This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

virus removal tools not working [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

computer is acting odd. the short cuts on the desktop don't respond. i have to start, programs, rt click, and then open. norton says i need to run a scan for viruses, but keeps getting stuck (even though it ran overnight). tried to use my malwarebytes, but when it updated, i got a message "co create instance fault. 0x80040154 Class not registered". Please take a look when you have a chance. Would be much appreciated. Just want to mention that the 2 oti reports listed here were taken within an hour of each other. if that's a problem, i will redo.

OTL logfile created on: 1/19/2013 2:53:29 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Pauline Filighera\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.76 Gb Available Physical Memory | 50.65% Memory free
2.85 Gb Paging File | 2.08 Gb Available in Paging File | 72.81% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.72 Gb Total Space | 29.26 Gb Free Space | 26.19% Space Free | Partition Type: NTFS

Computer Name: FAMILY | User Name: Pauline Filighera | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Pauline Filighera\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Motive\pcCMService.exe (Alcatel-Lucent)
PRC - C:\Program Files\Common Files\Motive\pcServiceHost.exe (Alcatel-Lucent)
PRC - C:\Program Files\Dell V305\dldtmon.exe ()
PRC - C:\Program Files\Dell V305\dldtmsdmon.exe ()
PRC - C:\WINDOWS\SYSTEM32\dldtcoms.exe ( )
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\3add69b075f3da012fb97ce00cd795c0\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Dell V305\dldtmon.exe ()
MOD - C:\Program Files\Dell V305\dldtmsdmon.exe ()
MOD - C:\Program Files\Dell V305\app4r.monitor.core.dll ()
MOD - C:\Program Files\Dell V305\app4r.monitor.common.dll ()
MOD - C:\Program Files\Dell V305\app4r.devmons.mcmdevmon.dll ()
MOD - C:\Program Files\Dell V305\dldtdrs.dll ()
MOD - C:\Program Files\Dell V305\dldtscw.dll ()
MOD - C:\WINDOWS\SYSTEM32\dldtdrs.dll ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\dldtdrpp.dll ()
MOD - C:\Program Files\Dell V305\dldtcaps.dll ()
MOD - C:\Program Files\Dell V305\dldtmonr.dll ()
MOD - C:\WINDOWS\SYSTEM32\dldtcaps.dll ()
MOD - C:\WINDOWS\SYSTEM32\msdmo.dll ()
MOD - C:\WINDOWS\SYSTEM32\DLDTcfg.dll ()
MOD - C:\Program Files\Dell V305\DLDTcfg.dll ()
MOD - C:\Program Files\Dell V305\app4r.devmons.mcmdevmon.autoplayutil.dll ()
MOD - C:\Program Files\Dell V305\dldtcnv4.dll ()
MOD - C:\WINDOWS\SYSTEM32\dldtcnv4.dll ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldtdatr.dll ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldtcats.dll ()


========== Services (SafeList) ==========

SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\6.4.0.9\ccSvcHst.exe (Symantec Corporation)
SRV - (pcCMService) – C:\Program Files\Common Files\Motive\pcCMService.exe (Alcatel-Lucent)
SRV - (pcServiceHost) – C:\Program Files\Common Files\Motive\pcServiceHost.exe (Alcatel-Lucent)
SRV - (dldt_device) – C:\WINDOWS\SYSTEM32\dldtcoms.exe ( )
SRV - (dldtCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\dldtserv.exe ()
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (NMSSvc) – C:\WINDOWS\SYSTEM32\NMSSvc.Exe (Intel Corporation)
SRV - (Bjmcmng) – C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (wanatw) – System32\DRIVERS\wanatw4.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (lbrtfdc) – File not found
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys File not found
DRV - (iAimTV2) – System32\DRIVERS\wATV03nt.sys File not found
DRV - (EL90XBC) – System32\DRIVERS\el90xbc5.sys File not found
DRV - (cpuz134) – C:\DOCUME~1\PAULIN~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys File not found
DRV - (Changer) – File not found
DRV - (bvrp_pci) – File not found
DRV - (ASPI32) – File not found
DRV - (SMR311) – C:\WINDOWS\SYSTEM32\DRIVERS\SMR311.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20130118.022\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20130118.022\NAVENG.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20130111.001\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20130118.001\IDSXpx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0604000.009\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0604000.009\srtspx.sys (Symantec Corporation)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (ccSet_N360) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0604000.009\ccsetx86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0604000.009\symefa.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0604000.009\symtdi.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0604000.009\ironx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0604000.009\symds.sys (Symantec Corporation)
DRV - (mfehidk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys (McAfee, Inc.)
DRV - (gameenum) – C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (LBeepKE) – C:\WINDOWS\SYSTEM32\DRIVERS\LBeepKE.sys (Logitech, Inc.)
DRV - (LHidKe) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidKE.Sys (Logitech, Inc.)
DRV - (LMouKE) – C:\WINDOWS\SYSTEM32\DRIVERS\LMouKE.Sys (Logitech, Inc.)
DRV - (L8042Kbd) – C:\WINDOWS\SYSTEM32\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (cdudf_xp) – C:\WINDOWS\System32\drivers\cdudf_xp.sys (Roxio)
DRV - (UdfReadr_xp) – C:\WINDOWS\System32\drivers\udfreadr_xp.sys (Roxio)
DRV - (pwd_2k) – C:\WINDOWS\System32\drivers\pwd_2K.sys (Roxio)
DRV - (mmc_2K) – C:\WINDOWS\System32\drivers\Mmc_2k.sys (Roxio)
DRV - (dvd_2K) – C:\WINDOWS\System32\drivers\Dvd_2k.sys (Roxio)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Roxio)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Roxio)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (PCDCODEC) – C:\WINDOWS\SYSTEM32\DRIVERS\atinpdxx.sys (ATI Technologies Inc.)
DRV - (MVDCODEC) – C:\WINDOWS\SYSTEM32\DRIVERS\atinmdxx.sys (ATI Technologies Inc.)
DRV - (atinrvxx) – C:\WINDOWS\SYSTEM32\DRIVERS\atinrvxx.sys (ATI Technologies Inc.)
DRV - (ATIXSAudio) – C:\WINDOWS\SYSTEM32\DRIVERS\atinxsxx.sys (ATI Technologies Inc.)
DRV - (ativraxx) – C:\WINDOWS\SYSTEM32\DRIVERS\atinraxx.sys (ATI Technologies Inc.)
DRV - (ATITUNEP) – C:\WINDOWS\SYSTEM32\DRIVERS\atintuxx.sys (ATI Technologies Inc.)
DRV - (NMSCFG) – C:\WINDOWS\SYSTEM32\DRIVERS\NMSCFG.SYS (Intel Corporation)
DRV - (P16X) – C:\WINDOWS\SYSTEM32\DRIVERS\P16X.sys (Creative Technology Ltd.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (LMouFlt2) – C:\WINDOWS\SYSTEM32\DRIVERS\lmouflt2.sys (Logitech)
DRV - (LHidUsb) – C:\WINDOWS\SYSTEM32\DRIVERS\LHIDUSB.SYS (Logitech)
DRV - (LHidFlt2) – C:\WINDOWS\SYSTEM32\DRIVERS\LHIDFLT2.SYS (Logitech)
DRV - (LKbdFlt2) – C:\WINDOWS\SYSTEM32\DRIVERS\lkbdflt2.sys (Logitech)
DRV - (itchfltr) – C:\WINDOWS\SYSTEM32\DRIVERS\itchfltr.sys (Logitech Inc. )
DRV - (PfModNT) – C:\WINDOWS\SYSTEM32\PFMODNT.SYS (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?PC=msnHomeST&OCID;=msnHomepage
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {19B74285-AD12-4EC9-8112-49AAEF4C141D}
IE - HKCU\..\SearchScopes\{19B74285-AD12-4EC9-8112-49AAEF4C141D}: "URL" = http://search.yahoo.com/search?p={searchte…0624,6686,0,8,0
IE - HKCU\..\SearchScopes\{FBAD8B09-36F4-4700-BCC8-38CEB87E85BA}: "URL" = http://www.mysearchresults.com/search?&…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.yahoo.com"
FF - prefs.js..extensions.enabledAddons: %7B635abd67-4fe9-1b23-4f01-e679fa7484c1%7D:2.5.1.20121012015120
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@Motive.com/npMotiveRequest,version=1.0: C:\Program Files\Common Files\Motive\npMotiveRequest.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.10.835: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.1136: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.11.847: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\Documents and Settings\All Users\Application Data\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPlgn\ [2012/09/30 09:25:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\coFFPlgn\ [2013/01/19 14:13:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/18 18:32:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/18 18:31:49 | 000,000,000 | —D | M]

[2012/09/30 10:35:24 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Pauline Filighera\Application Data\Mozilla\Extensions
[2010/01/05 11:36:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Pauline Filighera\Application Data\Mozilla\Extensions\[removed]
[2012/10/23 05:03:48 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Pauline Filighera\Application Data\Mozilla\Firefox\Profiles\2fyzut90.default\extensions
[2012/10/16 19:01:35 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Pauline Filighera\Application Data\Mozilla\Firefox\Profiles\2fyzut90.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2013/01/18 18:31:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/01/18 18:31:35 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\distribution\extensions
[2013/01/18 18:31:40 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2013/01/18 18:32:19 | 000,262,552 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/03/18 13:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/03/18 13:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/10/10 20:05:38 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/06/07 08:43:22 | 000,002,134 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\search.xml
[2012/10/10 20:05:38 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/10/05 22:16:09 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (no name) - {bb46be07-13eb-4c49-b0f0-fc78b9ea4983} - No CLSID value found.
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [dldtamon] C:\Program Files\Dell V305\dldtamon.exe ()
O4 - HKLM..\Run: [dldtmon.exe] C:\Program Files\Dell V305\dldtmon.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL (ATI Technologies Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsupport.com/OneClickFix/tgctlsr.cab (Reg Error: Key error.)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (Reg Error: Key error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/Facebo…toUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab (Reg Error: Key error.)
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} http://community.webshots.com/html/atx/wsaxcontrol.cab (Webshots Multiple Media Uploader - Container)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1349007454890 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} https://www.taxsimple.org/tsweb/msrdp.cab (Microsoft RDP Client Control (redist))
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} http://chat.yahoo.com/cab/yacsui.cab (Yahoo! Audio UI1)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_07)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://128.175.60.37/cam/AxisCamControl.ocx (CamImage Class)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://www.pandasoftware.com/activescan/as5/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} http://community.webshots.com/html/WSPhotoUploader.CAB (Webshots Photo Uploader)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Reg Error: Key error.)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/3.0.1.0…inAxControl.CAB (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DCF18086-0455-491C-B239-FC28ACBF6A2A}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\bw+0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw+0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0 {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0s {d1923cc4-fd50-4f43-9d11-9ae50da3401b} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\mhtml - No CLSID value found
O18 - Protocol\Handler\offline-8876480 {D1923CC4-FD50-4F43-9D11-9AE50DA3401B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\WRNotifier: DllName - (WRLogonNTF.dll) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Pauline Filighera\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Pauline Filighera\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (SsiEfr.e)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ctmp3 - C:\WINDOWS\SYSTEM32\ctmp3.acm (Creative Technology Ltd.)
Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\L3CODECX.ACM (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks, Inc.)
Drivers32: VIDC.DRAW - DVIDEO.DLL File not found
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VCR1 - ATIVCR1.DLL File not found
Drivers32: VIDC.VCR2 - ATIVCR2.DLL File not found
Drivers32: VIDC.YU12 - C:\WINDOWS\System32\atiyuv12.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\atiyuv12.dll ()
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/01/19 14:06:20 | 000,097,440 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SMR311.SYS
[2013/01/19 14:06:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\NPE
[2013/01/18 18:31:32 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/01/06 16:38:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\Application Data\SpeedyPC Software
[2013/01/06 16:38:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\Application Data\DriverCure
[2013/01/06 16:38:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SpeedyPC Software
[2012/12/31 06:22:25 | 000,000,000 | R–D | C] – C:\Documents and Settings\Pauline Filighera\My Documents\HP Photo Creations
[2012/12/31 06:22:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Pauline Filighera\Application Data\Visan
[2012/12/31 06:21:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Visan
[2004/08/13 08:10:01 | 004,354,084 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\All Users\spybotsd13.exe

========== Files - Modified Within 30 Days ==========

[2013/01/19 15:00:00 | 000,000,908 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/19 14:56:00 | 000,000,392 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{05FB7325-A3E5-4A8D-86AB-E2AE041BC2C9}.job
[2013/01/19 14:31:40 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2013/01/19 14:31:35 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2013/01/19 14:17:21 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/01/19 14:10:49 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2013/01/19 14:10:45 | 000,000,904 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/19 14:10:45 | 000,000,418 | —- | M] () – C:\WINDOWS\tasks\ProgramUpdateCheck.job
[2013/01/19 14:09:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2013/01/19 14:09:21 | 1609,613,312 | -HS- | M] () – C:\hiberfil.sys
[2013/01/19 14:06:20 | 000,097,440 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SMR311.SYS
[2013/01/12 17:05:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/01/09 05:17:18 | 000,697,864 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/01/09 05:17:18 | 000,074,248 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/01/09 03:39:50 | 000,276,560 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/01/09 03:23:07 | 000,447,232 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2013/01/09 03:23:07 | 000,073,844 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2013/01/09 03:08:17 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/01/06 00:34:35 | 006,009,856 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2013/01/01 19:56:20 | 000,035,863 | —- | M] () – C:\Documents and Settings\Pauline Filighera\Desktop\PartsListPic.png
[2012/12/26 17:58:08 | 000,099,110 | —- | M] () – C:\Documents and Settings\Pauline Filighera\My Documents\Police Report 12.15.12.pdf
[2012/12/21 07:01:00 | 005,154,221 | —- | M] () – C:\Documents and Settings\Pauline Filighera\Desktop\Casey'sCar.JPG

========== Files Created - No Company Name ==========

[2013/01/09 03:39:46 | 000,993,848 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2013/01/01 19:56:08 | 000,035,863 | —- | C] () – C:\Documents and Settings\Pauline Filighera\Desktop\PartsListPic.png
[2012/12/26 17:58:08 | 000,099,110 | —- | C] () – C:\Documents and Settings\Pauline Filighera\My Documents\Police Report 12.15.12.pdf
[2012/12/21 07:01:00 | 005,154,221 | —- | C] () – C:\Documents and Settings\Pauline Filighera\Desktop\Casey'sCar.JPG
[2012/11/04 09:39:13 | 000,000,142 | —- | C] () – C:\WINDOWS\SoftWriting.ini
[2012/09/15 18:24:03 | 000,027,520 | —- | C] () – C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\dt.dat
[2012/06/06 15:28:12 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dldtvs.dll
[2012/06/06 15:28:10 | 000,360,448 | —- | C] () – C:\WINDOWS\System32\dldtcoin.dll
[2012/06/06 15:27:11 | 000,782,336 | —- | C] () – C:\WINDOWS\System32\dldtdrs.dll
[2012/06/06 15:27:11 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\dldtcaps.dll
[2012/06/06 15:27:11 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\dldtcnv4.dll
[2012/06/06 15:26:29 | 000,017,064 | —- | C] () – C:\WINDOWS\System32\dldtwupd.exe
[2012/06/06 15:26:28 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\dldtwupd.dll
[2012/06/06 15:26:08 | 000,438,272 | —- | C] ( ) – C:\WINDOWS\System32\DLDThcp.dll
[2012/06/06 15:26:08 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\DLDTinst.dll
[2012/06/06 15:26:07 | 000,843,776 | —- | C] ( ) – C:\WINDOWS\System32\dldtusb1.dll
[2012/06/06 15:26:07 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\dldtutil.dll
[2012/06/06 15:26:07 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\dldtinpa.dll
[2012/06/06 15:26:07 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\dldtiesc.dll
[2012/06/06 15:26:06 | 001,105,920 | —- | C] ( ) – C:\WINDOWS\System32\dldtserv.dll
[2012/06/06 15:26:06 | 000,647,168 | —- | C] ( ) – C:\WINDOWS\System32\dldtpmui.dll
[2012/06/06 15:26:06 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\dldtprox.dll
[2012/06/06 15:26:05 | 000,569,344 | —- | C] ( ) – C:\WINDOWS\System32\dldtlmpm.dll
[2012/06/06 15:26:05 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\dldtjswr.dll
[2012/06/06 15:26:04 | 000,663,552 | —- | C] ( ) – C:\WINDOWS\System32\dldthbn3.dll
[2012/06/06 15:26:04 | 000,320,168 | —- | C] ( ) – C:\WINDOWS\System32\dldtih.exe
[2012/06/06 15:26:04 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\dldtinsb.dll
[2012/06/06 15:26:04 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dldtins.dll
[2012/06/06 15:26:04 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dldtinsr.dll
[2012/06/06 15:26:03 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\dldtgrd.dll
[2012/06/06 15:26:03 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dldtcub.dll
[2012/06/06 15:26:03 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\dldtcu.dll
[2012/06/06 15:26:03 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dldtcur.dll
[2012/06/06 15:26:02 | 000,851,968 | —- | C] ( ) – C:\WINDOWS\System32\dldtcomc.dll
[2012/06/06 15:26:02 | 000,594,600 | —- | C] ( ) – C:\WINDOWS\System32\dldtcoms.exe
[2012/06/06 15:26:02 | 000,376,832 | —- | C] ( ) – C:\WINDOWS\System32\dldtcomm.dll
[2012/06/06 15:26:01 | 000,365,224 | —- | C] ( ) – C:\WINDOWS\System32\dldtcfg.exe
[2012/06/06 15:26:01 | 000,077,906 | —- | C] () – C:\WINDOWS\System32\DLDTcfg.dll
[2012/03/24 05:59:35 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2012/03/24 05:59:35 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2012/02/15 19:04:48 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2006/11/13 13:41:20 | 000,001,753 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2004/01/07 20:09:02 | 000,000,140 | —- | C] () – C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\fusioncache.dat
[2003/08/12 08:52:44 | 000,005,120 | —- | C] () – C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2003/05/01 02:54:38 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/08/20 00:30:51 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 07:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/13 19:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/11/08 20:02:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/09/30 08:40:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2010/10/16 07:48:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2003/05/01 02:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2010/10/16 08:37:51 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2006/10/09 15:40:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2012/12/22 08:56:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2012/07/04 12:42:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IsolatedStorage
[2008/01/03 19:32:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2012/09/30 08:39:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/09/30 15:54:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Optimizer Pro
[2008/12/21 18:36:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2013/01/06 16:52:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpeedyPC Software
[2012/11/04 14:31:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ThumbnailCache4R
[2012/12/31 06:22:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visan
[2012/07/04 12:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\White Sky, Inc
[2011/03/07 15:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/18 11:18:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/29 05:39:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/01/17 08:26:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
[2012/06/07 08:45:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\blekkotb_019
[2012/09/30 10:36:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\CallingID
[2003/12/12 17:45:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\Canon
[2012/09/23 08:49:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\Comcast
[2012/09/30 09:16:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\comcasttb
[2013/01/06 16:38:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\DriverCure
[2012/10/06 17:22:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\DVDVideoSoft
[2012/06/10 19:15:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\ElevatedDiagnostics
[2011/11/03 15:40:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\Garmin
[2012/09/30 09:31:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\ID Vault
[2012/09/23 12:04:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\IObit
[2005/06/26 19:02:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\Leadertech
[2007/04/01 15:59:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\Smith Micro
[2013/01/06 16:38:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\SpeedyPC Software
[2013/01/05 17:58:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\TweakNow PowerPack 2011
[2012/12/31 06:22:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\Visan

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EX_ >
[2002/08/29 05:00:00 | 000,351,603 | —- | M] () MD5=2690171B51B4DBA59C02E89DB7FE6C9B – C:\I386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 06:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 02:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: EXPLORER.EXE.000 >
[2004/08/04 02:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe.000

< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2013/01/19 14:10:48 | 000,076,048 | —- | M] () MD5=C07EEFE33C66D0AEDAAD65D235A22B86 – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf

< MD5 for: EXPLORER.SC_ >
[2002/08/29 05:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\I386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2002/09/03 11:32:50 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2002/08/29 05:00:00 | 000,167,956 | —- | M] () MD5=13A43EAD75BC03C50815444AC3018010 – C:\I386\IEXPLORE.CHM
[2009/02/21 00:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/07/17 13:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7(2)\iexplore.chm
[2004/07/17 13:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm
[2004/07/17 13:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ServicePackFiles\i386\iexplore.chm
[2006/09/01 07:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\748dc217ab589bebb960b61219\iexplore.chm
[2006/09/01 07:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.chm

< MD5 for: IEXPLORE.CHW >
[2005/03/16 20:19:12 | 000,185,057 | —- | M] () MD5=248A376A14A92FBF5E94621BAE0771DA – C:\WINDOWS\Help\iexplore.chw

< MD5 for: IEXPLORE.EX_ >
[2002/08/29 05:00:00 | 000,036,925 | —- | M] () MD5=BAC737FDAA9B648A6EBFF76BFAEC7501 – C:\I386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2008/04/13 19:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie8\iexplore.exe
[2008/04/13 19:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\ERDNT\cache\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
[2004/08/04 02:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe

< MD5 for: IEXPLORE.EXE.26E3AD32.INI >
[2005/03/30 09:12:41 | 000,002,215 | —- | M] () MD5=115989149E411B7F664C67B5C668E6F1 – C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\ApplicationHistory\iexplore.exe.26e3ad32.ini

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2006/10/17 12:04:26 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=E83C9C1F9DD9D47BB44871BFC7E69DDD – C:\748dc217ab589bebb960b61219\iexplore.exe.mui
[2006/10/17 12:04:26 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=E83C9C1F9DD9D47BB44871BFC7E69DDD – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.HLP >
[2002/08/29 05:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\I386\IEXPLORE.HLP
[2002/09/03 11:35:04 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2002/08/29 05:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\I386\SERVICES
[2002/08/29 05:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\SYSTEM32\DRIVERS\ETC\SERVICES

< MD5 for: SERVICES.CFG >
[2012/12/18 09:28:18 | 000,558,791 | —- | M] () MD5=A9983CC532F9B3FB1E87918D2313731D – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.EXE >
[2009/02/06 06:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 19:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 19:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\ERDNT\cache\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\SYSTEM32\DLLCACHE\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\SYSTEM32\services.exe
[2004/08/04 02:56:55 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2002/08/29 05:00:00 | 000,101,376 | —- | M] (Microsoft Corporation) MD5=E3DF4A0252D287C44606EE55355E1623 – C:\I386\SERVICES.EXE

< MD5 for: SERVICES.EXE-3019B50A.PF >
[2013/01/19 14:09:51 | 000,019,464 | —- | M] () MD5=5EEB129CC07EE570B09A0A81F6B8526C – C:\WINDOWS\Prefetch\SERVICES.EXE-3019B50A.pf

< MD5 for: SERVICES.LNK >
[2010/02/01 01:00:26 | 000,001,602 | —- | M] () MD5=118593D1EC4924AEE77DB3DFA12559A3 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2002/08/29 05:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\I386\SERVICES.MSC
[2002/09/03 11:59:12 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\SYSTEM32\services.msc

< MD5 for: SERVICES.SWF >
[2001/06/12 22:55:50 | 003,089,990 | —- | M] () MD5=B3C169DBC6A61FEB39E4D9C6DE97F777 – C:\Program Files\EarthLink 5.0\Media\services.swf

< MD5 for: WINLOGON.EXE >
[2004/08/04 02:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2002/08/29 05:00:00 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=2246D8D8F4714A2CEDB21AB9B1849ABB – C:\I386\WINLOGON.EXE
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SYSTEM32\DLLCACHE\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SYSTEM32\winlogon.exe

< MD5 for: WINLOGON.EXE-0957F9B2.PF >
[2013/01/19 14:09:51 | 000,056,854 | —- | M] () MD5=63E7240AAF820C9205168C138D19F570 – C:\WINDOWS\Prefetch\WINLOGON.EXE-0957F9B2.pf

< %SYSTEMDRIVE%\*.* >
[2002/09/03 11:59:19 | 000,245,920 | R— | M] () – C:\$LDR$
[2012/03/21 05:41:32 | 000,033,148 | —- | M] () – C:\aaw7boot.log
[2012/10/06 07:22:20 | 000,004,641 | —- | M] () – C:\AdwCleaner[S1].txt
[2009/08/26 12:40:33 | 000,000,211 | —- | M] () – C:\Boot.bak
[2013/01/19 14:31:35 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2002/09/03 08:38:46 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2012/10/07 07:36:21 | 000,000,143 | —- | M] () – C:\CFScript.txt
[2004/08/03 22:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2002/09/03 08:59:58 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2003/05/01 02:37:38 | 000,005,319 | RH– | M] () – C:\DELL.SDR
[2012/06/06 14:46:03 | 000,000,539 | —- | M] () – C:\dlbt.log
[2013/01/19 14:09:21 | 1609,613,312 | -HS- | M] () – C:\hiberfil.sys
[2009/04/02 05:43:58 | 000,000,404 | —- | M] () – C:\INSTALL.LOG
[2002/09/03 08:59:58 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2003/05/01 03:10:46 | 000,000,501 | -H– | M] () – C:\IPH.PH
[2010/06/13 11:37:07 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2002/09/03 08:59:58 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/09/17 18:37:35 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/10/05 08:34:39 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/01/19 14:09:19 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2001/06/09 14:25:34 | 000,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2010/06/08 15:07:17 | 000,000,449 | —- | M] () – C:\rkill.log
[2010/01/06 17:36:18 | 000,002,239 | —- | M] () – C:\rollback.ini
[2007/12/29 12:30:13 | 000,000,512 | —- | M] () – C:\ScanSectorLog.dat
[2012/11/04 14:56:50 | 000,000,495 | —- | M] () – C:\stub.log
[2005/10/31 10:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
[2003/05/01 03:05:28 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2002/09/03 12:07:44 | 000,441,775 | R— | M] () – C:\txtsetup.sif

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/13 17:46:52 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2002/02/12 00:00:00 | 000,013,824 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD43.DLL
[2002/02/12 00:00:00 | 000,043,008 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP43.DLL
[2009/07/02 06:40:18 | 000,147,968 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\dldtdrpp.dll
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >
[2004/05/18 10:49:54 | 000,000,213 | —- | M] () – C:\Documents and Settings\All Users\Favorites\Yahoo! Bookmarks.url

< %APPDATA%\Microsoft\*.* >
[2005/10/10 12:19:21 | 000,001,546 | -H– | M] () – C:\Documents and Settings\Pauline Filighera\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/13 13:34:48 | 000,262,144 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/13 17:29:24 | 000,524,288 | —- | M] () – C:\WINDOWS\System32\config\security.sav
[2004/08/13 13:34:48 | 021,757,952 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/13 13:34:49 | 006,291,456 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/10/05 08:47:20 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/10/05 13:00:40 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Pauline Filighera\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2003/05/06 11:26:21 | 000,000,079 | —- | M] () – C:\Documents and Settings\Pauline Filighera\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2012/09/23 12:00:33 | 027,669,608 | —- | M] (IObit ) – C:\Documents and Settings\Pauline Filighera\Desktop\asc-setup.exe
[2009/05/28 18:53:20 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Pauline Filighera\Desktop\ATF-Cleaner.exe
[2010/11/26 08:43:36 | 002,963,664 | —- | M] (Piriform Ltd) – C:\Documents and Settings\Pauline Filighera\Desktop\ccsetup301.exe
[2010/06/11 06:20:42 | 000,532,480 | —- | M] (Trend Micro Incorporated) – C:\Documents and Settings\Pauline Filighera\Desktop\cwshredder.exe
[2012/10/13 07:44:35 | 018,494,856 | —- | M] (Mozilla) – C:\Documents and Settings\Pauline Filighera\Desktop\Firefox Setup 16.0.1.exe
[2012/10/06 17:22:16 | 023,152,792 | —- | M] (DVDVideoSoft Ltd. ) – C:\Documents and Settings\Pauline Filighera\Desktop\FreeYouTubeToiPodConverter.exe
[2011/06/26 16:49:50 | 000,371,987 | —- | M] () – C:\Documents and Settings\Pauline Filighera\Desktop\ir.exe
[2009/05/24 13:37:55 | 002,434,880 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Pauline Filighera\Desktop\mbam-rules.exe
[2009/05/28 19:22:12 | 003,371,384 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Pauline Filighera\Desktop\mbam-setup.exe
[2011/10/15 11:13:57 | 009,443,304 | —- | M] (TweakNow.com ) – C:\Documents and Settings\Pauline Filighera\Desktop\PowerPack342.exe
[2011/10/14 14:17:21 | 005,843,472 | —- | M] (TweakNow.com ) – C:\Documents and Settings\Pauline Filighera\Desktop\RegCleaner640.exe
[2010/06/12 12:42:01 | 000,444,416 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Pauline Filighera\Desktop\TFC.exe
[2010/06/11 20:04:47 | 001,968,248 | —- | M] (W3i, LLC) – C:\Documents and Settings\Pauline Filighera\Desktop\tinyzip.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-01-19 08:01:06

========== Alternate Data Streams ==========

@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\All Users\Documents\.DS_Store:AFP_AfpInfo

< End of report >

————————————————————————-
OTL Extras logfile created on: 1/19/2013 1:30:41 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Pauline Filighera\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.77 Gb Available Physical Memory | 51.38% Memory free
2.86 Gb Paging File | 2.04 Gb Available in Paging File | 71.57% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.72 Gb Total Space | 29.14 Gb Free Space | 26.08% Space Free | Partition Type: NTFS

Computer Name: FAMILY | User Name: Pauline Filighera | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.reg [@ = Regedit.Document] – c:\Winnt\Regedit.exe %1

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger – (Logitech)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger – (Microsoft Corporation)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger – (Logitech)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – (Google)
"C:\WINDOWS\SYSTEM32\fxsclnt.exe" = C:\WINDOWS\SYSTEM32\fxsclnt.exe:*:Enabled:Microsoft Fax Console – (Microsoft Corporation)
"C:\WINDOWS\SYSTEM32\dldtcoms.exe" = C:\WINDOWS\SYSTEM32\dldtcoms.exe:*:Enabled:V305 Server – ( )
"C:\Program Files\Dell V305\dldtmon.exe" = C:\Program Files\Dell V305\dldtmon.exe:*:Enabled:Printer Device Monitor – ()
"C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldtpswx.exe" = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldtpswx.exe:*:Enabled:Printer Status Window Interface – ()
"C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldttime.exe" = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldttime.exe:*:Enabled:Time Executable – ()
"C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldtjswx.exe" = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\dldtjswx.exe:*:Enabled:Job Status Window Interface – ()
"C:\Program Files\Dell V305\frun.exe" = C:\Program Files\Dell V305\frun.exe:*:Enabled:Printing Application – ()
"C:\Program Files\Dell V305\dldtlscn.exe" = C:\Program Files\Dell V305\dldtlscn.exe:*:Enabled: – ()
"C:\Program Files\Common Files\Motive\pcServiceHost.exe" = C:\Program Files\Common Files\Motive\pcServiceHost.exe:*:Enabled:pcServiceHost – (Alcatel-Lucent)
"C:\Program Files\File Type Assistant\tsassist.exe" = C:\Program Files\File Type Assistant\tsassist.exe:*:Enabled:ProgramUpdateCheck – (Trusted Software ApS)
"C:\Program Files\Dell V305\Diagnostics\DLDTdiag.exe" = C:\Program Files\Dell V305\Diagnostics\DLDTdiag.exe:*:Enabled: – ()
"C:\Program Files\Dell V305\Wireless\dldtwpss.exe" = C:\Program Files\Dell V305\Wireless\dldtwpss.exe:*:Enabled: – (Lexmark International, Inc.)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01A4AEDE-F219-49A2-B855-16A016EAF9A4}" = Intel® PROSet II
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
"{03F1CC67-5BD8-4C36-8394-76311B2AE69A}" = ArcSoft PhotoStudio 5
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0F6F6876-6334-4977-B5DD-CFC12E193420}" = iTunes
"{1126EA35-9A55-4152-AA35-29865470F172}" = Memory Card Utility
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert
"{1D5355BA-562B-4C29-83C0-1D0ED41B2D87}" = TinyZIP
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{25AF0BD1-DF07-4447-8E91-28E99617C556}" = DeadAIM
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint
"{349BB121-EDE7-4E86-9698-182FC14B84B6}" = DVDDec
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{438D221C-5B5B-4E4B-B7BD-A86512E5B6C1}" = DAO
"{44A537A5-859C-43A6-8285-C0668142A090}" = iPod for Windows 2005-03-23
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = MouseWare 9.41 .3
"{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{64116298-93C5-401D-B06C-39D8E3338508}" = DAO
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77792D6B-6505-4B64-842D-58864D2FA797}" = MMC81
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8 Dell Edition
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARDR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}_STANDARDR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{96E16100-A77F-4B31-B9AD-FFBA040EE1BD}" = Sound Blaster Live!
"{976EA7B1-7562-483D-88DA-4323D263B7CD}" = DiMAGE Viewer
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{99D34763-7E45-4FE5-8424-28DBC3A5F0BF}" = GUIDE PLUS+™ for Windows® System - ATI
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D98F245-3010-43C6-B3B0-67A464DA298E}" = ELNKInst
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1" = Free YouTube Downloader 3.5.128
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.5)
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B94AA0EE-8F75-4773-A25C-E986D94134B2}" = Microsoft RAW Image Thumbnailer and Viewer for Windows XP
"{BC019EBE-613F-491F-9A83-08E3E8A74CE6}" = EarthLink Free Trial
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1D14C0D-FDAA-4DF2-8441-A902805CCE8C}" = ArcSoft PhotoBase 3
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}" = Apple Mobile Device Support
"{D8AC335B-4479-4B88-A6CF-A37C9A25CC8A}" = DiscoverEcon Schiller 9e
"{E3436EE2-D5CB-4249-840B-3A0140CC34C3}" = Classic PhoneTools
"{E56D39F8-2A9F-44B4-B068-A72E45A073E6}" = Safari
"{EE7B9A8D-19F0-450D-8E94-3E391E6044CD}" = KhalSetup
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ATI Display Driver" = ATI Display Driver
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"CCleaner" = CCleaner
"Comcast" = EasySolve
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"Dell V305" = Dell V305
"DivX Player" = DivX Player
"DivX Pro Codec Adware" = DivX Pro Codec Adware
"ie8" = Windows Internet Explorer 8
"InstallShield_{349BB121-EDE7-4E86-9698-182FC14B84B6}" = ATI DVD Decoder [removed]
"InstallShield_{438D221C-5B5B-4E4B-B7BD-A86512E5B6C1}" = DAO
"InstallShield_{44A537A5-859C-43A6-8285-C0668142A090}" = iPod for Windows 2005-03-23
"InstallShield_{523E6F2A-2D59-4D91-90E8-6C49931C9F50}" = iTunes
"InstallShield_{77792D6B-6505-4B64-842D-58864D2FA797}" = ATI Multimedia Center [removed]
"InstallShield_{9D98F245-3010-43C6-B3B0-67A464DA298E}" = Earthlink Installer - uninstall 'Earthlink 5.0' entry first if present
"JetMP3" = JetMP3
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.0.1400
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Microsoft Press Interactive Training" = Microsoft Interactive Training
"Mihov Image Resizer" = Mihov Image Resizer 1.2 (remove only)
"Mozilla Firefox 18.0.1 (x86 en-US)" = Mozilla Firefox 18.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"N360" = Norton Security Suite
"Network Play System (Patching)" = Network Play System (Patching)
"PhotoRecord" = Canon PhotoRecord
"Pixillion" = Pixillion Image Converter
"PROR" = Microsoft Office Professional 2007
"PROSet" = Intel® PRO Ethernet Adapter and Software
"RealPlayer 6.0" = RealOne Player
"Registry Mechanic_is1" = Registry Mechanic 5.1
"Shockwave" = Shockwave
"SimpleOCR 3.1" = SimpleOCR 3.1
"STANDARDR" = Microsoft Office Standard 2007
"Trusted Software Assistant_is1" = File Type Assistant
"Webshots Desktop" = Webshots Desktop
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinMX" = WinMX
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Mail AutoComplete" = Yahoo! Address AutoComplete

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Consumer Input Software" = Consumer Input Software (remove only)

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 1/18/2013 6:43:25 PM | Computer Name = FAMILY | Source = .NET Runtime Optimization Service | ID = 1110
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Service Manager returned a fatal error (0x80004002). Will stop service

Error - 1/19/2013 4:00:59 AM | Computer Name = FAMILY | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft .NET Framework 1.1 – Error 1706.No valid source
could be found for product Microsoft .NET Framework 1.1. The Windows installer
cannot continue.

Error - 1/19/2013 4:01:02 AM | Computer Name = FAMILY | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 1.1 - Update '{6C298884-91FD-408C-9D90-5A59D2C29FD1}'
could not be installed. Error code 1603. Additional information is available in
the log file C:\WINDOWS\TEMP\NDP1.1sp1-KB2742597-X86\NDP1.1sp1-KB2742597-X86-msi.0.log.

Error - 1/19/2013 4:01:03 AM | Computer Name = FAMILY | Source = NativeWrapper | ID = 5000
Description =

Error - 1/19/2013 9:55:48 AM | Computer Name = FAMILY | Source = Application Hang | ID = 1002
Description = Hanging application ccsvchst.exe, version 11.2.3.6, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/19/2013 9:55:50 AM | Computer Name = FAMILY | Source = Application Hang | ID = 1002
Description = Hanging application ccsvchst.exe, version 11.2.3.6, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/19/2013 9:55:56 AM | Computer Name = FAMILY | Source = Application Hang | ID = 1002
Description = Hanging application ccsvchst.exe, version 11.2.3.6, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/19/2013 9:56:48 AM | Computer Name = FAMILY | Source = Application Hang | ID = 1001
Description = Fault bucket -1183152384.

Error - 1/19/2013 9:56:50 AM | Computer Name = FAMILY | Source = Application Hang | ID = 1001
Description = Fault bucket -1183152384.

Error - 1/19/2013 9:56:57 AM | Computer Name = FAMILY | Source = Application Hang | ID = 1001
Description = Fault bucket -1183152384.

[ OSession Events ]
Error - 11/21/2008 5:42:54 PM | Computer Name = FAMILY | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 35194
seconds with 0 seconds of active time. This session ended with a crash.

Error - 2/27/2009 8:31:33 AM | Computer Name = FAMILY | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1284
seconds with 0 seconds of active time. This session ended with a crash.

Error - 11/18/2010 5:05:44 PM | Computer Name = FAMILY | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 93473
seconds with 420 seconds of active time. This session ended with a crash.

Error - 7/3/2011 12:54:42 PM | Computer Name = FAMILY | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 17205
seconds with 0 seconds of active time. This session ended with a crash.

Error - 9/30/2011 6:55:35 AM | Computer Name = FAMILY | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 38
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 1/15/2013 4:21:23 AM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the dldtCATSCustConnectService
service to connect.

Error - 1/15/2013 4:21:23 AM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7000
Description = The dldtCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 1/16/2013 4:02:26 AM | Computer Name = FAMILY | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 1.1 SP1 on
Windows XP, Windows Vista, and Windows Server 2008 x86 (KB2742597).

Error - 1/17/2013 4:02:44 AM | Computer Name = FAMILY | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 1.1 SP1 on
Windows XP, Windows Vista, and Windows Server 2008 x86 (KB2742597).

Error - 1/18/2013 4:02:22 AM | Computer Name = FAMILY | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 1.1 SP1 on
Windows XP, Windows Vista, and Windows Server 2008 x86 (KB2742597).

Error - 1/18/2013 7:53:31 AM | Computer Name = FAMILY | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 1.1 SP1 on
Windows XP, Windows Vista, and Windows Server 2008 x86 (KB2742597).

Error - 1/18/2013 6:43:35 PM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7000
Description = The ASPI32 service failed to start due to the following error: %%2

Error - 1/18/2013 6:43:35 PM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the dldtCATSCustConnectService
service to connect.

Error - 1/18/2013 6:43:35 PM | Computer Name = FAMILY | Source = Service Control Manager | ID = 7000
Description = The dldtCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 1/19/2013 4:02:21 AM | Computer Name = FAMILY | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 1.1 SP1 on
Windows XP, Windows Vista, and Windows Server 2008 x86 (KB2742597).


< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

[external image: Posted Image] Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
the scan twice has gotten stuck and won't proceed from the same spot. i am posting what did get done. i had let it sit for maybe 1/2 hour without any movement . after i post, i will try again, even if i let it sit overnight, but it appears to stop doing anything. aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2013-01-21 17:12:13 —————————– 17:12:13.046 OS Version: Windows 5.1.2600 Service Pack 3 17:12:13.046 Number of processors: 1 586 0x207 17:12:13.046 ComputerName: FAMILY UserName: 17:12:14.312 Initialize success 17:12:39.828 AVAST engine defs: 13012100 17:12:44.859 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 17:12:44.859 Disk 0 Vendor: WDC_WD1200JB-75CRA0 16.06V16 Size: 114440MB BusType: 3 17:12:44.890 Disk 0 MBR read successfully 17:12:44.890 Disk 0 MBR scan 17:12:44.953 Disk 0 Windows XP default MBR code 17:12:44.953 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 39 MB offset 63 17:12:44.984 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 114400 MB offset 80325 17:12:45.000 Disk 0 scanning sectors +234372285 17:12:45.125 Disk 0 scanning C:\WINDOWS\system32\drivers 17:13:16.250 Service scanning 17:13:41.109 Modules scanning 17:14:02.000 Disk 0 trace - called modules: 17:14:02.031 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll intelide.sys PCIIDEX.SYS 17:14:02.531 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a565ab8] 17:14:02.531 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a5cad98] 17:14:03.343 AVAST engine scan C:\WINDOWS 17:14:26.578 AVAST engine scan C:\WINDOWS\system32 17:20:37.312 AVAST engine scan C:\WINDOWS\system32\drivers 17:21:27.187 AVAST engine scan C:\Documents and Settings\Pauline Filighera 17:50:27.906 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Pauline Filighera\My Documents\MBR.dat" 17:50:28.062 The log file has been saved successfully to "C:\Documents and Settings\Pauline Filighera\My Documents\aswMBR.txt" —————————————————-
sorry to post twice. i have been able to finish the scan successfully. i should have been more patient this pm. i know i am only supposed to post once, and wait for a reply. will do so in future. aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2013-01-21 17:57:28 —————————– 17:57:28.156 OS Version: Windows 5.1.2600 Service Pack 3 17:57:28.156 Number of processors: 1 586 0x207 17:57:28.156 ComputerName: FAMILY UserName: 17:57:29.875 Initialize success 17:57:54.765 AVAST engine defs: 13012100 17:58:02.796 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 17:58:02.796 Disk 0 Vendor: WDC_WD1200JB-75CRA0 16.06V16 Size: 114440MB BusType: 3 17:58:02.875 Disk 0 MBR read successfully 17:58:02.875 Disk 0 MBR scan 17:58:02.921 Disk 0 Windows XP default MBR code 17:58:02.921 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 39 MB offset 63 17:58:02.968 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 114400 MB offset 80325 17:58:03.000 Disk 0 scanning sectors +234372285 17:58:03.203 Disk 0 scanning C:\WINDOWS\system32\drivers 17:58:53.812 Service scanning 17:59:21.359 Modules scanning 17:59:58.359 Disk 0 trace - called modules: 17:59:58.406 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll intelide.sys PCIIDEX.SYS 17:59:58.921 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a565ab8] 17:59:58.921 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a5cad98] 17:59:59.468 AVAST engine scan C:\WINDOWS 18:00:45.265 AVAST engine scan C:\WINDOWS\system32 18:12:46.812 AVAST engine scan C:\WINDOWS\system32\drivers 18:14:50.062 AVAST engine scan C:\Documents and Settings\Pauline Filighera 19:42:27.781 AVAST engine scan C:\Documents and Settings\All Users 19:54:53.078 Scan finished successfully 20:50:09.609 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Pauline Filighera\Desktop\MBR.dat" 20:50:09.656 The log file has been saved successfully to "C:\Documents and Settings\Pauline Filighera\Desktop\aswMBR.txt"
Hi,

Good job. :)

[external image: Posted Image] AdwCleaner
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
———-
# AdwCleaner v2.107 - Logfile created 01/22/2013 at 17:41:33 # Updated 21/01/2013 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Pauline Filighera - FAMILY # Boot Mode : Normal # Running from : C:\Documents and Settings\Pauline Filighera\My Documents\Downloads\AdwCleaner(1).exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** ***** [Registry] ***** Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\InstallCore Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} Key Deleted : HKLM\Software\Conduit ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Registry is clean. -\\ Mozilla Firefox v18.0.1 (en-US) File : C:\Documents and Settings\Pauline Filighera\Application Data\Mozilla\Firefox\Profiles\2fyzut90.default\prefs.js [OK] File is clean. ************************* AdwCleaner[S1].txt - [4641 octets] - [06/10/2012 07:10:45] AdwCleaner[S2].txt - [1062 octets] - [22/01/2013 17:41:33] ########## EOF - C:\AdwCleaner[S2].txt - [1122 octets] ##########
Hi,

Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

[external image: Posted Image] Run OTL.exe
  • Copy/paste the following text written inside of the quote box into the Custom Scans/Fixes box located at the bottom of OTL


    :Services

    :OTL
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…rch/search.html
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
    IE - HKCU\..\SearchScopes\{FBAD8B09-36F4-4700-BCC8-38CEB87E85BA}: "URL" = http://www.mysearchresults.com/search?&…q={searchTerms}
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab (Reg Error: Key error.)
    O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
    O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
    [2003/08/12 08:52:44 | 000,005,120 | —- | C] () – C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2012/06/07 08:45:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Pauline Filighera\Application Data\blekkotb_019

    :Files
    ipconfig /flushdns /c

    :Commands
    [emptytemp]
    [resethosts]
    [start explorer]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-

Post the new OTL log and let me know how your system is running now. :)
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\CustomSearch| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FBAD8B09-36F4-4700-BCC8-38CEB87E85BA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FBAD8B09-36F4-4700-BCC8-38CEB87E85BA}\ not found.
Starting removal of ActiveX control {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
C:\WINDOWS\Downloaded Program Files\popcaploader.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}\ not found.
File Animation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab not found.
Starting removal of ActiveX control DirectAnimation Java Classes
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\DirectAnimation Java Classes\ not found.
File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found.
Starting removal of ActiveX control Microsoft XML Parser for Java
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
C:\Documents and Settings\Pauline Filighera\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
C:\Documents and Settings\Pauline Filighera\Application Data\blekkotb_019 folder moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Pauline Filighera\My Documents\Downloads\cmd.bat deleted successfully.
C:\Documents and Settings\Pauline Filighera\My Documents\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Casey

User: Colin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes
->Flash cache emptied: 492 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 49621 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: Owner

User: Pauline Filighera
->Temp folder emptied: 81825364 bytes
->Temporary Internet Files folder emptied: 85059647 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 79490640 bytes
->Flash cache emptied: 12006 bytes

User: TEMP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3266235 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 166377995 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 397.00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.69.0 log created on 01232013_201305

Files\Folders moved on Reboot…
C:\WINDOWS\temp\Perflib_Perfdata_3e0.dat moved successfully.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
——————————————————–
Hey Jeff,

Erunt wouldn't run. I got that coinstance message that i got with malwarebytes ( the reference is in my initial message). I don't know if i mentioned it but most of my desktop icons and also the icons in my start menu are lnk icons now and won't open. i have been going to run…www.yahoo.com to get the internet to open.

otherwise, it runs ok once i get the internet to open.

let me know what you think.

p
Download Windows Repair (all in one) from this site

Install and then run the program.

On the Start Repairs tab, select Advanced Mode and click Start
[external image: Posted Image]


Select all of the items in the screen shot below (the picture below is just an example) and check Restart System When Finished.

[external image: Posted Image]
———-

Let me know if your icons are fixed up now.
JEFF, The icons are fixed! So relieved. Also, norton allowed me to complete a quick scan, which it couldn't complete earlier. I have little faith in norton, though. avg seemed to work better. norton comes w/ my internet provider for no fee and the avg free edition expired. i wonder if i should try that avast? Anyway, let me know if there is anything else I should do. P
Hi,

Glad to hear it seems fixed up. :)

[external image: Posted Image] Malwarebytes

Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-
C:\Documents and Settings\Pauline Filighera\Desktop\FreeYouTubeToiPodConverter.exe Win32/OpenCandy application C:\Documents and Settings\Pauline Filighera\Desktop\tinyzip.exe probably a variant of Win32/InstallIQ application C:\Documents and Settings\Pauline Filighera\My Documents\Downloads\cbsidlm-tr1_7-SimpleOCR-ORG2-10073196.exe Win32/DownloadAdmin.D application C:\Documents and Settings\Pauline Filighera\My Documents\Downloads\FreeYouTubeDownloaderInstaller.exe a variant of Win32/Somoto.A application ——————————————— Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.01.25.01 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Pauline Filighera :: FAMILY [administrator] 1/24/2013 9:03:47 PM mbam-log-2013-01-24 (21-03-47).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 304748 Time elapsed: 17 minute(s), 34 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ————————————————————— Here they are. Let me know what you think when you have a chance to look. p
Hi,

Run the following and let me know how your system is running….

[external image: Posted Image] Run OTL.exe
  • Copy/paste the following text written inside of the quote box into the Custom Scans/Fixes box located at the bottom of OTL


    :Services

    :Files
    C:\Documents and Settings\Pauline Filighera\Desktop\FreeYouTubeToiPodConverter.exe
    C:\Documents and Settings\Pauline Filighera\Desktop\tinyzip.exe
    C:\Documents and Settings\Pauline Filighera\My Documents\Downloads\cbsidlm-tr1_7-SimpleOCR-ORG2-10073196.exe
    C:\Documents and Settings\Pauline Filighera\My Documents\Downloads\FreeYouTubeDownloaderInstaller.exe

    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-
All processes killed ========== SERVICES/DRIVERS ========== ========== FILES ========== C:\Documents and Settings\Pauline Filighera\Desktop\FreeYouTubeToiPodConverter.exe moved successfully. C:\Documents and Settings\Pauline Filighera\Desktop\tinyzip.exe moved successfully. C:\Documents and Settings\Pauline Filighera\My Documents\Downloads\cbsidlm-tr1_7-SimpleOCR-ORG2-10073196.exe moved successfully. C:\Documents and Settings\Pauline Filighera\My Documents\Downloads\FreeYouTubeDownloaderInstaller.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Casey User: Colin ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 235583 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Owner User: Pauline Filighera ->Temp folder emptied: 117219 bytes ->Temporary Internet Files folder emptied: 36817 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 335176184 bytes ->Flash cache emptied: 1580 bytes User: TEMP ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 3190738 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 323.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 01262013_205027 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\Pauline Filighera\Local Settings\Temp\~DF4087.tmp not found! File\Folder C:\Documents and Settings\Pauline Filighera\Local Settings\Temp\~DF409D.tmp not found! C:\Documents and Settings\Pauline Filighera\Local Settings\Temporary Internet Files\Content.Word\~WRS{02BB8FEF-A9F0-4AF0-86BC-060320586253}.tmp moved successfully. File\Folder C:\WINDOWS\temp\Perflib_Perfdata_d0.dat not found! PendingFileRenameOperations files… Registry entries deleted on Reboot… ————————————————————————————– all seems well. let me know if i should abandon norton and pick something else to protect my system. p

all seems well.

:thumbup:
———-

let me know if i should abandon norton and pick something else to protect my system.

If you have a paid subscription for Norton I would continue with it, but when you are finished with it you might try either Microsoft Security Essentials or Avast.
——-

Providing there are no other malware related problems…

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!!

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
———-

Clean up with OTL:
  • Right-click and Run as Administrator OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
———-

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.
If you didn't already have it I would keep Malwarebytes AntiMalware though.


Here are some tips to reduce the potential for spyware infection in the future:

1. Internet Explorer. Even if you don't use it as your main browser it should be kept up-to-date because that is the browser Windows uses for updates.
Make your Internet Explorer more secure
- This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. FireFox. If you use Firefox, I recommend installing the following add-ons to help make your Firefox browser more secure:
NoScript
AdBlock Plus

3. Enable Protected Mode in Internet Explorer. This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps:
  • Open Internet Explorer
  • Click on Tools > Internet Options
  • Press Security tab
  • Select Internet zone then place check next to Enable Protected Mode if not already done
  • Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
  • Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.
4. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

5. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

6. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

7. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

8.Finally, I strongly recommend that you read How to Prevent Malware found here and also PC Safety and Security - What Do I Need?.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI