This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Search box won't delete [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Search box just appeared . I tried to go to tools, internet options, search options, highlighted the Search Here box, and deleted but it's still here. i did run malwarebytes and it did find a pupbundle, but the search box is still here. computer had been stalling and i tried to use system restore, but it did not restart with success; just said computer couldn't be changed to the earlier date i had picked. just last week i deleted avg from my computer and added norton security since it's free with comcast and now this!!! Please advise.

OTL logfile created on: 10/3/2012 6:26:03 AM - Run 1
OTL by OldTimer - Version 3.2.70.1 Folder = C:\Documents and Settings\Pauline Filighera\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.48 Gb Available Physical Memory | 31.71% Memory free
2.85 Gb Paging File | 1.63 Gb Available in Paging File | 56.93% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.72 Gb Total Space | 37.51 Gb Free Space | 33.58% Space Free | Partition Type: NTFS
Drive G: | 7.34 Gb Total Space | 6.77 Gb Free Space | 92.13% Space Free | Partition Type: FAT32

Computer Name: FAMILY | User Name: Pauline Filighera | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Pauline Filighera\Desktop\otl.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Pauline Filighera\Application Data\DefaultTab\DefaultTab\DTUpdate.exe ()
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\IObit\Advanced SystemCare 5\ASC.exe (IObit)
PRC - C:\Program Files\Norton Security Suite\Engine\6.3.0.14\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Motive\pcCMService.exe (Alcatel-Lucent)
PRC - C:\Program Files\Common Files\Motive\pcServiceHost.exe (Alcatel-Lucent)
PRC - C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe (IObit)
PRC - C:\WINDOWS\SYSTEM32\dldtcoms.exe ( )
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\Pauline Filighera\Application Data\DefaultTab\DefaultTab\DTUpdate.exe ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\DiskMap.dll ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\WebUI.dll ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\sqlite3.dll ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\NtfsData.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ()
MOD - C:\Program Files\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\madexcept_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\madbasic_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\maddisAsm_.bpl ()
MOD - C:\WINDOWS\SYSTEM32\dldtdrs.dll ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\dldtdrpp.dll ()
MOD - C:\WINDOWS\SYSTEM32\dldtcaps.dll ()
MOD - C:\Program Files\Microsoft Office\Office12\ADDINS\ColleagueImport.dll ()
MOD - C:\WINDOWS\SYSTEM32\DLDTcfg.dll ()
MOD - C:\WINDOWS\SYSTEM32\dldtcnv4.dll ()


========== Services (SafeList) ==========

SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (DefaultTabUpdate) – C:\Documents and Settings\Pauline Filighera\Application Data\DefaultTab\DefaultTab\DTUpdate.exe ()
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\6.3.0.14\ccSvcHst.exe (Symantec Corporation)
SRV - (pcCMService) – C:\Program Files\Common Files\Motive\pcCMService.exe (Alcatel-Lucent)
SRV - (pcServiceHost) – C:\Program Files\Common Files\Motive\pcServiceHost.exe (Alcatel-Lucent)
SRV - (dldt_device) – C:\WINDOWS\SYSTEM32\dldtcoms.exe ( )
SRV - (dldtCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\dldtserv.exe ()
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (NMSSvc) – C:\WINDOWS\SYSTEM32\NMSSvc.Exe (Intel Corporation)
SRV - (Bjmcmng) – C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (wanatw) – System32\DRIVERS\wanatw4.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (lbrtfdc) – File not found
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys File not found
DRV - (iAimTV2) – System32\DRIVERS\wATV03nt.sys File not found
DRV - (EL90XBC) – System32\DRIVERS\el90xbc5.sys File not found
DRV - (Changer) – File not found
DRV - (bvrp_pci) – File not found
DRV - (ASPI32) – File not found
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20121002.025\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20121002.025\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20121002.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20120928.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0603000.00E\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0603000.00E\srtspx.sys (Symantec Corporation)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (ccSet_N360) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0603000.00E\ccsetx86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0603000.00E\symefa.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0603000.00E\symtdi.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0603000.00E\ironx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0603000.00E\symds.sys (Symantec Corporation)
DRV - (mfehidk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys (McAfee, Inc.)
DRV - (gameenum) – C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (LBeepKE) – C:\WINDOWS\SYSTEM32\DRIVERS\LBeepKE.sys (Logitech, Inc.)
DRV - (LHidKe) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidKE.Sys (Logitech, Inc.)
DRV - (LMouKE) – C:\WINDOWS\SYSTEM32\DRIVERS\LMouKE.Sys (Logitech, Inc.)
DRV - (L8042Kbd) – C:\WINDOWS\SYSTEM32\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (cdudf_xp) – C:\WINDOWS\System32\drivers\cdudf_xp.sys (Roxio)
DRV - (UdfReadr_xp) – C:\WINDOWS\System32\drivers\udfreadr_xp.sys (Roxio)
DRV - (pwd_2k) – C:\WINDOWS\System32\drivers\pwd_2K.sys (Roxio)
DRV - (mmc_2K) – C:\WINDOWS\System32\drivers\Mmc_2k.sys (Roxio)
DRV - (dvd_2K) – C:\WINDOWS\System32\drivers\Dvd_2k.sys (Roxio)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Roxio)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Roxio)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (MxlW2k) – C:\WINDOWS\System32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (PCDCODEC) – C:\WINDOWS\SYSTEM32\DRIVERS\atinpdxx.sys (ATI Technologies Inc.)
DRV - (MVDCODEC) – C:\WINDOWS\SYSTEM32\DRIVERS\atinmdxx.sys (ATI Technologies Inc.)
DRV - (atinrvxx) – C:\WINDOWS\SYSTEM32\DRIVERS\atinrvxx.sys (ATI Technologies Inc.)
DRV - (ATIXSAudio) – C:\WINDOWS\SYSTEM32\DRIVERS\atinxsxx.sys (ATI Technologies Inc.)
DRV - (ativraxx) – C:\WINDOWS\SYSTEM32\DRIVERS\atinraxx.sys (ATI Technologies Inc.)
DRV - (ATITUNEP) – C:\WINDOWS\SYSTEM32\DRIVERS\atintuxx.sys (ATI Technologies Inc.)
DRV - (NMSCFG) – C:\WINDOWS\SYSTEM32\DRIVERS\NMSCFG.SYS (Intel Corporation)
DRV - (P16X) – C:\WINDOWS\SYSTEM32\DRIVERS\P16X.sys (Creative Technology Ltd.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (LMouFlt2) – C:\WINDOWS\SYSTEM32\DRIVERS\lmouflt2.sys (Logitech)
DRV - (LHidUsb) – C:\WINDOWS\SYSTEM32\DRIVERS\LHIDUSB.SYS (Logitech)
DRV - (LHidFlt2) – C:\WINDOWS\SYSTEM32\DRIVERS\LHIDFLT2.SYS (Logitech)
DRV - (LKbdFlt2) – C:\WINDOWS\SYSTEM32\DRIVERS\lkbdflt2.sys (Logitech)
DRV - (itchfltr) – C:\WINDOWS\SYSTEM32\DRIVERS\itchfltr.sys (Logitech Inc. )
DRV - (PfModNT) – C:\WINDOWS\SYSTEM32\PFMODNT.SYS (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?PC=msnHomeST&OCID;=msnHomepage
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {19B74285-AD12-4EC9-8112-49AAEF4C141D}
IE - HKCU\..\SearchScopes\{19B74285-AD12-4EC9-8112-49AAEF4C141D}: "URL" = http://search.yahoo.com/search?p={searchte…0624,6686,0,8,0
IE - HKCU\..\SearchScopes\{FBAD8B09-36F4-4700-BCC8-38CEB87E85BA}: "URL" = http://www.mysearchresults.com/search?&…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@funwebproducts.com/Plugin: C:\Program Files\FunWebProducts\Installr\1.bin\NPFunWeb.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@Motive.com/npMotiveRequest,version=1.0: C:\Program Files\Common Files\Motive\npMotiveRequest.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.10.835: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.1136: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.11.847: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPlgn\ [2012/09/30 10:25:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\coFFPlgn\ [2012/10/02 20:36:41 | 000,000,000 | —D | M]

[2012/09/30 11:35:24 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Pauline Filighera\Application Data\Mozilla\Extensions
[2010/01/05 12:36:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Pauline Filighera\Application Data\Mozilla\Extensions\[removed]
[2012/09/30 11:35:28 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/17 09:44:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/17 07:06:14 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/17 13:36:24 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/17 08:19:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/17 08:28:07 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/03/18 14:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/03/18 14:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/06/07 09:43:22 | 000,002,134 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\search.xml

O1 HOSTS File: ([2010/06/13 12:30:51 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {134DA043-566E-4572-82E6-8978D0ED03D8} - No CLSID value found.
O2 - BHO: (Qwiklinx) - {3E7C8B5A-96AB-438F-BF9B-782400655440} - C:\Documents and Settings\Pauline Filighera\Application Data\Qwiklinx\Qwiklinx.dll (Qwiklinx, Inc.)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\6.3.0.14\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\6.3.0.14\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Documents and Settings\Pauline Filighera\Application Data\DefaultTab\DefaultTab\DefaultTabBHO.dll (Search Results LLC.)
O2 - BHO: (DCA BHO) - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files\Consumer Input\dca-bho.dll (Compete, Inc.)
O2 - BHO: (no name) - {bb46be07-13eb-4c49-b0f0-fc78b9ea4983} - No CLSID value found.
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\6.3.0.14\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\6.3.0.14\coieplg.dll (Symantec Corporation)
O4 - HKCU..\Run: [Advanced SystemCare 5] C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe (IObit)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_24.dll (Sun Microsystems, Inc.)
O9 - Extra Button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL (ATI Technologies Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsupport.com/OneClickFix/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/Facebo…toUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab (Reg Error: Unable to open value key)
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} http://community.webshots.com/html/atx/wsaxcontrol.cab (Webshots Multiple Media Uploader - Container)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab (Reg Error: Unable to open value key)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1349007454890 (MUWebControl Class)
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} https://www.taxsimple.org/tsweb/msrdp.cab (Microsoft RDP Client Control (redist))
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} http://chat.yahoo.com/cab/yacsui.cab (Yahoo! Audio UI1)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://128.175.60.37/cam/AxisCamControl.ocx (CamImage Class)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://www.pandasoftware.com/activescan/as5/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} http://community.webshots.com/html/WSPhotoUploader.CAB (Webshots Photo Uploader)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Reg Error: Unable to open value key)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab (Reg Error: Unable to open value key)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab (Reg Error: Unable to open value key)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Unable to open value key)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Unable to open value key)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/3.0.1.0…inAxControl.CAB (Reg Error: Unable to open value key)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Unable to open value key)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DCF18086-0455-491C-B239-FC28ACBF6A2A}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\bw+0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw+0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\offline-8876480 {D1923CC4-FD50-4F43-9D11-9AE50DA3401B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\WRNotifier: DllName - (WRLogonNTF.dll) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Pauline Filighera\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Pauline Filighera\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (SsiEfr.e)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ctmp3 - C:\WINDOWS\SYSTEM32\ctmp3.acm (Creative Technology Ltd.)
Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\L3CODECX.ACM (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks, Inc.)
Drivers32: VIDC.DRAW - DVIDEO.DLL File not found
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VCR1 - ATIVCR1.DLL File not found
Drivers32: VIDC.VCR2 - ATIVCR2.DLL File not found
Drivers32: VIDC.YU12 - C:\WINDOWS\System32\atiyuv12.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\atiyuv12.dll ()
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/03 06:24:23 | 000,600,064 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Pauline Filighera\Desktop\otl.exe
[2012/09/30 16:55:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\FileTypeAssistant
[2012/09/30 16:54:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2012/09/30 16:54:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Optimizer Pro
[2012/09/30 16:49:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\My Documents\ShopToWin
[2012/09/30 16:48:34 | 000,000,000 | —D | C] – C:\extensions
[2012/09/30 16:48:29 | 000,000,000 | —D | C] – C:\Program Files\Qwiklinx
[2012/09/30 16:48:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\Application Data\Qwiklinx
[2012/09/30 16:45:19 | 000,000,000 | —D | C] – C:\Program Files\File Type Assistant
[2012/09/30 16:45:12 | 000,000,000 | —D | C] – C:\Program Files\Consumer Input
[2012/09/30 16:44:26 | 000,000,000 | —D | C] – C:\Program Files\Free Offers from Freeze.com
[2012/09/30 16:44:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\Application Data\DefaultTab
[2012/09/30 16:41:24 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agcgauge.ax
[2012/09/30 16:41:12 | 000,046,112 | —- | C] (Adaptec, Inc ) – C:\WINDOWS\System32\dllcache\adptsf50.sys
[2012/09/30 16:41:11 | 000,010,880 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\admjoy.sys
[2012/09/30 16:41:10 | 000,747,392 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8830.sys
[2012/09/30 16:41:10 | 000,553,984 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8820.sys
[2012/09/30 16:41:09 | 000,584,448 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8810.sys
[2012/09/30 16:41:09 | 000,020,160 | —- | C] (ADMtek Incorporated) – C:\WINDOWS\System32\dllcache\adm8511.sys
[2012/09/30 16:41:08 | 000,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adicvls.sys
[2012/09/30 16:41:07 | 000,061,440 | —- | C] (Color Flatbed Scanner) – C:\WINDOWS\System32\dllcache\acerscad.dll
[2012/09/30 16:41:06 | 000,297,728 | —- | C] (Silicon Integrated Systems Corp.) – C:\WINDOWS\System32\dllcache\ac97sis.sys
[2012/09/30 16:41:06 | 000,084,480 | —- | C] (VIA Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ac97via.sys
[2012/09/30 16:41:05 | 000,231,552 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\ac97ali.sys
[2012/09/30 16:41:05 | 000,096,256 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\ac97intc.sys
[2012/09/30 16:41:04 | 000,462,848 | —- | C] (Aureal Inc.) – C:\WINDOWS\System32\dllcache\a3dapi.dll
[2012/09/30 16:41:03 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\61883.sys
[2012/09/30 16:41:03 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\8514a.dll
[2012/09/30 16:41:03 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\4mmdat.sys
[2012/09/30 16:41:02 | 000,689,216 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2012/09/30 16:41:02 | 000,148,352 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2012/09/30 16:41:01 | 000,762,780 | —- | C] (3Com, Inc.) – C:\WINDOWS\System32\dllcache\3cwmcru.sys
[2012/09/30 16:41:01 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\1394vdbg.sys
[2012/09/30 16:41:00 | 000,053,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\1394bus.sys
[2012/09/30 16:40:42 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.dll
[2012/09/30 16:33:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\7-zip
[2012/09/30 16:33:31 | 000,000,000 | —D | C] – C:\Program Files\7-zip
[2012/09/30 12:03:56 | 000,924,320 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0603000.00E\symefa.sys
[2012/09/30 12:03:56 | 000,388,216 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0603000.00E\symtdi.sys
[2012/09/30 12:03:56 | 000,345,208 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0603000.00E\symtdiv.sys
[2012/09/30 12:03:56 | 000,340,088 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0603000.00E\symds.sys
[2012/09/30 12:03:56 | 000,318,584 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0603000.00E\symnets.sys
[2012/09/30 12:03:55 | 000,574,112 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0603000.00E\srtsp.sys
[2012/09/30 12:03:55 | 000,149,624 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0603000.00E\ironx86.sys
[2012/09/30 12:03:55 | 000,132,768 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0603000.00E\ccsetx86.sys
[2012/09/30 12:03:55 | 000,032,928 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0603000.00E\srtspx.sys
[2012/09/30 12:02:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360\0603000.00E
[2012/09/30 10:23:59 | 000,060,872 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2012/09/30 10:23:58 | 000,141,944 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/09/30 10:23:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2012/09/30 10:23:58 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2012/09/30 10:22:54 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360
[2012/09/30 10:22:51 | 000,000,000 | —D | C] – C:\Program Files\Windows Sidebar
[2012/09/30 10:22:51 | 000,000,000 | —D | C] – C:\Program Files\Norton Security Suite
[2012/09/30 10:22:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Norton Security Suite
[2012/09/30 10:22:36 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2012/09/30 10:22:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2012/09/30 10:22:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\My Documents\Symantec
[2012/09/30 10:19:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Norton
[2012/09/30 10:19:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Norton
[2012/09/30 10:16:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\Application Data\comcasttb
[2012/09/30 10:06:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\White_Sky,_Inc
[2012/09/30 10:06:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\Application Data\CallingID
[2012/09/29 15:49:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\Desktop\New Folder
[2012/09/23 16:53:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\Sun
[2012/09/23 13:19:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\IObit
[2012/09/23 13:02:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Advanced SystemCare 5
[2012/09/23 13:02:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\Application Data\IObit
[2012/09/23 13:02:05 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2012/09/23 13:00:29 | 027,669,608 | —- | C] (IObit ) – C:\Documents and Settings\Pauline Filighera\Desktop\asc-setup.exe
[2012/09/23 10:05:52 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/09/23 10:00:36 | 000,821,736 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2012/09/23 10:00:36 | 000,246,760 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2012/09/23 10:00:27 | 000,174,056 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2012/09/23 10:00:27 | 000,174,056 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2012/09/23 10:00:27 | 000,093,672 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2012/09/23 09:49:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\Application Data\Comcast
[2004/08/13 09:10:01 | 004,354,084 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\All Users\spybotsd13.exe

========== Files - Modified Within 30 Days ==========

[2012/10/03 06:32:00 | 000,000,392 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{05FB7325-A3E5-4A8D-86AB-E2AE041BC2C9}.job
[2012/10/03 06:24:23 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Pauline Filighera\Desktop\otl.exe
[2012/10/03 06:17:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/03 06:00:00 | 000,000,908 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/02 21:46:12 | 000,009,103 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\VT20121002.018
[2012/10/02 20:38:26 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/02 20:35:51 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2012/10/02 20:34:49 | 000,000,904 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/02 20:34:48 | 000,000,418 | —- | M] () – C:\WINDOWS\tasks\ProgramUpdateCheck.job
[2012/10/02 20:34:45 | 000,000,434 | —- | M] () – C:\WINDOWS\tasks\PC Optimizer Pro startups.job
[2012/10/02 20:34:18 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2012/10/02 20:34:05 | 1609,613,312 | -HS- | M] () – C:\hiberfil.sys
[2012/10/02 19:22:51 | 000,274,968 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/10/02 07:07:00 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/10/02 06:05:27 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2012/10/01 16:44:00 | 000,000,462 | —- | M] () – C:\WINDOWS\tasks\PC Optimizer Pro Updates.job
[2012/09/30 16:33:33 | 000,000,633 | —- | M] () – C:\Documents and Settings\All Users\Desktop\7-zip.lnk
[2012/09/30 16:21:00 | 000,001,931 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton Security Suite.LNK
[2012/09/30 16:19:11 | 000,808,676 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\Cat.DB
[2012/09/30 12:19:11 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/09/30 10:23:58 | 000,141,944 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/09/30 10:23:58 | 000,060,872 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2012/09/30 10:23:58 | 000,007,468 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/09/30 10:23:58 | 000,000,806 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/09/30 10:19:47 | 000,000,860 | —- | M] () – C:\Documents and Settings\Pauline Filighera\Desktop\Norton Installation Files.lnk
[2012/09/30 09:51:52 | 000,000,815 | —- | M] () – C:\Documents and Settings\Pauline Filighera\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/09/29 17:05:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/09/29 07:11:22 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\rp_stats.dat
[2012/09/29 07:11:22 | 000,000,044 | —- | M] () – C:\WINDOWS\System32\rp_rules.dat
[2012/09/23 13:03:44 | 000,000,925 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Uninstaller.lnk
[2012/09/23 13:03:39 | 000,000,874 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 5.lnk
[2012/09/23 13:03:07 | 000,000,892 | —- | M] () – C:\Documents and Settings\Pauline Filighera\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 5.lnk
[2012/09/23 13:00:33 | 027,669,608 | —- | M] (IObit ) – C:\Documents and Settings\Pauline Filighera\Desktop\asc-setup.exe
[2012/09/23 10:00:09 | 000,093,672 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2012/09/23 10:00:08 | 000,821,736 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2012/09/23 10:00:08 | 000,746,984 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2012/09/23 10:00:08 | 000,246,760 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2012/09/23 10:00:08 | 000,174,056 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2012/09/23 10:00:08 | 000,174,056 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2012/09/23 10:00:08 | 000,143,872 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2012/09/21 02:17:13 | 000,696,240 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/09/21 02:17:13 | 000,073,136 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/09/15 19:24:03 | 000,027,520 | —- | M] () – C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\dt.dat
[2012/09/13 21:04:04 | 002,408,416 | —- | M] () – C:\Documents and Settings\Pauline Filighera\Desktop\9-13-2012 9;04;04 PM.JPG
[2012/09/13 21:00:54 | 002,295,527 | —- | M] () – C:\Documents and Settings\Pauline Filighera\Desktop\9-13-2012 9;00;54 PM.JPG
[2012/09/07 17:04:46 | 000,022,856 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2012/10/02 21:47:41 | 000,009,103 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\VT20121002.018
[2012/09/30 16:54:16 | 000,000,462 | —- | C] () – C:\WINDOWS\tasks\PC Optimizer Pro Updates.job
[2012/09/30 16:54:15 | 000,000,434 | —- | C] () – C:\WINDOWS\tasks\PC Optimizer Pro startups.job
[2012/09/30 16:45:27 | 000,000,418 | —- | C] () – C:\WINDOWS\tasks\ProgramUpdateCheck.job
[2012/09/30 16:33:33 | 000,000,633 | —- | C] () – C:\Documents and Settings\All Users\Desktop\7-zip.lnk
[2012/09/30 16:18:40 | 000,808,676 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\Cat.DB
[2012/09/30 12:03:56 | 000,007,877 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\symnetv.cat
[2012/09/30 12:03:56 | 000,007,492 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\symds.cat
[2012/09/30 12:03:56 | 000,007,458 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\symnet.cat
[2012/09/30 12:03:56 | 000,007,434 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\symefa.cat
[2012/09/30 12:03:56 | 000,003,435 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\symefa.inf
[2012/09/30 12:03:56 | 000,002,852 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\symds.inf
[2012/09/30 12:03:56 | 000,001,469 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\symnetv.inf
[2012/09/30 12:03:56 | 000,001,441 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\symnet.inf
[2012/09/30 12:03:55 | 000,007,450 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\iron.cat
[2012/09/30 12:03:55 | 000,007,446 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\ccsetx86.cat
[2012/09/30 12:03:55 | 000,007,398 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\srtspx.cat
[2012/09/30 12:03:55 | 000,007,380 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\srtsp.cat
[2012/09/30 12:03:55 | 000,001,388 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\srtspx.inf
[2012/09/30 12:03:55 | 000,001,388 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\srtsp.inf
[2012/09/30 12:03:55 | 000,000,827 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\ccsetx86.inf
[2012/09/30 12:03:55 | 000,000,742 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\iron.inf
[2012/09/30 12:02:52 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0603000.00E\isolate.ini
[2012/09/30 10:23:58 | 000,007,468 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/09/30 10:23:58 | 000,000,806 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/09/30 10:23:48 | 000,001,931 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton Security Suite.LNK
[2012/09/30 10:19:43 | 000,000,860 | —- | C] () – C:\Documents and Settings\Pauline Filighera\Desktop\Norton Installation Files.lnk
[2012/09/23 13:03:44 | 000,000,925 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Uninstaller.lnk
[2012/09/23 13:03:39 | 000,000,874 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 5.lnk
[2012/09/23 13:03:07 | 000,000,892 | —- | C] () – C:\Documents and Settings\Pauline Filighera\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 5.lnk
[2012/09/15 19:24:03 | 000,027,520 | —- | C] () – C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\dt.dat
[2012/09/13 21:04:10 | 002,408,416 | —- | C] () – C:\Documents and Settings\Pauline Filighera\Desktop\9-13-2012 9;04;04 PM.JPG
[2012/09/13 21:01:51 | 002,295,527 | —- | C] () – C:\Documents and Settings\Pauline Filighera\Desktop\9-13-2012 9;00;54 PM.JPG
[2012/07/04 13:45:56 | 000,657,720 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/06/06 16:28:12 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dldtvs.dll
[2012/06/06 16:28:10 | 000,360,448 | —- | C] () – C:\WINDOWS\System32\dldtcoin.dll
[2012/06/06 16:27:11 | 000,782,336 | —- | C] () – C:\WINDOWS\System32\dldtdrs.dll
[2012/06/06 16:27:11 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\dldtcaps.dll
[2012/06/06 16:27:11 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\dldtcnv4.dll
[2012/06/06 16:26:29 | 000,017,064 | —- | C] () – C:\WINDOWS\System32\dldtwupd.exe
[2012/06/06 16:26:28 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\dldtwupd.dll
[2012/06/06 16:26:08 | 000,438,272 | —- | C] ( ) – C:\WINDOWS\System32\DLDThcp.dll
[2012/06/06 16:26:08 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\DLDTinst.dll
[2012/06/06 16:26:07 | 000,843,776 | —- | C] ( ) – C:\WINDOWS\System32\dldtusb1.dll
[2012/06/06 16:26:07 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\dldtutil.dll
[2012/06/06 16:26:07 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\dldtinpa.dll
[2012/06/06 16:26:07 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\dldtiesc.dll
[2012/06/06 16:26:06 | 001,105,920 | —- | C] ( ) – C:\WINDOWS\System32\dldtserv.dll
[2012/06/06 16:26:06 | 000,647,168 | —- | C] ( ) – C:\WINDOWS\System32\dldtpmui.dll
[2012/06/06 16:26:06 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\dldtprox.dll
[2012/06/06 16:26:05 | 000,569,344 | —- | C] ( ) – C:\WINDOWS\System32\dldtlmpm.dll
[2012/06/06 16:26:05 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\dldtjswr.dll
[2012/06/06 16:26:04 | 000,663,552 | —- | C] ( ) – C:\WINDOWS\System32\dldthbn3.dll
[2012/06/06 16:26:04 | 000,320,168 | —- | C] ( ) – C:\WINDOWS\System32\dldtih.exe
[2012/06/06 16:26:04 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\dldtinsb.dll
[2012/06/06 16:26:04 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dldtins.dll
[2012/06/06 16:26:04 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dldtinsr.dll
[2012/06/06 16:26:03 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\dldtgrd.dll
[2012/06/06 16:26:03 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dldtcub.dll
[2012/06/06 16:26:03 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\dldtcu.dll
[2012/06/06 16:26:03 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dldtcur.dll
[2012/06/06 16:26:02 | 000,851,968 | —- | C] ( ) – C:\WINDOWS\System32\dldtcomc.dll
[2012/06/06 16:26:02 | 000,594,600 | —- | C] ( ) – C:\WINDOWS\System32\dldtcoms.exe
[2012/06/06 16:26:02 | 000,376,832 | —- | C] ( ) – C:\WINDOWS\System32\dldtcomm.dll
[2012/06/06 16:26:01 | 000,365,224 | —- | C] ( ) – C:\WINDOWS\System32\dldtcfg.exe
[2012/06/06 16:26:01 | 000,077,906 | —- | C] () – C:\WINDOWS\System32\DLDTcfg.dll
[2012/03/24 06:59:35 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2012/03/24 06:59:35 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2012/02/15 20:04:48 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2006/11/13 14:41:20 | 000,001,753 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2004/01/07 21:09:02 | 000,000,140 | —- | C] () – C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\fusioncache.dat
[2003/08/12 09:52:44 | 000,004,608 | —- | C] () – C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2003/05/01 03:54:38 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\System32\shdocvw.dll – [2008/08/20 01:30:51 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/09/30 09:40:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2010/10/16 08:48:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2012/06/08 09:33:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\blekko toolbars
[2012/10/02 21:01:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2003/05/01 03:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2010/10/16 09:37:51 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2006/10/09 16:40:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2012/09/23 13:19:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2012/07/04 13:42:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IsolatedStorage
[2008/01/03 20:32:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2012/09/30 09:39:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/09/30 16:54:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Optimizer Pro
[2008/12/21 19:36:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2012/07/04 13:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\White Sky, Inc
[2011/03/07 16:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/18 12:18:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/29 06:39:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/01/17 09:26:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
[2012/06/07 09:45:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\blekkotb_019
[2012/09/30 11:36:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\CallingID
[2003/12/12 18:45:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\Canon
[2012/09/23 09:49:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\Comcast
[2012/09/30 10:16:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\comcasttb
[2012/09/30 16:44:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\DefaultTab
[2012/06/10 20:15:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\ElevatedDiagnostics
[2011/11/03 16:40:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\Garmin
[2012/09/30 10:31:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\ID Vault
[2012/09/23 13:04:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\IObit
[2005/06/26 20:02:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\Leadertech
[2012/09/30 16:48:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\Qwiklinx
[2007/04/01 16:59:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\Smith Micro
[2011/10/15 12:14:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\TweakNow PowerPack 2011
[2011/10/14 15:18:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\TweakNow RegCleaner 2011

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EX_ >
[2002/08/29 06:00:00 | 000,351,603 | —- | M] () MD5=2690171B51B4DBA59C02E89DB7FE6C9B – C:\I386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 03:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: EXPLORER.EXE.000 >
[2004/08/04 03:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe.000

< MD5 for: EXPLORER.SC_ >
[2002/08/29 06:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\I386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2002/09/03 12:32:50 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2002/08/29 06:00:00 | 000,167,956 | —- | M] () MD5=13A43EAD75BC03C50815444AC3018010 – C:\I386\IEXPLORE.CHM
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/07/17 14:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7(2)\iexplore.chm
[2004/07/17 14:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm
[2004/07/17 14:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ServicePackFiles\i386\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\748dc217ab589bebb960b61219\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.chm

< MD5 for: IEXPLORE.CHW >
[2005/03/16 21:19:12 | 000,185,057 | —- | M] () MD5=248A376A14A92FBF5E94621BAE0771DA – C:\WINDOWS\Help\iexplore.chw

< MD5 for: IEXPLORE.EX_ >
[2002/08/29 06:00:00 | 000,036,925 | —- | M] () MD5=BAC737FDAA9B648A6EBFF76BFAEC7501 – C:\I386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2008/04/13 20:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie8\iexplore.exe
[2008/04/13 20:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
[2004/08/04 03:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe

< MD5 for: IEXPLORE.EXE.26E3AD32.INI >
[2005/03/30 10:12:41 | 000,002,215 | —- | M] () MD5=115989149E411B7F664C67B5C668E6F1 – C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\ApplicationHistory\iexplore.exe.26e3ad32.ini

< MD5 for: IEXPLORE.EXE.HDMP >
[2012/10/02 19:54:12 | 008,915,867 | —- | M] () MD5=19D37C60EF6F61AC0762C849229082BE – C:\Documents and Settings\Pauline Filighera\Local Settings\temp\WER5a87.dir00\iexplore.exe.hdmp
[2012/10/02 19:54:36 | 008,915,867 | —- | M] () MD5=59DCE6C591403A32F9EC0B019ECB4486 – C:\Documents and Settings\Pauline Filighera\Local Settings\temp\WER45e8.dir00\iexplore.exe.hdmp
[2012/10/02 19:54:34 | 008,915,867 | —- | M] () MD5=59DCE6C591403A32F9EC0B019ECB4486 – C:\Documents and Settings\Pauline Filighera\Local Settings\temp\WER5ee4.dir00\iexplore.exe.hdmp
[2012/10/02 19:54:17 | 008,915,867 | —- | M] () MD5=5A013C219E60AAB103DA1E0DA991CCB2 – C:\Documents and Settings\Pauline Filighera\Local Settings\temp\WER44b8.dir00\iexplore.exe.hdmp
[2012/10/02 19:54:17 | 008,915,867 | —- | M] () MD5=765B673FA176A9B2FAA87119B2C51979 – C:\Documents and Settings\Pauline Filighera\Local Settings\temp\WER5f2d.dir00\iexplore.exe.hdmp
[2012/10/02 19:54:20 | 008,915,867 | —- | M] () MD5=EEAFC52ADD1936C976F3EE2416CB28D7 – C:\Documents and Settings\Pauline Filighera\Local Settings\temp\WER5d75.dir00\iexplore.exe.hdmp

< MD5 for: IEXPLORE.EXE.MDMP >
[2012/10/02 19:53:46 | 000,114,422 | —- | M] () MD5=25D8CBD0BD8950DB9684A6C62971E5B9 – C:\Documents and Settings\Pauline Filighera\Local Settings\temp\WER5ee4.dir00\iexplore.exe.mdmp
[2012/10/02 19:53:47 | 000,114,422 | —- | M] () MD5=32915220E45A16A3526BBF6770EAF5E6 – C:\Documents and Settings\Pauline Filighera\Local Settings\temp\WER5a87.dir00\iexplore.exe.mdmp
[2012/10/02 19:53:47 | 000,114,422 | —- | M] () MD5=3932A7684CB20E8ACE6C981A85EF834E – C:\Documents and Settings\Pauline Filighera\Local Settings\temp\WER5f2d.dir00\iexplore.exe.mdmp
[2012/10/02 19:53:47 | 000,114,422 | —- | M] () MD5=4FE136DE9EFB9CFD60A524554078BBB6 – C:\Documents and Settings\Pauline Filighera\Local Settings\temp\WER44b8.dir00\iexplore.exe.mdmp
[2012/10/02 19:53:47 | 000,114,422 | —- | M] () MD5=85415C85A761E9598D63381BBD2AFA8D – C:\Documents and Settings\Pauline Filighera\Local Settings\temp\WER5d75.dir00\iexplore.exe.mdmp
[2012/10/02 19:53:48 | 000,114,422 | —- | M] () MD5=CF48B875295DE4BF7D52104627FD213D – C:\Documents and Settings\Pauline Filighera\Local Settings\temp\WER45e8.dir00\iexplore.exe.mdmp

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2006/10/17 13:04:26 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=E83C9C1F9DD9D47BB44871BFC7E69DDD – C:\748dc217ab589bebb960b61219\iexplore.exe.mui
[2006/10/17 13:04:26 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=E83C9C1F9DD9D47BB44871BFC7E69DDD – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2012/10/03 06:20:39 | 000,134,064 | —- | M] () MD5=6B903D954154CBAC8F6DB713337F9353 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HLP >
[2002/08/29 06:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\I386\IEXPLORE.HLP
[2002/09/03 12:35:04 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2002/08/29 06:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\I386\SERVICES
[2002/08/29 06:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\SYSTEM32\DRIVERS\ETC\SERVICES

< MD5 for: SERVICES.CFG >
[2012/07/27 16:51:34 | 000,586,083 | —- | M] () MD5=6DE4EA437EC1FE6DB27CADB0A7EA8DC2 – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.DLL >
[2003/05/31 12:25:42 | 000,018,432 | —- | M] () MD5=F3E6066CA7F2056DFC94EDCEDCDDCB4C – C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\ChanDir\MMJB\services.dll

< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\ERDNT\cache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\SYSTEM32\DLLCACHE\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\SYSTEM32\services.exe
[2004/08/04 03:56:55 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2002/08/29 06:00:00 | 000,101,376 | —- | M] (Microsoft Corporation) MD5=E3DF4A0252D287C44606EE55355E1623 – C:\I386\SERVICES.EXE

< MD5 for: SERVICES.LNK >
[2010/02/01 02:00:26 | 000,001,602 | —- | M] () MD5=118593D1EC4924AEE77DB3DFA12559A3 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2002/08/29 06:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\I386\SERVICES.MSC
[2002/09/03 12:59:12 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\SYSTEM32\services.msc

< MD5 for: SERVICES.SWF >
[2001/06/12 23:55:50 | 003,089,990 | —- | M] () MD5=B3C169DBC6A61FEB39E4D9C6DE97F777 – C:\Program Files\EarthLink 5.0\Media\services.swf

< MD5 for: WINLOGON.EXE >
[2004/08/04 03:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2002/08/29 06:00:00 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=2246D8D8F4714A2CEDB21AB9B1849ABB – C:\I386\WINLOGON.EXE
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SYSTEM32\DLLCACHE\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SYSTEM32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2002/09/03 12:59:19 | 000,245,920 | R— | M] () – C:\$LDR$
[2012/03/21 06:41:32 | 000,033,148 | —- | M] () – C:\aaw7boot.log
[2009/08/26 13:40:33 | 000,000,211 | —- | M] () – C:\Boot.bak
[2012/10/02 06:05:27 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2002/09/03 09:38:46 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2002/09/03 09:59:58 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2003/05/01 03:37:38 | 000,005,319 | RH– | M] () – C:\DELL.SDR
[2012/06/06 15:46:03 | 000,000,539 | —- | M] () – C:\dlbt.log
[2012/10/02 20:34:05 | 1609,613,312 | -HS- | M] () – C:\hiberfil.sys
[2009/04/02 06:43:58 | 000,000,404 | —- | M] () – C:\INSTALL.LOG
[2002/09/03 09:59:58 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2003/05/01 04:10:46 | 000,000,501 | -H– | M] () – C:\IPH.PH
[2010/06/13 12:37:07 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2002/09/03 09:59:58 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/09/17 19:37:35 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/10/05 09:34:39 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/10/02 20:34:04 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2001/06/09 15:25:34 | 000,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2010/06/08 16:07:17 | 000,000,449 | —- | M] () – C:\rkill.log
[2010/01/06 18:36:18 | 000,002,239 | —- | M] () – C:\rollback.ini
[2007/12/29 13:30:13 | 000,000,512 | —- | M] () – C:\ScanSectorLog.dat
[2012/06/07 12:50:34 | 000,000,495 | —- | M] () – C:\stub.log
[2005/10/31 11:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
[2003/05/01 04:05:28 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2002/09/03 13:07:44 | 000,441,775 | R— | M] () – C:\txtsetup.sif

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/13 18:46:52 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2002/02/12 01:00:00 | 000,013,824 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD43.DLL
[2002/02/12 01:00:00 | 000,043,008 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP43.DLL
[2009/07/02 07:40:18 | 000,147,968 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\dldtdrpp.dll
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >
[2004/05/18 11:49:54 | 000,000,213 | —- | M] () – C:\Documents and Settings\All Users\Favorites\Yahoo! Bookmarks.url

< %APPDATA%\Microsoft\*.* >
[2005/10/10 13:19:21 | 000,001,546 | -H– | M] () – C:\Documents and Settings\Pauline Filighera\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/13 14:34:48 | 000,262,144 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/13 18:29:24 | 000,524,288 | —- | M] () – C:\WINDOWS\System32\config\security.sav
[2004/08/13 14:34:48 | 021,757,952 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/13 14:34:49 | 006,291,456 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/10/05 09:47:20 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/10/05 14:00:40 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Pauline Filighera\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2003/05/06 12:26:21 | 000,000,079 | —- | M] () – C:\Documents and Settings\Pauline Filighera\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2012/09/23 13:00:33 | 027,669,608 | —- | M] (IObit ) – C:\Documents and Settings\Pauline Filighera\Desktop\asc-setup.exe
[2009/05/28 19:53:20 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Pauline Filighera\Desktop\ATF-Cleaner.exe
[2010/06/14 15:38:00 | 002,131,808 | —- | M] (AVG Technologies) – C:\Documents and Settings\Pauline Filighera\Desktop\avg_free_stb_all_9_114_cnet.exe
[2010/11/26 09:43:36 | 002,963,664 | —- | M] (Piriform Ltd) – C:\Documents and Settings\Pauline Filighera\Desktop\ccsetup301.exe
[2010/06/11 07:20:42 | 000,532,480 | —- | M] (Trend Micro Incorporated) – C:\Documents and Settings\Pauline Filighera\Desktop\cwshredder.exe
[2011/06/26 17:49:50 | 000,371,987 | —- | M] () – C:\Documents and Settings\Pauline Filighera\Desktop\ir.exe
[2009/05/24 14:37:55 | 002,434,880 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Pauline Filighera\Desktop\mbam-rules.exe
[2009/05/28 20:22:12 | 003,371,384 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Pauline Filighera\Desktop\mbam-setup.exe
[2012/10/03 06:24:23 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Pauline Filighera\Desktop\otl.exe
[2011/10/15 12:13:57 | 009,443,304 | —- | M] (TweakNow.com ) – C:\Documents and Settings\Pauline Filighera\Desktop\PowerPack342.exe
[2011/10/14 15:17:21 | 005,843,472 | —- | M] (TweakNow.com ) – C:\Documents and Settings\Pauline Filighera\Desktop\RegCleaner640.exe
[2010/06/12 13:42:01 | 000,444,416 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Pauline Filighera\Desktop\TFC.exe
[2010/06/11 21:04:47 | 001,968,248 | —- | M] (W3i, LLC) – C:\Documents and Settings\Pauline Filighera\Desktop\tinyzip.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-09-22 07:02:06

< >
[2002/08/29 06:00:00 | 000,000,065 | RH– | C] () – C:\WINDOWS\Tasks\DESKTOP.INI
[2003/05/01 03:47:22 | 000,000,006 | -H– | C] () – C:\WINDOWS\Tasks\SA.DAT
[2009/05/14 18:40:06 | 000,000,486 | —- | C] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/11/18 19:50:17 | 000,000,904 | —- | C] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2009/11/18 19:50:17 | 000,000,908 | —- | C] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2010/10/28 22:32:40 | 000,000,392 | -H– | C] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{05FB7325-A3E5-4A8D-86AB-E2AE041BC2C9}.job
[2011/08/08 15:01:07 | 000,000,284 | —- | C] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2012/04/11 06:59:54 | 000,000,830 | —- | C] () – C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012/09/30 16:45:27 | 000,000,418 | —- | C] () – C:\WINDOWS\Tasks\ProgramUpdateCheck.job
[2012/09/30 16:54:15 | 000,000,434 | —- | C] () – C:\WINDOWS\Tasks\PC Optimizer Pro startups.job
[2012/09/30 16:54:16 | 000,000,462 | —- | C] () – C:\WINDOWS\Tasks\PC Optimizer Pro Updates.job

< >

< End of report >
———-

OTL Extras logfile created on: 10/3/2012 6:26:03 AM - Run 1
OTL by OldTimer - Version 3.2.70.1 Folder = C:\Documents and Settings\Pauline Filighera\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.48 Gb Available Physical Memory | 31.71% Memory free
2.85 Gb Paging File | 1.63 Gb Available in Paging File | 56.93% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.72 Gb Total Space | 37.51 Gb Free Space | 33.58% Space Free | Partition Type: NTFS
Drive G: | 7.34 Gb Total Space | 6.77 Gb Free Space | 92.13% Space Free | Partition Type: FAT32

Computer Name: FAMILY | User Name: Pauline Filighera | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Unable to open value key File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Unable to open value key
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Unable to open value key
Unknown [openas] – "C:\Program Files\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger – (Logitech)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger – (Microsoft Corporation)
"C:\StubInstaller.exe" = C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer – (LimeWire)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger – (Logitech)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – (Google)
"C:\WINDOWS\SYSTEM32\fxsclnt.exe" = C:\WINDOWS\SYSTEM32\fxsclnt.exe:*:Enabled:Microsoft Fax Console – (Microsoft Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\WINDOWS\SYSTEM32\dldtcoms.exe" = C:\WINDOWS\SYSTEM32\dldtcoms.exe:*:Enabled:V305 Server – ( )
"C:\Program Files\Dell V305\dldtmon.exe" = C:\Program Files\Dell V305\dldtmon.exe:*:Enabled:Printer Device Monitor – ()
"C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldtpswx.exe" = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldtpswx.exe:*:Enabled:Printer Status Window Interface – ()
"C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldttime.exe" = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldttime.exe:*:Enabled:Time Executable – ()
"C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldtjswx.exe" = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldtjswx.exe:*:Enabled:Job Status Window Interface – ()
"C:\Program Files\Dell V305\frun.exe" = C:\Program Files\Dell V305\frun.exe:*:Enabled:Printing Application – ()
"C:\Program Files\Dell V305\dldtlscn.exe" = C:\Program Files\Dell V305\dldtlscn.exe:*:Enabled: – ()
"C:\Program Files\Common Files\Motive\pcServiceHost.exe" = C:\Program Files\Common Files\Motive\pcServiceHost.exe:*:Enabled:pcServiceHost – (Alcatel-Lucent)
"C:\Program Files\File Type Assistant\tsassist.exe" = C:\Program Files\File Type Assistant\tsassist.exe:*:Enabled:ProgramUpdateCheck – (Trusted Software ApS)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01A4AEDE-F219-49A2-B855-16A016EAF9A4}" = Intel® PROSet II
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
"{03F1CC67-5BD8-4C36-8394-76311B2AE69A}" = ArcSoft PhotoStudio 5
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{1126EA35-9A55-4152-AA35-29865470F172}" = Memory Card Utility
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert
"{1D5355BA-562B-4C29-83C0-1D0ED41B2D87}" = TinyZIP
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{25AF0BD1-DF07-4447-8E91-28E99617C556}" = DeadAIM
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 24
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{2E497885-E60B-420A-832D-0148B392E058}_is1" = Qwiklinx
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint
"{349BB121-EDE7-4E86-9698-182FC14B84B6}" = DVDDec
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{438D221C-5B5B-4E4B-B7BD-A86512E5B6C1}" = DAO
"{44A537A5-859C-43A6-8285-C0668142A090}" = iPod for Windows 2005-03-23
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = MouseWare 9.41 .3
"{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
"{64116298-93C5-401D-B06C-39D8E3338508}" = DAO
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77792D6B-6505-4B64-842D-58864D2FA797}" = MMC81
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8 Dell Edition
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARDR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}_STANDARDR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{96E16100-A77F-4B31-B9AD-FFBA040EE1BD}" = Sound Blaster Live!
"{976EA7B1-7562-483D-88DA-4323D263B7CD}" = DiMAGE Viewer
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{99D34763-7E45-4FE5-8424-28DBC3A5F0BF}" = GUIDE PLUS+™ for Windows® System - ATI
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D98F245-3010-43C6-B3B0-67A464DA298E}" = ELNKInst
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B94AA0EE-8F75-4773-A25C-E986D94134B2}" = Microsoft RAW Image Thumbnailer and Viewer for Windows XP
"{BC019EBE-613F-491F-9A83-08E3E8A74CE6}" = EarthLink Free Trial
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1D14C0D-FDAA-4DF2-8441-A902805CCE8C}" = ArcSoft PhotoBase 3
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C73CA646-73B3-4AEF-A136-C37505745174}" = iTunes
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D8AC335B-4479-4B88-A6CF-A37C9A25CC8A}" = DiscoverEcon Schiller 9e
"{E3436EE2-D5CB-4249-840B-3A0140CC34C3}" = Classic PhoneTools
"{E56D39F8-2A9F-44B4-B068-A72E45A073E6}" = Safari
"{EE7B9A8D-19F0-450D-8E94-3E391E6044CD}" = KhalSetup
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"7-zip" = 7-zip v9.20
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced SystemCare 5_is1" = Advanced SystemCare 5
"ATI Display Driver" = ATI Display Driver
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"CCleaner" = CCleaner
"Comcast" = EasySolve
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"DefaultTab" = DefaultTab
"Dell V305" = Dell V305
"DivX Player" = DivX Player
"DivX Pro Codec Adware" = DivX Pro Codec Adware
"ie8" = Windows Internet Explorer 8
"InstallShield_{349BB121-EDE7-4E86-9698-182FC14B84B6}" = ATI DVD Decoder [removed]
"InstallShield_{438D221C-5B5B-4E4B-B7BD-A86512E5B6C1}" = DAO
"InstallShield_{44A537A5-859C-43A6-8285-C0668142A090}" = iPod for Windows 2005-03-23
"InstallShield_{523E6F2A-2D59-4D91-90E8-6C49931C9F50}" = iTunes
"InstallShield_{77792D6B-6505-4B64-842D-58864D2FA797}" = ATI Multimedia Center [removed]
"InstallShield_{9D98F245-3010-43C6-B3B0-67A464DA298E}" = Earthlink Installer - uninstall 'Earthlink 5.0' entry first if present
"JetMP3" = JetMP3
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.0.1400
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Microsoft Press Interactive Training" = Microsoft Interactive Training
"Mihov Image Resizer" = Mihov Image Resizer 1.2 (remove only)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"MUSICMATCH Jukebox" = MUSICMATCH Jukebox
"N360" = Norton Security Suite
"Network Play System (Patching)" = Network Play System (Patching)
"PhotoRecord" = Canon PhotoRecord
"PROR" = Microsoft Office Professional 2007
"PROSet" = Intel® PRO Ethernet Adapter and Software
"RealPlayer 6.0" = RealOne Player
"Registry Mechanic_is1" = Registry Mechanic 5.1
"Shockwave" = Shockwave
"STANDARDR" = Microsoft Office Standard 2007
"Trusted Software Assistant_is1" = File Type Assistant
"TweakNow PowerPack 2011 SP3b_is1" = TweakNow PowerPack 2011 SP3a
"TweakNow RegCleaner 2011_is1" = TweakNow RegCleaner 2011
"Webshots Desktop" = Webshots Desktop
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinMX" = WinMX
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Mail AutoComplete" = Yahoo! Address AutoComplete

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Consumer Input Software" = Consumer Input Software (remove only)

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/25/2012 7:11:06 AM | Computer Name = FAMILY | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 9/29/2012 7:11:45 AM | Computer Name = FAMILY | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 9/30/2012 10:06:58 AM | Computer Name = FAMILY | Source = IDVault | ID = 0
Description = IsStrikeForceAlreadyRunning MainModule.FileName; failed Only part
of a ReadProcessMemory or WriteProcessMemory request was completed at System.Diagnostics.NtProcessManager.GetModuleInfos(Int32
processId, Boolean firstModuleOnly) at System.Diagnostics.NtProcessManager.GetFirstModuleInfo(Int32
processId) at System.Diagnostics.Process.get_MainModule() at .?. ()

Error - 9/30/2012 10:08:07 AM | Computer Name = FAMILY | Source = IDVault | ID = 0
Description = IsStrikeForceAlreadyRunning MainModule.FileName; failed Only part
of a ReadProcessMemory or WriteProcessMemory request was completed at System.Diagnostics.NtProcessManager.GetModuleInfos(Int32
processId, Boolean firstModuleOnly) at System.Diagnostics.NtProcessManager.GetFirstModuleInfo(Int32
processId) at System.Diagnostics.Process.get_MainModule() at .?. ()

Error - 9/30/2012 10:08:44 AM | Computer Name = FAMILY | Source = IDVault | ID = 0
Description = IsStrikeForceAlreadyRunning failed Cannot process request because
the process (4084) has exited. at System.Diagnostics.Process.GetProcessHandle(Int32
access, Boolean throwIfExited) at System.Diagnostics.Process.OpenProcessHandle()

at System.Diagnostics.Process.set_EnableRaisingEvents(Boolean value) at .?.()

Error - 9/30/2012 10:09:23 AM | Computer Name = FAMILY | Source = IDVault | ID = 0
Description = IsStrikeForceAlreadyRunning failed Cannot process request because
the process (312) has exited. at System.Diagnostics.Process.GetProcessHandle(Int32
access, Boolean throwIfExited) at System.Diagnostics.Process.OpenProcessHandle()

at System.Diagnostics.Process.set_EnableRaisingEvents(Boolean value) at .?.()

Error - 10/2/2012 6:49:44 PM | Computer Name = FAMILY | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/2/2012 6:49:45 PM | Computer Name = FAMILY | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/2/2012 6:50:20 PM | Computer Name = FAMILY | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

Error - 10/2/2012 6:51:01 PM | Computer Name = FAMILY | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

[ OSession Events ]
Error - 11/21/2008 5:42:54 PM | Computer Name = FAMILY | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 35194
seconds with 0 seconds of active time. This session ended with a crash.

Error - 2/27/2009 8:31:33 AM | Computer Name = FAMILY | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1284
seconds with 0 seconds of active time. This session ended with a crash.

Error - 11/18/2010 5:05:44 PM | Computer Name = FAMILY | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 93473
seconds with 420 seconds of active time. This session ended with a crash.

Error - 7/3/2011 12:54:42 PM | Computer Name = FAMILY | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 17205
seconds with 0 seconds of active time. This session ended with a crash.

Error - 9/30/2011 6:55:35 AM | Computer Name = FAMILY | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 38
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 10/2/2012 8:14:33 PM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7000
Description = The ASPI32 service failed to start due to the following error: %%2

Error - 10/2/2012 8:14:33 PM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the dldtCATSCustConnectService
service to connect.

Error - 10/2/2012 8:14:33 PM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7000
Description = The dldtCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 10/2/2012 8:18:40 PM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7000
Description = The ASPI32 service failed to start due to the following error: %%2

Error - 10/2/2012 8:18:40 PM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the dldtCATSCustConnectService
service to connect.

Error - 10/2/2012 8:18:40 PM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7000
Description = The dldtCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 10/2/2012 8:35:31 PM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7000
Description = The ASPI32 service failed to start due to the following error: %%2

Error - 10/2/2012 8:35:31 PM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the dldtCATSCustConnectService
service to connect.

Error - 10/2/2012 8:35:31 PM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7000
Description = The dldtCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 10/2/2012 8:35:31 PM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
agp440


< End of report >
Hello pfilighera,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort. This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"
Hi pfilighera,

Download and run ComboFix (select one of the following locations)

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
    (remember to re-enable them when we're done)
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Next

Download AdwCleaner from here and save it to your desktop.
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
In your next post please provide the following:
  • ComboFix.txt
  • AdwCleaner log
When I as downloading The AdwCleaner, somehow i was directed to download a file from www.reimage. i stopped the scan once i realized i had been duped, but i think that's now on my computer unless the AswCleaner that i eventually downloaded deleted it. this happened after the combofix download and before the adwcleaner download. what a mess.
Hello, Just wanted to let you know that i did go to the control panel, add/remove programs and uninstalled that program that i inadvertantly downloaded. i know that you are busy and didn't want to keep it for a few days until you replied. i believe the search box is gone now, but i do keep getting security boxes popping up warning that i am leaving a secure area which i didn't get before.
I read the security box just now. it was advising me that it was a secure site and noone can view it. i checked the box that said don't tell me again.
Hi pfilighera,

In the future kindly post the logs requested into your reply. Please do not attach them unless requested to do so. Thanks. :)

I noticed that you have both AVG Anti-Virus Free Edition 2012 and Norton Security Suite(AV) installed. Having more than one antivirus program running at the same time can
seriously degrade the performance of your system. Please uninstall either AVG Anti-Virus Free Edition 2012 or Norton Security Suite (which ever you prefer) using either the provided
uninstall feature that is part of the antivirus program or through Add/Remove Programs (for Vista and Win 7 users to go to Programs and Features in the Control Panel).
As a rule of thumb one should run one firewall, one antivirus program in memory, and one antispyware utility in memory. It's fine to have other security tools available
on an as-needed or on-demand basis, but when multiple tools simultaneously perform the same function, you're asking for trouble.

- - - - - - - - - -

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the codebox below into it:

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\StubInstaller.exe"=-

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, please post the C:\ComboFix.txt for further review.

Next

Locate Malwarebytes' Anti-Malware (it should be on your desktop).
  • Double - click the MBAM icon to launch the program.
  • Once the program has loaded, select the Update tab to get the latest updates before performing the scan.
  • Select Perform quick scan, then click Scan.

    [external image: Posted Image]

  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Next

Please run Eset Online Scanner

Administrator rights are required to run ESET Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.

In your next post please provide the following:
  • ComboFix log
  • MBAM log
  • ESET log
  • Tell me how your computer is running at the moment
Hello,

The fact that avg shows up is interesting, as i did uninstall it before installing norton. avg is not in the control panel, add/remove programs. there is ati and then bcm and i checked the rest of the programs and it is not there. it is on the desktop, though. can i just delete that? or what do you suggest?

ComboFix 12-10-04.02 - Pauline Filighera 10/07/2012 8:46.4.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.834 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Pauline Filighera\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Norton Security Suite *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Security Suite *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
.
((((((((((((((((((((((((( Files Created from 2012-09-07 to 2012-10-07 )))))))))))))))))))))))))))))))
.
.
2012-10-06 22:22 . 2012-10-06 22:22 ——– d—–w- c:\documents and settings\Pauline Filighera\Application Data\DVDVideoSoft
2012-10-04 23:58 . 2012-10-04 23:58 ——– d—–w- C:\N360_BACKUP
2012-09-30 20:55 . 2012-09-30 21:00 ——– d—–w- c:\documents and settings\Pauline Filighera\Local Settings\Application Data\FileTypeAssistant
2012-09-30 20:54 . 2012-09-30 20:54 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Optimizer Pro
2012-09-30 20:48 . 2012-09-30 20:48 ——– d—–w- C:\extensions
2012-09-30 20:45 . 2012-09-30 20:45 ——– d—–w- c:\program files\File Type Assistant
2012-09-30 20:45 . 2012-09-30 20:45 ——– d—–w- c:\program files\Consumer Input
2012-09-30 20:40 . 2001-08-17 18:56 66048 -c–a-w- c:\windows\system32\dllcache\s3legacy.dll
2012-09-30 20:33 . 2012-09-30 20:33 ——– d—–w- c:\program files\7-zip
2012-09-30 14:23 . 2012-09-30 14:23 60872 —-a-w- c:\windows\system32\S32EVNT1.DLL
2012-09-30 14:23 . 2012-09-30 15:56 ——– d—–w- c:\program files\Common Files\Symantec Shared
2012-09-30 14:23 . 2012-09-30 14:23 ——– d—–w- c:\program files\Symantec
2012-09-30 14:23 . 2012-09-30 14:23 141944 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-09-30 14:22 . 2012-09-30 20:21 ——– d—–w- c:\windows\system32\drivers\N360
2012-09-30 14:22 . 2012-09-30 14:22 ——– d—–w- c:\program files\Norton Security Suite
2012-09-30 14:22 . 2012-09-30 14:22 ——– d—–w- c:\program files\Windows Sidebar
2012-09-30 14:22 . 2012-09-30 14:22 ——– d—–w- c:\program files\NortonInstaller
2012-09-30 14:19 . 2012-09-30 14:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2012-09-30 14:16 . 2012-09-30 14:16 ——– d—–w- c:\documents and settings\Pauline Filighera\Application Data\comcasttb
2012-09-30 14:06 . 2012-09-30 14:06 ——– d—–w- c:\documents and settings\Pauline Filighera\Local Settings\Application Data\White_Sky,_Inc
2012-09-30 14:06 . 2012-09-30 15:36 ——– d—–w- c:\documents and settings\Pauline Filighera\Application Data\CallingID
2012-09-23 20:53 . 2012-09-23 20:53 ——– d—–w- c:\documents and settings\Pauline Filighera\Local Settings\Application Data\Sun
2012-09-23 17:19 . 2012-09-23 17:19 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2012-09-23 17:02 . 2012-09-23 17:04 ——– d—–w- c:\documents and settings\Pauline Filighera\Application Data\IObit
2012-09-23 17:02 . 2012-09-23 17:02 ——– d—–w- c:\program files\IObit
2012-09-23 14:05 . 2012-09-23 14:05 ——– d—–w- c:\program files\Common Files\Java
2012-09-23 14:00 . 2012-09-23 14:00 821736 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-09-23 14:00 . 2012-09-23 14:00 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-23 13:49 . 2012-09-23 13:49 ——– d—–w- c:\documents and settings\Pauline Filighera\Application Data\Comcast
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-23 14:00 . 2010-08-17 11:06 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-09-23 14:00 . 2010-05-17 13:44 746984 —-a-w- c:\windows\system32\deployJava1.dll
2012-09-21 06:17 . 2012-04-11 10:59 696240 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-21 06:17 . 2012-03-21 10:54 73136 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-07 21:04 . 2009-05-29 00:22 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-28 15:14 . 2004-02-06 23:05 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2002-09-03 16:39 43520 ——w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2002-09-03 16:35 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2012-05-28 288128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
2004-03-14 20:33 684032 —-a-w- c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-07-27 20:51 919008 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 5]
2012-05-28 19:56 288128 —-a-w- c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2011-04-20 16:48 58656 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
2001-09-04 21:24 28672 —-a-w- c:\windows\SYSTEM32\Ati2mdxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2003-01-22 02:00 315392 —-a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
2003-08-29 08:59 122880 —-a-w- c:\windows\BCMSMMSG.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJLaunchEXE]
2002-03-14 14:41 630784 —-a-w- c:\program files\Canon\BJCard\BJLaunch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comcast_McciTrayApp]
2012-06-12 00:01 1966592 —-a-w- c:\program files\Comcast\pcTrayApp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\SYSTEM32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
2003-02-24 21:11 266313 —-a-w- c:\program files\AIM95\DeadAIM.ocm
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 15:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
2002-04-03 06:01 135264 —-a-w- c:\program files\Creative\SBLive\Diagnostics\diagent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dldtamon]
2010-02-10 12:39 16040 —-a-w- c:\program files\Dell V305\dldtamon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dldtmon.exe]
2010-02-10 12:39 672424 —-a-w- c:\program files\Dell V305\dldtmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
2002-08-14 23:22 28672 —-a-r- c:\windows\SYSTEM32\DSentry.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
2011-07-27 10:13 434080 —-a-w- c:\progra~1\COMMON~1\MICROS~1\DW\DWTRIG20.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EM_EXEC]
2001-10-09 14:41 35328 —-a-w- c:\progra~1\MOUSEW~1\system\EM_EXEC.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2004-08-04 05:31 208952 —-a-w- c:\windows\IME\IMJP8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-07-19 22:29 421736 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
2007-06-28 20:51 32768 —-a-w- c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
2006-05-10 13:48 94208 —-a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2002-08-14 22:29 90112 —-a-w- c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2002-09-03 16:26 455168 —-a-w- c:\windows\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2002-09-03 16:26 455168 —-a-w- c:\windows\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-11-04 15:30 413696 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 13:04 252848 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2003-05-01 08:10 151597 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 06:00 90112 —-a-w- c:\windows\Updreg.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zBrowser Launcher]
2001-10-09 06:59 200704 —-a-w- c:\program files\Logitech\iTouch\iTouch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\SYSTEM32\\dldtcoms.exe"=
"c:\\Program Files\\Dell V305\\dldtmon.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\dldtpswx.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\dldttime.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\dldtjswx.exe"=
"c:\\Program Files\\Dell V305\\frun.exe"=
"c:\\Program Files\\Dell V305\\dldtlscn.exe"=
"c:\\Program Files\\Common Files\\Motive\\pcServiceHost.exe"=
"c:\\Program Files\\File Type Assistant\\tsassist.exe"=
.
R0 SymDS;Symantec Data Store;c:\windows\SYSTEM32\DRIVERS\N360\0603000.00E\symds.sys [9/30/2012 12:03 PM 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\SYSTEM32\DRIVERS\N360\0603000.00E\symefa.sys [9/30/2012 12:03 PM 924320]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20120928.001\BHDrvx86.sys [10/1/2012 12:47 PM 995488]
R1 ccSet_N360;Norton Security Suite Settings Manager;c:\windows\SYSTEM32\DRIVERS\N360\0603000.00E\ccsetx86.sys [9/30/2012 12:03 PM 132768]
R1 SymIRON;Symantec Iron Driver;c:\windows\SYSTEM32\DRIVERS\N360\0603000.00E\ironx86.sys [9/30/2012 12:03 PM 149624]
R2 dldt_device;dldt_device;c:\windows\system32\dldtcoms.exe -service –> c:\windows\system32\dldtcoms.exe -service [?]
R2 LBeepKE;LBeepKE;c:\windows\SYSTEM32\DRIVERS\LBeepKE.sys [6/28/2007 4:47 PM 3712]
R2 N360;Norton Security Suite;c:\program files\Norton Security Suite\Engine\6.3.0.14\ccsvchst.exe [9/30/2012 12:03 PM 138272]
R2 pcCMService;pcCMService;c:\program files\Common Files\Motive\pcCMService.exe [5/25/2012 11:00 PM 368640]
R2 pcServiceHost;pcServiceHost;c:\program files\Common Files\Motive\pcServiceHost.exe [9/22/2012 8:48 AM 342016]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [9/30/2012 11:00 AM 106656]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20121005.002\IDSXpx86.sys [10/5/2012 7:49 PM 373728]
S2 dldtCATSCustConnectService;dldtCATSCustConnectService;c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldtserv.exe [6/6/2012 4:28 PM 98984]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/18/2009 7:50 PM 135664]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SYSTEM32\Macromed\Flash\FlashPlayerUpdateService.exe [4/11/2012 6:59 AM 250288]
S3 cpuz134;cpuz134;\??\c:\docume~1\PAULIN~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys –> c:\docume~1\PAULIN~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [11/18/2009 7:50 PM 135664]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys –> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 —-a-w- c:\windows\SYSTEM32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 06:17]
.
2012-10-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:34]
.
2012-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-18 23:50]
.
2012-10-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-18 23:50]
.
2012-10-06 c:\windows\Tasks\ProgramUpdateCheck.job
- c:\program files\File Type Assistant\tsassist.exe [2012-09-30 18:22]
.
2012-10-07 c:\windows\Tasks\User_Feed_Synchronization-{05FB7325-A3E5-4A8D-86AB-E2AE041BC2C9}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uSearchAssistant =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-07 09:00
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\N360]
"ImagePath"="\"c:\program files\Norton Security Suite\Engine\6.3.0.14\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\6.3.0.14\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(680)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(1352)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-10-07 09:04:22
ComboFix-quarantined-files.txt 2012-10-07 13:04
ComboFix2.txt 2012-10-06 03:23
.
Pre-Run: 36,323,893,248 bytes free
Post-Run: 36,612,456,448 bytes free
.
- - End Of File - - 851167508F7425535D273055E8D28ECB
——————————-

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Database version: v2012.10.07.03

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Pauline Filighera :: FAMILY [administrator]

10/7/2012 9:13:43 AM
mbam-log-2012-10-07 (09-13-43).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 286141
Time elapsed: 5 minute(s), 26 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
—————-

i will reply with the rest of you requests in a separate posting.
ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=d82666e11e15c149949496d62319651b # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-10-07 03:06:26 # local_time=2012-10-07 11:06:26 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=2560 16777215 100 0 0 0 0 0 # compatibility_mode=3584 16777191 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # compatibility_mode=9217 16777214 0 9 85641812 116965184 0 0 # scanned=99742 # found=1 # cleaned=0 # scan_time=5747 C:\Documents and Settings\Pauline Filighera\Desktop\tinyzip.exe probably a variant of Win32/InstallIQ application (unable to clean) 00000000000000000000000000000000 I ———————————— Computer running better, Thanks to you.
Hi pfilighera,

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the codebox below into it:

SecCenter::
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}

File::
C:\Documents and Settings\Pauline Filighera\Desktop\tinyzip.exe

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, please post the C:\ComboFix.txt for further review.

In your next post please provide the following:
  • ComboFix.txt
  • Do you have any remaining issues?
ComboFix 12-10-04.02 - Pauline Filighera 10/07/2012 22:23:10.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.962 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Pauline Filighera\Desktop\CFScript.txt
AV: Norton Security Suite *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Security Suite *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
FILE ::
"c:\documents and settings\Pauline Filighera\Desktop\tinyzip.exe"
.
.
((((((((((((((((((((((((( Files Created from 2012-09-08 to 2012-10-08 )))))))))))))))))))))))))))))))
.
.
2012-10-07 13:26 . 2012-10-07 13:26 ——– d—–w- c:\program files\ESET
2012-10-06 22:22 . 2012-10-06 22:22 ——– d—–w- c:\documents and settings\Pauline Filighera\Application Data\DVDVideoSoft
2012-10-04 23:58 . 2012-10-04 23:58 ——– d—–w- C:\N360_BACKUP
2012-09-30 20:55 . 2012-09-30 21:00 ——– d—–w- c:\documents and settings\Pauline Filighera\Local Settings\Application Data\FileTypeAssistant
2012-09-30 20:54 . 2012-09-30 20:54 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Optimizer Pro
2012-09-30 20:48 . 2012-09-30 20:48 ——– d—–w- C:\extensions
2012-09-30 20:45 . 2012-09-30 20:45 ——– d—–w- c:\program files\File Type Assistant
2012-09-30 20:45 . 2012-09-30 20:45 ——– d—–w- c:\program files\Consumer Input
2012-09-30 20:40 . 2001-08-17 18:56 66048 -c–a-w- c:\windows\system32\dllcache\s3legacy.dll
2012-09-30 20:33 . 2012-09-30 20:33 ——– d—–w- c:\program files\7-zip
2012-09-30 14:23 . 2012-09-30 14:23 60872 —-a-w- c:\windows\system32\S32EVNT1.DLL
2012-09-30 14:23 . 2012-09-30 15:56 ——– d—–w- c:\program files\Common Files\Symantec Shared
2012-09-30 14:23 . 2012-09-30 14:23 ——– d—–w- c:\program files\Symantec
2012-09-30 14:23 . 2012-09-30 14:23 141944 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-09-30 14:22 . 2012-09-30 20:21 ——– d—–w- c:\windows\system32\drivers\N360
2012-09-30 14:22 . 2012-09-30 14:22 ——– d—–w- c:\program files\Norton Security Suite
2012-09-30 14:22 . 2012-09-30 14:22 ——– d—–w- c:\program files\Windows Sidebar
2012-09-30 14:22 . 2012-09-30 14:22 ——– d—–w- c:\program files\NortonInstaller
2012-09-30 14:19 . 2012-09-30 14:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2012-09-30 14:16 . 2012-09-30 14:16 ——– d—–w- c:\documents and settings\Pauline Filighera\Application Data\comcasttb
2012-09-30 14:06 . 2012-09-30 14:06 ——– d—–w- c:\documents and settings\Pauline Filighera\Local Settings\Application Data\White_Sky,_Inc
2012-09-30 14:06 . 2012-09-30 15:36 ——– d—–w- c:\documents and settings\Pauline Filighera\Application Data\CallingID
2012-09-23 20:53 . 2012-09-23 20:53 ——– d—–w- c:\documents and settings\Pauline Filighera\Local Settings\Application Data\Sun
2012-09-23 17:19 . 2012-09-23 17:19 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2012-09-23 17:02 . 2012-09-23 17:04 ——– d—–w- c:\documents and settings\Pauline Filighera\Application Data\IObit
2012-09-23 17:02 . 2012-09-23 17:02 ——– d—–w- c:\program files\IObit
2012-09-23 14:05 . 2012-09-23 14:05 ——– d—–w- c:\program files\Common Files\Java
2012-09-23 14:00 . 2012-09-23 14:00 821736 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-09-23 14:00 . 2012-09-23 14:00 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-23 13:49 . 2012-09-23 13:49 ——– d—–w- c:\documents and settings\Pauline Filighera\Application Data\Comcast
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-23 14:00 . 2010-08-17 11:06 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-09-23 14:00 . 2010-05-17 13:44 746984 —-a-w- c:\windows\system32\deployJava1.dll
2012-09-21 06:17 . 2012-04-11 10:59 696240 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-21 06:17 . 2012-03-21 10:54 73136 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-07 21:04 . 2009-05-29 00:22 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-28 15:14 . 2004-02-06 23:05 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2002-09-03 16:39 43520 ——w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2002-09-03 16:35 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2012-05-28 288128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
2004-03-14 20:33 684032 —-a-w- c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-07-27 20:51 919008 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 5]
2012-05-28 19:56 288128 —-a-w- c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2011-04-20 16:48 58656 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
2001-09-04 21:24 28672 —-a-w- c:\windows\SYSTEM32\Ati2mdxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2003-01-22 02:00 315392 —-a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
2003-08-29 08:59 122880 —-a-w- c:\windows\BCMSMMSG.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJLaunchEXE]
2002-03-14 14:41 630784 —-a-w- c:\program files\Canon\BJCard\BJLaunch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comcast_McciTrayApp]
2012-06-12 00:01 1966592 —-a-w- c:\program files\Comcast\pcTrayApp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\SYSTEM32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
2003-02-24 21:11 266313 —-a-w- c:\program files\AIM95\DeadAIM.ocm
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 15:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
2002-04-03 06:01 135264 —-a-w- c:\program files\Creative\SBLive\Diagnostics\diagent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dldtamon]
2010-02-10 12:39 16040 —-a-w- c:\program files\Dell V305\dldtamon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dldtmon.exe]
2010-02-10 12:39 672424 —-a-w- c:\program files\Dell V305\dldtmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
2002-08-14 23:22 28672 —-a-r- c:\windows\SYSTEM32\DSentry.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
2011-07-27 10:13 434080 —-a-w- c:\progra~1\COMMON~1\MICROS~1\DW\DWTRIG20.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EM_EXEC]
2001-10-09 14:41 35328 —-a-w- c:\progra~1\MOUSEW~1\system\EM_EXEC.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2004-08-04 05:31 208952 —-a-w- c:\windows\IME\IMJP8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-07-19 22:29 421736 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
2007-06-28 20:51 32768 —-a-w- c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
2006-05-10 13:48 94208 —-a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2002-08-14 22:29 90112 —-a-w- c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2002-09-03 16:26 455168 —-a-w- c:\windows\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2002-09-03 16:26 455168 —-a-w- c:\windows\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-11-04 15:30 413696 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 13:04 252848 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2003-05-01 08:10 151597 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 06:00 90112 —-a-w- c:\windows\Updreg.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zBrowser Launcher]
2001-10-09 06:59 200704 —-a-w- c:\program files\Logitech\iTouch\iTouch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\SYSTEM32\\dldtcoms.exe"=
"c:\\Program Files\\Dell V305\\dldtmon.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\dldtpswx.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\dldttime.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\dldtjswx.exe"=
"c:\\Program Files\\Dell V305\\frun.exe"=
"c:\\Program Files\\Dell V305\\dldtlscn.exe"=
"c:\\Program Files\\Common Files\\Motive\\pcServiceHost.exe"=
"c:\\Program Files\\File Type Assistant\\tsassist.exe"=
.
R0 SymDS;Symantec Data Store;c:\windows\SYSTEM32\DRIVERS\N360\0603000.00E\symds.sys [9/30/2012 12:03 PM 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\SYSTEM32\DRIVERS\N360\0603000.00E\symefa.sys [9/30/2012 12:03 PM 924320]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20120928.001\BHDrvx86.sys [10/1/2012 12:47 PM 995488]
R1 ccSet_N360;Norton Security Suite Settings Manager;c:\windows\SYSTEM32\DRIVERS\N360\0603000.00E\ccsetx86.sys [9/30/2012 12:03 PM 132768]
R1 SymIRON;Symantec Iron Driver;c:\windows\SYSTEM32\DRIVERS\N360\0603000.00E\ironx86.sys [9/30/2012 12:03 PM 149624]
R2 dldt_device;dldt_device;c:\windows\system32\dldtcoms.exe -service –> c:\windows\system32\dldtcoms.exe -service [?]
R2 LBeepKE;LBeepKE;c:\windows\SYSTEM32\DRIVERS\LBeepKE.sys [6/28/2007 4:47 PM 3712]
R2 N360;Norton Security Suite;c:\program files\Norton Security Suite\Engine\6.3.0.14\ccsvchst.exe [9/30/2012 12:03 PM 138272]
R2 pcCMService;pcCMService;c:\program files\Common Files\Motive\pcCMService.exe [5/25/2012 11:00 PM 368640]
R2 pcServiceHost;pcServiceHost;c:\program files\Common Files\Motive\pcServiceHost.exe [9/22/2012 8:48 AM 342016]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [9/30/2012 11:00 AM 106656]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20121005.002\IDSXpx86.sys [10/5/2012 7:49 PM 373728]
S2 dldtCATSCustConnectService;dldtCATSCustConnectService;c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldtserv.exe [6/6/2012 4:28 PM 98984]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/18/2009 7:50 PM 135664]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SYSTEM32\Macromed\Flash\FlashPlayerUpdateService.exe [4/11/2012 6:59 AM 250288]
S3 cpuz134;cpuz134;\??\c:\docume~1\PAULIN~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys –> c:\docume~1\PAULIN~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [11/18/2009 7:50 PM 135664]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys –> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 —-a-w- c:\windows\SYSTEM32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 06:17]
.
2012-10-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:34]
.
2012-10-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-18 23:50]
.
2012-10-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-18 23:50]
.
2012-10-07 c:\windows\Tasks\ProgramUpdateCheck.job
- c:\program files\File Type Assistant\tsassist.exe [2012-09-30 18:22]
.
2012-10-08 c:\windows\Tasks\User_Feed_Synchronization-{05FB7325-A3E5-4A8D-86AB-E2AE041BC2C9}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uSearchAssistant =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-07 22:36
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\N360]
"ImagePath"="\"c:\program files\Norton Security Suite\Engine\6.3.0.14\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\6.3.0.14\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(680)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(6276)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-10-07 22:39:40
ComboFix-quarantined-files.txt 2012-10-08 02:39
ComboFix2.txt 2012-10-07 13:04
ComboFix3.txt 2012-10-06 03:23
.
Pre-Run: 36,364,578,816 bytes free
Post-Run: 36,455,931,904 bytes free
.
- - End Of File - - 6D002CD873D0433EE9F940C3DF00FED2
——————————————-

No issues to speak of. avg still on desktop. just delete?
Hi pfilighera,

Your log appears to be clean. We have a few items to take care of before we get to the All Clean Speech.

Yes, you can just delete the AVG file from your desktop. Your last log shows that your Norton Security Suite's Anti-Virus is disabled. To help protect yourself this must be enabled. Failing to do so will leave your computer vulnerable to re-infection.

Next

The following will implement important cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bold text into the Run box and click OK:

ComboFix /Uninstall
(Note the space between the ..X and the /U, it needs to be there.)

[external image: Posted Image]

Next

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
Next

  • Please go to Start > Control Panel > Add Remove Programs.
  • Locate the following programs:
    • Java™ 6 Update 24
  • Click Remove and allow Windows to completely remove each one in turn.Then reboot your computer to complete this part of the process.
Next

Clear Java Cache
  • Start button, select Control Panel.
  • In the Control Panel, open the Java Control Panel.
  • Click on Settings button under Temporary Internet Files.
  • Click Delete Files button at the Temporary Files Settings window.
  • Click on OK button at confirmation dialog.
  • Exit the Control Panel.

With the above items taken care of let's move on to the All Clean part of the process.

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Make your Mozilla Firefox more secure - This can be done by adding these add-ons:
Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
all good advice that i appreciate. Thank you. I am going to start another thread. my husband's machine has been hijacked. thought i would mention it so if you see my name again, you will know why. when it rains, it pours. thank you for all your help.
Hi pfilighera, You're welcome. Glad I was able to help. :D If you would like you can just post the diagnostic logs for your husband's computer here in this thread and we can get started on cleaning his machine also.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI