This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Sluggish Internet Browsing [Solved]

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Thank you for your help on this forum!

My issue is that my wife's profile on this computer is intermittently sluggish. It's not infrequent, it is just not constant. There are times she can navigate at the speed she wants to , but other times she'll sit for quite some time waiting for a page to load, or a link to respond. Other programs don't seem to be overly sluggish. Just internet. My profile almost never suffers in the same way hers does. I haven't heard complaints from the kids, either.

Here is my HiJackThis log:
————————————————————–
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:14:14 AM, on 9/11/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe
C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Browny02\BrYNSvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Documents and Settings\Christine\My Documents\Downloads\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\coIEPlg.dll
O2 - BHO: dTPodcastBHO - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files\Common Files\doubleTwist\IEPodcastPlugin.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: WeCareReminder - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Homepage Print 2BHO - {EFC91ACA-519F-428D-8472-81E158609D25} - C:\PROGRA~1\HOMEPA~1\IEBand.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\coIEPlg.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Homepage Print 2 - {C4FB9EEC-5B29-486B-ACD1-D93A4396E567} - C:\PROGRA~1\HOMEPA~1\IEBand.dll
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Nuance\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Nuance\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [PPort12reminder] "C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [PDFHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfpro5hook.exe
O4 - HKLM\..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe
O4 - HKLM\..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
O4 - HKLM\..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [PrinterShare] C:\Program Files\PrinterShare\paConsole.exe -minimized
O4 - HKCU\..\Run: [ISUSPM] C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe -scheduler
O4 - HKCU\..\Run: [{5F9E7405-B335-47cf-8F9A-74FD2576E4A9}] C:\Program Files\Homepage Print 2\DeskCapture.exe
O4 - HKCU\..\Run: [5B1520D7DB72273AE404110900762E3215575058._service_run] "C:\Program Files\Google\Chrome\Application\chrome.exe" –type=service
O4 - HKLM\..\Policies\Explorer\Run: [153982406] C:\DOCUME~1\ALLUSE~1\LOCALS~1\Temp\6a39f6d2092d95c6.exe
O4 - HKUS\S-1-5-21-1755230115-917001253-2734630794-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Christine')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Startup: Shortcut to paConsole.lnk = C:\Program Files\PrinterShare\paConsole.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with PDF Viewer Plus - res://C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.support.gateway.com/support/pro…r/PCPitStop.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru…cat-no-eula.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - http://www.symantec.com/techsupp/asa/ss/sa…abs/tgctlsr.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {BCBC9371-9827-11DA-A72B-0800200C9A66} (View22RTEv4 Class) - http://merillat.view22.com/release_3_9_177/View22RTEv4.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://liasophia.webex.com/client/T26L/nbr/ieatgpc.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files\Browny02\BrYNSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Norton Internet Security. (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 10601 bytes
————————————————————

Thanks again!

Chris
Hello anirishfool and Welcome to What The Tech,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort. This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
Hi anirishfool,
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Next

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.

In your next post please provide the following:
  • OTL.txt
  • Extras.txt
  • Gmer.txt
Thanks for the instructions BUT….. Wow - I downloaded OTL to my downloads folder, then cut/paste to my desk top. I double clicked the icon and got a popup - told it to run the program. There where some whirr's and buzzes, then they stopped. And the OTL icon DISAPPEARED!!! Returned to downloads - original file gone as well. Downloads list in firefox shows a blank icon but is no good. Redownload - this time copy/paste to desk top. Watched my processes in Windows Task Manager - OTL makes a brief appearance then goes away. Same thing this time - OTL disappears. Ran it from the original in Downloads, same thing AND it disappeared from in there. No new window, not "output" options. WTH!?!?! BTW - when i go to the home XP screen to choose my wife's signon, there is usually something like "2 programs running." The number listed seems to be one more program running than I was aware of. Thanks again - will await further instruction.
Hi anirishfool,

Note: If using Firefox right-click on any download links and choose Save As

Please download OTH to your desktop
Please download OTL to your desktop
Please download the attached file Scan.txt to your desktop

Double click the OTH file to run it and click Kill All Processes, your desktop will go blank.

[external image: Posted Image]

Then select Start OTL. OTL will now run
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Click the Internet Explorer button, post these logs in your Virus Removal topic.
In your next post please provide the following:
  • OTL.txt
  • Extras.txt
Could not find Scan.txt attached

Here is OTL
——————–
OTL logfile created on: 9/12/2012 10:22:26 PM - Run 1
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Documents and Settings\Christine\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.97 Gb Total Physical Memory | 1.40 Gb Available Physical Memory | 71.20% Memory free
2.82 Gb Paging File | 2.39 Gb Available in Paging File | 84.72% Paging File free
Paging file location(s): C:\pagefile.sys 1024 1024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 52.88 Gb Free Space | 35.50% Space Free | Partition Type: NTFS
Drive G: | 931.28 Gb Total Space | 697.16 Gb Free Space | 74.86% Space Free | Partition Type: FAT32

Computer Name: OPTIPLEX | User Name: Christine | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/09/12 22:17:25 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Christine\Desktop\OTL.scr
PRC - [2012/09/12 22:17:17 | 000,259,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Christine\Desktop\OTH.scr
PRC - [2012/06/15 22:24:19 | 000,138,272 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe


========== Modules (No Company Name) ==========

MOD - [2009/02/27 17:38:20 | 000,139,264 | R— | M] () – C:\Program Files\Brother\BrUtilities\BrLogAPI.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe – (navapsvc)
SRV - File not found [On_Demand | Stopped] – %SystemRoot%\System32\appmgmts.dll – (AppMgmt)
SRV - [2012/09/09 12:58:26 | 000,250,568 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/06 20:19:50 | 000,114,144 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/06/15 22:24:19 | 000,138,272 | R— | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe – (NIS)
SRV - [2010/03/09 01:40:36 | 000,144,672 | —- | M] (Nuance Communications, Inc.) [Auto | Stopped] – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe – (PDFProFiltSrvPP)
SRV - [2010/01/25 09:22:56 | 000,245,760 | —- | M] (Brother Industries, Ltd.) [On_Demand | Stopped] – C:\Program Files\Browny02\BrYNSvc.exe – (BrYNSvc)
SRV - [2009/07/20 13:28:10 | 000,121,360 | —- | M] (Logitech, Inc.) [Disabled | Stopped] – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe – (LBTServ)
SRV - [2008/12/27 19:22:53 | 000,651,720 | —- | M] (Macrovision Europe Ltd.) [Disabled | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2008/09/16 13:03:18 | 000,169,312 | —- | M] (Adobe Systems Incorporated) [Disabled | Stopped] – C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor7.0)
SRV - [2008/05/21 17:25:30 | 000,012,800 | —- | M] (Pure Networks, Inc.) [On_Demand | Stopped] – C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe – (nmraapache)
SRV - [2008/05/16 06:11:44 | 000,648,504 | —- | M] (Pure Networks, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe – (nmservice)
SRV - [2008/02/09 20:06:33 | 000,238,968 | —- | M] (Symantec Corporation) [Auto | Stopped] – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
SRV - [2008/02/09 20:06:25 | 003,220,856 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE – (LiveUpdate)
SRV - [2004/11/02 17:59:50 | 000,316,544 | —- | M] (Symantec Corporation) [Auto | Stopped] – C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe – (SymWSC)
SRV - [2004/01/05 03:27:32 | 000,065,795 | —- | M] (HP) [On_Demand | Stopped] – C:\WINDOWS\system32\hpzipm12.exe – (Pml Driver HPZ12)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMREDRV.SYS – (SYMREDRV)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\NIS\1008030.006\SYMNDIS.SYS – (SYMNDIS)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\NIS\1008030.006\SYMIDS.SYS – (SYMIDS)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\NIS\1008030.006\SYMFW.SYS – (SYMFW)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMDNS.SYS – (SYMDNS)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI10.sys – (EraserUtilDrvI10)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys – (DSproct)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - [2012/08/31 20:27:25 | 000,373,728 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\IPSDefs\20120912.001\IDSXpx86.sys – (IDSxpx86)
DRV - [2012/08/31 18:09:14 | 000,995,488 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\BASHDefs\20120905.001\BHDrvx86.sys – (BHDrvx86)
DRV - [2012/08/22 19:16:24 | 001,601,184 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\VirusDefs\20120912.004\NAVEX15.SYS – (NAVEX15)
DRV - [2012/08/22 19:16:24 | 000,092,704 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\VirusDefs\20120912.004\NAVENG.SYS – (NAVENG)
DRV - [2012/08/20 18:13:41 | 000,141,944 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2012/08/13 18:49:22 | 000,106,656 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2012/07/31 20:34:45 | 000,376,480 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2012/07/05 22:17:57 | 000,574,112 | R— | M] (Symantec Corporation) [File_System | On_Demand | Running] – C:\WINDOWS\system32\drivers\NIS\1308000.00E\srtsp.sys – (SRTSP)
DRV - [2012/07/05 22:17:57 | 000,032,928 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NIS\1308000.00E\srtspx.sys – (SRTSPX)
DRV - [2012/06/07 00:43:43 | 000,132,768 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NIS\1308000.00E\ccSetx86.sys – (ccSet_NIS)
DRV - [2012/05/21 21:37:12 | 000,924,320 | R— | M] (Symantec Corporation) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\NIS\1308000.00E\SymEFA.sys – (SymEFA)
DRV - [2012/04/17 22:13:32 | 000,388,216 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NIS\1308000.00E\symtdi.sys – (SYMTDI)
DRV - [2012/04/17 22:13:22 | 000,340,088 | R— | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\NIS\1308000.00E\SymDS.sys – (SymDS)
DRV - [2012/04/17 21:42:14 | 000,149,624 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NIS\1308000.00E\Ironx86.sys – (SymIRON)
DRV - [2011/07/27 14:48:16 | 000,006,656 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\iPodDrv.sys – (iPodDrv)
DRV - [2011/05/13 04:21:06 | 000,121,064 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ssadbus.sys – (ssadbus)
DRV - [2010/02/11 03:38:10 | 003,565,056 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2009/11/02 23:06:12 | 000,011,520 | R— | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BrUsbSib.sys – (BrUsbSIb)
DRV - [2009/11/02 23:06:11 | 000,071,424 | R— | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BrSerIb.sys – (BrSerIb)
DRV - [2009/06/17 12:56:16 | 000,037,392 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LMouFilt.Sys – (LMouFilt)
DRV - [2009/06/17 12:56:06 | 000,035,472 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LHidFilt.Sys – (LHidFilt)
DRV - [2008/05/16 06:10:32 | 000,023,992 | —- | M] (Pure Networks, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\pnarp.sys – (pnarp)
DRV - [2008/05/16 06:10:30 | 000,025,272 | —- | M] (Pure Networks, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\purendis.sys – (purendis)
DRV - [2007/02/08 09:45:14 | 000,029,184 | R— | M] (Thesycon GmbH, Germany) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\dsiarhwprog.sys – (dsiarhwprog)
DRV - [2006/09/14 04:45:38 | 000,003,456 | —- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\atiide.sys – (atiide)
DRV - [2006/05/17 04:03:24 | 000,044,544 | R— | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\bcm4sbxp.sys – (bcm4sbxp)
DRV - [2006/03/17 11:18:58 | 000,392,960 | —- | M] (Sensaura) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\senfilt.sys – (SenFiltService)
DRV - [2005/02/23 15:58:56 | 000,011,776 | —- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\afc.sys – (Afc)
DRV - [2004/10/07 21:16:04 | 000,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\AFS2K.SYS – (AFS2K)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=4070130
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o;=101881&l;…q={SEARCHTERMS}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=4070130
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/hws/sb/dell-usuk-rel…html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {27A3715C-E3A7-4C4D-A599-A4F164BB845E}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{27A3715C-E3A7-4C4D-A599-A4F164BB845E}: "URL" = http://www.google.com/search?q={searchTerm…tPage}&rlz;=
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o;=101881&l;…q={SEARCHTERMS}
IE - HKCU\..\SearchScopes\{C46446CC-2AF7-4BF2-ABD4-EDA62E8E50FF}: "URL" = http://websearch.ask.com/redirect?client=i…21-1CD66B1AAB2A
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledAddons: [removed]:1.0
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}:6.0.33
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src;=kw&tb;=DAT&o;=15236&locale;=en_US&apn;_uid=2AEF9D5D-3351-4500-AA58-97C900A14FF4&apn;_ptnrs=FC&apn;_sauid=E9EDF1C5-B517-467A-9921-1CD66B1AAB2A&apn;_dtid=YYYYYYYYUS&&q;="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@doubletwist.com/NPPodcast: C:\Program Files\Common Files\doubleTwist\NPPodcast.dll (doubleTwist Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2009/11/16 13:32:33 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.17.4: C:\Program Files\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2629: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=5.2.5.48: C:\Program Files\Musicnotes\npsibelius.dll ()
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\PROGRA~1\SONYON~1\npsoe.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Homepage Print 2\Firefox [2012/02/24 19:45:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\IPSFFPlgn\ [2012/08/22 17:30:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn\ [2012/08/26 11:20:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/06 20:19:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/09/06 20:19:37 | 000,000,000 | —D | M]

[2010/09/19 09:23:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Christine\Application Data\Mozilla\Extensions
[2012/05/02 10:09:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Christine\Application Data\Mozilla\Firefox\Profiles\oz8clgls.default\extensions
[2010/12/21 21:20:29 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Christine\Application Data\Mozilla\Firefox\Profiles\oz8clgls.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/09/06 20:19:30 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/09/06 20:19:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/09/06 20:19:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/08/04 12:51:12 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/09/06 20:19:50 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/08/30 07:31:24 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/08/30 07:31:24 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/04 06:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (PodcastBHO Class) - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O2 - BHO: (Homepage Print 2BHO) - {EFC91ACA-519F-428D-8472-81E158609D25} - C:\Program Files\Homepage Print 2\IEBand.dll (CORPUS CORPORATION)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Homepage Print 2) - {C4FB9EEC-5B29-486B-ACD1-D93A4396E567} - C:\Program Files\Homepage Print 2\IEBand.dll (CORPUS CORPORATION)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort12reminder] C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 153982406 = C:\DOCUME~1\ALLUSE~1\LOCALS~1\Temp\6a39f6d2092d95c6.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: taxactonline.com ([www] https in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.support.gateway.com/support/pro…r/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} http://a516.g.akamai.net/f/516/25175/7d/ru…cat-no-eula.cab (Citrix ICA Client)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} http://www.symantec.com/techsupp/asa/ss/sa…abs/tgctlsr.cab (Reg Error: Key error.)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1005.cab (MySpace Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {BCBC9371-9827-11DA-A72B-0800200C9A66} http://merillat.view22.com/release_3_9_177/View22RTEv4.cab (View22RTEv4 Class)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (CRLDownloadWrapper Class)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.microsoft.com/download/7/E…04/clearadj.cab (CTAdjust Class)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://liasophia.webex.com/client/T26L/nbr/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{66C4589B-81D7-4B7E-BC0F-79C9D08DEC60}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Pure Networks, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\dimsntfy: DllName - () - File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Dell.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/29 16:55:11 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/07/17 17:40:58 | 000,000,000 | —D | M] - G:\autorun – [ FAT32 ]
O32 - AutoRun File - [2002/10/17 09:56:50 | 000,000,036 | RH– | M] () - G:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/09/12 22:17:24 | 000,600,064 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Christine\Desktop\OTL.scr
[2012/09/12 22:17:07 | 000,259,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Christine\Desktop\OTH.scr
[2012/09/12 03:04:22 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2012/09/11 10:23:06 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Christine\Desktop\HiJackThis.exe
[2012/09/06 20:19:26 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/08/20 18:01:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Norton
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/09/12 22:33:00 | 000,000,232 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/09/12 22:28:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1755230115-917001253-2734630794-1006UA.job
[2012/09/12 22:17:25 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Christine\Desktop\OTL.scr
[2012/09/12 22:17:17 | 000,259,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Christine\Desktop\OTH.scr
[2012/09/12 21:53:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/12 21:36:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/09/12 20:53:02 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/12 20:39:40 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/09/12 19:02:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/09/12 16:58:17 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/09/12 10:28:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1755230115-917001253-2734630794-1006Core.job
[2012/09/12 08:10:08 | 000,002,515 | —- | M] () – C:\Documents and Settings\Christine\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2012/09/12 03:05:59 | 000,689,969 | —- | M] () – C:\WINDOWS\System32\drivers\NIS\1308000.00E\Cat.DB
[2012/09/11 09:59:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Christine\Desktop\HiJackThis.exe
[2012/09/10 15:34:57 | 000,002,497 | —- | M] () – C:\Documents and Settings\Christine\Desktop\Microsoft Office Word 2003.lnk
[2012/09/03 13:55:01 | 000,001,858 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/08/26 11:19:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/08/26 11:18:28 | 2111,934,464 | -HS- | M] () – C:\hiberfil.sys
[2012/08/22 19:25:54 | 000,008,942 | —- | M] () – C:\WINDOWS\System32\drivers\NIS\1308000.00E\VT20120731.038
[2012/08/22 17:26:39 | 000,002,018 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton Internet Security.LNK
[2012/08/20 18:13:41 | 000,141,944 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/08/20 18:13:41 | 000,060,872 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2012/08/20 18:13:41 | 000,007,468 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/08/20 18:13:41 | 000,000,806 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/08/15 03:14:02 | 000,207,304 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/08/15 03:11:33 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/06/25 00:49:52 | 000,165,560 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/05/09 19:48:38 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2012/05/08 19:39:54 | 000,593,920 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2012/05/08 19:38:56 | 000,001,107 | —- | C] () – C:\WINDOWS\ATICIM.INI
[2012/03/04 22:18:22 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2012/02/24 19:47:25 | 000,000,000 | RHS- | C] () – C:\WINDOWS\FFSSET.BIN
[2012/02/24 19:22:48 | 000,000,737 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2012/02/24 19:22:48 | 000,000,093 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2012/02/24 19:22:25 | 000,003,303 | —- | C] () – C:\WINDOWS\BRPARAM.INI
[2012/02/24 19:21:08 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\BRTCPCON.DLL
[2012/02/24 19:21:08 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\BRLMW03A.INI
[2012/02/24 19:20:40 | 000,000,086 | —- | C] () – C:\WINDOWS\Brfaxrx.ini
[2012/02/24 19:20:40 | 000,000,000 | —- | C] () – C:\WINDOWS\brdfxspd.dat
[2012/02/16 02:37:44 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/02/13 20:49:13 | 000,034,296 | —- | C] () – C:\WINDOWS\System32\drivers\mbamcatchme.sys
[2011/01/26 07:57:24 | 000,009,216 | -H– | C] () – C:\Documents and Settings\Christine\fbchathistory.dat
[2010/10/27 17:50:56 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2009/03/07 11:55:07 | 000,047,534 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LuUninstall.LiveUpdate
[2007/04/29 23:45:44 | 000,010,752 | —- | C] () – C:\Documents and Settings\Christine\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/08 00:55:25 | 000,000,132 | —- | C] () – C:\Documents and Settings\Christine\Local Settings\Application Data\fusioncache.dat

========== LOP Check ==========

[2012/02/24 19:20:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ControlCenter4
[2009/03/26 23:08:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2007/04/11 16:45:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2009/12/25 21:11:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Musicnotes
[2008/12/29 16:54:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2012/08/20 17:52:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2012/02/23 21:13:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PrinterShare
[2012/02/24 19:16:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/09/28 18:38:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Screentime
[2008/12/27 19:26:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2008/07/08 17:23:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/09/05 08:01:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\View22
[2012/03/04 22:16:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2009/04/26 20:46:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2012/02/24 19:17:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\zeon
[2010/12/28 13:38:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/28 20:49:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/31 14:09:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2012/03/28 13:28:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\ControlCenter4
[2011/05/10 14:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\Foxit Software
[2009/03/10 21:24:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\OpenOffice.org
[2012/02/26 19:53:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\PC-FAX TX
[2011/11/14 21:22:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\Softland
[2008/03/05 13:08:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\WebEx
[2008/07/23 21:12:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\WinPatrol
[2012/09/12 22:33:00 | 000,000,232 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



< End of report >
—————
Here is Extras:

——-
OTL Extras logfile created on: 9/12/2012 10:22:26 PM - Run 1
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Documents and Settings\Christine\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.97 Gb Total Physical Memory | 1.40 Gb Available Physical Memory | 71.20% Memory free
2.82 Gb Paging File | 2.39 Gb Available in Paging File | 84.72% Paging File free
Paging file location(s): C:\pagefile.sys 1024 1024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 52.88 Gb Free Space | 35.50% Space Free | Partition Type: NTFS
Drive G: | 931.28 Gb Total Space | 697.16 Gb Free Space | 74.86% Space Free | Partition Type: FAT32

Computer Name: OPTIPLEX | User Name: Christine | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"67:UDP" = 67:UDP:*:Enabled:DHCP Discovery Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe" = C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Disabled:BearShare
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Disabled:EasyShare – (Eastman Kodak Company)
"C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe" = C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe:*:Enabled:Symantec Service Framework
"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" = C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware – (Malwarebytes Corporation)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Disabled:Yahoo! Messenger
"C:\Program Files\PrinterShare\paConsole.exe" = C:\Program Files\PrinterShare\paConsole.exe:*:Enabled:PrinterAnywhere Console – (PrinterAnywhere)
"C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe" = C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:LocalSubNet:Enabled:Pure Networks Platform Service – (Pure Networks, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{03ADC8AB-C130-0C3D-1FF9-2C385DF25689}" = CCC Help Czech
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional
"{07021185-008D-ABF9-7716-475AC035F8B3}" = CCC Help Spanish
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{0F8D0406-7755-AC37-6529-73AD649DBE32}" = Catalyst Control Center Graphics Previews Common
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{1526D87C-A955-4FAB-BF18-697BA457E352}" = Norton WMI Update
"{162F8A0F-3EBF-4E2A-A37C-E8E29C261C25}" = Garmin City Navigator North America NT 2009.11 Update
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1F7473D9-6C0B-4F5A-8FA4-AB8AD78CBE54}" = DocProc
"{22072CC8-7230-96F8-52F4-05EAF3F906B6}" = CCC Help Polish
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2368ADBD-6FDF-4B9F-FE41-E20B4D78E79E}" = CCC Help Chinese Standard
"{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes
"{25EF0DC4-B072-2E04-4581-A13C91423CE6}" = CCC Help Portuguese
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java™ 6 Update 35
"{26F7855C-443B-00A6-F7B8-A97A5403F617}" = CCC Help Danish
"{28656860-4728-433C-8AD4-D1A930437BC8}" = Nuance PDF Viewer Plus
"{29B50D30-EAFC-4cea-9F76-3A0E3729E9B0}" = SkinsHP1
"{2CB4A925-48A7-DA65-DCEE-D4DE224B7D84}" = CCC Help English
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D
"{2E132061-C78A-48D4-A899-1D13B9D189FA}" = Memories Disc Creator 2.0
"{306D75B9-7FFF-FF65-0C76-57F2FE4FE1D6}" = Catalyst Control Center Core Implementation
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{32B12FE4-5A51-751A-1FB6-A14E97EBDD5C}" = CCC Help German
"{34957B51-9676-41CE-9E52-44AE91B73F1C}" = HP Software Update
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{351512E5-01BD-E878-6F57-AA3E517D9ECE}" = Skins
"{354A387E-0374-21A3-6832-335674A6D7D1}" = CCC Help French
"{366FFC89-C800-4366-B903-B9C4314109A5}" = Garmin WebUpdater
"{3C00BEE9-26D0-D9E0-A2D1-62F70D412A12}" = CCC Help Turkish
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4346F7AA-3D56-0941-424C-4454E04D37F6}" = CCC Help Italian
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{4573AC44-BEDA-11D4-AA41-00C0DF245F7E}" = FloorPlan 3D v6
"{47BBA5AA-CA6F-4A41-858D-A7A776F29A8B}" = Google SketchUp 8
"{48242276-DB89-42e8-9678-BD4280D7B99A}" = Copy
"{4837718C-5B6E-4496-B283-FFFB5A937825}" = ABBYY PDF Transformer 1.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CAE2F2C-75CD-A0DE-7520-449BCBBCC833}" = CCC Help Korean
"{4CB9ECB1-DF32-43B5-B615-3119DAA32E95}" = Process Viewer
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{53735ECE-E461-4FD0-B742-23A352436D3A}" = Logitech Updater
"{54266945-8A11-424D-B20F-4F747A714FBA}" = DV TS
"{57008A17-E76A-4832-A195-FE6A94DC8A66}" = Homepage Print 2
"{578B6EF9-119B-4FB8-8377-7DAFA9588B97}" = Network Magic
"{57F7F0A5-8F22-8E63-E819-803B5C9CA3A5}" = CCC Help Dutch
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5C0808C3-03E3-486E-BC31-A60C71F0A6F4}" = Let's Ride Friends Forever
"{5EA437D2-7A57-B60E-E8F2-76BFAC0895A5}" = CCC Help Chinese Traditional
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{61AF4E75-050E-0304-3417-8BC16417FEB1}" = CCC Help Greek
"{632005DA-C291-5275-284C-5EE96B05C714}" = Catalyst Control Center HydraVision Full
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.7
"{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}" = Nuance PaperPort 12
"{6C72BE0C-3E25-CACD-0070-2FD9C02ABA14}" = ccc-core-preinstall
"{6DE13770-01B7-4366-8DA6-48237793F445}" = VoiceOver Kit
"{6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}" = PaperPort Image Printer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7239791B-F20F-4816-8AC3-89AB8A1AEDA6}" = PrinterShare 2.3.06
"{723C033E-63EA-4227-BAB2-0AA8693C16EB}" = Director
"{745A92AF-53B4-41A7-91C3-9B026B1D5897}" = InstantShare
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}" = overland
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{81DD5688-695A-4c1d-AE7D-368BF857725A}" = TrayApp
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{85AF94EC-55DE-452A-8FD7-C34E598B3F1F}" = Adobe Premiere Elements 7.0 Templates
"{86B879A5-927E-4536-B5FC-17CA96B60078}" = Garmin Communicator Plugin
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Arcade Town Toolbar
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{880BB617-914E-17E8-D877-A96BAC5794D2}" = Catalyst Control Center Graphics Full New
"{8897CF22-DB6C-8248-895C-12BFA2677F51}" = CCC Help Hungarian
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8D7133DE-27D2-47E5-B248-4180278D32AA}" = Catalyst Control Center - Branding
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9023F316-615A-4A89-BCFF-1E16107A88AB}" = 1ClickImageExtractor
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{94358C28-335B-4E43-BC4E-C59576BAB653}" = ASPCA Reminder by We-Care.com v4.0.16.1
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{96334581-5554-3E5F-8BC9-924C3C3AC5BE}" = Google Talk Plugin
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B03C535-3AEA-4ef2-B326-0A01A2207034}" = CreativeProjects
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1B36B88-AF90-43A3-8906-6DBEE89B4FBD}" = Brother MFL-Pro Suite MFC-J625DW
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A83000000003}" = Adobe Reader 8.3.1
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{AEB9948B-4FF2-47C9-990E-47014492A0FE}" = MSXML 6.0 Parser
"{AF710FDE-2815-8C8D-5281-8004C2654AA6}" = CCC Help Russian
"{AFBBF30D-ADA9-4313-464E-14458B6BE034}" = PhotoshopdotcomInspirationBrowser
"{AFF2D965-C6F2-A210-FBF7-532612AA1D23}" = CCC Help Swedish
"{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B21336EE-4AEF-9940-4AC7-EDB89854B8D3}" = CCC Help Thai
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{BBA69346-61A1-BD34-E75A-4D81232DB1FE}" = Catalyst Control Center Localization All
"{BC339BFD-F550-471a-8D26-4D08126C62F7}" = SkinsHP2
"{BFD5ED08-F066-92D5-BE67-3B9AE5DCFF0C}" = CCC Help Japanese
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C4609F15-FB3C-D97E-BAA1-4F10815039C2}" = Catalyst Control Center Graphics Full Existing
"{C4868E88-F5B5-4E45-9592-C7062BD97441}" = Symantec Technical Support Web Controls
"{C9507D0D-1A9C-486E-91D6-33A71CCA55F2}" = Pure Networks Platform
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB6075D9-F912-40AE-BEA6-E590DA24F16B}" = Adobe Photoshop Elements 7.0
"{CBE3E0AF-73BB-4c21-8B96-B09E003EDE7F}" = QuickProjects
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}" = WinZip 12.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D01FAC3D-86B4-3A19-9D10-9156A0EB3EBE}" = CCC Help Finnish
"{D186329B-1B4D-408D-ABEC-EA5CE1F182C9}" = Overland
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D564B5E2-CCB5-4A5C-B35E-2FC30BBC9336}" = Adobe Premiere Elements 7.0
"{D73722C8-3F65-C75B-A631-5D36894DAB92}" = ccc-core-static
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DC47F79D-E180-4D5E-9490-18C5C0B2009F}_is1" = Super Crossword Creator 5.0.8
"{DDAD33B6-8C00-428D-087B-A7088355B9BE}" = Catalyst Control Center Graphics Light
"{DFF8B500-3D4F-4950-B2F6-BA0EDA96ABD8}" = Avery Easy Peel Label Sorter
"{E333F074-FC7F-596D-3D61-44F0EC28E8C0}" = ccc-utility
"{E5BD1F9C-8BBA-410E-837D-94D523269F8F}" = ArcSoft MediaConverter
"{E6CF5B58-E775-46C0-BFF2-F39A0014FE4A}" = muvee autoProducer 4.1
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{E8BFBD0A-8002-4dc9-869C-E495FA9DCE7A}" = PhotoGallery
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{F4933D9F-89CC-4CA9-B5B0-CF32968890C7}" = BookScan&Whiteboard; Suite
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F59205C8-E5FB-43F5-AAB2-16C1760D4F59}" = FaceFilter Studio Brother Edition
"{F6234880-85BE-4DCB-8A45-1FF85A1A8552}" = SmartSound Quicktracks for Premiere Elements
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FA38F9E4-BED7-E021-B660-8FDFF7EC6E1A}" = CCC Help Norwegian
"{FB64BF25-3593-4E4E-AA85-84AEF1D1475F}" = Broadcom Management Programs
"{FBBF532A-47AC-457d-AC06-0D3163D8911E}" = WebReg
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FF102450-55AA-4AE1-ACE4-E271E2470C83}" = hpmdtab
"45A7283175C62FAC673F913C1F532C5361F97841" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
"Action Replay DSi Code Manager_is1" = Action Replay DSi Code Manager
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe PhotoDeluxe Home Edition 4.0" = Adobe PhotoDeluxe Home Edition 4.0
"Adobe Photoshop Elements 7" = Adobe Photoshop Elements 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Age of Mythology 1.0" = Age of Mythology
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"Batman_Mimobot_1024x768" = Batman_Mimobot_1024x768 Screen Saver
"Batman_Mimobot_1680x1050" = Batman_Mimobot_1680x1050 Screen Saver
"Citrix ICA Web Client" = MetaFrame Presentation Server Web Client for Win32
"doPDF 7 printer_is1" = doPDF 7.1 printer
"doubleTwist" = doubleTwist
"Feudalism 2_is1" = Feudalism 2
"ffdshow_is1" = ffdshow [rev 2527] [2008-12-19]
"Foxit Reader" = Foxit Reader
"Free Realms Installer" = Free Realms Installer
"Google Chrome" = Google Chrome
"GPL Ghostscript 8.64" = GPL Ghostscript 8.64
"HijackThis" = HijackThis 1.99.1
"Hijackthis_is1" = Hijackthis 1.99.1
"HP Photo & Imaging" = HP Image Zone 3.5
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{F6234880-85BE-4DCB-8A45-1FF85A1A8552}" = SmartSound Quicktracks for Premiere Elements
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 15.0.1 (x86 en-US)" = Mozilla Firefox 15.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Musicnotes Combined Installer_is1" = Musicnotes Software Suite 1.2
"NeroMultiInstaller!UninstallKey" = Nero Suite
"Network MagicUninstall" = Network Magic
"New LEGO Digital Designer" = LEGO Digital Designer
"NIS" = Norton Internet Security
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NSS" = Norton Security Scan
"PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.
1" = Adobe Photoshop.com Inspiration Browser
"PremElem70" = Adobe Premiere Elements 7.0
"PremElem70Templates" = Adobe Premiere Elements 7.0 Templates
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"RealPlayer 6.0" = RealPlayer
"RegistryBooster 2_is1" = Uniblue RegistryBooster 2
"Roller Coaster Factory 2" = Roller Coaster Factory 2
"SpywareBlaster_is1" = SpywareBlaster 4.1
"Virtools3DLifePlayer" = Virtools 3D Life Player
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPatrol" = WinPatrol 2008
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Arcade Town Toolbar Updater

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/12/2012 5:36:42 PM | Computer Name = OPTIPLEX | Source = Bonjour Service | ID = 100
Description = ResolveSimultaneousProbe: 00000000 Our Record 3 lost: 0C3CFCCB 22
optiplex._printershare._tcp.local. SRV 0 0 13924 OPTIPLEX.local.

Error - 9/12/2012 5:36:42 PM | Computer Name = OPTIPLEX | Source = Bonjour Service | ID = 100
Description = ResolveSimultaneousProbe: 003D76F0 Pkt Record: 0C3CFCCB 22
optiplex._printershare._tcp.local. SRV 0 0 13924 OPTIPLEX.local.

Error - 9/12/2012 5:36:42 PM | Computer Name = OPTIPLEX | Source = Bonjour Service | ID = 100
Description = ResolveSimultaneousProbe: 00000000 Our Record 2 won: 0C3CFCCB 22
optiplex._printershare._tcp.local. SRV 0 0 25654 OPTIPLEX.local.

Error - 9/12/2012 5:36:42 PM | Computer Name = OPTIPLEX | Source = Bonjour Service | ID = 100
Description = ResolveSimultaneousProbe: 003D76F0 Pkt Record: 0C3CFCCB 22
optiplex._printershare._tcp.local. SRV 0 0 25654 OPTIPLEX.local.

Error - 9/12/2012 5:36:42 PM | Computer Name = OPTIPLEX | Source = Bonjour Service | ID = 100
Description = ResolveSimultaneousProbe: 00000000 Our Record 3 lost: 0C3CFCCB 22
optiplex._printershare._tcp.local. SRV 0 0 13924 OPTIPLEX.local.

Error - 9/12/2012 5:36:42 PM | Computer Name = OPTIPLEX | Source = Bonjour Service | ID = 100
Description = ResolveSimultaneousProbe: 003D76F0 Pkt Record: 0C3CFCCB 22
optiplex._printershare._tcp.local. SRV 0 0 25654 OPTIPLEX.local.

Error - 9/12/2012 5:36:42 PM | Computer Name = OPTIPLEX | Source = Bonjour Service | ID = 100
Description = ResolveSimultaneousProbe: 00000000 Our Record 3 lost: 0C3CFCCB 22
optiplex._printershare._tcp.local. SRV 0 0 13924 OPTIPLEX.local.

Error - 9/12/2012 5:36:43 PM | Computer Name = OPTIPLEX | Source = Bonjour Service | ID = 100
Description = mDNSCoreReceiveResponse: Ignoring response received before we even
began probing: 22 optiplex._printershare._tcp.local. SRV 0 0 13924 OPTIPLEX.local.

Error - 9/12/2012 5:36:44 PM | Computer Name = OPTIPLEX | Source = Bonjour Service | ID = 100
Description = mDNSCoreReceiveResponse: Received from 192.168.0.100:5353 22 optiplex._printershare._tcp.local.
SRV 0 0 25654 OPTIPLEX.local.

Error - 9/12/2012 5:36:44 PM | Computer Name = OPTIPLEX | Source = Bonjour Service | ID = 100
Description = mDNSCoreReceiveResponse: ProbeCount 2; will deregister 22 optiplex._printershare._tcp.local.
SRV 0 0 13924 OPTIPLEX.local.

[ System Events ]
Error - 9/12/2012 10:22:04 PM | Computer Name = OPTIPLEX | Source = Service Control Manager | ID = 7034
Description = The Ati HotKey Poller service terminated unexpectedly. It has done
this 1 time(s).

Error - 9/12/2012 10:22:04 PM | Computer Name = OPTIPLEX | Source = Service Control Manager | ID = 7031
Description = The Print Spooler service terminated unexpectedly. It has done this
1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 9/12/2012 10:22:04 PM | Computer Name = OPTIPLEX | Source = Service Control Manager | ID = 7034
Description = The Automatic LiveUpdate Scheduler service terminated unexpectedly.
It has done this 1 time(s).

Error - 9/12/2012 10:22:04 PM | Computer Name = OPTIPLEX | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 9/12/2012 10:22:04 PM | Computer Name = OPTIPLEX | Source = Service Control Manager | ID = 7034
Description = The Bonjour Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 9/12/2012 10:22:04 PM | Computer Name = OPTIPLEX | Source = Service Control Manager | ID = 7034
Description = The PDFProFiltSrvPP service terminated unexpectedly. It has done
this 1 time(s).

Error - 9/12/2012 10:22:05 PM | Computer Name = OPTIPLEX | Source = Service Control Manager | ID = 7034
Description = The SymWMI Service service terminated unexpectedly. It has done this
1 time(s).

Error - 9/12/2012 10:22:05 PM | Computer Name = OPTIPLEX | Source = Service Control Manager | ID = 7034
Description = The BrYNSvc service terminated unexpectedly. It has done this 1 time(s).

Error - 9/12/2012 10:22:05 PM | Computer Name = OPTIPLEX | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).

Error - 9/12/2012 10:22:05 PM | Computer Name = OPTIPLEX | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).


< End of report >
—
Hi anirishfool,

Double click OTH on your desktop to run the program
Please download the attached file Scan.txt to your desktop

Double click the OTH file to run it and click Kill All Processes, your desktop will go blank.

[external image: Posted Image]

Then select Start OTL. OTL will now run

  • Double-click on the Custom Scans box and a message box will popup asking if you want to load a custom scan from a file
    Select Scan.txt that you downloaded
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open a notepad window. OTL.Txt. It is saved in the same location as OTL.
  • Click the Internet Explorer button, post the log in your Virus Removal topic.
In your next post please provide the following:
  • OTL.txt

Attachments:

I downloaded Scan.txt to my desktop, then scanned as instructed.

There was no "extras" created.

Here is OTL


OTL logfile created on: 9/13/2012 10:08:50 AM - Run 3
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Documents and Settings\Christine\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.97 Gb Total Physical Memory | 1.38 Gb Available Physical Memory | 70.41% Memory free
2.82 Gb Paging File | 2.35 Gb Available in Paging File | 83.39% Paging File free
Paging file location(s): C:\pagefile.sys 1024 1024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 52.85 Gb Free Space | 35.48% Space Free | Partition Type: NTFS
Drive G: | 931.28 Gb Total Space | 697.16 Gb Free Space | 74.86% Space Free | Partition Type: FAT32

Computer Name: OPTIPLEX | User Name: Christine | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/09/12 22:17:25 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Christine\Desktop\OTL.scr
PRC - [2012/09/12 22:17:17 | 000,259,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Christine\Desktop\OTH.scr
PRC - [2012/06/15 22:24:19 | 000,138,272 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe


========== Modules (No Company Name) ==========

MOD - [2009/02/27 17:38:20 | 000,139,264 | R— | M] () – C:\Program Files\Brother\BrUtilities\BrLogAPI.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe – (navapsvc)
SRV - File not found [On_Demand | Stopped] – %SystemRoot%\System32\appmgmts.dll – (AppMgmt)
SRV - [2012/09/09 12:58:26 | 000,250,568 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/06 20:19:50 | 000,114,144 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/06/15 22:24:19 | 000,138,272 | R— | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe – (NIS)
SRV - [2010/03/09 01:40:36 | 000,144,672 | —- | M] (Nuance Communications, Inc.) [Auto | Stopped] – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe – (PDFProFiltSrvPP)
SRV - [2010/01/25 09:22:56 | 000,245,760 | —- | M] (Brother Industries, Ltd.) [On_Demand | Stopped] – C:\Program Files\Browny02\BrYNSvc.exe – (BrYNSvc)
SRV - [2009/07/20 13:28:10 | 000,121,360 | —- | M] (Logitech, Inc.) [Disabled | Stopped] – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe – (LBTServ)
SRV - [2008/12/27 19:22:53 | 000,651,720 | —- | M] (Macrovision Europe Ltd.) [Disabled | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2008/09/16 13:03:18 | 000,169,312 | —- | M] (Adobe Systems Incorporated) [Disabled | Stopped] – C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor7.0)
SRV - [2008/05/21 17:25:30 | 000,012,800 | —- | M] (Pure Networks, Inc.) [On_Demand | Stopped] – C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe – (nmraapache)
SRV - [2008/05/16 06:11:44 | 000,648,504 | —- | M] (Pure Networks, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe – (nmservice)
SRV - [2008/02/09 20:06:33 | 000,238,968 | —- | M] (Symantec Corporation) [Auto | Stopped] – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
SRV - [2008/02/09 20:06:25 | 003,220,856 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE – (LiveUpdate)
SRV - [2004/11/02 17:59:50 | 000,316,544 | —- | M] (Symantec Corporation) [Auto | Stopped] – C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe – (SymWSC)
SRV - [2004/01/05 03:27:32 | 000,065,795 | —- | M] (HP) [On_Demand | Stopped] – C:\WINDOWS\system32\hpzipm12.exe – (Pml Driver HPZ12)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMREDRV.SYS – (SYMREDRV)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\NIS\1008030.006\SYMNDIS.SYS – (SYMNDIS)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\NIS\1008030.006\SYMIDS.SYS – (SYMIDS)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\NIS\1008030.006\SYMFW.SYS – (SYMFW)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMDNS.SYS – (SYMDNS)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI10.sys – (EraserUtilDrvI10)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys – (DSproct)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - [2012/09/12 23:40:55 | 001,601,184 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\VirusDefs\20120912.036\NAVEX15.SYS – (NAVEX15)
DRV - [2012/09/12 23:40:55 | 000,092,704 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\VirusDefs\20120912.036\NAVENG.SYS – (NAVENG)
DRV - [2012/08/31 20:27:25 | 000,373,728 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\IPSDefs\20120912.001\IDSXpx86.sys – (IDSxpx86)
DRV - [2012/08/31 18:09:14 | 000,995,488 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\BASHDefs\20120905.001\BHDrvx86.sys – (BHDrvx86)
DRV - [2012/08/20 18:13:41 | 000,141,944 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2012/08/13 18:49:22 | 000,106,656 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2012/07/31 20:34:45 | 000,376,480 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2012/07/05 22:17:57 | 000,574,112 | R— | M] (Symantec Corporation) [File_System | On_Demand | Running] – C:\WINDOWS\system32\drivers\NIS\1308000.00E\srtsp.sys – (SRTSP)
DRV - [2012/07/05 22:17:57 | 000,032,928 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NIS\1308000.00E\srtspx.sys – (SRTSPX)
DRV - [2012/06/07 00:43:43 | 000,132,768 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NIS\1308000.00E\ccSetx86.sys – (ccSet_NIS)
DRV - [2012/05/21 21:37:12 | 000,924,320 | R— | M] (Symantec Corporation) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\NIS\1308000.00E\SymEFA.sys – (SymEFA)
DRV - [2012/04/17 22:13:32 | 000,388,216 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NIS\1308000.00E\symtdi.sys – (SYMTDI)
DRV - [2012/04/17 22:13:22 | 000,340,088 | R— | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\NIS\1308000.00E\SymDS.sys – (SymDS)
DRV - [2012/04/17 21:42:14 | 000,149,624 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NIS\1308000.00E\Ironx86.sys – (SymIRON)
DRV - [2011/07/27 14:48:16 | 000,006,656 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\iPodDrv.sys – (iPodDrv)
DRV - [2011/05/13 04:21:06 | 000,121,064 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ssadbus.sys – (ssadbus)
DRV - [2010/02/11 03:38:10 | 003,565,056 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2009/11/02 23:06:12 | 000,011,520 | R— | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BrUsbSib.sys – (BrUsbSIb)
DRV - [2009/11/02 23:06:11 | 000,071,424 | R— | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BrSerIb.sys – (BrSerIb)
DRV - [2009/06/17 12:56:16 | 000,037,392 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LMouFilt.Sys – (LMouFilt)
DRV - [2009/06/17 12:56:06 | 000,035,472 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LHidFilt.Sys – (LHidFilt)
DRV - [2008/05/16 06:10:32 | 000,023,992 | —- | M] (Pure Networks, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\pnarp.sys – (pnarp)
DRV - [2008/05/16 06:10:30 | 000,025,272 | —- | M] (Pure Networks, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\purendis.sys – (purendis)
DRV - [2007/02/08 09:45:14 | 000,029,184 | R— | M] (Thesycon GmbH, Germany) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\dsiarhwprog.sys – (dsiarhwprog)
DRV - [2006/09/14 04:45:38 | 000,003,456 | —- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\atiide.sys – (atiide)
DRV - [2006/05/17 04:03:24 | 000,044,544 | R— | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\bcm4sbxp.sys – (bcm4sbxp)
DRV - [2006/03/17 11:18:58 | 000,392,960 | —- | M] (Sensaura) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\senfilt.sys – (SenFiltService)
DRV - [2005/02/23 15:58:56 | 000,011,776 | —- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\afc.sys – (Afc)
DRV - [2004/10/07 21:16:04 | 000,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\AFS2K.SYS – (AFS2K)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070130
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070130
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/hws/sb/dell-usuk-rel…html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {27A3715C-E3A7-4C4D-A599-A4F164BB845E}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{27A3715C-E3A7-4C4D-A599-A4F164BB845E}: "URL" = http://www.google.com/search?q={searchTerm…tPage}&rlz=
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}
IE - HKCU\..\SearchScopes\{C46446CC-2AF7-4BF2-ABD4-EDA62E8E50FF}: "URL" = http://websearch.ask.com/redirect?client=i…21-1CD66B1AAB2A
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledAddons: [removed]:1.0
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}:6.0.33
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=DAT&o=15236&locale=en_US&apn_uid=2AEF9D5D-3351-4500-AA58-97C900A14FF4&apn_ptnrs=FC&apn_sauid=E9EDF1C5-B517-467A-9921-1CD66B1AAB2A&apn_dtid=YYYYYYYYUS&&q="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@doubletwist.com/NPPodcast: C:\Program Files\Common Files\doubleTwist\NPPodcast.dll (doubleTwist Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2009/11/16 13:32:33 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.17.4: C:\Program Files\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2629: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=5.2.5.48: C:\Program Files\Musicnotes\npsibelius.dll ()
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\PROGRA~1\SONYON~1\npsoe.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Homepage Print 2\Firefox [2012/02/24 19:45:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\IPSFFPlgn\ [2012/08/22 17:30:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn\ [2012/09/12 22:49:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/06 20:19:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/09/06 20:19:37 | 000,000,000 | —D | M]

[2010/09/19 09:23:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Christine\Application Data\Mozilla\Extensions
[2012/05/02 10:09:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Christine\Application Data\Mozilla\Firefox\Profiles\oz8clgls.default\extensions
[2010/12/21 21:20:29 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Christine\Application Data\Mozilla\Firefox\Profiles\oz8clgls.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/09/06 20:19:30 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/09/06 20:19:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/09/06 20:19:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/08/04 12:51:12 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/09/06 20:19:50 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/08/30 07:31:24 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/08/30 07:31:24 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/04 06:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (PodcastBHO Class) - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O2 - BHO: (Homepage Print 2BHO) - {EFC91ACA-519F-428D-8472-81E158609D25} - C:\Program Files\Homepage Print 2\IEBand.dll (CORPUS CORPORATION)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Homepage Print 2) - {C4FB9EEC-5B29-486B-ACD1-D93A4396E567} - C:\Program Files\Homepage Print 2\IEBand.dll (CORPUS CORPORATION)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort12reminder] C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 153982406 = C:\DOCUME~1\ALLUSE~1\LOCALS~1\Temp\6a39f6d2092d95c6.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: taxactonline.com ([www] https in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.support.gateway.com/support/pro…r/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} http://a516.g.akamai.net/f/516/25175/7d/ru…cat-no-eula.cab (Citrix ICA Client)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} http://www.symantec.com/techsupp/asa/ss/sa…abs/tgctlsr.cab (Reg Error: Key error.)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1005.cab (MySpace Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {BCBC9371-9827-11DA-A72B-0800200C9A66} http://merillat.view22.com/release_3_9_177/View22RTEv4.cab (View22RTEv4 Class)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (CRLDownloadWrapper Class)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.microsoft.com/download/7/E…04/clearadj.cab (CTAdjust Class)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://liasophia.webex.com/client/T26L/nbr/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{66C4589B-81D7-4B7E-BC0F-79C9D08DEC60}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Pure Networks, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\dimsntfy: DllName - () - File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Christine\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Christine\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/29 16:55:11 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/07/17 17:40:58 | 000,000,000 | —D | M] - G:\autorun – [ FAT32 ]
O32 - AutoRun File - [2002/10/17 09:56:50 | 000,000,036 | RH– | M] () - G:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/09/12 22:17:24 | 000,600,064 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Christine\Desktop\OTL.scr
[2012/09/12 22:17:07 | 000,259,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Christine\Desktop\OTH.scr
[2012/09/11 10:23:06 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Christine\Desktop\HiJackThis.exe
[2012/09/06 20:19:26 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/08/20 18:01:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Norton
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/09/13 10:13:00 | 000,000,232 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/09/13 09:53:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/13 09:46:15 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/13 09:46:09 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/09/13 06:36:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/09/13 06:28:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1755230115-917001253-2734630794-1006UA.job
[2012/09/12 22:54:35 | 000,093,368 | —- | M] () – C:\Documents and Settings\Christine\Desktop\Flowers.jpg
[2012/09/12 22:47:16 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/09/12 22:46:45 | 2111,934,464 | -HS- | M] () – C:\hiberfil.sys
[2012/09/12 22:17:25 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Christine\Desktop\OTL.scr
[2012/09/12 22:17:17 | 000,259,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Christine\Desktop\OTH.scr
[2012/09/12 19:02:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/09/12 16:58:17 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/09/12 10:28:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1755230115-917001253-2734630794-1006Core.job
[2012/09/12 08:10:08 | 000,002,515 | —- | M] () – C:\Documents and Settings\Christine\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2012/09/12 03:05:59 | 000,689,969 | —- | M] () – C:\WINDOWS\System32\drivers\NIS\1308000.00E\Cat.DB
[2012/09/11 09:59:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Christine\Desktop\HiJackThis.exe
[2012/09/10 15:34:57 | 000,002,497 | —- | M] () – C:\Documents and Settings\Christine\Desktop\Microsoft Office Word 2003.lnk
[2012/09/03 13:55:01 | 000,001,858 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/08/22 19:25:54 | 000,008,942 | —- | M] () – C:\WINDOWS\System32\drivers\NIS\1308000.00E\VT20120731.038
[2012/08/22 17:26:39 | 000,002,018 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton Internet Security.LNK
[2012/08/20 18:13:41 | 000,141,944 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/08/20 18:13:41 | 000,060,872 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2012/08/20 18:13:41 | 000,007,468 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/08/20 18:13:41 | 000,000,806 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/08/15 03:14:02 | 000,207,304 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/08/15 03:11:33 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/09/12 22:49:28 | 000,093,368 | —- | C] () – C:\Documents and Settings\Christine\Desktop\Flowers.jpg
[2012/06/25 00:49:52 | 000,165,560 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/05/09 19:48:38 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2012/05/08 19:39:54 | 000,593,920 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2012/05/08 19:38:56 | 000,001,107 | —- | C] () – C:\WINDOWS\ATICIM.INI
[2012/03/04 22:18:22 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2012/02/24 19:47:25 | 000,000,000 | RHS- | C] () – C:\WINDOWS\FFSSET.BIN
[2012/02/24 19:22:48 | 000,000,737 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2012/02/24 19:22:48 | 000,000,093 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2012/02/24 19:22:25 | 000,003,303 | —- | C] () – C:\WINDOWS\BRPARAM.INI
[2012/02/24 19:21:08 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\BRTCPCON.DLL
[2012/02/24 19:21:08 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\BRLMW03A.INI
[2012/02/24 19:20:40 | 000,000,086 | —- | C] () – C:\WINDOWS\Brfaxrx.ini
[2012/02/24 19:20:40 | 000,000,000 | —- | C] () – C:\WINDOWS\brdfxspd.dat
[2012/02/16 02:37:44 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/02/13 20:49:13 | 000,034,296 | —- | C] () – C:\WINDOWS\System32\drivers\mbamcatchme.sys
[2011/01/26 07:57:24 | 000,009,216 | -H– | C] () – C:\Documents and Settings\Christine\fbchathistory.dat
[2010/10/27 17:50:56 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2009/03/07 11:55:07 | 000,047,534 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LuUninstall.LiveUpdate
[2007/04/29 23:45:44 | 000,010,752 | —- | C] () – C:\Documents and Settings\Christine\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/08 00:55:25 | 000,000,132 | —- | C] () – C:\Documents and Settings\Christine\Local Settings\Application Data\fusioncache.dat

========== LOP Check ==========

[2012/02/24 19:20:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ControlCenter4
[2009/03/26 23:08:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2007/04/11 16:45:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2009/12/25 21:11:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Musicnotes
[2008/12/29 16:54:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2012/08/20 17:52:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2012/02/23 21:13:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PrinterShare
[2012/02/24 19:16:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/09/28 18:38:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Screentime
[2008/12/27 19:26:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2008/07/08 17:23:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/09/05 08:01:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\View22
[2012/03/04 22:16:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2009/04/26 20:46:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2012/02/24 19:17:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\zeon
[2010/12/28 13:38:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/28 20:49:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/31 14:09:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2012/03/28 13:28:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\ControlCenter4
[2011/05/10 14:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\Foxit Software
[2009/03/10 21:24:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\OpenOffice.org
[2012/02/26 19:53:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\PC-FAX TX
[2011/11/14 21:22:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\Softland
[2008/03/05 13:08:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\WebEx
[2008/07/23 21:12:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\WinPatrol
[2012/09/13 10:13:00 | 000,000,232 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



< End of report >
Hello anirishfool,

Please delete OTH, OTL and the Scan.txt file from your desktop

Print out these instructions as we may need to close every window that is open later in the fix.

It is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If this is the case, then you will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.

Do not reboot your computer after running rkill as the malware programs will start again.

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 5 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.
  • rkill.exe
  • rkill.com
  • rkill.scr
  • WiNlOgOn.exe
  • uSeRiNiT.exe
Do not reboot your computer after running rkill as the malware programs will start again.

Next
  • Download OTL to your desktop.
  • Download the attached file Scan.txt to your desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Double-click on the Custom Scans box and a message box will popup asking if you want to load a custom scan from a file
    Select Scan.txt that you downloaded
  • Click the Run Fix button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt.
    Note:This log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
In your next post please provide the following:
  • OTL.txt

Attachments:

This is the file that was created. All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\153982406 deleted successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users ->Temp folder emptied: 0 bytes User: AOM ->Temp folder emptied: 3820170 bytes ->Temporary Internet Files folder emptied: 138414 bytes ->Java cache emptied: 15 bytes ->FireFox cache emptied: 724979075 bytes ->Flash cache emptied: 27132 bytes User: Carter ->Temp folder emptied: 141440 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 1010435070 bytes ->Google Chrome cache emptied: 26184531 bytes ->Flash cache emptied: 75029 bytes User: Chris ->Temp folder emptied: 1138433005 bytes ->Temporary Internet Files folder emptied: 137831547 bytes ->Java cache emptied: 46443898 bytes ->FireFox cache emptied: 326508461 bytes ->Google Chrome cache emptied: 49367468 bytes ->Flash cache emptied: 68845 bytes User: Christine ->Temp folder emptied: 81284441 bytes ->Temporary Internet Files folder emptied: 3008467 bytes ->Java cache emptied: 37687778 bytes ->FireFox cache emptied: 344884318 bytes ->Flash cache emptied: 89925 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 13376746 bytes ->FireFox cache emptied: 318010160 bytes ->Google Chrome cache emptied: 856432 bytes ->Flash cache emptied: 54902 bytes User: Kids ->Temp folder emptied: 181431 bytes ->Temporary Internet Files folder emptied: 745991 bytes ->Java cache emptied: 3048969 bytes ->FireFox cache emptied: 151717699 bytes ->Flash cache emptied: 263634 bytes User: Kyla ->Temp folder emptied: 630401 bytes ->Temporary Internet Files folder emptied: 7552702 bytes ->Java cache emptied: 3077762 bytes ->FireFox cache emptied: 338714842 bytes ->Google Chrome cache emptied: 7051363 bytes ->Flash cache emptied: 260996 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Owner ->Temp folder emptied: 20560948 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Java cache emptied: 32447560 bytes ->Flash cache emptied: 12263 bytes User: Ryan ->Temp folder emptied: 214932819 bytes ->Temporary Internet Files folder emptied: 61881040 bytes ->Java cache emptied: 1544533 bytes ->FireFox cache emptied: 938451217 bytes ->Google Chrome cache emptied: 62641178 bytes ->Flash cache emptied: 1322832 bytes User: stoner ->Temp folder emptied: 8807150 bytes ->Temporary Internet Files folder emptied: 30674860 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 378796130 bytes ->Google Chrome cache emptied: 10239001 bytes ->Flash cache emptied: 5349 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 41585 bytes %systemroot%\System32 .tmp files removed: 3048465 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 277753787 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 303487193 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 32902 bytes RecycleBin emptied: 28789126 bytes Total Files Cleaned = 6,821.00 mb OTL by OldTimer - Version 3.2.61.3 log created on 09132012_194252 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\2w%252FA%253D5404709%252FR%253D0%252F%252A%2524%2Chttp%253A%252F%252Fus.mc374.mail.yahoo.com%252Fdarla%252Fmd[1].php%253Fen%253Dcp1252%2C%7C238933%7C19;sz=728x90;ord=1243292524 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\2w%252FA%253D5404709%252FR%253D0%252F%252A%2524%2Chttp%253A%252F%252Fus.mc374.mail.yahoo.com%252Fdarla%252Fmd[1].php%253Fen%253Dcp1252%2C%7C238933%7C19;sz=728x90;ord=1243292612 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\74N7ECAV1KTDGCARZIK4PCAIVAJTRCA3QXPJJCAB699RXCA4WGGNMCATT7CJ8CAKRCAU5CABVT4 PFCAPLA6QICAUET9QICAL2U1E7CAJKU8DWCAFNY9T1CA5VYK9ZCAZVK97MCA0XZAQACAHLTNN6CA05CYX 3CA0QEYV4CAGUS2Z9 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\9GJjZp0obJX0ABuQf%2FB%3Dms6SB9G_RvU-%2FJ%3D1243293053564300%2FK%3D90sVfBqi7642aNehej3emg%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\CGJjZp0ocPkoABwTd%2FB%3D_I0HCtG_Rvw-%2FJ%3D1243364938651614%2FK%3DPkjiDkkUjmUsbzqUN6e0iA%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\FGJjZp0ob9UUADmMq%2FB%3DNrs6BNj8a24-%2FJ%3D1243346246027298%2FK%3DCDuhxQt6oELRYxZALg.nTQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\G_Rvw-%2FJ%3D1242775166484584%2FK%3Dchgcs_NO6mWeoeXnlPd0wA%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1242775318 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\G_Rvw-%2FJ%3D1243090145976338%2FK%3DIR6j2ChWMwg8Xpjiq.zw8g%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1243090147 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\G_Rvw-%2FJ%3D1243090145976338%2FK%3DIR6j2ChWMwg8Xpjiq.zw8g%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1243090151 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\G_Rvw-%2FJ%3D1243090418584124%2FK%3DK9lyVGtlIv.hHGZHMhrYYg%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1243090419 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\G_Rvw-%2FJ%3D1243090418584124%2FK%3DK9lyVGtlIv.hHGZHMhrYYg%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1243090727 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\G_Rvw-%2FJ%3D1243365090397210%2FK%3D0yndF1Hsl_ptCzybMQW20g%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1243433484 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\KGJjZp0ocMcEACjyB%2FB%3DuGbbCdG_Rvw-%2FJ%3D1243361729796334%2FK%3D5aahMOndaxDlNQ5h8ncOaQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\KGJjZp0ocMcEACjyB%2FB%3DuGbbCdG_Rvw-%2FJ%3D1243361729796334%2FK%3D5aahMOndaxDlNQ5h8ncOaQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[2].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\KGJjZp0ocMcEACjyB%2FB%3DuGbbCdG_Rvw-%2FJ%3D1243361729796334%2FK%3D5aahMOndaxDlNQ5h8ncOaQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[3].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\KGJjZp0ocMcEACjyB%2FB%3DuGbbCdG_Rvw-%2FJ%3D1243361729796334%2FK%3D5aahMOndaxDlNQ5h8ncOaQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[4].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\kGJjZp0ocPuIAA7Nn%2FB%3DR6gJCtG_Rvw-%2FJ%3D1243365090397210%2FK%3D0yndF1Hsl_ptCzybMQW20g%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\L6OGVCA58KXYLCA5BK744CA7JVSYACAI83A7FCAYRKU33CA1DYCG3CAPQITSXCAHDMKU6CACNR4 JVCAFCK9L9CAQMN79PCA8PBL0RCAPV7KTRCAY6OQ11CA5EWXVDCAS5J6HACA0Q9KSQCAYPPKHYCAAUFX2 ACA2QNTZYCA5RU7X2 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\OFNoSzh5UWZ3Q1NpSEFDcywxXzExNTMzNF9BSVpidjlFQUFKeVNTaEZXVFFEJTJGMWxkayUyQkt RLCZoYXNoPTNhMDAyOTI4MDc5NTlhYTBlMjIzZDg1MGI1ODk0OTk1Ji5qc3JhbmQ9MzA1MTk4NwR2aXNp YmxlAzEEd3QDMQ–[1] not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\pGJjZp0ob87MAAEGI%2FB%3DCnaXBdgnMuk-%2FJ%3D1243345843174713%2FK%3DyAQI9cSxTxrzQ8.u_gjC4Q%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\pGJjZp0oSsroABYFp%2FB%3DujoXCtG_fyU-%2FJ%3D1242739386624609%2FK%3D24NZpWQknN.5v_w86497KQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\U1NoTFglMkJBMXhTSHdYU0J3LDFfMTI1NTQ5X0FJVmJ2OUVBQU9QOFNoSzh5UWZ3Q1NpSEFDcyw xXzExNTMzNF9BSVpidjlFQUFKeVNTaEZXVFFEJTJGMWxkayUyQktRLCYuanNyYW5kPTc2NjkwMzkEdmlz aWJsZQMxBHd0AzE-[1] not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\U4XKRCARYJVOYCAHP4A4MCA2UCHLUCAMII20CCA1DR807CA3EITS8CAUUJYNOCAP6RH6RCAOTD0 GYCAA3O7KACATHPO59CAX677OBCA7ZZ94WCAM64JC2CAQJXO9YCAI9MX8DCA4TR8N7CAGL001KCAZA8SK 9CAMEBZ35CAMNUH74 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\WTSTA-%2FJ%3D1242777245401750%2FK%3DJFHX_SJR4h_dsS5ZQHmaGg%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1242777246 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\X0FJdGJ2OUVBQVdNVlNob1h1UXZuNDJWaUV2cyZmaWQ9SW5ib3gmc29ydD1kYXRlJm9yZGVyPWR vd24mc3RhcnRNaWQ9MCZmaWx0ZXJCeT0mLnJhbmQ9MTk1NTcyNDYwNSYuanNyYW5kPTY3MzQ0MjQEdmlz aWJsZQMxBHd0AzE-[1] not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\_GJjZp0obIWwACNxi%2FB%3DoKnzBUSO5.4-%2FJ%3D1243292012717995%2FK%3DXV7OzSFqk1R4buC1PArm2w%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\VU3QXTMU\_GJjZp0obIWwACNxi%2FB%3DoKnzBUSO5.4-%2FJ%3D1243292012717995%2FK%3DXV7OzSFqk1R4buC1PArm2w%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[2].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\24319178;noperf=1;alias=93245389;noaddonpl=y;kvcity=ephrata;kvst=pa;kvdma=h arrisburg;kvco=usa;kvzip=17522;kvmn=93245389;target=_blank;aduho=240;grp=19177635 9;misc=191776359[1] not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\7OWV5CAV0XGRUCAL6CQCFCA6M1BGDCA70O3L6CAP1AYGMCA53QA3FCA5YXUXKCASC8D3OCARCDV 6GCAWUXX7ECA9V1OU2CAQ0QO0BCAOXD5FCCAR0SCPDCAFCDMSGCA5HQ1T6CAYN0DBVCAQXMY3WCACMIQQ NCAVW4KCOCAEU5KK3 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\AGJjZp0ocJ7EAA8Zm%2FB%3Dm_CWBNj8a24-%2FJ%3D1243359153370415%2FK%3D30XT6vP0LvDLqXVa0tmkmQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\AGJjZp0ocJ7EAA8Zm%2FB%3Dm_CWBNj8a24-%2FJ%3D1243359153370415%2FK%3D30XT6vP0LvDLqXVa0tmkmQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[2].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\djlFQUFEMmdTaE5YUmdzMFRCbWRUakEsMV8zNjkwX0FJWmJ2OUVBQUg4TVNoTlc0QVA2eGlTVmR wZywmaGFzaD0wY2ZiZTlmNDRlMGMyN2M2YmE5N2UyZDM2NmNlYTA1OCYuanNyYW5kPTI5NTk0NDcEdmlz aWJsZQMxBHd0AzE-[1] not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\G_Rvw-%2FJ%3D1243361733233244%2FK%3D5pgIRx__pK7Du1bFAMc5Yw%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1243363555 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\G_Rvw-%2FJ%3D1243361733233244%2FK%3D5pgIRx__pK7Du1bFAMc5Yw%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1243364004 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\G_Rvw-%2FJ%3D1243365090397210%2FK%3D0yndF1Hsl_ptCzybMQW20g%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1243365093 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\j8Yno-%2FJ%3D1242739390355232%2FK%3DVYDpBox0Edskumq_qTmD5A%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1242765672 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\JnN0YXJ0TWlkPTAmZmlsdGVyQnk9JnRvcF9icHJlc3NfZGVsZXRlPTEmY21kPW1zZy5kZWxldGU mbWNydW1iPVdPQ0IyNkwvL2xTJi5yYW5kPTEzNDMwMDQ1MjEmY2xlYW4mLmpzcmFuZD05NTMwNDc2BHZp c2libGUDMQR3dAMx[2] not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\KGJjZp0ocMcEACjyB%2FB%3DuGbbCdG_Rvw-%2FJ%3D1243361729796334%2FK%3D5aahMOndaxDlNQ5h8ncOaQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\kGJjZp0ocPuIAA7Nn%2FB%3DR6gJCtG_Rvw-%2FJ%3D1243365090397210%2FK%3D0yndF1Hsl_ptCzybMQW20g%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\pGJjZp0ob87MAAEGI%2FB%3DCnaXBdgnMuk-%2FJ%3D1243345843174713%2FK%3DyAQI9cSxTxrzQ8.u_gjC4Q%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\U2h2SXZRbzlURTY2dHdBLDFfMjE4N19BSWxidjlFQUFJOUZTaHV3cnduVEN4UWpkMmcsJmhhc2g 9ZDFkYjkxNzAyOWM2ZmJjNDYzMjQ2MzQyODMyMjNmMDUmLmpzcmFuZD0xODI5NjgwBHZpc2libGUDMQR3 dAMwLjk5NDc3MQ–[1] not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\VHIS4CA9NDECRCABZPO26CAZ3BV60CAYN6P12CAX600LWCA4TZ81XCAZBXHECCA22A2EICAS6DB N1CA31NC4GCAU7YAE0CAT5GWEZCA8D5R91CA3MXITOCA4FWSWMCAK47O9ECA6VPYA2CANA8UWZCAJVO3J 3CADRCD5OCAWHFJXN not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\SSNI2B7Z\_GJjZp0obIWwACNxi%2FB%3DoKnzBUSO5.4-%2FJ%3D1243292012717995%2FK%3DXV7OzSFqk1R4buC1PArm2w%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\.GJjZp0oYDfIAB6_s%2FB%3DNN4.AtG_Rvw-%2FJ%3D1243090418584124%2FK%3DK9lyVGtlIv.hHGZHMhrYYg%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\2w%252FA%253D5404709%252FR%253D0%252F%252A%2524%2Chttp%253A%252F%252Fus.mc374.mail.yahoo.com%252Fdarla%252Fmd[1].php%253Fen%253Dcp1252%2C%7C238933%7C19;sz=728x90;ord=1243292528 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\64TBLCAUKOTAACAWISSX7CAR69AA6CAZ48THQCA8JK50VCAMJH5B0CAC2AMFTCANSOX97CAVYK3 VQCA9BQ8M2CA7AKS92CAIU3SW4CAVVXHOSCAHX5OSXCAXDQB6MCA1Z9PWRCAFZVHCYCAY1YV1ICA8RTZM ECABTPK6GCAFY5PAW not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\dWxhcgRQYXJ0VHlwZQNZYWhvbyEEUmVzUG9zQQMwBFJlc1Bvc1IDMARTcmNoQ3VycgNtZXNzYWd lBFNyY2hEZXN0A21lc3NhZ2V2aWV3BF9RdWVyeUlkAzE0OTUyNzkwMDA0YTFjM2VkNjk5OTA4BF9TAzE1 MDUwMDYxMw–[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\G_fyU-%2FJ%3D1242739386624609%2FK%3D24NZpWQknN.5v_w86497KQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1242765663 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\G_Rvw-%2FJ%3D1242933642127856%2FK%3DzG_4Z_p9dQ4zqygdbLaAFQ%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1242935046 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\G_Rvw-%2FJ%3D1243090145976338%2FK%3DIR6j2ChWMwg8Xpjiq.zw8g%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1243090302 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\G_Rvw-%2FJ%3D1243361733233244%2FK%3D5pgIRx__pK7Du1bFAMc5Yw%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1243363413 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\j8Yno-%2FJ%3D1242739390355232%2FK%3DVYDpBox0Edskumq_qTmD5A%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1242739479 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\j8Yno-%2FJ%3D1242739390355232%2FK%3DVYDpBox0Edskumq_qTmD5A%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1242765683 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\K48QKCAZCYTKYCAS4215PCAS9UPEXCAS3TPW1CABSQCM9CA6C1C9JCAKCOH0DCAM6Z3LLCA0SAV 9ECA9GATOJCACY8JGGCAIIU3U1CANV0T3UCAUKXVM0CA1ZGWR2CA0KZWFKCAKH0RWFCA07SLY7CAXE15H HCAUWRD4RCA2SUQ5J not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\KGJjZp0ocMcEACjyB%2FB%3DuGbbCdG_Rvw-%2FJ%3D1243361729796334%2FK%3D5aahMOndaxDlNQ5h8ncOaQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\KM85TCAN7IVUZCAV5VT4NCAVD5A96CA3I3TZDCAWXEYT7CA2UE3PCCADJ8NYECAWL8IFGCA3EAX Q8CAKTZLU8CAHVS15DCA83VPKWCACRZJRPCA1VSOW9CAYRHXEWCAM14VTWCAZGEA4ACAXA1PEXCAJRP0A JCAE765LGCAAQC3Y1 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\N78XFCABI3WV9CAVAT6SECAWDVY2TCABBW4B8CAWIAI8MCACDAA62CAXSL2MBCAFOOTMMCAJHFD OTCASGSBOHCAZDI0X1CANI9DH3CAK7TQU6CAYFUHA5CASN1S92CA2H9AWZCAECS83ECA2GRRWTCAGH1SV MCAFT8UIFCAIJWVS0 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\nGJjZp0ocJPgAB4IV%2FB%3DZ3PdCdG_fyw-%2FJ%3D1243358456596101%2FK%3DMzpHKA.1l724hilGHifPnQ%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\v=5%3Bm=2%3Bl=3400%3Bc=17812%3Bb=88445%3Bp=ui%3D33RbnFaP98J_FNAIS4TGl-H_5rEqKfPogO8wzPPA%3Btr%3DBQ2p3oHP4k1%3Btm%3D0-0%3Bts=20090519092313%3Bdct=;ord=20090519092313[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\v=5%3Bm=2%3Bl=3730%3Bc=14132%3Bb=68701%3Bp=ui%3D33RbnFaP98J_FNAIS4TGl-H_5rEqKfPogO8wzPPA%3Btr%3DEVijTYc-h54%3Btm%3D0-0%3Bts=20090519210857%3Bdct=;ord=20090519210857[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\VGJjZp0ob6jkADgW_%2FB%3DGonjCNG_Rvw-%2FJ%3D1243343417989185%2FK%3DXccXrf6MxPYpIoHVOL8Agw%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\yGJjZp0ocHaMACp2Y%2FB%3DQWnmCdG_XMA-%2FJ%3D1243356579796573%2FK%3DARHy4qES5nbTbU273Wu1dg%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\yGJjZp0ocHaMACp2Y%2FB%3DQWnmCdG_XMA-%2FJ%3D1243356579796573%2FK%3DARHy4qES5nbTbU273Wu1dg%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[2].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\HI0EOOVC\zGJjZp0oYEnIADDEF%2FB%3Dr0sLAdj8a24-%2FJ%3D1243091570921599%2FK%3DMLtfQQmAg3mxbcEX3I3xlQ%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\20C7ACA9ZT8X4CAC9GU9ACATLV8WQCABPLF75CAMH0MDVCAOKXGW0CABMC8D6CAA6BB23CAXV0H 9VCAU0VZO5CA4D163LCA9OU7NKCA21BY0XCAL638FBCAO1T0G8CAHLXDCWCA34BWVNCANGVMJ4CAKFYQ4 OCAO5DPX0CANTB4YV not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\3365090397210%252FK%253D0yndF1Hsl_ptCzybMQW20g%252FA%253D5404709%252FR%253D0%252F_%2524%252Chttp%253A%252F%252Fus.mc374.mail.yahoo.com%252Fdarla%252Fmd[1].php%253Fen%253Dcp1252 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\7EIANCA7JQNZZCAYRDWF3CAI9H0ADCA72D1CACAY1APBSCA2JRHO7CABR6UT1CAP7H5SNCAVO9E XJCAO855P3CAZYYAFGCAHO4UBVCACROORNCAIY9RBCCAAAJXROCAE148O4CAIC7SD2CARXEV8KCAFCR20 CCATL3IITCAECYDIW not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\8MDZPCA6MEVMCCAW9RSJUCATTS7J2CAL25YKZCAF7XM9UCAN0E8WWCAMJFRBRCA7XD0YICA8QZ1 HRCAYN053RCAVPK24JCAVG6AGYCAUWGPKVCA8RV9YRCAW7GVSPCAIUI8NYCAUU1EHTCAJKFA8SCA4CNNJ UCAUOC9VICAFLCOO3 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\cGJjZp0ob9asACRos%2FB%3Dc1v_A9j8a5o-%2FJ%3D1243346347715031%2FK%3DfM3n7xWCEXYRkCLaykVSLA%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\CGJjZp0ocPkoABwTd%2FB%3D_I0HCtG_Rvw-%2FJ%3D1243364938651614%2FK%3DPkjiDkkUjmUsbzqUN6e0iA%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\dGFydE1pZD0wJmZpbHRlckJ5PSZ0b3BfYnByZXNzX2RlbGV0ZT0xJmNtZD1tc2cuZGVsZXRlJm1 jcnVtYj1XT0NCMjZMLy9sUyYucmFuZD0xMzQzMDA0NTIxJmNsZWFuJi5qc3JhbmQ9OTUzMDQ3NgR2aXNp YmxlAzEEd3QDMQ–[1] not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\G%255FRvw%252D%252FJ%253D1243343417989185%252FK%253DXccXrf6MxPYpIoHVOL8Agw%252FA%253D5406807%252FR%253D0%252F%252A%2524,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\G%255FRvw%252D%252FJ%253D1243343417989185%252FK%253DXccXrf6MxPYpIoHVOL8Agw%252FA%253D5406807%252FR%253D0%252F%252A%2524,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[2].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\G_fyU-%2FJ%3D1242739386624609%2FK%3D24NZpWQknN.5v_w86497KQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1242739499 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\G_Rvw-%2FJ%3D1243090145976338%2FK%3DIR6j2ChWMwg8Xpjiq.zw8g%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1243090256 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\G_Rvw-%2FJ%3D1243090418584124%2FK%3DK9lyVGtlIv.hHGZHMhrYYg%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1243090538 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\G_Rvw-%2FJ%3D1243361733233244%2FK%3D5pgIRx__pK7Du1bFAMc5Yw%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].php%3Fen%3Dcp1252,;ord=1243362811 not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\KGJjZp0ocMcEACjyB%2FB%3DuGbbCdG_Rvw-%2FJ%3D1243361729796334%2FK%3D5aahMOndaxDlNQ5h8ncOaQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\KGJjZp0ocMcEACjyB%2FB%3DuGbbCdG_Rvw-%2FJ%3D1243361729796334%2FK%3D5aahMOndaxDlNQ5h8ncOaQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[2].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\KGJjZp0ocMcEACjyB%2FB%3DuGbbCdG_Rvw-%2FJ%3D1243361729796334%2FK%3D5aahMOndaxDlNQ5h8ncOaQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[3].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\KGJjZp0ocMcEACjyB%2FB%3DuGbbCdG_Rvw-%2FJ%3D1243361729796334%2FK%3D5aahMOndaxDlNQ5h8ncOaQ%2FA%3D5406807%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[4].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\kGJjZp0ocPuIAA7Nn%2FB%3DR6gJCtG_Rvw-%2FJ%3D1243365090397210%2FK%3D0yndF1Hsl_ptCzybMQW20g%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\LGJjZp0oQFygADyao%2FB%3Dnv8XBNG_Rvw-%2FJ%3D1242568489090627%2FK%3DeCWebGoxDCWn.ikwECEMhw%2FA%3D5404709%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\TlNXU2dmMDdBRlVsQiUyRklkUzgsMV8xNDIxMl9BSWxidjlFQUFGalhTZ1pBYVFDbzRCU3ElMkZ UYywmaGFzaD1lYjY1NTllZmYzOGNmMDBmYzdiMTA2MGNmNjQwMWY4MiYuanNyYW5kPTMzMDQwOTUEdmlz aWJsZQMxBHd0AzE-[1] not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\v=5%3Bm=2%3Bl=3730%3Bc=17812%3Bb=88444%3Bp=ui%3D33RbnFaP98J_FNAIS4TGl-H_5rEqKfPogO8wzPPA%3Btr%3DAKk7bq2Zon2%3Btm%3D0-0%3Bts=20090519210745%3Bdct=;ord=20090519210745[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\v=5%3Bm=2%3Bl=3732%3Bc=17812%3Bb=88444%3Bp=ui%3D33RbnFaP98J_FNAIS4TGl-H_5rEqKfPogO8wzPPA%3Btr%3DBeSSr92N3Fs%3Btm%3D0-0%3Bts=20090518212305%3Bdct=;ord=20090518212305[1].htm not found! File\Folder C:\Documents and Settings\Christine\Local Settings\Temp\Temporary Internet Files\Content.IE5\743KAJS4\xGJjZp0oTP_IABOsf%2FB%3DqquwC9G_Rvw-%2FJ%3D1242775539966583%2FK%3De70M8QdHrhotNuUAbh3BSw%2FA%3D5404712%2FR%3D0%2F%2A%24,http%3A%2F%2Fus.mc374.mail.yahoo.com%2Fdarla%2Fmd[1].htm not found! File\Folder C:\WINDOWS\temp\ZAP5.tmp\System.Windows.Forms.dll not found! File\Folder C:\WINDOWS\temp\ZAP381.tmp\System.Windows.Forms.dll not found! File\Folder C:\WINDOWS\temp\NDP1.1sp1-KB2656370-X86\NDP1.1sp1-KB2656370-X86-msi.0.log not found! File\Folder C:\WINDOWS\temp\NDP1.1sp1-KB2656370-X86\NDP1.1sp1-KB2656370-X86-wrapper.log not found! File move failed. C:\WINDOWS\temp\Perflib_Perfdata_44c.dat scheduled to be moved on reboot. PendingFileRenameOperations files… Registry entries deleted on Reboot…
Hello anirishfool,

You should have some functionality back now and OTL should run without difficulty. I'd like to get some further diagnostic scans.

  • Re-run OTL (it should be located on your desktop).
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Next

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
In your next post please provide the following:
  • OTL.txt
  • Gmer.txt
Ok, Done -

Again, there was no "Extras.txt" from OTL, but the other stuff is below.

OTL logfile created on: 9/13/2012 10:24:27 PM - Run 5
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Documents and Settings\Christine\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.97 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 69.50% Memory free
2.82 Gb Paging File | 2.28 Gb Available in Paging File | 81.04% Paging File free
Paging file location(s): C:\pagefile.sys 1024 1024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 59.56 Gb Free Space | 39.98% Space Free | Partition Type: NTFS
Drive G: | 931.28 Gb Total Space | 697.16 Gb Free Space | 74.86% Space Free | Partition Type: FAT32

Computer Name: OPTIPLEX | User Name: Christine | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Christine\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Adobe\Reader 8.0\Reader\ViewerPS.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Brother\BrUtilities\BrLogAPI.dll ()


========== Services (SafeList) ==========

SRV - (navapsvc) – C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (NIS) – C:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe (Symantec Corporation)
SRV - (PDFProFiltSrvPP) – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
SRV - (BrYNSvc) – C:\Program Files\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (AdobeActiveFileMonitor7.0) – C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (nmraapache) – C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe (Pure Networks, Inc.)
SRV - (nmservice) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Pure Networks, Inc.)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (SymWSC) – C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (Symantec Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\hpzipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (SYMREDRV) – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMREDRV.SYS File not found
DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\NIS\1008030.006\SYMNDIS.SYS File not found
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\NIS\1008030.006\SYMIDS.SYS File not found
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\NIS\1008030.006\SYMFW.SYS File not found
DRV - (SYMDNS) – C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMDNS.SYS File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (EraserUtilDrvI10) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI10.sys File not found
DRV - (DSproct) – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys File not found
DRV - (Changer) – File not found
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\VirusDefs\20120913.019\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\VirusDefs\20120913.019\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\IPSDefs\20120913.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\BASHDefs\20120905.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\NIS\1308000.00E\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\NIS\1308000.00E\srtspx.sys (Symantec Corporation)
DRV - (ccSet_NIS) – C:\WINDOWS\system32\drivers\NIS\1308000.00E\ccSetx86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NIS\1308000.00E\SymEFA.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\NIS\1308000.00E\symtdi.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NIS\1308000.00E\SymDS.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NIS\1308000.00E\Ironx86.sys (Symantec Corporation)
DRV - (iPodDrv) – C:\WINDOWS\system32\drivers\iPodDrv.sys (Windows ® Codename Longhorn DDK provider)
DRV - (ssadbus) – C:\WINDOWS\system32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (BrUsbSIb) – C:\WINDOWS\system32\drivers\BrUsbSib.sys (Brother Industries Ltd.)
DRV - (BrSerIb) – C:\WINDOWS\system32\drivers\BrSerIb.sys (Brother Industries Ltd.)
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (pnarp) – C:\WINDOWS\system32\drivers\pnarp.sys (Pure Networks, Inc.)
DRV - (purendis) – C:\WINDOWS\system32\drivers\purendis.sys (Pure Networks, Inc.)
DRV - (dsiarhwprog) – C:\WINDOWS\system32\drivers\dsiarhwprog.sys (Thesycon GmbH, Germany)
DRV - (atiide) – C:\WINDOWS\system32\drivers\atiide.sys (ATI Technologies Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (SenFiltService) – C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070130
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070130
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/hws/sb/dell-usuk-rel…html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {27A3715C-E3A7-4C4D-A599-A4F164BB845E}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{27A3715C-E3A7-4C4D-A599-A4F164BB845E}: "URL" = http://www.google.com/search?q={searchTerm…tPage}&rlz=
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}
IE - HKCU\..\SearchScopes\{C46446CC-2AF7-4BF2-ABD4-EDA62E8E50FF}: "URL" = http://websearch.ask.com/redirect?client=i…21-1CD66B1AAB2A
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledAddons: [removed]:1.0
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}:6.0.33
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=DAT&o=15236&locale=en_US&apn_uid=2AEF9D5D-3351-4500-AA58-97C900A14FF4&apn_ptnrs=FC&apn_sauid=E9EDF1C5-B517-467A-9921-1CD66B1AAB2A&apn_dtid=YYYYYYYYUS&&q="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@doubletwist.com/NPPodcast: C:\Program Files\Common Files\doubleTwist\NPPodcast.dll (doubleTwist Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2009/11/16 13:32:33 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.17.4: C:\Program Files\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2629: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=5.2.5.48: C:\Program Files\Musicnotes\npsibelius.dll ()
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\PROGRA~1\SONYON~1\npsoe.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Homepage Print 2\Firefox [2012/02/24 19:45:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\IPSFFPlgn\ [2012/08/22 17:30:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn\ [2012/09/12 22:49:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/06 20:19:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/09/06 20:19:37 | 000,000,000 | —D | M]

[2010/09/19 09:23:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Christine\Application Data\Mozilla\Extensions
[2012/05/02 10:09:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Christine\Application Data\Mozilla\Firefox\Profiles\oz8clgls.default\extensions
[2010/12/21 21:20:29 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Christine\Application Data\Mozilla\Firefox\Profiles\oz8clgls.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/09/06 20:19:30 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/09/06 20:19:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/09/06 20:19:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/08/04 12:51:12 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/09/06 20:19:50 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/08/30 07:31:24 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/08/30 07:31:24 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/04 06:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (PodcastBHO Class) - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O2 - BHO: (Homepage Print 2BHO) - {EFC91ACA-519F-428D-8472-81E158609D25} - C:\Program Files\Homepage Print 2\IEBand.dll (CORPUS CORPORATION)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Homepage Print 2) - {C4FB9EEC-5B29-486B-ACD1-D93A4396E567} - C:\Program Files\Homepage Print 2\IEBand.dll (CORPUS CORPORATION)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort12reminder] C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: taxactonline.com ([www] https in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.support.gateway.com/support/pro…r/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} http://a516.g.akamai.net/f/516/25175/7d/ru…cat-no-eula.cab (Citrix ICA Client)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} http://www.symantec.com/techsupp/asa/ss/sa…abs/tgctlsr.cab (Reg Error: Key error.)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1005.cab (MySpace Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {BCBC9371-9827-11DA-A72B-0800200C9A66} http://merillat.view22.com/release_3_9_177/View22RTEv4.cab (View22RTEv4 Class)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (CRLDownloadWrapper Class)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.microsoft.com/download/7/E…04/clearadj.cab (CTAdjust Class)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://liasophia.webex.com/client/T26L/nbr/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{66C4589B-81D7-4B7E-BC0F-79C9D08DEC60}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Pure Networks, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\dimsntfy: DllName - () - File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Christine\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Christine\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/29 16:55:11 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/07/17 17:40:58 | 000,000,000 | —D | M] - G:\autorun – [ FAT32 ]
O32 - AutoRun File - [2002/10/17 09:56:50 | 000,000,036 | RH– | M] () - G:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/09/13 19:42:52 | 000,000,000 | —D | C] – C:\_OTL
[2012/09/13 18:20:51 | 000,600,064 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Christine\Desktop\OTL.exe
[2012/09/13 18:12:26 | 001,659,808 | —- | C] (Bleeping Computer, LLC) – C:\Documents and Settings\Christine\Desktop\rkill.exe
[2012/09/11 10:23:06 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Christine\Desktop\HiJackThis.exe
[2012/09/06 20:19:26 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/09/03 22:28:45 | 000,157,680 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/09/03 22:28:45 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/09/03 22:28:45 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/08/20 18:01:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Norton

========== Files - Modified Within 30 Days ==========

[2012/09/13 22:28:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1755230115-917001253-2734630794-1006UA.job
[2012/09/13 22:28:00 | 000,000,232 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/09/13 21:53:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/13 21:36:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/09/13 20:53:00 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/13 18:21:51 | 000,154,793 | —- | M] () – C:\Documents and Settings\Christine\Desktop\OTL Frontpage.jpg
[2012/09/13 18:20:52 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Christine\Desktop\OTL.exe
[2012/09/13 18:12:29 | 001,659,808 | —- | M] (Bleeping Computer, LLC) – C:\Documents and Settings\Christine\Desktop\rkill.exe
[2012/09/13 10:28:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1755230115-917001253-2734630794-1006Core.job
[2012/09/13 09:46:09 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/09/12 22:54:35 | 000,093,368 | —- | M] () – C:\Documents and Settings\Christine\Desktop\Flowers.jpg
[2012/09/12 22:47:16 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/09/12 22:46:45 | 2111,934,464 | -HS- | M] () – C:\hiberfil.sys
[2012/09/12 19:02:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/09/12 16:58:17 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/09/12 08:10:08 | 000,002,515 | —- | M] () – C:\Documents and Settings\Christine\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2012/09/12 03:05:59 | 000,689,969 | —- | M] () – C:\WINDOWS\System32\drivers\NIS\1308000.00E\Cat.DB
[2012/09/11 09:59:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Christine\Desktop\HiJackThis.exe
[2012/09/10 15:34:57 | 000,002,497 | —- | M] () – C:\Documents and Settings\Christine\Desktop\Microsoft Office Word 2003.lnk
[2012/09/09 12:58:25 | 000,696,520 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/09/09 12:58:25 | 000,073,416 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/09/03 13:55:01 | 000,001,858 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/08/28 20:24:56 | 000,477,168 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\npdeployJava1.dll
[2012/08/28 20:24:53 | 000,473,072 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2012/08/28 20:10:12 | 000,157,680 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/08/28 20:10:07 | 000,149,488 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/08/28 20:09:57 | 000,149,488 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/08/28 18:39:23 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/08/22 19:25:54 | 000,008,942 | —- | M] () – C:\WINDOWS\System32\drivers\NIS\1308000.00E\VT20120731.038
[2012/08/22 17:26:39 | 000,002,018 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton Internet Security.LNK
[2012/08/20 18:13:41 | 000,141,944 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/08/20 18:13:41 | 000,060,872 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2012/08/20 18:13:41 | 000,007,468 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/08/20 18:13:41 | 000,000,806 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/08/15 03:14:02 | 000,207,304 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/08/15 03:11:33 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK

========== Files Created - No Company Name ==========

[2012/09/13 18:21:51 | 000,154,793 | —- | C] () – C:\Documents and Settings\Christine\Desktop\OTL Frontpage.jpg
[2012/09/12 22:49:28 | 000,093,368 | —- | C] () – C:\Documents and Settings\Christine\Desktop\Flowers.jpg
[2012/06/25 00:49:52 | 000,165,560 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/05/09 19:48:38 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2012/05/08 19:39:54 | 000,593,920 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2012/05/08 19:38:56 | 000,001,107 | —- | C] () – C:\WINDOWS\ATICIM.INI
[2012/03/04 22:18:22 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2012/02/24 19:47:25 | 000,000,000 | RHS- | C] () – C:\WINDOWS\FFSSET.BIN
[2012/02/24 19:22:48 | 000,000,737 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2012/02/24 19:22:48 | 000,000,093 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2012/02/24 19:22:25 | 000,003,303 | —- | C] () – C:\WINDOWS\BRPARAM.INI
[2012/02/24 19:21:08 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\BRTCPCON.DLL
[2012/02/24 19:21:08 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\BRLMW03A.INI
[2012/02/24 19:20:40 | 000,000,086 | —- | C] () – C:\WINDOWS\Brfaxrx.ini
[2012/02/24 19:20:40 | 000,000,000 | —- | C] () – C:\WINDOWS\brdfxspd.dat
[2012/02/16 02:37:44 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/02/13 20:49:13 | 000,034,296 | —- | C] () – C:\WINDOWS\System32\drivers\mbamcatchme.sys
[2011/01/26 07:57:24 | 000,009,216 | -H– | C] () – C:\Documents and Settings\Christine\fbchathistory.dat
[2010/10/27 17:50:56 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2009/03/07 11:55:07 | 000,047,534 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LuUninstall.LiveUpdate
[2007/04/29 23:45:44 | 000,010,752 | —- | C] () – C:\Documents and Settings\Christine\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/08 00:55:25 | 000,000,132 | —- | C] () – C:\Documents and Settings\Christine\Local Settings\Application Data\fusioncache.dat

========== LOP Check ==========

[2012/02/24 19:20:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ControlCenter4
[2009/03/26 23:08:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2007/04/11 16:45:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2009/12/25 21:11:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Musicnotes
[2008/12/29 16:54:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2012/08/20 17:52:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2012/02/23 21:13:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PrinterShare
[2012/02/24 19:16:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/09/28 18:38:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Screentime
[2008/12/27 19:26:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2008/07/08 17:23:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/09/05 08:01:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\View22
[2012/03/04 22:16:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2009/04/26 20:46:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2012/02/24 19:17:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\zeon
[2010/12/28 13:38:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/28 20:49:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/31 14:09:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2012/03/28 13:28:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\ControlCenter4
[2011/05/10 14:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\Foxit Software
[2009/03/10 21:24:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\OpenOffice.org
[2012/02/26 19:53:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\PC-FAX TX
[2011/11/14 21:22:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\Softland
[2008/03/05 13:08:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\WebEx
[2008/07/23 21:12:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Christine\Application Data\WinPatrol
[2012/09/13 22:28:00 | 000,000,232 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >
[2002/10/07 20:35:23 | 001,020,000 | —- | M] (Microsoft Corporation) – C:\EBU1.exe
[2010/12/01 21:54:22 | 027,024,112 | —- | M] (Microsoft Corporation) – C:\PowerPointViewer.exe

< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 06:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/04 06:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe

< MD5 for: SVCHOST.EXE >
[2008/04/13 20:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 20:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2004/08/04 06:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/04 06:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/04 06:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: ST3160812AS
Partitions: 2
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 - Fixed\thard disk media
Interface type: USB
Media Type: Fixed\thard disk media
Model: WD 10EACS External USB Device
Partitions: 1
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: Brother MFC-J625DW USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 0.00GB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 149.00GB
Starting Offset: 41126400
Hidden sectors: 0


DeviceID: Disk #1, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 932.00GB
Starting Offset: 32256
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\CCC\2.0.0.0__90ba9c70f846762e] -> C:\WINDOWS\WinSxS\MSIL_CCC_90ba9c70f846762e_2.0.0.0_x-ww_c7ed2bb0 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\CLI\2.0.0.0__90ba9c70f846762e] -> C:\WINDOWS\WinSxS\MSIL_CLI_90ba9c70f846762e_2.0.0.0_x-ww_42656733 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\LOG\2.0.3693.42530__90ba9c70f846762e] -> C:\WINDOWS\WinSxS\MSIL_LOG_90ba9c70f846762e_2.0.3693.42530_x-ww_47e32df4 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\MOM\2.0.0.0__90ba9c70f846762e] -> C:\WINDOWS\WinSxS\MSIL_MOM_90ba9c70f846762e_2.0.0.0_x-ww_a60193a8 -> Junction

< End of report >
=======================================================================

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-09-14 07:52:15
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 ST3160812AS rev.3.ADJ
Running: gmer.exe; Driver: C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\uwldapod.sys


—- System - GMER 1.0.15 —-

SSDT 8A0F3FD0 ZwAlertResumeThread
SSDT 89EFCD90 ZwAlertThread
SSDT 8A103A18 ZwAllocateVirtualMemory
SSDT 89F64958 ZwAssignProcessToJobObject
SSDT 8A460C90 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xB5D9BD40]
SSDT 8A0FFFC0 ZwCreateMutant
SSDT 8A0CBAC8 ZwCreateSymbolicLinkObject
SSDT 8A0E00E8 ZwCreateThread
SSDT 89F64A18 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xB5D9BFC0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xB5D9C680]
SSDT 8A324910 ZwDuplicateObject
SSDT 89F08A60 ZwFreeVirtualMemory
SSDT 8A124B08 ZwImpersonateAnonymousToken
SSDT 8A0F3EF0 ZwImpersonateThread
SSDT 8A316B10 ZwLoadDriver
SSDT 8A5E8E78 ZwMapViewOfSection
SSDT 8A0FFF00 ZwOpenEvent
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwOpenKey [0xB5D9C430]
SSDT 89F915E8 ZwOpenProcess
SSDT 8A2F6B78 ZwOpenProcessToken
SSDT 89F67BF8 ZwOpenSection
SSDT 8A131D58 ZwOpenThread
SSDT 8A0CBB98 ZwProtectVirtualMemory
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwRenameKey [0xB5D9CBF0]
SSDT 8A352738 ZwResumeThread
SSDT 8A3671E8 ZwSetContextThread
SSDT 8A34BDB0 ZwSetInformationProcess
SSDT 8A0E5F08 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xB5D9C910]
SSDT 89F67CB8 ZwSuspendProcess
SSDT 8A3527F8 ZwSuspendThread
SSDT 8A2E2408 ZwTerminateProcess
SSDT 8A5D41A8 ZwTerminateThread
SSDT 8A381050 ZwUnmapViewOfSection
SSDT 8A2FE958 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 2DC4 8050467C 8 Bytes CALL F8DA3F96
.text ntkrnlpa.exe!ZwCallbackReturn + 2F30 805047E8 4 Bytes [E8, 71, 36, 8A]
.text ntkrnlpa.exe!ZwCallbackReturn + 2FE0 80504898 6 Bytes [08, 24, 2E, 8A, A8, 41]
.text ntkrnlpa.exe!ZwCallbackReturn + 3030 805048E8 4 Bytes JMP CB6CD31C
? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xB8BFE000, 0x1C5D38, 0xE8000020]
init C:\WINDOWS\system32\drivers\Senfilt.sys entry point in "init" section [0xB5F62A00]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[1660] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 011C0C00 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[1660] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 013F7B4C C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[1660] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 013F7B29 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[1660] kernel32.dll!ValidateLocale + B130 7C844958 7 Bytes JMP 011C3FAC C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[1660] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 013F7AAA C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi anirishfool,

Again, there was no "Extras.txt" from OTL,

It will only produce and Extras.txt on subsequent runs if we request it.


Download AdwCleaner from here and save it to your desktop.
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
Next

Locate Malwarebytes' Anti-Malware.
  • Double - click the MBAM icon to launch the program.
  • Once the program has loaded, select the Update tab to get the latest updates before performing the scan.
  • Select Perform quick scan, then click Scan.

    [external image: Posted Image]

  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Next

Please run Eset Online Scanner

Administrator rights are required to run ESET Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
In your next post please provide the following:
  • AdwCleaner log
  • MBAM log
  • ESET log.txt
ADWARE: # AdwCleaner v2.001 - Logfile created 09/14/2012 at 21:54:26 # Updated 09/09/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Christine - OPTIPLEX # Boot Mode : Normal # Running from : C:\Documents and Settings\Christine\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\xbk9icq2.default\searchplugins\Askcom.xml File Deleted : C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\xbk9icq2.default\searchplugins\Conduit.xml File Deleted : C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job Folder Deleted : C:\Documents and Settings\All Users\Application Data\Trymedia Folder Deleted : C:\Documents and Settings\All Users\Application Data\WeCareReminder Folder Deleted : C:\Documents and Settings\AOM\Local Settings\Application Data\AskToolbar Folder Deleted : C:\Documents and Settings\Carter\Local Settings\Application Data\AskToolbar Folder Deleted : C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\e4cotmtw.default\extensions\wecarereminder@bryan Folder Deleted : C:\Documents and Settings\Chris\Application Data\OpenCandy Folder Deleted : C:\Documents and Settings\Chris\Local Settings\Application Data\AskToolbar Folder Deleted : C:\Documents and Settings\Christine\Local Settings\Application Data\AskToolbar Folder Deleted : C:\Documents and Settings\Kids\Local Settings\Application Data\AskToolbar Folder Deleted : C:\Documents and Settings\Kyla\Local Settings\Application Data\AskToolbar Folder Deleted : C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\xbk9icq2.default\ConduitCommon Folder Deleted : C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\xbk9icq2.default\CT3018509 Folder Deleted : C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\xbk9icq2.default\extensions\{22dfbf5b-a7cd-4b25-9471-3dc68c71855f} Folder Deleted : C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\xbk9icq2.default\extensions\[removed] Folder Deleted : C:\Documents and Settings\Ryan\Local Settings\Application Data\AskToolbar Folder Deleted : C:\Documents and Settings\stoner\Local Settings\Application Data\AskToolbar Folder Deleted : C:\Program Files\Ask.com Folder Deleted : C:\WINDOWS\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} ***** [Registry] ***** Key Deleted : HKCU\Software\APN Key Deleted : HKCU\Software\AskToolbar Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Key Deleted : HKLM\Software\APN Key Deleted : HKLM\Software\AskToolbar Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4FBBF769-ECEB-420A-B536-133B1D505C36} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLL Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F773BB94-6C19-4643-A570-0E429103D1C3} Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder Key Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder.1 Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F773BB94-6C19-4643-A570-0E429103D1C3} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12920CF-BE13-4C09-890D-1B6EFFFE2FBE} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC5B6CDA-8F90-4740-9A8C-28AC5D3C73FE} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 Restored : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] -\\ Mozilla Firefox v15.0.1 (en-US) Profile name : default File : C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\e4cotmtw.default\prefs.js C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\e4cotmtw.default\user.js … Deleted ! Deleted : user_pref("browser.search.defaultengine", "Ask.com"); Deleted : user_pref("browser.search.defaultenginename", "Ask.com"); Deleted : user_pref("browser.search.order.1", "Ask.com"); Deleted : user_pref("browser.search.selectedEngine", "Ask.com"); Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://search.yahoo.com/search?fr=ffds1&p="); Profile name : default File : C:\Documents and Settings\Kids\Application Data\Mozilla\Firefox\Profiles\nx4g0yxx.default\prefs.js Deleted : user_pref("browser.search.defaultengine", "Ask.com"); Deleted : user_pref("browser.search.defaultenginename", "Ask.com"); Deleted : user_pref("browser.search.order.1", "Ask.com"); Deleted : user_pref("browser.search.selectedEngine", "Ask.com"); Deleted : user_pref("extensions.asktb.ff-original-keyword-url", ""); Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=DAT&o=15236&locale=e[…] Profile name : default File : C:\Documents and Settings\Christine\Application Data\Mozilla\Firefox\Profiles\oz8clgls.default\prefs.js Deleted : user_pref("browser.search.defaultengine", "Ask.com"); Deleted : user_pref("browser.search.defaultenginename", "Ask.com"); Deleted : user_pref("browser.search.order.1", "Ask.com"); Deleted : user_pref("browser.search.selectedEngine", "Ask.com"); Deleted : user_pref("extensions.asktb.ff-original-keyword-url", ""); Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=DAT&o=15236&locale=e[…] Profile name : default File : C:\Documents and Settings\Kyla\Application Data\Mozilla\Firefox\Profiles\qzvaya82.default\prefs.js Deleted : user_pref("browser.search.defaultengine", "Ask.com"); Deleted : user_pref("browser.search.defaultenginename", "Ask.com"); Deleted : user_pref("browser.search.order.1", "Ask.com"); Deleted : user_pref("browser.search.selectedEngine", "Ask.com"); Deleted : user_pref("extensions.asktb.ff-original-keyword-url", ""); Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=DAT&o=15236&locale=e[…] Profile name : default File : C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\xbk9icq2.default\prefs.js Deleted : user_pref("CT3018509..clientLogIsEnabled", false); Deleted : user_pref("CT3018509..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[…] Deleted : user_pref("CT3018509..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[…] Deleted : user_pref("CT3018509.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Deleted : user_pref("CT3018509.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Deleted : user_pref("CT3018509.AppTrackingLastCheckTime", "Thu Jan 19 2012 15:07:33 GMT-0500 (Eastern Standard[…] Deleted : user_pref("CT3018509.BrowserCompStateIsOpen_1000515", true); Deleted : user_pref("CT3018509.BrowserCompStateIsOpen_129575141437797586", true); Deleted : user_pref("CT3018509.BrowserCompStateIsOpen_129683388555092712", true); Deleted : user_pref("CT3018509.BrowserCompStateIsOpen_129774349446762757", true); Deleted : user_pref("CT3018509.CT3018509", "CT3018509"); Deleted : user_pref("CT3018509.CommunitiesChangesLastCheckTime", "0"); Deleted : user_pref("CT3018509.CurrentServerDate", "14-9-2012"); Deleted : user_pref("CT3018509.DSChangedManually", false); Deleted : user_pref("CT3018509.DSProtectChoice", true); Deleted : user_pref("CT3018509.DSProtectCount", 1); Deleted : user_pref("CT3018509.DialogsAlignMode", "LTR"); Deleted : user_pref("CT3018509.DialogsGetterLastCheckTime", "Wed Sep 12 2012 15:15:51 GMT-0400 (Eastern Daylig[…] Deleted : user_pref("CT3018509.DownloadReferralCookieData", "{\"BannerName\":\"\",\"BannerTypeId\":\"\",\"Bann[…] Deleted : user_pref("CT3018509.EMailNotifierPollDate", "Sun Aug 14 2011 07:21:10 GMT-0400 (Eastern Daylight Ti[…] Deleted : user_pref("CT3018509.EnableClickToSearchBox", false); Deleted : user_pref("CT3018509.EnableSearchHistory", false); Deleted : user_pref("CT3018509.EnableSearchSuggest", false); Deleted : user_pref("CT3018509.ExternalComponentPollDate129510405198305199", "Tue Dec 20 2011 17:36:38 GMT-050[…] Deleted : user_pref("CT3018509.ExternalComponentPollDate129510405203040747", "Sun Aug 14 2011 07:21:02 GMT-040[…] Deleted : user_pref("CT3018509.FirstServerDate", "14-8-2011"); Deleted : user_pref("CT3018509.FirstTime", true); Deleted : user_pref("CT3018509.FirstTimeFF3", true); Deleted : user_pref("CT3018509.FixPageNotFoundErrors", false); Deleted : user_pref("CT3018509.GroupingInvalidateCache", false); Deleted : user_pref("CT3018509.GroupingLastCheckTime", "0"); Deleted : user_pref("CT3018509.GroupingLastServerUpdateTime", "0"); Deleted : user_pref("CT3018509.GroupingServerCheckInterval", 1440); Deleted : user_pref("CT3018509.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Deleted : user_pref("CT3018509.HPProtectChoice", true); Deleted : user_pref("CT3018509.HPProtectCount", 1); Deleted : user_pref("CT3018509.HasUserGlobalKeys", true); Deleted : user_pref("CT3018509.HomePageProtectorEnabled", true); Deleted : user_pref("CT3018509.HomepageBeforeUnload", "hxxp://search.conduit.com/?ctid=CT3018509&SearchSource=[…] Deleted : user_pref("CT3018509.Initialize", true); Deleted : user_pref("CT3018509.InitializeCommonPrefs", true); Deleted : user_pref("CT3018509.InstallationAndCookieDataSentCount", 3); Deleted : user_pref("CT3018509.InstallationType", "DirectDownload"); Deleted : user_pref("CT3018509.InstalledDate", "Sun Aug 14 2011 07:21:05 GMT-0400 (Eastern Daylight Time)"); Deleted : user_pref("CT3018509.InvalidateCache", false); Deleted : user_pref("CT3018509.IsAlertDBUpdated", true); Deleted : user_pref("CT3018509.IsGrouping", false); Deleted : user_pref("CT3018509.IsInitSetupIni", true); Deleted : user_pref("CT3018509.IsMulticommunity", false); Deleted : user_pref("CT3018509.IsOpenThankYouPage", true); Deleted : user_pref("CT3018509.IsOpenUninstallPage", true); Deleted : user_pref("CT3018509.IsProtectorsInit", true); Deleted : user_pref("CT3018509.LanguagePackLastCheckTime", "Fri Sep 14 2012 16:50:12 GMT-0400 (Eastern Dayligh[…] Deleted : user_pref("CT3018509.LanguagePackReloadIntervalMM", 1440); Deleted : user_pref("CT3018509.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[…] Deleted : user_pref("CT3018509.LastLogin_3.12.0.7", "Fri Apr 27 2012 15:27:43 GMT-0400 (Eastern Daylight Time)[…] Deleted : user_pref("CT3018509.LastLogin_3.12.2.3", "Wed May 30 2012 06:23:22 GMT-0400 (Eastern Daylight Time)[…] Deleted : user_pref("CT3018509.LastLogin_3.13.0.6", "Wed Jul 18 2012 11:52:38 GMT-0400 (Eastern Daylight Time)[…] Deleted : user_pref("CT3018509.LastLogin_3.14.1.0", "Tue Aug 21 2012 13:57:06 GMT-0400 (Eastern Daylight Time)[…] Deleted : user_pref("CT3018509.LastLogin_3.15.1.0", "Fri Sep 14 2012 16:50:12 GMT-0400 (Eastern Daylight Time)[…] Deleted : user_pref("CT3018509.LastLogin_3.6.0.10", "Tue Sep 06 2011 19:34:54 GMT-0400 (Eastern Daylight Time)[…] Deleted : user_pref("CT3018509.LastLogin_3.7.0.6", "Fri Nov 04 2011 03:37:47 GMT-0400 (Eastern Daylight Time)"[…] Deleted : user_pref("CT3018509.LastLogin_3.8.0.8", "Mon Dec 05 2011 19:44:31 GMT-0500 (Eastern Standard Time)"[…] Deleted : user_pref("CT3018509.LastLogin_3.8.1.0", "Tue Jan 10 2012 15:58:56 GMT-0500 (Eastern Standard Time)"[…] Deleted : user_pref("CT3018509.LastLogin_3.9.0.3", "Wed Jan 25 2012 15:13:45 GMT-0500 (Eastern Standard Time)"[…] Deleted : user_pref("CT3018509.LatestVersion", "3.15.1.0"); Deleted : user_pref("CT3018509.Locale", "en-us"); Deleted : user_pref("CT3018509.MCDetectTooltipHeight", "83"); Deleted : user_pref("CT3018509.MCDetectTooltipShow", false); Deleted : user_pref("CT3018509.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Deleted : user_pref("CT3018509.MCDetectTooltipWidth", "295"); Deleted : user_pref("CT3018509.MyStuffEnabledAtInstallation", true); Deleted : user_pref("CT3018509.OriginalFirstVersion", "3.6.0.10"); Deleted : user_pref("CT3018509.RadioIsPodcast", false); Deleted : user_pref("CT3018509.RadioLastCheckTime", "0"); Deleted : user_pref("CT3018509.RadioLastUpdateIPServer", "0"); Deleted : user_pref("CT3018509.RadioLastUpdateServer", "0"); Deleted : user_pref("CT3018509.RadioMediaID", "9962"); Deleted : user_pref("CT3018509.RadioMediaType", "Media Player"); Deleted : user_pref("CT3018509.RadioMenuSelectedID", "EBRadioMenu_CT30185099962"); Deleted : user_pref("CT3018509.RadioShrinkedFromSetup", false); Deleted : user_pref("CT3018509.RadioStationName", "California%20Rock"); Deleted : user_pref("CT3018509.RadioStationURL", "hxxp://feedlive.net/california.asx"); Deleted : user_pref("CT3018509.SHRINK_TOOLBAR", 1); Deleted : user_pref("CT3018509.SavedHomepage", "hxxp://www.kongregate.com/accounts/Guest/card_album"); Deleted : user_pref("CT3018509.SearchBackToDefaultEngine", false); Deleted : user_pref("CT3018509.SearchBoxWidth", 100); Deleted : user_pref("CT3018509.SearchEngineBeforeUnload", "Ask.com"); Deleted : user_pref("CT3018509.SearchFromAddressBarIsInit", true); Deleted : user_pref("CT3018509.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT301[…] Deleted : user_pref("CT3018509.SearchInNewTabEnabled", true); Deleted : user_pref("CT3018509.SearchInNewTabIntervalMM", 1440); Deleted : user_pref("CT3018509.SearchInNewTabLastCheckTime", "Fri Sep 14 2012 16:50:11 GMT-0400 (Eastern Dayli[…] Deleted : user_pref("CT3018509.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[…] Deleted : user_pref("CT3018509.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[…] Deleted : user_pref("CT3018509.SearchInNewTabUserEnabled", false); Deleted : user_pref("CT3018509.SearchProtectorEnabled", false); Deleted : user_pref("CT3018509.SearchProtectorToolbarDisabled", false); Deleted : user_pref("CT3018509.ServiceMapLastCheckTime", "Fri Sep 14 2012 16:50:11 GMT-0400 (Eastern Daylight […] Deleted : user_pref("CT3018509.SettingsLastCheckTime", "Fri Sep 14 2012 16:50:11 GMT-0400 (Eastern Daylight Ti[…] Deleted : user_pref("CT3018509.SettingsLastUpdate", "1347202496"); Deleted : user_pref("CT3018509.ThirdPartyComponentsInterval", 504); Deleted : user_pref("CT3018509.ThirdPartyComponentsLastCheck", "Tue Jan 17 2012 20:56:51 GMT-0500 (Eastern Sta[…] Deleted : user_pref("CT3018509.ThirdPartyComponentsLastUpdate", "1312887586"); Deleted : user_pref("CT3018509.ToolbarShrinkedFromSetup", false); Deleted : user_pref("CT3018509.TrusteLinkUrl", "hxxp://trust.conduit.com/CT3018509"); Deleted : user_pref("CT3018509.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[…] Deleted : user_pref("CT3018509.UserID", "UN25660706052152327"); Deleted : user_pref("CT3018509.ValidationData_Search", 1); Deleted : user_pref("CT3018509.ValidationData_Toolbar", 2); Deleted : user_pref("CT3018509.WeatherNetwork", ""); Deleted : user_pref("CT3018509.WeatherPollDate", "Sun Aug 14 2011 07:21:11 GMT-0400 (Eastern Daylight Time)"); Deleted : user_pref("CT3018509.WeatherUnit", "F"); Deleted : user_pref("CT3018509.alertChannelId", "1410096"); Deleted : user_pref("CT3018509.approveUntrustedApps", true); Deleted : user_pref("CT3018509.backendstorage.cb_firstuse0100", "31"); Deleted : user_pref("CT3018509.backendstorage.cbfirsttime", "5765642044656320313420323031312031303A30393A30312[…] Deleted : user_pref("CT3018509.backendstorage.shoppingapp.gk.exipres", "5361742044656320323420323031312031383A[…] Deleted : user_pref("CT3018509.backendstorage.shoppingapp.gk.geolocation", "756E6974656420737461746573"); Deleted : user_pref("CT3018509.backendstorage.url_history", "687474703A2F2F7777772E636F6F6C6D6174682D67616D657[…] Deleted : user_pref("CT3018509.backendstorage.url_history_time", "31333234333830393932333234"); Deleted : user_pref("CT3018509.componentAlertEnabled", false); Deleted : user_pref("CT3018509.components.1000034", false); Deleted : user_pref("CT3018509.components.1000082", false); Deleted : user_pref("CT3018509.components.1000234", false); Deleted : user_pref("CT3018509.components.1000515", false); Deleted : user_pref("CT3018509.components.129510405198305199", false); Deleted : user_pref("CT3018509.components.129510405202747765", false); Deleted : user_pref("CT3018509.components.129510405202923554", false); Deleted : user_pref("CT3018509.components.129510405203040747", false); Deleted : user_pref("CT3018509.components.129510405203206770", false); Deleted : user_pref("CT3018509.components.129510405203597413", false); Deleted : user_pref("CT3018509.components.129510405203782968", false); Deleted : user_pref("CT3018509.components.129570392343604094", false); Deleted : user_pref("CT3018509.components.129575141437797586", false); Deleted : user_pref("CT3018509.components.129683388555092712", false); Deleted : user_pref("CT3018509.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[…] Deleted : user_pref("CT3018509.globalFirstTimeInfoLastCheckTime", "Tue Jan 17 2012 20:56:55 GMT-0500 (Eastern […] Deleted : user_pref("CT3018509.homepageProtectorEnableByLogin", true); Deleted : user_pref("CT3018509.initDone", true); Deleted : user_pref("CT3018509.isAppTrackingManagerOn", true); Deleted : user_pref("CT3018509.isFirstRadioInstallation", false); Deleted : user_pref("CT3018509.myStuffEnabled", true); Deleted : user_pref("CT3018509.myStuffPublihserMinWidth", 400); Deleted : user_pref("CT3018509.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[…] Deleted : user_pref("CT3018509.myStuffServiceIntervalMM", 1440); Deleted : user_pref("CT3018509.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[…] Deleted : user_pref("CT3018509.oldAppsList", "129510405195990639,129510405197729003,111,129510405198305199,129[…] Deleted : user_pref("CT3018509.revertSettingsEnabled", false); Deleted : user_pref("CT3018509.searchProtectorDialogDelayInSec", 10); Deleted : user_pref("CT3018509.searchProtectorEnableByLogin", true); Deleted : user_pref("CT3018509.testingCtid", ""); Deleted : user_pref("CT3018509.toolbarAppMetaDataLastCheckTime", "Fri Sep 14 2012 16:50:12 GMT-0400 (Eastern D[…] Deleted : user_pref("CT3018509.toolbarContextMenuLastCheckTime", "Tue Jan 24 2012 20:09:33 GMT-0500 (Eastern S[…] Deleted : user_pref("CT3018509.usageEnabled", false); Deleted : user_pref("CT3018509.usagesFlag", 2); Deleted : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3018509&Search[…] Deleted : user_pref("CommunityToolbar.ConduitSearchList", "Game Master 2.1 Customized Web Search"); Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3018509/CT3018509[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1410096/1405754/US", "\"0\"[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3018509", […] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.6.[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3018509",[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT3018509&octid=[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/equalize[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/minimize[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/play.gif[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/stop.gif[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/vol.gif"[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[…] Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[…] Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Documents and Settings\\Ryan\\Application […] Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.9.0.3"); Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://www.akaqa.com/gadget/ask", "620x448"); Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", ""); Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT3018509"); Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT3018509"); Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT3018509"); Deleted : user_pref("CommunityToolbar.globalUserId", "9af42460-faa5-42b2-9787-4d526e73be89"); Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Wed Jan 25 2012 15:13:4[…] Deleted : user_pref("CommunityToolbar.notifications.alertEnabled", false); Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 60); Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Sun Aug 14 2011 07:21:10 GMT-040[…] Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Deleted : user_pref("CommunityToolbar.notifications.locale", "en"); Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Wed Jan 25 2012 15:13:39 GMT-0500 (E[…] Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Deleted : user_pref("CommunityToolbar.notifications.userId", "0fac1532-7de4-475f-8539-d701f52db965"); Deleted : user_pref("browser.search.defaultengine", "Ask.com"); Deleted : user_pref("browser.search.defaultenginename", "Ask.com"); Deleted : user_pref("browser.search.defaultthis.engineName", "Game Master 2.1 Customized Web Search"); Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3018509&Sea[…] Deleted : user_pref("browser.search.order.1", "Ask.com"); Deleted : user_pref("browser.search.selectedEngine", "Ask.com"); Deleted : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3018509&SearchSource=13"); Deleted : user_pref("extensions.asktb.InstallDir", "C:\\Program Files\\Ask.com\\"); Deleted : user_pref("extensions.asktb.abar-war-regex", "conduit\\.com"); Deleted : user_pref("extensions.asktb.abar-war-timeout", "4000"); Deleted : user_pref("extensions.asktb.autofill-competitor-query-enabled", true); Deleted : user_pref("extensions.asktb.cbid", "FC"); Deleted : user_pref("extensions.asktb.config-updated", true); Deleted : user_pref("extensions.asktb.crumb", "2011.11.10+09.52.26-toolbar006iad-US-RXBocmF0YSxQQSxVbml0ZWQgU3[…] Deleted : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://www.ask.com/web?q={query}&o={o}&l={l}[…] Deleted : user_pref("extensions.asktb.displaybehavior", ""); Deleted : user_pref("extensions.asktb.displaytext", ""); Deleted : user_pref("extensions.asktb.dtid", "YYYYYYYYUS"); Deleted : user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", true); Deleted : user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "USPA0300"); Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://www.google.com/search?ie=UTF-8&oe=UTF-[…] Deleted : user_pref("extensions.asktb.fresh-install", false); Deleted : user_pref("extensions.asktb.guid", "2AEF9D5D-3351-4500-AA58-97C900A14FF4"); Deleted : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com[…] Deleted : user_pref("extensions.asktb.if", "su"); Deleted : user_pref("extensions.asktb.l", "dis"); Deleted : user_pref("extensions.asktb.last-config-req", "1347655809310"); Deleted : user_pref("extensions.asktb.last-search-timestamp", "1336831904270"); Deleted : user_pref("extensions.asktb.locale", "en_US"); Deleted : user_pref("extensions.asktb.lstation", ""); Deleted : user_pref("extensions.asktb.new-tab-enabled", true); Deleted : user_pref("extensions.asktb.news-native-on", true); Deleted : user_pref("extensions.asktb.o", "15236"); Deleted : user_pref("extensions.asktb.overlay-reloaded-using-restart", true); Deleted : user_pref("extensions.asktb.pstate", ""); Deleted : user_pref("extensions.asktb.qsrc", "2871"); Deleted : user_pref("extensions.asktb.r", "4"); Deleted : user_pref("extensions.asktb.sa", "YES"); Deleted : user_pref("extensions.asktb.saguid", "E9EDF1C5-B517-467A-9921-1CD66B1AAB2A"); Deleted : user_pref("extensions.asktb.search-history-queries", "I'm offering"); Deleted : user_pref("extensions.asktb.search-plugin-suggestions-url", "hxxp://ss.websearch.ask.com/query?qsrc=[…] Deleted : user_pref("extensions.asktb.search-suggestions-enabled", true); Deleted : user_pref("extensions.asktb.silent-upgrade", true); Deleted : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", true); Deleted : user_pref("extensions.asktb.socialmini-first", true); Deleted : user_pref("extensions.asktb.socialmini-interval", "1200000"); Deleted : user_pref("extensions.asktb.socialmini-max-char-ticker", "33"); Deleted : user_pref("extensions.asktb.socialmini-max-items", "30"); Deleted : user_pref("extensions.asktb.socialmini-native-on", true); Deleted : user_pref("extensions.asktb.socialmini-speed", "5000"); Deleted : user_pref("extensions.asktb.socialmini-transition-first-open", false); Deleted : user_pref("extensions.asktb.themeid", ""); Deleted : user_pref("extensions.asktb.timeinstalled", "5/4/2012 12:53:37 PM"); Deleted : user_pref("extensions.asktb.v", "3.15.1.100013"); Deleted : user_pref("extensions.asktb.version", "5.15.1.22229"); Deleted : user_pref("extensions.asktb.volume", ""); Deleted : user_pref("extensions.enabledAddons", "{22dfbf5b-a7cd-4b25-9471-3dc68c71855f}:3.15.1.0,[removed]:1[…] Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=DAT&o=15236&locale=e[…] Profile name : default File : C:\Documents and Settings\AOM\Application Data\Mozilla\Firefox\Profiles\88ikj5yd.default\prefs.js Deleted : user_pref("browser.search.defaultengine", "Ask.com"); Deleted : user_pref("browser.search.defaultenginename", "Ask.com"); Deleted : user_pref("browser.search.order.1", "Ask.com"); Deleted : user_pref("browser.search.selectedEngine", "Ask.com"); Deleted : user_pref("extensions.asktb.ff-original-keyword-url", ""); Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=DAT&o=15236&locale=e[…] Profile name : default File : C:\Documents and Settings\stoner\Application Data\Mozilla\Firefox\Profiles\sa7v08xn.default\prefs.js Deleted : user_pref("browser.search.defaultengine", "Ask.com"); Deleted : user_pref("browser.search.defaultenginename", "Ask.com"); Deleted : user_pref("browser.search.order.1", "Ask.com"); Deleted : user_pref("browser.search.selectedEngine", "Ask.com"); Deleted : user_pref("extensions.asktb.ff-original-keyword-url", ""); Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=DAT&o=15236&locale=e[…] Profile name : default File : C:\Documents and Settings\Carter\Application Data\Mozilla\Firefox\Profiles\mrqc3dxi.default\prefs.js Deleted : user_pref("browser.search.defaultengine", "Ask.com"); Deleted : user_pref("browser.search.defaultenginename", "Ask.com"); Deleted : user_pref("browser.search.order.1", "Ask.com"); Deleted : user_pref("browser.search.selectedEngine", "Ask.com"); Deleted : user_pref("extensions.asktb.ff-original-keyword-url", ""); Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=DAT&o=15236&locale=e[…] ************************* AdwCleaner[S1].txt - [33104 octets] - [14/09/2012 21:54:26] ########## EOF - C:\AdwCleaner[S1].txt - [33165 octets] ########## ################################################################################ ############# MBAM: Malwarebytes Anti-Malware 1.65.0.1400 www.malwarebytes.org Database version: v2012.09.14.07 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Christine :: OPTIPLEX [administrator] 9/14/2012 10:03:53 PM mbam-log-2012-09-14 (22-03-53).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 389238 Time elapsed: 6 minute(s), 35 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowControlPanel (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ################################################################################ ## ESET: C:\Documents and Settings\Chris\My Documents\Downloads\cnet_PrinterShare2306_exe.exe a variant of Win32/InstallCore.D application C:\RECYCLER\S-1-5-21-1755230115-917001253-2734630794-1006\Dc1.exe a variant of Win32/InstallCore.D application C:\RECYCLER\S-1-5-21-1755230115-917001253-2734630794-1011\Dc9.exe a variant of Win32/Adware.Trymedia.A application

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI