This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can't remove Ask.com [Solved]

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Tying hard but can't remove the annoying Ask.com search engine or prevent it from hijacking my Google Chrome searches. The usual "add/remove" tools, and various manual procedures don't work or are outdated. Thanks.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:03:10 PM, on 10/14/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\USB Storage RW\shwicon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\HP DVD\Umbrella\DVDTray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\My Documents\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: DataMngr - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\PROGRA~1\IMESHA~1\Mediabar\Datamngr\BROWSE~1.DLL
O2 - BHO: Search-Results Toolbar - {bff6b2ca-366c-4a90-b685-d87776deb0d2} - C:\PROGRA~1\IMESHA~1\Mediabar\Datamngr\SRTOOL~1\searchresultsDx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coIEPlg.dll
O3 - Toolbar: Search-Results Toolbar - {bff6b2ca-366c-4a90-b685-d87776deb0d2} - C:\PROGRA~1\IMESHA~1\Mediabar\Datamngr\SRTOOL~1\searchresultsDx.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDTray] "C:\Program Files\HP DVD\Umbrella\DVDTray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\IMESHA~1\Mediabar\Datamngr\DATAMN~1.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [mserv] C:\Documents and Settings\Administrator\Application Data\svcst.exe
O4 - HKCU\..\Run: [yuxvxnwm] C:\Documents and Settings\Administrator\Local Settings\Application Data\usnevg\ljkesftav.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - S-1-5-18 Startup: PowerReg Scheduler V3.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: PowerReg Scheduler V3.exe (User 'Default user')
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Help - {6B0BE67B-807A-4BC9-B7EE-D60E2BBE32A1} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {6D7FAE45-95AF-42FF-B7FC-01A6232F8A27} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Support - {B8BC8EC4-A445-41B2-873F-132F2EB14733} - http://www.comcastsupport.com (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/sdccommon/download/tgctlsr.cab
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/distribution/al…x-w32-2.0.1.cab
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/63.24/uploader2.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - AppInit_DLLs: C:\PROGRA~1\IMESHA~1\Mediabar\Datamngr\datamngr.dll C:\PROGRA~1\IMESHA~1\Mediabar\Datamngr\IEBHO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe

–
End of file - 9725 bytes
Hello piechase and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly.

Satchfan
Hello again

P2P - I see you have P2P software, (iMesh), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Run HijackThis

Open HijackThis and click Do a system scan only.

Place a check mark next to:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.net
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
O2 - BHO: DataMngr - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\PROGRA~1\IMESHA~1\Mediabar\Datamngr\BROWSE~1.DLL
O2 - BHO: Search-Results Toolbar - {bff6b2ca-366c-4a90-b685-d87776deb0d2} - C:\PROGRA~1\IMESHA~1\Mediabar\Datamngr\SRTOOL~1\searchresultsDx.dll
O3 - Toolbar: Search-Results Toolbar - {bff6b2ca-366c-4a90-b685-d87776deb0d2} - C:\PROGRA~1\IMESHA~1\Mediabar\Datamngr\SRTOOL~1\searchresultsDx.dll
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\IMESHA~1\Mediabar\Datamngr\DATAMN~1.EXE
O4 - HKCU\..\Run: [mserv] C:\Documents and Settings\Administrator\Application Data\svcst.exe
O4 - HKCU\..\Run: [yuxvxnwm] C:\Documents and Settings\Administrator\Local Settings\Application Data\usnevg\ljkesftav.exe
O20 - AppInit_DLLs: C:\PROGRA~1\IMESHA~1\Mediabar\Datamngr\datamngr.dll C:\PROGRA~1\IMESHA~1\Mediabar\Datamngr\IEBHO.dll


Close all windows except for HijackThis and click Fix checked.

===================================================

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply. Note - do NOT attempt any Fix yet.
Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
Hello Satchfan,
OTL.Txt, Extras.Txt & aswMBR follow. I had suspected "Imesh" and attempted removal through XP's "add or remove programs"; it appeared to uninstall, however "Imesh" still appears in the address bar whenever I open Google chrome. Thank you, Jim

OTL logfile created on: 10/15/2012 9:18:07 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.50 Gb Total Physical Memory | 1.92 Gb Available Physical Memory | 76.69% Memory free
3.10 Gb Paging File | 2.57 Gb Available in Paging File | 82.80% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.32 Gb Total Space | 77.82 Gb Free Space | 72.51% Space Free | Partition Type: NTFS
Drive D: | 4.45 Gb Total Space | 0.75 Gb Free Space | 16.89% Space Free | Partition Type: FAT32
Drive H: | 62.45 Mb Total Space | 33.19 Mb Free Space | 53.14% Space Free | Partition Type: FAT
Drive L: | 232.83 Gb Total Space | 203.16 Gb Free Space | 87.26% Space Free | Partition Type: FAT32

Computer Name: BREEZEWAY | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/10/15 09:14:41 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
PRC - [2012/09/20 12:20:34 | 001,898,960 | —- | M] (iMesh, Inc) – C:\Program Files\iMesh Applications\Mediabar\Datamngr\datamngrUI.exe
PRC - [2011/04/16 20:45:11 | 000,130,008 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccsvchst.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2003/12/10 23:09:34 | 000,046,592 | R— | M] (Dantz Development Corporation) – C:\Program Files\Dantz\Retrospect\wdsvc.exe
PRC - [2003/11/12 13:46:34 | 000,049,152 | —- | M] (Dantz Development Corporation) – C:\Program Files\Dantz\Retrospect\retrorun.exe
PRC - [2003/07/23 11:41:54 | 000,065,536 | —- | M] (Hewlett-Packard Company) – C:\Program Files\HP DVD\Umbrella\DVDTray.exe
PRC - [2002/10/25 18:33:46 | 000,069,632 | —- | M] (MyComp) – C:\Program Files\USB Storage RW\shwicon.exe


========== Modules (No Company Name) ==========

MOD - [2012/01/08 09:41:12 | 000,093,696 | —- | M] () – C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2006/10/22 13:22:00 | 000,212,992 | —- | M] () – C:\WINDOWS\system32\nvapi.dll


========== Services (SafeList) ==========

SRV - [2012/10/08 21:55:53 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2011/06/13 23:09:22 | 000,267,568 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Fix it Center\Matsvc.exe – (MatSvc)
SRV - [2011/04/16 20:45:11 | 000,130,008 | R— | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe – (N360)
SRV - [2003/12/10 23:09:34 | 000,046,592 | R— | M] (Dantz Development Corporation) [Auto | Running] – C:\Program Files\Dantz\Retrospect\wdsvc.exe – (RetroWDSvc)
SRV - [2003/11/12 13:46:34 | 000,110,592 | —- | M] (Dantz Development Corporation) [Auto | Stopped] – C:\Program Files\Dantz\Retrospect\rthlpsvc.exe – (Retrospect Helper)
SRV - [2003/11/12 13:46:34 | 000,049,152 | —- | M] (Dantz Development Corporation) [Auto | Running] – C:\Program Files\Dantz\Retrospect\retrorun.exe – (RetroLauncher)
SRV - [2002/11/14 11:09:14 | 000,077,824 | —- | M] (HP) [On_Demand | Stopped] – C:\WINDOWS\system32\hphipm11.exe – (Pml Driver HPH11)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMNDIS.SYS – (SYMNDIS)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMIDS.SYS – (SYMIDS)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMFW.SYS – (SYMFW)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PCDRDRV)
DRV - File not found [Kernel | Auto | Stopped] – C:\Program Files\LogMeIn\x86\RaInfo.sys – (LMIInfo)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [File_System | Boot | Stopped] – system32\DRIVERS\Lbd.sys – (Lbd)
DRV - File not found [Kernel | System | Stopped] – – (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys – (EraserUtilDrvI9)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - [2012/09/13 08:18:35 | 001,601,184 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20121014.006\NAVEX15.SYS – (NAVEX15)
DRV - [2012/09/13 08:18:35 | 000,092,704 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20121014.006\NAVENG.SYS – (NAVENG)
DRV - [2012/08/31 20:27:25 | 000,373,728 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20121012.001\IDSXpx86.sys – (IDSxpx86)
DRV - [2012/08/31 18:09:14 | 000,995,488 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20120928.001\BHDrvx86.sys – (BHDrvx86)
DRV - [2012/08/09 08:22:40 | 000,376,480 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2012/08/09 08:22:40 | 000,106,656 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2011/05/18 08:13:42 | 000,126,584 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2011/04/20 21:37:49 | 000,369,784 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\symtdi.sys – (SYMTDI)
DRV - [2011/03/30 23:00:09 | 000,516,216 | —- | M] (Symantec Corporation) [File_System | System | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\srtsp.sys – (SRTSP)
DRV - [2011/03/30 23:00:09 | 000,050,168 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\srtspx.sys – (SRTSPX)
DRV - [2011/03/14 22:31:23 | 000,744,568 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\symefa.sys – (SymEFA)
DRV - [2011/01/27 02:47:10 | 000,340,088 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\symds.sys – (SymDS)
DRV - [2010/11/15 21:45:33 | 000,136,312 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\ironx86.sys – (SymIRON)
DRV - [2009/09/16 10:22:48 | 000,214,664 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2009/09/16 10:22:48 | 000,079,816 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2009/09/16 10:22:48 | 000,040,552 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfesmfk.sys – (mfesmfk)
DRV - [2009/09/16 10:22:48 | 000,035,272 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2009/09/16 10:22:14 | 000,034,248 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mferkdk.sys – (mferkdk)
DRV - [2008/05/19 15:24:04 | 000,083,288 | —- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] – C:\WINDOWS\System32\LMIRfsClientNP.dll – (LMIRfsClientNP)
DRV - [2008/03/07 13:39:50 | 000,045,848 | —- | M] (LogMeIn, Inc.) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys – (LMIRfsDriver)
DRV - [2004/10/01 11:24:02 | 002,279,424 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM)
DRV - [2004/08/04 01:31:32 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\rtl8139.sys – (rtl8139)
DRV - [2003/10/01 18:41:28 | 000,177,664 | —- | M] (Emuzed, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\EvcapMau.sys – (EvcapMaui)
DRV - [2003/05/02 03:12:14 | 000,009,856 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (pfc)
DRV - [2003/03/08 01:13:22 | 000,624,369 | —- | M] (LT) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ltmdmnt.sys – (ltmodem5)
DRV - [2003/01/07 13:32:26 | 000,015,400 | R— | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\NetMotCM.sys – (ndiscm)
DRV - [2001/11/01 14:14:04 | 000,017,024 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\scopex0.sys – (GT891x)
DRV - [2001/09/20 09:58:48 | 000,153,824 | —- | M] (Zoran Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\NUVvid2.sys – (NUVision)
DRV - [2001/09/20 09:47:38 | 000,025,184 | —- | M] (Zoran Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nuvaud2.sys – (nuvaud2)
DRV - [2001/08/05 22:13:54 | 000,314,720 | R— | M] (Grandtech Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\scopex1.SYS – (DCamUSBGrandTek)
DRV - [2001/06/04 16:00:00 | 000,014,112 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}


IE - HKU\.DEFAULT\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost

IE - HKU\S-1-5-18\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost

IE - HKU\S-1-5-19\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.msnbc.msn.com/ [binary data]
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..\SearchScopes\{5AFB1C08-DA54-4C8F-AF4B-8A05B911FC67}: "URL" = http://www.google.com/search?q={searchTerm…1I7GGLJ_enUS292
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..\SearchScopes\{611F04C5-F1CA-4EBA-96D7-9789A5C7AE4B}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7GGLD
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7GGLJ
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}: "URL" = http://inboxtoolbar.com/search/dispatcher….0342&lng=en
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-698036064-2301516679-3255942371-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..network.proxy.no_proxies_on: "localhost"


FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2629: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2012/02/08 08:50:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_13_2 [2012/10/14 20:18:33 | 000,000,000 | —D | M]

[2011/03/01 22:30:16 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ulda3u9v.default\extensions
[2007/10/08 19:25:52 | 000,024,576 | —- | M] (My Web Search) – C:\Program Files\mozilla firefox\plugins\NPMySrWB.dll

========== Chrome ==========

CHR - homepage: http://search.imesh.net/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://search.imesh.net/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2002/08/29 15:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..\Toolbar\ShellBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..\Toolbar\WebBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O4 - HKLM..\Run: [DVDTray] C:\Program Files\HP DVD\Umbrella\DVDTray.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW" File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKU\.DEFAULT..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe File not found
O4 - HKU\S-1-5-18..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe File not found
O4 - HKU\S-1-5-21-698036064-2301516679-3255942371-500..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe (Leader Technologies)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [ [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-698036064-2301516679-3255942371-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O15 - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-698036064-2301516679-3255942371-500\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsupport.com/sdccommon/download/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} http://www.alternatiff.com/distribution/al…x-w32-2.0.1.cab (AlternaTIFF ActiveX)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} http://picasaweb.google.com/s/v/63.24/uploader2.cab (UploadListView Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EB963901-38AC-4F95-94FA-E6B7B8E09825}: DhcpNameServer = 75.75.75.75 75.75.76.76
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\Userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/05/06 00:12:36 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2002/09/11 03:02:32 | 000,000,045 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2002/10/17 09:56:50 | 000,000,036 | RH– | M] () - L:\AUTORUN.INF – [ FAT32 ]
O32 - AutoRun File - [2003/03/21 12:00:56 | 000,000,000 | RH-D | M] - L:\AUTORUN – [ FAT32 ]
O33 - MountPoints2\{f0820590-d333-11df-b3e3-000c6e7713b0}\Shell - "" = AutoRun
O33 - MountPoints2\{f0820590-d333-11df-b3e3-000c6e7713b0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f0820590-d333-11df-b3e3-000c6e7713b0}\Shell\AutoRun\command - "" = L:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/08 22:08:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Quicken
[2012/10/08 22:08:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Palo Alto Software
[2012/10/05 09:09:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\Nana-Grampa-Larkin
[2012/09/29 15:36:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\Favorites
[2012/09/24 23:03:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\searchresultstb
[2012/09/24 23:03:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\AppData
[2012/09/24 23:03:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\imeshtoolbar2
[2012/09/24 23:03:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\92AF
[2012/09/24 23:03:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2012/09/24 23:01:38 | 000,000,000 | —D | C] – C:\Program Files\iMesh Applications
[2012/09/24 23:00:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\PackageAware
[2012/09/17 21:09:21 | 000,477,168 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\npdeployJava1.dll
[2012/09/17 21:09:21 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/09/17 21:09:20 | 000,157,680 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/09/17 21:09:19 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/09/17 21:09:19 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/09/17 21:08:37 | 000,000,000 | —D | C] – C:\Program Files\Java
[2005/12/02 20:18:20 | 019,846,914 | —- | C] (NVIDIA Corporation) – C:\Program Files\71.89_win2kxp_english.exe
[2005/08/09 22:34:49 | 006,860,424 | —- | C] (Microsoft Corporation ) – C:\Program Files\MicrosoftAntiSpywareInstall.exe
[2005/07/25 17:33:26 | 002,575,792 | —- | C] (Simple Star, Inc.) – C:\Program Files\comcast_photoshow_deluxe_4.exe
[2005/07/25 15:58:57 | 000,465,096 | —- | C] (Simple Star, Inc.) – C:\Program Files\SnapfishPhotoShow.exe
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/15 08:55:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/15 08:35:01 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/15 07:53:46 | 000,087,959 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2012/10/15 07:53:15 | 000,000,616 | -H– | M] () – C:\WINDOWS\tasks\ConfigExec.job
[2012/10/15 07:52:31 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/15 07:50:16 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc208ea0ecc77e.job
[2012/10/15 07:49:44 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/15 07:49:23 | 2683,752,448 | -HS- | M] () – C:\hiberfil.sys
[2012/10/14 21:38:00 | 000,000,580 | -H– | M] () – C:\WINDOWS\tasks\DataUpload.job
[2012/10/14 20:48:23 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmpB02EC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmpEEEDC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmpA8FDC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmp2E0EC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmp24EDC.FOT
[2012/10/14 12:19:46 | 000,001,824 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/10/14 12:19:46 | 000,001,802 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/10/12 17:25:10 | 000,019,783 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\JimLHS-Expenses.ods
[2012/10/10 08:50:02 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/10/09 14:31:31 | 000,037,926 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\tomichromeII.ods
[2012/10/08 22:14:32 | 000,001,318 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2012/10/08 22:14:32 | 000,000,431 | —- | M] () – C:\WINDOWS\intuprof.ini
[2012/10/08 22:09:39 | 000,000,064 | —- | M] () – C:\WINDOWS\qwimp.ini
[2012/10/08 22:08:48 | 000,001,486 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Quicken 2004.lnk
[2012/10/08 22:08:48 | 000,000,228 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Best for Quicken - Low Intro APR and Optional Travel Rewards.url
[2012/10/08 22:08:48 | 000,000,203 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Special Offer from Citibank.url
[2012/10/08 22:08:48 | 000,000,189 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Visit Quicken.com.url
[2012/10/08 22:08:30 | 000,000,686 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
[2012/10/08 21:55:47 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/08 21:55:47 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/09/24 10:42:38 | 000,001,181 | —- | M] () – C:\WINDOWS\cdplayer.ini
[2012/09/21 13:06:29 | 000,010,240 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\displays.odt
[2012/09/17 21:08:45 | 000,477,168 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\npdeployJava1.dll
[2012/09/17 21:08:45 | 000,157,680 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/09/17 21:08:45 | 000,149,488 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/09/17 21:08:45 | 000,149,488 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/09/17 21:08:45 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/09/17 21:08:44 | 000,473,072 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/14 20:48:23 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmpB02EC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmpEEEDC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmpA8FDC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmp2E0EC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmp24EDC.FOT
[2012/10/08 22:09:39 | 000,000,064 | —- | C] () – C:\WINDOWS\qwimp.ini
[2012/10/08 22:08:48 | 000,000,228 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Best for Quicken - Low Intro APR and Optional Travel Rewards.url
[2012/10/08 22:08:48 | 000,000,203 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Special Offer from Citibank.url
[2012/10/08 22:08:48 | 000,000,189 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Visit Quicken.com.url
[2012/10/08 22:08:30 | 000,000,686 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
[2012/10/08 22:08:29 | 000,001,486 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Quicken 2004.lnk
[2012/09/20 22:17:16 | 000,010,240 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\displays.odt
[2012/02/15 20:01:42 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2009/10/07 18:01:34 | 000,019,707 | —- | C] () – C:\Documents and Settings\All Users\Application Data\exezeda.vbs
[2009/10/07 18:01:34 | 000,019,291 | —- | C] () – C:\Documents and Settings\All Users\Application Data\igodu.com
[2009/10/07 18:01:34 | 000,019,231 | —- | C] () – C:\Documents and Settings\All Users\Application Data\gunyfaj.sys
[2009/10/07 18:01:34 | 000,017,473 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\ajinavyrot.lib
[2009/10/07 18:01:34 | 000,015,316 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\tacevikob.bat
[2009/10/07 18:01:34 | 000,015,145 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\dyzitep.bin
[2009/10/07 18:01:34 | 000,014,250 | —- | C] () – C:\Documents and Settings\All Users\Application Data\opap.reg
[2009/10/07 18:01:34 | 000,011,715 | —- | C] () – C:\Program Files\Common Files\hijak.ban
[2009/10/07 18:01:34 | 000,011,269 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\cicizihu.ban
[2009/10/07 17:38:58 | 000,018,655 | —- | C] () – C:\Program Files\Common Files\isekopibej.db
[2009/10/07 17:38:58 | 000,017,958 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\gaje.reg
[2009/10/07 17:38:58 | 000,017,412 | —- | C] () – C:\Program Files\Common Files\hodusur.dat
[2009/10/07 17:38:58 | 000,015,582 | —- | C] () – C:\Documents and Settings\All Users\Application Data\gulynohyx.reg
[2009/10/07 17:38:58 | 000,015,450 | —- | C] () – C:\Program Files\Common Files\ytuxydy.pif
[2009/10/07 17:38:58 | 000,014,860 | —- | C] () – C:\Documents and Settings\All Users\Application Data\jimot.ban
[2009/10/07 17:38:58 | 000,014,336 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\weniwez.dl
[2009/10/07 17:38:58 | 000,014,289 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\amovehiri.bat
[2009/10/07 17:38:58 | 000,012,934 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\dahi.vbs
[2009/10/07 17:38:57 | 000,014,744 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\qalyso.pif
[2009/10/07 17:38:57 | 000,010,668 | —- | C] () – C:\Program Files\Common Files\gihirof.bat
[2009/10/07 17:38:57 | 000,010,329 | —- | C] () – C:\Program Files\Common Files\geso._dl
[2009/10/07 17:33:16 | 000,000,000 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\svcst.exe
[2009/07/13 13:22:03 | 003,296,158 | —- | C] () – C:\Documents and Settings\Administrator\FredAstaireEleanorPowell1.wmv
[2009/06/20 14:59:05 | 001,127,767 | —- | C] () – C:\Documents and Settings\Administrator\malpki.wmv
[2009/06/05 13:51:21 | 000,000,397 | —- | C] () – C:\Documents and Settings\Administrator\IceHarvast2.lnk
[2009/05/29 11:15:48 | 000,889,676 | —- | C] () – C:\Documents and Settings\Administrator\CourtesyofUSMarines (1).wmv
[2009/05/29 09:13:21 | 001,977,352 | —- | C] () – C:\Documents and Settings\Administrator\Weight_Lifting_Surprise.wmv
[2009/05/26 09:21:14 | 000,889,676 | —- | C] () – C:\Documents and Settings\Administrator\CourtesyofUSMarines.wmv
[2009/02/11 15:00:16 | 000,000,596 | RHS- | C] () – C:\Documents and Settings\Administrator\ntuser.pol
[2006/11/23 23:26:14 | 000,008,055 | —- | C] () – C:\Program Files\1615855.htm
[2006/11/21 12:52:32 | 000,252,416 | —- | C] () – C:\Program Files\uninstall_flash_player.exe
[2006/05/18 20:38:42 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/28 22:37:21 | 000,010,322 | —- | C] () – C:\Program Files\pot[1][1].tv_02119_20030815__hs-death.rm.torrent
[2006/02/10 14:01:01 | 017,496,033 | —- | C] () – C:\Program Files\1955-56 Parts manual-B.djvu
[2006/02/08 10:39:58 | 003,338,240 | —- | C] () – C:\Documents and Settings\Administrator\s-1-5-21-698036064-2301516679-3255942371-500.rrr
[2005/11/21 23:55:44 | 013,831,036 | —- | C] () – C:\Program Files\VibeComcastVMInstall.exe
[2004/03/29 21:35:38 | 000,000,616 | —- | C] () – C:\Documents and Settings\Administrator\plugin131_09.trace
[2004/01/02 13:30:54 | 000,000,507 | -H– | C] () – C:\Documents and Settings\Administrator\Application Data\hpothb07.tif
[2004/01/02 13:30:54 | 000,000,376 | -H– | C] () – C:\Documents and Settings\Administrator\Application Data\hpothb07.dat
[2004/01/01 21:49:21 | 000,061,678 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\PFP100JPR.{PB
[2004/01/01 21:49:21 | 000,012,358 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\PFP100JCM.{PB
[2003/12/27 14:00:09 | 000,086,528 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/05/06 01:14:38 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat

========== ZeroAccess Check ==========

[2003/05/06 00:08:52 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\System32\shdocvw.dll – [2008/04/13 20:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >
[2004/06/21 22:00:17 | 000,273,408 | —- | M] () – C:\F5U208_WinXP.exe

< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 03:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/04 03:56:55 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe

< MD5 for: SVCHOST.EXE >
[2008/04/13 20:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 20:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2004/08/04 03:56:57 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/04 03:56:57 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/04 03:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: ST3120025A
Partitions: 2
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: USB Card Reader USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 - Removable media other than\tfloppy
Interface type: USB
Media Type: Removable media other than\tfloppy
Model: USB Card Reader USB Device
Partitions: 1
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model: USB Card Reader USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE4 -
Interface type: USB
Media Type:
Model: USB Card Reader USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE5 - Fixed\thard disk media
Interface type: USB
Media Type: Fixed\thard disk media
Model: WD 2500JB External USB Device
Partitions: 1
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 4.00GB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 107.00GB
Starting Offset: 4791951360
Hidden sectors: 0


DeviceID: Disk #2, Partition #0
PartitionType: 12-bit FAT
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 62.00MB
Starting Offset: 28160
Hidden sectors: 0


DeviceID: Disk #5, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 233.00GB
Starting Offset: 32256
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction

< End of report >

EXTRAS.Txt
OTL Extras logfile created on: 10/15/2012 9:18:08 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.50 Gb Total Physical Memory | 1.92 Gb Available Physical Memory | 76.69% Memory free
3.10 Gb Paging File | 2.57 Gb Available in Paging File | 82.80% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.32 Gb Total Space | 77.82 Gb Free Space | 72.51% Space Free | Partition Type: NTFS
Drive D: | 4.45 Gb Total Space | 0.75 Gb Free Space | 16.89% Space Free | Partition Type: FAT32
Drive H: | 62.45 Mb Total Space | 33.19 Mb Free Space | 53.14% Space Free | Partition Type: FAT
Drive L: | 232.83 Gb Total Space | 203.16 Gb Free Space | 87.26% Space Free | Partition Type: FAT32

Computer Name: BREEZEWAY | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_USERS\S-1-5-21-698036064-2301516679-3255942371-500\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DoNotAllowExceptions" = 0
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\iMesh Applications\iMesh\iMesh.exe" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\hp center\137903\Program\BackWeb-137903.exe" = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe:*:Enabled:BackWeb-137903 – ()
"C:\Program Files\NetMeeting\conf.exe" = C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting® – (Microsoft Corporation)
"C:\Program Files\Support.com\bin\tgcmd.exe" = C:\Program Files\Support.com\bin\tgcmd.exe:*:Enabled:ComcastSUPPORT / Support.com Agent – (Support.com, Inc.)
"C:\Program Files\WildTangent\Blasterball 2\BB2.exe" = C:\Program Files\WildTangent\Blasterball 2\BB2.exe:*:Disabled:BB2
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Internet Explorer\iexplore.exe" = C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer – (Microsoft Corporation)
"C:\Program Files\FileZilla FTP Client\filezilla.exe" = C:\Program Files\FileZilla FTP Client\filezilla.exe:*:Enabled:FileZilla FTP Client – (FileZilla Project)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
"C:\WINDOWS\Explorer.EXE" = C:\WINDOWS\Explorer.EXE:*:Enabled:enable – (Microsoft Corporation)
"C:\Program Files\iMesh Applications\iMesh\iMesh.exe" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh
"C:\Program Files\iMesh Applications\Mediabar\Datamngr\SRTOOL~1\dtUser.exe" = C:\Program Files\iMesh Applications\Mediabar\Datamngr\SRTOOL~1\dtUser.exe:*:Enabled:Search-Results Toolbar DTX Broker – (APN LLC)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0DCFC7D5-8608-478C-8082-1FF848B978AF}" = USB Storage RW
"{0F9196C6-58B4-445B-B56E-B1200FECC151}" = Microsoft Bootvis
"{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = Lizardtech DjVu Control
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{158C641B-D60C-45E4-A380-B5725A4FE98A}" = ScopeCam Driver Installer
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{26A24AE4-039D-4CA4-87B4-2F83216035FF}" = Java™ 6 Update 35
"{29D88826-2AB9-11D5-8854-00902761A46D}" = WordPerfect Productivity Pack
"{31B27B28-5E06-4483-A363-8D1F2A97D38D}" = HP Officejet J3600 Series
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{444B6A7B-0E26-4416-A43F-D1C9AAE6075D}" = Canon CanoScan Toolbox 4.8
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{4D04C9A1-F28C-4F6F-9D66-81BB000693D9}" = BPDSoftware_Ini
"{50CD421F-CAFD-46C4-BEFD-E1C46FE63062}" = Manual CanoScan 8400F
"{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}" = Quicken 2004
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5E835305-63BB-4E55-BBB7-EEBBE67774DB}" = MyDVD
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{68658FCB-01BB-4980-A7C3-6ADB1E4E0C66}" = Browntech Image Plugin 2.02
"{6F60CD17-EE34-4f77-83B7-F8ADBDC31D46}" = ProductContext
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73B69C5C-87D6-471E-B695-0BD736C4B644}" = Retrospect 6.5
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7F34A21F-2DEB-4598-BB19-611D6BD24271}" = Managed DirectX (0900)
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{88FBDCF4-8ACF-46e6-9C33-231FBA6378D8}" = J3600
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{8CE4CB34-8187-42A1-B597-517760BEE8EC}" = BPD_Scan
"{8D5D99B8-DFA2-4018-ADE9-A6B83E655C65}" =
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{987AE1EA-9AF0-484D-A0F9-11A2E0EB4AA0}" = OpenOffice.org 2.0
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD 4
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A70500000002}" = Adobe Reader 7.0.5
"{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center
"{BDE90251-93EB-4F6A-89D8-086E2D91DC56}" = Coloreal
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb" = Microsoft Automated Troubleshooting Services Shim
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2261C4B-4D9B-4149-8472-31B7A2FEAB91}" = ArcSoft PhotoStudio 5.5
"{D27F8BF7-61A4-4F0D-A190-9E2CE8C0773B}" = 3600_Help
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Photoshop Elements 2.0" = Adobe Photoshop Elements 2.0
"ArcSoft Software Suite" = ArcSoft Picture Software
"BackWeb-137903 Uninstaller" = hp center
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"Comcast PhotoShow Deluxe 4" = Comcast PhotoShow Deluxe 4
"ComcastSUPPORT" = ComcastSUPPORT
"DivX Codec" = DivX 5.0.3 Pro Bundle
"EOS Utility" = Canon Utilities EOS Utility
"EPSON Printer and Utilities" = EPSON Printer Software
"FileZilla Client" = FileZilla Client 3.5.3
"Film Factory" = Film Factory
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"hp deskjet 5550 series" = hp deskjet 5550 series (Remove only)
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"hp instant support" = HP Instant Support
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPTOOLKIT" = toolkit
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Image Web Server IE Plugin" = Image Web Server IE Plugins 1,7,0,424
"imeshtoolbar2" = Search-Results Toolbar
"Inactive HP Printer Drivers (Remove only)" = Inactive HP Printer Drivers (Remove only)
"Insight" = Insight
"InstallShield_{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}" = Quicken 2004
"MGI_PRISM_V3_0" = MGI PhotoSuite III SE (Remove Only)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSN Music Assistant" = MSN Music Assistant
"MyCamera" = Canon Utilities MyCamera
"MyCameraDC" = Canon Utilities MyCamera DC
"N360" = Norton Security Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoStitch" = Canon Utilities PhotoStitch
"Picasa 3" = Picasa 3
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 6.0" = RealPlayer
"RecordPad" = RecordPad Sound Recorder Uninstall
"RemoteCaptureDC" = Canon Utilities RemoteCapture DC
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"SysTools Outlook Express Restore - Demo Version_is1" = SysTools Outlook Express Restore
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"Wave@MP3" = River Past Wave@MP3
"WeatherBug" = WeatherBug
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WordPerfect Productivity Pack" = WordPerfect Productivity Pack
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 10/14/2012 9:44:00 PM | Computer Name = BREEZEWAY | Source = MatSvc | ID = 262147
Description = The MATS service encountered a web service failure. hr=0xC004F018

Error - 10/14/2012 9:44:00 PM | Computer Name = BREEZEWAY | Source = MatSvc | ID = 262148
Description = The MATS service encountered a failure when uploading data. hr=0xC004F018


Error - 10/15/2012 7:52:47 AM | Computer Name = BREEZEWAY | Source = MatSvc | ID = 262147
Description = The MATS service encountered a web service failure. hr=0xC004F018

Error - 10/15/2012 7:52:47 AM | Computer Name = BREEZEWAY | Source = MatSvc | ID = 262148
Description = The MATS service encountered a failure when uploading data. hr=0xC004F018


Error - 10/15/2012 7:53:13 AM | Computer Name = BREEZEWAY | Source = MatSvc | ID = 262153
Description = The MATS service encountered a failure when diagnosing problems. hr=0x803C0101
SAP
folder: C:\Program Files\Microsoft Fix it Center\SAPFolder\Scheduled\DDA435FA-6E05-4DBF-80FE-C4EBE882E798.32


Error - 10/15/2012 7:53:15 AM | Computer Name = BREEZEWAY | Source = MatSvc | ID = 262159
Description = The scheduled MATS task encountered a failure when collecting configuration
data. hr=0x803C0101 .

Error - 10/15/2012 7:53:48 AM | Computer Name = BREEZEWAY | Source = MatSvc | ID = 262147
Description = The MATS service encountered a web service failure. hr=0xC004F018

Error - 10/15/2012 7:53:48 AM | Computer Name = BREEZEWAY | Source = MatSvc | ID = 262148
Description = The MATS service encountered a failure when uploading data. hr=0xC004F018


Error - 10/15/2012 7:57:21 AM | Computer Name = BREEZEWAY | Source = MatSvc | ID = 262147
Description = The MATS service encountered a web service failure. hr=0xC004F018

Error - 10/15/2012 7:57:21 AM | Computer Name = BREEZEWAY | Source = MatSvc | ID = 262148
Description = The MATS service encountered a failure when uploading data. hr=0xC004F018


[ Media Center Events ]
Error - 4/11/2010 8:08:34 AM | Computer Name = BREEZEWAY | Source = Recording | ID = 19
Description = The recording schedule has been corrupted and was automatically deleted
on 4/11/2010 8:08:34 AM. You may need to reschedule your recordings.

Error - 4/16/2010 3:03:17 PM | Computer Name = BREEZEWAY | Source = Recording | ID = 19
Description = The recording schedule has been corrupted and was automatically deleted
on 4/16/2010 3:03:17 PM. You may need to reschedule your recordings.

Error - 4/17/2010 7:14:39 PM | Computer Name = BREEZEWAY | Source = Recording | ID = 19
Description = The recording schedule has been corrupted and was automatically deleted
on 4/17/2010 7:14:39 PM. You may need to reschedule your recordings.

Error - 4/24/2010 8:18:00 AM | Computer Name = BREEZEWAY | Source = Recording | ID = 19
Description = The recording schedule has been corrupted and was automatically deleted
on 4/24/2010 8:18:00 AM. You may need to reschedule your recordings.

Error - 5/22/2010 2:08:29 PM | Computer Name = BREEZEWAY | Source = Recording | ID = 19
Description = The recording schedule has been corrupted and was automatically deleted
on 5/22/2010 2:08:29 PM. You may need to reschedule your recordings.

Error - 5/27/2010 8:03:32 AM | Computer Name = BREEZEWAY | Source = Recording | ID = 19
Description = The recording schedule has been corrupted and was automatically deleted
on 5/27/2010 8:03:32 AM. You may need to reschedule your recordings.

Error - 6/13/2010 8:23:58 AM | Computer Name = BREEZEWAY | Source = Recording | ID = 19
Description = The recording schedule has been corrupted and was automatically deleted
on 6/13/2010 8:23:58 AM. You may need to reschedule your recordings.

Error - 7/15/2010 4:40:32 PM | Computer Name = BREEZEWAY | Source = Recording | ID = 19
Description = The recording schedule has been corrupted and was automatically deleted
on 7/15/2010 4:40:32 PM. You may need to reschedule your recordings.

Error - 8/5/2010 8:10:10 AM | Computer Name = BREEZEWAY | Source = Recording | ID = 19
Description = The recording schedule has been corrupted and was automatically deleted
on 8/5/2010 8:10:10 AM. You may need to reschedule your recordings.

Error - 12/30/2011 8:14:23 AM | Computer Name = BREEZEWAY | Source = Recording | ID = 19
Description = The recording schedule has been corrupted and was automatically deleted
on 12/30/2011 7:14:23 AM. You may need to reschedule your recordings.

[ System Events ]
Error - 10/13/2012 8:10:41 AM | Computer Name = BREEZEWAY | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Kernel Information Provider service failed to start due
to the following error: %%3

Error - 10/13/2012 8:10:41 AM | Computer Name = BREEZEWAY | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 10/13/2012 8:12:48 AM | Computer Name = BREEZEWAY | Source = DCOM | ID = 10016
Description = The application-specific permission settings do not grant Local Activation
permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E}

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.

Error - 10/14/2012 9:38:31 AM | Computer Name = BREEZEWAY | Source = DCOM | ID = 10016
Description = The application-specific permission settings do not grant Local Activation
permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E}

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.

Error - 10/14/2012 8:19:16 PM | Computer Name = BREEZEWAY | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Kernel Information Provider service failed to start due
to the following error: %%3

Error - 10/14/2012 8:19:17 PM | Computer Name = BREEZEWAY | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 10/14/2012 8:20:01 PM | Computer Name = BREEZEWAY | Source = DCOM | ID = 10016
Description = The application-specific permission settings do not grant Local Activation
permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E}

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.

Error - 10/15/2012 7:51:48 AM | Computer Name = BREEZEWAY | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Kernel Information Provider service failed to start due
to the following error: %%3

Error - 10/15/2012 7:51:50 AM | Computer Name = BREEZEWAY | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 10/15/2012 7:53:04 AM | Computer Name = BREEZEWAY | Source = DCOM | ID = 10016
Description = The application-specific permission settings do not grant Local Activation
permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E}

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.


< End of report >

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-10-15 09:31:44
—————————–
09:31:44.234 OS Version: Windows 5.1.2600 Service Pack 3
09:31:44.234 Number of processors: 2 586 0x209
09:31:44.234 ComputerName: BREEZEWAY UserName:
09:31:45.390 Initialize success
09:34:08.328 AVAST engine defs: 12101500
09:34:16.812 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
09:34:16.812 Disk 0 Vendor: ST3120025A 4.06 Size: 114473MB BusType: 3
09:34:16.828 Disk 0 MBR read successfully
09:34:16.828 Disk 0 MBR scan
09:34:16.875 Disk 0 unknown MBR code
09:34:16.890 Disk 0 Partition 1 00 0B FAT32 RECOVERY 4569 MB offset 63
09:34:16.906 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 109893 MB offset 9359280
09:34:16.921 Disk 0 scanning sectors +234420480
09:34:17.015 Disk 0 scanning C:\WINDOWS\system32\drivers
09:34:34.140 Service scanning
09:35:24.625 Modules scanning
09:35:51.609 Disk 0 trace - called modules:
09:35:51.625 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
09:35:52.140 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a9f9ab8]
09:35:52.140 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\0000006f[0x8a9d6510]
09:35:52.140 5 ACPI.sys[f75ae620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a9fe940]
09:35:52.843 AVAST engine scan C:\WINDOWS
09:36:18.093 AVAST engine scan C:\WINDOWS\system32
09:40:37.640 AVAST engine scan C:\WINDOWS\system32\drivers
09:41:04.328 AVAST engine scan C:\Documents and Settings\Administrator
10:03:00.843 AVAST engine scan C:\Documents and Settings\All Users
10:05:52.390 Scan finished successfully
10:13:27.937 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Administrator\My Documents\Downloads\MBR.dat"
10:13:27.937 The log file has been saved successfully to "C:\Documents and Settings\Administrator\My Documents\Downloads\aswMBR.txt"
You have a lot of stuff on here that I’d like to get rid of so that it stops muddying the waters and allows us to see if there is anything more serious on your computer – these things don’t usually come alone.

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.
  • run AdwCleaner and select Delete
  • when it has finished it will ask to reboot - allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply
Satchfan
Here's the log. Thanks, Jim # AdwCleaner v2.005 - Logfile created 10/15/2012 at 19:37:58 # Updated 14/10/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Administrator - BREEZEWAY # Boot Mode : Normal # Running from : C:\Documents and Settings\Administrator\My Documents\Downloads\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Documents and Settings\All Users\Application Data\boost_interprocess Folder Deleted : C:\Program Files\Free Offers from Freeze.com Folder Deleted : C:\Program Files\Trymedia Folder Deleted : C:\WINDOWS\TempDir ***** [Registry] ***** Key Deleted : HKCU\Software\APN DTX Key Deleted : HKCU\Software\DataMngr Key Deleted : HKCU\Software\DataMngr_Toolbar Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{201F27D4-3704-41D6-89C1-AA35E39143ED} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3041D03E-FD4B-44E0-B742-2D9B88305F98} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041D03E-FD4B-44E0-B742-2D9B88305F98} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} Key Deleted : HKCU\Software\Softonic Key Deleted : HKLM\Software\AskBarDis Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{474597C5-AB09-49D6-A4D5-2E8D7341384E} Key Deleted : HKLM\SOFTWARE\Classes\IMsiDe1egate.Application.1 Key Deleted : HKLM\Software\DataMngr Key Deleted : HKLM\Software\Freeze.com Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D7E97865-918F-41E4-9CD0-25AB1C574CE8}] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Registry is clean. -\\ Mozilla Firefox v [Unable to get version] Profile name : default File : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ulda3u9v.default\prefs.js C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ulda3u9v.default\user.js … Deleted ! [OK] File is clean. -\\ Google Chrome v [Unable to get version] File : C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences Deleted [l.16] : homepage = "hxxp://search.imesh.net/", Deleted [l.20] : urls_to_restore_on_startup = [ "hxxp://search.imesh.net", "hxxp://www.google.com" ] Deleted [l.1383] : homepage = "hxxp://search.imesh.net/", Deleted [l.2055] : urls_to_restore_on_startup = [ "hxxp://search.imesh.net", "hxxp://www.google.com" ] ************************* AdwCleaner[S1].txt - [3839 octets] - [15/10/2012 19:37:58] ########## EOF - C:\AdwCleaner[S1].txt - [3899 octets] ##########
That’s done a good job.

Download Malwarebytes-Anti-Malware

Click here.
  • double-click mbam-setup.exe and follow the prompts to install the program.
  • at the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware. and Launch Malwarebytes' Anti-Malware, then click Finish..
  • if an update is found, it will download and install the latest version.
  • once the program has loaded, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

====================================

When you’ve done that, please run OTL again and post the new log.

Logs to include with the next post:

OTL.txt
Mbam.txt


Can you tell me if there are any outstanding problems.

Satchfan
Satchfan,
OTL log follows.
no MBAM log.
When it came to "mbam" I had touble. per your last instructions :
" Download Malwarebytes-Anti-Malware
"Click here."
double-click mbam-setup.exe and follow the prompts to install the program

I "clicked here" and was brought to this link: http://www.filehippo.com/download_malwarebytes_anti_malware/

I did not see: "mbam-setup.exe " that you had instructed me to execute! I should have stopped there!!

My download attempts gave me a program named "avg_avct_stb_all_2013_2741_ppc2" I ran a full scan. I did not see a log file, but received a finished page that said "AVG ran a complete computer scan and found 1 potentially dangerous threat which was removed".

All seemed ok at that point, I was not instructed to reboot but did anyway.
I ended up with a black screen, no video. I rebooted several more times, finally got video by booting to "safe" mode with network.
But now I have no network , No browsing, no email etc. The lan connection was not present. I tried cable swaps, bypassing my wireless router, the whole 9 yards. Stiil video only in safe mode and no network.

I did a "system restore" back to yesterday, it was successful and normal video was back but still, no network.
To make a long day short: The first Comcast tech on the phone could not resolve network issue, he made appt. to send out service truck, the second tech fixed network prob. He said I had a "CAPTIVE PORTAL"; he did a "full reprovision" of my MAC address.
That all brought back my network.
btw, I no longer have ASK.COM hijacking my Google chrome browses. (my original complaint)

I hope my pc is ok .

Thanks, Jim


OTL logfile created on: 10/16/2012 7:02:37 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.50 Gb Total Physical Memory | 1.94 Gb Available Physical Memory | 77.62% Memory free
3.10 Gb Paging File | 2.53 Gb Available in Paging File | 81.49% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.32 Gb Total Space | 77.76 Gb Free Space | 72.46% Space Free | Partition Type: NTFS
Drive D: | 4.45 Gb Total Space | 0.75 Gb Free Space | 16.89% Space Free | Partition Type: FAT32
Drive H: | 62.45 Mb Total Space | 33.19 Mb Free Space | 53.14% Space Free | Partition Type: FAT
Drive L: | 232.83 Gb Total Space | 203.16 Gb Free Space | 87.26% Space Free | Partition Type: FAT32

Computer Name: BREEZEWAY | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/10/15 09:14:41 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
PRC - [2011/04/16 20:45:11 | 000,130,008 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccsvchst.exe
PRC - [2008/04/13 20:12:28 | 000,060,416 | —- | M] (Microsoft Corporation) – C:\Program Files\Outlook Express\msimn.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2003/12/10 23:09:34 | 000,046,592 | R— | M] (Dantz Development Corporation) – C:\Program Files\Dantz\Retrospect\wdsvc.exe
PRC - [2003/11/12 13:46:34 | 000,049,152 | —- | M] (Dantz Development Corporation) – C:\Program Files\Dantz\Retrospect\retrorun.exe
PRC - [2003/07/23 11:41:54 | 000,065,536 | —- | M] (Hewlett-Packard Company) – C:\Program Files\HP DVD\Umbrella\DVDTray.exe
PRC - [2002/10/25 18:33:46 | 000,069,632 | —- | M] (MyComp) – C:\Program Files\USB Storage RW\shwicon.exe


========== Modules (No Company Name) ==========

MOD - [2012/01/08 09:41:12 | 000,093,696 | —- | M] () – C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2006/10/22 13:22:00 | 000,212,992 | —- | M] () – C:\WINDOWS\system32\nvapi.dll


========== Services (SafeList) ==========

SRV - [2012/10/08 21:55:53 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2011/06/13 23:09:22 | 000,267,568 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Fix it Center\Matsvc.exe – (MatSvc)
SRV - [2011/04/16 20:45:11 | 000,130,008 | R— | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe – (N360)
SRV - [2003/12/10 23:09:34 | 000,046,592 | R— | M] (Dantz Development Corporation) [Auto | Running] – C:\Program Files\Dantz\Retrospect\wdsvc.exe – (RetroWDSvc)
SRV - [2003/11/12 13:46:34 | 000,110,592 | —- | M] (Dantz Development Corporation) [Auto | Stopped] – C:\Program Files\Dantz\Retrospect\rthlpsvc.exe – (Retrospect Helper)
SRV - [2003/11/12 13:46:34 | 000,049,152 | —- | M] (Dantz Development Corporation) [Auto | Running] – C:\Program Files\Dantz\Retrospect\retrorun.exe – (RetroLauncher)
SRV - [2002/11/14 11:09:14 | 000,077,824 | —- | M] (HP) [On_Demand | Stopped] – C:\WINDOWS\system32\hphipm11.exe – (Pml Driver HPH11)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMNDIS.SYS – (SYMNDIS)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMIDS.SYS – (SYMIDS)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMFW.SYS – (SYMFW)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PCDRDRV)
DRV - File not found [Kernel | Auto | Stopped] – C:\Program Files\LogMeIn\x86\RaInfo.sys – (LMIInfo)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [File_System | Boot | Stopped] – system32\DRIVERS\Lbd.sys – (Lbd)
DRV - File not found [Kernel | System | Stopped] – – (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys – (EraserUtilDrvI9)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - [2012/09/13 08:18:35 | 001,601,184 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20121016.002\NAVEX15.SYS – (NAVEX15)
DRV - [2012/09/13 08:18:35 | 000,092,704 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20121016.002\NAVENG.SYS – (NAVENG)
DRV - [2012/08/31 20:27:25 | 000,373,728 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20121013.001\IDSXpx86.sys – (IDSxpx86)
DRV - [2012/08/31 18:09:14 | 000,995,488 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20120928.001\BHDrvx86.sys – (BHDrvx86)
DRV - [2012/08/09 08:22:40 | 000,376,480 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2012/08/09 08:22:40 | 000,106,656 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2011/05/18 08:13:42 | 000,126,584 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2011/04/20 21:37:49 | 000,369,784 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\symtdi.sys – (SYMTDI)
DRV - [2011/03/30 23:00:09 | 000,516,216 | —- | M] (Symantec Corporation) [File_System | System | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\srtsp.sys – (SRTSP)
DRV - [2011/03/30 23:00:09 | 000,050,168 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\srtspx.sys – (SRTSPX)
DRV - [2011/03/14 22:31:23 | 000,744,568 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\symefa.sys – (SymEFA)
DRV - [2011/01/27 02:47:10 | 000,340,088 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\symds.sys – (SymDS)
DRV - [2010/11/15 21:45:33 | 000,136,312 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\ironx86.sys – (SymIRON)
DRV - [2009/09/16 10:22:48 | 000,214,664 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2009/09/16 10:22:48 | 000,079,816 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2009/09/16 10:22:48 | 000,040,552 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfesmfk.sys – (mfesmfk)
DRV - [2009/09/16 10:22:48 | 000,035,272 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2009/09/16 10:22:14 | 000,034,248 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mferkdk.sys – (mferkdk)
DRV - [2008/05/19 15:24:04 | 000,083,288 | —- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] – C:\WINDOWS\System32\LMIRfsClientNP.dll – (LMIRfsClientNP)
DRV - [2008/03/07 13:39:50 | 000,045,848 | —- | M] (LogMeIn, Inc.) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys – (LMIRfsDriver)
DRV - [2004/10/01 11:24:02 | 002,279,424 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM)
DRV - [2004/08/04 01:31:32 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\rtl8139.sys – (rtl8139)
DRV - [2003/10/01 18:41:28 | 000,177,664 | —- | M] (Emuzed, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\EvcapMau.sys – (EvcapMaui)
DRV - [2003/05/02 03:12:14 | 000,009,856 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (pfc)
DRV - [2003/03/08 01:13:22 | 000,624,369 | —- | M] (LT) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ltmdmnt.sys – (ltmodem5)
DRV - [2003/01/07 13:32:26 | 000,015,400 | R— | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\NetMotCM.sys – (ndiscm)
DRV - [2001/11/01 14:14:04 | 000,017,024 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\scopex0.sys – (GT891x)
DRV - [2001/09/20 09:58:48 | 000,153,824 | —- | M] (Zoran Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\NUVvid2.sys – (NUVision)
DRV - [2001/09/20 09:47:38 | 000,025,184 | —- | M] (Zoran Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nuvaud2.sys – (nuvaud2)
DRV - [2001/08/05 22:13:54 | 000,314,720 | R— | M] (Grandtech Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\scopex1.SYS – (DCamUSBGrandTek)
DRV - [2001/06/04 16:00:00 | 000,014,112 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.msnbc.msn.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {5AFB1C08-DA54-4C8F-AF4B-8A05B911FC67}
IE - HKCU\..\SearchScopes\{5AFB1C08-DA54-4C8F-AF4B-8A05B911FC67}: "URL" = http://www.google.com/search?q={searchTerm…1I7GGLJ_enUS292
IE - HKCU\..\SearchScopes\{611F04C5-F1CA-4EBA-96D7-9789A5C7AE4B}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7GGLD
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7GGLJ
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..network.proxy.no_proxies_on: "localhost"
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2629: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2012/02/08 08:50:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_13_2 [2012/10/16 17:25:16 | 000,000,000 | —D | M]

[2011/03/01 22:30:16 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ulda3u9v.default\extensions
[2007/10/08 19:25:52 | 000,024,576 | —- | M] (My Web Search) – C:\Program Files\mozilla firefox\plugins\NPMySrWB.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U35 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.350.10 (Enabled) = C:\WINDOWS\system32\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

O1 HOSTS File: ([2002/08/29 15:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O4 - HKLM..\Run: [DVDTray] C:\Program Files\HP DVD\Umbrella\DVDTray.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW" File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe (Leader Technologies)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [ [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsupport.com/sdccommon/download/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} http://www.alternatiff.com/distribution/al…x-w32-2.0.1.cab (AlternaTIFF ActiveX)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} http://picasaweb.google.com/s/v/63.24/uploader2.cab (UploadListView Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EB963901-38AC-4F95-94FA-E6B7B8E09825}: DhcpNameServer = 75.75.75.75 75.75.76.76
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\Userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/05/06 00:12:36 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2002/09/11 03:02:32 | 000,000,045 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2002/10/17 09:56:50 | 000,000,036 | RH– | M] () - L:\AUTORUN.INF – [ FAT32 ]
O32 - AutoRun File - [2003/03/21 12:00:56 | 000,000,000 | RH-D | M] - L:\AUTORUN – [ FAT32 ]
O33 - MountPoints2\{f0820590-d333-11df-b3e3-000c6e7713b0}\Shell - "" = AutoRun
O33 - MountPoints2\{f0820590-d333-11df-b3e3-000c6e7713b0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f0820590-d333-11df-b3e3-000c6e7713b0}\Shell\AutoRun\command - "" = L:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/10/16 16:19:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Xfinity.com
[2012/10/16 08:28:51 | 000,000,000 | —D | C] – C:\$AVG
[2012/10/16 08:28:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG2013
[2012/10/16 08:26:19 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2012/10/16 08:23:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/10/16 08:23:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\MFAData
[2012/10/16 08:23:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2012/10/16 08:23:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Avg2013
[2012/10/15 21:51:17 | 000,000,000 | —D | C] – C:\WINDOWS\TempDir
[2012/10/08 22:08:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Quicken
[2012/10/08 22:08:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Palo Alto Software
[2012/10/05 09:09:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\Nana-Grampa-Larkin
[2012/09/29 15:36:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\Favorites
[2012/09/24 23:03:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\searchresultstb
[2012/09/24 23:03:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\AppData
[2012/09/24 23:03:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\imeshtoolbar2
[2012/09/24 23:03:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\92AF
[2012/09/24 23:01:38 | 000,000,000 | —D | C] – C:\Program Files\iMesh Applications
[2012/09/24 23:00:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\PackageAware
[2012/09/17 21:09:21 | 000,477,168 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\npdeployJava1.dll
[2012/09/17 21:09:21 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/09/17 21:09:20 | 000,157,680 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/09/17 21:09:19 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/09/17 21:09:19 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/09/17 21:08:37 | 000,000,000 | —D | C] – C:\Program Files\Java
[2005/12/02 20:18:20 | 019,846,914 | —- | C] (NVIDIA Corporation) – C:\Program Files\71.89_win2kxp_english.exe
[2005/08/09 22:34:49 | 006,860,424 | —- | C] (Microsoft Corporation ) – C:\Program Files\MicrosoftAntiSpywareInstall.exe
[2005/07/25 17:33:26 | 002,575,792 | —- | C] (Simple Star, Inc.) – C:\Program Files\comcast_photoshow_deluxe_4.exe
[2005/07/25 15:58:57 | 000,465,096 | —- | C] (Simple Star, Inc.) – C:\Program Files\SnapfishPhotoShow.exe
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/16 18:55:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/16 18:35:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/16 17:38:00 | 000,000,580 | -H– | M] () – C:\WINDOWS\tasks\DataUpload.job
[2012/10/16 17:28:35 | 000,000,616 | -H– | M] () – C:\WINDOWS\tasks\ConfigExec.job
[2012/10/16 17:27:35 | 000,087,959 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2012/10/16 17:27:27 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/16 17:24:54 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc208ea0ecc77e.job
[2012/10/16 17:24:25 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/16 17:24:09 | 2683,752,448 | -HS- | M] () – C:\hiberfil.sys
[2012/10/16 15:25:00 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/10/14 20:48:23 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmpB02EC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmpEEEDC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmpA8FDC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmp2E0EC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmp24EDC.FOT
[2012/10/14 12:19:46 | 000,001,824 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/10/14 12:19:46 | 000,001,802 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/10/12 17:25:10 | 000,019,783 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\JimLHS-Expenses.ods
[2012/10/10 08:50:02 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/10/09 14:31:31 | 000,037,926 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\tomichromeII.ods
[2012/10/08 22:14:32 | 000,001,318 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2012/10/08 22:14:32 | 000,000,431 | —- | M] () – C:\WINDOWS\intuprof.ini
[2012/10/08 22:09:39 | 000,000,064 | —- | M] () – C:\WINDOWS\qwimp.ini
[2012/10/08 22:08:48 | 000,001,486 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Quicken 2004.lnk
[2012/10/08 22:08:48 | 000,000,228 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Best for Quicken - Low Intro APR and Optional Travel Rewards.url
[2012/10/08 22:08:48 | 000,000,203 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Special Offer from Citibank.url
[2012/10/08 22:08:48 | 000,000,189 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Visit Quicken.com.url
[2012/10/08 22:08:30 | 000,000,686 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
[2012/10/08 21:55:47 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/08 21:55:47 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/09/24 10:42:38 | 000,001,181 | —- | M] () – C:\WINDOWS\cdplayer.ini
[2012/09/21 13:06:29 | 000,010,240 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\displays.odt
[2012/09/17 21:08:45 | 000,477,168 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\npdeployJava1.dll
[2012/09/17 21:08:45 | 000,157,680 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/09/17 21:08:45 | 000,149,488 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/09/17 21:08:45 | 000,149,488 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/09/17 21:08:45 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/09/17 21:08:44 | 000,473,072 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/16 15:51:15 | 2683,752,448 | -HS- | C] () – C:\hiberfil.sys
[2012/10/14 20:48:23 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmpB02EC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmpEEEDC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmpA8FDC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmp2E0EC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmp24EDC.FOT
[2012/10/08 22:09:39 | 000,000,064 | —- | C] () – C:\WINDOWS\qwimp.ini
[2012/10/08 22:08:48 | 000,000,228 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Best for Quicken - Low Intro APR and Optional Travel Rewards.url
[2012/10/08 22:08:48 | 000,000,203 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Special Offer from Citibank.url
[2012/10/08 22:08:48 | 000,000,189 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Visit Quicken.com.url
[2012/10/08 22:08:30 | 000,000,686 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
[2012/10/08 22:08:29 | 000,001,486 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Quicken 2004.lnk
[2012/09/20 22:17:16 | 000,010,240 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\displays.odt
[2012/02/15 20:01:42 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2009/10/07 18:01:34 | 000,019,707 | —- | C] () – C:\Documents and Settings\All Users\Application Data\exezeda.vbs
[2009/10/07 18:01:34 | 000,019,291 | —- | C] () – C:\Documents and Settings\All Users\Application Data\igodu.com
[2009/10/07 18:01:34 | 000,019,231 | —- | C] () – C:\Documents and Settings\All Users\Application Data\gunyfaj.sys
[2009/10/07 18:01:34 | 000,017,473 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\ajinavyrot.lib
[2009/10/07 18:01:34 | 000,015,316 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\tacevikob.bat
[2009/10/07 18:01:34 | 000,015,145 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\dyzitep.bin
[2009/10/07 18:01:34 | 000,014,250 | —- | C] () – C:\Documents and Settings\All Users\Application Data\opap.reg
[2009/10/07 18:01:34 | 000,011,715 | —- | C] () – C:\Program Files\Common Files\hijak.ban
[2009/10/07 18:01:34 | 000,011,269 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\cicizihu.ban
[2009/10/07 17:38:58 | 000,018,655 | —- | C] () – C:\Program Files\Common Files\isekopibej.db
[2009/10/07 17:38:58 | 000,017,958 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\gaje.reg
[2009/10/07 17:38:58 | 000,017,412 | —- | C] () – C:\Program Files\Common Files\hodusur.dat
[2009/10/07 17:38:58 | 000,015,582 | —- | C] () – C:\Documents and Settings\All Users\Application Data\gulynohyx.reg
[2009/10/07 17:38:58 | 000,015,450 | —- | C] () – C:\Program Files\Common Files\ytuxydy.pif
[2009/10/07 17:38:58 | 000,014,860 | —- | C] () – C:\Documents and Settings\All Users\Application Data\jimot.ban
[2009/10/07 17:38:58 | 000,014,336 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\weniwez.dl
[2009/10/07 17:38:58 | 000,014,289 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\amovehiri.bat
[2009/10/07 17:38:58 | 000,012,934 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\dahi.vbs
[2009/10/07 17:38:57 | 000,014,744 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\qalyso.pif
[2009/10/07 17:38:57 | 000,010,668 | —- | C] () – C:\Program Files\Common Files\gihirof.bat
[2009/10/07 17:38:57 | 000,010,329 | —- | C] () – C:\Program Files\Common Files\geso._dl
[2009/10/07 17:33:16 | 000,000,000 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\svcst.exe
[2009/07/13 13:22:03 | 003,296,158 | —- | C] () – C:\Documents and Settings\Administrator\FredAstaireEleanorPowell1.wmv
[2009/06/20 14:59:05 | 001,127,767 | —- | C] () – C:\Documents and Settings\Administrator\malpki.wmv
[2009/06/05 13:51:21 | 000,000,397 | —- | C] () – C:\Documents and Settings\Administrator\IceHarvast2.lnk
[2009/05/29 11:15:48 | 000,889,676 | —- | C] () – C:\Documents and Settings\Administrator\CourtesyofUSMarines (1).wmv
[2009/05/29 09:13:21 | 001,977,352 | —- | C] () – C:\Documents and Settings\Administrator\Weight_Lifting_Surprise.wmv
[2009/05/26 09:21:14 | 000,889,676 | —- | C] () – C:\Documents and Settings\Administrator\CourtesyofUSMarines.wmv
[2009/02/11 15:00:16 | 000,000,596 | RHS- | C] () – C:\Documents and Settings\Administrator\ntuser.pol
[2006/11/23 23:26:14 | 000,008,055 | —- | C] () – C:\Program Files\1615855.htm
[2006/11/21 12:52:32 | 000,252,416 | —- | C] () – C:\Program Files\uninstall_flash_player.exe
[2006/05/18 20:38:42 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/28 22:37:21 | 000,010,322 | —- | C] () – C:\Program Files\pot[1][1].tv_02119_20030815__hs-death.rm.torrent
[2006/02/10 14:01:01 | 017,496,033 | —- | C] () – C:\Program Files\1955-56 Parts manual-B.djvu
[2006/02/08 10:39:58 | 003,338,240 | —- | C] () – C:\Documents and Settings\Administrator\s-1-5-21-698036064-2301516679-3255942371-500.rrr
[2005/11/21 23:55:44 | 013,831,036 | —- | C] () – C:\Program Files\VibeComcastVMInstall.exe
[2004/03/29 21:35:38 | 000,000,616 | —- | C] () – C:\Documents and Settings\Administrator\plugin131_09.trace
[2004/01/02 13:30:54 | 000,000,507 | -H– | C] () – C:\Documents and Settings\Administrator\Application Data\hpothb07.tif
[2004/01/02 13:30:54 | 000,000,376 | -H– | C] () – C:\Documents and Settings\Administrator\Application Data\hpothb07.dat
[2004/01/01 21:49:21 | 000,061,678 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\PFP100JPR.{PB
[2004/01/01 21:49:21 | 000,012,358 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\PFP100JCM.{PB
[2003/12/27 14:00:09 | 000,086,528 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/05/06 01:14:38 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat

========== ZeroAccess Check ==========

[2003/05/06 00:08:52 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\System32\shdocvw.dll – [2008/04/13 20:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >
Your computer should be fine.

The link took you to the right page but you downloaded the wrong program.

At the top of the web page it has:

“Malwarebytes Anti-Malware 1.65
Malwarebytes- 10.04MB (Shareware)”


You need to click on the word “Malwarebytes” on the secomd row, (in red here), which will download the program.

If you installed AVG, please uninstall it as you cannot run 2 antiviruses.

Let me know how you get on and if there is a problem I’ll send you another link.

Satchfan
Yes, in hindsight, I see I picked the wrong program to run. I had been looking for "mbam-setup.exe".
All is well, I appreciate your quick response and good direction.
I made sure AVG was uninstalled and ran the Malwarebytes program. The mbam log follows.
Did you want me to re-run OTL ?
Thanks, Jim

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.10.17.12

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Administrator :: BREEZEWAY [administrator]

10/17/2012 5:34:50 PM
mbam-log-2012-10-17 (17-34-50).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 219134
Time elapsed: 34 minute(s), 47 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 2
HKCU\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.

Registry Values Detected: 7
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Data: 1 -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32|midi1 (Trojan.Riern) -> Data: C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe\Update\gdipar.dat -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32|wave1 (Trojan.Riern) -> Data: C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe\Update\gdipar.dat -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32|aux2 (Trojan.Riern) -> Data: C:\DOCUME~1\NETWOR~1\APPLIC~1\Adobe\Update\gdipar.dat -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32|mixer1 (Trojan.Riern) -> Data: C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe\Update\gdipar.dat -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32|aux1 (Trojan.Riern) -> Data: C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe\Update\gdipar.dat -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32|midi2 (Trojan.Riern) -> Data: C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe\Update\gdipar.dat -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 6
C:\Documents and Settings\Administrator\Application Data\RegSweep (Rogue.RegSweep) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Application Data\RegSweep\Log (Rogue.RegSweep) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Application Data\RegSweep\Registry Backups (Rogue.RegSweep) -> Quarantined and deleted successfully.
C:\Program Files\RegSweep (Rogue.RegSweep) -> Quarantined and deleted successfully.
C:\Program Files\RegSweep\Microsoft.VC80.CRT (Rogue.RegSweep) -> Quarantined and deleted successfully.
C:\Program Files\RegSweep\Microsoft.VC80.MFC (Rogue.RegSweep) -> Quarantined and deleted successfully.

Files Detected: 7
C:\Documents and Settings\Administrator\My Documents\Downloads\7zip_Setup.exe (PUP.Bundle.Installer.OI) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Application Data\svcst.exe (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.
C:\WINDOWS\bk23567.dat (KoobFace.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\fdgg34353edfgdfdf (KoobFace.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\msacm32.drv (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\wuasirvy.dll (Trojan.Banker) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Application Data\RegSweep\Registry Backups\2007-11-01_08-00-34.reg (Rogue.RegSweep) -> Quarantined and deleted successfully.

(end)
OTL logfile created on: 10/18/2012 7:39:35 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.50 Gb Total Physical Memory | 1.89 Gb Available Physical Memory | 75.77% Memory free
3.10 Gb Paging File | 2.47 Gb Available in Paging File | 79.74% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.32 Gb Total Space | 77.89 Gb Free Space | 72.58% Space Free | Partition Type: NTFS
Drive D: | 4.45 Gb Total Space | 0.75 Gb Free Space | 16.89% Space Free | Partition Type: FAT32
Drive H: | 62.45 Mb Total Space | 33.19 Mb Free Space | 53.14% Space Free | Partition Type: FAT

Computer Name: BREEZEWAY | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/10/15 09:14:41 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
PRC - [2012/10/10 06:06:17 | 001,239,064 | —- | M] (Google Inc.) – C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2011/06/13 23:09:22 | 000,267,568 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Fix it Center\Matsvc.exe
PRC - [2011/04/16 20:45:11 | 000,130,008 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccsvchst.exe
PRC - [2008/04/13 20:12:28 | 000,060,416 | —- | M] (Microsoft Corporation) – C:\Program Files\Outlook Express\msimn.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2003/12/10 23:09:34 | 000,046,592 | R— | M] (Dantz Development Corporation) – C:\Program Files\Dantz\Retrospect\wdsvc.exe
PRC - [2003/11/12 13:46:34 | 000,049,152 | —- | M] (Dantz Development Corporation) – C:\Program Files\Dantz\Retrospect\retrorun.exe
PRC - [2003/08/19 02:01:00 | 000,110,592 | —- | M] (Sonic Solutions) – C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
PRC - [2003/07/23 11:41:54 | 000,065,536 | —- | M] (Hewlett-Packard Company) – C:\Program Files\HP DVD\Umbrella\DVDTray.exe
PRC - [2002/10/25 18:33:46 | 000,069,632 | —- | M] (MyComp) – C:\Program Files\USB Storage RW\shwicon.exe


========== Modules (No Company Name) ==========

MOD - [2012/10/10 06:06:15 | 000,460,312 | —- | M] () – C:\Program Files\Google\Chrome\Application\22.0.1229.94\ppgooglenaclpluginchrome.dll
MOD - [2012/10/10 06:06:12 | 004,005,912 | —- | M] () – C:\Program Files\Google\Chrome\Application\22.0.1229.94\pdf.dll
MOD - [2012/10/10 06:04:44 | 000,156,712 | —- | M] () – C:\Program Files\Google\Chrome\Application\22.0.1229.94\avutil-51.dll
MOD - [2012/10/10 06:04:43 | 000,275,496 | —- | M] () – C:\Program Files\Google\Chrome\Application\22.0.1229.94\avformat-54.dll
MOD - [2012/10/10 06:04:42 | 002,168,360 | —- | M] () – C:\Program Files\Google\Chrome\Application\22.0.1229.94\avcodec-54.dll
MOD - [2012/01/08 09:41:12 | 000,093,696 | —- | M] () – C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2006/10/22 13:22:00 | 000,212,992 | —- | M] () – C:\WINDOWS\system32\nvapi.dll


========== Services (SafeList) ==========

SRV - [2012/10/08 21:55:53 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2011/06/13 23:09:22 | 000,267,568 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files\Microsoft Fix it Center\Matsvc.exe – (MatSvc)
SRV - [2011/04/16 20:45:11 | 000,130,008 | R— | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe – (N360)
SRV - [2003/12/10 23:09:34 | 000,046,592 | R— | M] (Dantz Development Corporation) [Auto | Running] – C:\Program Files\Dantz\Retrospect\wdsvc.exe – (RetroWDSvc)
SRV - [2003/11/12 13:46:34 | 000,110,592 | —- | M] (Dantz Development Corporation) [Auto | Stopped] – C:\Program Files\Dantz\Retrospect\rthlpsvc.exe – (Retrospect Helper)
SRV - [2003/11/12 13:46:34 | 000,049,152 | —- | M] (Dantz Development Corporation) [Auto | Running] – C:\Program Files\Dantz\Retrospect\retrorun.exe – (RetroLauncher)
SRV - [2002/11/14 11:09:14 | 000,077,824 | —- | M] (HP) [On_Demand | Stopped] – C:\WINDOWS\system32\hphipm11.exe – (Pml Driver HPH11)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMNDIS.SYS – (SYMNDIS)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMIDS.SYS – (SYMIDS)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMFW.SYS – (SYMFW)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PCDRDRV)
DRV - File not found [Kernel | Auto | Stopped] – C:\Program Files\LogMeIn\x86\RaInfo.sys – (LMIInfo)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [File_System | Boot | Stopped] – system32\DRIVERS\Lbd.sys – (Lbd)
DRV - File not found [Kernel | System | Stopped] – – (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys – (EraserUtilDrvI9)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - [2012/09/13 08:18:35 | 001,601,184 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20121016.021\NAVEX15.SYS – (NAVEX15)
DRV - [2012/09/13 08:18:35 | 000,092,704 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20121016.021\NAVENG.SYS – (NAVENG)
DRV - [2012/08/31 20:27:25 | 000,373,728 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20121016.001\IDSXpx86.sys – (IDSxpx86)
DRV - [2012/08/31 18:09:14 | 000,995,488 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20120928.001\BHDrvx86.sys – (BHDrvx86)
DRV - [2012/08/09 08:22:40 | 000,376,480 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2012/08/09 08:22:40 | 000,106,656 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2011/05/18 08:13:42 | 000,126,584 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2011/04/20 21:37:49 | 000,369,784 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\symtdi.sys – (SYMTDI)
DRV - [2011/03/30 23:00:09 | 000,516,216 | —- | M] (Symantec Corporation) [File_System | System | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\srtsp.sys – (SRTSP)
DRV - [2011/03/30 23:00:09 | 000,050,168 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\srtspx.sys – (SRTSPX)
DRV - [2011/03/14 22:31:23 | 000,744,568 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\symefa.sys – (SymEFA)
DRV - [2011/01/27 02:47:10 | 000,340,088 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\symds.sys – (SymDS)
DRV - [2010/11/15 21:45:33 | 000,136,312 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\N360\0502020.003\ironx86.sys – (SymIRON)
DRV - [2009/09/16 10:22:48 | 000,214,664 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2009/09/16 10:22:48 | 000,079,816 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2009/09/16 10:22:48 | 000,040,552 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfesmfk.sys – (mfesmfk)
DRV - [2009/09/16 10:22:48 | 000,035,272 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2009/09/16 10:22:14 | 000,034,248 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mferkdk.sys – (mferkdk)
DRV - [2008/05/19 15:24:04 | 000,083,288 | —- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] – C:\WINDOWS\System32\LMIRfsClientNP.dll – (LMIRfsClientNP)
DRV - [2008/03/07 13:39:50 | 000,045,848 | —- | M] (LogMeIn, Inc.) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys – (LMIRfsDriver)
DRV - [2004/10/01 11:24:02 | 002,279,424 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM)
DRV - [2004/08/04 01:31:32 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\rtl8139.sys – (rtl8139)
DRV - [2003/10/01 18:41:28 | 000,177,664 | —- | M] (Emuzed, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\EvcapMau.sys – (EvcapMaui)
DRV - [2003/05/02 03:12:14 | 000,009,856 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (pfc)
DRV - [2003/03/08 01:13:22 | 000,624,369 | —- | M] (LT) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ltmdmnt.sys – (ltmodem5)
DRV - [2003/01/07 13:32:26 | 000,015,400 | R— | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\NetMotCM.sys – (ndiscm)
DRV - [2001/11/01 14:14:04 | 000,017,024 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\scopex0.sys – (GT891x)
DRV - [2001/09/20 09:58:48 | 000,153,824 | —- | M] (Zoran Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\NUVvid2.sys – (NUVision)
DRV - [2001/09/20 09:47:38 | 000,025,184 | —- | M] (Zoran Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nuvaud2.sys – (nuvaud2)
DRV - [2001/08/05 22:13:54 | 000,314,720 | R— | M] (Grandtech Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\scopex1.SYS – (DCamUSBGrandTek)
DRV - [2001/06/04 16:00:00 | 000,014,112 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.msnbc.msn.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {5AFB1C08-DA54-4C8F-AF4B-8A05B911FC67}
IE - HKCU\..\SearchScopes\{5AFB1C08-DA54-4C8F-AF4B-8A05B911FC67}: "URL" = http://www.google.com/search?q={searchTerm…1I7GGLJ_enUS292
IE - HKCU\..\SearchScopes\{611F04C5-F1CA-4EBA-96D7-9789A5C7AE4B}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7GGLD
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7GGLJ
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l…q={SEARCHTERMS}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..network.proxy.no_proxies_on: "localhost"
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2629: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2012/02/08 08:50:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_13_2 [2012/10/18 07:34:20 | 000,000,000 | —D | M]

[2011/03/01 22:30:16 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ulda3u9v.default\extensions
[2007/10/08 19:25:52 | 000,024,576 | —- | M] (My Web Search) – C:\Program Files\mozilla firefox\plugins\NPMySrWB.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U35 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.350.10 (Enabled) = C:\WINDOWS\system32\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

O1 HOSTS File: ([2002/08/29 15:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O4 - HKLM..\Run: [DVDTray] C:\Program Files\HP DVD\Umbrella\DVDTray.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW" File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe (Leader Technologies)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [ [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsupport.com/sdccommon/download/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} http://www.alternatiff.com/distribution/al…x-w32-2.0.1.cab (AlternaTIFF ActiveX)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} http://picasaweb.google.com/s/v/63.24/uploader2.cab (UploadListView Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EB963901-38AC-4F95-94FA-E6B7B8E09825}: DhcpNameServer = 75.75.75.75 75.75.76.76
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\Userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/05/06 00:12:36 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2002/09/11 03:02:32 | 000,000,045 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{f0820590-d333-11df-b3e3-000c6e7713b0}\Shell - "" = AutoRun
O33 - MountPoints2\{f0820590-d333-11df-b3e3-000c6e7713b0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f0820590-d333-11df-b3e3-000c6e7713b0}\Shell\AutoRun\command - "" = L:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/10/17 17:32:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2012/10/17 17:31:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/10/17 17:31:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/10/17 17:31:49 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/10/17 17:31:49 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/10/17 16:54:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Avg2013
[2012/10/17 16:32:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\TuneUp Software
[2012/10/16 16:19:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Xfinity.com
[2012/10/16 08:26:19 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2012/10/16 08:23:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/10/16 08:23:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\MFAData
[2012/10/16 08:23:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2012/10/15 21:51:17 | 000,000,000 | —D | C] – C:\WINDOWS\TempDir
[2012/10/08 22:08:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Quicken
[2012/10/08 22:08:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Palo Alto Software
[2012/10/05 09:09:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\Nana-Grampa-Larkin
[2012/09/29 15:36:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\Favorites
[2012/09/24 23:03:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\searchresultstb
[2012/09/24 23:03:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\AppData
[2012/09/24 23:03:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\imeshtoolbar2
[2012/09/24 23:03:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\92AF
[2012/09/24 23:01:38 | 000,000,000 | —D | C] – C:\Program Files\iMesh Applications
[2012/09/24 23:00:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\PackageAware
[2005/12/02 20:18:20 | 019,846,914 | —- | C] (NVIDIA Corporation) – C:\Program Files\71.89_win2kxp_english.exe
[2005/08/09 22:34:49 | 006,860,424 | —- | C] (Microsoft Corporation ) – C:\Program Files\MicrosoftAntiSpywareInstall.exe
[2005/07/25 17:33:26 | 002,575,792 | —- | C] (Simple Star, Inc.) – C:\Program Files\comcast_photoshow_deluxe_4.exe
[2005/07/25 15:58:57 | 000,465,096 | —- | C] (Simple Star, Inc.) – C:\Program Files\SnapfishPhotoShow.exe
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/18 07:36:22 | 000,087,959 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2012/10/18 07:36:06 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/18 07:35:56 | 000,000,616 | -H– | M] () – C:\WINDOWS\tasks\ConfigExec.job
[2012/10/18 07:35:12 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/18 07:33:51 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc208ea0ecc77e.job
[2012/10/18 07:33:22 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/18 07:33:03 | 2683,752,448 | -HS- | M] () – C:\hiberfil.sys
[2012/10/17 22:55:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/17 18:25:27 | 000,004,231 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\mbam.rtf
[2012/10/17 17:38:00 | 000,000,580 | -H– | M] () – C:\WINDOWS\tasks\DataUpload.job
[2012/10/17 17:31:55 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/16 15:25:00 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/10/14 20:48:23 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmpB02EC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmpEEEDC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmpA8FDC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmp2E0EC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmp24EDC.FOT
[2012/10/14 12:19:46 | 000,001,824 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/10/14 12:19:46 | 000,001,802 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/10/12 17:25:10 | 000,019,783 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\JimLHS-Expenses.ods
[2012/10/10 08:50:02 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/10/09 14:31:31 | 000,037,926 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\tomichromeII.ods
[2012/10/08 22:14:32 | 000,001,318 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2012/10/08 22:14:32 | 000,000,431 | —- | M] () – C:\WINDOWS\intuprof.ini
[2012/10/08 22:09:39 | 000,000,064 | —- | M] () – C:\WINDOWS\qwimp.ini
[2012/10/08 22:08:48 | 000,001,486 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Quicken 2004.lnk
[2012/10/08 22:08:48 | 000,000,228 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Best for Quicken - Low Intro APR and Optional Travel Rewards.url
[2012/10/08 22:08:48 | 000,000,203 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Special Offer from Citibank.url
[2012/10/08 22:08:48 | 000,000,189 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Visit Quicken.com.url
[2012/10/08 22:08:30 | 000,000,686 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
[2012/10/08 21:55:47 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/08 21:55:47 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/09/29 19:54:26 | 000,022,856 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/09/24 10:42:38 | 000,001,181 | —- | M] () – C:\WINDOWS\cdplayer.ini
[2012/09/21 13:06:29 | 000,010,240 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\displays.odt
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/17 18:25:27 | 000,004,231 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\mbam.rtf
[2012/10/17 17:31:55 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/16 15:51:15 | 2683,752,448 | -HS- | C] () – C:\hiberfil.sys
[2012/10/14 20:48:23 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmpB02EC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmpEEEDC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmpA8FDC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmp2E0EC.FOT
[2012/10/14 20:48:22 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmp24EDC.FOT
[2012/10/08 22:09:39 | 000,000,064 | —- | C] () – C:\WINDOWS\qwimp.ini
[2012/10/08 22:08:48 | 000,000,228 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Best for Quicken - Low Intro APR and Optional Travel Rewards.url
[2012/10/08 22:08:48 | 000,000,203 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Special Offer from Citibank.url
[2012/10/08 22:08:48 | 000,000,189 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Visit Quicken.com.url
[2012/10/08 22:08:30 | 000,000,686 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
[2012/10/08 22:08:29 | 000,001,486 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Quicken 2004.lnk
[2012/09/20 22:17:16 | 000,010,240 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\displays.odt
[2012/02/15 20:01:42 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2009/10/07 18:01:34 | 000,019,707 | —- | C] () – C:\Documents and Settings\All Users\Application Data\exezeda.vbs
[2009/10/07 18:01:34 | 000,019,291 | —- | C] () – C:\Documents and Settings\All Users\Application Data\igodu.com
[2009/10/07 18:01:34 | 000,019,231 | —- | C] () – C:\Documents and Settings\All Users\Application Data\gunyfaj.sys
[2009/10/07 18:01:34 | 000,017,473 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\ajinavyrot.lib
[2009/10/07 18:01:34 | 000,015,316 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\tacevikob.bat
[2009/10/07 18:01:34 | 000,015,145 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\dyzitep.bin
[2009/10/07 18:01:34 | 000,014,250 | —- | C] () – C:\Documents and Settings\All Users\Application Data\opap.reg
[2009/10/07 18:01:34 | 000,011,715 | —- | C] () – C:\Program Files\Common Files\hijak.ban
[2009/10/07 18:01:34 | 000,011,269 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\cicizihu.ban
[2009/10/07 17:38:58 | 000,018,655 | —- | C] () – C:\Program Files\Common Files\isekopibej.db
[2009/10/07 17:38:58 | 000,017,958 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\gaje.reg
[2009/10/07 17:38:58 | 000,017,412 | —- | C] () – C:\Program Files\Common Files\hodusur.dat
[2009/10/07 17:38:58 | 000,015,582 | —- | C] () – C:\Documents and Settings\All Users\Application Data\gulynohyx.reg
[2009/10/07 17:38:58 | 000,015,450 | —- | C] () – C:\Program Files\Common Files\ytuxydy.pif
[2009/10/07 17:38:58 | 000,014,860 | —- | C] () – C:\Documents and Settings\All Users\Application Data\jimot.ban
[2009/10/07 17:38:58 | 000,014,336 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\weniwez.dl
[2009/10/07 17:38:58 | 000,014,289 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\amovehiri.bat
[2009/10/07 17:38:58 | 000,012,934 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\dahi.vbs
[2009/10/07 17:38:57 | 000,014,744 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\qalyso.pif
[2009/10/07 17:38:57 | 000,010,668 | —- | C] () – C:\Program Files\Common Files\gihirof.bat
[2009/10/07 17:38:57 | 000,010,329 | —- | C] () – C:\Program Files\Common Files\geso._dl
[2009/07/13 13:22:03 | 003,296,158 | —- | C] () – C:\Documents and Settings\Administrator\FredAstaireEleanorPowell1.wmv
[2009/06/20 14:59:05 | 001,127,767 | —- | C] () – C:\Documents and Settings\Administrator\malpki.wmv
[2009/06/05 13:51:21 | 000,000,397 | —- | C] () – C:\Documents and Settings\Administrator\IceHarvast2.lnk
[2009/05/29 11:15:48 | 000,889,676 | —- | C] () – C:\Documents and Settings\Administrator\CourtesyofUSMarines (1).wmv
[2009/05/29 09:13:21 | 001,977,352 | —- | C] () – C:\Documents and Settings\Administrator\Weight_Lifting_Surprise.wmv
[2009/05/26 09:21:14 | 000,889,676 | —- | C] () – C:\Documents and Settings\Administrator\CourtesyofUSMarines.wmv
[2009/02/11 15:00:16 | 000,000,596 | RHS- | C] () – C:\Documents and Settings\Administrator\ntuser.pol
[2006/11/23 23:26:14 | 000,008,055 | —- | C] () – C:\Program Files\1615855.htm
[2006/11/21 12:52:32 | 000,252,416 | —- | C] () – C:\Program Files\uninstall_flash_player.exe
[2006/05/18 20:38:42 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/28 22:37:21 | 000,010,322 | —- | C] () – C:\Program Files\pot[1][1].tv_02119_20030815__hs-death.rm.torrent
[2006/02/10 14:01:01 | 017,496,033 | —- | C] () – C:\Program Files\1955-56 Parts manual-B.djvu
[2006/02/08 10:39:58 | 003,338,240 | —- | C] () – C:\Documents and Settings\Administrator\s-1-5-21-698036064-2301516679-3255942371-500.rrr
[2005/11/21 23:55:44 | 013,831,036 | —- | C] () – C:\Program Files\VibeComcastVMInstall.exe
[2004/03/29 21:35:38 | 000,000,616 | —- | C] () – C:\Documents and Settings\Administrator\plugin131_09.trace
[2004/01/02 13:30:54 | 000,000,507 | -H– | C] () – C:\Documents and Settings\Administrator\Application Data\hpothb07.tif
[2004/01/02 13:30:54 | 000,000,376 | -H– | C] () – C:\Documents and Settings\Administrator\Application Data\hpothb07.dat
[2004/01/01 21:49:21 | 000,061,678 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\PFP100JPR.{PB
[2004/01/01 21:49:21 | 000,012,358 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\PFP100JCM.{PB
[2003/12/27 14:00:09 | 000,086,528 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/05/06 01:14:38 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat

========== ZeroAccess Check ==========

[2003/05/06 00:08:52 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\System32\shdocvw.dll – [2008/04/13 20:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >
Hm - Ask not completely gone so we'll have a go with something different which may shed some light on what is going on.

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, as they may otherwise interfere with our tools. See here for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    🖼Click to load external image (Posted Image)


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    🖼Click to load external image (Posted Image)


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Satchfan
All set with ComboFix log.

ComboFix 12-10-18.03 - Administrator 10/18/2012 14:06:06.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2559.1701 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: Norton Security Suite *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Security Suite *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\LogMeInRemoteUser\WINDOWS
c:\program files\Common Files\isekopibej.db
c:\windows\dudyrif.dll
c:\windows\gyzekub.exe
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\DC120fc7_32.dll
c:\windows\system32\ps2.bat
c:\windows\ugefa._sy
D:\Autorun.inf
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NVSVC
——-\Service_NVSvc
.
.
((((((((((((((((((((((((( Files Created from 2012-09-18 to 2012-10-18 )))))))))))))))))))))))))))))))
.
.
2012-10-17 21:32 . 2012-10-17 21:32 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2012-10-17 21:31 . 2012-10-17 21:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-10-17 21:31 . 2012-10-17 21:31 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-10-17 21:31 . 2012-09-29 23:54 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-10-17 20:54 . 2012-10-17 20:54 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Avg2013
2012-10-17 20:32 . 2012-10-17 20:32 ——– d—–w- c:\documents and settings\Administrator\Application Data\TuneUp Software
2012-10-16 20:19 . 2012-10-16 20:19 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Xfinity.com
2012-10-16 19:47 . 2012-10-16 19:47 ——– d—–w- c:\windows\system32\wbem\Repository
2012-10-16 12:26 . 2012-10-16 12:26 ——– d—–w- c:\program files\AVG
2012-10-16 12:23 . 2012-10-17 20:56 ——– d—–w- c:\documents and settings\All Users\Application Data\MFAData
2012-10-16 12:23 . 2012-10-16 12:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Common Files
2012-10-16 12:23 . 2012-10-16 12:23 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\MFAData
2012-10-15 00:48 . 2012-10-15 00:48 1409 —-a-w- c:\windows\system32\tmpB02EC.FOT
2012-10-15 00:48 . 2012-10-15 00:48 1409 —-a-w- c:\windows\system32\tmpEEEDC.FOT
2012-10-15 00:48 . 2012-10-15 00:48 1409 —-a-w- c:\windows\system32\tmpA8FDC.FOT
2012-10-15 00:48 . 2012-10-15 00:48 1409 —-a-w- c:\windows\system32\tmp2E0EC.FOT
2012-10-15 00:48 . 2012-10-15 00:48 1409 —-a-w- c:\windows\system32\tmp24EDC.FOT
2012-10-09 02:08 . 2012-10-09 02:08 ——– d—–w- c:\program files\Common Files\Palo Alto Software
2012-10-09 01:55 . 2012-10-09 01:55 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2012-09-25 03:03 . 2012-09-25 03:03 ——– d—–w- c:\documents and settings\Administrator\Application Data\searchresultstb
2012-09-25 03:03 . 2012-09-25 03:03 ——– d—–w- c:\documents and settings\Administrator\AppData
2012-09-25 03:03 . 2012-09-25 03:04 ——– d—–w- c:\documents and settings\Administrator\Application Data\imeshtoolbar2
2012-09-25 03:03 . 2012-09-25 03:03 ——– d—–w- c:\documents and settings\All Users\Application Data\92AF
2012-09-25 03:01 . 2012-10-02 13:21 ——– d—–w- c:\program files\iMesh Applications
2012-09-25 03:00 . 2012-09-25 03:00 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\PackageAware
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-09 01:55 . 2012-05-05 12:08 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-09 01:55 . 2011-10-20 15:26 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-18 01:08 . 2012-09-18 01:09 73728 —-a-w- c:\windows\system32\javacpl.cpl
2012-09-18 01:08 . 2012-09-18 01:09 477168 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-09-18 01:08 . 2011-11-28 02:03 473072 —-a-w- c:\windows\system32\deployJava1.dll
2012-08-28 15:14 . 2004-02-06 22:05 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2003-05-21 21:15 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2003-05-21 21:15 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2003-05-21 20:54 177664 —-a-w- c:\windows\system32\wintrust.dll
2012-08-21 13:33 . 2002-08-29 08:04 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-21 12:58 . 2002-08-29 08:04 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-07 21:38 . 2009-10-07 21:38 15450 -c–a-w- c:\program files\Common Files\ytuxydy.pif
2009-10-07 21:38 . 2009-10-07 21:38 10668 -c–a-w- c:\program files\Common Files\gihirof.bat
2006-11-21 16:52 . 2006-11-21 16:52 252416 -c–a-w- c:\program files\uninstall_flash_player.exe
2005-12-03 00:18 . 2005-12-03 00:18 19846914 -c–a-w- c:\program files\71.89_win2kxp_english.exe
2005-11-22 03:55 . 2005-11-22 03:55 13831036 -c–a-w- c:\program files\VibeComcastVMInstall.exe
2005-08-10 02:35 . 2005-08-10 02:34 6860424 -c–a-w- c:\program files\MicrosoftAntiSpywareInstall.exe
2005-07-25 21:33 . 2005-07-25 21:33 2575792 -c–a-w- c:\program files\comcast_photoshow_deluxe_4.exe
2005-07-25 19:59 . 2005-07-25 19:58 465096 -c–a-w- c:\program files\SnapfishPhotoShow.exe
.
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="c:\program files\AWS\WeatherBug\Weather.exe" [2006-04-07 1343488]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KYE_Showicon"="c:\program files\USB Storage RW\shwicon.exe -tKYE\USB Storage RW" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"ehTray"="c:\windows\ehome\ehtray.exe" [2008-04-14 50176]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"DVDTray"="c:\program files\HP DVD\Umbrella\DVDTray.exe" [2003-07-23 65536]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-05 421888]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [N/A]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Quicken Scheduled Updates.lnk - c:\program files\Quicken\bagent.exe [2003-12-12 57344]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-05-19 19:23 87352 —-a-w- c:\windows\system32\LMIinit.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^customize__IE.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\customize__IE.lnk
backup=c:\windows\pss\customize__IE.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center.lnk
backup=c:\windows\pss\hp center.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MsnFixer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\MsnFixer.lnk
backup=c:\windows\pss\MsnFixer.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus C62 Series (Copy 1)]
2002-04-10 08:00 74240 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\E_S0BIC1.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-12-11 01:52 49152 -c–a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager]
2005-05-09 23:16 192512 -c–a-w- c:\progra~1\Comcast\COMCAS~1\data\Xtras\bak\mssysmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 22:36 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\svchost]
c:\documents and settings\Administrator\Application Data\svcst.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [N/A]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Support.com\\bin\\tgcmd.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=
"c:\\Program Files\\iMesh Applications\\Mediabar\\Datamngr\\SRTOOL~1\\dtUser.exe"=
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0502020.003\symds.sys [7/16/2012 8:42 PM 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0502020.003\symefa.sys [7/16/2012 8:42 PM 744568]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20120928.001\BHDrvx86.sys [10/1/2012 2:41 PM 995488]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0502020.003\ironx86.sys [7/16/2012 8:42 PM 136312]
R2 N360;Norton Security Suite;c:\program files\Norton Security Suite\Engine\5.2.2.3\ccsvchst.exe [7/16/2012 8:42 PM 130008]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/9/2012 8:22 AM 106656]
R3 EvcapMaui;Emuzed EvcapMaui Device;c:\windows\system32\drivers\EvcapMau.sys [5/6/2003 12:54 AM 177664]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20121017.001\IDSXpx86.sys [10/18/2012 7:46 AM 373728]
R3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [6/13/2011 11:09 PM 267568]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/29/2010 11:34 PM 135664]
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\LogMeIn\x86\RaInfo.sys –> c:\program files\LogMeIn\x86\RaInfo.sys [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [5/5/2012 8:09 AM 250808]
S3 EraserUtilDrvI9;EraserUtilDrvI9;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1/29/2010 11:34 PM 135664]
S3 NUVision;NUVision Video Service;c:\windows\system32\drivers\NUVvid2.sys [6/21/2004 10:08 PM 153824]
S3 PCDRDRV;Pcdr Helper Driver; [x]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 01:55]
.
2012-10-18 c:\windows\Tasks\ConfigExec.job
- c:\program files\Microsoft Fix it Center\MatsApi.dll [2011-06-14 03:09]
.
2012-10-18 c:\windows\Tasks\DataUpload.job
- c:\program files\Microsoft Fix it Center\MatsApi.dll [2011-06-14 03:09]
.
2012-10-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc208ea0ecc77e.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 03:34]
.
2012-10-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 03:34]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Trusted Zone: internet
Trusted Zone: mcafee.com
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
SafeBoot-mcmscsvc
SafeBoot-MCODS
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-18 14:20
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\5.2.2.3\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-698036064-2301516679-3255942371-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b9,c4,20,b3,3c,af,cd,42,b5,7f,ac,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b9,c4,20,b3,3c,af,cd,42,b5,7f,ac,\
.
[HKEY_USERS\S-1-5-21-698036064-2301516679-3255942371-500\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(616)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(1560)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\LMIRfsClientNP.dll
.
———————— Other Running Processes ————————
.
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Dantz\Retrospect\retrorun.exe
c:\progra~1\Dantz\RETROS~1\wdsvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\program files\USB Storage RW\shwicon.exe
c:\windows\ALCXMNTR.EXE
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2012-10-18 14:35:33 - machine was rebooted
ComboFix-quarantined-files.txt 2012-10-18 18:35
.
Pre-Run: 83,505,672,192 bytes free
Post-Run: 84,942,864,384 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 2FE8DD55D9EA8F8D9D4AFB64AB17FB3A
Run ComboFix

Delete the version of ComboFix you have here:

c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe

Download a new version which MUST be saved directly to your desktop. To do this, choose save as and then make sure you choose Desktop

Download a new version from one of the following locations:

Link1
Link2
Link3

When it is downloaded, click the Windows “Start” button, select Run, then copy/paste the following bolded text into the run box and then click OK

C:\Qoobox\Add-Remove Programs.txt

Please post back with the list.

================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.
Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI