This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Various Issues - Trojans Found - Am I Clean? - What Do I Do Now? [Solv

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello Tech Helpers,

I seem to have a bit of an issue with my computer that I can't figure out myself. I'm no computer expert (probably a moderate user level), so I would appreciate any help anyone can give me with these issues.

First off, the problems…

- When doing a google search and click on a link, I sometimes get redirected to random websites. Most of the time it pops up with that yellow “this site looks suspicious” bar from checkpoint, but sometimes redirects the link to a seemingly random site that has no relation to what the link should be. This does not happen all the time though. Seems like it happens once or twice after the first search, then google runs fine. It's annoying, but I don't know how malicious such an issue is.

- I also seem to be missing keystrokes when typing online. It happens on google, inside hotmail, and within just about every site that has those little typing boxes like on forums and such (I'm actually typing this in OpenOffice because typing in the topic box on this forum was dropping letters like crazy. For example, if I wanted to type… “The quick brown fox was hiding in the barn after the farmer chased him from the chicken coupe” it would turn out something like this… “Theuick brown ox wasiding n the banaftr the farmechasd him frothe chikencoup”. I don't type all that fast and am certain I'm hitting all the keys, the just don't seem to be registering. This happens even with a external keyboard, but doesn't occur when not typing online.

- The internet seems to be running quite a bit slower that usual. Takes longer to switch tabs and open links than it did a month or so ago. Seems to load webpages speedy enough, so perhaps it's just the way Internet Explorer works (I have been seriously considering switch to Google Chrome, but have only ever used IE, so I'm hesitant to try something new just yet).


And the specs for the computer in question are…

Dell Laptop
Model: m5040
Processor: AMD e-450 APU with Radeon HD Graphics 1.65 Ghz
RAM: 4.00 GB (3.61 Useable)
64-Bit Operating System
451 GB hard drive (406 GB free)

Currently have the follow preventative programs installed which I update and scan with at least bi-weekly…

Avast
Malwarebytes
SuperAntiSpyware
ZoneAlarm Firewall
Ccleaner

I have recently run scans on all the above programs.

Malwarebytes found a few things which were removed and the laptop restarted. I ran a second Malwarebytes scan right away, which came up clean. I thought things were fine, so I proceeded as normal and still noticed some problems the next day (today), so I ran another Malwarebytes scan, which found two things.

All other programs came up clean (aside from the usual cookies, which were removed as well).

Am I clean? I haven't noticed any further redirecting on google searches since the last Malwarebyte scan and removal, but there still seems to be an issue with running slower than normal and is definitely still an issue with missing keystrokes.

Here are the logs for the two infected Malwarebytes scans, in order of occurance…

1st Scan
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.19.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Mom's Laptop :: MOMSLAPTOP-PC [administrator]

8/19/2012 7:03:51 AM
mbam-log-2012-08-19 (07-03-51).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 369008
Time elapsed: 1 hour(s), 31 minute(s), 37 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 1
C:\svchost (Trojan.Backdoor) -> Quarantined and deleted successfully.

Files Detected: 4
C:\Users\Mom's LappyToppy\AppData\Local\Temp\~!#B334.tmp (RootKit.0Access) -> Quarantined and deleted successfully.
C:\Windows\Temp\_avast_\unp247063442.tmp (Trojan.LameShield) -> Quarantined and deleted successfully.
C:\svchost\3D1A3642EB4.exe (Trojan.SpyEyes) -> Quarantined and deleted successfully.
C:\svchost\6A653C4F2648002 (Trojan.Backdoor) -> Quarantined and deleted successfully.

(end)


2nd Scan
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.20.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Mom's Laptop :: MOMSLAPTOP-PC [administrator]

8/20/2012 3:08:41 PM
mbam-log-2012-08-20 (15-08-41).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 345203
Time elapsed: 1 hour(s), 9 minute(s), 55 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\Users\Mom's LappyToppy\AppData\Local\Temp\~!#BD26.tmp (Trojan.Winlock) -> Quarantined and deleted successfully.
C:\Users\Mom's LappyToppy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\67a63b13-589fa2fc (Trojan.Downloader) -> Quarantined and deleted successfully.

(end)





And because it seems to be the first thing tech helpers ask for, here is the most recent HijackThis log…

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:21:51 PM, on 8/20/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Normal

Running processes:
C:\windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.myplaycity.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Zonealarm Helper Object - {2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C} - C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.5.20.3\bh\zonealarm.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120206004708.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: ZoneAlarm Security Toolbar - {438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59} - C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.5.20.3\zonealarmTlbr.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ZoneAlarm] "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe"
O4 - HKLM\..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
O4 - HKLM\..\RunOnce: [DSUpdateLauncher] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe"
O4 - HKLM\..\RunOnce: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3025214537-1139218706-3833391685-1005\..\Run: [SpeedBitVideoAccelerator] "C:\Program Files (x86)\SpeedBit Video Accelerator\VideoAccelerator.exe" /startup (User 'Mom's LappyToppy')
O4 - S-1-5-21-3025214537-1139218706-3833391685-1005 Startup: OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (User 'Mom's LappyToppy')
O4 - S-1-5-21-3025214537-1139218706-3833391685-1005 User Startup: OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (User 'Mom's LappyToppy')
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: ZoneAlarm LTD Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - Unknown owner - C:\Program Files\Common Files\McSvHost.exe (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\windows\system32\mfevtps.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Dell DataSafe Online (NOBU) - Dell, Inc. - C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: RoxMediaDB12OEM - Sonic Solutions - c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11615 bytes
Hi Quazimoto, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    services.*
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.



Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it. If asked to download Avast's database please do so.

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.


Please post back with
  • both OTL logs
  • aswMBR log
  • mbr.zip (attached)
Thank You For Replying.

All requested scans have been done. Here are the logs…




OTL logfile created on: 8/20/2012 6:43:55 PM - Run 1
OTL by OldTimer - Version 3.2.58.1 Folder = C:\Users\Mom's LappyToppy\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.61 Gb Total Physical Memory | 1.79 Gb Available Physical Memory | 49.61% Memory free
9.01 Gb Paging File | 7.11 Gb Available in Paging File | 78.93% Paging File free
Paging file location(s): c:\pagefile.sys 5538 6143 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.01 Gb Total Space | 406.63 Gb Free Space | 90.16% Space Free | Partition Type: NTFS

Computer Name: MOMSLAPTOP-PC | User Name: Mom's Laptop | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mom's LappyToppy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxslt.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (McMPFSvc) – C:\Program Files\Common Files\McSvHost.exe /McCoreSvc File not found
SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
SRV:64bit: - (mfevtp) – C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (AMD FUEL Service) – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (vsmon) – C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (Atheros Bt&Wlan; Coex Agent) – C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
SRV - (AtherosSvc) – C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AdminService.exe (Atheros Commnucations)
SRV - (RoxWatch12) – c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe (Sonic Solutions)
SRV - (RoxMediaDB12OEM) – c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe (Sonic Solutions)
SRV - (NOBU) – C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe (Dell, Inc.)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswSnx) – C:\windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswTdi) – C:\windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (hitmanpro35) – C:\Windows\SysNative\drivers\hitmanpro36.sys ()
DRV:64bit: - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV:64bit: - (Fs_Rec) – C:\windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfenlfk) – C:\Windows\SysNative\drivers\mfenlfk.sys (McAfee, Inc.)
DRV:64bit: - (cfwids) – C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (amd_xata) – C:\Windows\SysNative\drivers\amd_xata.sys (Advanced Micro Devices)
DRV:64bit: - (amd_sata) – C:\Windows\SysNative\drivers\amd_sata.sys (Advanced Micro Devices)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (BtFilter) – C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
DRV:64bit: - (BTATH_HCRP) – C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:64bit: - (BTATH_RCP) – C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:64bit: - (BTATH_LWFLT) – C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
DRV:64bit: - (AthBTPort) – C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:64bit: - (BTATH_BUS) – C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:64bit: - (BTATH_A2DP) – C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:64bit: - (Vsdatant) – C:\Windows\SysNative\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (ApfiltrService) – C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (amdiox64) – C:\Windows\SysNative\drivers\amdiox64.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.myplaycity.com/
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{62E582F9-6A52-49D5-A4D5-6A5EFE027F68}: "URL" = http://websearch.ask.com/redirect?client=i…92-F202E3467D98
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER [2012/04/06 19:07:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker [2012/03/27 22:30:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/02/06 01:47:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/07/05 03:03:28 | 000,000,000 | —D | M]

[2012/03/27 22:30:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20120206004705.dll (McAfee, Inc.)
O2:64bit: - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Zonealarm Helper Object) - {2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C} - C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.5.20.3\bh\zonealarm.dll (Montera Technologeis LTD)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20120206004708.dll (McAfee, Inc.)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Toolbar) - {438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59} - C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.5.20.3\zonealarmTlbr.dll (Montera Technologeis LTD)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKLM..\RunOnce: [DSUpdateLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe (Dell)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O4 - HKLM..\RunOnce: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\ToasterLauncher.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B5D6C06A-1676-495C-AEC6-7873B51EAA53}: DhcpNameServer = 192.168.1.1 [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/08/20 15:44:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2012/08/19 13:46:29 | 000,426,184 | —- | C] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerApp.exe
[2012/08/19 13:44:03 | 000,000,000 | —D | C] – C:\windows\SysWow64\Adobe
[2012/08/16 22:00:01 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mshtmled.dll
[2012/08/16 22:00:01 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mshtmled.dll
[2012/08/16 21:59:59 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\url.dll
[2012/08/16 21:59:59 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\url.dll
[2012/08/16 21:59:56 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieui.dll
[2012/08/16 21:59:56 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieui.dll
[2012/08/16 21:59:56 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieUnatt.exe
[2012/08/16 21:59:55 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieUnatt.exe
[2012/08/16 21:59:54 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\inetcpl.cpl
[2012/08/16 21:59:54 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\inetcpl.cpl
[2012/08/16 21:59:53 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript9.dll
[2012/08/16 21:59:50 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript.dll
[2012/08/16 21:59:50 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\jscript.dll
[2012/08/14 23:33:43 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\win32spl.dll
[2012/08/14 23:33:43 | 000,492,032 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\win32spl.dll
[2012/08/14 23:33:42 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\windows\splwow64.exe
[2012/08/14 23:33:38 | 000,503,808 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\srcore.dll
[2012/08/14 23:33:35 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\browcli.dll
[2012/08/14 23:33:34 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\netapi32.dll
[2012/08/14 23:33:34 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\browcli.dll
[2012/08/14 23:33:26 | 000,956,928 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\localspl.dll
[2012/08/06 09:55:19 | 000,000,000 | —D | C] – C:\Program Files\Paint.NET
[2012/08/06 09:54:36 | 000,000,000 | —D | C] – C:\Users\Mom's Laptop\AppData\Local\Paint.NET
[2012/07/24 18:32:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v7.1
[2012/07/24 18:32:17 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SDKs

========== Files - Modified Within 30 Days ==========

[2012/08/20 18:03:12 | 000,000,830 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2012/08/20 17:26:05 | 000,020,928 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/20 17:26:05 | 000,020,928 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/20 17:17:33 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/08/20 17:17:28 | 2903,519,232 | -HS- | M] () – C:\hiberfil.sys
[2012/08/20 12:00:00 | 000,000,422 | —- | M] () – C:\windows\tasks\SystemToolsDailyTest.job
[2012/08/20 09:09:30 | 000,779,724 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2012/08/20 09:09:30 | 000,660,770 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2012/08/20 09:09:30 | 000,121,408 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2012/08/19 23:10:56 | 000,000,000 | -H– | M] () – C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/08/19 13:46:29 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerApp.exe
[2012/08/19 13:46:29 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/08/19 12:36:09 | 000,000,000 | —- | M] () – C:\windows\SysWow64\config.nt
[2012/08/16 22:06:16 | 000,348,680 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2012/08/08 10:39:23 | 000,000,564 | —- | M] () – C:\windows\tasks\PCDoctorBackgroundMonitorTask.job
[2012/08/06 09:55:51 | 000,001,178 | —- | M] () – C:\Users\Public\Desktop\Paint.NET.lnk
[2012/08/03 08:18:32 | 000,000,824 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk

========== Files Created - No Company Name ==========

[2012/08/19 23:10:56 | 000,000,000 | -H– | C] () – C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/08/19 13:46:32 | 000,000,830 | —- | C] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2012/08/06 09:55:51 | 000,001,190 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk
[2012/08/06 09:55:51 | 000,001,178 | —- | C] () – C:\Users\Public\Desktop\Paint.NET.lnk
[2012/07/17 19:37:49 | 000,000,064 | —- | C] () – C:\windows\GPlrLanc.dat
[2011/12/29 02:59:44 | 000,003,929 | —- | C] () – C:\windows\SysWow64\atipblag.dat
[2011/12/29 02:00:16 | 000,000,000 | —- | C] () – C:\windows\ativpsrm.bin
[2011/12/29 01:52:00 | 000,017,776 | —- | C] () – C:\windows\EvtMessage.dll
[2011/11/16 16:49:04 | 000,000,096 | —- | C] () – C:\windows\LaunApp.ini
[2011/11/16 16:49:01 | 000,000,325 | —- | C] () – C:\windows\Prelaunch.ini
[2011/11/16 16:49:01 | 000,000,271 | —- | C] () – C:\windows\WisPriority.ini
[2011/11/16 16:49:01 | 000,000,035 | —- | C] () – C:\windows\DELL_LANGCODE.ini
[2011/11/16 16:49:01 | 000,000,033 | —- | C] () – C:\windows\DELL_OSTYPE.ini
[2011/11/16 16:49:01 | 000,000,032 | —- | C] () – C:\windows\WisHWDest.ini
[2011/11/16 16:49:01 | 000,000,028 | —- | C] () – C:\windows\WisLangCode.ini
[2011/11/16 16:49:01 | 000,000,023 | —- | C] () – C:\windows\WisSysInfo.ini
[2011/11/16 15:25:01 | 000,773,940 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/08/06 03:47:32 | 000,059,904 | —- | C] () – C:\windows\SysWow64\OVDecode.dll

========== LOP Check ==========

[2012/05/02 11:32:35 | 000,000,000 | —D | M] – C:\Users\Mom's Laptop\AppData\Roaming\CheckPoint
[2012/06/08 23:39:30 | 000,000,000 | —D | M] – C:\Users\Mom's Laptop\AppData\Roaming\DriverCure
[2012/02/06 01:26:10 | 000,000,000 | —D | M] – C:\Users\Mom's Laptop\AppData\Roaming\Fingertapps
[2012/07/17 19:39:10 | 000,000,000 | —D | M] – C:\Users\Mom's Laptop\AppData\Roaming\iWin
[2012/02/06 01:19:21 | 000,000,000 | —D | M] – C:\Users\Mom's Laptop\AppData\Roaming\Leadertech
[2012/06/06 18:10:53 | 000,000,000 | —D | M] – C:\Users\Mom's Laptop\AppData\Roaming\OpenOffice.org
[2012/06/08 23:39:30 | 000,000,000 | —D | M] – C:\Users\Mom's Laptop\AppData\Roaming\ParetoLogic
[2012/03/03 14:43:40 | 000,000,000 | —D | M] – C:\Users\Mom's Laptop\AppData\Roaming\SoftGrid Client
[2012/06/06 18:02:53 | 000,000,000 | —D | M] – C:\Users\Mom's Laptop\AppData\Roaming\Temp
[2012/02/08 19:54:09 | 000,000,000 | —D | M] – C:\Users\Mom's Laptop\AppData\Roaming\TP
[2012/05/02 11:50:08 | 000,000,000 | —D | M] – C:\Users\Mom's Laptop\AppData\Roaming\Windows Live Writer
[2012/08/08 10:39:23 | 000,000,564 | —- | M] () – C:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2012/08/09 20:32:45 | 000,032,596 | —- | M] () – C:\windows\Tasks\SCHEDLGU.TXT
[2012/08/20 12:00:00 | 000,000,422 | —- | M] () – C:\windows\Tasks\SystemToolsDailyTest.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2010/11/20 23:23:51 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/02/23 09:08:04 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/12/29 02:38:56 | 000,003,637 | -H– | M] () – C:\dell.sdr
[2012/08/20 17:17:28 | 2903,519,232 | -HS- | M] () – C:\hiberfil.sys
[2012/07/12 08:44:28 | 000,000,040 | —- | M] () – C:\log.txt
[2012/08/20 17:17:30 | 1512,046,591 | -HS- | M] () – C:\pagefile.sys
[2012/03/27 22:30:21 | 000,000,125 | —- | M] () – C:\user.js

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/07/03 12:21:32 | 000,041,224 | —- | M] (AVAST Software) – C:\windows\avastSS.scr
[2010/11/10 04:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/11/21 03:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 23:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 23:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/11/21 03:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010/11/21 03:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2010/11/21 03:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010/11/21 03:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-D5E97654.PF >
[2012/08/20 18:15:51 | 000,046,192 | —- | M] () MD5=ED9D03A36531E5DB9D80A60280ADB6EB – C:\Windows\Prefetch\EXPLORER.EXE-D5E97654.pf

< MD5 for: IEXPLORE.EXE >
[2012/06/02 07:47:54 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2012/05/17 19:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_1798a687b4d6030f\iexplore.exe
[2012/06/29 01:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Program Files\Internet Explorer\iexplore.exe
[2012/06/29 01:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2012/05/17 18:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_181271f4ce004017\iexplore.exe
[2012/06/02 05:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2012/05/17 22:51:05 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=4E99F42504A99D5024C2EFA015001937 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_0d43fc3580754114\iexplore.exe
[2012/06/28 22:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012/06/02 08:52:21 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2010/11/20 23:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2011/12/29 01:48:06 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2012/06/28 21:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012/06/28 21:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2012/06/02 04:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010/11/20 23:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2012/06/28 19:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2011/12/29 01:48:06 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2012/05/17 21:37:57 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=F8B2D47ED17C1D087D14EC747E5AC57A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_0dbdc7a2999f7e1c\iexplore.exe

< MD5 for: IEXPLORE.EXE(1).1012.DMP >
[2012/07/10 02:36:33 | 009,030,772 | —- | M] () MD5=66D185D6EA2F93A9C5F7A724B06A695F – C:\Users\Mom's LappyToppy\AppData\Local\CrashDumps\iexplore.exe(1).1012.dmp

< MD5 for: IEXPLORE.EXE(1).3860.DMP >
[2012/06/26 14:15:15 | 008,902,561 | —- | M] () MD5=2BE3DBDCD87747831345298218422CCA – C:\Users\Mom's LappyToppy\AppData\Local\CrashDumps\iexplore.exe(1).3860.dmp

< MD5 for: IEXPLORE.EXE.1012.DMP >
[2012/07/10 02:36:15 | 009,032,532 | —- | M] () MD5=A171B1A61F7DF06661F5B6B08BFBC1D5 – C:\Users\Mom's LappyToppy\AppData\Local\CrashDumps\iexplore.exe.1012.dmp

< MD5 for: IEXPLORE.EXE.3860.DMP >
[2012/06/26 14:14:59 | 008,904,321 | —- | M] () MD5=8E7627AACE0FB2D84C0481133689209B – C:\Users\Mom's LappyToppy\AppData\Local\CrashDumps\iexplore.exe.3860.dmp

< MD5 for: IEXPLORE.EXE.656.DMP >
[2012/08/14 02:27:28 | 008,083,647 | —- | M] () MD5=5B9A92040ECEAE653B314BCFAC3BEFE7 – C:\Users\Mom's LappyToppy\AppData\Local\CrashDumps\iexplore.exe.656.dmp

< MD5 for: IEXPLORE.EXE.6824.DMP >
[2012/08/20 15:11:36 | 002,936,635 | —- | M] () MD5=170ABD3ACDD8EAF17732F8C6CB56E106 – C:\Users\Mom's LappyToppy\AppData\Local\CrashDumps\iexplore.exe.6824.dmp

< MD5 for: IEXPLORE.EXE.MUI >
[2011/12/29 01:48:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011/12/29 01:48:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui
[2011/12/29 01:48:06 | 000,005,632 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2011/12/29 01:48:06 | 000,005,632 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-A033F7A0.PF >
[2012/08/20 18:43:07 | 000,376,632 | —- | M] () MD5=90062EF6CF76D165CAEA54009EEB6FB7 – C:\Windows\Prefetch\IEXPLORE.EXE-A033F7A0.pf

< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.ASFX >
[2012/04/04 01:54:08 | 000,002,637 | —- | M] () MD5=016DFC4F3F133AE19338EECD1924886A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ro_RO\Services\Services.asfx
[2012/04/04 01:54:08 | 000,002,970 | —- | M] () MD5=05A68D76420994EF8DF33184BFA98E04 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\uk_UA\Services\Services.asfx
[2012/04/04 01:54:04 | 000,002,555 | —- | M] () MD5=272301585AC133486E70228DA27659AC – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\zh_TW\Services\Services.asfx
[2012/04/04 01:54:02 | 000,002,562 | —- | M] () MD5=27CE9BD3209B549BB776B8C877455A91 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\nb_NO\Services\Services.asfx
[2012/04/04 01:54:02 | 000,002,632 | —- | M] () MD5=2998A4AE8D0EF5122CCB985CF7E9D9D3 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ko_KR\Services\Services.asfx
[2012/04/04 01:54:02 | 000,002,545 | —- | M] () MD5=2EEC9DDBD0B4EE5F65532322C383938A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\zh_CN\Services\Services.asfx
[2012/04/04 01:54:04 | 000,002,629 | —- | M] () MD5=3A0082D76426A87FB4937D426C491C10 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\Services\Services.asfx
[2012/04/04 01:54:04 | 000,002,590 | —- | M] () MD5=448953BD0CF26CE03D9E7CC1A7B278BC – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\tr_TR\Services\Services.asfx
[2012/04/04 01:53:58 | 000,002,605 | —- | M] () MD5=5A2C5D0DA3EAAB2AA77F16947D0E14FF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\it_IT\Services\Services.asfx
[2012/04/04 01:54:04 | 000,002,679 | —- | M] () MD5=5DD2704563A6A79C466E44CD966B2655 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\hu_HU\Services\Services.asfx
[2012/04/04 01:53:56 | 000,002,711 | —- | M] () MD5=6B0E7B068BD530B8FCEBC04CC8844AA9 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ja_JP\Services\Services.asfx
[2012/04/04 01:54:08 | 000,002,582 | —- | M] () MD5=797FC263D59784AD1498560C34FA7DA1 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sl_SI\Services\Services.asfx
[2012/04/04 01:53:56 | 000,002,626 | —- | M] () MD5=8073B18DC740B965256CE0957E363AC5 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fr_FR\Services\Services.asfx
[2012/04/04 01:54:02 | 000,002,634 | —- | M] () MD5=912DD5C0C7C8D7572AD598414D56E24A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pt_BR\Services\Services.asfx
[2012/04/04 01:53:56 | 000,002,655 | —- | M] () MD5=ABFBB9D0398492D849690C344C1316BB – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\de_DE\Services\Services.asfx
[2012/04/04 01:54:08 | 000,002,638 | —- | M] () MD5=C2C37202B0E55877A64ADDBDE738284E – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sk_SK\Services\Services.asfx
[2012/04/04 01:54:04 | 000,002,589 | —- | M] () MD5=C313AD3602D4965A1918E86B9F3E84CF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Services\Services.asfx
[2012/04/04 01:54:10 | 000,002,609 | —- | M] () MD5=C7FA88C21103C70826F274A0E865AEDF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\Services\Services.asfx
[2012/04/04 01:54:10 | 000,002,576 | —- | M] () MD5=D27D52045EB6A2EE031F7D2EA0349BC3 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\Services\Services.asfx
[2012/04/04 01:54:02 | 000,002,560 | —- | M] () MD5=D5642B1BFE0A70231D14C11D3D3FD60D – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\Services\Services.asfx
[2012/04/04 01:54:08 | 000,002,588 | —- | M] () MD5=DB216743CDE75637621E2FD39431BBD4 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\hr_HR\Services\Services.asfx
[2012/04/04 01:53:58 | 000,002,620 | —- | M] () MD5=DCF7A8843832327386B81ABD189AC236 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\Services\Services.asfx
[2012/04/04 01:54:04 | 000,002,997 | —- | M] () MD5=DD3F4DAF426555D8D85FF4D7C5A04F37 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ru_RU\Services\Services.asfx
[2010/11/15 23:02:32 | 000,000,228 | R— | M] () MD5=E09422BE0C7636A7B63A1527C4C1372D – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx
[2012/04/04 01:54:02 | 000,002,599 | —- | M] () MD5=F09D769A94767C3C7E7015A5C6C99A39 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fi_FI\Services\Services.asfx
[2012/04/04 01:53:58 | 000,002,628 | —- | M] () MD5=F844D742DB53C7D671BF7ED6517414D1 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\nl_NL\Services\Services.asfx
[2012/04/04 01:53:58 | 000,002,582 | —- | M] () MD5=FED4BDA3B6A9EB9DB59C254D8C987495 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sv_SE\Services\Services.asfx

< MD5 for: SERVICES.ASFX1 >
[2010/11/15 23:02:32 | 000,000,228 | R— | M] () MD5=A7B7A4CC1A717292474115CD3A4AC121 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx1

< MD5 for: SERVICES.ASFX10 >
[2010/11/15 23:02:34 | 000,000,233 | R— | M] () MD5=3382FAB54FC906B0E40269D903A8D690 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx10

< MD5 for: SERVICES.ASFX11 >
[2010/11/15 23:02:26 | 000,000,227 | R— | M] () MD5=F36865AB3B9813962B7EDBE66FA1C28A – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx11

< MD5 for: SERVICES.ASFX12 >
[2010/11/15 23:02:30 | 000,000,225 | R— | M] () MD5=9287C7268CC0F37F1DDE18CEBB128685 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx12

< MD5 for: SERVICES.ASFX13 >
[2010/11/15 23:02:30 | 000,000,228 | R— | M] () MD5=95326C46AC2654AFF5C8543DFE22CCB3 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx13

< MD5 for: SERVICES.ASFX14 >
[2010/11/15 23:02:26 | 000,000,228 | R— | M] () MD5=14DA84ECAF57B5ADA36B9093FF04CF32 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx14

< MD5 for: SERVICES.ASFX15 >
[2010/11/15 23:02:26 | 000,000,231 | R— | M] () MD5=CF94F061685A38BABE0BBD463191EDE7 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx15

< MD5 for: SERVICES.ASFX16 >
[2010/11/15 23:02:34 | 000,000,232 | R— | M] () MD5=B6E63D87C73CED2D6B433C542C5C3965 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx16

< MD5 for: SERVICES.ASFX17 >
[2010/11/15 23:02:34 | 000,000,230 | R— | M] () MD5=545E97C4F4CEA743A8D86B685EE2EDBB – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx17

< MD5 for: SERVICES.ASFX18 >
[2010/11/15 23:02:24 | 000,000,230 | R— | M] () MD5=2577B66F38E0DEA25F328DA4A0FED322 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx18

< MD5 for: SERVICES.ASFX19 >
[2010/11/15 23:02:26 | 000,000,225 | R— | M] () MD5=0A27F1D6595A69800A43CDE155B1E4A0 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx19

< MD5 for: SERVICES.ASFX2 >
[2010/11/15 23:02:36 | 000,000,264 | R— | M] () MD5=0652D24D4E2799851A6DF1705E2BFFDA – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx2

< MD5 for: SERVICES.ASFX20 >
[2010/11/15 23:02:38 | 000,000,231 | R— | M] () MD5=C85F2519DC6AECF93F67AA613A320136 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx20

< MD5 for: SERVICES.ASFX21 >
[2010/11/15 23:02:26 | 000,000,231 | R— | M] () MD5=8C95C0528EA7049A1DFC7A7342461D75 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx21

< MD5 for: SERVICES.ASFX22 >
[2010/11/15 23:02:24 | 000,000,231 | R— | M] () MD5=9F2731666F5771CC5C1E4EEDC8FB8607 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx22

< MD5 for: SERVICES.ASFX23 >
[2010/11/15 23:02:26 | 000,000,225 | R— | M] () MD5=0E89BE53F56B22390CF61584B649CE01 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx23

< MD5 for: SERVICES.ASFX24 >
[2010/11/15 23:02:32 | 000,000,229 | R— | M] () MD5=E57594DB9B9D78AB4B53D34CAFEB8497 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx24

< MD5 for: SERVICES.ASFX25 >
[2010/11/15 23:02:36 | 000,000,232 | R— | M] () MD5=611CB9CC21D2DDAD711690671F70EF39 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx25

< MD5 for: SERVICES.ASFX3 >
[2010/11/15 23:02:34 | 000,000,229 | R— | M] () MD5=F9824728970AC8199BABDC9CBA5E038C – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx3

< MD5 for: SERVICES.ASFX4 >
[2010/11/15 23:02:26 | 000,000,226 | R— | M] () MD5=55EA57D90AE22BDF0132597EF0D7C9C7 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx4

< MD5 for: SERVICES.ASFX5 >
[2010/11/15 23:02:34 | 000,000,233 | R— | M] () MD5=846C265B751189E88B74F0155DB6B828 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx5

< MD5 for: SERVICES.ASFX6 >
[2010/11/15 23:02:36 | 000,000,231 | R— | M] () MD5=89BD37C4118540FD5AA8CDD0C24D6C0A – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx6

< MD5 for: SERVICES.ASFX7 >
[2010/11/15 23:02:34 | 000,000,245 | R— | M] () MD5=0B82FAB8FF5F988C5311DF1144A7D740 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx7

< MD5 for: SERVICES.ASFX8 >
[2010/11/15 23:02:34 | 000,000,231 | R— | M] () MD5=5226417D3C8206000A8983BDC1243075 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx8

< MD5 for: SERVICES.ASFX9 >
[2010/11/15 23:02:30 | 000,000,234 | R— | M] () MD5=EBD8D036504F2935675F5F432F076DBA – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx9

< MD5 for: SERVICES.CFG >
[2012/04/04 01:53:54 | 000,585,987 | —- | M] () MD5=7BAB089A4F862C6BC86E0201D5BF1779 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2010/11/15 23:02:22 | 000,032,633 | R— | M] () MD5=EA1C35DD541D60819D55482130BD585D – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 03:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\windows\SysNative\en-US\services.exe.mui
[2010/11/21 03:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOCHIADS.COM.SOL >
[2012/07/29 20:26:33 | 000,000,499 | —- | M] () MD5=A0FDB0E06BC6E26B8DF524B5CD2FCE35 – C:\Users\Mom's LappyToppy\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G6N3EFDE\mochiads.com\services.mochiads.com.sol

< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2010/11/21 03:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\windows\SysNative\services.msc
[2010/11/21 03:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010/11/21 03:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 03:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PNG >
[2011/03/18 02:58:44 | 000,001,509 | —- | M] () MD5=F4EC3ABEAE15FA9BB42D721E9D543F44 – C:\Program Files\Dell Support Center\Images\icons\png\24_24\services.png

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: SERVICES.RDB >
[2011/01/17 18:52:22 | 000,237,568 | —- | M] () MD5=507957679AE4579C15D57FA741EA6FFA – C:\Program Files (x86)\OpenOffice.org 3\URE\misc\services.rdb
[2011/01/17 18:51:48 | 005,539,328 | —- | M] () MD5=F2B666905F7FDAA80C86A101A7DE62F9 – C:\Program Files (x86)\OpenOffice.org 3\Basis\program\services.rdb

< MD5 for: WINLOGON.ADML >
[2010/11/21 03:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\windows\SysNative\winlogon.exe
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/21 03:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\windows\SysNative\en-US\winlogon.exe.mui
[2010/11/21 03:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010/11/21 03:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\windows\SysNative\wbem\en-US\winlogon.mfl
[2010/11/21 03:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:DFC5A2B2

< End of report >
OTL Extras logfile created on: 8/20/2012 6:43:55 PM - Run 1
OTL by OldTimer - Version 3.2.58.1 Folder = C:\Users\Mom's LappyToppy\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.61 Gb Total Physical Memory | 1.79 Gb Available Physical Memory | 49.61% Memory free
9.01 Gb Paging File | 7.11 Gb Available in Paging File | 78.93% Paging File free
Paging file location(s): c:\pagefile.sys 5538 6143 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.01 Gb Total Space | 406.63 Gb Free Space | 90.16% Space Free | Partition Type: NTFS

Computer Name: MOMSLAPTOP-PC | User Name: Mom's Laptop | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – "C:\windows\system32\rundll32.exe" "C:\windows\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00B81E45-5609-4561-AE8B-91F534DA2F7A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{00EDCF2E-1DAB-45A4-A90A-0BC9959A4717}" = lport=2869 | protocol=6 | dir=in | app=system |
"{07C92F06-C12D-4F60-AB79-654DDCBBFA6A}" = rport=10243 | protocol=6 | dir=out | app=system |
"{09F9BE00-3F4A-4CB0-AA4C-A6F4B6E6DE9C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0D5CE97C-1C86-4E32-8579-D65336A841C0}" = rport=139 | protocol=6 | dir=out | app=system |
"{2E59F28E-6314-4A64-ABC0-3E8080B5C422}" = rport=445 | protocol=6 | dir=out | app=system |
"{36932454-02EA-4358-B698-A203DBA1D360}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{45A54F41-A6AF-45C2-83B0-021FE269F40E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4AF59315-176A-4FC5-BAAA-66DC21AAE1B1}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{53AA2EDB-6F7B-458E-8A1E-91A78EA48EDF}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |
"{6D41A02C-C99B-4D55-B7F7-6FE498908D86}" = rport=138 | protocol=17 | dir=out | app=system |
"{6E6D1E3F-E104-4C2D-A496-314C53C99E9B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{73F0EFE6-C8DC-489C-9728-6AD63242DAFD}" = lport=10243 | protocol=6 | dir=in | app=system |
"{7BB356FF-C8AD-43F0-8129-B53689001016}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |
"{8DABE9EE-F912-47C0-BB36-5EBE8FE26F5D}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |
"{8F63D76F-213C-48D4-BBA0-22C36936CAAB}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9D6B9030-9283-4948-9E0D-13414E329199}" = lport=138 | protocol=17 | dir=in | app=system |
"{9E9E4310-FDE5-4EDF-B038-7696C0D81A78}" = lport=137 | protocol=17 | dir=in | app=system |
"{A1A565F9-3F45-4C71-8DB3-3014DF6D5CEA}" = lport=139 | protocol=6 | dir=in | app=system |
"{AAE453E4-6172-46A5-B7CB-208F971F80F6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B1A44B3A-D516-4776-8F7B-4D3971CAD8D9}" = lport=445 | protocol=6 | dir=in | app=system |
"{B4C7F4CE-0124-4C24-9C98-E7CB08C7C565}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BFD185B5-055A-460C-A46A-E0264B8AC852}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{F3CC3EAA-4F03-46EC-AE24-F7BD2D7EC398}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{F479A20D-AD28-4760-AAB4-1259F899E590}" = rport=137 | protocol=17 | dir=out | app=system |
"{F50EAC43-5B7C-4714-BDE9-311B9112CEC4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F83C680F-A968-4141-8E96-3329484512D0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FC050BBC-0D56-49F0-BB30-F1370C6F7AFD}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{098DAA2B-1180-4B47-AEB8-0CE3A2215419}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0AA63E48-798B-4692-ADEB-FF5B84FCF556}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{0CC05797-92C7-4BA8-B3F6-ADE66491169A}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{110C7DF7-C966-49D7-B2D9-F62F97855FE9}" = protocol=17 | dir=in | app=c:\programdata\kodak\installer\setup.exe |
"{20CF3F52-61BE-40F9-A520-2F5A1AC3BCB1}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{21F13527-8383-4C29-87D0-7BF3B11C6945}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\center\aiohomecenter.exe |
"{261F2969-B778-443E-AC00-D3681FF6CA3D}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{263F7C25-3582-4067-A492-D9A4FEA5A244}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{26BE05E4-3025-4683-B3C5-2733FF4C33CE}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\center\networkprinterdiscovery.exe |
"{2A6CF6F7-0972-42E5-80A0-D3A1BADB83A6}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3A3CE57A-15E4-43FA-9DAC-F7802C7E1A91}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{3DE9B540-6F99-4D9B-BBF7-73A6DE99A90D}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{447CB016-3A42-47E9-9F2D-59823874AC53}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4998E43F-DA24-48FE-96CC-25E653C98C35}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\center\kodak.statistics.exe |
"{519BDD18-590E-47EA-9C4C-088E872F59A4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{51E3CF3B-6A86-4F56-A650-E73EDE3BF1BC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{54AA27AB-05D7-4808-BFB8-0CDA06661378}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\center\networkprinterdiscovery.exe |
"{5D2C9182-83D8-49CD-9D7F-4F5ACF67C3BC}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{5F9F05F9-6DFF-4920-BB4B-0DFABC062CF8}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{61907587-62FF-453B-9BF1-E220F0D540B7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6AC884F5-F780-45D2-BD61-D5DA76382F04}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\firmware\kodakaioupdater.exe |
"{6F967147-7C26-47D1-ACB5-0947E63FE644}" = dir=in | app=c:\program files\dell stage\dell stage\stage_primary.exe |
"{77345210-30E0-48D1-BFF8-740CA4C290E2}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\center\aiohomecenter.exe |
"{798B948E-77F2-4FCA-B559-F9305EC088C8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{85ED68B7-B6B7-4913-A4C0-BCDDBF334C90}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{8F4FFDE1-0C64-4174-B2CB-A26223BC4C40}" = dir=in | app=c:\program files\dell stage\dell stage\accuweather\accuweather.exe |
"{8FAC03FD-4C44-4A22-8D71-3F83C8790993}" = dir=in | app=c:\program files\dell stage\musicstage\musicstageengine.exe |
"{90D1DF1F-235B-442C-A9AE-3BCB01B27915}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{94D2F7F8-E832-43CD-8A08-D3E72A58B202}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{9567F3EF-25A7-4185-9D07-7EC0085FC176}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{964F2348-0D8B-4FC0-A5FF-D43EB2BF36A1}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\firmware\kodakaioupdater.exe |
"{971CE12F-2DDD-4573-8EDA-2471FBF0CAD5}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\center\kodak.statistics.exe |
"{9B1E3E0D-39FC-4572-BBD4-BEFE825AB494}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A784A117-F582-44EC-8EB6-68A215D4F7B9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A8009383-36FF-4678-88A2-C5752FFB5167}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{B27C7C96-E018-44D3-926B-2BB1D521FE3A}" = protocol=6 | dir=out | app=system |
"{B4AAE192-E01C-4730-A4EC-DAE6C389653A}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{BAA305D9-6E37-4FA0-B199-B6913D11301B}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{C6714045-8613-4A2F-940E-1AFA93459EB0}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CF608E0D-1D84-4DB5-88DD-11C7F06777AC}" = protocol=6 | dir=in | app=c:\programdata\kodak\installer\setup.exe |
"{DCEE37D0-8E3B-4CCE-BD68-DA546ED88C3A}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{E0CEAAE8-D54D-48EB-AB1C-C7A2190946CB}" = dir=in | app=c:\program files (x86)\dell\videostage\videostage.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Bluetooth Win7 Suite (64)
"{26A24AE4-039D-4CA4-87B4-2F86416027FF}" = Java™ 6 Update 27 (64-bit)
"{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}" = Kodak AIO Printer
"{3156336D-8E44-3671-A6FE-AE51D3D6564E}" = Microsoft Windows SDK for Windows 7 (7.1)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6A29BC26-68EB-EE27-0775-C6A5D9880FB8}" = ATI AVIVO64 Codecs
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{8F56EA58-DCEE-8262-12AC-5C7ED4B3FE01}" = ATI Catalyst Install Manager
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}" = RBVirtualFolder64Inst
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{AB7F413C-C973-1E76-1500-A379C6876468}" = ccc-utility64
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{D44E2164-C3EA-09BF-8396-07BFF727025A}" = AMD Media Foundation Decoders
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F82DEF3B-AB08-942C-3EA9-18277410B384}" = AMD Fuel
"CCleaner" = CCleaner
"Dell Support Center" = Dell Support Center
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"SDKSetup_7.1.7600.0.30514" = Microsoft Windows SDK for Windows 7 (7.1)
"ZoneAlarm LTD Toolbar" = ZoneAlarm LTD Toolbar

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0ECFCB07-9BFE-4970-ACA1-D568D982760B}" = Complete Care Business Service Agreement
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2244FF47-8247-C94C-4459-0B6F57495400}" = CCC Help Hungarian
"{25AE6DBA-D866-1325-1F82-D6BFFA4D6110}" = CCC Help Chinese Standard
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216027FF}" = Java™ 6 Update 27
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Dell WLAN and Bluetooth Client Installation
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A0F2CC5-3065-492C-8380-B03AA7106B1A}" = Dell Product Registration
"{315B5C4F-8FB3-117A-DB04-C09D99781848}" = Catalyst Control Center Profiles Mobile
"{3250260C-7A95-4632-893B-89657EB5545B}" = PhotoShowExpress
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33B2BCA3-DAAA-92E4-A612-1E25349CC439}" = Catalyst Control Center Localization All
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{39D06E77-8921-4056-8901-36D0035BAECA}" = Dell Stage
"{3BD7DD08-991B-4A2F-A165-614ED14EAADD}" = Dell MusicStage
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{4296F858-23E0-1875-96F4-ECAC0B65B2A5}" = CCC Help Russian
"{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}" = Banctec Service Agreement
"{44619C87-6A22-E5B5-B756-A4E87CF287ED}" = CCC Help Japanese
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{48B41C3A-9A92-4B81-B653-C97FEB85C910}" = C4USelfUpdater
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CDFB50C-EFC7-5740-8351-9DA8327076AB}" = CCC Help Chinese Traditional
"{4D6E7356-0D53-D9DF-B65E-13A44B4621C2}" = Catalyst Control Center InstallProxy
"{51F2D101-6579-CA0C-0B69-DEC94C4C7EC9}" = CCC Help German
"{56BA241F-580C-43D2-8403-947241AAE633}" = center
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{58DB59A3-47B7-CB43-8AAA-400A6EB3FAD3}" = CCC Help Korean
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63229B8B-B757-2A22-D56B-36CA72DD401B}" = CCC Help Greek
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}" = Roxio Creator Starter
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73B91779-D763-560C-2623-5835DFBC5016}" = CCC Help Thai
"{7746BFAA-2B5D-4FFD-A0E8-4558F4668105}" = Roxio Burn
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7EC66A95-AC2D-4127-940B-0445A526AB2F}" = Dell DataSafe Online
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B09AC97-2063-0928-0C94-7330E4AEF4D9}" = CCC Help Danish
"{8B16758A-B4E4-F49C-76C4-13D2A067CC24}" = CCC Help Swedish
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{903679E8-44C8-4C07-9600-05C92654FC50}" = QualxServ Service Agreement
"{91CF243B-116F-965D-726C-89713A3B1922}" = CCC Help Norwegian
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{933FBD25-7171-D8B5-3E31-095750D6BD8C}" = CCC Help Finnish
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{97F75C51-951B-E04C-8CFD-25900D388693}" = CCC Help Polish
"{98AB97E8-FA29-02A4-941D-222C4A83DAC3}" = AMD VISION Engine Control Center
"{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Sonic CinePlayer Decoder Pack
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8B88634-7F90-402F-B66A-86429755F6A5}" = eBay
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB2FDE4F-6BED-4E9E-B676-3DCCEBB1FBFE}" = Dell Home Systems Service Agreement
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.3) MUI
"{AD57ECE4-976A-0447-4C4C-644C6059341F}" = CCC Help Turkish
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{AFC08A81-D3C5-46F4-8F08-876E4BA606EA}" = Dell Digital Delivery
"{AFEA7544-6B97-4867-A94D-1C39BA61B64F}" = Catalyst Control Center - Branding
"{B106F6AB-EEC6-FCC3-1492-0A54E7B0D52E}" = CCC Help French
"{B62174EB-2AE6-D3A0-381D-DA9FDBF70C82}" = CCC Help Czech
"{B73009A8-78AB-47D2-9D63-99271D9457B1}" = CCC Help Italian
"{BE731865-5041-3F42-C7E9-68292DB8A044}" = Catalyst Control Center Graphics Previews Common
"{BE94C681-68E2-4561-8ABC-8D2E799168B4}" = essentials
"{BFBCF96F-7361-486A-965C-54B17AC35421}" = ocr
"{C33AA6D6-F5EC-48F3-AFDC-8141345D473A}" = Premium Service Agreement
"{C594B957-CC60-589C-D825-E6406D8759F5}" = CCC Help Spanish
"{C5BF5D70-6C6E-915A-A3DA-F4F86ACEEFE3}" = CCC Help Portuguese
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CED8DCFA-2DD0-49EF-377A-F414B644D8E3}" = CCC Help English
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D9313DEC-F4B0-430A-8565-63F8450D2D42}" = ZoneAlarm Security
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E4335E82-17B3-460F-9E70-39D9BC269DB3}" = Dell PhotoStage
"{E50FD74A-DAAC-C9D0-F9D8-EDCDD08CAB2D}" = CCC Help Dutch
"{E8DBC0AE-4A2D-4859-84E9-C50C3EBA4DB0}" = ZoneAlarm Firewall
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EF53BFAB-4C10-40DB-A82D-9B07111715C6}" = aioscnnr
"{EF56258E-0326-48C5-A86C-3BAC26FC15DF}" = Roxio Creator Starter
"{EF85FEF4-EB92-4075-A6D2-5F519BB30A2C}" = Accidental Damage Services Agreement
"{F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}" = Roxio Creator Starter
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F47C37A4-7189-430A-B81D-739FF8A7A554}" = Consumer In-Home Service Agreement
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Audacity_is1" = Audacity 2.0
"avast" = avast! Free Antivirus
"Dell Webcam Central" = Dell Webcam Central
"Free MP3 WMA OGG Converter_is1" = Free MP3 WMA OGG Converter 8.9.1
"InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"LAME_is1" = LAME v3.99.3 (for Windows)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"WinLiveSuite" = Windows Live Essentials
"ZoneAlarm Free" = ZoneAlarm Free
"ZoneAlarm Security Toolbar" = ZoneAlarm Security Toolbar

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 7/26/2012 10:40:25 PM | Computer Name = MomsLaptop-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/26/2012 10:42:25 PM | Computer Name = MomsLaptop-PC | Source = CVHSVC | ID = 100
Description = Information only. Too many failures while downloading ranges: 2

Error - 7/26/2012 10:42:37 PM | Computer Name = MomsLaptop-PC | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 1

Error - 7/26/2012 10:43:44 PM | Computer Name = MomsLaptop-PC | Source = CVHSVC | ID = 100
Description = Information only. (Stream product id=0x0066): Streaming Failed

Error - 7/27/2012 7:10:52 PM | Computer Name = MomsLaptop-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/27/2012 7:13:03 PM | Computer Name = MomsLaptop-PC | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 1

Error - 7/27/2012 7:15:22 PM | Computer Name = MomsLaptop-PC | Source = CVHSVC | ID = 100
Description = Information only. Too many failures while downloading ranges: 2

Error - 7/27/2012 7:16:57 PM | Computer Name = MomsLaptop-PC | Source = CVHSVC | ID = 100
Description = Information only. (Stream product id=0x0066): Streaming Failed

Error - 7/27/2012 10:15:47 PM | Computer Name = MomsLaptop-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/27/2012 10:18:15 PM | Computer Name = MomsLaptop-PC | Source = CVHSVC | ID = 100
Description = Information only. Too many failures while downloading ranges: 2

Error - 7/27/2012 10:18:29 PM | Computer Name = MomsLaptop-PC | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : 1

[ Dell Events ]
Error - 2/6/2012 8:02:40 PM | Computer Name = MomsLaptop-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 2/6/2012 8:02:40 PM | Computer Name = MomsLaptop-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 6/9/2012 11:31:03 AM | Computer Name = MomsLaptop-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

[ Media Center Events ]
Error - 3/12/2012 10:36:34 AM | Computer Name = MomsLaptop-PC | Source = MCUpdate | ID = 0
Description = 10:36:34 AM - Error connecting to the internet. 10:36:34 AM - Unable
to contact server..

Error - 3/12/2012 10:37:38 AM | Computer Name = MomsLaptop-PC | Source = MCUpdate | ID = 0
Description = 10:37:28 AM - Error connecting to the internet. 10:37:28 AM - Unable
to contact server..

[ System Events ]
Error - 8/20/2012 5:18:42 PM | Computer Name = MomsLaptop-PC | Source = Service Control Manager | ID = 7000
Description = The McAfee Personal Firewall Service service failed to start due to
the following error: %%2

Error - 8/20/2012 5:28:48 PM | Computer Name = MomsLaptop-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/20/2012 5:31:25 PM | Computer Name = MomsLaptop-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/20/2012 5:32:21 PM | Computer Name = MomsLaptop-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/20/2012 5:32:47 PM | Computer Name = MomsLaptop-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/20/2012 5:33:03 PM | Computer Name = MomsLaptop-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/20/2012 6:02:35 PM | Computer Name = MomsLaptop-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/20/2012 6:02:36 PM | Computer Name = MomsLaptop-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/20/2012 6:15:19 PM | Computer Name = MomsLaptop-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 8/20/2012 6:43:09 PM | Computer Name = MomsLaptop-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.


< End of report >


———————————————————————————————————–



aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-08-20 19:22:52
—————————–
19:22:52.709 OS Version: Windows x64 6.1.7601 Service Pack 1
19:22:52.709 Number of processors: 2 586 0x200
19:22:52.756 ComputerName: MOMSLAPTOP-PC UserName: Mom's Laptop
19:22:56.297 Initialize success
19:22:57.062 AVAST engine defs: 12082001
19:23:01.929 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000077
19:23:01.929 Disk 0 Vendor: ST950032 D005 Size: 476940MB BusType: 11
19:23:01.945 Disk 0 MBR read successfully
19:23:01.945 Disk 0 MBR scan
19:23:01.976 Disk 0 Windows 7 default MBR code
19:23:01.991 Disk 0 Partition 1 00 DE Dell Utility DELL 8.0 100 MB offset 2048
19:23:02.007 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 206848
19:23:02.023 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 461838 MB offset 30926848
19:23:02.054 Disk 0 scanning C:\windows\system32\drivers
19:23:18.761 Service scanning
19:23:45.734 Modules scanning
19:23:45.749 Disk 0 trace - called modules:
19:23:45.781 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
19:23:45.796 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80045f4300]
19:23:45.796 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa8004112ac0]
19:23:45.812 5 amd_xata.sys[fffff88001094b3f] -> nt!IofCallDriver -> \Device\00000077[0xfffffa800410e540]
19:23:47.621 AVAST engine scan C:\windows
19:23:51.740 AVAST engine scan C:\windows\system32
19:27:31.934 AVAST engine scan C:\windows\system32\drivers
19:27:56.645 AVAST engine scan C:\Users\Mom's Laptop
19:29:02.336 AVAST engine scan C:\ProgramData
19:31:04.906 Scan finished successfully
19:57:40.431 Disk 0 MBR has been saved successfully to "C:\Users\Mom's Laptop\Desktop\MBR.dat"
19:57:40.431 The log file has been saved successfully to "C:\Users\Mom's Laptop\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-08-20 19:22:52
—————————–
19:22:52.709 OS Version: Windows x64 6.1.7601 Service Pack 1
19:22:52.709 Number of processors: 2 586 0x200
19:22:52.756 ComputerName: MOMSLAPTOP-PC UserName: Mom's Laptop
19:22:56.297 Initialize success
19:22:57.062 AVAST engine defs: 12082001
19:23:01.929 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000077
19:23:01.929 Disk 0 Vendor: ST950032 D005 Size: 476940MB BusType: 11
19:23:01.945 Disk 0 MBR read successfully
19:23:01.945 Disk 0 MBR scan
19:23:01.976 Disk 0 Windows 7 default MBR code
19:23:01.991 Disk 0 Partition 1 00 DE Dell Utility DELL 8.0 100 MB offset 2048
19:23:02.007 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 206848
19:23:02.023 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 461838 MB offset 30926848
19:23:02.054 Disk 0 scanning C:\windows\system32\drivers
19:23:18.761 Service scanning
19:23:45.734 Modules scanning
19:23:45.749 Disk 0 trace - called modules:
19:23:45.781 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
19:23:45.796 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80045f4300]
19:23:45.796 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa8004112ac0]
19:23:45.812 5 amd_xata.sys[fffff88001094b3f] -> nt!IofCallDriver -> \Device\00000077[0xfffffa800410e540]
19:23:47.621 AVAST engine scan C:\windows
19:23:51.740 AVAST engine scan C:\windows\system32
19:27:31.934 AVAST engine scan C:\windows\system32\drivers
19:27:56.645 AVAST engine scan C:\Users\Mom's Laptop
19:29:02.336 AVAST engine scan C:\ProgramData
19:31:04.906 Scan finished successfully
19:57:40.431 Disk 0 MBR has been saved successfully to "C:\Users\Mom's Laptop\Desktop\MBR.dat"
19:57:40.431 The log file has been saved successfully to "C:\Users\Mom's Laptop\Desktop\aswMBR.txt"
19:58:24.560 Disk 0 MBR has been saved successfully to "C:\Users\Mom's Laptop\Desktop\MBR.dat"
19:58:24.575 The log file has been saved successfully to "C:\Users\Mom's Laptop\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-08-20 19:22:52
—————————–
19:22:52.709 OS Version: Windows x64 6.1.7601 Service Pack 1
19:22:52.709 Number of processors: 2 586 0x200
19:22:52.756 ComputerName: MOMSLAPTOP-PC UserName: Mom's Laptop
19:22:56.297 Initialize success
19:22:57.062 AVAST engine defs: 12082001
19:23:01.929 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000077
19:23:01.929 Disk 0 Vendor: ST950032 D005 Size: 476940MB BusType: 11
19:23:01.945 Disk 0 MBR read successfully
19:23:01.945 Disk 0 MBR scan
19:23:01.976 Disk 0 Windows 7 default MBR code
19:23:01.991 Disk 0 Partition 1 00 DE Dell Utility DELL 8.0 100 MB offset 2048
19:23:02.007 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 206848
19:23:02.023 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 461838 MB offset 30926848
19:23:02.054 Disk 0 scanning C:\windows\system32\drivers
19:23:18.761 Service scanning
19:23:45.734 Modules scanning
19:23:45.749 Disk 0 trace - called modules:
19:23:45.781 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
19:23:45.796 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80045f4300]
19:23:45.796 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa8004112ac0]
19:23:45.812 5 amd_xata.sys[fffff88001094b3f] -> nt!IofCallDriver -> \Device\00000077[0xfffffa800410e540]
19:23:47.621 AVAST engine scan C:\windows
19:23:51.740 AVAST engine scan C:\windows\system32
19:27:31.934 AVAST engine scan C:\windows\system32\drivers
19:27:56.645 AVAST engine scan C:\Users\Mom's Laptop
19:29:02.336 AVAST engine scan C:\ProgramData
19:31:04.906 Scan finished successfully
19:57:40.431 Disk 0 MBR has been saved successfully to "C:\Users\Mom's Laptop\Desktop\MBR.dat"
19:57:40.431 The log file has been saved successfully to "C:\Users\Mom's Laptop\Desktop\aswMBR.txt"
19:58:24.560 Disk 0 MBR has been saved successfully to "C:\Users\Mom's Laptop\Desktop\MBR.dat"
19:58:24.575 The log file has been saved successfully to "C:\Users\Mom's Laptop\Desktop\aswMBR.txt"
20:05:12.591 Disk 0 MBR has been saved successfully to "C:\Users\Mom's Laptop\Desktop\MBR.dat"
20:05:12.607 The log file has been saved successfully to "C:\Users\Mom's Laptop\Desktop\aswMBR.txt"

^^^^^^^ (Sorry about the multiple log saves - wasn't seeing it appear on the desktop at first) ^^^^^^^

Attachments:

Hi Quazimoto,

I don't see any malware in your logs but that doesn't mean there may not be any. Before we use some other tools to check we need to sort out your security programs as we may be also dealing with some conflicts.

Besides Avast and Zone Alarm I see what looks like remnants of McAfee and the McAfee firewall. Did you previously use McAfee and uninstall it as I don't see it in the uninstall list?



Malwarebytes and SuperAntiSpyware

It's all right to have both of these provided only one or neither is running with real time protection enabled.

I also see a HitmanPro driver. Is this something you tried at one time?
Hello, Thank You for your continued assistance. I greatly appreciate it. I believe that McAfee and McAfee firewall came pre-installed on the laptop when I bought it. I had used it in the past on another computer and didn't like it, so I don't ever use it nowadays. As far as this machine is concerned, the first thingI did when I got it was to download Avast, Malwarebytes, and SuperAntiSpyware, and Zonealarm so I've never actually used McAfee. I think I probably deleted it from the 'Uninstall A Program' list at some point and don't see anything McAfee listed there. There does appear to be a McAfee sub-folder in the Program Files (x86) folder though. Niether Malwarebytes or SuperAntiSpyware run with real-time protection. And whe scanning with either, I only do one at a time. Avast does run with real-time protection and boh Avast and Zonealarm are st to automatically start-up when I turn the computer on. Malwarebytes and SuperAntiSpyware are started and run manually when it comes time for a scan on either. Concerning HitmanPro Driver. Yes, that is something I tried at one time. A few months ago I somehow picked-up a google redirect virus (where it was redircting every link I clicked on after a google search). HitmanPro Driver was something that I saw suggested on a couple forums (via google search on a different computer) that might have helped eliminate that problem. If I remember correctly, it was one of those limited-time full trial things, so I deleted it (well, I guess thought I did if it popping up in the logs - lol). I don't remember what it was that actually go rid of the redirect virus that time, but everything as fine until a couple days ago when I started noticing the redirects again. It only happens sometimes now (more often than not clicking on google links works fine). Anyway, HitmanPro Driver is NOT something I currently use and I assuming should be removed completely somehow.
Hi Quazimoto,

Ok seems like you have a good grasp on your security programs as how to run them and which should b running in real time. We'll clean up the McAfee and go from there.

Download the MCPR tool from: http://download.mcafee.com/products/licens…atches/MCPR.exe and, when prompted, save it to your desktop.
  • right-click MCPR.exe, and select Run as Administrator.
  • When you see the User Account Control dialog box, click Yes.
  • At the McAfee Software Removal screen, click Next.
  • At the End User License Agreement (EULA) dialog box, click Next to accept the agreement.
  • When prompted, type the Captcha information to validate to application security, then click Next.
    •If you have Family Protection installed, type your Administrator user name and password, and click Next.
    •If you cannot authenticate, follow the on-screen instructions to obtain an uninstall code. If you do not have Family Protection installed, you will not receive this authentication prompt.
  • When you see the message CleanUp Successful, restart your computer. Your McAfee product will not be fully removed until after the restart.
Let me know how you make out and if the computer is any better after running the tool.
McAfee removal tool was run successfully and the laptp was rebooted. It does actually seem to be running faster and smoother now. It does sometimes take a few moments to be ableto switch tabs when browsing, but I leaning towards that being more of an internet explorer quirk (I've been seriously considering switching browsers after being a life long IE user - seems like there's a not-so-nifty new bug/quirk every week). So, removing the McAfee remenats seems to have helped that issue. Not sure how removing McAfee could have helped it, but after a few google searches and clicking on about two dozen links, I haven't been redirected yet today. However, I am still having a problem with missing keystrokes. Only does it online in things such as message boxes, search bars, and other such places. Same thing happens when using a external keyboard. But there are no missing keystrokes at all when typing offline. This seems to be a widespread problem for Internet Explorer users. Searching online, I see dozens of threads and questions about the issue and everyone seems to have a different possible cause. I did try a few things before posting this thread (removing skype, updating keyboard drivers, updating/disablig Adobe Shockwave in the internet add-ons, running with no add-ons, etc…) and am still getting dropped keystrokes. It is very annoying. Anyway, back to trojan infection aftermath; Is there anything else I should do to make double and triple sure the machine is clean?
Hi Quazimoto, The mbr.zip you attached seems to be corrupt. Please delete all copies of mbr.dat and mbr.zip from your desktop. Then rerun aswMBR and post the new mbr.dat that is produced. It must be attached and can be zipped or unzipped.
No Problemo… Scan has been re-run and MBR.dat attached below. Update: I think the file might still be corrput for some reason. Not sure whether doing so was a mistake or not, but I tried to open it, just to take a look for curisoity sake (I like to learn about things I don't already know yet). It wouldn't open normally, so I chose to open with notepad. Once opened, it was just a single line of weird looking characters. I'm certainly no expect, but I suspect that's not what it's supposed to look like. I ran a second scan and opened the new .dat file and see the same thing. I had the thought that maybe something got screwed up when I initially downloaded the program so I tried to re-download from the link above. Apparently Avast's site is down or something because after clicking on the link, the new tab that opens either just sits there and spins (the little circle by the cursor arrow) or pops up with one of those "Internet Explorer cannot display the webpage" screens. Not sure what to do now and any advice is appreciated.

Attachments:

Hi Quazimoto,

When viewed in notepad it is normal for the contents to be unreadable. You need a different program to read it.

The last one you uploaded is also corrupted. What are you using to zip the file?

Try renaming the file to mbr.txt and attaching it unzipped.
To zip the file all I did was Right Click > Send To > Compressed (Zipped) Folder. I re-downloaded the program and ran a new scan, then renamed the file. The renamed file is attached.

Attachments:

Hi Quazimoto,

Don't know why the others were corrupted but this one uploaded fine. It looks ok.

We'll look a little deeper.

Download ComboFix from:

Link 1

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Right click on ComboFix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.

Thanks
Many thanks for your continued assistance. Huh, that's odd. But, at least the latest one worked fine and more importantly, looks alright. ComboFix has been run and here is the log from it (Note: It appears I may have mistakenly neglected to disable Windows Defender before running the scan - totally spaced my mind that that was running. My apologies if that has tarnished the results at all. Just let me know if need be and I shall run the scan again)… ComboFix 12-08-22.01 - Mom's Laptop 08/22/2012 8:16.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3692.2111 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} FW: ZoneAlarm Free Firewall *Disabled* {E6380B7E-D4B2-19F1-083E-56486607704B} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Mom's LappyToppy\AppData\Roaming\byiagi.dll c:\users\Mom's LappyToppy\AppData\Roaming\lpnadm.dll . . ((((((((((((((((((((((((( Files Created from 2012-07-22 to 2012-08-22 ))))))))))))))))))))))))))))))) . . 2012-08-22 12:28 . 2012-08-22 12:28 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-08-22 12:13 . 2012-08-22 12:13 69000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6429C48B-816D-4EF9-9384-6611B0D4F55A}\offreg.dll 2012-08-21 22:05 . 2012-08-01 22:58 9309624 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6429C48B-816D-4EF9-9384-6611B0D4F55A}\mpengine.dll 2012-08-20 19:44 . 2012-08-20 19:44 388096 —-a-r- c:\users\Mom's LappyToppy\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2012-08-20 19:44 . 2012-08-20 19:44 ——– d—–w- c:\program files (x86)\Trend Micro 2012-08-19 17:46 . 2012-08-19 17:46 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-08-19 17:44 . 2012-08-19 17:44 ——– d—–w- c:\windows\SysWow64\Adobe 2012-08-17 02:01 . 2012-07-06 20:07 552960 —-a-w- c:\windows\system32\drivers\bthport.sys 2012-08-17 02:00 . 2012-06-29 03:39 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-08-17 02:00 . 2012-06-29 00:00 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-08-17 02:00 . 2012-06-29 03:40 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-08-17 02:00 . 2012-06-29 05:02 174200 —-a-w- c:\program files\Internet Explorer\sqmapi.dll 2012-08-17 02:00 . 2012-06-29 01:00 140920 —-a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll 2012-08-17 02:00 . 2012-06-29 00:06 194560 —-a-w- c:\program files (x86)\Internet Explorer\ieproxy.dll 2012-08-15 03:33 . 2012-02-11 06:43 751104 —-a-w- c:\windows\system32\win32spl.dll 2012-08-15 03:33 . 2012-02-11 06:36 559104 —-a-w- c:\windows\system32\spoolsv.exe 2012-08-15 03:33 . 2012-02-11 05:43 492032 —-a-w- c:\windows\SysWow64\win32spl.dll 2012-08-15 03:33 . 2012-02-11 06:36 67072 —-a-w- c:\windows\splwow64.exe 2012-08-15 03:33 . 2012-05-05 08:36 503808 —-a-w- c:\windows\system32\srcore.dll 2012-08-15 03:33 . 2012-05-05 07:46 43008 —-a-w- c:\windows\SysWow64\srclient.dll 2012-08-15 03:33 . 2012-07-04 22:13 59392 —-a-w- c:\windows\system32\browcli.dll 2012-08-15 03:33 . 2012-07-04 22:13 136704 —-a-w- c:\windows\system32\browser.dll 2012-08-15 03:33 . 2012-07-04 22:16 73216 —-a-w- c:\windows\system32\netapi32.dll 2012-08-15 03:33 . 2012-07-04 21:14 41984 —-a-w- c:\windows\SysWow64\browcli.dll 2012-08-15 03:33 . 2012-07-18 18:15 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-08-15 03:33 . 2012-05-14 05:26 956928 —-a-w- c:\windows\system32\localspl.dll 2012-08-06 13:57 . 2012-08-06 13:57 ——– d—–w- c:\users\Mom's LappyToppy\AppData\Local\Paint.NET 2012-08-06 13:55 . 2012-08-06 13:55 ——– d—–w- c:\program files\Paint.NET 2012-08-06 13:54 . 2012-08-06 13:54 ——– d—–w- c:\users\Mom's Laptop\AppData\Local\Paint.NET 2012-07-24 22:32 . 2012-07-24 22:32 ——– d—–w- c:\program files\Microsoft SDKs . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-08-19 17:46 . 2011-12-29 05:46 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-16 23:02 . 2012-02-12 19:33 62134624 —-a-w- c:\windows\system32\MRT.exe 2012-07-03 17:46 . 2012-02-06 06:06 24904 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-07-03 16:21 . 2012-02-26 13:42 54072 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-07-03 16:21 . 2012-02-06 05:50 355856 —-a-w- c:\windows\system32\drivers\aswSP.sys 2012-07-03 16:21 . 2012-02-06 05:50 958400 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2012-07-03 16:21 . 2012-02-06 05:50 59728 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2012-07-03 16:21 . 2012-02-06 05:50 71064 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-07-03 16:21 . 2012-02-06 05:50 25232 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-07-03 16:21 . 2012-02-06 05:50 41224 —-a-w- c:\windows\avastSS.scr 2012-07-03 16:21 . 2012-02-06 05:50 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe 2012-07-03 16:21 . 2012-02-06 05:50 285328 —-a-w- c:\windows\system32\aswBoot.exe 2012-06-09 05:43 . 2012-07-11 07:18 14172672 —-a-w- c:\windows\system32\shell32.dll 2012-06-06 06:06 . 2012-07-11 07:18 2004480 —-a-w- c:\windows\system32\msxml6.dll 2012-06-06 06:06 . 2012-07-11 07:18 1881600 —-a-w- c:\windows\system32\msxml3.dll 2012-06-06 06:02 . 2012-07-11 07:17 1133568 —-a-w- c:\windows\system32\cdosys.dll 2012-06-06 05:05 . 2012-07-11 07:18 1390080 —-a-w- c:\windows\SysWow64\msxml6.dll 2012-06-06 05:05 . 2012-07-11 07:18 1236992 —-a-w- c:\windows\SysWow64\msxml3.dll 2012-06-06 05:03 . 2012-07-11 07:17 805376 —-a-w- c:\windows\SysWow64\cdosys.dll 2012-06-02 22:19 . 2012-06-19 12:12 38424 —-a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-19 12:13 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:19 . 2012-06-19 12:13 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-19 12:13 44056 —-a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-19 12:12 701976 —-a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:15 . 2012-06-19 12:13 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:15 . 2012-06-19 12:12 99840 —-a-w- c:\windows\system32\wudriver.dll 2012-06-02 19:19 . 2012-06-19 12:12 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 19:15 . 2012-06-19 12:12 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-06-02 05:50 . 2012-07-11 07:18 458704 —-a-w- c:\windows\system32\drivers\cng.sys 2012-06-02 05:48 . 2012-07-11 07:18 151920 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-06-02 05:48 . 2012-07-11 07:17 95600 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-06-02 05:45 . 2012-07-11 07:18 340992 —-a-w- c:\windows\system32\schannel.dll 2012-06-02 05:44 . 2012-07-11 07:18 307200 —-a-w- c:\windows\system32\ncrypt.dll 2012-06-02 04:40 . 2012-07-11 07:17 22016 —-a-w- c:\windows\SysWow64\secur32.dll 2012-06-02 04:40 . 2012-07-11 07:17 225280 —-a-w- c:\windows\SysWow64\schannel.dll 2012-06-02 04:39 . 2012-07-11 07:17 219136 —-a-w- c:\windows\SysWow64\ncrypt.dll 2012-06-02 04:34 . 2012-07-11 07:17 96768 —-a-w- c:\windows\SysWow64\sspicli.dll 2012-05-31 16:25 . 2010-11-21 03:27 279656 ——w- c:\windows\system32\MpSigStub.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976] "ZoneAlarm"="c:\program files (x86)\CheckPoint\ZoneAlarm\zatray.exe" [2012-03-19 73360] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe" [2010-08-12 163040] "DSUpdateLauncher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" [2010-07-21 18240] "STToasterLauncher"="c:\program files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe" [2010-08-12 120032] . c:\users\Mom's LappyToppy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "midi2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McSvHost.exe [x] R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-19 250056] R3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro36.sys [2012-03-23 27424] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-10-30 250984] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-02-08 1255736] R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2011-06-16 79488] S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2011-06-16 40064] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-08-06 204288] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-08-06 365568] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-07-03 71064] S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe [2011-05-20 146592] S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe [2011-05-20 80032] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 ISWKL;ZoneAlarm LTD Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2012-03-16 33672] S2 IswSvc;ZoneAlarm LTD Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [2012-03-16 827520] S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-08-20 689472] S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-08-06 9361408] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-08-06 309760] S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [2011-05-20 36000] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2011-03-30 114704] S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [2011-05-20 298656] S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [2011-05-20 29344] S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [2011-05-20 201376] S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [2011-05-20 55456] S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [2011-05-20 154272] S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [2011-05-20 282272] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2011-01-20 176096] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2010-11-29 44672] . . — Other Services/Drivers In Memory — . *Deregistered* - aswMBR . Contents of the 'Scheduled Tasks' folder . 2012-08-22 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-19 17:46] . 2012-08-08 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job - c:\program files\Dell Support Center\uaclauncher.exe [2011-03-22 17:20] . 2012-08-21 c:\windows\Tasks\SystemToolsDailyTest.job - c:\program files\Dell Support Center\pcdrcui.exe [2011-03-22 17:20] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-07-03 16:21 133400 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2011-03-29 608112] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-05-27 1128448] "QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2011-03-24 3668336] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://home.myplaycity.com/ mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.1.1 [removed] . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file) SafeBoot-03787059.sys HKLM-Run-ISW - (no file) AddRemove-WildTangentGameProvider-dell-genres - c:\program files (x86)\WildTangent\Dell Games\Game Explorer Categories - genres\Uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-08-22 08:34:17 ComboFix-quarantined-files.txt 2012-08-22 12:34 . Pre-Run: 436,828,352,512 bytes free Post-Run: 436,912,484,352 bytes free . - - End Of File - - 11A0B75F306E3DD8ADC0E1A196363446
Hi Quazimoto,

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

File::
c:\windows\system32\drivers\hitmanpro36.sys
c:\program files\Common Files\McSvHost.exe
 
driver::
McMPFSvc
hitmanpro35

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

Please post the combofix log.

How's the computer now?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI