEA39E52-DA8B-409D-A4B3-D981D93200DB}
[2012/06/27 19:29:16 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{C0B03C68-969B-4EEA-B0DD-D0D380CA1FC5}
[2012/06/27 07:28:21 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{990EAC21-FA23-446B-A39E-2C19D034EF97}
[2012/06/27 07:28:00 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{21E2773F-2713-44BD-98C5-621AE6CB8355}
[2012/06/26 19:27:24 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{3A4C149D-89DB-49A1-B400-C2BBB255E413}
[2012/06/26 19:27:14 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{0674556F-3D6C-4368-B841-74A67A975ADC}
[2012/06/26 19:27:04 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{AA3F889F-9B0C-41C0-84FD-DE7BD28445C3}
[2012/06/26 19:26:42 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{E3B5A438-C14A-4B8C-9B96-087DD327DF99}
[2012/06/26 07:25:57 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{FADDF3DC-EA7A-4BD1-9EBA-A74B1DA315C2}
[2012/06/26 07:25:47 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{D0CAEE5E-68F2-4036-9F99-8C2453A07E31}
[2012/06/26 07:25:38 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{4A3CCC4E-1B9D-4C4C-9570-873A1684107F}
[2012/06/26 07:25:16 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{C5CF9FD2-0D6F-4CDF-8049-448984081195}
[2012/06/25 19:23:22 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{439D8B6E-8EBB-4A44-A171-5DBE53754DC1}
[2012/06/25 19:23:00 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{C80FAFBC-30CE-4D8E-AC99-B3256AEBF0F0}
[2012/06/25 07:04:49 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{F27F8E72-748F-4C33-9552-4AD25D25CD5D}
[2012/06/25 07:04:39 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{DE090289-4AAA-4859-B00D-FAEAADC1E7D2}
[2012/06/25 07:04:30 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{F59C6A5D-4071-463C-8786-FF5FE2BB8994}
[2012/06/25 07:04:08 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{E54524B0-6739-4B5C-89D4-DED83DF91441}
[2012/06/24 19:02:04 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{1324D474-CA13-4000-99B1-E7AAE4A08A8D}
[2012/06/24 19:01:32 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{71EBA3BA-F864-40FB-963D-6F894B88E62C}
[2012/06/23 21:27:55 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{6072F511-6258-4F47-B3A2-423AC066FB20}
[2012/06/23 21:27:40 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{15B3612F-83FC-4C11-8E4E-67EADE3AFDDD}
[2012/06/23 19:31:21 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{9197B652-D615-407A-B19F-A1364708F5B7}
[2012/06/23 05:36:15 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\Macromedia
[2012/06/22 19:23:08 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{289D8416-4E4E-4BEE-866D-F70394BB9784}
[2012/06/22 19:22:45 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{28AF25D5-1924-467F-ACCD-9D290F235724}
[2012/06/22 07:21:36 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{C565D4AD-DC33-4F92-9990-02D67920F689}
[2012/06/22 07:21:13 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{41981685-E92A-4350-BF93-6728F57E2A76}
[2012/06/21 19:20:15 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{3A31124B-3E21-46D0-A567-F324F7C0069F}
[2012/06/21 19:19:53 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{6FDBF319-4B0C-42A8-9A07-50447E0088DB}
[2012/06/21 07:18:56 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{3AF03AC6-135D-4754-A1BC-F0C6620A0074}
[2012/06/21 07:18:35 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{DF77E8E1-DA96-4C0C-BC91-F427C52BE5F3}
[2012/06/20 19:17:37 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{0FF254E3-B968-43AB-9464-D195CF91D071}
[2012/06/20 19:17:15 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{B5505181-29FC-486B-AEDC-65636B0B5EB6}
[2012/06/20 07:16:22 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{BA1ABA83-0783-4DC2-B32A-1D180D5EF3F1}
[2012/06/20 07:16:00 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{D772FB6C-16E2-4D17-ABE3-7F7B781F081A}
[2012/06/19 19:13:42 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{811D1448-369D-4A61-B623-77813FE4C070}
[2012/06/19 19:13:06 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{A51B2802-EA7C-4342-B7A0-B036AC45CAEB}
[2012/06/19 06:46:03 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{FCA9B886-64BB-4B42-8D6C-BAE9576E336E}
[2012/06/19 06:45:41 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{423CB21B-463B-405C-B8BF-4B1D8CED2E5A}
[2012/06/18 18:45:05 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{46F3CC35-DDA3-4385-99BB-1B83DCC34058}
[2012/06/18 18:44:41 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{09636C01-4975-4558-98A6-87877BB7F7C4}
[2012/06/18 06:42:45 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{44531DC2-0CE9-45E9-8E77-9EBCE154D149}
[2012/06/18 06:42:23 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{8F0FB53F-CFF9-4F9B-ACEC-09FA74BBC5C6}
[2012/06/17 18:41:23 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{363C9C30-DFEC-47AB-8707-0390006DEE6D}
[2012/06/17 18:41:02 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{8A39767B-C1FE-4636-9311-828FA67579F0}
[2012/06/17 06:39:23 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{6912737D-DDC8-4FD7-AA45-715AB53C0CC0}
[2012/06/17 06:38:54 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{95F58310-9A10-453A-B521-7EF7121D26B5}
[2012/06/16 21:07:09 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{8BF2A819-4B76-4FA7-95F4-95047E83BB11}
[2012/06/16 09:06:01 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{89940275-5E73-4FCE-93D3-7D31A766B51C}
[2012/06/16 09:05:39 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{74E7ECC3-4EE4-4908-AFE6-0C7312228087}
[2012/06/15 21:02:18 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{1794FF5D-4661-4E1F-BA86-25995267DE4D}
[2012/06/15 21:01:35 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{1274C061-1BEF-424F-A1F2-BE428007678B}
[2012/06/14 20:20:33 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{3F3C4ADC-DC74-4B6F-AB0E-AC950DB22F02}
[2012/06/14 20:20:15 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{D58221A5-362B-461D-8B70-F825BAA6A4A3}
[2012/06/14 06:31:36 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{11AB78BE-1A59-4BD2-9767-084502FC21B9}
[2012/06/14 06:31:14 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{AE6977FB-1F74-45FC-8B5A-1366B00A913A}
[1 C:\Users\DARLENE'S\Documents\*.tmp files -> C:\Users\DARLENE'S\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/13 22:16:00 | 000,000,904 | โ€”- | M] () โ€“ C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/13 22:07:03 | 000,000,830 | โ€”- | M] () โ€“ C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/13 20:53:02 | 000,000,944 | โ€”- | M] () โ€“ C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-717187791-2577701650-807877497-1001UA.job
[2012/07/13 17:53:24 | 000,000,922 | โ€”- | M] () โ€“ C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-717187791-2577701650-807877497-1001Core.job
[2012/07/13 12:51:31 | 000,021,520 | โ€”- | M] () โ€“ C:\Windows\DCEBoot64.exe
[2012/07/13 12:51:31 | 000,008,948 | โ€”- | M] () โ€“ C:\Windows\DCEBOOT.CFG
[2012/07/13 07:31:29 | 000,000,900 | โ€”- | M] () โ€“ C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/13 06:14:40 | 000,009,920 | -Hโ€“ | M] () โ€“ C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/13 06:14:40 | 000,009,920 | -Hโ€“ | M] () โ€“ C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/13 06:05:31 | 000,067,584 | โ€“S- | M] () โ€“ C:\Windows\bootstat.dat
[2012/07/13 06:05:29 | 2962,309,120 | -HS- | M] () โ€“ C:\hiberfil.sys
[2012/07/13 06:05:27 | 000,001,692 | โ€”- | M] () โ€“ C:\Windows\DCEBOOT.RST
[2012/07/13 06:04:37 | 000,129,024 | โ€”- | M] () โ€“ C:\Windows\RegBootClean64.exe
[2012/07/12 21:22:29 | 000,222,565 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\AppData\Local\census.cache
[2012/07/12 21:19:33 | 000,131,384 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\AppData\Local\ars.cache
[2012/07/12 20:39:08 | 000,000,036 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\AppData\Local\housecall.guid.cache
[2012/07/12 20:37:16 | 002,002,944 | โ€”- | M] (Trend Micro Inc.) โ€“ C:\Users\DARLENE'S\Desktop\HousecallLauncher.exe
[2012/07/12 19:21:01 | 000,625,664 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\Desktop\dds.scr
[2012/07/12 19:20:29 | 000,388,608 | โ€”- | M] (Trend Micro Inc.) โ€“ C:\Users\DARLENE'S\Desktop\HiJackThis.exe
[2012/07/12 19:20:11 | 000,596,480 | โ€”- | M] (OldTimer Tools) โ€“ C:\Users\DARLENE'S\Desktop\OTL.exe
[2012/07/12 17:39:13 | 000,102,400 | โ€”- | M] () โ€“ C:\Windows\RegBootClean.exe
[2012/07/11 17:26:55 | 000,440,536 | โ€”- | M] () โ€“ C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/09 16:12:18 | 000,660,530 | โ€”- | M] () โ€“ C:\Windows\SysNative\perfh009.dat
[2012/07/09 16:12:18 | 000,121,426 | โ€”- | M] () โ€“ C:\Windows\SysNative\perfc009.dat
[2012/07/09 16:12:17 | 000,779,266 | โ€”- | M] () โ€“ C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/08 06:18:48 | 000,000,366 | โ€”- | M] () โ€“ C:\Windows\tasks\Driver Fetch.job
[2012/07/07 16:18:30 | 000,086,016 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/06/23 06:14:21 | 000,000,824 | โ€”- | M] () โ€“ C:\Windows\SysNative\drivers\etc\tmvsthfud.bin
[2012/06/23 06:14:16 | 000,000,824 | โ€”- | M] () โ€“ C:\Windows\SysNative\drivers\etc\tmvsthfss.bin
[2012/06/18 18:35:28 | 000,002,012 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk
[1 C:\Users\DARLENE'S\Documents\*.tmp files -> C:\Users\DARLENE'S\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/13 17:23:30 | 000,095,744 | โ€”- | C] () โ€“ C:\Windows\Installer\{4d69ce62-0186-2acc-f4de-bc14bad586a2}\U\80000032.@
[2012/07/13 17:23:26 | 000,080,896 | โ€”- | C] () โ€“ C:\Windows\Installer\{4d69ce62-0186-2acc-f4de-bc14bad586a2}\U\80000064.@
[2012/07/13 06:13:50 | 000,008,948 | โ€”- | C] () โ€“ C:\Windows\DCEBOOT.CFG
[2012/07/13 06:05:27 | 000,001,692 | โ€”- | C] () โ€“ C:\Windows\DCEBOOT.RST
[2012/07/12 21:22:29 | 000,222,565 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\AppData\Local\census.cache
[2012/07/12 21:19:33 | 000,131,384 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\AppData\Local\ars.cache
[2012/07/12 20:37:46 | 000,000,036 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\AppData\Local\housecall.guid.cache
[2012/07/12 19:36:29 | 000,021,520 | โ€”- | C] () โ€“ C:\Windows\DCEBoot64.exe
[2012/07/12 19:21:00 | 000,625,664 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\Desktop\dds.scr
[2012/07/12 17:58:08 | 000,000,804 | โ€”- | C] () โ€“ C:\Windows\Installer\{4d69ce62-0186-2acc-f4de-bc14bad586a2}\L\00000004.@
[2012/07/12 07:42:35 | 000,129,024 | โ€”- | C] () โ€“ C:\Windows\RegBootClean64.exe
[2012/07/12 07:42:22 | 000,102,400 | โ€”- | C] () โ€“ C:\Windows\RegBootClean.exe
[2012/05/14 17:07:28 | 000,057,344 | โ€”- | C] () โ€“ C:\Windows\SysWow64\ff_vfw.dll
[2012/04/16 17:39:11 | 000,000,106 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\jobq.dat
[2012/03/08 21:13:01 | 000,732,592 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\01174842.one
[2012/01/11 06:48:39 | 000,002,048 | -HS- | C] () โ€“ C:\Windows\Installer\{4d69ce62-0186-2acc-f4de-bc14bad586a2}\@
[2012/01/01 14:11:07 | 000,028,993 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\AppData\Roaming\UserTile.png
[2011/08/28 08:10:45 | 000,000,027 | โ€”- | C] () โ€“ C:\Windows\BarCode.ini
[2011/05/13 06:36:38 | 000,773,482 | โ€”- | C] () โ€“ C:\Windows\SysWow64\PerfStringBackup.INI
[2011/01/16 12:50:52 | 000,029,234 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\Cal0000.htm
[2011/01/16 12:50:52 | 000,000,412 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\Cal0000.vcs
[2010/08/31 19:19:11 | 000,397,312 | โ€”- | C] () โ€“ C:\Windows\SysWow64\Snbd6w95.dll
[2010/08/31 19:19:11 | 000,072,704 | โ€”- | C] () โ€“ C:\Windows\SysWow64\XMain32A.dll
[2010/08/31 19:19:11 | 000,044,544 | โ€”- | C] () โ€“ C:\Windows\SysWow64\gif89.dll
[2010/08/31 19:18:42 | 000,000,357 | โ€”- | C] () โ€“ C:\Windows\Generations.INI
[2010/08/04 19:50:33 | 000,000,000 | โ€”- | C] () โ€“ C:\Windows\nsreg.dat
[2010/07/28 21:08:46 | 000,127,868 | โ€”- | C] () โ€“ C:\Windows\SysWow64\igcompkrng575.bin
[2010/07/28 21:08:44 | 000,104,796 | โ€”- | C] () โ€“ C:\Windows\SysWow64\igfcg575m.bin
[2010/03/31 21:31:45 | 000,007,666 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\AppData\Local\Resmon.ResmonCfg
[2010/03/29 20:48:20 | 000,086,016 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/28 18:43:19 | 000,002,370 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\AppData\Roaming\wklnhst.dat
[2010/03/28 17:00:37 | 000,000,355 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\Computer - Shortcut.lnk

========== LOP Check ==========

[2011/01/10 21:23:06 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\Avery
[2011/05/19 17:31:43 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\Catalina Marketing Corp
[2012/03/14 17:45:45 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\Dropbox
[2010/04/17 07:27:31 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\Facebook
[2012/02/25 21:31:51 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\GARMIN
[2010/11/14 20:23:16 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\GPS Utility
[2012/05/14 17:03:21 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\OpenCandy
[2012/04/15 14:58:08 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\Serif
[2011/12/14 20:32:30 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\Smilebox
[2010/09/08 18:24:15 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\Snippage.B28FB424FD6880E47B18D7D649F6CC93BDE9B29B.1
[2012/03/31 22:56:08 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\SumatraPDF
[2011/04/26 21:08:17 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\Temp
[2010/03/28 18:43:41 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\Template
[2011/03/30 05:45:44 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\Trusteer
[2011/01/22 16:06:02 | 000,000,000 | โ€”D | M] โ€“ C:\Users\DARLENE'S\AppData\Roaming\Windows Live Writer
[2011/06/24 21:23:54 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Guest\AppData\Roaming\Trusteer
[2012/01/08 18:15:56 | 000,000,000 | โ€”D | M] โ€“ C:\Users\QUEEN OF THE ROAD\AppData\Roaming\GARMIN
[2011/06/24 21:50:31 | 000,000,000 | โ€”D | M] โ€“ C:\Users\QUEEN OF THE ROAD\AppData\Roaming\Trusteer
[2012/07/08 06:18:48 | 000,000,366 | โ€”- | M] () โ€“ C:\Windows\Tasks\Driver Fetch.job
[2012/07/13 17:53:24 | 000,000,922 | โ€”- | M] () โ€“ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-717187791-2577701650-807877497-1001Core.job
[2012/07/13 20:53:02 | 000,000,944 | โ€”- | M] () โ€“ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-717187791-2577701650-807877497-1001UA.job
[2012/06/09 18:44:40 | 000,032,534 | โ€”- | M] () โ€“ C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< MD5 for: EXPLORER.EXE >
[2011/02/26 02:23:14 | 002,870,272 | โ€”- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 โ€“ C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 01:19:21 | 002,616,320 | โ€”- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 โ€“ C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | โ€”- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F โ€“ C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | โ€”- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 โ€“ C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | โ€”- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 โ€“ C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | โ€”- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF โ€“ C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | โ€”- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 โ€“ C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | โ€”- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 โ€“ C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | โ€”- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 โ€“ C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | โ€”- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 โ€“ C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 02:19:07 | 002,868,224 | โ€”- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 โ€“ C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | โ€”- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E โ€“ C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | โ€”- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E โ€“ C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 02:34:59 | 002,870,272 | โ€”- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE โ€“ C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | โ€”- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D โ€“ C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 09:24:45 | 002,872,320 | โ€”- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 โ€“ C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 02:38:38 | 002,870,272 | โ€”- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F โ€“ C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | โ€”- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 โ€“ C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | โ€”- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 โ€“ C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | โ€”- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 โ€“ C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 02:26:45 | 002,870,784 | โ€”- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D โ€“ C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 02:17:37 | 002,868,224 | โ€”- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 โ€“ C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 21:14:41 | 000,020,992 | โ€”- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 โ€“ C:\Windows\SysWOW64\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | โ€”- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 โ€“ C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | โ€”- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D โ€“ C:\Windows\SysNative\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | โ€”- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D โ€“ C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 08:17:48 | 000,026,624 | โ€”- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 โ€“ C:\Windows\SysWOW64\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | โ€”- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 โ€“ C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 21:14:43 | 000,026,112 | โ€”- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 โ€“ C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 21:39:48 | 000,030,208 | โ€”- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE โ€“ C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 09:25:24 | 000,030,720 | โ€”- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 โ€“ C:\Windows\SysNative\userinit.exe
[2010/11/20 09:25:24 | 000,030,720 | โ€”- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 โ€“ C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 09:25:30 | 000,390,656 | โ€”- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 โ€“ C:\Windows\SysNative\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | โ€”- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 โ€“ C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 21:39:52 | 000,389,120 | โ€”- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A โ€“ C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 03:01:57 | 000,389,632 | โ€”- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE โ€“ C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 02:24:40 | 000,389,632 | โ€”- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A โ€“ C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< End of report >


Here is Extras.txt

OTL Extras logfile created on: 8/19/2010 6:26:23 AM - Run 5
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\DARLENE'S\Desktop\WEEKLY SCANS
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 47.00% Memory free
7.00 Gb Paging File | 5.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453.66 Gb Total Space | 337.05 Gb Free Space | 74.30% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DARLENES-PC
Current User Name: DARLENE'S
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] โ€“ C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] โ€“ C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] โ€“ "%1" %* File not found
cmdfile [open] โ€“ "%1" %* File not found
comfile [open] โ€“ "%1" %* File not found
exefile [open] โ€“ "%1" %* File not found
helpfile [open] โ€“ Reg Error: Key error.
htmlfile โ€“ "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] โ€“ "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] โ€“ %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] โ€“ "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] โ€“ "%1" %* File not found
regfile [merge] โ€“ Reg Error: Key error.
scrfile [config] โ€“ "%1" File not found
scrfile [install] โ€“ rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] โ€“ "%1" /S File not found
txtfile โ€“ Reg Error: Key error.
Unknown [openas] โ€“ %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] โ€“ cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] โ€“ Reg Error: Value error.
Drive [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] โ€“ "%1" %*
cmdfile [open] โ€“ "%1" %*
comfile [open] โ€“ "%1" %*
cplfile [cplopen] โ€“ %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] โ€“ "%1" %*
helpfile [open] โ€“ Reg Error: Key error.
htmlfile โ€“ "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] โ€“ "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] โ€“ %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] โ€“ "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] โ€“ "%1" %*
regfile [merge] โ€“ Reg Error: Key error.
scrfile [config] โ€“ "%1"
scrfile [install] โ€“ rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] โ€“ "%1" /S
txtfile โ€“ Reg Error: Key error.
Unknown [openas] โ€“ %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] โ€“ cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] โ€“ Reg Error: Value error.
Drive [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP1700" = Canon iP1700
"{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}" = Intelยฎ Turbo Boost Technology Monitor
"{709BE6E5-DE39-4E2F-9B9B-8DE299519495}" = Windows Live MIME IFilter
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro AntiVirus
"{76C32FF0-2957-4F56-8B5D-F62E3FB6B609}" = Windows Live ID Sign-in Assistant
"{8AA463DE-2446-40A9-9C8F-E9C225E072D5}" = Windows Live Remote Client
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intelยฎ Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D2B0322-44AE-460E-9283-4D2D7A9205AE}" = Trend Micro AntiVirus
"{AD712BC2-B0CD-4187-B8F3-B74932F77C9E}" = Windows Live Remote Client Resources
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{E4E1C2C2-37A1-4409-B26D-BFA3A52CDE6A}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy Software Installer
"{FC347CBB-0E51-4AD9-B97F-46C121DA2432}" = Windows Live Remote Service Resources
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"CanonMyPrinter" = Canon My Printer
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{007EA334-6071-41BF-B8C7-4C4E37E49DA7}" = Messenger Companion
"{035C76D2-7D8E-484D-8CA3-686C0B474A2B}" = MSVCRT
"{07766F89-EFAA-4635-86B7-636B89EA2C0D}" = Bing Bar Platform
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{0CA72D12-F6C6-4D43-A2A0-41F5AA17E2B6}" = Netflix in Windows Media Center
"{11EFF057-8ED2-4321-A19D-D673DECB36CC}" = Junk Mail filter update
"{15F4085A-BC98-4590-AFFD-03BBBE49524E}" = Garmin Communicator Plugin
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{224935E4-2014-4B22-95DC-2CCF5428B4BF}" = Windows Live Writer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2578D94A-A88A-4643-9DAA-F0A5E981EB04}" = Windows Live Messenger
"{2607FE6B-1D61-46E5-A544-54666B0EF908}" = Windows Live Mail
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Javaโ„ข 6 Update 21
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"{2C4F4D53-78D6-41FB-A4D7-105C537464EB}" = Mesh Runtime
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{328019A7-0012-401D-96A2-4CDDD02675A8}" = Garmin POI Loader
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Gateway Power Management
"{3F62782D-2798-4540-B493-F6472197900E}" = Microsoft Search Enhancement Pack
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{46BAF2A0-3789-4E49-B000-4BB64426D1BF}" = Windows Live Installer
"{46C106C9-3856-4A6A-AAC8-7070FBA02D2F}" = Windows Live Movie Maker
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EC66844-AE87-47DC-B02D-E36C75EAF22C}" = Windows Live Sync Beta
"{510D2239-6C2E-457B-9590-485EC552D94D}" = Garmin USB Drivers
"{52CDDA92-56B6-4BA5-BD8D-E13B186008CB}" = D3DX10
"{58B42F3F-EC8D-4A53-9813-5EA43C4E9350}" = Garmin City Navigator North America NT 2009
"{58FA5D40-E35A-47ED-8AFA-68CCC758559E}" = Garmin MapSource
"{61E7F654-7D99-4C69-94D8-DF53E297AF9B}" = Windows Live Photo Common
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intelยฎ Management Engine Components
"{6592C2B8-949A-4C88-BCB9-0990A218B215}" = Windows Live UX Platform
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{67E4EE98-59F4-4210-89A6-A20AF5BEC689}" = Microsoft Streets and Trips 2005
"{6917F87D-921D-4EFA-9AA5-8CDEA9E28520}" = MSVCRT_amd64
"{6B0AE911-A3F4-4D55-9CA7-C76DC2BCEA86}" = Windows Live UX Platform Language Pack
"{6D9021DC-CF1B-4148-8C80-6D8E8A8A33EB}" = Video Web Camera
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{74B0BEB0-2EB3-448F-B8E9-40983BC902E1}" = Windows Live SOXE Definitions
"{75AE8014-1184-4BC0-B279-C879540719EE}" = PhotoMail Maker
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7A8E7F22-3628-4846-A578-516BDCB2CEAA}" = Windows Live Sync Beta
"{7EFA8362-CE86-46E7-BEB9-B2DB4F0D0EE6}" = Windows Live Photo Gallery Beta
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Gateway Recovery Management
"{828DB235-8D79-4E39-A327-AEC9A1185070}" = LiveUpload to Facebook
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83BC206C-98A5-4CF3-B884-2B58CD4AB951}" = Windows Live Writer
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E74FC72-018A-4EC5-86AA-D8021309D484}" = Windows Live Messenger
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{91803386-4FBD-4C38-9644-26B0F9464031}" = Windows Live Photo Gallery
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95140000-0048-0409-0000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 32-bit
"{95140000-0079-0409-0000-0000000FF1CE}" = Windows Live Provider for Microsoft Outlook Social Connector 32-bit
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9D0467C4-F69C-4E9D-8765-7774D8971F5C}" = Windows Live Messenger Companion Core
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet TV for Windows Media Center
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{A3D88A98-506E-4CFC-B294-E256C679B0EE}" = Microsoft Store Download Manager
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.3.3 MUI
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5BD2B33-FDB8-4DE5-87B3-2810CAF4A6E4}" = Windows Live PIMT Platform
"{C2687C43-507E-4D4B-A30A-3C836C756226}" = Windows Live Mail
"{C2D129C0-7508-11DF-9F1B-005056806466}" = Google Earth
"{D17111CB-C992-42A9-9D56-C19395102AAA}" = Garmin WebUpdater
"{D4790ACB-4BB4-4FE6-9F64-1D4486C8E40C}" = Windows Live Photo Common Beta
"{D65F8E34-C050-4E6C-86DB-D2B9075749A0}" = Windows Live Sync ActiveX Control for Remote Connections
"{D943C8AC-9E03-4C2D-B54C-A28ABE931665}" = Windows Live Movie Maker
"{E24DFAA7-9495-4F7D-BB9E-211C2D0A76E5}" = Windows Live Writer Resources
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E2D09AC2-4153-4817-AAEB-24F92A8BCE88}" = Windows Media Center Add-in for Flash
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EACF374B-9D4C-4A07-8EB3-706BD8DAA650}" = Windows Live Essentials Beta
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Gateway Updater
"{EE338AB8-4E85-4C04-AC07-1357A266DD35}" = Windows Live Writer
"{EFBE9DAB-9C80-4911-847B-2A2C25E8F9CB}" = Windows Live SOXE
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intelยฎ Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intelยฎ Control Center
"{FA5D1C9E-154D-49B1-8CF0-DF5FAB6171EA}" = Windows Live Communications Platform
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Best Buy Software Installer" = Best Buy Software Installer
"CameraUserGuide-PSSX120IS" = Canon PowerShot SX120 IS Camera User Guide
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDC8" = Canon Utilities CameraWindow DC 8
"CameraWindowLauncher" = Canon Utilities CameraWindow
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-WebPrint" = Easy-WebPrint
"ESET Online Scanner" = ESET Online Scanner v3
"Gateway InfoCentre" = Gateway InfoCentre
"Gateway Registration" = Gateway Registration
"Gateway Screensaver" = Gateway ScreenSaver
"Gateway Welcome Center" = Welcome Center
"Google Chrome" = Google Chrome
"Identity Card" = Identity Card
"IncrediMail" = IncrediMail 2.0
"InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Gateway MyBackup
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"MyCamera" = Canon Utilities MyCamera
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"Personal Printing Guide" = Canon Personal Printing Guide
"PhotoMail" = PhotoMail Maker
"PhotoStitch" = Canon Utilities PhotoStitch
"Picasa 3" = Picasa 3
"Software Guide" = Canon DIGITAL CAMERA Solution Disk Software Guide
"The Unzip Wizard" = The Unzip Wizard
"Verizon Help and Support" = Verizon Help and Support Tool
"WinLiveSuite" = Windows Live Essentials Beta
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Smilebox" = Smilebox

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Hi,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to format and reinstall your Operating System please let me know and we can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
โ€”โ€”โ€”-

Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
โ€”โ€”โ€”-

If you are running Malwarebytes 1.6 or better, please disable it for the duration of this run.

To disable Malwarebytes
  • Open the scanner and select the Protection tab
  • Remove the tick from "Start Protection Module with Windows" as seen below
[external image: Posted Image]

Once complete continue with the instructionsโ€ฆ
โ€”โ€”โ€”-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Files
    C:\Windows\Installer\{4d69ce62-0186-2acc-f4de-bc14bad586a2}
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
โ€”โ€”โ€”-

Download Combofix from the link below, and save it to your desktop.
Link

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
โ€”โ€”โ€”-
I have been gone all day on a long bike ride, was very refreshingโ€ฆ.until I came home to read your recent reply. Geez! Can it get any worse!! I guess I will do what I have to do. This morning when I got up, I ran a the last scan from your first reply using aswMBR: here is the text aswMBR version 0.9.9.1665 Copyrightยฉ 2011 AVAST Software Run date: 2012-07-14 06:07:50 โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“ 06:07:50.272 OS Version: Windows x64 6.1.7601 Service Pack 1 06:07:50.272 Number of processors: 4 586 0x2502 06:07:50.273 ComputerName: DARLENES-PC UserName: DARLENE'S 06:08:00.772 Initialize success 06:09:06.459 AVAST engine defs: 12071400 06:09:27.850 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 06:09:27.852 Disk 0 Vendor: ST950032 0001 Size: 476940MB BusType: 3 06:09:28.030 Disk 0 MBR read successfully 06:09:28.032 Disk 0 MBR scan 06:09:28.179 Disk 0 Windows 7 default MBR code 06:09:28.183 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 12291 MB offset 63 06:09:29.058 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 101 MB offset 25173855 06:09:29.115 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 464545 MB offset 25382700 06:09:30.825 Disk 0 scanning C:\Windows\system32\drivers 06:10:52.710 Service scanning 06:14:47.249 Modules scanning 06:14:47.258 Disk 0 trace - called modules: 06:14:47.306 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 06:14:47.313 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80058b9060] 06:14:47.525 3 CLASSPNP.SYS[fffff88001b9b43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004ab0050] 06:15:04.431 AVAST engine scan C:\Windows 06:15:58.308 AVAST engine scan C:\Windows\system32 06:37:34.233 AVAST engine scan C:\Windows\system32\drivers 06:38:19.077 AVAST engine scan C:\Users\DARLENE'S 08:01:09.200 File: C:\Users\DARLENE'S\AppData\Local\Temp\ICReinstall_PDFReaderSetup.exe **INFECTED** Win32:Adware-gen [Adw] 09:56:08.731 AVAST engine scan C:\ProgramData 10:06:55.012 Scan finished successfully 20:01:50.408 Disk 0 MBR has been saved successfully to "C:\Users\DARLENE'S\Desktop\JULY PROBLEM\awsMBR\MBR.dat" 20:01:50.417 The log file has been saved successfully to "C:\Users\DARLENE'S\Desktop\JULY PROBLEM\awsMBR\aswMBR.txt" I will print your most recent response and and begin those steps. Thanks for all your help! Dar
Jeff - I have downloaded ERUNT and followed your instructions.

to the best of knowledge I am not running Malwarebytes.

I also ran OTEL and copied your code, when it was done, it asked to be rebooted, I did that, then a notepad popped up with this below:

All processes killed
========== SERVICES/DRIVERS ==========
========== FILES ==========
C:\Windows\Installer\{4d69ce62-0186-2acc-f4de-bc14bad586a2}\U folder moved successfully.
C:\Windows\Installer\{4d69ce62-0186-2acc-f4de-bc14bad586a2}\L folder moved successfully.
C:\Windows\Installer\{4d69ce62-0186-2acc-f4de-bc14bad586a2} folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator

User: All Users

User: DARLENE'S
->Temp folder emptied: 4845913659 bytes
->Temporary Internet Files folder emptied: 1280243084 bytes
->Java cache emptied: 2568323 bytes
->FireFox cache emptied: 55026687 bytes
->Google Chrome cache emptied: 7018683 bytes
->Flash cache emptied: 248329 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 134 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Guest
->Temp folder emptied: 283387 bytes
->Temporary Internet Files folder emptied: 10255210 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 531 bytes

User: Public

User: QUEEN OF THE ROAD
->Temp folder emptied: 5283495 bytes
->Temporary Internet Files folder emptied: 183530777 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 6121480 bytes
->Flash cache emptied: 2398 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1093602000 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 134 bytes
RecycleBin emptied: 26088348373 bytes

Total Files Cleaned = 32,023.00 mb


OTL by OldTimer - Version 3.2.54.0 log created on 07142012_202518

Files\Folders moved on Rebootโ€ฆ
C:\Users\DARLENE'S\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations filesโ€ฆ
File C:\Users\DARLENE'S\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!

Registry entries deleted on Rebootโ€ฆ

โ€”โ€”โ€”-
your instructions say to run OTEL again - so I shall let it run while I am sleeping. Tomorrow is another rideโ€ฆjust not as long.

Dar

thanks again for your help!




Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
โ€”โ€”โ€”-

If you are running Malwarebytes 1.6 or better, please disable it for the duration of this run.

To disable Malwarebytes
  • Open the scanner and select the Protection tab
  • Remove the tick from "Start Protection Module with Windows" as seen below
[external image: Posted Image]

Once complete continue with the instructionsโ€ฆ
โ€”โ€”โ€”-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Files
    C:\Windows\Installer\{4d69ce62-0186-2acc-f4de-bc14bad586a2}
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
โ€”โ€”โ€”-

Download Combofix from the link below, and save it to your desktop.
Link

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
โ€”โ€”โ€”-

:thumbup:


OK! I'm up. called the bank customer service number last night after reading your last postโ€ฆuseless people. "Brandi" told me that she could not change my bank password to my log in - I have to do that myself onlineโ€ฆhmmm..so I repeated my plea and she repeated her last comment again. I told her thanks, you've been a BIG help!! I did the next best thing. I called my daughter, had her go to my bank site and log in as me, and change my password, my husbands password too. Then I had her go to PAYPAL and change that password.

I wake up this morning to OTL's text log:

OTL logfile created on: 7/14/2012 10:27:51 PM - Run 7
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\DARLENE'S\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.68 Gb Total Physical Memory | 2.29 Gb Available Physical Memory | 62.25% Memory free
7.36 Gb Paging File | 5.90 Gb Available in Paging File | 80.22% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453.66 Gb Total Space | 59.01 Gb Free Space | 13.01% Space Free | Partition Type: NTFS

Computer Name: DARLENES-PC | User Name: DARLENE'S | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\DARLENE'S\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Web Assistant\ExtensionUpdaterService.exe ()
PRC - C:\Program Files\Wajam\Updater\WajamUpdater.exe (Wajam)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intelยฎ Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intelยฎ Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
PRC - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)


========== Modules (No Company Name) ==========

MOD - C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\39624\RapportMS.dll ()
MOD - C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll ()
MOD - \\?\globalroot\systemroot\syswow64\mswsock.DLL ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (!SASCORE) โ€“ C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SRV:64bit: - (Web Assistant Updater) โ€“ C:\Program Files\Web Assistant\ExtensionUpdaterService.exe ()
SRV:64bit: - (WajamUpdater) โ€“ C:\Program Files\Wajam\Updater\WajamUpdater.exe (Wajam)
SRV:64bit: - (SfCtlCom) โ€“ C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV:64bit: - (wlcrasvc) โ€“ C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (TmProxy) โ€“ C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV:64bit: - (TMBMServer) โ€“ C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV:64bit: - (TurboBoost) โ€“ C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intelยฎ Corporation)
SRV:64bit: - (ePowerSvc) โ€“ C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (Updater Service) โ€“ C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
SRV - (AdobeFlashPlayerUpdateSvc) โ€“ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) โ€“ C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (RapportMgmtService) โ€“ C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (AdobeARMservice) โ€“ C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Kodak AiO Network Discovery Service) โ€“ C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
SRV - (BBSvc) โ€“ C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) โ€“ C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (NTI IScheduleSvc) โ€“ C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (clr_optimization_v4.0.30319_32) โ€“ C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) โ€“ C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (IAANTMON) Intelยฎ โ€“ C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (UNS) Intelยฎ โ€“ C:\Program Files (x86)\Intel\Intelยฎ Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intelยฎ โ€“ C:\Program Files (x86)\Intel\Intelยฎ Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Greg_Service) โ€“ C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) โ€“ C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (HsfXAudioService) โ€“ C:\Windows\SysWOW64\XAudio64.dll (Conexant Systems, Inc.)
SRV - (YahooAUService) โ€“ C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (RapportKE64) โ€“ C:\Windows\SysNative\drivers\RapportKE64.sys (Trusteer Ltd.)
DRV:64bit: - (fssfltr) โ€“ C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) โ€“ C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (iPodDrv) โ€“ C:\Windows\SysNative\drivers\iPodDrv.sys (Windows ยฎ Codename Longhorn DDK provider)
DRV:64bit: - (tmxpflt) โ€“ C:\Windows\SysNative\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV:64bit: - (tmpreflt) โ€“ C:\Windows\SysNative\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV:64bit: - (vsapint) โ€“ C:\Windows\SysNative\drivers\vsapint.sys (Trend Micro Inc.)
DRV:64bit: - (amdsata) โ€“ C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) โ€“ C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) โ€“ C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) โ€“ C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (igfx) โ€“ C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (tmtdi) โ€“ C:\Windows\SysNative\drivers\tmtdi.sys (Trend Micro Inc.)
DRV:64bit: - (athr) โ€“ C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (TurboB) โ€“ C:\Windows\SysNative\drivers\TurboB.sys ()
DRV:64bit: - (IntcDAud) Intelยฎ โ€“ C:\Windows\SysNative\drivers\IntcDAud.sys (Intelยฎ Corporation)
DRV:64bit: - (Impcd) โ€“ C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (SynTP) โ€“ C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (iaStor) โ€“ C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (HECIx64) Intelยฎ โ€“ C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) โ€“ C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (k57nd60a) Broadcom NetLink โ„ข โ€“ C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (amdsbs) โ€“ C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) โ€“ C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) โ€“ C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (atikmdag) โ€“ C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (PxHlpa64) โ€“ C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (VX3000) โ€“ C:\Windows\SysNative\drivers\VX3000.sys (Microsoft Corporation)
DRV:64bit: - (RTHDMIAzAudService) โ€“ C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (SrvHsfV92) โ€“ C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) โ€“ C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) โ€“ C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (ebdrv) โ€“ C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) โ€“ C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) โ€“ C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) โ€“ C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (grmnusb) โ€“ C:\Windows\SysNative\drivers\grmnusb.sys (GARMIN Corp.)
DRV:64bit: - (NTIDrvr) โ€“ C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) โ€“ C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (XAudio) โ€“ C:\Windows\SysNative\drivers\XAudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DPV) โ€“ C:\Windows\SysNative\drivers\CAX_DPV.sys (Conexant Systems, Inc.)
DRV:64bit: - (CAXHWAZL) โ€“ C:\Windows\SysNative\drivers\CAXHWAZL.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) โ€“ C:\Windows\SysNative\drivers\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (USBModem) โ€“ C:\Windows\SysNative\drivers\lgx64modem.sys (LG Electronics Inc.)
DRV:64bit: - (UsbDiag) โ€“ C:\Windows\SysNative\drivers\lgx64diag.sys (LG Electronics Inc.)
DRV:64bit: - (usbbus) โ€“ C:\Windows\SysNative\drivers\lgx64bus.sys (LG Electronics Inc.)
DRV:64bit: - (mdmxsdk) โ€“ C:\Windows\SysNative\drivers\mdmxsdk.sys (Conexant)
DRV - (RapportCerberus_34302) โ€“ C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_34302.sys ()
DRV - (RapportEI64) โ€“ C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys (Trusteer Ltd.)
DRV - (RapportPG64) โ€“ C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys (Trusteer Ltd.)
DRV - (MREMP50) โ€“ C:\Program Files (x86)\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) โ€“ C:\Program Files (x86)\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (RSUSBSTOR) โ€“ C:\Windows\SysWOW64\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (WIMMount) โ€“ C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (DKbFltr) Dritek Keyboard Filter Driver (64-bit) โ€“ C:\Windows\SysWOW64\drivers\DKbFltr.sys (Dritek System Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACGโ€ฆ54z105a4482y249
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACGโ€ฆ54z105a4482y249
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTermโ€ฆmp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACGโ€ฆ54z105a4482y249
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACGโ€ฆ54z105a4482y249
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&โ€ฆamp;rlz=1I7ACGW
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTermโ€ฆmp;sourceid=ie7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/mb57?a=DgVbUgHIqP
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTNavAssist.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}โ€ฆamp;FORM=IE8SRC
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&โ€ฆGW_enUS372US372
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTermโ€ฆGW_enUS372US372
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{8B63A8D6-BBED-4341-8867-790E5F524C96}: "URL" = http://mystart.incredimail.com/?search={seโ€ฆ;loc=search_box
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}: "URL" = browseforchange/search/redirect/?type=default&user;_id=fc386360-1883-468b-b65f-0f72af09d09e&query;={searchTerms}
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={A72286Fโ€ฆmp;d=2012-05-15 05:44:51&v;=11.0.0.9&sap;=dsp&q;={searchTerms}
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{BE81E2ED-2E2A-9BB0-8041-CF4B1D205A72}: "URL" = http://int.ask.com/ar?siteid=10000946&โ€ฆferrer:source?}
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com/?search={seโ€ฆbox_im2_test_v2
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-717187791-2577701650-807877497-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://forums.whatthetech.com/index.php?act=UserCP&CODE;=26"
FF - prefs.js..extensions.enabledItems: morningCoffee@shaneliesegang:1.33
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7Be4dcb1dd-7e64-4ac9-a5b3-74f0e7ab7eb8%7Dโˆฃ=469dad1e907047d0b4bea113f0f38de2-99689a59add06bdedde022257a874a8682ddc4d9&ds;=od011&v;=11.0.0.9โŸจ=enโ‰บ=sa&d;=2012-05-15%2005%3A44%3A51&sap;=ku&q;="
FF - prefs.js..network.proxy.type: 0


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files (x86)\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@doubletwist.com/NPPodcast: C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll (doubleTwist Corporation)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\DARLENE'S\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\DARLENE'S\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX [2012/05/20 21:15:26 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/06/25 23:13:20 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2012/05/20 21:15:26 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/17 19:19:03 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/25 20:45:07 | 000,000,000 | โ€”D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/17 19:19:03 | 000,000,000 | โ€”D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/25 20:45:07 | 000,000,000 | โ€”D | M]

[2010/08/04 19:50:45 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Extensions
[2012/03/31 22:46:31 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\.BackupManager\extensions
[2012/03/31 22:46:31 | 000,000,000 | โ€”D | M] (Browse For Change) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\.BackupManager\extensions\[removed]
[2012/07/09 17:55:36 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions
[2012/05/14 17:02:28 | 000,000,000 | -H-D | M] (No name found) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\.BackupManager
[2012/05/14 17:01:17 | 000,000,000 | โ€”D | M] (Garmin Communicator) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/07/02 17:03:06 | 000,000,000 | โ€”D | M] (AddThis) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2012/05/14 17:00:46 | 000,000,000 | โ€”D | M] (Browse For Change) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]
[2012/07/02 17:01:33 | 000,000,000 | โ€”D | M] ("I Want This") โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]
[2011/09/11 14:53:52 | 000,000,000 | โ€”D | M] (ShopAtHome.com Intelligent Shopping Toolbar) โ€“ C:\Users\DARLENE'S\AppData\Roaming\mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]
[2011/03/29 17:57:23 | 000,002,183 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\searchplugins\MyStart Search.xml
[2012/03/19 05:50:04 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/05/20 21:15:26 | 000,000,000 | โ€”D | M] (Web Assistant) โ€“ C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
[1832/11/29 00:58:45 | 000,004,819 | โ€”- | M] () (No name found) โ€“ C:\USERS\DARLENE'S\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RS6A0NLK.DEFAULT\EXTENSIONS\[removed]
[2011/05/15 07:02:15 | 000,107,019 | โ€”- | M] () (No name found) โ€“ C:\USERS\DARLENE'S\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RS6A0NLK.DEFAULT\EXTENSIONS\[removed]
[2011/12/31 11:18:41 | 000,330,316 | โ€”- | M] () (No name found) โ€“ C:\USERS\DARLENE'S\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\RS6A0NLK.DEFAULT\EXTENSIONS\[removed]
[2012/06/17 19:19:03 | 000,085,472 | โ€”- | M] (Mozilla Foundation) โ€“ C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/05/19 17:31:43 | 000,466,944 | โ€”- | M] (Catalina Marketing Corporation) โ€“ C:\Program Files (x86)\mozilla firefox\plugins\NPcol400.dll
[2011/05/19 17:31:43 | 000,466,944 | โ€”- | M] (Catalina Marketing Corporation) โ€“ C:\Program Files (x86)\mozilla firefox\plugins\NPcol500.dll
[2011/03/18 14:32:12 | 000,091,552 | โ€”- | M] (Coupons, Inc.) โ€“ C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2012/03/03 08:31:08 | 000,476,904 | โ€”- | M] (Sun Microsystems, Inc.) โ€“ C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 14:32:14 | 000,091,552 | โ€”- | M] (Coupons, Inc.) โ€“ C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/05/15 05:44:27 | 000,003,749 | โ€”- | M] () โ€“ C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/02/13 06:47:31 | 000,002,252 | โ€”- | M] () โ€“ C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/02/13 06:47:31 | 000,002,040 | โ€”- | M] () โ€“ C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://mystart.incredimail.com/mb57?a=DgVbUgHIqP

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | โ€”- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension64.dll ()
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (PodcastBHO Class) - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files (x86)\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files (x86)\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (Javaโ„ข Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\wajam.dll (Wajam)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (ShopAtHomeIEHelper Class) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files (x86)\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome.com)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {06C7AD57-B655-418D-9AB8-9526A6D2E052} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (ShopAtHome.com Toolbar) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files (x86)\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3:64bit: - HKU\S-1-5-21-717187791-2577701650-807877497-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [DriverAccess] C:\Program Files (x86)\Driver Assure Corp\DriverAccess\DriverAccess.exe -tray File not found
O4:64bit: - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\SysNative\spool\drivers\x64\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Conime] %windir%\system32\conime.exe File not found
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe File not found
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-717187791-2577701650-807877497-1001..\Run: [Applications] C:\Users\DARLENE'S\AppData\Local\assembly\Applications\gqqpr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-717187791-2577701650-807877497-1001..\Run: [IncrediMail] C:\Program Files (x86)\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy Software Installer.lnk = File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy Software Installer.lnk = File not found
O4 - Startup: C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy Software Installer.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: &Add; animation to IncrediMail Style Box - C:\Program Files (x86)\IncrediMail\Bin\resources\WebMenuImg.htm ()
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint Preview - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8:64bit: - Extra context menu item: Easy-WebPrint Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: &Add; animation to IncrediMail Style Box - C:\Program Files (x86)\IncrediMail\Bin\resources\WebMenuImg.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5โ€ฆheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2FF8D282-F78A-4A33-ABC2-49E72A341482} http://riteaid.storefront.com/images/globaโ€ฆeUpload1_10.CAB (SFImageUpload1_10.ImageUpload)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWireโ€ฆloadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialoโ€ฆosoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shocโ€ฆash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0โ€ฆinAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CF79823C-E338-4FCB-AD89-F2024E306D53}: DhcpNameServer = 192.168.1.1 [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (C:\Windows\DCEBoot64.exe)
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (ngsโ€ฆ)
O34 - HKLM BootExecute: (ountPoints2\F\Shell)
O34 - HKLM BootExecute: (nts2\E\Shell)
O34 - HKLM BootExecute: (hel)
O35:64bit: - HKLM\..comfile [open] โ€“ "%1" %*
O35:64bit: - HKLM\..exefile [open] โ€“ "%1" %*
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37:64bit: - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37:64bit: - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/07/14 21:44:38 | 000,000,000 | Rโ€“D | C] โ€“ C:\Users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 8
[2012/07/14 20:21:02 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/07/14 20:21:01 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files (x86)\ERUNT
[2012/07/14 20:13:15 | 000,791,393 | โ€”- | C] (Lars Hederer ) โ€“ C:\Users\DARLENE'S\Desktop\erunt-setup.exe
[2012/07/14 17:00:02 | 000,000,000 | -H-D | C] โ€“ C:\Users\DARLENE'S\Desktop\.BackupManager
[2012/07/14 06:03:51 | 004,731,392 | โ€”- | C] (AVAST Software) โ€“ C:\Users\DARLENE'S\Desktop\aswMBR.exe
[2012/07/13 17:34:23 | 000,000,000 | -HSD | C] โ€“ C:\Windows\SysWow64\%APPDATA%
[2012/07/12 21:11:51 | 000,000,000 | โ€”D | C] โ€“ C:\Windows\pss
[2012/07/12 20:38:28 | 000,256,904 | โ€”- | C] (Trend Micro Inc.) โ€“ C:\Windows\SysWow64\drivers\tmcomm.sys
[2012/07/12 20:37:13 | 002,002,944 | โ€”- | C] (Trend Micro Inc.) โ€“ C:\Users\DARLENE'S\Desktop\HousecallLauncher.exe
[2012/07/12 19:34:19 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\Desktop\JULY PROBLEM
[2012/07/12 19:20:29 | 000,388,608 | โ€”- | C] (Trend Micro Inc.) โ€“ C:\Users\DARLENE'S\Desktop\HiJackThis.exe
[2012/07/12 19:20:08 | 000,596,480 | โ€”- | C] (OldTimer Tools) โ€“ C:\Users\DARLENE'S\Desktop\OTL.exe
[2012/07/12 07:04:20 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{139A6829-F1F7-41E6-A681-E7FDF1431EC0}
[2012/07/12 07:03:58 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{7BBC262B-889F-4FE4-AFD5-DF54E23F8639}
[2012/07/11 19:02:44 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{AA275D44-BB3E-45C1-AEB0-0CD2015B901A}
[2012/07/11 19:02:21 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{52090F60-850B-46E8-9AE8-FC6005F5DF28}
[2012/07/11 07:01:24 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{95216132-7E02-4BD3-AC34-105B937858CC}
[2012/07/11 07:01:03 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{F11B5F0A-6C67-4CE4-88D1-CF34B8F37866}
[2012/07/11 06:04:30 | 000,237,056 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\url.dll
[2012/07/11 06:04:30 | 000,231,936 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysWow64\url.dll
[2012/07/11 06:04:30 | 000,096,768 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\mshtmled.dll
[2012/07/11 06:04:30 | 000,073,216 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysWow64\mshtmled.dll
[2012/07/11 06:04:28 | 000,248,320 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\ieui.dll
[2012/07/11 06:04:28 | 000,176,640 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysWow64\ieui.dll
[2012/07/11 06:04:28 | 000,173,056 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\ieUnatt.exe
[2012/07/11 06:04:28 | 000,142,848 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysWow64\ieUnatt.exe
[2012/07/11 06:04:26 | 001,427,968 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysWow64\inetcpl.cpl
[2012/07/11 06:04:25 | 002,311,680 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\jscript9.dll
[2012/07/11 06:04:25 | 001,494,528 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\inetcpl.cpl
[2012/07/11 06:04:24 | 000,818,688 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\jscript.dll
[2012/07/11 06:04:24 | 000,716,800 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysWow64\jscript.dll
[2012/07/11 05:56:12 | 000,002,048 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysWow64\msxml3r.dll
[2012/07/11 05:56:12 | 000,002,048 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\msxml3r.dll
[2012/07/11 05:55:57 | 000,307,200 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\ncrypt.dll
[2012/07/11 05:55:48 | 001,133,568 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\cdosys.dll
[2012/07/11 05:55:48 | 000,805,376 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysWow64\cdosys.dll
[2012/07/10 18:59:00 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{31492FF8-E7ED-4A77-BB9A-E9DBBC5DD560}
[2012/07/10 18:58:39 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{A1F0F47B-35BA-49D7-B3BF-E8021C0773E5}
[2012/07/10 06:26:18 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{0D5A58A6-4597-4598-8CBD-BD29BCCF3F2E}
[2012/07/10 06:25:56 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{1D981AB9-111E-418E-BFE5-D1AE5B842000}
[2012/07/09 18:24:57 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{ABB3A7CE-E804-4A10-9B3A-7F5AB06962C1}
[2012/07/09 18:24:33 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{7E111857-3D9B-4E39-B814-702FE047058B}
[2012/07/09 06:23:36 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{EED5E5AB-6D80-4861-8883-78AE6B39DDD3}
[2012/07/09 06:23:14 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{7E660141-CFE3-42EC-A2FA-D8A0E60AC2D0}
[2012/07/08 18:22:11 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{3B4C8DAE-9DE3-46E9-876B-2A3CC79B2F6C}
[2012/07/08 18:21:49 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{C44EA1D3-1F19-4403-AEDB-C22BD8FDB513}
[2012/07/08 06:19:29 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{7EE27FA6-B2DC-497E-9E6E-F751EAB956BB}
[2012/07/08 06:19:02 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{A83A6CA8-6D37-41DE-A70D-5C75AC52EE51}
[2012/07/07 15:51:35 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{8BE945D5-3E0D-4E03-A34A-A7A8FDDDB349}
[2012/07/07 15:51:02 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{3261F800-A2FA-4891-AB3D-5C78861F43BB}
[2012/07/07 05:48:26 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{6A498AC1-E11B-4497-8E27-7977C4BF3E2F}
[2012/07/06 17:18:09 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{36D9D348-281D-4931-BA74-BF97AECC8803}
[2012/07/06 17:17:40 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{4F4CC4EF-B03B-405C-AF12-F357ECC07CB2}
[2012/07/06 06:23:34 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{022F52A5-A2DF-4F8C-B32F-AE789598BC86}
[2012/07/05 17:37:34 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{4B6DF989-E67A-4BAE-A3B5-DF3F6914E4F5}
[2012/07/05 17:37:11 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{81CA895D-B46E-41AC-BA85-AB4D51BA29E4}
[2012/07/04 22:08:27 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{7F07EEC5-2861-4EB7-BE31-719D6E2260D6}
[2012/07/04 22:08:16 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{C91E45DF-1874-45F6-9CA9-9E8242357B6F}
[2012/07/04 17:26:21 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{965F5248-D96E-4D87-8888-76ED539A899B}
[2012/07/03 20:25:44 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{5B39F650-B109-44FE-84EF-4991496B1283}
[2012/07/03 20:25:22 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{E7823B6E-6BE3-4BA5-BD83-AD4BB2695144}
[2012/07/03 08:24:25 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{36E0CA8E-F6EF-47FB-B2E2-FFA96C171FC6}
[2012/07/03 08:24:03 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{E5446C28-14B9-4CCF-A09B-AED25292D7F4}
[2012/07/02 20:23:02 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{5967C27C-BD6B-412E-AD25-A8571E7F6089}
[2012/07/02 20:22:39 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{8701F7FC-6FB7-482F-9495-B73C1E834E77}
[2012/07/02 08:21:59 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{B0593EB0-F1C4-476E-A3ED-F396F96EF8C4}
[2012/07/02 08:21:38 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{5494C62E-D09A-4BB4-8C79-DDDC25A9849A}
[2012/07/01 20:20:40 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{4E21C335-F594-491A-9B0C-6A40C6B8E3F0}
[2012/07/01 20:20:18 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{DC303853-A8A9-4170-8ECB-4595ED9322F8}
[2012/07/01 08:19:23 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{618AB4B1-3DAF-4209-B9C8-263D700381C1}
[2012/07/01 08:19:02 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{F3C73D18-FE3E-4AF0-942A-1AE3A903BE23}
[2012/06/30 20:17:14 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{A0710D1F-1209-4CD5-811A-9D9EAEB4AF5E}
[2012/06/30 20:16:37 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{850F8AD1-C754-46D6-A9E2-AFA9F96C835B}
[2012/06/30 08:15:12 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{22768A20-770E-4FAD-A29C-1A366922C6B0}
[2012/06/30 08:14:50 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{33BBAF33-97FD-4271-A406-BB66C60EB731}
[2012/06/29 20:12:55 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{337C97E8-75D9-4D05-AFAE-5387D1015D69}
[2012/06/29 20:12:18 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{AF38A96C-7F3D-41F7-BB8D-BECEFC19B22F}
[2012/06/29 07:33:25 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{6F6D880B-87B2-469D-97AA-3C6C54050E42}
[2012/06/29 07:33:03 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{EFB9539C-BECF-4950-95BB-C82F5ABE0B3D}
[2012/06/28 19:32:10 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{14581703-DEE8-4FDB-8BB7-C8C5E1DEED1F}
[2012/06/28 19:31:48 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{3177E9EB-D3F0-4130-9DE4-5171BD7B6E92}
[2012/06/28 07:30:53 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{32C5C6DD-F581-47C0-AF51-823C60E3F7BC}
[2012/06/28 07:30:31 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{06DBDBE1-7B3A-4127-B8BF-B5A6BD19F8E9}
[2012/06/27 19:29:37 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{FEA39E52-DA8B-409D-A4B3-D981D93200DB}
[2012/06/27 19:29:16 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{C0B03C68-969B-4EEA-B0DD-D0D380CA1FC5}
[2012/06/27 07:28:21 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{990EAC21-FA23-446B-A39E-2C19D034EF97}
[2012/06/27 07:28:00 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{21E2773F-2713-44BD-98C5-621AE6CB8355}
[2012/06/26 19:27:24 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{3A4C149D-89DB-49A1-B400-C2BBB255E413}
[2012/06/26 19:27:14 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{0674556F-3D6C-4368-B841-74A67A975ADC}
[2012/06/26 19:27:04 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{AA3F889F-9B0C-41C0-84FD-DE7BD28445C3}
[2012/06/26 19:26:42 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{E3B5A438-C14A-4B8C-9B96-087DD327DF99}
[2012/06/26 07:25:57 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{FADDF3DC-EA7A-4BD1-9EBA-A74B1DA315C2}
[2012/06/26 07:25:47 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{D0CAEE5E-68F2-4036-9F99-8C2453A07E31}
[2012/06/26 07:25:38 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{4A3CCC4E-1B9D-4C4C-9570-873A1684107F}
[2012/06/26 07:25:16 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{C5CF9FD2-0D6F-4CDF-8049-448984081195}
[2012/06/25 19:23:22 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{439D8B6E-8EBB-4A44-A171-5DBE53754DC1}
[2012/06/25 19:23:00 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{C80FAFBC-30CE-4D8E-AC99-B3256AEBF0F0}
[2012/06/25 07:04:49 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{F27F8E72-748F-4C33-9552-4AD25D25CD5D}
[2012/06/25 07:04:39 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{DE090289-4AAA-4859-B00D-FAEAADC1E7D2}
[2012/06/25 07:04:30 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{F59C6A5D-4071-463C-8786-FF5FE2BB8994}
[2012/06/25 07:04:08 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{E54524B0-6739-4B5C-89D4-DED83DF91441}
[2012/06/24 19:02:04 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{1324D474-CA13-4000-99B1-E7AAE4A08A8D}
[2012/06/24 19:01:32 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{71EBA3BA-F864-40FB-963D-6F894B88E62C}
[2012/06/23 21:27:55 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{6072F511-6258-4F47-B3A2-423AC066FB20}
[2012/06/23 21:27:40 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{15B3612F-83FC-4C11-8E4E-67EADE3AFDDD}
[2012/06/23 19:31:21 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{9197B652-D615-407A-B19F-A1364708F5B7}
[2012/06/23 05:36:15 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\Macromedia
[2012/06/22 19:23:08 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{289D8416-4E4E-4BEE-866D-F70394BB9784}
[2012/06/22 19:22:45 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{28AF25D5-1924-467F-ACCD-9D290F235724}
[2012/06/22 07:21:36 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{C565D4AD-DC33-4F92-9990-02D67920F689}
[2012/06/22 07:21:13 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{41981685-E92A-4350-BF93-6728F57E2A76}
[2012/06/21 19:20:15 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{3A31124B-3E21-46D0-A567-F324F7C0069F}
[2012/06/21 19:19:53 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{6FDBF319-4B0C-42A8-9A07-50447E0088DB}
[2012/06/21 17:41:04 | 002,622,464 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\wucltux.dll
[2012/06/21 17:41:04 | 000,057,880 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\wuauclt.exe
[2012/06/21 17:41:04 | 000,044,056 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\wups2.dll
[2012/06/21 17:40:19 | 000,701,976 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\wuapi.dll
[2012/06/21 17:40:19 | 000,099,840 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\wudriver.dll
[2012/06/21 17:40:19 | 000,038,424 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\wups.dll
[2012/06/21 17:38:54 | 000,186,752 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\wuwebv.dll
[2012/06/21 17:38:54 | 000,036,864 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\SysNative\wuapp.exe
[2012/06/21 07:18:56 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{3AF03AC6-135D-4754-A1BC-F0C6620A0074}
[2012/06/21 07:18:35 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{DF77E8E1-DA96-4C0C-BC91-F427C52BE5F3}
[2012/06/20 19:17:37 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{0FF254E3-B968-43AB-9464-D195CF91D071}
[2012/06/20 19:17:15 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{B5505181-29FC-486B-AEDC-65636B0B5EB6}
[2012/06/20 07:16:22 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{BA1ABA83-0783-4DC2-B32A-1D180D5EF3F1}
[2012/06/20 07:16:00 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{D772FB6C-16E2-4D17-ABE3-7F7B781F081A}
[2012/06/19 19:13:42 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{811D1448-369D-4A61-B623-77813FE4C070}
[2012/06/19 19:13:06 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{A51B2802-EA7C-4342-B7A0-B036AC45CAEB}
[2012/06/19 06:46:03 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{FCA9B886-64BB-4B42-8D6C-BAE9576E336E}
[2012/06/19 06:45:41 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{423CB21B-463B-405C-B8BF-4B1D8CED2E5A}
[2012/06/18 18:45:05 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{46F3CC35-DDA3-4385-99BB-1B83DCC34058}
[2012/06/18 18:44:41 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{09636C01-4975-4558-98A6-87877BB7F7C4}
[2012/06/18 06:42:45 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{44531DC2-0CE9-45E9-8E77-9EBCE154D149}
[2012/06/18 06:42:23 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{8F0FB53F-CFF9-4F9B-ACEC-09FA74BBC5C6}
[2012/06/17 18:41:23 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{363C9C30-DFEC-47AB-8707-0390006DEE6D}
[2012/06/17 18:41:02 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{8A39767B-C1FE-4636-9311-828FA67579F0}
[2012/06/17 06:39:23 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{6912737D-DDC8-4FD7-AA45-715AB53C0CC0}
[2012/06/17 06:38:54 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{95F58310-9A10-453A-B521-7EF7121D26B5}
[2012/06/16 21:07:09 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{8BF2A819-4B76-4FA7-95F4-95047E83BB11}
[2012/06/16 09:06:01 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{89940275-5E73-4FCE-93D3-7D31A766B51C}
[2012/06/16 09:05:39 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{74E7ECC3-4EE4-4908-AFE6-0C7312228087}
[2012/06/15 21:02:18 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{1794FF5D-4661-4E1F-BA86-25995267DE4D}
[2012/06/15 21:01:35 | 000,000,000 | โ€”D | C] โ€“ C:\Users\DARLENE'S\AppData\Local\{1274C061-1BEF-424F-A1F2-BE428007678B}
[1 C:\Users\DARLENE'S\Documents\*.tmp files -> C:\Users\DARLENE'S\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/14 22:22:01 | 000,092,672 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/07/14 22:16:01 | 000,000,904 | โ€”- | M] () โ€“ C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/14 22:07:02 | 000,000,830 | โ€”- | M] () โ€“ C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/14 22:03:58 | 000,660,530 | โ€”- | M] () โ€“ C:\Windows\SysNative\perfh009.dat
[2012/07/14 22:03:58 | 000,121,426 | โ€”- | M] () โ€“ C:\Windows\SysNative\perfc009.dat
[2012/07/14 22:03:57 | 000,779,266 | โ€”- | M] () โ€“ C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/14 21:50:45 | 000,021,520 | โ€”- | M] () โ€“ C:\Windows\DCEBoot64.exe
[2012/07/14 21:50:45 | 000,003,700 | โ€”- | M] () โ€“ C:\Windows\DCEBOOT.CFG
[2012/07/14 21:49:31 | 000,009,920 | -Hโ€“ | M] () โ€“ C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/14 21:49:31 | 000,009,920 | -Hโ€“ | M] () โ€“ C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/14 21:41:43 | 000,000,900 | โ€”- | M] () โ€“ C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/14 21:40:46 | 000,067,584 | โ€“S- | M] () โ€“ C:\Windows\bootstat.dat
[2012/07/14 21:40:44 | 2962,309,120 | -HS- | M] () โ€“ C:\hiberfil.sys
[2012/07/14 21:40:42 | 000,004,288 | โ€”- | M] () โ€“ C:\Windows\DCEBOOT.RST
[2012/07/14 20:53:06 | 000,000,944 | โ€”- | M] () โ€“ C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-717187791-2577701650-807877497-1001UA.job
[2012/07/14 20:21:02 | 000,000,931 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\Desktop\NTREGOPT.lnk
[2012/07/14 20:21:02 | 000,000,912 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\Desktop\ERUNT.lnk
[2012/07/14 20:13:16 | 000,791,393 | โ€”- | M] (Lars Hederer ) โ€“ C:\Users\DARLENE'S\Desktop\erunt-setup.exe
[2012/07/14 17:53:00 | 000,000,922 | โ€”- | M] () โ€“ C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-717187791-2577701650-807877497-1001Core.job
[2012/07/14 06:03:54 | 004,731,392 | โ€”- | M] (AVAST Software) โ€“ C:\Users\DARLENE'S\Desktop\aswMBR.exe
[2012/07/13 06:04:37 | 000,129,024 | โ€”- | M] () โ€“ C:\Windows\RegBootClean64.exe
[2012/07/12 21:22:29 | 000,222,565 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\AppData\Local\census.cache
[2012/07/12 21:19:33 | 000,131,384 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\AppData\Local\ars.cache
[2012/07/12 20:39:08 | 000,000,036 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\AppData\Local\housecall.guid.cache
[2012/07/12 20:37:16 | 002,002,944 | โ€”- | M] (Trend Micro Inc.) โ€“ C:\Users\DARLENE'S\Desktop\HousecallLauncher.exe
[2012/07/12 19:21:01 | 000,625,664 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\Desktop\dds.scr
[2012/07/12 19:20:29 | 000,388,608 | โ€”- | M] (Trend Micro Inc.) โ€“ C:\Users\DARLENE'S\Desktop\HiJackThis.exe
[2012/07/12 19:20:11 | 000,596,480 | โ€”- | M] (OldTimer Tools) โ€“ C:\Users\DARLENE'S\Desktop\OTL.exe
[2012/07/12 17:39:13 | 000,102,400 | โ€”- | M] () โ€“ C:\Windows\RegBootClean.exe
[2012/07/11 20:07:22 | 000,426,184 | โ€”- | M] (Adobe Systems Incorporated) โ€“ C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/07/11 20:07:22 | 000,070,344 | โ€”- | M] (Adobe Systems Incorporated) โ€“ C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/07/11 17:26:55 | 000,440,536 | โ€”- | M] () โ€“ C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/08 06:18:48 | 000,000,366 | โ€”- | M] () โ€“ C:\Windows\tasks\Driver Fetch.job
[2012/06/23 06:14:21 | 000,000,824 | โ€”- | M] () โ€“ C:\Windows\SysNative\drivers\etc\tmvsthfud.bin
[2012/06/23 06:14:16 | 000,000,824 | โ€”- | M] () โ€“ C:\Windows\SysNative\drivers\etc\tmvsthfss.bin
[2012/06/18 18:35:28 | 000,002,012 | โ€”- | M] () โ€“ C:\Users\DARLENE'S\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk
[1 C:\Users\DARLENE'S\Documents\*.tmp files -> C:\Users\DARLENE'S\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/14 21:50:01 | 000,003,700 | โ€”- | C] () โ€“ C:\Windows\DCEBOOT.CFG
[2012/07/14 20:21:02 | 000,000,931 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\Desktop\NTREGOPT.lnk
[2012/07/14 20:21:02 | 000,000,912 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\Desktop\ERUNT.lnk
[2012/07/13 06:05:27 | 000,004,288 | โ€”- | C] () โ€“ C:\Windows\DCEBOOT.RST
[2012/07/12 21:22:29 | 000,222,565 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\AppData\Local\census.cache
[2012/07/12 21:19:33 | 000,131,384 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\AppData\Local\ars.cache
[2012/07/12 20:37:46 | 000,000,036 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\AppData\Local\housecall.guid.cache
[2012/07/12 19:36:29 | 000,021,520 | โ€”- | C] () โ€“ C:\Windows\DCEBoot64.exe
[2012/07/12 19:21:00 | 000,625,664 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\Desktop\dds.scr
[2012/07/12 07:42:35 | 000,129,024 | โ€”- | C] () โ€“ C:\Windows\RegBootClean64.exe
[2012/07/12 07:42:22 | 000,102,400 | โ€”- | C] () โ€“ C:\Windows\RegBootClean.exe
[2012/05/14 17:07:28 | 000,057,344 | โ€”- | C] () โ€“ C:\Windows\SysWow64\ff_vfw.dll
[2012/04/16 17:39:11 | 000,000,106 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\jobq.dat
[2012/03/08 21:13:01 | 000,732,592 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\01174842.one
[2012/01/01 14:11:07 | 000,028,993 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\AppData\Roaming\UserTile.png
[2011/08/28 08:10:45 | 000,000,027 | โ€”- | C] () โ€“ C:\Windows\BarCode.ini
[2011/05/13 06:36:38 | 000,773,482 | โ€”- | C] () โ€“ C:\Windows\SysWow64\PerfStringBackup.INI
[2011/01/16 12:50:52 | 000,029,234 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\Cal0000.htm
[2011/01/16 12:50:52 | 000,000,412 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\Cal0000.vcs
[2010/08/31 19:19:11 | 000,397,312 | โ€”- | C] () โ€“ C:\Windows\SysWow64\Snbd6w95.dll
[2010/08/31 19:19:11 | 000,072,704 | โ€”- | C] () โ€“ C:\Windows\SysWow64\XMain32A.dll
[2010/08/31 19:19:11 | 000,044,544 | โ€”- | C] () โ€“ C:\Windows\SysWow64\gif89.dll
[2010/08/31 19:18:42 | 000,000,357 | โ€”- | C] () โ€“ C:\Windows\Generations.INI
[2010/08/04 19:50:33 | 000,000,000 | โ€”- | C] () โ€“ C:\Windows\nsreg.dat
[2010/07/28 21:08:46 | 000,127,868 | โ€”- | C] () โ€“ C:\Windows\SysWow64\igcompkrng575.bin
[2010/07/28 21:08:44 | 000,104,796 | โ€”- | C] () โ€“ C:\Windows\SysWow64\igfcg575m.bin
[2010/03/31 21:31:45 | 000,007,666 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\AppData\Local\Resmon.ResmonCfg
[2010/03/29 20:48:20 | 000,092,672 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/28 18:43:19 | 000,002,370 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\AppData\Roaming\wklnhst.dat
[2010/03/28 17:00:37 | 000,000,355 | โ€”- | C] () โ€“ C:\Users\DARLENE'S\Computer - Shortcut.lnk

< End of report >


Looks like greek to meโ€ฆโ€ฆ

Thanks again!

Darlene
Jeff: I am going to run Combo Fix right now, but I have a few questions. We have verizon fios here and 2 pcs networked. Do these trojans\viruses travel thru the network from my laptop to the desktop pc? I'm concerned about this possibility. Is it smart to remove my laptop from the network while this is going on? also, sometimes my daughter comes over with her laptop and gets on the network, could her laptop get these infections from my laptop? Is her pc unsafe logging on here? If I need to remove my laptop from the network, I'll need to know how to do that. also, if I have to reinstall the OS - how do I get that? This laptop did not come with disks for that. When I bought this laptop, I made a back up disk that I labeled: "Repair Disk - Windows 7 64 bit" Not sure what this is, not sure if this will be of any help. I dated this disk 3-31-10 Thanks! Dar
Hi, I think that you will be alright as this infection I have not seen jump computers yet. The OTL log looked better for the main infection that was on your system. Please run ComboFix and post that new log. :)

Hi,

I think that you will be alright as this infection I have not seen jump computers yet. The OTL log looked better for the main infection that was on your system. Please run ComboFix and post that new log. :)


HI

I tried to run ComboFix this morning, I disabled Trend Micro, but when I tried to run Combo Fix, it said Trend was still running and that I could damage my computer so I stopped. I reinstated Trend and we went for a ride with the bike club. Great ride! About 200 miles round trip. Now back to THIS problem! I will try to disable Trend again and re run ComboFix - if it states I may damage my laptop, I will stop again and wait till I hear from you!!!!

thanks again!!!

thanks for the info on the network here. I will tell my hubby that he is safe to do any person stuff (banking) on his tower and my daughter is here, she wants to jump on too - so all is well in that department then, thanks goodness!!

will report back soon!

dar

Hi,

I think that you will be alright as this infection I have not seen jump computers yet. The OTL log looked better for the main infection that was on your system. Please run ComboFix and post that new log. :)


HI

I tried to run ComboFix this morning, I disabled Trend Micro, but when I tried to run Combo Fix, it said Trend was still running and that I could damage my computer so I stopped. I reinstated Trend and we went for a ride with the bike club. Great ride! About 200 miles round trip. Now back to THIS problem! I will try to disable Trend again and re run ComboFix - if it states I may damage my laptop, I will stop again and wait till I hear from you!!!!

thanks again!!!

thanks for the info on the network here. I will tell my hubby that he is safe to do any person stuff (banking) on his tower and my daughter is here, she wants to jump on too - so all is well in that department then, thanks goodness!!

will report back soon!

dar


OK - I disabled Trend Micro and tried to run Combo Fix - same error - I brought up Trend, disabled Real Time and tried again. Same thing. I even tried the HELP screen to find help - no luck. So I have not run Combo Fix as I'm scared I may damage my laptop like the warning box says.

Now what?

Dar

Hi,

Just go ahead and continue past the warning. It shouldn't cause any problems for it to run. :)


Good Morning!

I went to bed last night as combofix was still running. I woke up this morning and firefox and IE will not load - good thing I have my husbands tower up here!! I saved the text file on a thmb drive and here it is:

ComboFix 12-07-14.01 - DARLENE'S 07/15/2012 21:43:17.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3767.2387 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Trend Micro AntiVirus *Enabled/Updated* {68F968AC-2AA0-091D-848C-803E83E35902}
SP: Trend Micro AntiVirus *Enabled/Updated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\I Want This
c:\program files (x86)\I Want This\appAPIinternalWrapper.js
c:\program files (x86)\I Want This\fb.js
c:\program files (x86)\I Want This\I Want This.exe
c:\program files (x86)\I Want This\I Want This.ico
c:\program files (x86)\I Want This\I Want This.ini
c:\program files (x86)\I Want This\I Want ThisGui.exe
c:\program files (x86)\I Want This\I Want ThisInstaller.log
c:\program files (x86)\I Want This\jquery.js
c:\program files (x86)\I Want This\json.js
c:\program files (x86)\I Want This\Uninstall.exe
c:\program files (x86)\SelectRebates
c:\program files (x86)\SelectRebates\FFToolbar\chrome.manifest
c:\program files (x86)\SelectRebates\FFToolbar\chrome\sahtoolbar.jar
c:\program files (x86)\SelectRebates\FFToolbar\defaults\preferences\sahtoolbar.js
c:\program files (x86)\SelectRebates\FFToolbar\install.rdf
c:\program files (x86)\SelectRebates\SelectAlerts.dat
c:\program files (x86)\SelectRebates\SelectRebates.ini
c:\program files (x86)\SelectRebates\SelectRebatesA.dat
c:\program files (x86)\SelectRebates\SelectRebatesApi.exe
c:\program files (x86)\SelectRebates\SelectRebatesB.dat
c:\program files (x86)\SelectRebates\SelectRebatesBT.dat
c:\program files (x86)\SelectRebates\SelectRebatesUninstall.exe
c:\program files (x86)\SelectRebates\SRebates.dll
c:\program files (x86)\SelectRebates\SRFF3.dll
c:\program files (x86)\SelectRebates\Toolbar\AddtoList.bmp
c:\program files (x86)\SelectRebates\Toolbar\basis.xml
c:\program files (x86)\SelectRebates\Toolbar\Basis.xml.dym
c:\program files (x86)\SelectRebates\Toolbar\Blank.bmp
c:\program files (x86)\SelectRebates\Toolbar\CashBack.bmp
c:\program files (x86)\SelectRebates\Toolbar\Coupons.bmp
c:\program files (x86)\SelectRebates\Toolbar\GroceryCoupon.bmp
c:\program files (x86)\SelectRebates\Toolbar\i_magnifying.bmp
c:\program files (x86)\SelectRebates\Toolbar\icons.bmp
c:\program files (x86)\SelectRebates\Toolbar\logo.bmp
c:\program files (x86)\SelectRebates\Toolbar\logo_24.bmp
c:\program files (x86)\SelectRebates\Toolbar\logo_HotSpots.bmp
c:\program files (x86)\SelectRebates\Toolbar\ReviewSite.bmp
c:\program files (x86)\SelectRebates\Toolbar\RightControls.dym
c:\program files (x86)\SelectRebates\Toolbar\sahtb-alert.bmp
c:\program files (x86)\SelectRebates\Toolbar\sahtb-go.bmp
c:\program files (x86)\SelectRebates\Toolbar\sahtb-grocerycoupons.bmp
c:\program files (x86)\SelectRebates\Toolbar\sahtb-icons.bmp
c:\program files (x86)\SelectRebates\Toolbar\sahtb-restaurant.bmp
c:\program files (x86)\SelectRebates\Toolbar\sahtb-wishlist.bmp
c:\program files (x86)\SelectRebates\Toolbar\Scissors.bmp
c:\program files (x86)\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
c:\program files\Web Assistant\ExTEnsion32.dll
c:\users\DARLENE'S\AppData\Local\assembly\Applications\gqqpr.dll
c:\users\DARLENE'S\AppData\Local\assembly\tmp
c:\users\DARLENE'S\AppData\Local\I Want This
c:\users\DARLENE'S\AppData\Local\I Want This\Chrome\I Want This.crx
c:\users\DARLENE'S\AppData\Roaming\Microsoft\Windows\Recent\GWRRA PA District Home Page.url
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\.BackupManager\BackupManager.list
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome.manifest
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\.BackupManager\BackupManager.list
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\.BackupManager\BackupManager.list
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\background.html
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\browser.xul
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\crossrider.js
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\crossriderapi.js
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\dialog.js
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\lib\.BackupManager\BackupManager.list
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\lib\faye-browser-min.js
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\manage-apps-style.css
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\manage-apps.html
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\messaging.js
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\options.js
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\options.xul
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\push.html
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\search_dialog.xul
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\chrome\content\update.html
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\defaults\.BackupManager\BackupManager.list
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\defaults\preferences\.BackupManager\BackupManager.list
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\defaults\preferences\prefs.js
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\install.rdf
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\locale\.BackupManager\BackupManager.list
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\locale\en-US\.BackupManager\BackupManager.list
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\locale\en-US\translations.dtd
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\.BackupManager\BackupManager.list
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\button1.png
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\button2.png
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\button3.png
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\button4.png
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\button5.png
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\crossrider_statusbar.png
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\icon128.png
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\icon16.png
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\icon24.png
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\icon48.png
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\panelarrow-up.png
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\popup.css
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\popup.html
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\popup_binding.xml
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\skin.css
c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\extensions\[removed]\skin\update.css
c:\users\DARLENE'S\Documents\15E2D6A.tmp
c:\windows\security\Database\tmp.edb
.
Infected copy of c:\windows\system32\Services.exe was found and disinfected
Restored copy from - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-06-16 to 2012-07-16 )))))))))))))))))))))))))))))))
.
.
2012-07-16 01:58 . 2012-07-16 01:58 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\QUEEN OF THE ROAD\AppData\Local\temp
2012-07-16 01:58 . 2012-07-16 01:58 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Guest\AppData\Local\temp
2012-07-16 01:58 . 2012-07-16 01:58 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Default\AppData\Local\temp
2012-07-15 00:21 . 2012-07-15 00:21 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\ERUNT
2012-07-13 21:34 . 2012-07-13 21:34 โ€”โ€”โ€“ d-shโ€“w- c:\windows\SysWow64\%APPDATA%
2012-07-13 00:38 . 2012-06-05 07:37 256904 โ€”-a-w- c:\windows\SysWow64\drivers\tmcomm.sys
2012-07-12 23:36 . 2012-07-15 22:49 21520 โ€”-a-w- c:\windows\DCEBoot64.exe
2012-07-12 11:42 . 2012-07-13 10:04 129024 โ€”-a-w- c:\windows\RegBootClean64.exe
2012-07-12 11:42 . 2012-07-12 21:39 102400 โ€”-a-w- c:\windows\RegBootClean.exe
2012-07-11 10:12 . 2012-06-12 03:08 3148800 โ€”-a-w- c:\windows\system32\win32k.sys
2012-07-11 09:56 . 2012-06-06 06:06 2004480 โ€”-a-w- c:\windows\system32\msxml6.dll
2012-07-11 09:56 . 2012-06-06 06:06 1881600 โ€”-a-w- c:\windows\system32\msxml3.dll
2012-07-11 09:56 . 2012-06-06 05:05 1390080 โ€”-a-w- c:\windows\SysWow64\msxml6.dll
2012-07-11 09:56 . 2012-06-06 05:05 1236992 โ€”-a-w- c:\windows\SysWow64\msxml3.dll
2012-07-11 09:56 . 2010-06-26 03:55 2048 โ€”-a-w- c:\windows\system32\msxml3r.dll
2012-07-11 09:56 . 2010-06-26 03:24 2048 โ€”-a-w- c:\windows\SysWow64\msxml3r.dll
2012-06-23 09:36 . 2012-06-23 09:36 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\DARLENE'S\AppData\Local\Macromedia
2012-06-21 21:41 . 2012-06-02 22:19 2428952 โ€”-a-w- c:\windows\system32\wuaueng.dll
2012-06-21 21:41 . 2012-06-02 22:19 57880 โ€”-a-w- c:\windows\system32\wuauclt.exe
2012-06-21 21:41 . 2012-06-02 22:19 44056 โ€”-a-w- c:\windows\system32\wups2.dll
2012-06-21 21:41 . 2012-06-02 22:15 2622464 โ€”-a-w- c:\windows\system32\wucltux.dll
2012-06-21 21:40 . 2012-06-02 22:19 38424 โ€”-a-w- c:\windows\system32\wups.dll
2012-06-21 21:40 . 2012-06-02 22:19 701976 โ€”-a-w- c:\windows\system32\wuapi.dll
2012-06-21 21:40 . 2012-06-02 22:15 99840 โ€”-a-w- c:\windows\system32\wudriver.dll
2012-06-21 21:38 . 2012-06-02 19:19 186752 โ€”-a-w- c:\windows\system32\wuwebv.dll
2012-06-21 21:38 . 2012-06-02 19:15 36864 โ€”-a-w- c:\windows\system32\wuapp.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-15 12:29 . 2010-03-31 12:52 539984 โ€”-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2012-07-14 00:51 . 2010-03-28 22:27 737072 โ€”-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2012-07-14 00:50 . 2010-03-28 22:26 4283672 โ€”-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2012-07-14 00:50 . 2010-05-18 21:24 42776 โ€”-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2012-07-12 00:07 . 2012-05-28 10:48 426184 โ€”-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-12 00:07 . 2011-05-14 15:12 70344 โ€”-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-05 21:43 . 2010-04-09 13:51 737072 โ€”-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
2012-07-05 21:42 . 2010-04-09 13:51 4283672 โ€”-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2012-07-05 21:42 . 2010-06-03 09:36 42776 โ€”-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2012-06-09 01:42 . 2011-03-30 09:45 101400 โ€”-a-w- c:\windows\system32\drivers\RapportKE64.sys
2012-05-04 11:06 . 2012-06-12 21:38 5559664 โ€”-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 10:03 . 2012-06-12 21:38 3968368 โ€”-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03 . 2012-06-12 21:38 3913072 โ€”-a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40 . 2012-06-12 21:38 209920 โ€”-a-w- c:\windows\system32\profsvc.dll
2012-04-28 03:55 . 2012-06-12 21:38 210944 โ€”-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-26 05:41 . 2012-06-12 21:39 77312 โ€”-a-w- c:\windows\system32\rdpwsx.dll
2012-04-26 05:41 . 2012-06-12 21:39 149504 โ€”-a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-26 05:34 . 2012-06-12 21:39 9216 โ€”-a-w- c:\windows\system32\rdrmemptylst.exe
2012-04-24 05:37 . 2012-06-12 21:38 184320 โ€”-a-w- c:\windows\system32\cryptsvc.dll
2012-04-24 05:37 . 2012-06-12 21:38 140288 โ€”-a-w- c:\windows\system32\cryptnet.dll
2012-04-24 05:37 . 2012-06-12 21:38 1462272 โ€”-a-w- c:\windows\system32\crypt32.dll
2012-04-24 04:36 . 2012-06-12 21:38 140288 โ€”-a-w- c:\windows\SysWow64\cryptsvc.dll
2012-04-24 04:36 . 2012-06-12 21:38 1158656 โ€”-a-w- c:\windows\SysWow64\crypt32.dll
2012-04-24 04:36 . 2012-06-12 21:38 103936 โ€”-a-w- c:\windows\SysWow64\cryptnet.dll
2012-04-19 00:56 . 2012-04-19 00:56 94208 โ€”-a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2012-04-19 00:56 . 2012-04-19 00:56 69632 โ€”-a-w- c:\windows\SysWow64\QuickTime.qts
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn1\YTNavAssist.dll" [2011-01-21 213816]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 โ€”-a-w- c:\users\DARLENE'S\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 โ€”-a-w- c:\users\DARLENE'S\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 โ€”-a-w- c:\users\DARLENE'S\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IncrediMail"="c:\program files (x86)\IncrediMail\bin\IncMail.exe" [2012-06-18 366536]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-17 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2009-09-17 1157640]
"RemoteControl8"="c:\program files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" [2009-04-16 91432]
"PDVD8LanguageShortcut"="c:\program files (x86)\CyberLink\PowerDVD8\Language\Language.exe" [2009-04-16 50472]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]
"EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe" [2011-06-16 2922496]
.
c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Best Buy Software Installer.lnk - c:\program files\Best Buy Software Installer\Best Buy Software Installer.exe [2009-10-28 1132984]
.
c:\users\QUEEN OF THE ROAD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Best Buy Software Installer.lnk - c:\program files\Best Buy Software Installer\Best Buy Software Installer.exe [2009-10-28 1132984]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-29 136176]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-12 250056]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-29 136176]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-17 113120]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-02 225280]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-11-02 126352]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-31 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
S0 RapportKE64;RapportKE64;c:\windows\System32\Drivers\RapportKE64.sys [2012-06-09 101400]
S1 RapportCerberus_34302;RapportCerberus_34302;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_34302.sys [2012-06-18 397520]
S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2012-06-09 55096]
S1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2012-06-09 297048]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 ePowerSvc;Acer ePower Service;c:\program files\Gateway\Gateway Power Management\ePowerSvc.exe [2009-10-29 844320]
S2 Greg_Service;GRegService;c:\program files (x86)\Gateway\Registration\GregHSRW.exe [2009-08-28 1150496]
S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2009-07-14 27136]
S2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [2011-07-27 14952]
S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files (x86)\Kodak\AiO\Center\EKAiOHostService.exe [2011-12-19 394672]
S2 McciCMService64;McciCMService64;c:\program files\Common Files\Motive\McciCMService.exe [2010-03-17 517632]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe [2010-05-24 255744]
S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2012-06-09 976728]
S2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2011-07-12 42768]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2009-11-02 13784]
S2 UNS;Intelยฎ Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intelยฎ Management Engine Components\UNS\UNS.exe [2009-09-30 2320920]
S2 Updater Service;Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [2009-07-04 240160]
S2 WajamUpdater;WajamUpdater;c:\program files\Wajam\Updater\WajamUpdater.exe [2012-03-09 109064]
S2 Web Assistant Updater;Web Assistant Updater;c:\program files\Web Assistant\ExtensionUpdaterService.exe [2012-05-08 185856]
S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [2009-02-12 292864]
S3 HECIx64;Intelยฎ Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2009-10-26 151936]
S3 IntcDAud;Intelยฎ Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2009-10-29 244736]
S3 k57nd60a;Broadcom NetLink โ„ข Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2009-08-05 320040]
S3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2010-03-30 917768]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-28 00:07]
.
2012-07-15 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-717187791-2577701650-807877497-1001Core.job
- c:\users\DARLENE'S\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-08-31 21:48]
.
2012-07-16 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-717187791-2577701650-807877497-1001UA.job
- c:\users\DARLENE'S\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-08-31 21:48]
.
2012-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-29 02:22]
.
2012-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-29 02:22]
.
.
โ€”โ€”โ€” X64 Entries โ€”โ€”โ€”โ€“
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
2012-05-08 19:14 201728 โ€”-a-w- c:\program files\Web Assistant\Extension64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 โ€”-a-w- c:\users\DARLENE'S\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 โ€”-a-w- c:\users\DARLENE'S\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 โ€”-a-w- c:\users\DARLENE'S\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 โ€”-a-w- c:\users\DARLENE'S\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-10-13 186904]
"Acer ePower Management"="c:\program files\Gateway\Gateway Power Management\ePowerTray.exe" [2009-10-29 822816]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-20 8306208]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-03-30 1022368]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 161304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 415256]
"EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe" [2011-06-16 2922496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
โ€”โ€”- Supplementary Scan โ€”โ€”-
.
uStart Page = hxxp://mystart.incredimail.com/mb57?a=DgVbUgHIqP
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l;=0409&m;=nv79&r;=27360310n935l0454z105a4482y249
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Add; animation to IncrediMail Style Box - c:\program files (x86)\IncrediMail\bin\resources\WebMenuImg.htm
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
IE: Se&nd; to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1 [removed]
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB
FF - ProfilePath - c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://forums.whatthetech.com/index.php?act=UserCP&CODE;=26
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Be4dcb1dd-7e64-4ac9-a5b3-74f0e7ab7eb8%7Dโˆฃ=469dad1e907047d0b4bea113f0f38de2-99689a59add06bdedde022257a874a8682ddc4d9&ds;=od011&v;=11.0.0.9โŸจ=enโ‰บ=sa&d;=2012-05-15%2005%3A44%3A51&sap;=ku&q;=
FF - prefs.js: network.proxy.type - 0
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{06C7AD57-B655-418D-9AB8-9526A6D2E052} - (no file)
Wow6432Node-HKCU-Run-Applications - c:\users\DARLENE'S\AppData\Local\assembly\Applications\gqqpr.dll
Wow6432Node-HKLM-Run-Conime - c:\windows\system32\conime.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-DriverAccess - c:\program files (x86)\Driver Assure Corp\DriverAccess\DriverAccess.exe
AddRemove-I Want This - c:\program files (x86)\I Want This\Uninstall.exe
.
.
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” Other Running Processes โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
.
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Intel\Intelยฎ Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Common Files\Motive\McciCMService.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\Trusteer\Rapport\bin\RapportService.exe
.
**************************************************************************
.
Completion time: 2012-07-15 22:16:26 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-16 02:16
.
Pre-Run: 59,639,349,248 bytes free
Post-Run: 59,389,468,672 bytes free
.
- - End Of File - - 61DD7BC7C399AE743BFF2D0C0DEAE385


If my Firefox and IE are deleted now, how do I restore those?? I'm getting nervous now!

I work 8:30 am to 5:00 pm, so I won't be able to follow any further instructions until after dinner tonight. I sure hope my browsers can be restored!!

Have a great day!
Dar

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI