This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

searchq [Solved]

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ok, followed instructions but upon reboot and then logging in, my computer screen went blank for 5 minutes and nothing was happening so I restarted the computer again and clicked on my OTL shortcut and this .txt came up, I hope it is for the process just ran:

my computer is running fine and actually seemed faster after the 'combofix' however certain websites that I frequent aren't 'working'; these include ticketmaster.com, grooveshark.com, and http://las.mlxchange.com. that last website is the one I included the error log for-I need this one for my job and is very important to get working-I have confirmed that the website is operable by verifying on my other computer.

please advise, thank you

All processes killed
========== FILES ==========
C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components folder moved successfully.
C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome folder moved successfully.
C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed] folder moved successfully.
C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Firefox\Profiles\vc2rmakq.default\extensions\[removed]\components folder moved successfully.
C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Firefox\Profiles\vc2rmakq.default\extensions\[removed]\chrome folder moved successfully.
C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Firefox\Profiles\vc2rmakq.default\extensions\[removed] folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: cwestmas2011
->Temp folder emptied: 296261 bytes
->Temporary Internet Files folder emptied: 36326724 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 47153299 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 1093 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: TEMP
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1216 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 49286 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 80.00 mb


[EMPTYFLASH]

User: All Users

User: cwestmas2011
->Flash cache emptied: 0 bytes

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: TEMP

Total Flash Files Cleaned = 0.00 mb

Error: Unable to interpret <[Reboot> in the current context!

OTL by OldTimer - Version 3.2.64.0 log created on 09232012_211124

Files\Folders moved on Reboot…
C:\Users\cwestmas2011\AppData\Local\Temp\Low\REG2A8F.tmp moved successfully.
C:\Users\cwestmas2011\AppData\Local\Temp\Low\REG3BC.tmp moved successfully.
C:\Users\cwestmas2011\AppData\Local\Temp\Low\REG79A5.tmp moved successfully.
C:\Users\cwestmas2011\AppData\Local\Temp\Low\REG8CCA.tmp moved successfully.
C:\Users\cwestmas2011\AppData\Local\Temp\Low\REG9DF8.tmp moved successfully.
C:\Users\cwestmas2011\AppData\Local\Temp\Low\REGE285.tmp moved successfully.
File move failed. C:\Users\cwestmas2011\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\I29XQ1EE\adloader[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\I29XQ1EE\index[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\I29XQ1EE\xmlProxy[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\I29XQ1EE\xmlProxy[3].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\I29XQ1EE\xmlProxy[4].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\H7771W32\EditMessageLight[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\H7771W32\LocalStorage[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\H7771W32\RteFrame_16.2.7056.0906[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\H7771W32\supplierIframe[2].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\H7771W32\tt[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FE4G24V\default[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4FE4G24V\resourcespreload[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3FZ92ES5\adoapn_AppNexusDemoActionTag_1[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3FZ92ES5\AjaxHistoryFrame[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3FZ92ES5\flextag[2].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3FZ92ES5\iframe[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3FZ92ES5\InboxLight[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3FZ92ES5\Messenger[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3FZ92ES5\ST_MF-160x600_(6.18.12)[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
Hello satchmo

my computer is running fine and actually seemed faster after the 'combofix' however certain websites that I frequent aren't 'working'; these include ticketmaster.com, grooveshark.com, and http://las.mlxchange.com. that last website is the one I included the error log for-I need this one for my job and is very important to get working-I have confirmed that the website is operable by verifying on my other computer

I'm not sure why that would be happening.

Once we have confirmed that your machine is malware free I will hand you over to the email and internet forum who will be better able to assist with this issue.

Please re-scan with OTL and post the new log as requested.
Here's the new otl log, i ran the same directions as I had done today already which may not have been what you wanted me to do. Let me know if I need to do something different. All processes killed ========== FILES ========== File\Folder C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed] not found. File\Folder C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Firefox\Profiles\vc2rmakq.default\extensions\[removed] not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: cwestmas2011 ->Temp folder emptied: 345146 bytes ->Temporary Internet Files folder emptied: 51747410 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 1095 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes User: TEMP ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 49286 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 50.00 mb [EMPTYFLASH] User: All Users User: cwestmas2011 ->Flash cache emptied: 0 bytes User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: Public User: TEMP Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.64.0 log created on 09232012_002755 Files\Folders moved on Reboot… File\Folder C:\Users\cwestmas2011\AppData\Local\Temp\Low\hsperfdata_cwestmas2011\7296 not found! C:\Users\cwestmas2011\AppData\Local\Temp\Low\REG1DA0.tmp moved successfully. C:\Users\cwestmas2011\AppData\Local\Temp\Low\REG254B.tmp moved successfully. C:\Users\cwestmas2011\AppData\Local\Temp\Low\REG2675.tmp moved successfully. C:\Users\cwestmas2011\AppData\Local\Temp\Low\REG4609.tmp moved successfully. C:\Users\cwestmas2011\AppData\Local\Temp\Low\REG52C4.tmp moved successfully. C:\Users\cwestmas2011\AppData\Local\Temp\Low\REG8640.tmp moved successfully. C:\Users\cwestmas2011\AppData\Local\Temp\Low\REGB7AD.tmp moved successfully. C:\Users\cwestmas2011\AppData\Local\Temp\Low\REGB868.tmp moved successfully. C:\Users\cwestmas2011\AppData\Local\Temp\Low\REGBDD5.tmp moved successfully. File\Folder C:\Users\cwestmas2011\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found! C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RZHOYC0Q\adsCAU0TOAT.htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RZHOYC0Q\beacon[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RZHOYC0Q\beacon[2].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RZHOYC0Q\fpi[1].htm moved successfully. File\Folder C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RZHOYC0Q\las-vegas[1].htm not found! C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RZHOYC0Q\mlb-baseball-public-betting-chart[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RZHOYC0Q\p-01-0VIaSjnOLg[1].gif moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RZHOYC0Q\RteFrame_16.2.7056.0906[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RZHOYC0Q\visitormatch[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RZHOYC0Q\x1743[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RZHOYC0Q\xd_arbiter[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LW32UP04\ads[5].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LW32UP04\baseball-scores-matchups[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LW32UP04\controller[2].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LW32UP04\EditMessageLight[2].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LW32UP04\fastbutton[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LW32UP04\fpi[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LW32UP04\fpi[2].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LW32UP04\InboxLight[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LW32UP04\like[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LW32UP04\p-01-0VIaSjnOLg[1].gif moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LW32UP04\si[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LW32UP04\xd_arbiter[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LW32UP04\xmlProxy[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LW32UP04\xmlProxy[3].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BBK6U4V2\abbrresults[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BBK6U4V2\adloader[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BBK6U4V2\affiliatecontent[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BBK6U4V2\beacon[4].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BBK6U4V2\controller[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BBK6U4V2\ddc[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BBK6U4V2\iframe[2].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BBK6U4V2\index[2].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BBK6U4V2\LocalStorage[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BBK6U4V2\sh101[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BBK6U4V2\siCAJH0BYK.htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4GT015VC\ads[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4GT015VC\AjaxHistoryFrame[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4GT015VC\ddc[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4GT015VC\ddc[2].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4GT015VC\flextag[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4GT015VC\Messenger[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4GT015VC\p-01-0VIaSjnOLg[1].gif moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4GT015VC\parlay_calculator[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4GT015VC\visitormatch[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4GT015VC\x1743[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4GT015VC\xmlProxy[1].htm moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully. C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully. File\Folder C:\Windows\temp\mcafee_HeLdPLNPytU8set not found! PendingFileRenameOperations files… Registry entries deleted on Reboot…
Hello satchmo

I need to you to scan your machine with OTL exactly the same way as you did in post number 2.

Once the scan has completed, please post the log for me to review.
here is the resulting log:

OTL logfile created on: 9/23/2012 6:03:54 PM - Run 2
OTL by OldTimer - Version 3.2.64.0 Folder = C:\Users\cwestmas2011\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.98 Gb Total Physical Memory | 6.38 Gb Available Physical Memory | 79.90% Memory free
15.96 Gb Paging File | 13.05 Gb Available in Paging File | 81.73% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 918.22 Gb Total Space | 852.49 Gb Free Space | 92.84% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: CWESTMAS2011-PC | User Name: cwestmas2011 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/09/20 22:08:23 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Users\cwestmas2011\Desktop\OTL.exe
PRC - [2012/09/18 07:54:35 | 000,690,888 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_265_ActiveX.exe
PRC - [2012/09/07 17:04:46 | 000,676,936 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/07 17:04:46 | 000,399,432 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/07 17:04:44 | 000,766,536 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/08/02 16:06:28 | 000,173,056 | —- | M] (Dell Products, LP.) – C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
PRC - [2012/07/27 13:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/06/11 16:22:16 | 000,240,208 | —- | M] (Microsoft Corporation.) – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE
PRC - [2012/04/30 15:15:14 | 007,968,008 | —- | M] (AVM Software Inc.) – C:\Program Files (x86)\Paltalk Messenger\paltalk.exe
PRC - [2012/02/01 11:50:58 | 000,968,048 | —- | M] () – C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
PRC - [2011/11/25 16:32:36 | 000,687,400 | —- | M] (Nero AG) – C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2011/09/06 11:29:20 | 004,259,648 | —- | M] (SoftThinks - Dell) – C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
PRC - [2011/08/18 09:05:54 | 002,751,808 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
PRC - [2011/08/18 09:05:46 | 001,692,480 | —- | M] (SoftThinks SAS) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
PRC - [2011/08/17 12:29:52 | 000,480,880 | —- | M] () – C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
PRC - [2011/08/01 11:56:48 | 000,460,096 | —- | M] (SoftThinks - Dell) – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
PRC - [2010/11/17 09:35:40 | 001,440,240 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\Roxio Burn.exe
PRC - [2010/11/17 09:35:34 | 000,514,544 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2010/09/13 17:32:32 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/09/13 17:32:30 | 000,283,160 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2010/03/10 15:26:30 | 000,237,568 | —- | M] (Alcor Micro Corp.) – C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe
PRC - [2009/03/30 16:00:54 | 000,221,184 | —- | M] (Brother Industries, Ltd.) – C:\Program Files (x86)\Brother\Brmfcmon\BrMfcMon.exe
PRC - [2008/11/09 13:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe


========== Modules (No Company Name) ==========

MOD - [2012/06/14 03:30:26 | 000,475,136 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\09557e6c5a83a1cb68c7c50a841c8064\IAStorUtil.ni.dll
MOD - [2012/06/14 03:26:39 | 014,340,608 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll
MOD - [2012/06/14 03:26:28 | 012,436,480 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012/06/14 03:26:24 | 001,591,808 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012/06/14 03:26:18 | 012,237,824 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
MOD - [2012/05/10 10:36:25 | 000,014,336 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\220b0516e45e7f9bbf6a631490c1243a\IAStorCommon.ni.dll
MOD - [2012/05/10 10:36:11 | 002,297,856 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll
MOD - [2012/05/10 07:52:14 | 000,368,128 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll
MOD - [2012/05/10 07:52:05 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MOD - [2012/05/10 07:51:23 | 003,347,968 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
MOD - [2012/05/10 07:51:20 | 005,452,800 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012/05/10 07:51:18 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012/05/10 07:51:17 | 007,967,232 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012/05/10 07:51:12 | 011,492,864 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2012/04/30 15:15:21 | 001,837,808 | —- | M] () – C:\Program Files (x86)\Paltalk Messenger\Images.dll
MOD - [2012/04/30 15:15:18 | 000,048,368 | —- | M] () – C:\Program Files (x86)\Paltalk Messenger\ctrlkey.dll
MOD - [2012/02/01 11:50:58 | 000,968,048 | —- | M] () – C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
MOD - [2012/02/01 11:44:34 | 008,151,040 | —- | M] () – C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtGui4.dll
MOD - [2012/02/01 11:44:34 | 002,278,400 | —- | M] () – C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtCore4.dll
MOD - [2011/09/27 08:23:00 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 08:22:40 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/08/18 09:05:54 | 002,751,808 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
MOD - [2011/08/17 12:29:52 | 000,480,880 | —- | M] () – C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
MOD - [2010/11/24 21:44:02 | 000,375,280 | —- | M] () – c:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\SQLite352.dll
MOD - [2010/11/17 09:35:40 | 001,440,240 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\Roxio Burn.exe
MOD - [2010/11/17 09:35:34 | 000,514,544 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
MOD - [2010/11/17 09:35:28 | 000,657,904 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\BBEngineAS.dll
MOD - [2009/02/27 17:38:20 | 000,139,264 | R— | M] () – C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/08/24 23:46:28 | 000,383,608 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\mcafee\virusscan\mcods.exe – (McODS)
SRV:64bit: - [2012/06/22 07:38:04 | 000,177,144 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Windows\SysNative\mfevtps.exe – (mfevtp)
SRV:64bit: - [2012/06/22 07:34:52 | 000,218,320 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe – (mfefire)
SRV:64bit: - [2012/06/22 07:33:12 | 000,237,920 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV:64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (MSK80Service)
SRV:64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe – (McProxy)
SRV:64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Disabled | Stopped] – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe – (McOobeSv)
SRV:64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe – (McNASvc)
SRV:64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV:64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV:64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV:64bit: - [2011/06/21 19:57:42 | 000,341,296 | —- | M] (Nitro PDF Software) [Auto | Running] – C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe – (NitroReaderDriverReadSpool2)
SRV:64bit: - [2011/03/08 16:00:50 | 000,224,704 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – c:\Program Files\mcafee\msc\McAWFwk.exe – (McAWFwk)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009/07/13 18:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2012/09/21 23:15:41 | 000,250,288 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/10 11:38:18 | 000,114,144 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/09/07 17:04:46 | 000,676,936 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/09/07 17:04:46 | 000,399,432 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/08/02 16:06:28 | 000,173,056 | —- | M] (Dell Products, LP.) [Auto | Running] – C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe – (DellDigitalDelivery)
SRV - [2012/07/27 13:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/07/17 12:18:00 | 000,562,688 | —- | M] () [Auto | Stopped] – C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe – (DefaultTabSearch)
SRV - [2012/07/13 13:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/06/11 16:22:16 | 000,240,208 | —- | M] (Microsoft Corporation.) [On_Demand | Running] – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE – (BBUpdate)
SRV - [2012/06/11 16:22:16 | 000,193,616 | —- | M] (Microsoft Corporation.) [Auto | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE – (BBSvc)
SRV - [2011/11/25 16:32:36 | 000,687,400 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Nero\Update\NASvc.exe – (NAUpdate)
SRV - [2011/11/08 13:16:25 | 001,045,256 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2011/08/18 09:05:46 | 001,692,480 | —- | M] (SoftThinks SAS) [Auto | Running] – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe – (SftService)
SRV - [2010/11/25 04:34:18 | 000,219,632 | —- | M] (Sonic Solutions) [Auto | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe – (RoxWatch12)
SRV - [2010/11/25 04:33:18 | 001,116,656 | —- | M] (Sonic Solutions) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe – (RoxMediaDB12OEM)
SRV - [2010/09/13 17:32:32 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc)
SRV - [2010/08/25 19:28:54 | 002,823,000 | —- | M] (Dell, Inc.) [Auto | Running] – C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe – (NOBU)
SRV - [2010/03/18 14:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 14:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2008/11/09 13:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/09/15 08:25:48 | 000,095,392 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\SMR310.SYS – (SMR310)
DRV:64bit: - [2012/09/07 17:04:46 | 000,025,928 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2012/06/22 07:40:58 | 000,069,672 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\cfwids.sys – (cfwids)
DRV:64bit: - [2012/06/22 07:38:16 | 000,335,784 | —- | M] (McAfee, Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\mfewfpk.sys – (mfewfpk)
DRV:64bit: - [2012/06/22 07:36:54 | 000,106,112 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mferkdet.sys – (mferkdet)
DRV:64bit: - [2012/06/22 07:36:12 | 000,752,672 | —- | M] (McAfee, Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\mfehidk.sys – (mfehidk)
DRV:64bit: - [2012/06/22 07:35:02 | 000,513,456 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfefirek.sys – (mfefirek)
DRV:64bit: - [2012/06/22 07:34:22 | 000,300,392 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfeavfk.sys – (mfeavfk)
DRV:64bit: - [2012/06/22 07:34:00 | 000,169,320 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfeapfk.sys – (mfeapfk)
DRV:64bit: - [2012/04/20 16:40:58 | 000,196,440 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HipShieldK.sys – (HipShieldK)
DRV:64bit: - [2012/02/29 23:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/11/08 14:49:54 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/11/08 14:49:54 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/07/19 12:35:00 | 000,015,360 | —- | M] (June Fabrics Technology Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\pneteth.sys – (pneteth)
DRV:64bit: - [2010/11/20 20:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 20:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 20:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/11/11 10:10:50 | 000,155,752 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nvhda64v.sys – (NVHDA)
DRV:64bit: - [2010/10/15 18:28:18 | 000,317,440 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud)
DRV:64bit: - [2010/09/21 20:59:38 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (MEIx64)
DRV:64bit: - [2010/09/14 05:24:26 | 000,437,272 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2010/06/08 05:36:18 | 000,406,056 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\k57nd60a.sys – (k57nd60a)
DRV:64bit: - [2010/05/20 16:42:44 | 003,058,168 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\BCMWL664.SYS – (BCM43XX)
DRV:64bit: - [2010/03/19 02:00:00 | 000,055,856 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2010/02/27 08:32:14 | 000,158,976 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 18:18:06 | 000,281,088 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\BrSerIb.sys – (BrSerIb)
DRV:64bit: - [2009/06/10 13:41:10 | 000,015,360 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\BrUsbSIb.sys – (BrUsbSIb)
DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2006/11/01 11:51:00 | 000,151,656 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\WimFltr.sys – (WimFltr)
DRV - [2009/07/13 18:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE:64bit: - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DKUS
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?PC=msnHomeST&OCID;=msnHomepage
IE - HKCU\..\SearchScopes,DefaultScope = {9CC0CE6A-33A7-F5FF-A61D-F0902379161B}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…FF-E75EAECF2AF8
IE - HKCU\..\SearchScopes\{3D77D279-C46D-41A1-BD31-190D1666D714}: "URL" = http://www.mysearchresults.com/search?&…q={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GGLL_en
IE - HKCU\..\SearchScopes\{8F428628-7435-4175-A65D-27BA8813145A}: "URL" = http://search.yahoo.com/search?p={searchte…37,17118,0,18,0
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\..\SearchScopes\{9CC0CE6A-33A7-F5FF-A61D-F0902379161B}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;form=ZGAIDF
IE - HKCU\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.com/toolbarv/askRedirec…amp;toolbar=FRW
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.msn.com"
FF - prefs.js..extensions.enabledAddons: {ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}:1.1
FF - prefs.js..extensions.enabledAddons: [removed]:1.0.0
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=169&systemid;=406&sr;=0&q;="


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_278.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\NitroPDF: C:\Program Files (x86)\Nitro PDF\Reader 2\npnitromozilla.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\cwestmas2011\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\cwestmas2011\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/10 11:38:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\McAfee\MSK [2012/09/21 19:34:37 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/10 11:38:19 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012/09/15 09:57:57 | 000,000,000 | —D | M] (No name found) – C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Extensions
[2012/09/23 21:11:25 | 000,000,000 | —D | M] (No name found) – C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Firefox\Profiles\vc2rmakq.default\extensions
[2012/09/15 09:49:58 | 000,000,000 | —D | M] (PinPhotoZoom - Eaisly zoom photos in Pinterest!) – C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Firefox\Profiles\vc2rmakq.default\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}
[2012/09/20 20:29:59 | 000,001,982 | —- | M] () – C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Firefox\Profiles\vc2rmakq.default\searchplugins\search-here.xml
[2012/07/01 14:32:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) – C:\USERS\CWESTMAS2011\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VC2RMAKQ.DEFAULT\EXTENSIONS\[removed]
[2012/09/10 11:38:19 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/09/10 11:38:17 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/09/10 11:38:17 | 000,002,253 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\Program Files (x86)\Nitro PDF\Reader 2\npnitromozilla.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\cwestmas2011\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~2\mcafee\msc\npmcsn~1.dll
CHR - Extension: RivalGaming = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\adhmhclafdhfabmmglbcngpddpdeijgd\
CHR - Extension: YouTube = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: DefaultTab = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\1.1.8_0\
CHR - Extension: PinPhotoZoom plugin for chrome = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbdamgnimlipjnpgiakiojcbbmcmiibn\1.1_0\
CHR - Extension: Gmail = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/09/21 20:11:07 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (PinPhotoZoom) - {4a0c8953-9d4e-4790-b732-2b9fc9ebce05} - C:\Users\cwestmas2011\AppData\Roaming\PinPhotoZoom\64\AutocompletePro64.dll (SimplyGen)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (PinPhotoZoom) - {4a0c8953-9d4e-4790-b732-2b9fc9ebce05} - C:\Users\cwestmas2011\AppData\Roaming\PinPhotoZoom\AutocompletePro.dll (SimplyGen)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\cwestmas2011\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll File not found
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RunDLLEntry_EptMon] C:\Windows\SysNative\EptMon64.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [RunDLLEntry_THXCfg] C:\Windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NeroLauncher] C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe ()
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe (Alcor Micro Corp.)
O4 - HKLM..\Run: [THX Audio Control Panel] C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - Startup: C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk = C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files (x86)\Paltalk Messenger\paltalk.exe (AVM Software Inc.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.5.1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EE91BDD2-159C-4FBE-B47A-2393B104EA7A}: DhcpNameServer = [removed] [removed] [removed]
O18:64bit: - Protocol\Handler\cozi - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/09/23 21:11:24 | 000,000,000 | —D | C] – C:\_OTL
[2012/09/23 19:33:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/09/23 03:00:41 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/09/23 03:00:41 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/09/23 03:00:41 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/09/23 03:00:41 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/09/23 03:00:41 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/09/23 03:00:41 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/09/23 03:00:41 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/09/23 03:00:41 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/09/23 03:00:41 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/09/23 03:00:41 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/09/23 03:00:40 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/09/23 03:00:40 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/09/23 03:00:40 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/09/23 03:00:40 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/09/23 03:00:39 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/09/23 00:37:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/09/22 23:00:26 | 000,448,512 | —- | C] (OldTimer Tools) – C:\Users\cwestmas2011\Desktop\TFC.exe
[2012/09/21 20:14:19 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/09/21 20:11:18 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/09/21 20:04:55 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/09/21 20:04:55 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/09/21 20:04:55 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/09/21 20:04:51 | 000,000,000 | —D | C] – C:\Qoobox
[2012/09/21 20:04:40 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/09/21 20:02:04 | 004,754,290 | R— | C] (Swearware) – C:\Users\cwestmas2011\Desktop\ComboFix.exe
[2012/09/21 20:01:35 | 000,940,544 | —- | C] (Apache Software Foundation) – C:\Users\cwestmas2011\AppData\Local\log4cxx.dll
[2012/09/21 19:33:12 | 000,196,440 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\HipShieldK.sys
[2012/09/20 22:26:17 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\cwestmas2011\Desktop\aswMBR.exe
[2012/09/20 22:08:13 | 000,600,064 | —- | C] (OldTimer Tools) – C:\Users\cwestmas2011\Desktop\OTL.exe
[2012/09/20 21:20:55 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\cwestmas2011\Desktop\HiJackThis.exe
[2012/09/20 20:38:45 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/09/20 20:18:05 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\PC Cleaners
[2012/09/20 20:17:32 | 004,584,312 | —- | C] (PC Cleaners) – C:\Windows\uninst.exe
[2012/09/20 20:17:31 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\PCPro
[2012/09/20 20:17:31 | 000,000,000 | —D | C] – C:\ProgramData\PC1Data
[2012/09/19 23:25:27 | 000,008,704 | —- | C] (ScanSpyware.net) – C:\Windows\SysWow64\ssbtsr.exe
[2012/09/19 23:25:27 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\ScanSpyware
[2012/09/19 23:25:27 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ScanSpyware
[2012/09/19 23:25:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\ScanSpyware
[2012/09/19 20:42:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/09/19 20:42:41 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012/09/18 12:09:54 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012/09/18 09:59:44 | 000,000,000 | —D | C] – C:\Windows\SysNative\%LOCALAPPDATA%
[2012/09/18 09:05:32 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Local\CrashDumps
[2012/09/17 22:24:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/09/17 22:24:05 | 000,033,240 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2012/09/17 22:23:23 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/09/17 22:23:21 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/09/17 22:23:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2012/09/17 22:23:21 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2012/09/15 10:04:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileViewer
[2012/09/15 10:00:47 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\Malwarebytes
[2012/09/15 10:00:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/15 10:00:38 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/09/15 10:00:37 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/09/15 10:00:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/09/15 09:57:56 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivalGaming
[2012/09/15 09:57:51 | 000,000,000 | —D | C] – C:\ProgramData\Yahoo!
[2012/09/15 09:57:49 | 000,000,000 | —D | C] – C:\ProgramData\Yahoo! Companion
[2012/09/15 09:57:49 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\Yahoo!
[2012/09/15 09:57:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Yahoo!
[2012/09/15 09:50:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\File Type Assistant
[2012/09/15 09:50:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\FreeFileViewer
[2012/09/15 09:50:03 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shop to Win 17
[2012/09/15 09:50:02 | 000,000,000 | —D | C] – C:\ProgramData\Tarma Installer
[2012/09/15 09:49:57 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\PinPhotoZoom
[2012/09/15 09:49:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\PinPhotoZoom
[2012/09/15 09:49:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\DefaultTab
[2012/09/15 09:49:51 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\DefaultTab
[2012/09/15 08:25:48 | 000,095,392 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SMR310.SYS
[2012/09/15 08:25:44 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Local\NPE
[2012/09/15 08:25:44 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2012/09/13 07:04:15 | 000,000,000 | R–D | C] – C:\Users\cwestmas2011\Desktop\MySyncUPFiles
[2012/09/12 02:37:49 | 000,376,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2012/09/12 02:37:49 | 000,288,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2012/09/12 02:37:48 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\RNDISMP.sys
[2012/09/12 02:37:47 | 000,574,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2012/09/11 21:00:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/09/11 21:00:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype

========== Files - Modified Within 30 Days ==========

[2012/09/23 20:47:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3398785354-3721342185-2269831038-1001Core.job
[2012/09/23 18:01:16 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/23 18:01:15 | 000,000,936 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3398785354-3721342185-2269831038-1001UA.job
[2012/09/23 18:01:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/09/23 00:39:30 | 000,021,296 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/23 00:39:30 | 000,021,296 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/23 00:36:56 | 000,778,834 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/09/23 00:36:56 | 000,660,068 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/09/23 00:36:56 | 000,120,996 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/09/23 00:32:10 | 2133,676,031 | -HS- | M] () – C:\hiberfil.sys
[2012/09/22 23:00:28 | 000,448,512 | —- | M] (OldTimer Tools) – C:\Users\cwestmas2011\Desktop\TFC.exe
[2012/09/21 23:15:41 | 000,696,240 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/09/21 23:15:41 | 000,073,136 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/09/21 20:44:29 | 000,458,240 | —- | M] () – C:\Users\cwestmas2011\Desktop\CKScanner.exe
[2012/09/21 20:11:07 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/09/21 20:02:21 | 004,754,290 | R— | M] (Swearware) – C:\Users\cwestmas2011\Desktop\ComboFix.exe
[2012/09/20 22:54:39 | 000,000,512 | —- | M] () – C:\Users\cwestmas2011\Desktop\MBR.dat
[2012/09/20 22:26:34 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\cwestmas2011\Desktop\aswMBR.exe
[2012/09/20 22:08:23 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Users\cwestmas2011\Desktop\OTL.exe
[2012/09/20 21:21:01 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\cwestmas2011\Desktop\HiJackThis.exe
[2012/09/20 20:38:46 | 000,002,414 | —- | M] () – C:\Users\cwestmas2011\Desktop\Google Chrome.lnk
[2012/09/20 20:17:20 | 004,584,312 | —- | M] (PC Cleaners) – C:\Windows\uninst.exe
[2012/09/20 08:26:35 | 000,000,805 | —- | M] () – C:\Windows\ScanSpyware.INI
[2012/09/19 23:25:27 | 000,001,185 | —- | M] () – C:\Users\cwestmas2011\Desktop\Diagnose & Fix.lnk
[2012/09/19 23:25:27 | 000,001,171 | —- | M] () – C:\Users\cwestmas2011\Desktop\ScanSpyware.lnk
[2012/09/19 20:42:43 | 000,000,784 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/09/17 22:24:10 | 000,001,785 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/09/17 08:18:23 | 000,000,148 | —- | M] () – C:\Users\cwestmas2011\Desktop\Personal Credit Cards, First Bankcard, a division of First National Bank of Omaha (2).url
[2012/09/15 10:04:17 | 000,001,109 | —- | M] () – C:\Users\cwestmas2011\Application Data\Microsoft\Internet Explorer\Quick Launch\FreeFileViewer.lnk
[2012/09/15 10:00:38 | 000,001,115 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/15 08:25:48 | 000,095,392 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SMR310.SYS
[2012/09/14 14:53:22 | 000,000,097 | —- | M] () – C:\Windows\SysWow64\PDFWRITR.INI
[2012/09/14 14:53:22 | 000,000,097 | —- | M] () – C:\Windows\SysWow64\__PDF.INI
[2012/09/10 08:36:38 | 000,001,064 | —- | M] () – C:\Users\cwestmas2011\Desktop\trends - Shortcut.lnk
[2012/09/07 17:04:46 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/09/06 20:00:11 | 000,001,118 | —- | M] () – C:\Users\cwestmas2011\Desktop\Poker Income - Shortcut.lnk
[2012/09/06 20:00:01 | 000,001,145 | —- | M] () – C:\Users\cwestmas2011\Desktop\Gambling Income - Shortcut.lnk
[2012/09/04 09:54:42 | 000,000,221 | —- | M] () – C:\Users\cwestmas2011\Desktop\LenderX.url
[2012/08/29 15:14:23 | 000,000,126 | —- | M] () – C:\Windows\VSS.EService.INI
[2012/08/29 11:10:20 | 000,001,307 | —- | M] () – C:\Users\cwestmas2011\Desktop\CNLVZoningOrdinanceCombined - Shortcut.lnk
[2012/08/27 13:48:25 | 000,000,186 | —- | M] () – C:\Users\cwestmas2011\Desktop\The Appraisal Hub, LLC Home - Nationwide Real Estate Appraisal Management Company.url

========== Files Created - No Company Name ==========

[2012/09/21 20:44:01 | 000,458,240 | —- | C] () – C:\Users\cwestmas2011\Desktop\CKScanner.exe
[2012/09/21 20:04:55 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/09/21 20:04:55 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/09/21 20:04:55 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/09/21 20:04:55 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/09/21 20:04:55 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/09/20 22:54:39 | 000,000,512 | —- | C] () – C:\Users\cwestmas2011\Desktop\MBR.dat
[2012/09/20 20:38:46 | 000,002,414 | —- | C] () – C:\Users\cwestmas2011\Desktop\Google Chrome.lnk
[2012/09/20 20:37:05 | 000,000,936 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3398785354-3721342185-2269831038-1001UA.job
[2012/09/20 20:37:05 | 000,000,884 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3398785354-3721342185-2269831038-1001Core.job
[2012/09/20 08:26:35 | 000,000,805 | —- | C] () – C:\Windows\ScanSpyware.INI
[2012/09/19 23:25:27 | 000,001,185 | —- | C] () – C:\Users\cwestmas2011\Desktop\Diagnose & Fix.lnk
[2012/09/19 23:25:27 | 000,001,171 | —- | C] () – C:\Users\cwestmas2011\Desktop\ScanSpyware.lnk
[2012/09/19 20:42:43 | 000,000,784 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/09/17 22:24:10 | 000,001,785 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/09/17 08:18:23 | 000,000,148 | —- | C] () – C:\Users\cwestmas2011\Desktop\Personal Credit Cards, First Bankcard, a division of First National Bank of Omaha (2).url
[2012/09/15 10:00:38 | 000,001,115 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/15 09:50:47 | 000,001,109 | —- | C] () – C:\Users\cwestmas2011\Application Data\Microsoft\Internet Explorer\Quick Launch\FreeFileViewer.lnk
[2012/09/10 08:36:38 | 000,001,064 | —- | C] () – C:\Users\cwestmas2011\Desktop\trends - Shortcut.lnk
[2012/09/06 20:00:11 | 000,001,118 | —- | C] () – C:\Users\cwestmas2011\Desktop\Poker Income - Shortcut.lnk
[2012/09/06 20:00:01 | 000,001,145 | —- | C] () – C:\Users\cwestmas2011\Desktop\Gambling Income - Shortcut.lnk
[2012/09/04 09:54:42 | 000,000,221 | —- | C] () – C:\Users\cwestmas2011\Desktop\LenderX.url
[2012/08/29 11:10:20 | 000,001,307 | —- | C] () – C:\Users\cwestmas2011\Desktop\CNLVZoningOrdinanceCombined - Shortcut.lnk
[2012/08/27 13:48:25 | 000,000,186 | —- | C] () – C:\Users\cwestmas2011\Desktop\The Appraisal Hub, LLC Home - Nationwide Real Estate Appraisal Management Company.url
[2011/11/22 16:24:28 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PDFWRITR.INI
[2011/11/22 16:24:28 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\__PDF.INI
[2011/11/19 07:25:53 | 000,000,126 | —- | C] () – C:\Windows\VSS.EService.INI
[2011/11/15 14:09:12 | 000,000,740 | —- | C] () – C:\Windows\Brpfx04a.ini
[2011/11/15 14:09:12 | 000,000,093 | —- | C] () – C:\Windows\brpcfx.ini
[2011/11/15 14:08:54 | 000,000,426 | —- | C] () – C:\Windows\BRWMARK.INI
[2011/11/15 14:06:51 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2011/11/15 14:06:51 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2011/11/15 14:06:50 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2011/11/15 14:06:32 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\BRTCPCON.DLL
[2011/11/15 14:06:21 | 000,000,114 | —- | C] () – C:\Windows\SysWow64\BRLMW03A.INI
[2011/11/15 14:04:54 | 000,031,767 | —- | C] () – C:\Windows\maxlink.ini
[2011/11/11 22:57:48 | 000,430,080 | —- | C] ( ) – C:\Windows\SysWow64\LMUD1P32comc.dll
[2011/11/11 20:41:32 | 000,421,888 | —- | C] ( ) – C:\Windows\SysWow64\lexlog.dll
[2011/11/11 19:40:33 | 000,000,145 | —- | C] () – C:\Windows\Apexwin.ini
[2011/11/11 19:39:04 | 000,343,040 | —- | C] () – C:\Windows\SysWow64\lffpx7.dll
[2011/11/11 19:39:04 | 000,116,736 | —- | C] () – C:\Windows\SysWow64\lfkodak.dll
[2011/11/11 19:39:03 | 000,017,920 | —- | C] () – C:\Windows\SysWow64\Implode.dll
[2011/11/11 19:38:57 | 000,495,616 | —- | C] () – C:\Windows\SysWow64\Tx32.dll
[2011/11/11 19:38:57 | 000,000,260 | —- | C] () – C:\Windows\SysWow64\ic32.ini
[2011/11/11 19:38:43 | 000,004,608 | —- | C] () – C:\Windows\SysWow64\Cp5.dll
[2011/11/11 19:38:42 | 000,000,086 | —- | C] () – C:\Windows\LHOUSE.INI
[2011/11/11 19:38:39 | 000,514,832 | —- | C] () – C:\Windows\SysWow64\LEAD45.DLL
[2011/11/11 19:38:39 | 000,467,348 | —- | C] () – C:\Windows\SysWow64\TGDRAW16.DLL
[2011/11/11 19:38:39 | 000,201,065 | —- | C] () – C:\Windows\SysWow64\TGDXF16.DLL
[2011/11/11 19:38:39 | 000,193,842 | —- | C] () – C:\Windows\SysWow64\TGENT16.DLL
[2011/11/11 19:38:39 | 000,152,384 | —- | C] () – C:\Windows\SysWow64\TGCURV16.DLL
[2011/11/11 19:38:39 | 000,136,200 | —- | C] () – C:\Windows\SysWow64\TGSOLD16.DLL
[2011/11/11 19:38:39 | 000,127,656 | —- | C] () – C:\Windows\SysWow64\TG2D16.DLL
[2011/11/11 19:38:39 | 000,083,240 | —- | C] () – C:\Windows\SysWow64\TGCIRC16.DLL
[2011/11/11 19:38:39 | 000,081,770 | —- | C] () – C:\Windows\SysWow64\TGCLIP16.DLL
[2011/11/11 19:38:39 | 000,070,784 | —- | C] () – C:\Windows\SysWow64\TG3D16.DLL
[2011/11/11 19:38:39 | 000,070,632 | —- | C] () – C:\Windows\SysWow64\TGPOLY16.DLL
[2011/11/11 19:38:39 | 000,062,976 | —- | C] () – C:\Windows\SysWow64\TGSURF16.DLL
[2011/11/11 19:38:39 | 000,062,464 | —- | C] () – C:\Windows\SysWow64\TGKERN16.DLL
[2011/11/11 19:38:39 | 000,059,872 | —- | C] () – C:\Windows\SysWow64\TGARC16.DLL
[2011/11/11 19:38:39 | 000,053,864 | —- | C] () – C:\Windows\SysWow64\TGSPHR16.DLL
[2011/11/11 19:38:39 | 000,049,256 | —- | C] () – C:\Windows\SysWow64\TGTRF16.DLL
[2011/11/11 19:38:39 | 000,044,032 | —- | C] () – C:\Windows\SysWow64\TGTOOL16.DLL
[2011/11/11 19:38:39 | 000,042,464 | —- | C] () – C:\Windows\SysWow64\TGDBAS16.DLL
[2011/11/11 19:38:39 | 000,030,768 | —- | C] () – C:\Windows\SysWow64\TGCONV16.DLL
[2011/11/11 19:38:39 | 000,030,144 | —- | C] () – C:\Windows\SysWow64\TGTRIG16.DLL
[2011/11/11 19:38:39 | 000,027,304 | —- | C] () – C:\Windows\SysWow64\TGAREA16.DLL
[2011/11/11 19:38:39 | 000,026,408 | —- | C] () – C:\Windows\SysWow64\TGTRIA16.DLL
[2011/11/11 19:38:39 | 000,025,612 | —- | C] () – C:\Windows\SysWow64\TGVOL16.DLL
[2011/11/11 19:12:41 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/11/08 13:16:51 | 000,001,264 | —- | C] () – C:\Windows\THXCfg_SP_APOIM.ini
[2011/11/08 13:16:51 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_HP_APOIM.ini
[2011/11/08 13:16:51 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_APOIM.ini
[2011/11/08 13:16:50 | 000,177,664 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2011/11/08 13:16:50 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2011/02/10 09:10:51 | 000,772,558 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/02/09 21:03:48 | 000,000,326 | —- | C] () – C:\Windows\primopdf.ini

========== ZeroAccess Check ==========

[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

========== LOP Check ==========

[2012/04/05 13:31:08 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\ACI
[2012/09/21 20:09:25 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\DefaultTab
[2011/11/11 19:39:09 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\EServices
[2012/05/19 07:56:19 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\Fingertapps
[2011/11/11 23:28:17 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\GetRightToGo
[2011/12/07 11:57:19 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\Nitro PDF
[2012/07/01 14:34:57 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\OpenCandy
[2012/07/01 14:36:43 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\Paltalk
[2012/09/20 20:18:05 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\PC Cleaners
[2011/12/07 11:58:02 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\PC-FAX TX
[2011/11/13 17:52:50 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\PCDr
[2012/09/20 20:18:06 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\PCPro
[2012/09/15 09:49:57 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\PinPhotoZoom
[2012/01/06 15:23:44 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\PokerCreations
[2012/09/14 14:47:14 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\PrimoPDF
[2012/01/19 12:50:25 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\ScanSoft
[2012/09/19 23:25:30 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\ScanSpyware
[2012/03/04 14:53:32 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\SouthPointPoker
[2012/01/19 12:50:31 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\Zeon

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: AGP440.SYS >
[2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysNative\drivers\AGP440.sys
[2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\erdnt\cache64\atapi.sys
[2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\drivers\atapi.sys
[2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\erdnt\cache86\cngaudit.dll
[2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 18:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\erdnt\cache64\cngaudit.dll
[2009/07/13 18:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\SysNative\cngaudit.dll
[2009/07/13 18:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2007/04/26 03:41:38 | 000,304,920 | —- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\Drivers\storage\R154092\iastor.sys
[2010/09/14 05:24:26 | 000,437,272 | —- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F – C:\Drivers\storage\R284354\x64\iaStor.sys
[2010/09/14 05:24:26 | 000,437,272 | —- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F – C:\Windows\SysNative\drivers\iaStor.sys
[2010/09/14 05:24:26 | 000,437,272 | —- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F – C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_2b0c50dc63f09dae\iaStor.sys
[2010/09/14 05:24:26 | 000,437,272 | —- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F – C:\Windows\SysNative\DriverStore\FileRepository\iastor.inf_amd64_neutral_5b314ccea0aa569d\iaStor.sys

< MD5 for: IASTORV.SYS >
[2010/11/20 20:23:47 | 000,410,496 | —- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D – C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010/11/20 20:23:47 | 000,410,496 | —- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011/11/08 14:49:54 | 000,410,496 | —- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011/11/08 14:49:54 | 000,410,496 | —- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 – C:\Windows\SysNative\drivers\iaStorV.sys
[2011/11/08 14:49:54 | 000,410,496 | —- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 – C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011/11/08 14:49:54 | 000,410,496 | —- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2010/11/20 20:24:01 | 000,695,808 | —- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 – C:\Windows\erdnt\cache64\netlogon.dll
[2010/11/20 20:24:01 | 000,695,808 | —- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 – C:\Windows\SysNative\netlogon.dll
[2010/11/20 20:24:01 | 000,695,808 | —- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010/11/20 20:24:09 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B – C:\Windows\erdnt\cache86\netlogon.dll
[2010/11/20 20:24:09 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B – C:\Windows\SysWOW64\netlogon.dll
[2010/11/20 20:24:09 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2011/11/08 14:49:54 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011/11/08 14:49:54 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A – C:\Windows\SysNative\drivers\nvstor.sys
[2011/11/08 14:49:54 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011/11/08 14:49:54 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010/11/20 20:23:47 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010/11/20 20:23:47 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys

< MD5 for: SCECLI.DLL >
[2010/11/20 20:23:54 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 – C:\Windows\erdnt\cache86\scecli.dll
[2010/11/20 20:23:54 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 – C:\Windows\SysWOW64\scecli.dll
[2010/11/20 20:23:54 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/20 20:24:32 | 000,232,960 | —- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C – C:\Windows\erdnt\cache64\scecli.dll
[2010/11/20 20:24:32 | 000,232,960 | —- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C – C:\Windows\SysNative\scecli.dll
[2010/11/20 20:24:32 | 000,232,960 | —- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\drivers\*.sys /90 >

< >
[2009/07/13 22:08:49 | 000,000,006 | -H– | C] () – C:\Windows\Tasks\SA.DAT
[2009/07/13 22:08:49 | 000,032,542 | —- | C] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/04/08 10:58:15 | 000,000,830 | —- | C] () – C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012/09/20 20:37:05 | 000,000,884 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3398785354-3721342185-2269831038-1001Core.job
[2012/09/20 20:37:05 | 000,000,936 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3398785354-3721342185-2269831038-1001UA.job

< End of report >
Hello satchmo

Thank you for the log.


  • Please remove the following Chrome extension


    • Open Chrome.
    • Click the wrench icon wrench icon on the browser toolbar.
    • Click Tools.
    • Select Extensions.
    • Click the trash can icon Remove an extension from Chrome by the extension you'd like to completely remove (RivalGaming).
    • A confirmation dialog appears, click Remove.

  • Please open OTL


    • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

      :OTL
      File not found (No name found) – C:\USERS\CWESTMAS2011\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VC2RMAKQ.DEFAULT\EXTENSIONS\[removed]
      CHR - Extension: RivalGaming = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\adhmhclafdhfabmmglbcngpddpdeijgd\
      O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\cwestmas2011\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll File not found
      O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
      O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
      O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      O18:64bit: - Protocol\Handler\cozi - No CLSID value found
      O18:64bit: - Protocol\Handler\livecall - No CLSID value found
      O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
      O18:64bit: - Protocol\Handler\msnim - No CLSID value found
      O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
      O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
      O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
      O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
      [2012/09/15 09:57:56 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivalGaming
      [2012/09/15 09:50:03 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shop to Win 17
      
      :Files
      C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivalGaming
      C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shop to Win 17
      ipconfig /flushdns /c
      
      :Commands
      [resethosts]
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
    • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
    • Allow the program to run unhindered.
    • Your machine will re-start itself. This is normal.
    • A log will be created after your machine reboots. Please post the contents of the log in your next reply.

    Please post the OTL log in your next reply and let me know of you are still unable to access your work web site.
New OTL log. I'm still unable to access my work website; here is the error message again if it helps.

Login :
SiteCode : LAS
EventID : 1007
Category : 4
Severity : 1
Log : JS Exception caught in http://www.passioni.me/javascript/toolbar.user.js - Window.OnError: Unexpected quantifier in line 32
Date : Mon Sep 24 2012 - 09:42:08 EDT


All processes killed
========== OTL ==========
File C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\adhmhclafdhfabmmglbcngpddpdeijgd not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\cozi\ deleted successfully.
File Protocol\Handler\cozi - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully.
File Protocol\Handler\skype4com - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype-ie-addon-data\ deleted successfully.
File Protocol\Handler\skype-ie-addon-data - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
File Protocol\Handler\wlpg - No CLSID value found not found.
C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivalGaming folder moved successfully.
C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shop to Win 17 folder moved successfully.
========== FILES ==========
File\Folder C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivalGaming not found.
File\Folder C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shop to Win 17 not found.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\cwestmas2011\Desktop\cmd.bat deleted successfully.
C:\Users\cwestmas2011\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: cwestmas2011
->Temp folder emptied: 10570587 bytes
->Temporary Internet Files folder emptied: 57681517 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 1905008 bytes
->Flash cache emptied: 1014 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: TEMP
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1216 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 49286 bytes
RecycleBin emptied: 370774 bytes

Total Files Cleaned = 67.00 mb


[EMPTYFLASH]

User: All Users

User: cwestmas2011
->Flash cache emptied: 0 bytes

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: TEMP

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.64.0 log created on 09242012_063702

Files\Folders moved on Reboot…
C:\Users\cwestmas2011\AppData\Local\Temp\Low\REG40E6.tmp moved successfully.
C:\Users\cwestmas2011\AppData\Local\Temp\Low\REGA5B0.tmp moved successfully.
C:\Users\cwestmas2011\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\SM9FYKUT\default[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\SM9FYKUT\flextag[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\SM9FYKUT\InboxLight[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\SM9FYKUT\index[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\SM9FYKUT\RteFrame_16.2.7056.0906[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\SM9FYKUT\xmlProxy[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\K7211LU9\EditMessageLight[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\K7211LU9\iframe[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\K7211LU9\resourcespreload[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\K7211LU9\xmlProxy[2].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4YLV35WL\adloader[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4YLV35WL\AjaxHistoryFrame[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4YLV35WL\LocalStorage[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\150TL8F2\flextag[3].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\150TL8F2\Messenger[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\150TL8F2\xmlProxy[1].htm moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
C:\Users\cwestmas2011\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
Hello satchmo

Thank you for the log.

Are you unable to connect to the web site using any of your browsers or do some of them allow you access?

Please let me know (and which does what).
unfortunately that website states that it is only designed to work with IE. so firefox and chrome will not work with it. One other note, I believe the searchq search tool bar is still present on my google chrome browser. Thanks for staying with me on this.
Hello satchmo

I believe the searchq search tool bar is still present on my google chrome browser

Searchqu is not showing up anywhere in your latest OTL log.

Lets see if the following can help us pin it down:


  • Please download SystemLook by JPShortstuff


  • Please download SystemLook by JPShortstuff by clicking here and save it to your desktop.
  • Right click on SystemLook.exe and select "Run as Administrator" to run the program.
  • Copy the content of the following codebox into the main textfield:

:regfind
*Searchqu*

:filefind 
*Searchqu*

:folderfind 
*Searchqu*

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
  • Note: The log can also be found on your Desktop entitled SystemLook.txt

Please post the systemlook log in your next reply.
Here's the log the searchq field in chrome shows up in the upper right corner only (not a full side to side bar) and can be taken out by pressing an 'upward arrow' button (^) SystemLook 30.07.11 by jpshortstuff Log created at 13:14 on 25/09/2012 by cwestmas2011 Administrator - Elevation successful No Context: regfind No Context: *Searchqu* ========== filefind ========== Searching for "*Searchqu*" No files found. ========== folderfind ========== Searching for "*Searchqu" No folders found. -= EOF =-
quite correct: SystemLook 30.07.11 by jpshortstuff Log created at 13:34 on 25/09/2012 by cwestmas2011 Administrator - Elevation successful ========== regfind ========== Searching for "*Searchqu*" No data found. ========== filefind ========== Searching for "*Searchqu*" No files found. ========== folderfind ========== Searching for "*Searchqu" No folders found. -= EOF =-
Hello satchmo

I am not seeing any remaining evidence of Searchqu on your machine. I can only remove what I can see in your system logs. Since you can still see some leftovers of searchqu in your chrome browser it may be prudent to search through your chrome extensions etc, and remove anything pertaining to searchqu. If you do find anything there please let me know since I would have expected the systemlook search to flag it if it were present.

In the meantime I will ask our Tech Team if they can provide any advice relating to your website issue.

I'll get back to you as soon as I can :)
that's fine, i'm sure it won't be giving me any more problems if the scans aren't picking it up. Thanks for the help and look forward to resolving my website issue.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI