This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help! Google Chrome - Blekko Virus [Solved]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I just ran OTL per instructions on the "Are You Infected" topic, but there was only one report:

OTL logfile created on: 10/28/2012 1:47:56 PM - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.40 Gb Available Physical Memory | 73.89% Memory free
5.09 Gb Paging File | 4.20 Gb Available in Paging File | 82.50% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 292.97 Gb Total Space | 111.38 Gb Free Space | 38.02% Space Free | Partition Type: NTFS
Drive D: | 303.19 Gb Total Space | 188.71 Gb Free Space | 62.24% Space Free | Partition Type: NTFS

Computer Name: STEVE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL (3).exe (OldTimer Tools)
PRC - C:\Program Files\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Download Manager\DownloadManager.exe (DownloadManager)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
PRC - C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe (NVIDIA)
PRC - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
PRC - C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\hasplms.exe (Aladdin Knowledge Systems Ltd.)
PRC - C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\TaskSwitch.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM62.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM60.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM5E.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM5C.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM59.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM57.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM55.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM53.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM51.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM4F.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM4D.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM4B.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM49.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM47.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM45.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM43.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM41.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM3F.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM3D.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM3B.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM39.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM37.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM35.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM32.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM30.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM2E.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM2C.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM2A.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM28.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM26.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM24.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM22.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM20.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM1E.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM1C.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM18.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM16.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\YTMP7MC8AA\TAA1A.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM14.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM10.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM12.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEME.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEMC.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEMA.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM8.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM6.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM4.tmp ()
MOD - C:\Program Files\AVAST Software\Avast\defs\12102800\algo.dll ()
MOD - C:\Program Files\Google\Chrome\Application\22.0.1229.94\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files\Google\Chrome\Application\22.0.1229.94\PepperFlash\pepflashplayer.dll ()
MOD - C:\Program Files\Google\Chrome\Application\22.0.1229.94\pdf.dll ()
MOD - C:\Program Files\Google\Chrome\Application\22.0.1229.94\avutil-51.dll ()
MOD - C:\Program Files\Google\Chrome\Application\22.0.1229.94\avformat-54.dll ()
MOD - C:\Program Files\Google\Chrome\Application\22.0.1229.94\avcodec-54.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\SwiftShader\1.0.1.3\libEGL.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\SwiftShader\1.0.1.3\libGLESv2.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\dbc413807cb7360b3e26ef3ca1d54f9a\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b84bb74d7724e147a642a1d5358feb7\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\Program Files\ManyCam\Bin\cximagecrt.dll ()
MOD - C:\Program Files\ManyCam\Bin\CrashRpt.dll ()
MOD - C:\WINDOWS\assembly\GAC\Interop.SHDocVw\1.1.0.0__4b827ebe229d539f\Interop.SHDocVw.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\ManyCam\Bin\opencv_video220.dll ()
MOD - C:\Program Files\ManyCam\Bin\opencv_objdetect220.dll ()
MOD - C:\Program Files\ManyCam\Bin\opencv_highgui220.dll ()
MOD - C:\Program Files\ManyCam\Bin\opencv_imgproc220.dll ()
MOD - C:\Program Files\ManyCam\Bin\opencv_core220.dll ()
MOD - C:\Program Files\Yahoo!\Messenger\yui.dll ()
MOD - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
MOD - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\WINDOWS\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll ()
MOD - C:\WINDOWS\system32\qedit.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\TaskSwitch.exe ()


========== Services (SafeList) ==========

SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (MotoHelper) – C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (UpdateCenterService) – C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe (NVIDIA)
SRV - (nTuneService) – C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
SRV - (QuickBooksDB20) – C:\Program Files\Intuit\QuickBooks 2007\QBDBMgrN.exe (Intuit, Inc.)
SRV - (QuickBooksDB17) – C:\Program Files\Intuit\QuickBooks 2007\QBDBMgrN.exe (Intuit, Inc.)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
SRV - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Adobe Version Cue CS4) – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe (Adobe Systems Incorporated)
SRV - (hasplms) – C:\WINDOWS\system32\hasplms.exe (Aladdin Knowledge Systems Ltd.)
SRV - (UPHClean) – C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (TFSysMon) – system32\drivers\TfSysMon.sys File not found
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys File not found
DRV - (TfFsMon) – system32\drivers\TfFsMon.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mbr) – C:\DOCUME~1\Owner\LOCALS~1\Temp\mbr.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (esgiguard) – C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (AswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (mcaudrv_simple) – C:\WINDOWS\system32\drivers\mcaudrv.sys (ManyCam LLC)
DRV - (ManyCam) – C:\WINDOWS\system32\drivers\mcvidrv.sys (ManyCam LLC)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (motccgp) – C:\WINDOWS\system32\drivers\motccgp.sys (Motorola)
DRV - (motmodem) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (Motousbnet) – C:\WINDOWS\system32\drivers\Motousbnet.sys (Motorola)
DRV - (motusbdevice) – C:\WINDOWS\system32\drivers\motusbdevice.sys (Motorola Inc)
DRV - (DumpDrv) – C:\WINDOWS\System32\drivers\dumpdrv.sys (Microsoft Corporation)
DRV - (nvoclock) – C:\WINDOWS\system32\drivers\nvoclock.sys (NVIDIA Corp.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (LSI Corporation)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (motccgpfl) – C:\WINDOWS\system32\drivers\motccgpfl.sys (Motorola)
DRV - (BTCFilterService) – C:\WINDOWS\system32\drivers\motfilt.sys (Motorola Inc)
DRV - (KMWDFILTER) – C:\WINDOWS\system32\drivers\KMWDFILTER.sys (Windows ® Codename Longhorn DDK provider)
DRV - (nvsmu) – C:\WINDOWS\system32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (MotoSwitchService) – C:\WINDOWS\system32\drivers\motswch.sys (Motorola)
DRV - (AmdPPM) – C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (aksfridge) – C:\WINDOWS\system32\drivers\aksfridge.sys (Aladdin Knowledge Systems Ltd.)
DRV - (Hardlock) – C:\WINDOWS\system32\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.)
DRV - (MTDVC2) – C:\WINDOWS\system32\drivers\mtdv2ku2.sys (Matsushita Electric Industrial Co., Ltd.)
DRV - (MTDVC2_ENUM) – C:\WINDOWS\system32\drivers\mtdv2ks2.sys (Matsushita Electric Industrial Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {08695E7C-3FF8-408F-89E5-CDCE161D6692}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{08695E7C-3FF8-408F-89E5-CDCE161D6692}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_…e=tb50winampie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {08695E7C-3FF8-408F-89E5-CDCE161D6692}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{08695E7C-3FF8-408F-89E5-CDCE161D6692}: "URL" = http://www.google.com/search?q={searchTerm…1I7FDUM_enUS474
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://blekko.com/ws/?source=6a1885c1&…q={searchTerms}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={4A3504E…mp;d=2012-04-06 15:09:33&v=10.2.0.3&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{9B97950D-482C-1D79-568F-FC7B9D40C785}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKCU\..\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}: "URL" = http://search.alot.com/web?q={searchTerms}…n=1.1.3001.0(B)
IE - HKCU\..\SearchScopes\{BDD10262-D0F4-4FAB-B402-A433F6E86C5C}: "URL" = http://websearch.ask.com/redirect?client=i…16-86D71B1F03FE
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?p={searchTerms}
IE - HKCU\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_…e=tb50winampie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)


[2012/03/10 10:48:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/06 17:37:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/12/01 21:12:43 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/25 10:32:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/01/30 13:17:14 | 000,000,000 | —D | M] (PHPNukeEN Toolbar) – C:\Program Files\Mozilla Firefox\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}
[2010/11/12 19:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

========== Chrome ==========

CHR - homepage: http://blekko.com/ws/?source=6a1885c1&…mp;tbp=homepage
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://blekko.com/ws/?source=6a1885c1&…mp;tbp=homepage
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - Extension: avast! WebRep = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0\

O1 HOSTS File: ([2012/10/28 13:26:39 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O2 - BHO: (Fast Search) - {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files\Surf Canyon\surfcanyon.dll (Surf Canyon Incorporated)
O2 - BHO: (RebateRobot BHO) - {66616350-A70C-4FF5-912E-A92B8076F6F7} - C:\Program Files\RebateRobot\RebateRobot.dll File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe_ID0ENQBO] C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /installquiet File not found
O4 - HKLM..\Run: [QuickBooksDB20] C:\Program Files\Intuit\QuickBooks 2007\QBDBMgrN.exe (Intuit, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime Alternative\qttask.exe (Apple Inc.)
O4 - HKCU..\Run: [DownloadManager] C:\Program Files\Download Manager\DownloadManager.exe (DownloadManager)
O4 - HKCU..\Run: [ManyCam] C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Program Files\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MaxRecentDocs = 18
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: verbosestatus = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Owner\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} file:///C:/Program%20Files/Land%20Desktop%20R2/AcDcToday.ocx (AcDcToday Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} file:///C:/Program%20Files/Land%20Desktop%20R2/InstFred.ocx (InstaFred Control)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} file:///C:/Program%20Files/Land%20Desktop%20R2/AcPreview.ocx (AcPreview Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{57D9B49F-9F74-4830-BDE9-39538E21FEBA}: DhcpNameServer = 75.75.76.76 75.75.75.75 192.168.1.1
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files\Intuit\QuickBooks 2007\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/12/14 16:34:49 | 000,000,000 | —D | M] - C:\Autodesk – [ NTFS ]
O32 - AutoRun File - [2011/02/22 09:58:33 | 000,000,047 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\WINDOWS\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\WINDOWS\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\WINDOWS\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\WINDOWS\System32\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/28 13:07:39 | 000,000,000 | —D | C] – C:\ComboFix
[2012/10/21 10:19:10 | 000,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2012/10/17 13:20:23 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012/10/17 13:19:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2012/10/14 16:24:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\blekko toolbars
[2012/10/14 15:35:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\FrostWire
[2012/10/14 15:35:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\.frostwire5
[2012/10/14 15:35:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\DVDVideoSoftIEHelpers
[2012/10/14 15:34:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\OpenCandy
[2012/10/10 21:06:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Mozilla
[2012/10/10 21:06:52 | 000,000,000 | —D | C] – C:\Config.Msi
[2010/02/09 18:59:22 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\Owner\Application Data\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2012/10/28 13:32:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/28 13:31:41 | 000,444,794 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/10/28 13:31:40 | 000,072,544 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/10/28 13:27:18 | 000,272,291 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2012/10/28 13:26:39 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/10/28 13:26:33 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/28 13:26:03 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/28 13:25:59 | 3488,858,112 | -HS- | M] () – C:\hiberfil.sys
[2012/10/28 13:06:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-2147235713-725345543-1003UA.job
[2012/10/28 13:06:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-2147235713-725345543-1003Core.job
[2012/10/28 12:53:37 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/28 10:23:01 | 000,000,354 | —- | M] () – C:\WINDOWS\tasks\MotoHelper Routing.job
[2012/10/28 08:28:01 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{D34A4223-3F9E-489B-8675-157936D04B47}.job
[2012/10/27 19:59:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/10/27 10:09:58 | 002,384,016 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/10/27 09:26:23 | 000,217,088 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/26 14:42:54 | 000,775,834 | —- | M] () – C:\Documents and Settings\Owner\My Documents\PRLOGO.psd
[2012/10/26 10:23:01 | 000,000,370 | —- | M] () – C:\WINDOWS\tasks\MotoHelper Update.job
[2012/10/26 10:23:01 | 000,000,358 | —- | M] () – C:\WINDOWS\tasks\MotoHelper MUM.job
[2012/10/25 11:38:28 | 001,864,967 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Hummel_Cost_Sheet.pdf
[2012/10/21 19:16:01 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/10/14 15:34:53 | 000,000,902 | —- | M] () – C:\Documents and Settings\Owner\Desktop\DVDVideoSoft Free Studio.lnk
[2012/10/14 15:34:52 | 000,001,061 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Free YouTube to MP3 Converter.lnk
[2012/10/11 05:34:21 | 000,001,823 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/10/10 03:00:59 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/10/08 22:56:46 | 004,089,643 | —- | M] () – C:\Documents and Settings\Owner\My Documents\seatles.psd

========== Files Created - No Company Name ==========

[2012/10/27 10:15:04 | 3488,858,112 | -HS- | C] () – C:\hiberfil.sys
[2012/10/26 14:42:52 | 000,775,834 | —- | C] () – C:\Documents and Settings\Owner\My Documents\PRLOGO.psd
[2012/10/25 11:38:28 | 001,864,967 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Hummel_Cost_Sheet.pdf
[2012/10/14 15:34:53 | 000,000,902 | —- | C] () – C:\Documents and Settings\Owner\Desktop\DVDVideoSoft Free Studio.lnk
[2012/10/14 15:34:52 | 000,001,061 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Free YouTube to MP3 Converter.lnk
[2012/10/08 22:56:42 | 004,089,643 | —- | C] () – C:\Documents and Settings\Owner\My Documents\seatles.psd
[2012/10/07 13:01:51 | 000,000,978 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-2147235713-725345543-1003UA.job
[2012/10/07 13:01:51 | 000,000,926 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-2147235713-725345543-1003Core.job
[2012/03/08 17:25:50 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/03/08 17:25:50 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/03/08 17:25:50 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/03/08 17:25:50 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/03/08 17:25:50 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/03/07 18:24:22 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/03/04 11:06:24 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2012/02/10 15:59:00 | 000,045,056 | —- | C] () – C:\WINDOWS\scluins1.exe
[2012/02/10 15:59:00 | 000,036,864 | —- | C] () – C:\WINDOWS\smon03.exe
[2011/12/26 13:47:28 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/11/27 18:42:16 | 000,217,088 | —- | C] () – C:\WINDOWS\System32\qtmlClient.dll
[2011/07/06 19:59:52 | 000,000,127 | —- | C] () – C:\WINDOWS\smr.INI
[2011/06/24 15:16:27 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll0238.old
[2010/02/09 18:59:22 | 000,007,887 | —- | C] () – C:\Documents and Settings\Owner\Application Data\pcouffin.cat
[2010/02/09 18:59:22 | 000,001,144 | —- | C] () – C:\Documents and Settings\Owner\Application Data\pcouffin.inf
[2009/12/15 10:23:31 | 000,217,088 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/13 18:16:46 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat

========== ZeroAccess Check ==========

[2009/12/13 02:35:40 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/14 04:00:00 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 04:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/03/22 16:28:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ask
[2009/12/21 10:08:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2012/03/10 09:56:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/12/25 10:50:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2012/10/17 13:02:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\blekko toolbars
[2009/12/13 15:23:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Chief Architect X2
[2011/03/15 08:07:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2010/10/02 15:08:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2010/05/10 18:11:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2010/05/10 18:15:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 11
[2011/05/18 18:14:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/01/10 16:18:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/02/16 10:06:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Acoustica
[2010/06/26 10:32:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Amazon
[2011/02/22 10:13:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Autodesk
[2012/04/06 15:08:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Camfrog
[2012/09/12 09:56:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Chief Architect X2
[2010/03/17 07:37:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/10/14 15:35:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DVDVideoSoft
[2012/10/14 15:35:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DVDVideoSoftIEHelpers
[2011/03/10 11:49:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\EPSON
[2011/11/13 11:50:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\F4aQH6dWKfLhXjC
[2009/12/13 02:46:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Foxit
[2010/01/09 14:11:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Foxit Software
[2011/07/06 19:45:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Free Sound Recorder
[2012/05/14 12:16:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ManyCam
[2011/11/13 11:47:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mellOOBtxP
[2012/10/14 15:34:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenCandy
[2012/10/28 09:50:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Spotify
[2011/07/03 13:03:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Style Jukebox Settings
[2012/02/27 16:58:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TestApp
[2010/02/09 18:59:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Vso

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2008/04/14 04:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/14 04:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 04:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2012/10/28 13:30:38 | 000,097,080 | —- | M] () MD5=E5CED10E3744142C6034DBB3D6B4729B – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf

< MD5 for: EXPLORER.SCF >
[2008/04/14 04:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: EXPLORER.ZIP >
[2006/03/06 23:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.CHM >
[2009/02/21 02:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2008/07/12 15:10:18 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2008/04/22 04:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2011/12/16 07:00:16 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=1C206B8FEEC6882B7F7F479E95D2BDD9 – C:\WINDOWS\ie8\iexplore.exe
[2008/04/21 23:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie7updates\KB2647516-IE7\iexplore.exe
[2012/01/13 15:53:20 | 000,182,856 | —- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 15:09:26 | 000,638,816 | -HS- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/10/19 03:25:53 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\ERDNT\cache\IEXPLORE.EXE
[2009/03/08 15:09:26 | 000,638,816 | –S- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2011/12/16 06:35:06 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=DB9D9A73FACB0B11992201D670D73E16 – C:\WINDOWS\$hf_mig$\KB2647516-IE7\SP3QFE\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 15:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/10/19 03:29:55 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2008/07/12 15:10:19 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-0A31FE70.PF >
[2012/10/28 13:07:32 | 000,033,958 | —- | M] () MD5=EC88B481371925AE7E0988C63A2955A3 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-0A31FE70.pf

< MD5 for: IEXPLORE.EXE-12915967.PF >
[2012/10/28 13:07:31 | 000,013,640 | —- | M] () MD5=879237DB2B731E3EFDC7D98BC5A985EC – C:\WINDOWS\Prefetch\IEXPLORE.EXE-12915967.pf

< MD5 for: IEXPLORE.EXE-12BBAE74.PF >
[2012/10/28 13:07:35 | 000,011,478 | —- | M] () MD5=E1818A7A25B544F352376EC03B3E137E – C:\WINDOWS\Prefetch\IEXPLORE.EXE-12BBAE74.pf

< MD5 for: IEXPLORE.HLP >
[2008/04/14 04:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2008/04/14 07:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES.AIP >
[2008/09/18 04:07:48 | 000,118,784 | —- | M] (Adobe Systems Incorporated) MD5=41EE0A80B951D675B9227F29651511E0 – C:\Program Files\Adobe\Adobe Illustrator CS4\Plug-ins\Extensions\Services.aip

< MD5 for: SERVICES.CNF >
[2010/01/18 18:16:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\All Users\Documents\Emily Website\_vti_pvt\services.cnf
[2010/01/18 18:16:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\Owner\My Documents\Emily Website\_vti_pvt\services.cnf
[2010/01/18 18:16:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\Owner\My Documents\My Webs\Emily Website\_vti_pvt\services.cnf
[2005/11/06 09:24:02 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\Owner\My Documents\My Webs\Nelson2011\_vti_pvt\services.cnf

< MD5 for: SERVICES.CSS >
[2005/06/29 14:48:58 | 000,014,339 | —- | M] () MD5=9D415BDEF74ADF7B0CD791E40A911A38 – C:\Program Files\Intuit\QuickBooks 2007\Components\Services\services.css

< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 04:00:00 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\ERDNT\cache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe

< MD5 for: SERVICES.LNK >
[2012/03/07 18:09:49 | 000,001,612 | —- | M] () MD5=89CF57404350B631DAB42C865FC1A312 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2008/04/14 04:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: WINLOGON.EXE >
[2012/01/13 15:53:20 | 000,182,856 | —- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 04:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/14 04:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 04:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2011/06/19 20:23:23 | 001,346,854 | —- | M] () – C:\20.pdf
[2011/06/19 20:22:34 | 001,338,839 | —- | M] () – C:\21.pdf
[2011/02/22 09:58:33 | 000,000,047 | —- | M] () – C:\AUTOEXEC.BAT
[2009/12/13 02:33:11 | 000,000,211 | -HS- | M] () – C:\Boot.bak
[2012/03/07 18:03:03 | 000,000,282 | -HS- | M] () – C:\boot.ini
[2004/08/04 00:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2012/10/28 13:31:06 | 000,018,278 | —- | M] () – C:\ComboFix.txt
[2009/12/13 02:38:35 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/08/06 21:19:45 | 000,006,523 | —- | M] () – C:\DriverPack_WLAN_wnt5_x86-32.txt
[2012/10/28 13:25:59 | 3488,858,112 | -HS- | M] () – C:\hiberfil.sys
[2009/12/13 02:38:35 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/11/24 16:16:27 | 000,000,004 | —- | M] () – C:\mmxsys2.dat
[2009/12/13 02:38:35 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 04:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 04:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/03/06 18:17:55 | 000,092,858 | —- | M] () – C:\OTL.Txt
[2012/10/28 13:25:55 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2012/03/03 16:51:06 | 000,061,270 | —- | M] () – C:\TDSSKiller.2.7.18.0_03.03.2012_14.27.48_log.txt
[2012/03/03 18:54:16 | 000,112,750 | —- | M] () – C:\TDSSKiller.2.7.18.0_03.03.2012_17.12.00_log.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2012/03/07 18:08:08 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/08/14 10:19:28 | 000,091,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/03/21 11:00:00 | 000,049,152 | R— | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\IMFPRINT.DLL
[2009/08/14 10:19:28 | 000,589,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/03/06 20:15:19 | 000,041,184 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2012/03/07 12:33:41 | 000,524,288 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2012/03/04 19:07:23 | 000,057,344 | —- | M] () – C:\WINDOWS\System32\config\security.sav
[2012/03/07 12:33:41 | 054,263,808 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2012/03/07 12:33:41 | 009,175,040 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2012/03/07 18:09:49 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/13 02:40:13 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/12/13 02:40:13 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/12/25 10:40:56 | 001,918,464 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner\Desktop\aswMBR.exe
[2011/07/16 23:21:04 | 000,302,592 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gmer.exe
[2012/03/10 10:02:43 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/05/10 17:50:42 | 490,813,152 | —- | M] (Intuit, Inc. ) – C:\Documents and Settings\Owner\Desktop\QuickBooksPro2010.exe
[2012/03/02 10:40:38 | 002,062,896 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoRebootWithLoggedOnUsers" = 1
"RebootRelaunchTimeoutEnabled" = 1
"RebootRelaunchTimeout" = 1440

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-10-28 07:00:51

========== Alternate Data Streams ==========

@Alternate Data Stream - 157 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84

< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
Thanks Jeff! Here's the aswMBR report: aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-10-30 09:47:12 —————————– 09:47:12.812 OS Version: Windows 5.1.2600 Service Pack 3 09:47:12.812 Number of processors: 4 586 0x502 09:47:12.812 ComputerName: STEVE UserName: Owner 09:47:13.796 Initialize success 09:47:13.875 AVAST engine defs: 12103000 09:47:17.343 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e 09:47:17.343 Disk 0 Vendor: WDC_WD6400AACS-00D6B1 01.01A01 Size: 610480MB BusType: 3 09:47:17.359 Disk 0 MBR read successfully 09:47:17.359 Disk 0 MBR scan 09:47:17.375 Disk 0 Windows XP default MBR code 09:47:17.375 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 300002 MB offset 63 09:47:17.390 Disk 0 Partition - 00 0F Extended LBA 310467 MB offset 614405925 09:47:17.406 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 310467 MB offset 614405988 09:47:17.421 Disk 0 scanning sectors +1250242560 09:47:17.484 Disk 0 scanning C:\WINDOWS\system32\drivers 09:47:23.828 Service scanning 09:47:33.625 Modules scanning 09:47:36.500 Disk 0 trace - called modules: 09:47:36.500 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 09:47:36.500 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8adb3ab8] 09:47:36.500 3 CLASSPNP.SYS[b8108fd7] -> nt!IofCallDriver -> \Device\0000007c[0x8ad62250] 09:47:36.500 5 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x8ad61d98] 09:47:36.968 AVAST engine scan C:\WINDOWS 09:47:53.359 AVAST engine scan C:\WINDOWS\system32 09:49:57.953 AVAST engine scan C:\WINDOWS\system32\drivers 09:50:12.703 AVAST engine scan C:\Documents and Settings\Owner 10:05:14.750 AVAST engine scan C:\Documents and Settings\All Users 10:08:20.937 Scan finished successfully 10:21:16.875 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\My Documents\Downloads\MBR.dat" 10:21:16.890 The log file has been saved successfully to "C:\Documents and Settings\Owner\My Documents\Downloads\aswMBR.txt"
Hi,

Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
    IE - HKLM\..\SearchScopes\{08695E7C-3FF8-408F-89E5-CDCE161D6692}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
    IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_…e=tb50winampie7
    IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
    IE - HKCU\..\SearchScopes,DefaultScope = {08695E7C-3FF8-408F-89E5-CDCE161D6692}
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
    IE - HKCU\..\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}: "URL" = http://search.alot.com/web?q={searchTerms}…n=1.1.3001.0(
    IE - HKCU\..\SearchScopes\{BDD10262-D0F4-4FAB-B402-A433F6E86C5C}: "URL" = http://websearch.ask.com/redirect?client=i…16-86D71B1F03FE
    IE - HKCU\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_…e=tb50winampie7
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*
    [2010/01/30 13:17:14 | 000,000,000 | —D | M] (PHPNukeEN Toolbar) – C:\Program Files\Mozilla Firefox\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}
    O2 - BHO: (RebateRobot BHO) - {66616350-A70C-4FF5-912E-A92B8076F6F7} - C:\Program Files\RebateRobot\RebateRobot.dll File not found
    O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
    [2012/10/14 16:24:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\blekko toolbars
    [2012/10/14 15:34:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\OpenCandy
    [2012/10/27 09:26:23 | 000,217,088 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2012/03/22 16:28:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ask
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [emptytemp]
    [resethosts]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered. There will be a log created when it completes that I will need in your next reply. Reboot when it is done.
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-

AdwCleaner

Please download AdwCleaner by Xplode onto your desktop.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search.
  • A logfile will automatically open after the scan has finished.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[R1].txt as well.
———-
Yes! It's been crazy since the storm hit here in PA,

Here's the log for otl Run Fix (I'm doing the next two steps now and will post asap!)

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{08695E7C-3FF8-408F-89E5-CDCE161D6692}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08695E7C-3FF8-408F-89E5-CDCE161D6692}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ deleted successfully.
C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll moved successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A531D99C-5A22-449b-83DA-872725C6D0ED}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BDD10262-D0F4-4FAB-B402-A433F6E86C5C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDD10262-D0F4-4FAB-B402-A433F6E86C5C}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}\ not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
C:\Program Files\Mozilla Firefox\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}\searchplugin folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}\META-INF folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}\lib folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}\defaults folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}\components folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}\chrome folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813} folder moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{66616350-A70C-4FF5-912E-A92B8076F6F7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66616350-A70C-4FF5-912E-A92B8076F6F7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found.
File C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found.
File C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}\ not found.
File C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll not found.
C:\Documents and Settings\All Users\Application Data\blekko toolbars folder moved successfully.
C:\Documents and Settings\Owner\Application Data\OpenCandy\62431F87A49847939C7FEAA1E75B2E65 folder moved successfully.
C:\Documents and Settings\Owner\Application Data\OpenCandy\37438270988C4B9C9598AA0BF24D1C65 folder moved successfully.
C:\Documents and Settings\Owner\Application Data\OpenCandy folder moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
C:\Documents and Settings\All Users\Application Data\Ask\APN-Stub folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Ask folder moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Owner\My Documents\Downloads\cmd.bat deleted successfully.
C:\Documents and Settings\Owner\My Documents\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Custom Settings

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Owner
->Temp folder emptied: 2096168 bytes
->Temporary Internet Files folder emptied: 32969 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 6818185 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 607 bytes

User: QBDataServiceUser17
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: QBDataServiceUser20
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 778752 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 32768 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 9.00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.69.0 log created on 11022012_113344

Files\Folders moved on Reboot…
File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\hlktmp scheduled to be moved on reboot.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
OTL logfile created on: 11/2/2012 11:48:32 AM - Run 6
OTL by OldTimer - Version 3.2.36.2 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.46 Gb Available Physical Memory | 75.78% Memory free
5.09 Gb Paging File | 4.31 Gb Available in Paging File | 84.69% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 292.97 Gb Total Space | 111.34 Gb Free Space | 38.00% Space Free | Partition Type: NTFS
Drive D: | 303.19 Gb Total Space | 188.71 Gb Free Space | 62.24% Space Free | Partition Type: NTFS

Computer Name: STEVE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Download Manager\DownloadManager.exe (DownloadManager)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
PRC - C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe (NVIDIA)
PRC - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
PRC - C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\hasplms.exe (Aladdin Knowledge Systems Ltd.)
PRC - C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\TaskSwitch.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM58.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM56.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM54.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM52.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM61.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM5F.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM5D.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM5B.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM50.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM4E.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM4C.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM4A.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM48.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM46.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM44.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM42.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM40.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM3E.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM3C.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM3A.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM38.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM36.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM34.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM31.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM2F.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM2D.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM2B.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM29.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM25.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\YTMP7MC8AA\TAA27.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM21.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM23.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM1D.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM1B.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM17.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM19.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM1F.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEMF.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEMD.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEMB.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM15.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM13.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM9.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM11.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM3.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM7.tmp ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Temp\XTMP1MC3VE\DEM5.tmp ()
MOD - C:\Program Files\AVAST Software\Avast\defs\12110200\algo.dll ()
MOD - C:\Program Files\Google\Chrome\Application\22.0.1229.94\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files\Google\Chrome\Application\22.0.1229.94\pdf.dll ()
MOD - C:\Program Files\Google\Chrome\Application\22.0.1229.94\avutil-51.dll ()
MOD - C:\Program Files\Google\Chrome\Application\22.0.1229.94\avformat-54.dll ()
MOD - C:\Program Files\Google\Chrome\Application\22.0.1229.94\avcodec-54.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\dbc413807cb7360b3e26ef3ca1d54f9a\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b84bb74d7724e147a642a1d5358feb7\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\Program Files\ManyCam\Bin\cximagecrt.dll ()
MOD - C:\Program Files\ManyCam\Bin\CrashRpt.dll ()
MOD - C:\WINDOWS\assembly\GAC\Interop.SHDocVw\1.1.0.0__4b827ebe229d539f\Interop.SHDocVw.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\ManyCam\Bin\opencv_video220.dll ()
MOD - C:\Program Files\ManyCam\Bin\opencv_objdetect220.dll ()
MOD - C:\Program Files\ManyCam\Bin\opencv_highgui220.dll ()
MOD - C:\Program Files\ManyCam\Bin\opencv_imgproc220.dll ()
MOD - C:\Program Files\ManyCam\Bin\opencv_core220.dll ()
MOD - C:\Program Files\Yahoo!\Messenger\yui.dll ()
MOD - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
MOD - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\WINDOWS\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll ()
MOD - C:\WINDOWS\system32\qedit.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\TaskSwitch.exe ()


========== Win32 Services (SafeList) ==========

SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (MotoHelper) – C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (UpdateCenterService) – C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe (NVIDIA)
SRV - (nTuneService) – C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
SRV - (QuickBooksDB20) – C:\Program Files\Intuit\QuickBooks 2007\QBDBMgrN.exe (Intuit, Inc.)
SRV - (QuickBooksDB17) – C:\Program Files\Intuit\QuickBooks 2007\QBDBMgrN.exe (Intuit, Inc.)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
SRV - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Adobe Version Cue CS4) – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe (Adobe Systems Incorporated)
SRV - (hasplms) – C:\WINDOWS\System32\hasplms.exe (Aladdin Knowledge Systems Ltd.)
SRV - (UPHClean) – C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (TFSysMon) – File not found
DRV - (TfNetMon) – File not found
DRV - (TfFsMon) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (esgiguard) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – File not found
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (AswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (mcaudrv_simple) – C:\WINDOWS\system32\drivers\mcaudrv.sys (ManyCam LLC)
DRV - (ManyCam) – C:\WINDOWS\system32\drivers\mcvidrv.sys (ManyCam LLC)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (motccgp) – C:\WINDOWS\system32\drivers\motccgp.sys (Motorola)
DRV - (motmodem) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (Motousbnet) – C:\WINDOWS\system32\drivers\Motousbnet.sys (Motorola)
DRV - (motusbdevice) – C:\WINDOWS\system32\drivers\motusbdevice.sys (Motorola Inc)
DRV - (DumpDrv) – C:\WINDOWS\System32\drivers\dumpdrv.sys (Microsoft Corporation)
DRV - (nvoclock) – C:\WINDOWS\system32\drivers\nvoclock.sys (NVIDIA Corp.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (LSI Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (motccgpfl) – C:\WINDOWS\system32\drivers\motccgpfl.sys (Motorola)
DRV - (BTCFilterService) – C:\WINDOWS\system32\drivers\motfilt.sys (Motorola Inc)
DRV - (KMWDFILTER) – C:\WINDOWS\system32\drivers\KMWDFILTER.sys (Windows ® Codename Longhorn DDK provider)
DRV - (nvsmu) – C:\WINDOWS\system32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (MotoSwitchService) – C:\WINDOWS\system32\drivers\motswch.sys (Motorola)
DRV - (AmdPPM) – C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (aksfridge) – C:\WINDOWS\system32\drivers\aksfridge.sys (Aladdin Knowledge Systems Ltd.)
DRV - (Hardlock) – C:\WINDOWS\system32\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.)
DRV - (MTDVC2) – C:\WINDOWS\system32\drivers\mtdv2ku2.sys (Matsushita Electric Industrial Co., Ltd.)
DRV - (MTDVC2_ENUM) – C:\WINDOWS\system32\drivers\mtdv2ks2.sys (Matsushita Electric Industrial Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {08695E7C-3FF8-408F-89E5-CDCE161D6692}


IE - HKU\.DEFAULT\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\..\SearchScopes,DefaultScope = {08695E7C-3FF8-408F-89E5-CDCE161D6692}
IE - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\..\SearchScopes\{08695E7C-3FF8-408F-89E5-CDCE161D6692}: "URL" = http://www.google.com/search?q={searchTerm…1I7FDUM_enUS474
IE - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://blekko.com/ws/?source=6a1885c1&…q={searchTerms}
IE - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={4A3504E…mp;d=2012-04-06 15:09:33&v=10.2.0.3&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\..\SearchScopes\{9B97950D-482C-1D79-568F-FC7B9D40C785}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?p={searchTerms}
IE - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;192.168.*.*

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)


[2012/03/10 10:48:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/06 17:37:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/12/01 21:12:43 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/25 10:32:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/11/12 19:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime Alternative\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - Extension: avast! WebRep = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0\

O1 HOSTS File: ([2012/11/02 11:33:57 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O2 - BHO: (Fast Search) - {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files\Surf Canyon\surfcanyon.dll (Surf Canyon Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe_ID0ENQBO] C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /installquiet File not found
O4 - HKLM..\Run: [QuickBooksDB20] C:\Program Files\Intuit\QuickBooks 2007\QBDBMgrN.exe (Intuit, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime Alternative\qttask.exe (Apple Inc.)
O4 - HKU\S-1-5-21-1644491937-2147235713-725345543-1003..\Run: [DownloadManager] C:\Program Files\Download Manager\DownloadManager.exe (DownloadManager)
O4 - HKU\S-1-5-21-1644491937-2147235713-725345543-1003..\Run: [ManyCam] C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
O4 - HKU\S-1-5-21-1644491937-2147235713-725345543-1003..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKU\S-1-5-21-1644491937-2147235713-725345543-1003..\Run: [Spotify Web Helper] C:\Program Files\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-1644491937-2147235713-725345543-1003..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - HKU\S-1-5-18..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MaxRecentDocs = 18
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: verbosestatus = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1644491937-2147235713-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Owner\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} file:///C:/Program%20Files/Land%20Desktop%20R2/AcDcToday.ocx (AcDcToday Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} file:///C:/Program%20Files/Land%20Desktop%20R2/InstFred.ocx (InstaFred Control)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} file:///C:/Program%20Files/Land%20Desktop%20R2/AcPreview.ocx (AcPreview Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{57D9B49F-9F74-4830-BDE9-39538E21FEBA}: DhcpNameServer = 75.75.76.76 75.75.75.75 192.168.1.1
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files\Intuit\QuickBooks 2007\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/12/14 16:34:49 | 000,000,000 | —D | M] - C:\Autodesk – [ NTFS ]
O32 - AutoRun File - [2011/02/22 09:58:33 | 000,000,047 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKU\S-1-5-21-1644491937-2147235713-725345543-1003..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/11/02 11:33:56 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/11/02 11:32:16 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012/11/02 11:32:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2012/10/31 21:06:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Mozilla
[2012/10/28 13:07:39 | 000,000,000 | —D | C] – C:\ComboFix
[2012/10/21 10:19:10 | 000,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2012/10/17 13:20:23 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012/10/17 13:19:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2012/10/14 15:35:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\FrostWire
[2012/10/14 15:35:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\.frostwire5
[2012/10/14 15:35:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\DVDVideoSoftIEHelpers

========== Files - Modified Within 30 Days ==========

[2012/11/02 11:42:39 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{D34A4223-3F9E-489B-8675-157936D04B47}.job
[2012/11/02 11:42:19 | 000,444,794 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/11/02 11:42:19 | 000,072,544 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/11/02 11:41:10 | 000,272,291 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2012/11/02 11:37:25 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/02 11:35:10 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/11/02 11:35:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/11/02 11:35:02 | 3488,858,112 | -HS- | M] () – C:\hiberfil.sys
[2012/11/02 11:33:57 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2012/11/02 11:33:50 | 000,000,370 | —- | M] () – C:\WINDOWS\tasks\MotoHelper Initial Update.job
[2012/11/02 11:32:19 | 000,000,777 | —- | M] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/11/02 11:32:16 | 000,000,621 | —- | M] () – C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk
[2012/11/02 11:32:16 | 000,000,602 | —- | M] () – C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2012/11/02 11:32:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/02 11:06:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-2147235713-725345543-1003UA.job
[2012/11/02 10:23:01 | 000,000,354 | —- | M] () – C:\WINDOWS\tasks\MotoHelper Routing.job
[2012/11/01 13:06:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-2147235713-725345543-1003Core.job
[2012/10/28 19:16:00 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/10/27 19:59:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/10/27 10:09:58 | 002,384,016 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/10/26 14:42:54 | 000,775,834 | —- | M] () – C:\Documents and Settings\Owner\My Documents\PRLOGO.psd
[2012/10/26 10:23:01 | 000,000,370 | —- | M] () – C:\WINDOWS\tasks\MotoHelper Update.job
[2012/10/26 10:23:01 | 000,000,358 | —- | M] () – C:\WINDOWS\tasks\MotoHelper MUM.job
[2012/10/25 11:38:28 | 001,864,967 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Hummel_Cost_Sheet.pdf
[2012/10/14 15:34:53 | 000,000,902 | —- | M] () – C:\Documents and Settings\Owner\Desktop\DVDVideoSoft Free Studio.lnk
[2012/10/14 15:34:52 | 000,001,061 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Free YouTube to MP3 Converter.lnk
[2012/10/11 05:34:21 | 000,001,823 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/10/10 03:00:59 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/10/08 22:56:46 | 004,089,643 | —- | M] () – C:\Documents and Settings\Owner\My Documents\seatles.psd

========== Files Created - No Company Name ==========

[2012/11/02 11:33:50 | 000,000,370 | —- | C] () – C:\WINDOWS\tasks\MotoHelper Initial Update.job
[2012/11/02 11:32:19 | 000,000,777 | —- | C] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/11/02 11:32:16 | 000,000,621 | —- | C] () – C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk
[2012/11/02 11:32:16 | 000,000,602 | —- | C] () – C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2012/10/27 10:15:04 | 3488,858,112 | -HS- | C] () – C:\hiberfil.sys
[2012/10/26 14:42:52 | 000,775,834 | —- | C] () – C:\Documents and Settings\Owner\My Documents\PRLOGO.psd
[2012/10/25 11:38:28 | 001,864,967 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Hummel_Cost_Sheet.pdf
[2012/10/14 15:34:53 | 000,000,902 | —- | C] () – C:\Documents and Settings\Owner\Desktop\DVDVideoSoft Free Studio.lnk
[2012/10/14 15:34:52 | 000,001,061 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Free YouTube to MP3 Converter.lnk
[2012/10/08 22:56:42 | 004,089,643 | —- | C] () – C:\Documents and Settings\Owner\My Documents\seatles.psd
[2012/10/07 13:01:51 | 000,000,978 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-2147235713-725345543-1003UA.job
[2012/10/07 13:01:51 | 000,000,926 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-2147235713-725345543-1003Core.job
[2012/03/08 17:25:50 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/03/08 17:25:50 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/03/08 17:25:50 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/03/08 17:25:50 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/03/08 17:25:50 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/03/07 18:24:22 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/03/04 11:06:24 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2012/02/10 15:59:00 | 000,045,056 | —- | C] () – C:\WINDOWS\scluins1.exe
[2012/02/10 15:59:00 | 000,036,864 | —- | C] () – C:\WINDOWS\smon03.exe
[2011/12/26 13:47:28 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/11/27 18:42:16 | 000,217,088 | —- | C] () – C:\WINDOWS\System32\qtmlClient.dll
[2011/07/06 19:59:52 | 000,000,127 | —- | C] () – C:\WINDOWS\smr.INI
[2011/06/24 15:16:27 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll0238.old

========== Alternate Data Streams ==========

@Alternate Data Stream - 157 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84

< End of report >
# AdwCleaner v2.006 - Logfile created 11/02/2012 at 11:54:55 # Updated 30/10/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Owner - STEVE # Boot Mode : Normal # Running from : C:\Documents and Settings\Owner\My Documents\Downloads\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Documents and Settings\Owner\Desktop\Software Folder Found : C:\Documents and Settings\Owner\Local Settings\Application Data\APN Folder Found : C:\Documents and Settings\Owner\Local Settings\Application Data\DVDVideoSoftTB Folder Found : C:\Program Files\DVDVideoSoftTB Folder Found : C:\Program Files\Surf Canyon ***** [Registry] ***** Key Found : HKCU\Software\AppDataLow\Software Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\ConduitSearchScopes Key Found : HKCU\Software\Crossrider Key Found : HKCU\Software\DVDVideoSoftTB Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5AB7104A-B71F-49AD-9154-F7F8806AE848} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D360201-FFF5-11D1-8D03-00A0C959BC0A} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{57BCA5FA-5DBB-45A2-B558-1755C3F6253B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5AB7104A-B71F-49AD-9154-F7F8806AE848} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKCU\Software\Surf Canyon Key Found : HKLM\SOFTWARE\Classes\AppID\{A3514F71-E63F-440B-8076-14226E21B2BF} Key Found : HKLM\SOFTWARE\Classes\AppID\surfcanyon.DLL Key Found : HKLM\SOFTWARE\Classes\CLSID\{2D360201-FFF5-11D1-8D03-00A0C959BC0A} Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{5AB7104A-B71F-49AD-9154-F7F8806AE848} Key Found : HKLM\SOFTWARE\Classes\CLSID\{AAFFE112-08AB-4B91-8428-C008A22864FB} Key Found : HKLM\SOFTWARE\Classes\CLSID\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68} Key Found : HKLM\SOFTWARE\Classes\CLSID\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A} Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0002258.BHO Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0002258.BHO Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066226658} Key Found : HKLM\SOFTWARE\Classes\Interface\{68AD96A1-2A28-4841-ABD0-F5AA45F008C9} Key Found : HKLM\SOFTWARE\Classes\Interface\{77777777-7777-7777-7777-770077227758} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : HKLM\SOFTWARE\Classes\surfcanyon.BhoSite Key Found : HKLM\SOFTWARE\Classes\surfcanyon.BhoSite.1 Key Found : HKLM\SOFTWARE\Classes\surfcanyon.ShowSettings Key Found : HKLM\SOFTWARE\Classes\surfcanyon.ShowSettings.1 Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2086743 Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2269050 Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2704262 Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{BA3105E9-5DE6-4A1E-A819-6F5046AB67F5} Key Found : HKLM\Software\DVDVideoSoftTB Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65BCD620-07DD-012F-819F-073CF1B8F7C6} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AE1A3196-2A88-4225-A6A4-5D0008194C6C} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AFF9B4B8-FA52-46AC-94D0-8AC0F4474BF4} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DVDVideoSoftTB Toolbar Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\I Want This Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\PriceGong Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Surf Canyon Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5AB7104A-B71F-49AD-9154-F7F8806AE848} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Surf Canyon Key Found : HKU\S-1-5-21-1644491937-2147235713-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} Key Found : HKU\S-1-5-21-1644491937-2147235713-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Registry is clean. -\\ Google Chrome v [Unable to get version] File : C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences Found [l.8] : homepage = "hxxp://blekko.com/ws/?source=6a1885c1&toolbarid=blekkotb_002&u=C02117131EE751E7DEF8FA507B1F5E2B&tbp=homepage", Found [l.12] : urls_to_restore_on_startup = [ "hxxp://blekko.com/ws/?source=6a1885c1&toolbarid=blekkotb_002&u=C02117131EE751E7DEF8FA507B1F5E2B&tbp=homepage", "hxxp://www.google.com/" ] Found [l.1440] : homepage = "hxxp://blekko.com/ws/?source=6a1885c1&toolbarid=blekkotb_002&u=C02117131EE751E7DEF8FA507B1F5E2B&tbp=homepage", Found [l.1742] : urls_to_restore_on_startup = [ "hxxp://blekko.com/ws/?source=6a1885c1&toolbarid=blekkotb_002&u=C02117131EE751E7DEF8FA507B1F5E2B&tbp=homepage", "hxxp://www.google.com/" ] ************************* AdwCleaner[R1].txt - [7440 octets] - [02/11/2012 11:54:55] ########## EOF - C:\AdwCleaner[R1].txt - [7500 octets] ##########
AdwCleaner
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

Post the new log made by AdwCleaner and let me know how your system is running. :)
Tried Google Chrome three times and Blekko did not come up at all! # AdwCleaner v2.006 - Logfile created 11/02/2012 at 14:48:10 # Updated 30/10/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Owner - STEVE # Boot Mode : Normal # Running from : C:\Documents and Settings\Owner\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Documents and Settings\Owner\Desktop\Software Folder Deleted : C:\Documents and Settings\Owner\Local Settings\Application Data\APN Folder Deleted : C:\Documents and Settings\Owner\Local Settings\Application Data\DVDVideoSoftTB Folder Deleted : C:\Program Files\DVDVideoSoftTB Folder Deleted : C:\Program Files\Surf Canyon ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software Key Deleted : HKCU\Software\ConduitSearchScopes Key Deleted : HKCU\Software\Crossrider Key Deleted : HKCU\Software\DVDVideoSoftTB Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5AB7104A-B71F-49AD-9154-F7F8806AE848} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D360201-FFF5-11D1-8D03-00A0C959BC0A} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{57BCA5FA-5DBB-45A2-B558-1755C3F6253B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5AB7104A-B71F-49AD-9154-F7F8806AE848} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKCU\Software\Surf Canyon Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A3514F71-E63F-440B-8076-14226E21B2BF} Key Deleted : HKLM\SOFTWARE\Classes\AppID\surfcanyon.DLL Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2D360201-FFF5-11D1-8D03-00A0C959BC0A} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5AB7104A-B71F-49AD-9154-F7F8806AE848} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AAFFE112-08AB-4B91-8428-C008A22864FB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A} Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0002258.BHO Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066226658} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{68AD96A1-2A28-4841-ABD0-F5AA45F008C9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{77777777-7777-7777-7777-770077227758} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\surfcanyon.BhoSite Key Deleted : HKLM\SOFTWARE\Classes\surfcanyon.BhoSite.1 Key Deleted : HKLM\SOFTWARE\Classes\surfcanyon.ShowSettings Key Deleted : HKLM\SOFTWARE\Classes\surfcanyon.ShowSettings.1 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2086743 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2269050 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2704262 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{BA3105E9-5DE6-4A1E-A819-6F5046AB67F5} Key Deleted : HKLM\Software\DVDVideoSoftTB Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65BCD620-07DD-012F-819F-073CF1B8F7C6} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AE1A3196-2A88-4225-A6A4-5D0008194C6C} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AFF9B4B8-FA52-46AC-94D0-8AC0F4474BF4} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DVDVideoSoftTB Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\I Want This Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\PriceGong Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Surf Canyon Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5AB7104A-B71F-49AD-9154-F7F8806AE848} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Surf Canyon Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Registry is clean. -\\ Google Chrome v [Unable to get version] File : C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences Deleted [l.8] : homepage = "hxxp://blekko.com/ws/?source=6a1885c1&toolbarid=blekkotb_002&u=C02117131EE751E7DEF8FA507B1F5E2B&tbp=homepage", Deleted [l.12] : urls_to_restore_on_startup = [ "hxxp://blekko.com/ws/?source=6a1885c1&toolbarid=blekkotb_002&u=C02117131EE751E7DEF8FA507B1F5E2B&tbp=homepage", "hxxp://www.google.com/" ] Deleted [l.1440] : homepage = "hxxp://blekko.com/ws/?source=6a1885c1&toolbarid=blekkotb_002&u=C02117131EE751E7DEF8FA507B1F5E2B&tbp=homepage", Deleted [l.1878] : urls_to_restore_on_startup = [ "hxxp://blekko.com/ws/?source=6a1885c1&toolbarid=blekkotb_002&u=C02117131EE751E7DEF8FA507B1F5E2B&tbp=homepage", "hxxp://www.google.com/" ] ************************* AdwCleaner[R1].txt - [7569 octets] - [02/11/2012 11:54:55] AdwCleaner[S2].txt - [7007 octets] - [02/11/2012 14:48:10] ########## EOF - C:\AdwCleaner[S2].txt - [7067 octets] ##########
Good to hear! :)

Please open OTL.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the Extra Registry section change it to All
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open 2 notepad windows, OTL.Txt and Extra.txt. Please post the Extra.txt.
———-
OTL Extras logfile created on: 11/2/2012 3:32:00 PM - Run 7
OTL by OldTimer - Version 3.2.36.2 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.63 Gb Available Physical Memory | 80.97% Memory free
5.09 Gb Paging File | 4.49 Gb Available in Paging File | 88.16% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 292.97 Gb Total Space | 108.04 Gb Free Space | 36.88% Space Free | Partition Type: NTFS
Drive D: | 303.19 Gb Total Space | 188.71 Gb Free Space | 62.24% Space Free | Partition Type: NTFS
Drive J: | 3.73 Gb Total Space | 1.92 Gb Free Space | 51.61% Space Free | Partition Type: FAT32

Computer Name: STEVE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.bat [@ = batfile] – "%1" %*
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] – "%1" %*
.com [@ = ComFile] – "%1" %*
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.exe [@ = exefile] – "%1" %*
.hlp [@ = hlpfile] – C:\WINDOWS\System32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – "%1" %*
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
.inf [@ = inffile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
.js [@ = JSFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] – "%1" %*
.reg [@ = regfile] – C:\WINDOWS\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] – "%1" /S
.txt [@ = txtfile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
.scr [@ = AutoCADScriptFile] – C:\WINDOWS\System32\notepad.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] – "%1" %*
batfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] – "%SYSTEMROOT%\hh.exe" %1 (Microsoft Corporation)
cmdfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] – "%1" %*
cmdfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – winhlp32.exe %1 (Microsoft Corporation)
hlpfile [open] – %SystemRoot%\System32\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] – "%1" %*
htmlfile – "C:\PROGRA~1\MICROS~2\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\PROGRA~1\MICROS~2\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
InternetShortcut [print] – "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
regfile [open] – regedit.exe "%1" (Microsoft Corporation)
regfile [merge] – Reg Error: Key error.
regfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
txtfile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] – %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
vbsfile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wsffile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
wsffile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
wsffile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wshfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirstRunDisabled" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
"3703:TCP" = 3703:TCP:*:Enabled:Adobe Version Cue CS4 Server
"3704:TCP" = 3704:TCP:*:Enabled:Adobe Version Cue CS4 Server
"51000:TCP" = 51000:TCP:*:Enabled:Adobe Version Cue CS4 Server
"51001:TCP" = 51001:TCP:*:Enabled:Adobe Version Cue CS4 Server
"1947:TCP" = 1947:TCP:*:Enabled:HASP SRM
"1947:UDP" = 1947:UDP:*:Enabled:HASP SRM
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 – (Adobe Systems Incorporated)
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe" = C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:*:Enabled:Adobe Version Cue CS4 Server – (Adobe Systems Incorporated)
"C:\Program Files\Intuit\QuickBooks 2007\QBDBMgrN.exe" = C:\Program Files\Intuit\QuickBooks 2007\QBDBMgrN.exe:*:Enabled:QuickBooks 2007 Data Manager – (Intuit, Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{06A9E630-DBA6-4D92-9DE7-A235AA6496C7}" = QuickBooks
"{0700E22B-A422-40A5-BD20-04BF618CA0F9}" = QuickBooks Pro 2010
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{14F70205-1940-4000-88C7-BE799A6B2CAD}" = Adobe Soundbooth CS4
"{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server
"{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
"{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{28F58CDE-6241-4B11-8232-6A5D4FB06E8B}" = PACE System Files
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models
"{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{314AD191-596F-40C0-ACED-3AD78C9649F1}_is1" = WMA MP3 Converter v4.3 build 1489
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35AF2D74-7048-876E-1869-68B6D635F446}" = Chief Architect X2
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{43D16DA8-BF42-3C62-89D3-3AD47829DC2E}" = Google Talk Plugin
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
"{4ED7D297-58F7-45C3-A9BA-A7CD6FA0D373}_is1" = SureThing CD Labeler LightScribe Trial 5
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5783F2D7-0008-0409-0000-0060B0CE6BBA}" = AutoCAD Land Development Desktop 2i
"{5783F2D7-8001-0409-0002-0060B0CE6BBA}" = AutoCAD 2010 - English
"{5783F2D7-8001-0409-1002-0060B0CE6BBA}" = AutoCAD 2010 Language Pack - English
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{5DF68560-292A-11D5-99D1-00010256D40E}" = DV Studio3
"{5EAD5443-7194-46CC-A055-428E6ABB1BAF}" = Adobe Encore CS4
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{65A92AAA-3D05-4C94-9F70-731C05E60C16}" = NVIDIA System Update
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}" = Safari
"{6F3D2F66-F050-45E3-BEB1-6523FE6D6690}" = MotoHelper MergeModules
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7406DF60-016D-476B-A2C7-55D997592047}" = Adobe OnLocation CS4
"{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA Performance
"{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
"{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E10A7CC-B4B4-4BF0-A75E-9F960D58AAC4}_is1" = RebateRobot for Online Shopping version 1.0.2
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{91170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{91208A47-5D08-4C79-986F-1931940F51BB}" = QuickBooks Product Listing Service
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A6EC82A0-1414-475D-8AFD-469089F3080D}" = Adobe Contribute CS4
"{A7050037-F0EA-4BAB-BCD5-FC05507D6147}" = Alt-Tab Task Switcher Powertoy for Windows XP
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-0000-7760-000000000002}" = Adobe Acrobat 7.0 Professional
"{AEB9948B-4FF2-47C9-990E-47014492A0FE}" = MSXML 6.0 Parser
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 Service Pack 1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 Service Pack 1
"{D1F94690-C59F-4BF1-A9C5-005DCCE8364D}_is1" = X2X Free MP3 Converter 3.1
"{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup
"{E9CFBE78-ED91-4FCF-9E6F-210E477E527D}" = NVIDIA System Monitor
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2
"{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
"{EF5120CC-BA3E-421E-9895-1B906507DD99}_is1" = Style Jukebox (Beta)
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F59A9E08-A6A4-4ACF-91F2-D0344956C30B}" = iTunes
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FA8BFB25-BF48-4F8B-8859-B30810745190}" = LightScribe System Software
"{FB29B583-945C-4094-BB4B-3A405574C560}" = Motorola Mobile Drivers Installation 5.0.0
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF77941A-2BFA-4A18-BE2E-69B9498E4D55}" = User Profile Hive Cleanup Service
"7-Zip" = 7-Zip 4.65
"Adobe Acrobat 7.0 Professional" = Adobe Acrobat 7.1.0 Professional
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_d2f336b2c5feeb945c28b7a0a45170f" = Adobe Creative Suite 4 Master Collection
"AMA" = AutoCAD 2000i Migration Assistance
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.12
"AnswerWorks" = AnswerWorks Runtime
"Audio MP3 Sound Recorder" = Audio MP3 Sound Recorder
"AutoCAD 2010 - English" = AutoCAD 2010 - English
"avast" = avast! Free Antivirus
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS Video Editor 4_is1" = AVS Video Editor 4
"AVS Video Recorder_is1" = AVS Video Recorder 2.4
"AVS YouTube Uploader 2.1_is1" = AVS YouTube Uploader version 2.1
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"CmdOpen Shell Extension" = Open Command Prompt Shell Extension (x86-32)
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Debut" = Debut Video Capture Software
"Download Manager" = Download Manager
"DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5_is1" = DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.2.3.2
"Easy DV to DVD" = Easy DV to DVD
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"ERUNT_is1" = ERUNT 1.1j
"Free Video to MP3 Converter_is1" = Free Video to MP3 Converter version 5.0.2.1125
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.33.1005
"Google Chrome" = Google Chrome
"HashCheck Shell Extension" = HashCheck Shell Extension (x86-32)
"HP-Color LaserJet 1600" = Color LaserJet 1600
"ie8" = Windows Internet Explorer 8
"InstallShield_{65A92AAA-3D05-4C94-9F70-731C05E60C16}" = NVIDIA System Update
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA Performance
"InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"InstallShield_{E9CFBE78-ED91-4FCF-9E6F-210E477E527D}" = NVIDIA System Monitor
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.2.0
"LSI Soft Modem" = LSI PCI-SV92EX Soft Modem
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"ManyCam" = ManyCam 3.0.53 (remove only)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft Silverlight" = Microsoft Silverlight
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Microsoft Visual Studio 2005 Tools for Office Runtime
"MotoHelper" = MotoHelper 2.0.24 Driver 4.7.1
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"PROPLUS" = Microsoft Office Professional Plus 2007
"QuicktimeAlt_is1" = QuickTime Alternative 3.0.0
"Replay Music4.40B" = Replay Music
"Sophocles" = Sophocles 2003 (Remove Only)
"Spotify" = Spotify
"Strategic Baseball Simulator 4.9.2" = Strategic Baseball Simulator 4.9.2
"Super Mp3 Recorder_is1" = Super Mp3 Recorder 2.5
"Unlocker" = Unlocker 1.8.7
"WAV to MP3 Encoder" = WAV to MP3 Encoder
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WinAVI Video Capture_is1" = WinAVI Video Capture 2.0
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Spotify" = Spotify

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/28/2012 12:54:29 PM | Computer Name = STEVE | Source = SQLANY 11.0 | ID = 1
Description =

Error - 10/28/2012 1:09:20 PM | Computer Name = STEVE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved

Error - 10/28/2012 1:09:20 PM | Computer Name = STEVE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 10/28/2012 1:09:20 PM | Computer Name = STEVE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 10/28/2012 1:14:06 PM | Computer Name = STEVE | Source = SQLANY 11.0 | ID = 1
Description =

Error - 10/28/2012 1:22:15 PM | Computer Name = STEVE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved

Error - 10/28/2012 1:27:20 PM | Computer Name = STEVE | Source = SQLANY 11.0 | ID = 1
Description =

Error - 10/30/2012 9:36:26 AM | Computer Name = STEVE | Source = SQLANY 11.0 | ID = 1
Description =

Error - 11/2/2012 11:36:04 AM | Computer Name = STEVE | Source = SQLANY 11.0 | ID = 1
Description =

Error - 11/2/2012 2:50:48 PM | Computer Name = STEVE | Source = SQLANY 11.0 | ID = 1
Description =

[ OSession Events ]
Error - 9/5/2011 1:37:20 PM | Computer Name = STEVE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 176
seconds with 60 seconds of active time. This session ended with a crash.

Error - 3/4/2012 5:02:11 PM | Computer Name = STEVE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 768
seconds with 60 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 11/2/2012 11:33:45 AM | Computer Name = STEVE | Source = Service Control Manager | ID = 7034
Description = The Performance Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 11/2/2012 11:33:46 AM | Computer Name = STEVE | Source = Service Control Manager | ID = 7034
Description = The QBCFMonitorService service terminated unexpectedly. It has done
this 1 time(s).

Error - 11/2/2012 11:33:46 AM | Computer Name = STEVE | Source = Service Control Manager | ID = 7034
Description = The Update Center Service service terminated unexpectedly. It has
done this 1 time(s).

Error - 11/2/2012 11:33:46 AM | Computer Name = STEVE | Source = Service Control Manager | ID = 7034
Description = The User Profile Hive Cleanup service terminated unexpectedly. It
has done this 1 time(s).

Error - 11/2/2012 11:33:46 AM | Computer Name = STEVE | Source = Service Control Manager | ID = 7034
Description = The Yahoo! Updater service terminated unexpectedly. It has done this
1 time(s).

Error - 11/2/2012 11:33:46 AM | Computer Name = STEVE | Source = Service Control Manager | ID = 7034
Description = The ForceWare Intelligent Application Manager (IAM) service terminated
unexpectedly. It has done this 1 time(s).

Error - 11/2/2012 11:33:46 AM | Computer Name = STEVE | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).

Error - 11/2/2012 11:33:46 AM | Computer Name = STEVE | Source = Service Control Manager | ID = 7034
Description = The ForceWare IP service service terminated unexpectedly. It has
done this 1 time(s).

Error - 11/2/2012 11:36:10 AM | Computer Name = STEVE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TFSysMon

Error - 11/2/2012 2:51:02 PM | Computer Name = STEVE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TFSysMon


< End of report >
Thanks.

I see that your Java software is out of date. Please go to Start >> Control Panel >> Programs and Features >> uninstall all versions of Java.

Now download and install the newest version from here >> http://java.com/en/download/index.jsp
————-

Clear Java Cache

See this page for instructions on how to clear java's cache.

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.
———-

Malwarebytes

Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-
Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Database version: v2012.11.03.04 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Owner :: STEVE [administrator] 11/3/2012 9:19:36 AM mbam-log-2012-11-03 (10-13-12).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 270715 Time elapsed: 8 minute(s), 24 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk (PUP.GamesPlayLab) -> No action taken. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
ESET log C:\Documents and Settings\Owner\My Documents\Downloads\iLividSetupV1 (1).exe Win32/Toolbar.SearchSuite application C:\Documents and Settings\Owner\My Documents\Downloads\iLividSetupV1 (2).exe Win32/Toolbar.SearchSuite application C:\Documents and Settings\Owner\My Documents\Downloads\iLividSetupV1.exe Win32/Toolbar.SearchSuite application C:\System Volume Information\_restore{E4A08339-023B-4921-BF2F-8AC9E414F373}\RP242\A0029114.exe a variant of Win32/InstallCore.D application

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI