This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Do I have anything else running?

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Windows XP machine has a ton of adwares running before and I removed a lot of them. I'm not certain if there is anything else that is hidden. Boot up time seems bogged down. Can anyone help?

—————

OTL logfile created on: 11/30/2012 11:16:43 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\YOUNG ONE\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.86 Mb Total Physical Memory | 481.32 Mb Available Physical Memory | 47.47% Memory free
2.38 Gb Paging File | 1.64 Gb Available in Paging File | 68.83% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Program Files
Drive C: | 145.00 Gb Total Space | 81.00 Gb Free Space | 55.86% Space Free | Partition Type: NTFS

Computer Name: JAMES-91746AC0C | User Name: YOUNG ONE | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\YOUNG ONE\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AOL\DataMask by AOL\pl.exe (AOL)
PRC - C:\Program Files\AOL\DataMask by AOL\ep.exe (AOL)
PRC - C:\Program Files\AOL\DataMask by AOL\epservice.exe (AOL)
PRC - C:\Program Files\AOL\DataMask by AOL\dps.exe (AOL)
PRC - C:\Documents and Settings\YOUNG ONE\Local Settings\Temp\TeamViewer\Version7\TeamViewer.exe (TeamViewer GmbH)
PRC - c:\Documents and Settings\YOUNG ONE\Local Settings\Temp\TeamViewer\Version7\TeamViewer_Desktop.exe (TeamViewer GmbH)
PRC - C:\Documents and Settings\YOUNG ONE\Local Settings\Temp\TeamViewer\Version7\tv_w32.exe (TeamViewer GmbH)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Google\Update\1.3.21.123\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
PRC - C:\Program Files\SentryBay\Update\SentryBayUpdate.exe (AOL)
PRC - C:\Program Files\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe (Symantec Corporation)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\WINXP\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\aol\1336533290\ee\aolsoftware.exe (AOL Inc.)
PRC - C:\WINXP\system32\mmc.exe (Microsoft Corporation)
PRC - C:\WINXP\explorer.exe (Microsoft Corporation)
PRC - C:\WINXP\system32\dfrgntfs.exe (Microsoft Corp. and Executive Software International, Inc.)
PRC - C:\WINXP\system32\HPZipm12.exe (HP)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\AOL\DataMask by AOL\libxmlsec.dll ()
MOD - C:\Program Files\AOL\DataMask by AOL\libxmlsec-mscrypto.dll ()
MOD - C:\Program Files\Evernote\Evernote\libtidy.dll ()
MOD - C:\Program Files\Evernote\Evernote\libxml2.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\AOL\DataMask by AOL\libxml2.dll ()
MOD - C:\WINXP\system32\msdmo.dll ()
MOD - C:\WINXP\system32\devenum.dll ()


========== Services (SafeList) ==========

SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (EntryProtect) – C:\Program Files\AOL\DataMask by AOL\epservice.exe (AOL)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\822\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (sbupdate) – C:\Program Files\SentryBay\Update\SentryBayUpdate.exe (AOL)
SRV - (Norton PC Checkup Application Launcher) – C:\Program Files\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
SRV - (mfevtp) – C:\WINXP\system32\mfevtps.exe (McAfee, Inc.)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\aol\acs\AOLacsd.exe (AOL LLC)
SRV - (Pml Driver HPZ12) – C:\WINXP\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mfeavfk01) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (SWDUMon) – C:\WINXP\system32\drivers\SWDUMon.sys ()
DRV - (epfilter) – C:\WINXP\system32\drivers\epfilter.sys (SentryBay)
DRV - (MBAMProtector) – C:\WINXP\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (ASCTRM) – C:\WINXP\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (mfehidk) – C:\WINXP\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\WINXP\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINXP\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINXP\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINXP\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINXP\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfendiskmp) – C:\WINXP\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – C:\WINXP\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINXP\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINXP\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (motccgpfl) – C:\WINXP\system32\drivers\motccgpfl.sys (Motorola)
DRV - (motccgp) – C:\WINXP\system32\drivers\motccgp.sys (Motorola)
DRV - (MPE) – C:\WINXP\system32\drivers\MPE.sys (Microsoft Corporation)
DRV - (motport) – C:\WINXP\system32\drivers\motport.sys (Motorola)
DRV - (motmodem) – C:\WINXP\system32\drivers\motmodem.sys (Motorola)
DRV - (emAudio) – C:\WINXP\system32\drivers\emAudio.sys (Pinnacle Systems GmbH)
DRV - (STHDA) – C:\WINXP\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (DCamUSBEMPIA) – C:\WINXP\system32\drivers\emDevice.sys (eMPIA Technology, Inc.)
DRV - (FiltUSBEMPIA) – C:\WINXP\system32\drivers\emFilter.sys (eMPIA Technology, Inc.)
DRV - (ScanUSBEMPIA) – C:\WINXP\system32\drivers\emScan.sys (eMPIA Technology, Inc.)
DRV - (MarvinBus) – C:\WINXP\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (bvrp_pci) – C:\WINXP\system32\drivers\bvrp_pci.sys ()
DRV - (HSFHWBS2) – C:\WINXP\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINXP\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINXP\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (wanatw) – C:\WINXP\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (OMCI) – C:\WINXP\system32\drivers\omci.sys (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.coupons.com/
IE - HKLM\..\URLSearchHook: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
IE - HKLM\..\SearchScopes,DefaultScope = {443789B7-F39C-4b5c-9287-DA72D38F4FE6}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…mrud=15-11-2012


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aol.com/?ncid=customie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/
IE - HKCU\..\URLSearchHook: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}…0000019d17406b1
IE - HKCU\..\SearchScopes\{40267B06-090D-4211-B671-4647C071C5C8}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…mrud=15-11-2012

IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://search.coupons.com/search.asp?p=df&…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: ich%40maltegoetz.de:1.4.3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINXP\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@update.sentrybay.com/SentryBay Update;version=8: C:\Program Files\SentryBay\Update\1.0.0.7621\npSentryBayOneClick8.dll (AOL)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/11/30 22:33:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AOL\DataMask by AOL\ffext [2012/11/14 15:42:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/28 07:52:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2012/11/24 05:44:16 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\YOUNG ONE\Application Data\Mozilla\Extensions
[2012/11/25 05:53:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\YOUNG ONE\Application Data\Mozilla\Firefox\Profiles\r4me9otk.default\extensions
[2012/11/25 05:53:12 | 000,000,000 | —D | M] (ProxTube - Unblock YouTube) – C:\Documents and Settings\YOUNG ONE\Application Data\Mozilla\Firefox\Profiles\r4me9otk.default\extensions\[removed]
[2012/11/24 00:43:09 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/11/20 01:17:52 | 000,262,112 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/11/20 01:17:14 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/11/20 01:17:14 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bjaehcnihbogidpfieaepehilfecnodk\4.2.0.7869_0\
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kochbcmingebnmbcpbbpfpmipakoipge\4.2.0.8207_0\
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk\1.20.90_0\crossrider
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk\1.20.90_0\
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\13.2.0.5_0\
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\13.2.0.5_0\.bak

O1 HOSTS File: ([2012/04/12 08:33:06 | 000,000,947 | —- | M]) - C:\WINXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DataMask by AOL) - {3955aa73-8c60-4a9b-acdb-0c2edb1b6748} - C:\Program Files\AOL\DataMask by AOL\epbho32.dll (AOL)
O2 - BHO: (AOL Toolbar Loader) - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20120709150211.dll (McAfee, Inc.)
O2 - BHO: (Price Check by AOL) - {D25B97E9-62B2-40CE-BECF-E43A7B879072} - C:\Program Files\Price Check by AOL\aolpricecheck.dll (AOL Inc.)
O2 - BHO: (ChromeFrame BHO) - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files\Google\Chrome\Application\24.0.1312.27\npchrome_frame.dll (Google Inc.)
O2 - BHO: (TBSB07898 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll File not found
O2 - BHO: (DataMask by AOL) - {ff507020-a257-4527-a222-b6f5732e55ee} - C:\Program Files\AOL\DataMask by AOL\plbho32.dll (AOL)
O3 - HKLM\..\Toolbar: (Coupons.com CouponBar) - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll File not found
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Coupons.com CouponBar) - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Data Protection Suite] C:\Program Files\AOL\DataMask by AOL\dps.exe (AOL)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\aol\1336533290\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [PhishLock] C:\Program Files\AOL\DataMask by AOL\pl.exe (AOL)
O4 - HKLM..\Run: [ROC_ROC_NT] "C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT File not found
O4 - Startup: C:\Documents and Settings\YOUNG ONE\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found
O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/4.0.3.0…xControl_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B3523D06-520B-4086-8151-9C5A7784F32F}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\gcf {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files\Google\Chrome\Application\24.0.1312.27\npchrome_frame.dll (Google Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINXP\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINXP\system32\userinit.exe) - C:\WINXP\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\822\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\822\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop Components:0 () - http://www.carmd.com/Content/Images/Home/b…at-is-CarMD.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/08/05 00:12:32 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{1d5c29de-b1d0-11e1-ba92-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{1d5c29de-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1d5c29de-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{1d5c29e0-b1d0-11e1-ba92-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{1d5c29e0-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1d5c29e0-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{1d5c29e2-b1d0-11e1-ba92-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{1d5c29e2-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1d5c29e2-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINXP\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINXP\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINXP\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINXP\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINXP\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINXP\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINXP\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINXP\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINXP\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINXP\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: vidc.mjpg - pvmjpg30.dll File not found
Drivers32: wave1 - C:\WINXP\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/11/30 22:28:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\YOUNG ONE\Desktop\OTL.exe
[2012/11/30 22:18:14 | 003,902,728 | —- | C] (TeamViewer GmbH) – C:\Documents and Settings\YOUNG ONE\Desktop\TeamViewer_Setup_en.exe
[2012/11/30 21:27:19 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\TeamViewer
[2012/11/28 07:51:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\QuickTime
[2012/11/28 06:44:56 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Start Menu\Programs\Staples Easy Button
[2012/11/28 06:44:56 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Staples Easy Button
[2012/11/28 06:44:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Staples Easy Button
[2012/11/28 06:44:54 | 000,000,000 | —D | C] – C:\Program Files\Staples Easy Button
[2012/11/25 14:58:34 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2012/11/25 14:47:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Norton PC Checkup 3.0
[2012/11/25 14:47:12 | 000,000,000 | —D | C] – C:\Program Files\Norton PC Checkup 3.0
[2012/11/25 14:47:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Norton
[2012/11/25 04:56:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\UAB
[2012/11/25 04:56:22 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\PC_Drivers_Headquarters
[2012/11/25 04:56:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Driver Restore
[2012/11/25 04:55:57 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\PCCUStubInstaller
[2012/11/25 04:53:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Driver Restore
[2012/11/25 04:53:14 | 000,000,000 | —D | C] – C:\Program Files\Driver Restore
[2012/11/24 05:43:47 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Mozilla
[2012/11/24 05:43:47 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Mozilla
[2012/11/24 00:43:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Mozilla
[2012/11/24 00:43:12 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/11/19 07:48:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/19 07:48:28 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\WINXP\System32\drivers\mbam.sys
[2012/11/19 07:48:28 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/11/19 07:28:13 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\SUPERAntiSpyware.com
[2012/11/19 07:28:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\SUPERAntiSpyware
[2012/11/19 07:28:03 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/11/15 01:29:09 | 000,000,000 | —D | C] – C:\Program Files\AOL Toolbar
[2012/11/15 01:28:50 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Software Update Utility
[2012/11/15 00:46:20 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\PerformerSoft
[2012/11/15 00:39:52 | 000,017,464 | —- | C] (PerformerSoft LLC) – C:\WINXP\System32\roboot.exe
[2012/11/12 01:48:39 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\OfficeSuiteX
[2012/11/12 01:47:40 | 000,000,000 | –SD | C] – C:\Documents and Settings\YOUNG ONE\Start Menu\Programs\Office Suite X 3.3
[2012/11/12 01:45:55 | 000,000,000 | —D | C] – C:\Program Files\Office Suite X 3
[2012/11/12 01:35:58 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Sun
[2012/11/12 01:35:31 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Desktop\OfSX
[2012/11/11 01:46:17 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Toolbar4
[2012/11/10 20:08:39 | 000,000,000 | —D | C] – C:\WINXP\System32\cache
[2012/11/09 02:01:44 | 000,000,000 | -H-D | C] – C:\WINXP\ie8
[2012/11/08 03:40:07 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\OfficeNow
[2012/11/08 03:18:41 | 000,000,000 | –SD | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\OfficeNow 3.5
[2012/11/08 03:15:52 | 000,000,000 | —D | C] – C:\Program Files\OfficeNow 3.5
[2012/11/08 03:14:32 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\My Documents\ShopToWin
[2012/11/08 03:13:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Tarma Installer
[2012/11/08 03:13:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Applications
[2012/11/08 03:12:36 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/11/08 03:11:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Babylon
[2012/11/08 03:11:47 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Babylon
[2012/11/08 03:11:33 | 000,000,000 | —D | C] – C:\Program Files\OfficeNow and Options
[1 C:\WINXP\*.tmp files -> C:\WINXP\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/11/30 23:06:30 | 000,000,890 | —- | M] () – C:\WINXP\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/30 22:32:08 | 000,000,886 | —- | M] () – C:\WINXP\tasks\SentryBayUpdateTaskMachineUA.job
[2012/11/30 22:28:12 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\YOUNG ONE\Desktop\OTL.exe
[2012/11/30 22:22:30 | 000,000,886 | —- | M] () – C:\WINXP\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/30 22:22:28 | 000,000,418 | —- | M] () – C:\WINXP\tasks\PC Optimizer Pro startups.job
[2012/11/30 22:22:27 | 000,000,882 | —- | M] () – C:\WINXP\tasks\SentryBayUpdateTaskMachineCore.job
[2012/11/30 22:21:29 | 000,002,048 | –S- | M] () – C:\WINXP\bootstat.dat
[2012/11/30 22:21:28 | 000,304,416 | —- | M] () – C:\WINXP\System32\FNTCACHE.DAT
[2012/11/30 22:18:16 | 003,902,728 | —- | M] (TeamViewer GmbH) – C:\Documents and Settings\YOUNG ONE\Desktop\TeamViewer_Setup_en.exe
[2012/11/30 21:53:25 | 000,000,000 | —- | M] () – C:\install.rdf
[2012/11/30 21:24:15 | 000,000,426 | -H– | M] () – C:\WINXP\tasks\User_Feed_Synchronization-{BAE1211D-518D-41FA-952A-BC9133310994}.job
[2012/11/30 20:22:40 | 000,013,024 | —- | M] () – C:\WINXP\System32\drivers\SWDUMon.sys
[2012/11/30 01:29:43 | 000,141,429 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\OakBuilding001.pdf
[2012/11/29 18:11:49 | 000,000,372 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\spider.sav
[2012/11/28 07:52:00 | 000,001,600 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\QuickTime Player.lnk
[2012/11/28 07:20:04 | 000,000,284 | —- | M] () – C:\WINXP\tasks\AppleSoftwareUpdate.job
[2012/11/28 06:44:55 | 000,001,587 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Staples Easy Button.lnk
[2012/11/28 04:03:33 | 000,006,598 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Desktop\New OpenDocument Spreadsheet.ods
[2012/11/28 03:44:01 | 000,000,446 | —- | M] () – C:\WINXP\tasks\PC Optimizer Pro Updates.job
[2012/11/28 02:55:18 | 000,002,206 | —- | M] () – C:\WINXP\System32\wpa.dbl
[2012/11/25 14:47:54 | 000,000,960 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Norton PC Checkup 3.0.lnk
[2012/11/25 14:47:49 | 000,000,400 | —- | M] () – C:\WINXP\tasks\PC Checkup 3 Weekly Scan.job
[2012/11/25 04:53:22 | 000,002,022 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Driver Restore.lnk
[2012/11/24 00:43:15 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Mozilla Firefox.lnk
[2012/11/24 00:41:48 | 000,077,472 | -H– | M] () – C:\WINXP\System32\mlfcache.dat
[2012/11/24 00:40:43 | 000,002,183 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Safari.lnk
[2012/11/20 17:10:36 | 000,000,284 | —- | M] () – C:\WINXP\tasks\PC Optimizer Pro Scan.job
[2012/11/20 00:54:52 | 000,591,480 | —- | M] () – C:\WINXP\System32\perfh009.dat
[2012/11/20 00:54:51 | 000,106,952 | —- | M] () – C:\WINXP\System32\perfc009.dat
[2012/11/19 08:15:47 | 000,000,664 | —- | M] () – C:\WINXP\System32\d3d9caps.dat
[2012/11/19 07:48:33 | 000,000,802 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/11/19 07:48:33 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/19 07:28:07 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/11/16 02:14:48 | 000,001,831 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/11/14 13:38:43 | 000,018,240 | —- | M] (SentryBay) – C:\WINXP\System32\drivers\epfilter.sys
[2012/11/14 02:52:12 | 000,001,393 | —- | M] () – C:\WINXP\imsins.BAK
[2012/11/14 01:28:32 | 000,013,492 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\Untitled 1.ods
[2012/11/12 06:35:12 | 000,014,144 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\D KID SPREAD SHEET.ods
[2012/11/12 01:47:40 | 000,000,885 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Desktop\Office Suite X 3.3.lnk
[2012/11/09 20:19:36 | 000,000,815 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/11/09 01:11:15 | 000,000,754 | —- | M] () – C:\WINXP\WORDPAD.INI
[2012/11/08 04:22:53 | 000,007,495 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\MY NOTES BJC.ods
[2012/11/08 03:18:42 | 000,000,827 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\OfficeNow 3.5.lnk
[2012/11/01 03:02:10 | 000,007,477 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\.facebook_-2119691970.jpg
[1 C:\WINXP\*.tmp files -> C:\WINXP\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/11/30 21:53:25 | 000,000,000 | —- | C] () – C:\install.rdf
[2012/11/28 07:51:59 | 000,001,600 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\QuickTime Player.lnk
[2012/11/28 06:44:55 | 000,001,587 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Staples Easy Button.lnk
[2012/11/28 04:03:33 | 000,006,598 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Desktop\New OpenDocument Spreadsheet.ods
[2012/11/28 04:02:18 | 000,001,764 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\VIPRE Internet Security.lnk
[2012/11/25 14:47:54 | 000,000,960 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Norton PC Checkup 3.0.lnk
[2012/11/25 14:47:49 | 000,000,400 | —- | C] () – C:\WINXP\tasks\PC Checkup 3 Weekly Scan.job
[2012/11/25 04:53:22 | 000,002,022 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Driver Restore.lnk
[2012/11/24 00:43:15 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Mozilla Firefox.lnk
[2012/11/24 00:43:15 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Mozilla Firefox.lnk
[2012/11/20 17:10:34 | 000,000,284 | —- | C] () – C:\WINXP\tasks\PC Optimizer Pro Scan.job
[2012/11/19 14:43:01 | 000,141,429 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\OakBuilding001.pdf
[2012/11/19 07:48:33 | 000,000,802 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/11/19 07:48:33 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/19 07:28:07 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/11/15 00:06:17 | 000,000,426 | -H– | C] () – C:\WINXP\tasks\User_Feed_Synchronization-{BAE1211D-518D-41FA-952A-BC9133310994}.job
[2012/11/14 01:28:32 | 000,013,492 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\Untitled 1.ods
[2012/11/12 06:35:12 | 000,014,144 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\D KID SPREAD SHEET.ods
[2012/11/12 01:47:40 | 000,000,885 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Desktop\Office Suite X 3.3.lnk
[2012/11/09 01:11:15 | 000,000,754 | —- | C] () – C:\WINXP\WORDPAD.INI
[2012/11/08 04:22:49 | 000,007,495 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\MY NOTES BJC.ods
[2012/11/08 03:18:42 | 000,000,827 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\OfficeNow 3.5.lnk
[2012/11/01 03:02:09 | 000,007,477 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\.facebook_-2119691970.jpg
[2012/10/08 13:11:12 | 000,013,024 | —- | C] () – C:\WINXP\System32\drivers\SWDUMon.sys
[2012/09/07 05:41:32 | 000,032,490 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\bgauuubu.exe
[2012/07/25 20:43:21 | 000,000,088 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Application Data\usb.inf
[2012/05/13 01:26:28 | 000,363,520 | —- | C] () – C:\WINXP\System32\PsisDecd.dll
[2012/05/01 01:17:15 | 000,000,391 | —- | C] () – C:\WINXP\label.ini
[2012/05/01 00:33:21 | 000,000,036 | —- | C] () – C:\WINXP\odbcddp.ini
[2012/05/01 00:33:20 | 000,001,327 | —- | C] () – C:\WINXP\ODBC.INI
[2012/05/01 00:20:37 | 000,001,286 | —- | C] () – C:\WINXP\resume32.ini
[2012/05/01 00:19:06 | 000,001,297 | —- | C] () – C:\WINXP\mymark32.ini
[2012/05/01 00:18:39 | 000,000,033 | —- | C] () – C:\WINXP\mybc32.ini
[2012/05/01 00:18:31 | 000,001,612 | —- | C] () – C:\WINXP\bussta32.ini
[2012/04/25 03:21:12 | 000,017,920 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/24 01:39:33 | 000,061,678 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Application Data\PFP100JPR.{PB
[2012/04/24 01:39:33 | 000,012,358 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Application Data\PFP100JCM.{PB
[2012/04/14 19:41:42 | 000,200,704 | —- | C] () – C:\WINXP\System32\igfxCoIn_v4704.dll
[2012/04/14 19:41:41 | 000,447,120 | —- | C] () – C:\WINXP\System32\igmedkrn.dll
[2012/04/13 23:40:03 | 000,000,664 | —- | C] () – C:\WINXP\System32\d3d9caps.dat
[2012/04/12 10:21:03 | 000,003,072 | —- | C] () – C:\WINXP\System32\iacenc.dll
[2012/04/11 20:21:58 | 000,077,824 | R— | C] () – C:\WINXP\System32\HPZIDS01.dll
[2012/04/11 04:48:32 | 000,077,472 | -H– | C] () – C:\WINXP\System32\mlfcache.dat
[2012/04/11 02:58:39 | 000,117,364 | —- | C] () – C:\WINXP\hpoins11.dat.temp
[2012/04/11 02:58:38 | 000,011,634 | —- | C] () – C:\WINXP\hpomdl11.dat.temp
[2012/04/10 19:33:21 | 000,000,000 | R— | C] () – C:\WINXP\System32\DVEMODEM.DAT
[2012/04/10 19:32:29 | 000,004,272 | R— | C] () – C:\WINXP\System32\drivers\bvrp_pci.sys
[2012/04/10 16:30:01 | 000,000,006 | —- | C] () – C:\WINXP\msoffice.ini
[2012/04/10 16:14:41 | 000,000,715 | —- | C] () – C:\WINXP\aolback.exe.lnk
[2012/04/09 10:24:28 | 000,000,132 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\fusioncache.dat
[2012/04/09 07:19:14 | 000,000,335 | —- | C] () – C:\WINXP\nsreg.dat
[2012/04/09 01:49:10 | 000,002,048 | –S- | C] () – C:\WINXP\bootstat.dat
[2012/04/09 01:43:36 | 000,021,640 | —- | C] () – C:\WINXP\System32\emptyregdb.dat
[2012/01/20 22:42:52 | 000,136,166 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-2129685425-2355302513-2605349347-1007-0.dat
[2011/07/04 14:27:55 | 000,272,054 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-2129685425-2355302513-2605349347-1006-0.dat
[2011/07/04 14:27:55 | 000,136,166 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat

========== ZeroAccess Check ==========

[2012/04/11 20:34:48 | 000,000,227 | RHS- | M] () – C:\WINXP\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2012/02/28 13:50:30 | 001,510,400 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINXP\system32\wbem\fastprox.dll – [2009/02/09 07:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINXP\system32\wbem\wbemess.dll – [2008/04/14 04:42:10 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/09/06 00:11:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\036E18E8ECDC1B1C236255877B07D329
[2012/10/18 00:20:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/11/08 03:13:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Applications
[2012/11/08 03:11:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Babylon
[2012/04/10 14:40:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Citrix
[2012/10/08 13:11:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Common Files
[2012/09/08 19:31:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Downloaded Installations
[2012/11/25 04:56:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Driver Restore
[2012/08/31 11:15:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Garmin
[2012/08/05 00:11:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\muvee Technologies
[2012/07/25 07:20:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\PC Optimizer Pro
[2012/05/10 12:43:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Pinnacle
[2012/05/10 12:44:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Pinnacle Studio HD
[2012/05/10 12:34:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Pinnacle Studio Plus
[2012/04/12 08:44:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Price Check by AOL
[2012/11/30 21:54:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\SpeedMaxPc
[2012/05/10 12:34:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Studio 15
[2012/11/30 22:13:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Tarma Installer
[2012/08/05 00:46:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\TEMP
[2012/11/25 04:57:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\UAB
[2012/11/30 21:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Viewpoint
[2012/06/07 10:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\White Sky, Inc
[2012/08/05 00:33:16 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\{299AD074-3B8B-4811-BF5C-E2EDBC6DEB23}
[2012/04/11 04:19:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/04/12 22:34:44 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\acccore
[2012/11/08 03:11:47 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Babylon
[2012/09/09 02:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Business Logic
[2012/05/13 00:33:45 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/10/04 12:39:41 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\DriverCure
[2012/04/25 03:00:48 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\FUJIFILM
[2012/08/31 11:15:09 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Garmin
[2012/07/25 21:11:57 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Image Zone Express
[2012/04/11 02:28:41 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\InterTrust
[2012/08/05 00:18:23 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\muvee Technologies
[2012/11/08 03:40:07 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\OfficeNow
[2012/11/12 01:48:39 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\OfficeSuiteX
[2012/07/14 02:59:59 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\OpenOffice.org
[2012/11/25 04:55:57 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\PCCUStubInstaller
[2012/11/30 21:49:45 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\PerformerSoft
[2012/08/11 02:41:37 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\SentryBay
[2012/10/10 04:18:08 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Smilebox
[2012/10/04 12:39:40 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\SpeedMaxPc
[2012/11/30 20:44:30 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Staples Easy Button
[2012/05/08 21:16:32 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\SupportSoft
[2012/11/30 21:27:19 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\TeamViewer
[2012/11/11 01:46:17 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Toolbar4
[2012/05/01 01:14:50 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Windows Desktop Search
[2012/10/18 22:33:35 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Windows Search

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >
[2012/04/08 15:01:46 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\..\JAMES YOUNG\Local Settings\Temp\smtmp
[2012/04/08 15:01:46 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\..\JAMES YOUNG\Local Settings\Temp\smtmp\1
[2012/04/27 11:01:03 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\..\JAMES YOUNG\Local Settings\Temp\smtmp\2

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EX_ >
[2004/08/04 05:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\i386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINXP\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINXP\ServicePackFiles\i386\explorer.exe
[2007/06/13 06:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\i386\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/12 08:57:20 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINXP\$NtServicePackUninstall$\explorer.exe

< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2012/04/08 17:52:48 | 000,090,326 | —- | M] () MD5=A1B929C5451DA91CBE6C337C73E65EB2 – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf

< MD5 for: EXPLORER.EXE-17D69B44.PF >
[2012/11/30 18:29:50 | 000,052,138 | —- | M] () MD5=7D75FA0502D072092F0BE1518785FAA0 – C:\WINXP\Prefetch\EXPLORER.EXE-17D69B44.pf

< MD5 for: EXPLORER.SC_ >
[2004/08/04 05:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\i386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2004/08/04 05:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
[2004/08/12 08:57:20 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINXP\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINXP\Help\iexplore.chm
[2004/08/04 05:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\i386\iexplore.chm
[2004/08/04 05:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm
[2004/08/12 08:58:01 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINXP\ie8\iexplore.chm

< MD5 for: IEXPLORE.CHW >
[2012/05/29 01:44:29 | 000,153,185 | —- | M] () MD5=3680C8BC82A0E88026ECFE100DB2C78A – C:\WINXP\Help\iexplore.chw

< MD5 for: IEXPLORE.EX_ >
[2004/08/04 05:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\i386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2008/04/13 19:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2008/04/14 04:42:24 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINXP\ie8\iexplore.exe
[2008/04/14 04:42:24 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINXP\ServicePackFiles\i386\iexplore.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINXP\system32\dllcache\iexplore.exe
[2004/08/04 05:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie8\iexplore.exe
[2004/08/12 08:58:01 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINXP\$NtServicePackUninstall$\iexplore.exe

< MD5 for: IEXPLORE.EXE.HDMP >
[2011/07/06 03:56:59 | 005,578,495 | —- | M] () MD5=04E4011AC97D9BBD00916842DA673BC7 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERed39.dir00\iexplore.exe.hdmp
[2012/01/19 22:51:36 | 004,409,131 | —- | M] () MD5=43077588CC285663DA30458A8688D205 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER8f20.dir00\iexplore.exe.hdmp
[2011/12/17 16:27:00 | 007,398,843 | —- | M] () MD5=935306B67B7AFBB4260245E7EF21F79E – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER0de0.dir00\iexplore.exe.hdmp
[2012/04/08 15:35:51 | 006,897,432 | —- | M] () MD5=9F1FA801F4FCCF7207524DF3A92AAA9C – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER722e.dir00\iexplore.exe.hdmp
[2012/11/20 16:50:12 | 019,163,917 | —- | M] () MD5=AA4D4D7F5C1337E315878FE35E45829F – C:\Documents and Settings\YOUNG ONE\Local Settings\Temp\WER912c.dir00\iexplore.exe.hdmp
[2012/02/16 07:05:08 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER2bf7.dir00\iexplore.exe.hdmp
[2011/10/16 07:04:36 | 014,412,897 | —- | M] () MD5=E685A77790767C8AB83646325F8104B2 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER7c69.dir00\iexplore.exe.hdmp
[2011/12/19 16:26:21 | 006,963,994 | —- | M] () MD5=FA810B9078808FAAC2F20140F6BFE932 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERfa3c.dir00\iexplore.exe.hdmp

< MD5 for: IEXPLORE.EXE.MDMP >
[2011/07/06 03:56:56 | 000,068,413 | —- | M] () MD5=1E571B6C12DA737D6CBA8209699DCA1C – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERed39.dir00\iexplore.exe.mdmp
[2011/10/09 05:25:21 | 000,083,359 | —- | M] () MD5=5479E40655C9EE59C363B7F1B3A41CCC – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER206a.dir00\iexplore.exe.mdmp
[2012/04/08 15:35:42 | 000,073,927 | —- | M] () MD5=571ED32BF2B1449FF5C93FBCC4864E6E – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER722e.dir00\iexplore.exe.mdmp
[2011/10/08 02:28:00 | 000,075,235 | —- | M] () MD5=66AD3D424DAF2ECB0B0072EA39C897AB – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERa8bb.dir00\iexplore.exe.mdmp
[2012/11/20 16:50:09 | 000,078,557 | —- | M] () MD5=68229361750175A92E913DCB5C10859F – C:\Documents and Settings\YOUNG ONE\Local Settings\Temp\WER912c.dir00\iexplore.exe.mdmp
[2011/10/16 07:04:33 | 000,115,299 | —- | M] () MD5=A02490CA1BD807F4798892008E7545E4 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER7c69.dir00\iexplore.exe.mdmp
[2011/12/17 16:26:57 | 000,072,225 | —- | M] () MD5=AFBBCF6A0A0B26CC462608AA5BA74214 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER0de0.dir00\iexplore.exe.mdmp
[2012/02/16 07:05:07 | 000,092,662 | —- | M] () MD5=D37DF78C2E5EB8121AE6C3D11F260586 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER2bf7.dir00\iexplore.exe.mdmp
[2012/01/19 22:51:33 | 000,063,229 | —- | M] () MD5=F41EB20F4B795CB9657D564E4AAE1ED9 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER8f20.dir00\iexplore.exe.mdmp
[2011/12/19 16:26:17 | 000,071,668 | —- | M] () MD5=FA7542F81DFF6FAEA4105F3B8450814D – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERfa3c.dir00\iexplore.exe.mdmp

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2012/04/08 18:01:55 | 000,088,036 | —- | M] () MD5=146BAD1D7DEA1BAC9C50EE0D71427AD6 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf
[2012/11/30 22:27:01 | 000,068,666 | —- | M] () MD5=F7D0A71D4B6B086555E8B5142D64DEF6 – C:\WINXP\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HLP >
[2004/08/04 05:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\i386\iexplore.hlp
[2004/08/04 05:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
[2004/08/12 08:58:01 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINXP\Help\iexplore.hlp

< MD5 for: SERVICES >
[2004/08/04 05:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\i386\services
[2004/08/04 05:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
[2004/08/12 09:05:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINXP\system32\drivers\etc\services

< MD5 for: SERVICES.CFG >
[2012/01/03 08:10:44 | 000,585,874 | —- | M] () MD5=0E19E0BEA7B159153258688CF8ED7716 – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.EXE >
[2009/02/06 06:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009/02/06 06:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINXP\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 19:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 19:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2008/04/14 04:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINXP\$NtUninstallKB956572$\services.exe
[2008/04/14 04:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINXP\ServicePackFiles\i386\services.exe
[2009/02/06 12:14:03 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=37561F8D4160D62DA86D24AE41FAE8DE – C:\i386\services.exe
[2009/02/06 12:14:03 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=37561F8D4160D62DA86D24AE41FAE8DE – C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2009/02/06 12:14:03 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=37561F8D4160D62DA86D24AE41FAE8DE – C:\WINXP\$NtServicePackUninstall$\services.exe
[2009/02/06 05:22:21 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=4712531AB7A01B7EE059853CA17D39BD – C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\services.exe
[2009/02/06 05:22:21 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=4712531AB7A01B7EE059853CA17D39BD – C:\WINXP\$hf_mig$\KB956572\SP2QFE\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINXP\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINXP\system32\dllcache\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINXP\system32\services.exe
[2004/08/12 09:05:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINXP\$NtUninstallKB956572_0$\services.exe

< MD5 for: SERVICES.LNK >
[2012/07/14 02:57:12 | 000,001,590 | —- | M] () MD5=1DC649CD3A981792970A2A7929CFF0D2 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
[2012/07/14 02:57:47 | 000,001,590 | —- | M] () MD5=2522AAD5468A85CCEBD8C6386910BA71 – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Administrative Tools\Services.lnk
[2012/07/14 02:58:35 | 000,001,608 | —- | M] () MD5=FFAE08D234081A15D87D50816B427810 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\smtmp\1\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2004/08/04 05:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\i386\services.msc
[2004/08/04 05:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
[2004/08/12 09:05:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINXP\system32\services.msc

< MD5 for: SERVICES.RDB >
[2012/06/04 07:32:06 | 000,008,060 | —- | M] () MD5=365F626303EBC6DB5DCA7BBC4FAE0564 – C:\Program Files\OfficeNow 3.5\URE\misc\services.rdb
[2011/12/23 18:19:16 | 000,237,568 | —- | M] () MD5=507957679AE4579C15D57FA741EA6FFA – C:\Program Files\Office Suite X 3\URE\misc\services.rdb
[2011/12/23 18:18:40 | 005,314,560 | —- | M] () MD5=B31F4ECB1247A650528A040A2D791105 – C:\Program Files\Office Suite X 3\Basis\program\services.rdb
[2012/06/04 22:31:04 | 000,180,201 | —- | M] () MD5=FB73C2F46884319721B2BBA533490429 – C:\Program Files\OfficeNow 3.5\program\services\services.rdb

< MD5 for: WINLOGON.EXE >
[2004/08/04 05:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\i386\winlogon.exe
[2004/08/04 05:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2004/08/12 09:09:30 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINXP\$NtServicePackUninstall$\winlogon.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINXP\ServicePackFiles\i386\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINXP\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2012/04/12 12:16:13 | 000,010,920 | —- | M] () – C:\aolconnfix.exe
[2012/04/12 12:16:13 | 000,001,039 | —- | M] () – C:\aolconnfix.txt
[2012/08/05 00:12:32 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2012/09/20 14:04:37 | 000,000,316 | -HS- | M] () – C:\boot.ini
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/06/20 20:55:34 | 000,008,290 | R— | M] () – C:\dell.sdr
[2011/07/21 01:45:48 | 000,001,471 | —- | M] () – C:\GingerSetup.log
[2007/03/30 00:07:43 | 1063,161,856 | -HS- | M] () – C:\hiberfil.sys
[2011/06/21 21:17:07 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2012/05/08 22:17:24 | 000,030,546 | —- | M] () – C:\install.log
[2012/11/30 21:53:25 | 000,000,000 | —- | M] () – C:\install.rdf
[2012/11/28 17:04:54 | 000,000,112 | —- | M] () – C:\INSTALLHELPER.LOG
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\IO.SYS
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\MSDOS.SYS
[2011/06/20 20:55:42 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/07/04 03:46:04 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/11/30 22:21:26 | 1594,662,912 | -HS- | M] () – C:\pagefile.sys
[2012/09/20 14:16:31 | 000,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2011/07/29 02:07:46 | 000,000,186 | —- | M] () – C:\picsetup.log
[2012/04/10 16:11:50 | 000,000,320 | -H– | M] () – C:\T4Metrics.log

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINXP\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINXP\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINXP\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINXP\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >
[2006/02/19 02:28:56 | 000,012,288 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\WINXP\Fonts\RandFont.dll

< %systemroot%\Fonts\*.ini >
[2012/04/09 01:46:11 | 000,000,067 | -HS- | M] () – C:\WINXP\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/04/10 13:02:32 | 000,074,240 | —- | M] (Hewlett-Packard Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\hpzpp054.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2007/03/29 19:31:36 | 000,094,208 | —- | M] () – C:\WINXP\System32\config\default.sav
[2007/03/29 19:31:36 | 000,634,880 | —- | M] () – C:\WINXP\System32\config\software.sav
[2007/03/29 19:31:36 | 000,901,120 | —- | M] () – C:\WINXP\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2012/04/12 09:31:03 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users.WINXP\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/04/12 10:17:14 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2012/04/09 01:56:53 | 000,000,079 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2012/04/16 02:23:10 | 001,552,605 | —- | M] (Ion Audio LLC ) – C:\Documents and Settings\YOUNG ONE\Desktop\EZVinylTapeConverterSetup_v10.exe
[2012/04/11 02:00:45 | 004,258,424 | —- | M] (McAfee, Inc.) – C:\Documents and Settings\YOUNG ONE\Desktop\McAfeeSetup.exe
[2012/11/30 22:28:12 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\YOUNG ONE\Desktop\OTL.exe
[2012/11/30 22:18:16 | 003,902,728 | —- | M] (TeamViewer GmbH) – C:\Documents and Settings\YOUNG ONE\Desktop\TeamViewer_Setup_en.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-11-14 08:06:46

========== Alternate Data Streams ==========

@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users.WINXP\Application Data\TEMP:79DD4F33

< End of report >


——————

OTL Extras logfile created on: 11/30/2012 11:16:43 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\YOUNG ONE\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.86 Mb Total Physical Memory | 481.32 Mb Available Physical Memory | 47.47% Memory free
2.38 Gb Paging File | 1.64 Gb Available in Paging File | 68.83% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Program Files
Drive C: | 145.00 Gb Total Space | 81.00 Gb Free Space | 55.86% Space Free | Partition Type: NTFS

Computer Name: JAMES-91746AC0C | User Name: YOUNG ONE | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\Common Files\aol\Loader\aolload.exe" = C:\Program Files\Common Files\aol\Loader\aolload.exe:*:Enabled:AOL Application Loader – (AOL Inc.)
"C:\Program Files\Common Files\aol\ACS\AOLDial.exe" = C:\Program Files\Common Files\aol\ACS\AOLDial.exe:*:Enabled:AOL – (America Online)
"C:\Program Files\Common Files\aol\ACS\AOLacsd.exe" = C:\Program Files\Common Files\aol\ACS\AOLacsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\America Online 9.0b\waol.exe" = C:\Program Files\America Online 9.0b\waol.exe:*:Enabled:AOL
"C:\Program Files\Common Files\aol\TopSpeed\2.0\aoltsmon.exe" = C:\Program Files\Common Files\aol\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon
"C:\Program Files\Common Files\aol\TopSpeed\2.0\aoltpspd.exe" = C:\Program Files\Common Files\aol\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed
"C:\Program Files\Common Files\aol\1334092339\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\aol\1334092339\EE\AOLServiceHost.exe:*:Enabled:AOL
"C:\Program Files\Common Files\aol\System Information\sinf.exe" = C:\Program Files\Common Files\aol\System Information\sinf.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\Common Files\aol\AOL Spyware Protection\AOLSP Scheduler.exe" = C:\Program Files\Common Files\aol\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL
"C:\Program Files\Common Files\aol\AOL Spyware Protection\asp.exe" = C:\Program Files\Common Files\aol\AOL Spyware Protection\asp.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe" = C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL – (Gteko Ltd.)
"C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed – (AOL Inc.)
"C:\Program Files\Common Files\aol\1334093993\ee\aolsoftware.exe" = C:\Program Files\Common Files\aol\1334093993\ee\aolsoftware.exe:*:Enabled:AOL Shared Components
"C:\Program Files\Common Files\aol\1334093993\ee\AOLDesktop.exe" = C:\Program Files\Common Files\aol\1334093993\ee\AOLDesktop.exe:*:Enabled:AOL Desktop
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service – (Apple Inc.)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe – (Hewlett-Packard Development Company, L.P.)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"E:\skype\Skype.exe" = E:\skype\Skype.exe:*:Enabled:Skype
"C:\Program Files\Common Files\aol\1336533290\ee\aolsoftware.exe" = C:\Program Files\Common Files\aol\1336533290\ee\aolsoftware.exe:*:Enabled:AOL Shared Components – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.7\waol.exe" = C:\Program Files\AOL Desktop 9.7\waol.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe" = C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe:*:Enabled:AOL Browser – (AOL Inc.)
"C:\Program Files\Pinnacle\Studio 15\Programs\RM.exe" = C:\Program Files\Pinnacle\Studio 15\Programs\RM.exe:*:Enabled:Render Manager – (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 15\Programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 15\Programs\Studio.exe:*:Enabled:Studio – (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 15\Programs\umi.exe" = C:\Program Files\Pinnacle\Studio 15\Programs\umi.exe:*:Enabled:umi – (Pinnacle Systems)
"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0F6F6876-6334-4977-B5DD-CFC12E193420}" = iTunes
"{12365698-8042-4774-8CAF-35BE91DC657B}" = Creative Vado HD Codec
"{1362E602-9625-42D3-B57F-CDA9D26F9DA8}" = Pinnacle Studio 15
"{13F054F3-0B07-4D15-9E80-C55B496AB557}" = Garmin Communicator Plugin
"{14ECAABB-C8B9-4A09-92F7-CDF1A45B6DDE}" = Google Drive
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F56A6C9-81CA-4B5F-B471-8CCB13CF85DA}" = Office Suite X 3.3
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{251C65C0-15FF-4603-98BB-E4A61C7DA424}" = CarMD
"{273130E8-117C-4237-A0FA-83EBBF11E051}" = Driver Restore
"{29D88826-2AB9-11D5-8854-00902761A46D}" = WordPerfect Office 2002
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{45D3CD3E-7715-4341-8441-A3A6409FCDE4}" = BIAS SoundSoap 2.0
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{524AC636-ADC4-4E42-B149-D0B6B5F4D24A}" = Garmin BaseCamp
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{555B2506-E17C-4EEF-AA70-03985F664BAD}" = Creative Vado Central muvee Plugin
"{5802F606-7F09-4CCE-800C-7B53B0906662}" = Mail List
"{5A9AA2C0-972F-4239-AA41-E409434194D5}" = MobileMe Control Panel
"{5FDA577D-2C25-405F-B759-235CA8016D19}" = Newsletters
"{628C2C7D-8AD1-E614-E8E2-6EEAD8D5F2D0}" = Acrobat.com
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6DE721A5-5E89-4D74-994C-652BB3C0672E}" = Pinnacle Video Driver
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{9A61BE73-18A3-4AC2-AFF1-E4B8D92158BD}" = OfficeNow 3.5
"{9AAD03E8-4F65-4DE2-8F6C-1B079C0C8521}" = Garmin Lifetime Updater
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3217415-0BD4-4252-BF9F-3AF4A267B04C}" = DataMask by AOL
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries
"{AA104808-94FA-4C82-ABFE-F630E44192E2}" = Resumes
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{ABA5E381-EC46-425C-86C5-5CD15BBFB4BF}" = Garmin USB Drivers
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{BA38CDB0-B61C-4490-9A9C-92241C05FA33}" = SentryBay Update Helper
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BC85D7C6-028A-4012-8E3C-B4D11D74E34B}" = DriverUpdate
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}" = Apple Mobile Device Support
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DED01768-E634-11E1-AEB0-984BE15F174E}" = Evernote v. 4.5.8
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{E488C022-045B-11D5-97A7-00C04F6BFB42}" = LabelMaker
"{E75AE16E-43CF-446D-AD44-999550BFD78E}" = Stationery
"{EC27311B-0012-11D5-8341-0001023FF70B}" = CD Organizer
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{FA4C2D53-205F-4245-9717-F3761154824D}" = Safari
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FC030CB5-46A6-4229-AD6E-0AC869F509C8}" = Pinnacle Studio Bonus Content
"{FE7E1DD7-EBCE-4696-ADE2-22BDBF2372DA}" = DocumentViewer
"98157A226B40B173301B0F53C8E98C47805D5152" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0)
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"AOL Deskbar" = AOL Deskbar
"AOL Toolbar" = AOL Toolbar
"AOL Toolbar for Firefox" = AOL Toolbar for Firefox
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AolCoach2_en" = AOL Coach Version 2.0(Build:20041026.5 en)
"Audacity_is1" = Audacity 1.2.4
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"Creative Vado HD Codec" = Creative Vado HD Codec
"EZ Vinyl Converter by MixMeister_is1" = EZ Vinyl Converter by MixMeister 1.0.5
"EZ Vinyl/Tape Converter by Ion Audio_is1" = EZ Vinyl/Tape Converter 10 by Ion Audio
"Google Chrome" = Google Chrome
"Google Chrome Frame" = Google Chrome Frame
"GoToAssist" = GoToAssist Corporate
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Document Viewer" = HP Document Viewer 7.0
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 17.0 (x86 en-US)" = Mozilla Firefox 17.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Norton PC Checkup_is1" = Norton PC Checkup
"OfficeNow_and_Options" = OfficeNow and Options
"Price Check by AOL" = Price Check by AOL
"PROSet" = Intel® PRO Network Connections Drivers
"RealPlayer 6.0" = RealPlayer Basic
"SoftwareUpdUtility" = Download Updater (AOL Inc.)
"Staples Easy Button" = Staples Easy Button (remove only)
"stax-Pinnacle_is1" = SureThing Express Labeler
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WordPerfect Office 2002" = WordPerfect Office 2002
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"AOL Toolbar" = AOL Toolbar
"Smilebox" = Smilebox

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 11/29/2012 12:52:33 AM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 11/29/2012 12:53:29 AM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 11/29/2012 12:55:23 AM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 11/29/2012 4:36:31 PM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.19328, fault address 0x000da6ff.

Error - 11/29/2012 4:36:31 PM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.19328, fault address 0x000da6ff.

Error - 11/30/2012 2:00:39 AM | Computer Name = JAMES-91746AC0C | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 2116 (0x844) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.4.0.387
/ 5400.1158 Object being scanned = \Device\HarddiskVolume2\Program Files\SUPERAntiSpyware\sasdifsv.sys

by C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 4(0)(0) 4(0)(0)
7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)

Error - 11/30/2012 1:35:46 PM | Computer Name = JAMES-91746AC0C | Source = Application Hang | ID = 1002
Description = Hanging application PCPerformer.exe, version 11.10.1.2217, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/30/2012 1:37:26 PM | Computer Name = JAMES-91746AC0C | Source = Application Hang | ID = 1001
Description = Fault bucket -1400214861.

Error - 11/30/2012 10:19:12 PM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module , version 13.2.0.5, fault address 0x000ea1b9.

Error - 11/30/2012 11:02:04 PM | Computer Name = JAMES-91746AC0C | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 3068 (0xbfc) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.4.0.387
/ 5400.1158 Object being scanned = \Device\HarddiskVolume2\Program Files\McAfee.com\Agent\mcagent.exe

by C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 4(0)(0) 4(0)(0)
7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)

[ System Events ]
Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}

Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}

Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}

Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}

Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}

Error - 12/1/2012 12:25:03 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}

Error - 12/1/2012 12:25:03 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}

Error - 12/1/2012 12:25:18 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}

Error - 12/1/2012 12:25:18 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}

Error - 12/1/2012 12:34:28 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}


< End of report >
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error
Hi here are the results of the ComboFix scan:

ComboFix 12-12-04.01 - YOUNG ONE 12/04/2012 20:27:51.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.496 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users.WINXP\Application Data\TEMP
c:\documents and settings\JAMES YOUNG\GoToAssistDownloadHelper.exe
c:\documents and settings\JAMES YOUNG\WINDOWS
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\arrow_refresh.png
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\basis.xml
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\0533ddea046b79382344642507f45004
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\09243a7e0d5263f96fccb70e16bb0476
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\0b9a7a3e0c1c165779dd33b229048b21
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\0c74e33c6b89503129478a0eae095b4d
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\0e1466e34ff25e57fa813d21ebfe7cf6
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\0fb67f15ee619bf63699876db03ab661
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\24234224fe547fa5f61335a325f858b5
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\2612ed9846214cbf7e954476bb044b3b
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\323af8f156d5bb22bb38cd2ce83959de
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\36402215e280142e9fec69a27ce97d32
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\3739298d2bc9d6b94dadd7b19b48ecb3
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\476905aa92e1c9a617bd41ce5318660f
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\4c667e8e6ec412f944dcb9352b851013
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\4d2e45ddaef75a6d2c9afdbc763c3752
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\4e2d5ba12b0ed08ba8960c3e874a01cb
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\560ff84a7533e0f37b61b702a5403538
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\59a443f04bf13d1170b3dfc61f51b928
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\5bc8ebf64906d196c815a3f28ee7be81
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\5dcc33988f89c01e09411de1fadabde2
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\5e4a0304a53d72265f5f470649d2f616
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\5fceefa5d8207202cd84891c2e491f65
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\753df778c49000ceb420710ab27250f3
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\7aab54a686f169a739561ca08b97d70b
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\829a174ff56578e2e86c6ea74ceac599
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\8c192effd1339f8e52b7695d8409b038
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\97be6f9cdebaa8074491269ce024994b
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\9ac01b227ded0862f1cacbfb3aa57c30
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\a03f31127270e5ec9c753d5978824827
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\a0c60a9410bfbe84abdf5e97d0c4c25b
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\aa65030026dd406f81e1d2f100fe7920
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\b4129101a6dd1056cc66cb8ee0ed07cb
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\b576b7d306b9484794e87c4894171e9c
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\b672745e0fa0b3d70622c3426bdb0fe6
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\b8cb931520574f1fbe2d6a417ab188a3
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\cadd36508a4b8f2e96e6251f59441e6d
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\cf00f968a680ae7de4f426758f29e399
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\d210e926e7fc2fc8277b03dcf0f51bf7
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\dd63f857ccdda3776635728c6e9c9da5
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\df93d78ff74b9089b7e56bad7abf8d54
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\e0274c4eebf32d7d1bf0e38726e4ea71
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\e676561c84d9a41ec2ac1b9379b89748
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\fdcfc40763b6755ae687e945adb4dba4
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\fe98d58b0232c74e3b47d141e87aaa18
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cache\merchant_notification
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\cog.png
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\computer_delete.png
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\dataLoader.js
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\icons3.bmp
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\include_files\879ecc39d0be00e1ba71e4872c078138
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\info.txt
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\login.png
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\logo.png
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\search.png
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\TbHelper2.exe
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\todays_deals.png
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\uninstall.exe
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\update.exe
c:\documents and settings\YOUNG ONE\Application Data\Toolbar4\{8660E5B3-6C41-44DE-8503-98D99BBECD41}\version.txt
c:\documents and settings\YOUNG ONE\Local Settings\Application Data\bgauuubu.exe
c:\documents and settings\YOUNG ONE\Local Settings\Application Data\I Want This
c:\documents and settings\YOUNG ONE\Local Settings\Application Data\I Want This\Chrome\I Want This.crx
c:\documents and settings\YOUNG ONE\My Documents\ShopToWin
c:\documents and settings\YOUNG ONE\Start Menu\Programs\Live Security Platinum
c:\documents and settings\YOUNG ONE\WINDOWS
c:\program files\alotappbar
c:\program files\alotappbar\alotUninst.exe
c:\program files\alotappbar\bin\alotappbar.dll
c:\program files\alotappbar\bin\alothelper.dll
c:\program files\alotappbar\bin\alotwidgets.exe
c:\program files\alotappbar\bin\BHO\ALOTHelperBHO.dll
c:\program files\I Want This
c:\program files\I Want This\I Want This.ico
c:\program files\I Want This\I Want This.ini
c:\program files\I Want This\I Want ThisGui.exe
c:\program files\I Want This\I Want ThisInstaller.log
c:\program files\StartNow Toolbar
c:\program files\StartNow Toolbar\Resources\images\engine_images.png
c:\program files\StartNow Toolbar\Resources\images\engine_maps.png
c:\program files\StartNow Toolbar\Resources\images\engine_news.png
c:\program files\StartNow Toolbar\Resources\images\engine_videos.png
c:\program files\StartNow Toolbar\Resources\images\engine_web.png
c:\program files\StartNow Toolbar\Resources\images\icon_amazon.png
c:\program files\StartNow Toolbar\Resources\images\icon_ebay.png
c:\program files\StartNow Toolbar\Resources\images\icon_facebook.png
c:\program files\StartNow Toolbar\Resources\images\icon_games.png
c:\program files\StartNow Toolbar\Resources\images\icon_msn.png
c:\program files\StartNow Toolbar\Resources\images\icon_shopping.png
c:\program files\StartNow Toolbar\Resources\images\icon_travel.png
c:\program files\StartNow Toolbar\Resources\images\icon_twitter.png
c:\program files\StartNow Toolbar\Resources\images\startnow_logo.png
c:\program files\StartNow Toolbar\Resources\installer.xml
c:\program files\StartNow Toolbar\Resources\protect\index.html
c:\program files\StartNow Toolbar\Resources\protect\NotIE6.css
c:\program files\StartNow Toolbar\Resources\protect\OnlyIE6.css
c:\program files\StartNow Toolbar\Resources\protect\SearchProtectIcon.png
c:\program files\StartNow Toolbar\Resources\protect\window.css
c:\program files\StartNow Toolbar\Resources\protect\window.js
c:\program files\StartNow Toolbar\Resources\reactivate\index.html
c:\program files\StartNow Toolbar\Resources\reactivate\LeftImage.png
c:\program files\StartNow Toolbar\Resources\reactivate\NotIE6.css
c:\program files\StartNow Toolbar\Resources\reactivate\OnlyIE6.css
c:\program files\StartNow Toolbar\Resources\reactivate\window.css
c:\program files\StartNow Toolbar\Resources\reactivate\window.js
c:\program files\StartNow Toolbar\Resources\skin\chevron_button.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_button_hover.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_button_normal.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_dropdown_button_normal.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_input_background.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_input_left.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_input_middle.png
c:\program files\StartNow Toolbar\Resources\skin\separator.png
c:\program files\StartNow Toolbar\Resources\skin\splitter.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ff_hover_c.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_c.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_l.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_r.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_c.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_l.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_r.png
c:\program files\StartNow Toolbar\Resources\toolbar.xml
c:\program files\StartNow Toolbar\Resources\update.xml
c:\program files\StartNow Toolbar\StartNowToolbarUninstall.exe
c:\program files\StartNow Toolbar\Toolbar32.dll
c:\program files\StartNow Toolbar\ToolbarUpdaterService.exe
c:\program files\StartNow Toolbar\uninstall.dat
c:\winxp\system32\Cache
c:\winxp\system32\Cache\0a9dadae42548093.fb
c:\winxp\system32\Cache\272512937d9e61a4.fb
c:\winxp\system32\Cache\287204568329e189.fb
c:\winxp\system32\Cache\28bc8f716fd76a47.fb
c:\winxp\system32\Cache\31a0997e9a5b5eb3.fb
c:\winxp\system32\Cache\32c84fe32bb74d60.fb
c:\winxp\system32\Cache\3917078cb68ec657.fb
c:\winxp\system32\Cache\590ba23ce359fd0c.fb
c:\winxp\system32\Cache\610289e025a3ee9a.fb
c:\winxp\system32\Cache\651c5d3cdbfb8bd1.fb
c:\winxp\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\winxp\system32\Cache\6d03dad1035885d3.fb
c:\winxp\system32\Cache\a8556537add6dfc5.fb
c:\winxp\system32\Cache\ad10a52aff5e038d.fb
c:\winxp\system32\Cache\c1fa887b03019701.fb
c:\winxp\system32\Cache\c4d28dca2e7648be.fb
c:\winxp\system32\Cache\d201ef9910cd39de.fb
c:\winxp\system32\Cache\d2e94710a5708128.fb
c:\winxp\system32\Cache\d79b9dfe81484ec4.fb
c:\winxp\system32\Cache\f998975c9cc711ee.fb
c:\winxp\system32\roboot.exe
c:\winxp\system32\URTTemp
c:\winxp\system32\URTTemp\fusion.dll
c:\winxp\system32\URTTemp\mscoree.dll
c:\winxp\system32\URTTemp\mscoree.dll.local
c:\winxp\system32\URTTemp\mscorsn.dll
c:\winxp\system32\URTTemp\mscorwks.dll
c:\winxp\system32\URTTemp\msvcr71.dll
c:\winxp\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-11-05 to 2012-12-05 )))))))))))))))))))))))))))))))
.
.
2012-12-01 02:27 . 2012-12-01 02:27 ——– d—–w- c:\documents and settings\YOUNG ONE\Application Data\TeamViewer
2012-11-28 12:52 . 2012-11-28 12:52 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2012-11-28 12:52 . 2012-11-28 12:52 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2012-11-28 12:52 . 2012-11-28 12:52 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2012-11-28 12:52 . 2012-11-28 12:52 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2012-11-28 12:52 . 2012-11-28 12:52 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2012-11-28 12:52 . 2012-11-28 12:52 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2012-11-28 12:52 . 2012-11-28 12:52 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2012-11-28 11:44 . 2012-12-01 01:44 ——– d—–w- c:\documents and settings\YOUNG ONE\Application Data\Staples Easy Button
2012-11-28 11:44 . 2012-11-28 11:44 ——– d—–w- c:\program files\Staples Easy Button
2012-11-25 19:58 . 2012-11-25 20:10 ——– d—–w- c:\program files\Common Files\Symantec Shared
2012-11-25 19:47 . 2012-11-25 19:49 ——– d—–w- c:\program files\Norton PC Checkup 3.0
2012-11-25 19:47 . 2012-11-25 19:48 ——– d—–w- c:\documents and settings\All Users.WINXP\Application Data\Norton
2012-11-25 09:56 . 2012-11-25 09:57 ——– d—–w- c:\documents and settings\All Users.WINXP\Application Data\UAB
2012-11-25 09:56 . 2012-11-25 09:56 ——– d—–w- c:\documents and settings\YOUNG ONE\Local Settings\Application Data\PC_Drivers_Headquarters
2012-11-25 09:56 . 2012-11-25 09:56 ——– d—–w- c:\documents and settings\All Users.WINXP\Application Data\Driver Restore
2012-11-25 09:55 . 2012-11-25 09:55 ——– d—–w- c:\documents and settings\YOUNG ONE\Application Data\PCCUStubInstaller
2012-11-25 09:53 . 2012-11-25 09:53 ——– d—–w- c:\program files\Driver Restore
2012-11-24 10:43 . 2012-11-24 10:43 ——– d—–w- c:\documents and settings\YOUNG ONE\Local Settings\Application Data\Mozilla
2012-11-24 05:43 . 2012-11-24 05:43 ——– d—–w- c:\documents and settings\NICOLE A\Local Settings\Application Data\Mozilla
2012-11-24 05:43 . 2012-11-24 05:43 ——– d—–w- c:\program files\Mozilla Maintenance Service
2012-11-24 05:34 . 2012-11-24 05:34 ——– d—–w- c:\documents and settings\NICOLE A\Application Data\SentryBay
2012-11-24 05:34 . 2012-11-24 05:40 ——– d—–w- c:\documents and settings\NICOLE A\Local Settings\Application Data\antiphishing-vmninternethelper1_1dn
2012-11-19 12:48 . 2012-11-19 12:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-11-19 12:48 . 2012-09-30 00:54 22856 —-a-w- c:\winxp\system32\drivers\mbam.sys
2012-11-19 12:28 . 2012-11-19 12:28 ——– d—–w- c:\documents and settings\YOUNG ONE\Application Data\SUPERAntiSpyware.com
2012-11-19 12:28 . 2012-11-19 12:28 ——– d—–w- c:\program files\SUPERAntiSpyware
2012-11-15 06:29 . 2012-11-15 06:29 ——– d—–w- c:\program files\AOL Toolbar
2012-11-15 06:28 . 2012-11-15 06:28 ——– d—–w- c:\program files\Common Files\Software Update Utility
2012-11-15 05:46 . 2012-12-01 02:49 ——– d—–w- c:\documents and settings\YOUNG ONE\Application Data\PerformerSoft
2012-11-12 06:48 . 2012-11-12 06:48 ——– d—–w- c:\documents and settings\YOUNG ONE\Application Data\OfficeSuiteX
2012-11-12 06:45 . 2012-11-12 06:46 ——– d—–w- c:\program files\Office Suite X 3
2012-11-09 07:01 . 2012-11-09 07:03 ——– dc-h–w- c:\winxp\ie8
2012-11-08 08:40 . 2012-11-08 08:40 ——– d—–w- c:\documents and settings\YOUNG ONE\Application Data\OfficeNow
2012-11-08 08:15 . 2012-11-08 08:18 ——– d—–w- c:\program files\OfficeNow 3.5
2012-11-08 08:13 . 2012-12-01 03:13 ——– d—–w- c:\documents and settings\All Users.WINXP\Application Data\Tarma Installer
2012-11-08 08:13 . 2012-11-08 08:13 ——– d—–w- c:\documents and settings\All Users.WINXP\Application Data\Applications
2012-11-08 08:11 . 2012-11-08 08:11 ——– d—–w- c:\documents and settings\All Users.WINXP\Application Data\Babylon
2012-11-08 08:11 . 2012-11-08 08:11 ——– d—–w- c:\documents and settings\YOUNG ONE\Application Data\Babylon
2012-11-08 08:11 . 2012-11-08 08:40 ——– d—–w- c:\program files\OfficeNow and Options
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-01 01:22 . 2012-10-08 18:11 13024 —-a-w- c:\winxp\system32\drivers\SWDUMon.sys
2012-11-14 18:38 . 2012-08-11 07:41 18240 —-a-w- c:\winxp\system32\drivers\epfilter.sys
2012-10-25 08:12 . 2012-10-25 08:12 94208 —-a-w- c:\winxp\system32\QuickTimeVR.qtx
2012-10-25 08:12 . 2012-10-25 08:12 69632 —-a-w- c:\winxp\system32\QuickTime.qts
2012-10-22 08:37 . 2004-08-12 14:09 1866368 —-a-w- c:\winxp\system32\win32k.sys
2012-10-15 12:54 . 2012-04-11 23:45 696760 —-a-w- c:\winxp\system32\FlashPlayerApp.exe
2012-10-15 12:54 . 2012-04-11 23:45 73656 —-a-w- c:\winxp\system32\FlashPlayerCPLApp.cpl
2012-10-02 18:04 . 2004-08-12 14:06 58368 —-a-w- c:\winxp\system32\synceng.dll
2012-11-20 06:17 . 2012-11-24 05:43 262112 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3955aa73-8c60-4a9b-acdb-0c2edb1b6748}]
2012-11-14 06:57 37256 —-a-w- c:\program files\AOL\DataMask by AOL\epbho32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2012-11-08 21:58 556056 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2012-11-08 21:58 556056 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2012-11-08 21:58 556056 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2012-11-08 21:58 556056 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Fast Start"="c:\program files\AOL Desktop 9.7\AOL.EXE" [2012-01-31 42320]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="c:\program files\Common Files\AOL\1336533290\ee\AOLSoftware.exe" [2010-03-08 41800]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-10 421776]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008]
"Data Protection Suite"="c:\program files\AOL\DataMask by AOL\dps.exe" [2012-11-14 1314696]
"PhishLock"="c:\program files\AOL\DataMask by AOL\pl.exe" [2012-11-14 798600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2012-10-25 421888]
.
c:\documents and settings\YOUNG ONE\Start Menu\Programs\Startup\
EvernoteClipper.lnk - c:\program files\Evernote\Evernote\EvernoteClipper.exe [2012-8-14 1014624]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2012-09-20 17:17 13672 —-a-w- c:\program files\Citrix\GoToAssist\822\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINXP^Start Menu^Programs^Startup^CD Organizer.lnk]
path=c:\documents and settings\All Users.WINXP\Start Menu\Programs\Startup\CD Organizer.lnk
backup=c:\winxp\pss\CD Organizer.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINXP^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINXP\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\winxp\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINXP^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=c:\documents and settings\All Users.WINXP\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=c:\winxp\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINXP^Start Menu^Programs^Startup^MySoftware NewsFlash.lnk]
path=c:\documents and settings\All Users.WINXP\Start Menu\Programs\Startup\MySoftware NewsFlash.lnk
backup=c:\winxp\pss\MySoftware NewsFlash.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINXP^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users.WINXP\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\winxp\pss\Windows Search.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^YOUNG ONE^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\YOUNG ONE\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\winxp\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^YOUNG ONE^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
path=c:\documents and settings\YOUNG ONE\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
backup=c:\winxp\pss\OpenOffice.org 3.1.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\winxp\system32\dumprep 0 -u [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-07-11 19:00 919008 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-07-31 11:20 38872 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
2012-01-31 18:25 42320 —-a-w- c:\program files\AOL Desktop 9.7\aol.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2011-11-02 13:51 59240 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-08-28 01:32 59280 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CarMD]
2010-04-07 11:39 796672 —-a-w- c:\program files\CarMD\CarMD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 09:42 15360 —-a-w- c:\winxp\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Data Protection Suite]
2012-11-14 06:55 1314696 —-a-w- c:\program files\AOL\DataMask by AOL\dps.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Garmin Lifetime Updater]
2012-06-04 13:31 1466760 —-a-w- c:\program files\Garmin\Lifetime Updater\GarminLifetime.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2010-03-08 07:27 41800 —-a-w- c:\program files\Common Files\aol\1336533290\ee\aolsoftware.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2006-10-06 23:13 114688 —-a-w- c:\winxp\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2006-10-06 23:11 98304 —-a-w- c:\winxp\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-09-10 03:30 421776 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe]
2012-03-22 01:16 1318816 —-a-w- c:\program files\McAfee.com\Agent\mcagent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 09:42 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2006-10-06 23:10 94208 —-a-w- c:\winxp\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhishLock]
2012-11-14 07:03 798600 —-a-w- c:\program files\AOL\DataMask by AOL\pl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2012-10-25 08:12 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2012-04-14 06:53 26112 —-a-w- c:\program files\Real\RealPlayer\realplay.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2006-03-20 20:00 282624 —-a-w- c:\winxp\stsystra.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USB2Check]
2006-11-06 17:31 81920 —-a-w- c:\winxp\system32\PCLECoInst.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USBToolTip]
2007-02-20 15:07 199752 —-a-w- c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"sbupdate"=2 (0x2)
"SBAMSvc"=2 (0x2)
"odserv"=3 (0x3)
"mfevtp"=2 (0x2)
"mfefire"=2 (0x2)
"McNaiAnn"=2 (0x2)
"mcmscsvc"=2 (0x2)
"idsvc"=3 (0x3)
"gusvc"=3 (0x3)
"gupdatem"=3 (0x3)
"gupdate"=2 (0x2)
"gfi_lanss10_attservice"=2 (0x2)
"EntryProtect"=2 (0x2)
"AdobeFlashPlayerUpdateSvc"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\aol\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\aol\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\aol\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Common Files\\aol\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\aol\\1336533290\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL Desktop 9.7\\waol.exe"=
"c:\\Program Files\\AOL Desktop 9.7\\AOLBrowser\\aolbrowser.exe"=
"c:\\Program Files\\Pinnacle\\Studio 15\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 15\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 15\\Programs\\umi.exe"=
"c:\\Program Files\\Common Files\\Mcafee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\winxp\system32\drivers\mfetdi2k.sys [7/9/2012 2:01 PM 89792]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [7/11/2012 1:54 PM 116608]
R2 EntryProtect;DataMask by AOL;c:\program files\AOL\DataMask by AOL\epservice.exe [6/8/2012 12:47 AM 45960]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [11/19/2012 7:48 AM 399432]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [7/9/2012 2:01 PM 214904]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\Mcafee\SystemCore\mfefire.exe [7/9/2012 2:02 PM 161664]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\winxp\system32\mfevtps.exe [7/9/2012 1:53 PM 151912]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe [11/25/2012 2:47 PM 132056]
R3 cfwids;McAfee Inc. cfwids;c:\winxp\system32\drivers\cfwids.sys [7/9/2012 2:01 PM 57600]
R3 epfilter;epfilter;c:\winxp\system32\drivers\epfilter.sys [8/11/2012 2:41 AM 18240]
R3 mfefirek;McAfee Inc. mfefirek;c:\winxp\system32\drivers\mfefirek.sys [7/9/2012 2:01 PM 340920]
R3 mfendiskmp;mfendiskmp;c:\winxp\system32\drivers\mfendisk.sys [7/9/2012 2:01 PM 83856]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11/19/2012 7:48 AM 676936]
S3 MBAMProtector;MBAMProtector;c:\winxp\system32\drivers\mbam.sys [11/19/2012 7:48 AM 22856]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\winxp\system32\drivers\mfendisk.sys [7/9/2012 2:01 PM 83856]
S3 mferkdet;McAfee Inc. mferkdet;c:\winxp\system32\drivers\mferkdet.sys [7/9/2012 2:01 PM 87656]
S3 motccgp;Motorola USB Composite Device Driver;c:\winxp\system32\drivers\motccgp.sys [8/21/2008 10:49 PM 18688]
S3 motccgpfl;MotCcgpFlService;c:\winxp\system32\drivers\motccgpfl.sys [8/21/2008 10:49 PM 8320]
S3 motport;Motorola USB Diagnostic Port;c:\winxp\system32\drivers\motport.sys [6/18/2007 7:18 PM 23680]
S3 SWDUMon;SWDUMon;c:\winxp\system32\drivers\SWDUMon.sys [10/8/2012 1:11 PM 13024]
S4 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [7/9/2012 2:01 PM 214904]
S4 sbupdate;AOL Update Service (sbupdate);c:\program files\SentryBay\Update\SentryBayUpdate.exe [8/11/2012 2:27 AM 129904]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - epinject
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2012-11-30 06:06 1606760 —-a-w- c:\program files\Google\Chrome\Application\24.0.1312.27\Installer\setup.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-28 c:\winxp\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2012-12-05 c:\winxp\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-27 11:02]
.
2012-12-05 c:\winxp\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-27 11:02]
.
2012-11-25 c:\winxp\Tasks\PC Checkup 3 Weekly Scan.job
- c:\program files\Norton PC Checkup 3.0\NLAppLauncher.exe [2012-11-25 20:14]
.
2012-12-05 c:\winxp\Tasks\SentryBayUpdateTaskMachineCore.job
- c:\program files\SentryBay\Update\SentryBayUpdate.exe [2012-08-11 07:27]
.
2012-12-04 c:\winxp\Tasks\SentryBayUpdateTaskMachineUA.job
- c:\program files\SentryBay\Update\SentryBayUpdate.exe [2012-08-11 07:27]
.
2012-12-05 c:\winxp\Tasks\User_Feed_Synchronization-{BAE1211D-518D-41FA-952A-BC9133310994}.job
- c:\winxp\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.com/
mStart Page = hxxp://search.coupons.com/
uInternet Settings,ProxyOverride =
IE: Add to Evernote 4.0 - c:\program files\Evernote\Evernote\EvernoteIE.dll/204
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.3.0/GarminAxControl_32.CAB
FF - ProfilePath - c:\documents and settings\YOUNG ONE\Application Data\Mozilla\Firefox\Profiles\r4me9otk.default\
FF - ExtSQL: 2012-11-14 15:42; [removed]; c:\program files\AOL\DataMask by AOL\ffext
FF - ExtSQL: 2012-11-24 05:33; {D19CA586-DD6C-4a0a-96F8-14644F340D60}; c:\program files\Common Files\McAfee\SystemCore
FF - ExtSQL: 2012-11-25 05:53; [removed]; c:\documents and settings\YOUNG ONE\Application Data\Mozilla\Firefox\Profiles\r4me9otk.default\extensions\[removed]
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-{8660E5B3-6C41-44DE-8503-98D99BBECD41} - c:\program files\Coupons.com CouponBar\tbcore3.dll
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
WebBrowser-{8660E5B3-6C41-44DE-8503-98D99BBECD41} - c:\program files\Coupons.com CouponBar\tbcore3.dll
HKLM-Run-ROC_ROC_NT - c:\program files\AVG Secure Search\ROC_ROC_NT.exe
MSConfigStartUp-SBAMTray - c:\program files\GFI Software\VIPRE\SBAMTray.exe
MSConfigStartUp-SelectRebates - c:\program files\SelectRebates\SelectRebates.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-12-04 20:50
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINXP\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINXP\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1036)
c:\program files\Citrix\GoToAssist\822\G2AWinLogon.dll
.
Completion time: 2012-12-04 20:55:54
ComboFix-quarantined-files.txt 2012-12-05 01:55
.
Pre-Run: 87,957,409,792 bytes free
Post-Run: 90,283,470,848 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINXP
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINXP="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - C911922D2BB0C05DA03D67473A5332D8
Please download AdwCleaner from here and save it to your desktop.
  • Right click on AdwCleaner.exe and click "Run as Administrator" to run the tool.
  • Click on Delete.
A logfile will automatically open after the scan has finished.

Please post the content of that logfile in your reply.

You can find the logfile at C:\AdwCleaner[Rn].txt as well - (n is the scan number.)








  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.







Next

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is not checked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
Here are the results from the ADWCleaner: # AdwCleaner v2.011 - Logfile created 12/06/2012 at 21:58:29 # Updated 02/12/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : YOUNG ONE - JAMES-91746AC0C # Boot Mode : Normal # Running from : C:\Documents and Settings\YOUNG ONE\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Deleted on reboot : C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk Folder Deleted : C:\Documents and Settings\All Users.WINXP\Application Data\Babylon Folder Deleted : C:\Documents and Settings\All Users.WINXP\Application Data\Tarma Installer Folder Deleted : C:\Documents and Settings\All Users.WINXP\Application Data\Viewpoint Folder Deleted : C:\Documents and Settings\GLORIA R\Application Data\AVG Secure Search Folder Deleted : C:\Documents and Settings\GLORIA R\Application Data\BabylonToolbar Folder Deleted : C:\Documents and Settings\GLORIA R\Application Data\FCSB000063941 Folder Deleted : C:\Documents and Settings\GLORIA R\Application Data\Toolbar4 Folder Deleted : C:\Documents and Settings\GLORIA R\Local Settings\Application Data\Google\Chrome\User Data\Default\databases\chrome-extension_mpfapcdfbbledbojijcbcclmlieaoogk_0 Folder Deleted : C:\Documents and Settings\YOUNG ONE\Application Data\Babylon Folder Deleted : C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\databases\chrome-extension_mpfapcdfbbledbojijcbcclmlieaoogk_0 Folder Deleted : C:\Program Files\AppGraffiti Folder Deleted : C:\Program Files\Ask.com Folder Deleted : C:\Program Files\Babylon Folder Deleted : C:\Program Files\Common Files\Software Update Utility Folder Deleted : C:\Program Files\Inbox Toolbar Folder Deleted : C:\Program Files\Inbox.com Folder Deleted : C:\Program Files\RebateInformer Folder Deleted : C:\Program Files\searchresults Folder Deleted : C:\Program Files\Viewpoint ***** [Registry] ***** Key Deleted : HKCU\Software\Crossrider Key Deleted : HKCU\Software\IGearSettings Key Deleted : HKCU\Software\InstalledBrowserExtensions Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCBCCB87-9224-4B8D-B117-F56D924BEB18} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18} Key Deleted : HKCU\Software\TBSB07898 Key Deleted : HKLM\Software\Babylon Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B27D9527-3762-4D71-963D-FB7A94FDD678} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1 Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1 Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D433A9D0-8267-40CB-8AD5-24F22FA5373F} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18} Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0002258.BHO Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0002258.BHO.1 Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0002258.FBApi Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0002258.FBApi.1 Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0002258.Sandbox Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0002258.Sandbox.1 Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1 Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1 Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{41D42E90-86D2-4521-9847-625D114F7D30} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550055225558} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{622382CB-942C-4580-A2B3-7B06A58D8538} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066226658} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{77777777-7777-7777-7777-770077227758} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403} Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1 Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1 Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1 Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1 Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1 Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier.1 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager.1 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440044224458} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C4E09482-2C6A-44B2-8D40-ABC01B36BB9D} Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk Key Deleted : HKLM\Software\MetaStream Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E} Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011221158} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SoftwareUpdUtility Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP Key Deleted : HKLM\Software\Viewpoint Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Registry is clean. -\\ Mozilla Firefox v17.0.1 (en-US) Profile name : default File : C:\Documents and Settings\YOUNG ONE\Application Data\Mozilla\Firefox\Profiles\r4me9otk.default\prefs.js [OK] File is clean. Profile name : default File : C:\Documents and Settings\GLORIA R\Application Data\Mozilla\Firefox\Profiles\aw6qcv2w.default\prefs.js [OK] File is clean. Profile name : default File : C:\Documents and Settings\NICOLE A\Application Data\Mozilla\Firefox\Profiles\nmoih9rj.default\prefs.js [OK] File is clean. -\\ Google Chrome v24.0.1312.35 File : C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences Deleted [l.1] : icon_url ={"backup":{"_signature":"pFmY0r7U3Lj5o6MPCPKGLJ1oYnsDTDtemsKuV1vEuxk=","_version":4,"extensions":{"i[…] File : C:\Documents and Settings\GLORIA R\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences Deleted [l.8] : homepage = "hxxps://isearch.avg.com/?cid={D0CDE182-3548-4843-9680-D385AF8DACED}&mid=d384ad5c0[…] Deleted [l.12] : urls_to_restore_on_startup = [ "hxxps://isearch.avg.com/?cid={D0CDE182-3548-4843-9680-D385[…] Deleted [l.217] : homepage = "hxxps://isearch.avg.com/?cid={D0CDE182-3548-4843-9680-D385AF8DACED}&mid=d384ad5c078e[…] Deleted [l.278] : urls_to_restore_on_startup = [ "hxxps://isearch.avg.com/?cid={D0CDE182-3548-4843-9680-D385AF8[…] File : C:\Documents and Settings\NICOLE A\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [13475 octets] - [06/12/2012 21:58:29] ########## EOF - C:\AdwCleaner[S1].txt - [13536 octets] ########## Results from Malwarebytes: Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Database version: v2012.12.07.02 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 YOUNG ONE :: JAMES-91746AC0C [administrator] 12/6/2012 10:08:20 PM mbam-log-2012-12-06 (22-08-20).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 476180 Time elapsed: 22 minute(s), 21 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk (PUP.GamesPlayLab) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) and from ESET: C:\Program Files\AIM\Sysfiles\WxBug.EXE Win32/Adware.WBug.A application C:\System Volume Information\_restore{1E4F9F41-0103-4908-9F6E-E22A5CBFE665}\RP204\A0069093.dll a variant of Win32/Adware.Yontoo.B application C:\System Volume Information\_restore{1E4F9F41-0103-4908-9F6E-E22A5CBFE665}\RP214\A0086879.exe a variant of Win32/SpeedingUpMyPC application C:\System Volume Information\_restore{1E4F9F41-0103-4908-9F6E-E22A5CBFE665}\RP214\A0086932.exe a variant of Win32/SpeedingUpMyPC application C:\System Volume Information\_restore{1E4F9F41-0103-4908-9F6E-E22A5CBFE665}\RP214\A0087340.dll a variant of Win32/Adware.Yontoo.A application C:\System Volume Information\_restore{1E4F9F41-0103-4908-9F6E-E22A5CBFE665}\RP214\A0087341.dll a variant of Win32/Adware.Yontoo.A application C:\System Volume Information\_restore{1E4F9F41-0103-4908-9F6E-E22A5CBFE665}\RP214\A0087343.dll a variant of Win32/Adware.Yontoo.B application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP130\A0042208.exe a variant of Win32/Adware.RegRevive application C:\WINDOWS\Temp\RegistryOptimizer.exe a variant of Win32/SpeedingUpMyPC application
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :files
    C:\Program Files\AIM\Sysfiles\WxBug.EXE 
    C:\WINDOWS\Temp\RegistryOptimizer.exe 
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )





Any more problems?
OTL froze on me so I had to run in Safe Mode. Seems to lag the system down after the reboot but then everything was normal. All processes killed ========== SERVICES/DRIVERS ========== ========== FILES ========== c:\program files\aim\sysfiles\WxBug.EXE moved successfully. c:\windows\temp\RegistryOptimizer.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 56468 bytes User: Administrator.JAMES-91746AC0C ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 470 bytes User: All Users ->Flash cache emptied: 35 bytes User: All Users.WINXP ->Flash cache emptied: 43 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 56468 bytes User: Default User.WINXP ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: DELL ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 56468 bytes User: GLORIA R ->Temp folder emptied: 9971655 bytes ->Temporary Internet Files folder emptied: 140603653 bytes ->FireFox cache emptied: 4767160 bytes ->Google Chrome cache emptied: 6631791 bytes ->Flash cache emptied: 9441 bytes User: GLORIA YOUNG ->Temp folder emptied: 25698750 bytes ->Temporary Internet Files folder emptied: 111698398 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 18545 bytes User: JAMES YOUNG ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 5544650 bytes ->Java cache emptied: 97085 bytes ->Google Chrome cache emptied: 7249180 bytes ->Apple Safari cache emptied: 21889024 bytes ->Flash cache emptied: 3121011 bytes User: LocalService ->Temp folder emptied: 65984 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService.NT AUTHORITY ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 318569509 bytes ->Java cache emptied: 12 bytes ->Flash cache emptied: 13167 bytes User: NetworkService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NICOLE A ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 5537862 bytes ->FireFox cache emptied: 8859668 bytes ->Google Chrome cache emptied: 6467716 bytes ->Apple Safari cache emptied: 2201600 bytes ->Flash cache emptied: 1093 bytes User: NICOLE YOUNG ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 6103 bytes User: YOUNG ONE ->Temp folder emptied: 20924210 bytes ->Temporary Internet Files folder emptied: 58428514 bytes ->FireFox cache emptied: 28832351 bytes ->Google Chrome cache emptied: 82086225 bytes ->Flash cache emptied: 108530 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 234 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 1458 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 830.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 12072012_230844 Files\Folders moved on Reboot… PendingFileRenameOperations files… Registry entries deleted on Reboot…
You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.













Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI