This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser redirecting and showing pop-up ads in corner [Solved]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thanks to my visiting cousin with less-than-stellar browsing habits, I've got a malware issue I can't seem to resolve in my browser. It is two-fold:

First, about 1 out of 5 times that I click on a link, I get redirected to another page that I didn't ask for.
Second, every 3rd page or so gives me an annoying pop-up ad in the lower right corner.

I've tried online solutions regarding clearing a hosts file, and I've run AdAware and MalwareBytes repeatedly but can't seem to resolve the issue.

I'm running Windows 7 64bit, and my browser of choice is Firefox, where I see both symptoms. I almost never use IE, but I have tested and the pop-ups are definitely occurring there as well.

I've run OTL and am pasting my log results below. I would GREATLY appreciate any help!

OTL logfile created on: 8/12/2012 8:31:15 AM - Run 1
OTL by OldTimer - Version 3.2.57.0 Folder = C:\_zipfiles
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.99 Gb Total Physical Memory | 4.43 Gb Available Physical Memory | 74.00% Memory free
11.98 Gb Paging File | 10.48 Gb Available in Paging File | 87.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 583.60 Gb Total Space | 287.44 Gb Free Space | 49.25% Space Free | Partition Type: NTFS
Drive D: | 12.47 Gb Total Space | 2.25 Gb Free Space | 18.05% Space Free | Partition Type: NTFS
Drive J: | 931.51 Gb Total Space | 341.38 Gb Free Space | 36.65% Space Free | Partition Type: NTFS
Drive K: | 298.02 Gb Total Space | 48.25 Gb Free Space | 16.19% Space Free | Partition Type: FAT32

Computer Name: HOTPOCKET | User Name: snadra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/08/12 08:29:54 | 000,596,992 | —- | M] (OldTimer Tools) – c:\_zipfiles\OTL.exe
PRC - [2012/08/12 08:29:54 | 000,596,992 | —- | M] (OldTimer Tools) – C:\_zipfiles\OTL.exe
PRC - [2012/08/12 08:29:54 | 000,596,992 | —- | M] (OldTimer Tools) – c:\_zipfiles\OTL.exe
PRC - [2012/08/05 20:27:42 | 000,913,888 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012/05/24 20:10:56 | 001,187,072 | —- | M] (Lavasoft Limited) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2012/05/24 20:10:55 | 002,152,720 | —- | M] (Lavasoft Limited) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2011/12/02 08:49:14 | 001,101,960 | —- | M] () – C:\Program Files (x86)\Lavasoft\Ad-Aware\AWSC.exe
PRC - [2009/12/01 20:49:52 | 000,210,216 | —- | M] (CyberLink) – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/10/20 14:50:34 | 000,128,296 | —- | M] (CyberLink Corp.) – c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
PRC - [2009/10/08 13:48:38 | 000,075,616 | —- | M] (AT&T) – C:\Program Files (x86)\AT&T Network Client\NetLogSvc.exe
PRC - [2009/10/08 13:48:30 | 000,452,448 | —- | M] (AT&T) – C:\Program Files (x86)\AT&T Network Client\netcfgsvr.exe
PRC - [2009/10/08 13:48:14 | 000,342,368 | —- | M] (AT&T) – C:\Program Files (x86)\AT&T Network Client\NetClientSvc.exe
PRC - [2009/03/16 03:47:28 | 000,122,880 | —- | M] () – C:\Windows\SysWOW64\WinMsgBalloonServer.exe
PRC - [2009/03/16 03:47:24 | 000,139,264 | —- | M] () – C:\Windows\SysWOW64\WinMsgBalloonClient.exe
PRC - [2009/03/16 03:47:22 | 000,122,880 | —- | M] (AMD) – C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
PRC - [2009/03/16 03:47:20 | 000,065,536 | —- | M] () – C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
PRC - [2008/11/20 13:47:28 | 000,062,768 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
PRC - [2008/09/30 21:59:26 | 000,192,512 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe
PRC - [2007/12/24 02:26:32 | 002,641,920 | —- | M] (pdfforge http://www.pdfforge.org/) – C:\Program Files (x86)\PDFCreator\PDFCreator.exe


========== Modules (No Company Name) ==========

MOD - [2012/08/05 20:27:42 | 002,003,424 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/09/27 08:23:00 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 08:22:40 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/07/26 19:28:33 | 006,271,648 | —- | M] () – C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2009/12/01 20:49:50 | 000,931,112 | —- | M] () – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
MOD - [2007/11/28 19:59:42 | 003,702,784 | —- | M] () – C:\Program Files (x86)\PDFCreator\GS8.61\gs8.61\Bin\gsdll32.dll


========== Win32 Services (SafeList) ==========

SRV - [2012/08/05 20:27:42 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/05/24 20:10:55 | 002,152,720 | —- | M] (Lavasoft Limited) [Auto | Running] – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/10/08 13:48:38 | 000,075,616 | —- | M] (AT&T) [On_Demand | Running] – C:\Program Files (x86)\AT&T Network Client\NetLogSvc.exe – (NetLogSvc)
SRV - [2009/10/08 13:48:30 | 000,452,448 | —- | M] (AT&T) [Auto | Running] – C:\Program Files (x86)\AT&T Network Client\netcfgsvr.exe – (netcfgsvr)
SRV - [2009/10/08 13:48:14 | 000,342,368 | —- | M] (AT&T) [Auto | Running] – C:\Program Files (x86)\AT&T Network Client\NetClientSvc.exe – (NetClientSvc)
SRV - [2009/06/10 17:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/03/16 03:47:22 | 000,122,880 | —- | M] (AMD) [Auto | Running] – C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe – (AMD_RAIDXpert)
SRV - [2008/09/30 21:59:26 | 000,192,512 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe – (HPBtnSrv)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/01 02:54:38 | 000,022,896 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/02/15 11:01:50 | 000,052,736 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/12/02 08:49:14 | 000,069,376 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\Lbd.sys – (Lbd)
DRV:64bit: - [2011/03/11 02:22:41 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 02:22:40 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/07/21 17:59:28 | 000,045,456 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\point64.sys – (Point64)
DRV:64bit: - [2010/07/07 19:18:58 | 000,051,600 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\dc3d.sys – (dc3d)
DRV:64bit: - [2009/10/08 13:30:24 | 000,221,184 | —- | M] (AT&T) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\agnfilt.sys – (agnfilt)
DRV:64bit: - [2009/10/08 13:30:24 | 000,014,848 | —- | M] (AT&T) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\avpnnic.sys – (avpnnic)
DRV:64bit: - [2009/08/20 20:05:06 | 000,239,616 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/07/31 07:10:58 | 000,237,936 | —- | M] (Advanced Micro Devices, Inc) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\ahcix64s.sys – (ahcix64s)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 20:39:20 | 000,023,040 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WSDPrint.sys – (WSDPrintDevice)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2009/05/11 07:49:20 | 000,081,952 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nvhda64v.sys – (NVHDA)
DRV:64bit: - [2009/05/08 16:08:00 | 000,020,520 | —- | M] (GARMIN Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\grmnusb.sys – (grmnusb)
DRV:64bit: - [2009/05/05 06:00:28 | 000,016,440 | —- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\AtiPcie.sys – (AtiPcie)
DRV:64bit: - [2009/04/03 09:39:58 | 000,034,872 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\usbfilter.sys – (usbfilter)
DRV:64bit: - [2009/03/02 15:12:18 | 000,011,576 | —- | M] (Samsung Electronics) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\SSPORT.SYS – (SSPORT)
DRV:64bit: - [2009/03/02 15:12:14 | 000,053,816 | —- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto | Stopped] – C:\Windows\SysNative\drivers\DGIVECP.SYS – (DgiVecp)
DRV:64bit: - [2008/02/22 00:10:36 | 000,196,992 | —- | M] (Omnivision Technologies, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\FilmScan.sys – (OV550I)
DRV - [2011/12/12 21:13:41 | 000,017,152 | —- | M] () [Kernel | On_Demand | Running] – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys – (Lavasoft Kernexplorer)
DRV - [2009/07/13 21:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {F7CDA56D-E1F1-47EE-B7FD-8C8E762763D5}
IE:64bit: - HKLM\..\SearchScopes\{4218CCD9-AB74-4ADD-BC94-D3C9E5E43A89}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
IE:64bit: - HKLM\..\SearchScopes\{F7CDA56D-E1F1-47EE-B7FD-8C8E762763D5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
IE - HKLM\..\SearchScopes,DefaultScope = {F7CDA56D-E1F1-47EE-B7FD-8C8E762763D5}
IE - HKLM\..\SearchScopes\{4218CCD9-AB74-4ADD-BC94-D3C9E5E43A89}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
IE - HKLM\..\SearchScopes\{F7CDA56D-E1F1-47EE-B7FD-8C8E762763D5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/?rlz=1V1IPYX
IE - HKCU\..\SearchScopes,DefaultScope = {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://www.google.com/search?ie=utf-8&…q={searchTerms}
IE - HKCU\..\SearchScopes\{4218CCD9-AB74-4ADD-BC94-D3C9E5E43A89}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
IE - HKCU\..\SearchScopes\{F7CDA56D-E1F1-47EE-B7FD-8C8E762763D5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:63050

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/08/05 20:27:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/06/19 20:14:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.0.11\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011/05/08 08:03:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.0.11\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/08/05 20:27:42 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/06/19 20:14:21 | 000,000,000 | —D | M]

[2012/03/26 18:51:37 | 000,000,000 | —D | M] (No name found) – C:\Users\snadra\AppData\Roaming\Mozilla\Extensions
[2010/05/24 19:17:05 | 000,000,000 | —D | M] (No name found) – C:\Users\snadra\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/05/03 18:16:25 | 000,000,000 | —D | M] (No name found) – C:\Users\snadra\AppData\Roaming\Mozilla\Firefox\Profiles\nwcw6jty.default\extensions
[2012/04/01 19:51:11 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/08/05 20:27:42 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/19 11:50:05 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/19 11:50:05 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/08/12 07:54:21 | 000,001,471 | RHS- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 216.240.133.193 www.google-analytics.com.
O1 - Hosts: 216.240.133.193 ad-emea.doubleclick.net.
O1 - Hosts: 216.240.133.193 www.statcounter.com.
O1 - Hosts: 69.72.252.254 www.google-analytics.com.
O1 - Hosts: 69.72.252.254 ad-emea.doubleclick.net.
O1 - Hosts: 69.72.252.254 www.statcounter.com.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Monitor.exe] File not found
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Recorder.exe] File not found
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW File not found
O4 - HKCU..\Run: [NetSP - restore settings on power failure] C:\Program Files (x86)\AT&T Network Client\NetSP.exe (AT&T)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Trusted sites)
O16 - DPF: {A4150320-98EC-4DB6-9BFB-EBF4B6FBEB16} http://192.168.2.155:155/codebase/DVM_IPCam2.ocx (DVM_IPCam2 Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F59C6D76-D012-4B2F-B424-08E5AB5CA7EE}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.I420 - File not found
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\Windows\SysWow64\scg726.acm (SHARP Corporation)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2009/11/08 18:34:53 | 000,454,656 | —- | C] (Simon Tatham) – C:\Program Files\putty.exe

========== Files - Modified Within 30 Days ==========

[2012/08/12 08:35:40 | 000,015,984 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/12 08:35:40 | 000,015,984 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/12 08:19:02 | 000,000,336 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForsnadra.job
[2012/08/12 08:19:01 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/08/12 08:18:45 | 530,493,439 | -HS- | M] () – C:\hiberfil.sys
[2012/08/09 20:11:47 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2012/08/09 20:11:47 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2012/08/08 21:37:12 | 000,726,444 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/08/08 21:37:12 | 000,624,162 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/08/08 21:37:12 | 000,106,538 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/08/05 12:30:37 | 000,001,106 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

========== Files Created - No Company Name ==========

[2012/03/31 17:32:03 | 000,000,126 | —- | C] () – C:\Windows\QUICKEN.INI
[2011/12/12 21:05:48 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/12/12 21:05:48 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/12/06 04:59:34 | 000,008,852 | -HS- | C] () – C:\Users\snadra\AppData\Local\x0ym23x1be4ukx
[2011/12/06 04:59:34 | 000,008,852 | -HS- | C] () – C:\ProgramData\x0ym23x1be4ukx
[2010/01/09 12:56:21 | 000,003,584 | —- | C] () – C:\Users\snadra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/10 18:38:09 | 000,000,600 | —- | C] () – C:\Users\snadra\AppData\Local\PUTTY.RND
[2009/11/08 18:15:10 | 000,000,112 | —- | C] () – C:\Users\snadra\AppData\Roaming\wklnhst.dat
[2009/10/08 13:30:18 | 000,217,942 | —- | C] () – C:\ProgramData\DeviceManager.xml.rc4

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2012/08/12 08:18:44 | 000,008,974 | —- | M] () – C:\aaw7boot.log
[2010/06/24 17:29:07 | 000,000,750 | —- | M] () – C:\FINIS_IT.TXT
[2012/08/12 08:18:45 | 530,493,439 | -HS- | M] () – C:\hiberfil.sys
[2006/12/02 02:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2012/08/12 08:18:45 | 2138,980,351 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/03/21 17:39:02 | 000,000,338 | -HS- | M] () – C:\Users\snadra\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >



OTL Extras logfile created on: 8/12/2012 8:31:16 AM - Run 1
OTL by OldTimer - Version 3.2.57.0 Folder = C:\_zipfiles
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.99 Gb Total Physical Memory | 4.43 Gb Available Physical Memory | 74.00% Memory free
11.98 Gb Paging File | 10.48 Gb Available in Paging File | 87.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 583.60 Gb Total Space | 287.44 Gb Free Space | 49.25% Space Free | Partition Type: NTFS
Drive D: | 12.47 Gb Total Space | 2.25 Gb Free Space | 18.05% Space Free | Partition Type: NTFS
Drive J: | 931.51 Gb Total Space | 341.38 Gb Free Space | 36.65% Space Free | Partition Type: NTFS
Drive K: | 298.02 Gb Total Space | 48.25 Gb Free Space | 16.19% Space Free | Partition Type: FAT32

Computer Name: HOTPOCKET | User Name: snadra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\PROGRA~2\AT&TNE~1\SwiApiMux.exe" = C:\PROGRA~2\AT&TNE~1\SwiApiMux.exe:*:Enabled:SwiApiMux – (Sierra Wireless, Inc.)
"C:\PROGRA~2\AT&TNE~1\SwiApiMux.exe" = C:\PROGRA~2\AT&TNE~1\SwiApiMux.exe:*:Enabled:SwiApiMux – (Sierra Wireless, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0077F71F-7483-4CFF-9C8B-03B547B94C8B}" = rport=138 | protocol=17 | dir=out | app=system |
"{089E60B7-B885-441F-801D-335EF5801F83}" = rport=10243 | protocol=6 | dir=out | app=system |
"{09700FB9-FAA9-4A07-947C-2BEF07F605CB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{133DDC6B-17C4-4B50-9148-39C4C5A14C14}" = lport=137 | protocol=17 | dir=in | app=system |
"{24046512-40A9-4117-A555-94946B823D7C}" = lport=10243 | protocol=6 | dir=in | app=system |
"{27E2FF77-497D-4317-A500-C8AC0F8FCA3A}" = rport=139 | protocol=6 | dir=out | app=system |
"{347889D0-87F2-4A2A-88B9-AB16A0DDD45D}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{3D5E0E6D-5009-43A6-B33B-D9D4B25AFACE}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{3D9F22A0-EB4C-4623-9B52-4BA5AFFA19AB}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3EA4A1A7-F421-46CC-BFB2-0972982D2C3C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{60D85F19-4AB0-4150-92BF-92FB5EBC552B}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{7E9C36CD-D0E9-474A-956E-5EFA818D27AF}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{92DD29CD-072E-4A8A-978C-EF82F8A21A03}" = lport=139 | protocol=6 | dir=in | app=system |
"{97E82D12-F5D7-4FC4-919E-88665F8928AF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A0303331-944A-426B-A662-D62B19BE4D22}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A142D746-5F7B-4E0C-9367-6FB8CBE134E8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B2BEE5B3-3A06-454A-B23D-4F1DAD73AA2B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{BF2DE77E-4306-4E27-B40B-2B04988059B5}" = rport=445 | protocol=6 | dir=out | app=system |
"{C19C99D5-1CEB-4583-B2AF-7C14625F18BD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C1D0964C-F100-4B4C-9942-363A4989B0CB}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C46203A7-FA97-4876-9FB1-766F4571232C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CECB9989-5FAA-465B-9182-B63F4941A750}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CFFF1543-EF4F-4DDA-9B56-64DA0561601A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D269CC01-0E60-4715-A27F-92C1F9ED3637}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{D7130756-0E7F-40EF-A332-1DE9D45417A4}" = lport=445 | protocol=6 | dir=in | app=system |
"{E595388A-903E-49D1-AD9D-ED45C6822988}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{E9AA42AC-D51F-44F0-AEF5-8C573D7ED585}" = lport=138 | protocol=17 | dir=in | app=system |
"{EB87C3B9-BB4E-4F27-839D-366379BFC6C7}" = rport=137 | protocol=17 | dir=out | app=system |
"{EECD5B79-87F9-4633-867E-B923951C63FE}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{EEFAEB49-0DA6-4799-A2F1-595A63CFF761}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{F03A5975-1B68-46DA-8B34-C959B03BFE2D}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03266655-8692-4DF1-ACB8-A97CA99C5283}" = protocol=17 | dir=in | app=c:\program files\hp\hp officejet pro 8500 a910\bin\hpnetworkcommunicator.exe |
"{0825F75C-4C0F-44D9-B32B-9E5A56B56D97}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{153AD6CD-0DF8-4A71-8BE7-6CBD57F0809E}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe |
"{17DEE7E4-AC05-4440-9992-217DE5920BB2}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{18B912D0-999D-443E-98E0-8010EB9ADA5C}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe |
"{190914AC-F7C6-4CBF-9E35-B5385931D274}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe |
"{1EA2F9B7-46F8-4F77-9576-88B696AF96EA}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{1FF57CE6-8F5B-4FE5-AE12-C64963B04638}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2CC01C43-0ECA-4E9D-AB43-EFBA8739DF75}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{48D304BA-E9FF-4079-BC46-933670B79DB4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{49CDE1C9-B635-4271-B368-72FDE8C80AF2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{4C59A6FB-683B-41A3-A5C8-E183FA952A59}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
"{4CC40A85-A752-41C4-9331-D48666FDDDF1}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe |
"{50738B81-8128-4EE8-8700-DFAD02801F8A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{59840B99-7309-4B00-A5D8-A6CCC7C50F8A}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
"{5A8534A2-D463-46AF-AE2B-A906B38E6304}" = protocol=17 | dir=in | app=c:\program files\wireless-g internet home monitoring camera\configuration.exe |
"{604A087A-9B01-4584-81C9-119090B5FC3F}" = protocol=6 | dir=in | app=c:\program files\hp\hp officejet pro 8500 a910\bin\devicesetup.exe |
"{715A878F-F72E-4BDE-AB36-CCC5ED93942D}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe |
"{788F65C2-0DF3-4096-9E57-8A932E9DF802}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
"{843D09B1-8200-4ACF-AAB9-BE1B97F6C421}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8E25C77D-63C0-4B66-BA9D-AB607EDA0E7C}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe |
"{9338CE0E-87B8-47EE-9CA2-5EB288AA3E55}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe |
"{99965A8B-59C7-4335-98EC-DD2344A3B51D}" = protocol=17 | dir=in | app=c:\program files\wireless-g internet home monitoring camera\configuration.exe |
"{9DFF3F8D-051F-49C7-86C0-856D9C08ABF3}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{9E727DFB-A6D2-4804-8A6B-DC4F912709C8}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A04C65EC-3FEA-40FF-AC82-E43D0C228AED}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A27A4868-55A8-43E2-A9D3-5AC48886AF8A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A59A8A75-CDD3-42A0-A9E3-7F964298E254}" = protocol=6 | dir=out | app=system |
"{A7607BC0-A7FE-4A44-B821-517155FAB42D}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe |
"{AC7C338E-83AE-46DE-B07C-BB54E237395A}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{AEE2EEF6-E62B-452B-95D9-61EF66BE7904}" = protocol=6 | dir=in | app=c:\program files\wireless-g internet home monitoring camera\configuration.exe |
"{AF93152F-DB20-4FC7-997B-D1123EEE1AB4}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{B00E8606-4697-4A63-9082-E1E6628BEBEE}" = protocol=17 | dir=in | app=c:\program files\hp\hp officejet pro 8500 a910\bin\devicesetup.exe |
"{B2C04DF4-AF77-4A67-9E4C-540B74877B54}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe |
"{BBE526C8-686E-4E62-B48A-A94C2CECB9DB}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{BC243FD8-4B59-46CF-9988-8B808748E473}" = protocol=6 | dir=in | app=c:\program files\hp\hp officejet pro 8500 a910\bin\hpnetworkcommunicator.exe |
"{BCEC6FBA-6905-49C6-B456-193F5AA801EA}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
"{C1CEB7BD-C17A-4ECC-A624-86693485FFB8}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe |
"{C73E3509-7E2D-4043-9305-ACEDA348947D}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{C9A27428-578E-47E8-98C4-2DE081F2E3A2}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{CB30EB66-2E83-4B90-9EE3-41559F10B8E4}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
"{CF98E356-F224-4E31-8AED-1FB195CECACE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D387DEC7-1B99-4F0B-BC79-C507A22CF177}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{D46A8E98-65FC-488E-AB27-47DBAD1F2BCE}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{D769540C-A651-48EA-A0A0-7CB7DDEDEC41}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{DA4B7EF0-42D8-4604-B284-8FF67A1920DC}" = protocol=6 | dir=in | app=c:\program files\wireless-g internet home monitoring camera\configuration.exe |
"{DBE2EA5E-5061-4F11-BC6A-D320284AE00C}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{DDE46BA6-9D03-4E3C-8EE1-6801436A9361}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E8A0E27D-B949-4A06-9184-C5BD1B30BB88}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{E8D38793-052A-44F3-A77A-DFACAE08D24C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{EDC5FA7D-A23C-4708-B836-F7BF7584F749}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
"{EEFE1A80-4997-4438-8D1A-8700439A82A5}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F3814D54-AC6A-4C09-BBDE-40052B80CF8F}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{F53B84B5-654E-46DE-B062-F3CDB96558D2}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{FC11E6B3-85CB-4BE9-A1A8-3C8873DAE6B4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{EEADA3CE-3F08-48B3-AF30-4BED924CD3B2}C:\windows\system32\ftp.exe" = protocol=6 | dir=in | app=c:\windows\system32\ftp.exe |
"TCP Query User{F6AB8215-93B7-4F80-B4FE-36881B9B6ADF}C:\windows\syswow64\ipcamera.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\ipcamera.exe |
"TCP Query User{F6C4E6D1-A4F4-4C16-B441-58B91AA7DEF8}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"UDP Query User{373B2DA4-0C3E-4F04-AA8F-E3FFCA058810}C:\windows\system32\ftp.exe" = protocol=17 | dir=in | app=c:\windows\system32\ftp.exe |
"UDP Query User{BCAC351A-C0D3-4C78-8921-E1B5A7ABF3B0}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"UDP Query User{D661D291-C500-4F18-B8A2-76F97DC56CF9}C:\windows\syswow64\ipcamera.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\ipcamera.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{26280024-DFB7-4967-90DB-7F9C6660D01E}" = HP MediaSmart SmartMenu
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{563F041C-DFDB-437B-A1E8-E141E0906076}" = Microsoft IntelliPoint 8.0
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{B75608B9-19B7-346D-2D8D-75A86E91F3E2}" = ATI Catalyst Install Manager
"{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}" = Apple Mobile Device Support
"{CF8FFD12-602B-422D-AF1D-511B411E7632}" = iTunes
"{EE7C94CC-BECB-4000-B5E3-D895307B9D5E}" = HP Officejet Pro 8500 A910 Basic Device Software
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{1261B07E-88EB-42ED-B356-3D921EE91D90}" = Canon Utilities Digital Photo Professional 1.6
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{16480125-0428-4097-9A2A-74464004D169}" = EOS Capture 1.3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{218BBBE3-FE63-4BB2-81A8-7435575A84FA}" = PhotoStitch
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java™ 7 Update 5
"{26E76762-7F20-4694-AD06-CC3A9B547A71}" = Microsoft Office Live Meeting 2007
"{28291BD5-92D2-4685-82DC-CCA925C53CCA}" = RemoteCapture Task 1.1
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes
"{33CF7CDF-9805-4500-9CC7-D19D52AD63C4}" = Canon Camera WIA Driver
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = PowerRecover
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5662C158-CA24-4228-BF6C-596FADA08682}" = Camera Support Core Library
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5FE545A1-D215-4216-9189-E7B39C9D1CC1}" = Quicken 2011
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{67431FA8-4B89-42DD-A68E-30D77F6C8D99}_is1" = HP Easy Backup
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77C84C38-E592-4A33-AB99-FA524120452F}" = Ad-Aware
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7B847C9D-6758-45E6-B598-3BD8F43EAE9E}" = Camera Window DS
"{82809116-D1EE-443C-AE31-F19E709DDF7A}" = AMD USB Filter Driver
"{862983D7-FA08-493E-A9ED-6B7859E069D3}" = Canon PhotoRecord
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{871B2A9D-0F12-44B3-88C1-E0CB10A232E4}" = HP Officejet Pro 8500 A910 Help
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B76B8E9-F773-4B75-A08C-120079EB765E}" = RAIDXpert
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-00D1-0409-0000-0000000FF1CE}" = Microsoft Office Access database engine 2007 (English)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A0F34E4E-25F0-4B68-AE8F-EF0C15CB1FED}" = RAW Image Task 2.0
"{A70D14C6-FF2C-4B8E-A643-7E74EC607614}" = Camera Window DVC
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.1
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{B60DCA15-56A3-4D2D-8747-22CF7D7B588B}" = HP Support Assistant
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}" = Canon ZoomBrowser EX
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C82185E8-C27B-4EF4-2009-4444BC2C2B6D}" = Microsoft Streets & Trips 2009
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{E73534D5-CC93-4C63-9072-5A9734255C74}" = Camera Window MC
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3B912F5-EB57-45AA-B3D1-EB532BCF6EF8}" = HP Setup
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Crimson Editor SVN286" = Crimson Editor SVN286
"FileZilla Client" = FileZilla Client [removed]
"InstallShield_{1261B07E-88EB-42ED-B356-3D921EE91D90}" = Canon Utilities Digital Photo Professional 1.6
"InstallShield_{16480125-0428-4097-9A2A-74464004D169}" = Canon Utilities EOS Capture 1.3
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{218BBBE3-FE63-4BB2-81A8-7435575A84FA}" = Canon Utilities PhotoStitch 3.1
"InstallShield_{28291BD5-92D2-4685-82DC-CCA925C53CCA}" = Canon RemoteCapture Task for ZoomBrowser EX
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes
"InstallShield_{33CF7CDF-9805-4500-9CC7-D19D52AD63C4}" = Canon EOS Kiss_N REBEL_XT 350D WIA Driver
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{5662C158-CA24-4228-BF6C-596FADA08682}" = Canon Camera Support Core Library
"InstallShield_{7B847C9D-6758-45E6-B598-3BD8F43EAE9E}" = Canon Camera Window DS for ZoomBrowser EX
"InstallShield_{8B76B8E9-F773-4B75-A08C-120079EB765E}" = RAIDXpert
"InstallShield_{A0F34E4E-25F0-4B68-AE8F-EF0C15CB1FED}" = Canon RAW Image Task for ZoomBrowser EX
"InstallShield_{A70D14C6-FF2C-4B8E-A643-7E74EC607614}" = Canon Camera Window DVC for ZoomBrowser EX
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{E73534D5-CC93-4C63-9072-5A9734255C74}" = Canon Camera Window for ZoomBrowser EX
"IP Camera" = IP Camera
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"Mozilla Firefox 14.0.1 (x86 en-US)" = Mozilla Firefox 14.0.1 (x86 en-US)
"Mozilla Thunderbird (3.0.11)" = Mozilla Thunderbird (3.0.11)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Paint Shop Pro 5.01" = Paint Shop Pro 5.01
"Samsung SCX-4100 Series" = Samsung SCX-4100 Series
"WildTangent hp Master Uninstall" = HP Games

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/7/2012 2:09:33 AM | Computer Name = hotpocket | Source = Windows Backup | ID = 4104
Description =

Error - 6/8/2012 2:09:40 AM | Computer Name = hotpocket | Source = Windows Backup | ID = 4104
Description =

Error - 6/9/2012 2:10:59 AM | Computer Name = hotpocket | Source = Windows Backup | ID = 4104
Description =

Error - 6/10/2012 2:09:44 AM | Computer Name = hotpocket | Source = Windows Backup | ID = 4104
Description =

Error - 6/11/2012 2:10:20 AM | Computer Name = hotpocket | Source = Windows Backup | ID = 4104
Description =

Error - 6/12/2012 2:10:52 AM | Computer Name = hotpocket | Source = Windows Backup | ID = 4104
Description =

Error - 6/13/2012 2:12:21 AM | Computer Name = hotpocket | Source = Windows Backup | ID = 4104
Description =

Error - 6/14/2012 2:10:44 AM | Computer Name = hotpocket | Source = Windows Backup | ID = 4104
Description =

Error - 6/15/2012 2:11:51 AM | Computer Name = hotpocket | Source = Windows Backup | ID = 4104
Description =

Error - 6/16/2012 2:11:03 AM | Computer Name = hotpocket | Source = Windows Backup | ID = 4104
Description =

Error - 6/17/2012 2:11:36 AM | Computer Name = hotpocket | Source = Windows Backup | ID = 4104
Description =

[ Hewlett-Packard Events ]
Error - 7/15/2010 6:00:58 PM | Computer Name = hotpocket | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

Error - 10/9/2010 7:13:14 PM | Computer Name = hotpocket | Source = Hewlett-Packard | ID = 0
Description = en-US Object reference not set to an instance of an object. HPSF at
HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender, RoutedEventArgs
e) at System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object target, RoutedEventArgs
routedEventArgs) at System.Windows.EventRoute.InvokeHandlersImpl(Object source,
RoutedEventArgs args, Boolean reRaised) at System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) at System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) at System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) at System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) at MS.Internal.LoadedOrUnloadedOperation.DoWork() at System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()

at System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() at System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) at System.Windows.Media.MediaContext.RenderMessageHandler(Object
resizedCompositionTarget) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)


Error - 9/22/2011 7:02:24 PM | Computer Name = hotpocket | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

Error - 11/9/2011 8:18:15 PM | Computer Name = hotpocket | Source = Hewlett-Packard | ID = 0
Description = en-US Object reference not set to an instance of an object. HPSF at
HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender, RoutedEventArgs
e) at System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object target, RoutedEventArgs
routedEventArgs) at System.Windows.EventRoute.InvokeHandlersImpl(Object source,
RoutedEventArgs args, Boolean reRaised) at System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) at System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) at System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) at System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) at MS.Internal.LoadedOrUnloadedOperation.DoWork() at System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()

at System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() at System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) at System.Windows.Media.MediaContext.RenderMessageHandler(Object
resizedCompositionTarget) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)


[ System Events ]
Error - 8/10/2011 3:36:43 AM | Computer Name = hotpocket | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%20

Error - 8/26/2011 7:38:33 PM | Computer Name = hotpocket | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:45:50 AM on ?8/?26/?2011 was unexpected.

Error - 8/26/2011 7:39:05 PM | Computer Name = hotpocket | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%20

Error - 8/26/2011 7:40:13 PM | Computer Name = hotpocket | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Presentation Foundation Font Cache 3.0.0.0 service to connect.

Error - 8/26/2011 7:40:13 PM | Computer Name = hotpocket | Source = Service Control Manager | ID = 7000
Description = The Windows Presentation Foundation Font Cache 3.0.0.0 service failed
to start due to the following error: %%1053

Error - 9/6/2011 6:46:10 AM | Computer Name = hotpocket | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk6\DR7.

Error - 9/6/2011 6:46:12 AM | Computer Name = hotpocket | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk6\DR7.

Error - 9/6/2011 5:44:34 PM | Computer Name = hotpocket | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk6\DR8.

Error - 9/6/2011 5:44:34 PM | Computer Name = hotpocket | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk6\DR8.

Error - 9/6/2011 5:44:35 PM | Computer Name = hotpocket | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk6\DR8.


< End of report >
Hi snadra, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it. If asked to download Avast's database please do so.

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.
Thanks for the prompt reply and offer to help, oldman960! I tried to attach the MBR.dat file but am getting an error from the forum saying "Upload failed. You are not permitted to upload this type of file." Here are the contents of my log: aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-08-12 15:53:58 —————————– 15:53:58.835 OS Version: Windows x64 6.1.7600 15:53:58.835 Number of processors: 4 586 0x502 15:53:58.836 ComputerName: HOTPOCKET UserName: snadra 15:54:00.485 Initialize success 15:55:04.641 AVAST engine defs: 12081200 15:55:30.978 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000054 15:55:30.983 Disk 0 Vendor: Hitachi_ STDO Size: 610480MB BusType: 8 15:55:30.994 Disk 0 MBR read successfully 15:55:30.999 Disk 0 MBR scan 15:55:31.007 Disk 0 unknown MBR code 15:55:31.018 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 15:55:31.035 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 597606 MB offset 206848 15:55:31.075 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 12772 MB offset 1224103936 15:55:31.266 Disk 0 scanning C:\Windows\system32\drivers 15:55:40.002 Service scanning 15:56:03.210 Modules scanning 15:56:03.210 Disk 0 trace - called modules: 15:56:03.221 ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll ahcix64s.sys 15:56:03.547 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80066cf060] 15:56:03.547 3 CLASSPNP.SYS[fffff880011b643f] -> nt!IofCallDriver -> \Device\00000054[0xfffffa80062599c0] 15:56:06.301 AVAST engine scan C:\Windows 15:56:08.942 AVAST engine scan C:\Windows\system32 15:58:47.002 AVAST engine scan C:\Windows\system32\drivers 15:58:59.159 AVAST engine scan C:\Users\snadra 16:01:54.930 Disk 0 MBR has been saved successfully to "C:\_zipfiles\MBR.dat" 16:01:54.938 The log file has been saved successfully to "C:\_zipfiles\aswMBR.txt"
Wow, this is not my day… I thought the scan had finished when I pulled the logs because it stopped updating messages, but then I just saw the "Scan Finished Successfully" message appear! New .dat (zipped) attached, and log file contents here: aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-08-12 15:53:58 —————————– 15:53:58.835 OS Version: Windows x64 6.1.7600 15:53:58.835 Number of processors: 4 586 0x502 15:53:58.836 ComputerName: HOTPOCKET UserName: snadra 15:54:00.485 Initialize success 15:55:04.641 AVAST engine defs: 12081200 15:55:30.978 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000054 15:55:30.983 Disk 0 Vendor: Hitachi_ STDO Size: 610480MB BusType: 8 15:55:30.994 Disk 0 MBR read successfully 15:55:30.999 Disk 0 MBR scan 15:55:31.007 Disk 0 unknown MBR code 15:55:31.018 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 15:55:31.035 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 597606 MB offset 206848 15:55:31.075 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 12772 MB offset 1224103936 15:55:31.266 Disk 0 scanning C:\Windows\system32\drivers 15:55:40.002 Service scanning 15:56:03.210 Modules scanning 15:56:03.210 Disk 0 trace - called modules: 15:56:03.221 ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll ahcix64s.sys 15:56:03.547 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80066cf060] 15:56:03.547 3 CLASSPNP.SYS[fffff880011b643f] -> nt!IofCallDriver -> \Device\00000054[0xfffffa80062599c0] 15:56:06.301 AVAST engine scan C:\Windows 15:56:08.942 AVAST engine scan C:\Windows\system32 15:58:47.002 AVAST engine scan C:\Windows\system32\drivers 15:58:59.159 AVAST engine scan C:\Users\snadra 16:01:54.930 Disk 0 MBR has been saved successfully to "C:\_zipfiles\MBR.dat" 16:01:54.938 The log file has been saved successfully to "C:\_zipfiles\aswMBR.txt" 16:06:53.073 AVAST engine scan C:\ProgramData 16:08:02.043 Scan finished successfully 16:08:21.715 Disk 0 MBR has been saved successfully to "C:\_zipfiles\MBR.dat" 16:08:21.720 The log file has been saved successfully to "C:\_zipfiles\aswMBR.txt"

Attachments:

Hi snadra,

Good job. Let's see if we can clean up the Hosts file with OTL. If it doesn't work don't worry we have other ways of doing it.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O1 - Hosts: 216.240.133.193 www.google-analytics.com.
O1 - Hosts: 216.240.133.193 ad-emea.doubleclick.net.
O1 - Hosts: 216.240.133.193 www.statcounter.com.
O1 - Hosts: 69.72.252.254 www.google-analytics.com.
O1 - Hosts: 69.72.252.254 ad-emea.doubleclick.net.
O1 - Hosts: 69.72.252.254 www.statcounter.com.
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:63050

:Files
ipconfig /flushdns /c

:Commands
[resethosts]
[emptytemp]
[createrestorepoint]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

Try a couple of searchs. Still redirected?
Thanks for the help. I've run the specified code with OTL. My log results are below. I did a few quick searches and didn't see any redirecting, but I have to rush off to work now, so I'll check more when I get home. Thanks again!




All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
216.240.133.193 www.google-analytics.com. removed from HOSTS file successfully
216.240.133.193 ad-emea.doubleclick.net. removed from HOSTS file successfully
216.240.133.193 www.statcounter.com. removed from HOSTS file successfully
69.72.252.254 www.google-analytics.com. removed from HOSTS file successfully
69.72.252.254 ad-emea.doubleclick.net. removed from HOSTS file successfully
69.72.252.254 www.statcounter.com. removed from HOSTS file successfully
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\_zipfiles\cmd.bat deleted successfully.
C:\_zipfiles\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: snadra
->Temp folder emptied: 63838188 bytes
->Temporary Internet Files folder emptied: 71980511 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 121481022 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 2020 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 142760 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 2427886711 bytes

Total Files Cleaned = 2,561.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.57.0 log created on 08132012_064812

Files\Folders moved on Reboot…
C:\Users\snadra\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Windows\temp\hsperfdata_HOTPOCKET$\1476 not found!

PendingFileRenameOperations files…
File C:\Users\snadra\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!
File C:\Windows\temp\hsperfdata_HOTPOCKET$\1476 not found!

Registry entries deleted on Reboot…
Hi snadra,

You are more than welcome.

Let's do a couple of more scans. You can also try some more searches as it looks as we may have gotten it.

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Next

As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.

Next

Open OTL and click the Quick Scan button. When it's finished only an OTL.txt will open this time. Please post it.

Please post back with
  • MBAM log
  • ESET log if there is one
  • OTL.txt
Any problems?
The problem appears to be fixed… I've done quite a bit of browsing today and haven't encountered either the redirect or the pop-up. Woohoo!

While trying to fix this myself previously, I had looked in the hosts file in the drivers/etc directory, but it was clean. Looking back at the logs, though, it looks like my computer was using one in a different location. Out of curiosity, how'd they manage that? Registry entries?

The ESET scan was clean. MBAM and OTL scans were too, and the logs are pasted below. I think we're good to go… This was driving me crazy, and I'm really glad I found you guys. Thanks again!


Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.14.07

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
snadra :: HOTPOCKET [administrator]

8/14/2012 7:18:11 PM
mbam-log-2012-08-14 (19-18-11).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 193266
Time elapsed: 1 minute(s), 58 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


OTL logfile created on: 8/14/2012 8:24:24 PM - Run 2
OTL by OldTimer - Version 3.2.57.0 Folder = C:\_zipfiles
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.99 Gb Total Physical Memory | 3.80 Gb Available Physical Memory | 63.48% Memory free
11.98 Gb Paging File | 10.00 Gb Available in Paging File | 83.49% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 583.60 Gb Total Space | 283.76 Gb Free Space | 48.62% Space Free | Partition Type: NTFS
Drive D: | 12.47 Gb Total Space | 2.25 Gb Free Space | 18.05% Space Free | Partition Type: NTFS
Drive J: | 931.51 Gb Total Space | 339.36 Gb Free Space | 36.43% Space Free | Partition Type: NTFS
Drive K: | 298.02 Gb Total Space | 48.25 Gb Free Space | 16.19% Space Free | Partition Type: FAT32

Computer Name: HOTPOCKET | User Name: snadra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/08/12 08:29:54 | 000,596,992 | —- | M] (OldTimer Tools) – C:\_zipfiles\OTL.exe
PRC - [2012/08/05 20:27:42 | 000,913,888 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012/07/03 13:46:42 | 000,973,488 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2011/09/30 09:28:06 | 000,884,304 | —- | M] () – C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
PRC - [2009/12/01 20:49:52 | 000,210,216 | —- | M] (CyberLink) – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/10/20 14:50:34 | 000,128,296 | —- | M] (CyberLink Corp.) – c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
PRC - [2009/10/08 13:48:38 | 000,075,616 | —- | M] (AT&T) – C:\Program Files (x86)\AT&T Network Client\NetLogSvc.exe
PRC - [2009/10/08 13:48:30 | 000,452,448 | —- | M] (AT&T) – C:\Program Files (x86)\AT&T Network Client\netcfgsvr.exe
PRC - [2009/10/08 13:48:14 | 000,342,368 | —- | M] (AT&T) – C:\Program Files (x86)\AT&T Network Client\NetClientSvc.exe
PRC - [2009/07/17 23:12:12 | 000,257,440 | R— | M] (Adobe Systems, Inc.) – C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10c.exe
PRC - [2009/03/16 03:47:28 | 000,122,880 | —- | M] () – C:\Windows\SysWOW64\WinMsgBalloonServer.exe
PRC - [2009/03/16 03:47:24 | 000,139,264 | —- | M] () – C:\Windows\SysWOW64\WinMsgBalloonClient.exe
PRC - [2009/03/16 03:47:22 | 000,122,880 | —- | M] (AMD) – C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
PRC - [2009/03/16 03:47:20 | 000,065,536 | —- | M] () – C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
PRC - [2008/11/20 13:47:28 | 000,062,768 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
PRC - [2008/09/30 21:59:26 | 000,192,512 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe
PRC - [2007/12/24 02:26:32 | 002,641,920 | —- | M] (pdfforge http://www.pdfforge.org/) – C:\Program Files (x86)\PDFCreator\PDFCreator.exe


========== Modules (No Company Name) ==========

MOD - [2012/08/05 20:27:42 | 002,003,424 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/09/30 09:28:06 | 000,884,304 | —- | M] () – C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
MOD - [2011/09/27 08:23:00 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 08:22:40 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/07/26 19:28:33 | 006,271,648 | —- | M] () – C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2009/12/01 20:49:50 | 000,931,112 | —- | M] () – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
MOD - [2007/11/28 19:59:42 | 003,702,784 | —- | M] () – C:\Program Files (x86)\PDFCreator\GS8.61\gs8.61\Bin\gsdll32.dll


========== Win32 Services (SafeList) ==========

SRV - [2012/08/05 20:27:42 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/05/24 20:10:55 | 002,152,720 | —- | M] (Lavasoft Limited) [Auto | Stopped] – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/10/08 13:48:38 | 000,075,616 | —- | M] (AT&T) [On_Demand | Running] – C:\Program Files (x86)\AT&T Network Client\NetLogSvc.exe – (NetLogSvc)
SRV - [2009/10/08 13:48:30 | 000,452,448 | —- | M] (AT&T) [Auto | Running] – C:\Program Files (x86)\AT&T Network Client\netcfgsvr.exe – (netcfgsvr)
SRV - [2009/10/08 13:48:14 | 000,342,368 | —- | M] (AT&T) [Auto | Running] – C:\Program Files (x86)\AT&T Network Client\NetClientSvc.exe – (NetClientSvc)
SRV - [2009/06/10 17:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/03/16 03:47:22 | 000,122,880 | —- | M] (AMD) [Auto | Running] – C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe – (AMD_RAIDXpert)
SRV - [2008/09/30 21:59:26 | 000,192,512 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe – (HPBtnSrv)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/01 02:54:38 | 000,022,896 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/02/15 11:01:50 | 000,052,736 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/12/02 08:49:14 | 000,069,376 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\Lbd.sys – (Lbd)
DRV:64bit: - [2011/03/11 02:22:41 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 02:22:40 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/07/21 17:59:28 | 000,045,456 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\point64.sys – (Point64)
DRV:64bit: - [2010/07/07 19:18:58 | 000,051,600 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\dc3d.sys – (dc3d)
DRV:64bit: - [2009/10/08 13:30:24 | 000,221,184 | —- | M] (AT&T) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\agnfilt.sys – (agnfilt)
DRV:64bit: - [2009/10/08 13:30:24 | 000,014,848 | —- | M] (AT&T) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\avpnnic.sys – (avpnnic)
DRV:64bit: - [2009/08/20 20:05:06 | 000,239,616 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/07/31 07:10:58 | 000,237,936 | —- | M] (Advanced Micro Devices, Inc) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\ahcix64s.sys – (ahcix64s)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 20:39:20 | 000,023,040 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WSDPrint.sys – (WSDPrintDevice)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2009/05/11 07:49:20 | 000,081,952 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nvhda64v.sys – (NVHDA)
DRV:64bit: - [2009/05/08 16:08:00 | 000,020,520 | —- | M] (GARMIN Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\grmnusb.sys – (grmnusb)
DRV:64bit: - [2009/05/05 06:00:28 | 000,016,440 | —- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\AtiPcie.sys – (AtiPcie)
DRV:64bit: - [2009/04/03 09:39:58 | 000,034,872 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\usbfilter.sys – (usbfilter)
DRV:64bit: - [2009/03/02 15:12:18 | 000,011,576 | —- | M] (Samsung Electronics) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\SSPORT.SYS – (SSPORT)
DRV:64bit: - [2009/03/02 15:12:14 | 000,053,816 | —- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto | Stopped] – C:\Windows\SysNative\drivers\DGIVECP.SYS – (DgiVecp)
DRV:64bit: - [2008/02/22 00:10:36 | 000,196,992 | —- | M] (Omnivision Technologies, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\FilmScan.sys – (OV550I)
DRV - [2011/12/12 21:13:41 | 000,017,152 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys – (Lavasoft Kernexplorer)
DRV - [2009/07/13 21:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {F7CDA56D-E1F1-47EE-B7FD-8C8E762763D5}
IE:64bit: - HKLM\..\SearchScopes\{4218CCD9-AB74-4ADD-BC94-D3C9E5E43A89}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
IE:64bit: - HKLM\..\SearchScopes\{F7CDA56D-E1F1-47EE-B7FD-8C8E762763D5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
IE - HKLM\..\SearchScopes,DefaultScope = {F7CDA56D-E1F1-47EE-B7FD-8C8E762763D5}
IE - HKLM\..\SearchScopes\{4218CCD9-AB74-4ADD-BC94-D3C9E5E43A89}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
IE - HKLM\..\SearchScopes\{F7CDA56D-E1F1-47EE-B7FD-8C8E762763D5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/?rlz=1V1IPYX
IE - HKCU\..\SearchScopes,DefaultScope = {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://www.google.com/search?ie=utf-8&…q={searchTerms}
IE - HKCU\..\SearchScopes\{4218CCD9-AB74-4ADD-BC94-D3C9E5E43A89}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
IE - HKCU\..\SearchScopes\{F7CDA56D-E1F1-47EE-B7FD-8C8E762763D5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/08/05 20:27:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/06/19 20:14:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.0.11\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011/05/08 08:03:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.0.11\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/08/05 20:27:42 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/06/19 20:14:21 | 000,000,000 | —D | M]

[2012/03/26 18:51:37 | 000,000,000 | —D | M] (No name found) – C:\Users\snadra\AppData\Roaming\Mozilla\Extensions
[2010/05/24 19:17:05 | 000,000,000 | —D | M] (No name found) – C:\Users\snadra\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/05/03 18:16:25 | 000,000,000 | —D | M] (No name found) – C:\Users\snadra\AppData\Roaming\Mozilla\Firefox\Profiles\nwcw6jty.default\extensions
[2012/04/01 19:51:11 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/08/05 20:27:42 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/19 11:50:05 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/19 11:50:05 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/08/13 06:48:12 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Monitor.exe] File not found
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Recorder.exe] File not found
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW File not found
O4 - HKCU..\Run: [NetSP - restore settings on power failure] C:\Program Files (x86)\AT&T Network Client\NetSP.exe (AT&T)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Trusted sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {A4150320-98EC-4DB6-9BFB-EBF4B6FBEB16} http://192.168.2.155:155/codebase/DVM_IPCam2.ocx (DVM_IPCam2 Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F59C6D76-D012-4B2F-B424-08E5AB5CA7EE}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/08/14 19:28:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/08/14 19:27:54 | 000,000,000 | -H-D | C] – C:\Windows\AxInstSV
[2012/08/13 06:48:12 | 000,000,000 | —D | C] – C:\_OTL
[2009/11/08 18:34:53 | 000,454,656 | —- | C] (Simon Tatham) – C:\Program Files\putty.exe

========== Files - Modified Within 30 Days ==========

[2012/08/13 07:06:37 | 000,015,984 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/13 07:06:37 | 000,015,984 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/13 06:51:30 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/08/13 06:51:13 | 530,493,439 | -HS- | M] () – C:\hiberfil.sys
[2012/08/13 06:48:12 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2012/08/12 08:19:02 | 000,000,336 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForsnadra.job
[2012/08/09 20:11:47 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2012/08/09 20:11:47 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2012/08/08 21:37:12 | 000,726,444 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/08/08 21:37:12 | 000,624,162 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/08/08 21:37:12 | 000,106,538 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/08/05 12:30:37 | 000,001,106 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

========== Files Created - No Company Name ==========

[2012/03/31 17:32:03 | 000,000,126 | —- | C] () – C:\Windows\QUICKEN.INI
[2011/12/12 21:05:48 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/12/12 21:05:48 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/12/06 04:59:34 | 000,008,852 | -HS- | C] () – C:\Users\snadra\AppData\Local\x0ym23x1be4ukx
[2011/12/06 04:59:34 | 000,008,852 | -HS- | C] () – C:\ProgramData\x0ym23x1be4ukx
[2010/01/09 12:56:21 | 000,003,584 | —- | C] () – C:\Users\snadra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/10 18:38:09 | 000,000,600 | —- | C] () – C:\Users\snadra\AppData\Local\PUTTY.RND
[2009/11/08 18:15:10 | 000,000,112 | —- | C] () – C:\Users\snadra\AppData\Roaming\wklnhst.dat
[2009/10/08 13:30:18 | 000,217,942 | —- | C] () – C:\ProgramData\DeviceManager.xml.rc4

========== LOP Check ==========

[2009/11/03 18:42:50 | 000,000,000 | -HSD | M] – C:\Users\snadra\AppData\Roaming\.#
[2012/01/27 16:29:40 | 000,000,000 | —D | M] – C:\Users\snadra\AppData\Roaming\07B91
[2012/01/27 16:29:40 | 000,000,000 | —D | M] – C:\Users\snadra\AppData\Roaming\B8B07
[2009/11/22 17:32:51 | 000,000,000 | —D | M] – C:\Users\snadra\AppData\Roaming\Canon
[2010/06/02 09:40:25 | 000,000,000 | —D | M] – C:\Users\snadra\AppData\Roaming\FileZilla
[2011/12/17 17:18:50 | 000,000,000 | —D | M] – C:\Users\snadra\AppData\Roaming\FontCreator
[2010/03/31 17:32:20 | 000,000,000 | —D | M] – C:\Users\snadra\AppData\Roaming\Free-backup.info
[2011/06/05 10:42:34 | 000,000,000 | —D | M] – C:\Users\snadra\AppData\Roaming\GARMIN
[2009/11/10 18:05:16 | 000,000,000 | —D | M] – C:\Users\snadra\AppData\Roaming\Sierra Wireless
[2009/11/08 18:15:11 | 000,000,000 | —D | M] – C:\Users\snadra\AppData\Roaming\Template
[2010/05/24 19:17:04 | 000,000,000 | —D | M] – C:\Users\snadra\AppData\Roaming\Thunderbird
[2010/06/09 08:14:26 | 000,000,000 | —D | M] – C:\Users\snadra\AppData\Roaming\WinBatch
[2011/12/09 20:24:51 | 000,000,384 | —- | M] () – C:\Windows\Tasks\At1.job
[2011/12/09 18:42:04 | 000,000,384 | —- | M] () – C:\Windows\Tasks\At2.job
[2009/07/14 01:08:49 | 000,032,148 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
Hi snadra,

No, no smoke and mirrors. OTl read the infected Hosts file as it would appear on your computer. On your 64bit system it would be found at C:\Windows\SysNative\drivers\etc\Hosts

A couple of small items to clean up. We'll clean up the tools after you post back.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
[2011/12/09 20:24:51 | 000,000,384 | —- | M] () – C:\Windows\Tasks\At1.job
[2011/12/09 18:42:04 | 000,000,384 | —- | M] () – C:\Windows\Tasks\At2.job
IE - HKCU\..\SearchScopes,DefaultScope = {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}

:Files
C:\Users\snadra\AppData\Roaming\.#
C:\Users\snadra\AppData\Roaming\07B91
C:\Users\snadra\AppData\Roaming\B8B07

:Commands
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.
Ah, I didn't realize the 64bit kept the hosts file in a different location. I was messing with the one in c:\windows\system32\drivers\etc, which is where I'm used to finding it. In retrospect the 32 makes it seem like the wrong place, since it's a 64bit OS. This is the only one of my computers with 64, so I didn't think of it :) Below is the log from the script run you requested. ========== SERVICES/DRIVERS ========== ========== OTL ========== C:\Windows\Tasks\At1.job moved successfully. C:\Windows\Tasks\At2.job moved successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! ========== FILES ========== C:\Users\snadra\AppData\Roaming\.# folder moved successfully. C:\Users\snadra\AppData\Roaming\07B91 folder moved successfully. C:\Users\snadra\AppData\Roaming\B8B07 folder moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.57.0 log created on 08162012_070203
Hi snadra,

Sorry about that, I think I may have confused the issue. sysnative is the way OTL logs the system32 folder on a 64bit computer. I forgot to edit the line when I pasted it into my reply. I'm not sure why you couldn't see entries in the Hosts file as it is a text file and to the best of my knowledge entries can't be hidden.

I do believe you are good to go.

We'll clean up the tools now.

From your desktop or from the location you saved them, please delete, if present
  • any notepads/logs that we created
  • aswMBR.exe
  • mbr.zip
  • mbr.dat

Next

W'll reset your system Restore points and remove any old infected ones. This will retain the last one created by OTL which is clean.

1.Open Disk Cleanup by clicking the Start button . In the search box, type Disk Cleanup, and then, in the list of results, click Disk Cleanup.

2.If prompted, select the drive that you want to clean up, and then click OK.

3.In the Disk Cleanup for (drive letter) dialog box, click Clean up system files. If you're prompted for an administrator password or confirmation, type the password or provide confirmation.

4.If prompted, select the drive that you want to clean up, and then click OK.

5.Click the More Options tab, under System Restore and Shadow Copies, click Clean up.

6.In the Disk Cleanup dialog box, click Delete.

7.Click Delete Files, and then click OK.

Next

Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep it updated and use it regularly.

Updates and upgrades

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources. If you choose Foxit please decline the Foxit ToolBar.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 9.5.1 first. Be sure to move any PDF documents to another folder first though.

Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Those you have now provided you are using a firewall. Windows 7 has a built in firewall which is pretty good when set up. You can find some very good information HERE .

You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

- Make sure you have reset Windows Updates to your chosen option. Click your start button > Control Panel > System > Windows updates (lower left) > change settings

- Keep your antivirus program updated, as well as any other security programs you have.

-More tips and programs can be found HERE

Please post back if you have any problems.

Take care

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI