This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC running slow and some wierd ads [Solved]

90 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I know this is going to be a long post, but it's not as bad as it looks. I'm not seeing anthing directly but that doesn't mean there isn't something hiding that we just aren't seeing. Obviously, if you are getting the ads served up to you, then something is going on. So we are going to do some updates that hopefully will help. There have been several exploits of add-ins lately that can cause this kind of problem. So work your way through this one step at a time. All in all this won't be nearly as bad as it looks from all the instructions, I promise!

Your plugins in Firefox technically look ok, but we do have a few issues. There have been some serious security issues with both Adobe and Java lately. Let's clear your Java cache first then we'll do some updating.

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

ClearJavaCache::


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe. ComboFix may request an update; please allow it.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.



Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 7 and Save it to your Desktop.
  • Scroll down to where it says Java SE 7u15
  • Click the Download button under JRE to the right.
  • Read the License Agreement then select Accept License Agreement
  • Click on the link to download Windows x86 Offline and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-7u15-windows-i586.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are three options in the window to clear the cache - Leave these two Checked
    Trace and Log Files
    Cached Applications and Applets
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.



Update Adobe Reader
There have been updates to Adobe Reader to address security vulnerabilities. You should download the latest version from the Adobe website. Please remove any old version of Adobe reader first, reboot the machine and then install the new version to avoid any potential issues. I've seen a few machines that have had problems from a straight upgrade.



Update Adobe Flash
There have been updates to Adobe Flash to address security vulnerabilities. You should download the latest version from the Adobe Flash downloads. There should be no need to uninstall anything first on this one. Just a straight update should be fine.


You have a large number of trusted items in your Internet Explorer trusted zones. If you allowed them there, then that is fine. If however, you don't remember allowing those items then I'd like you to do the following:

Reset Internet Explorer Trusted Domains

Launch Notepad (Start>All Programs>Accessories)
Copy/paste all all of the code in the box below to it. Don't forget to include Windows Registry Editor Version 5.00.
Save in: Desktop
File Name: ResetTrusted.reg
Save as Type: All files
Click Save

Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains]

Make sure all your browsers are closed before running the fix. On the desktop, doubleclick ResetTrusted.reg and allow it to run. When prompted, let it merge.

After running the fix, please reboot the computer and then see if the problem persists. Please let me know.





I'm a little hesitant about the Facebook plugin that you have installed for Firefox. Are you using the extra features in Facebook that it provides? If not, I have seen Facebook add-in's that serve up unwanted ads before. Technically, the plugin is legit, but if you aren't using the features we may want to think about getting rid of it.

I also noticed that while you have the HP smart web printing installed. It's a hidden extension, but typically when I've seen that there have been more entries involved. Is it functioning properly? If it is, that's fine. If not, maybe we should remove that entry too.

Let me know about those things as well as doing the updates above.
Hi Doris, I think that I've done everything correctly. At the end of your post you ask about Facebook and HP add ons. I'm fine to delete any of that stuff… I just don't know how. Here's the log that you asked for:

ComboFix 13-02-26.01 - Dave 02/28/2013 10:01:25.5.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3062.1614 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Dave\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Dave\AppData\Local\assembly\tmp
.
.
((((((((((((((((((((((((( Files Created from 2013-01-28 to 2013-02-28 )))))))))))))))))))))))))))))))
.
.
2013-02-28 18:16 . 2013-02-28 18:16 ——– d—–w- c:\users\Public\AppData\Local\temp
2013-02-28 18:16 . 2013-02-28 18:16 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-02-28 18:16 . 2013-02-28 18:16 ——– d—–w- c:\users\Administrator\AppData\Local\temp
2013-02-27 22:34 . 2013-02-27 22:34 ——– d—–w- C:\FRST
2013-02-27 21:48 . 2013-02-27 21:48 ——– d—–w- c:\users\Dave\AppData\Local\Proxure
2013-02-27 21:46 . 2013-02-27 21:46 ——– d—–w- c:\programdata\ClubSanDisk
2013-02-27 20:42 . 2013-02-08 00:45 6954968 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{34D6AF83-FC4D-4C65-A98C-504FAE342B88}\mpengine.dll
2013-02-27 02:03 . 2013-02-08 00:45 6954968 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-02-19 11:07 . 2013-01-08 22:01 768000 —-a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-19 04:22 . 2013-01-04 03:00 2347008 —-a-w- c:\windows\system32\win32k.sys
2013-02-19 04:22 . 2013-01-05 05:00 3967848 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-02-19 04:22 . 2013-01-05 05:00 3913064 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-02-19 04:22 . 2013-01-03 05:05 1293672 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-02-19 04:22 . 2013-01-03 05:04 187752 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-19 04:22 . 2013-01-04 04:50 169984 —-a-w- c:\windows\system32\winsrv.dll
2013-02-15 22:31 . 2013-02-15 22:31 186432 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2013-02-15 22:31 . 2013-02-15 22:31 186432 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
2013-02-12 06:49 . 2013-02-12 06:49 ——– d—–w- c:\program files\ESET
2013-02-12 05:50 . 2013-02-12 05:50 ——– d—–w- c:\windows\ERUNT
2013-02-12 05:50 . 2013-02-12 05:52 ——– d—–w- C:\JRT
2013-02-08 07:51 . 2013-02-08 07:51 ——– d—–w- c:\users\Dave\AppData\Local\LogMeIn
2013-02-08 07:51 . 2013-01-26 00:37 53096 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2013-02-08 07:51 . 2013-01-26 00:37 31592 —-a-w- c:\windows\system32\LMIport.dll
2013-02-08 07:51 . 2013-01-26 00:37 84352 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2013-02-08 07:51 . 2012-11-29 19:56 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2013-02-08 07:51 . 2013-01-26 00:37 92520 —-a-w- c:\windows\system32\LMIinit.dll
2013-02-08 07:51 . 2013-02-28 11:22 ——– d—–w- c:\programdata\LogMeIn
2013-02-08 07:50 . 2013-02-08 07:55 ——– d—–w- c:\program files\LogMeIn
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-27 20:25 . 2012-03-31 19:00 691568 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-27 20:25 . 2011-06-23 17:40 71024 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-30 10:53 . 2010-01-25 02:56 232336 ——w- c:\windows\system32\MpSigStub.exe
2013-01-20 23:59 . 2013-01-20 23:59 195296 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2013-01-20 23:59 . 2012-03-21 03:44 100328 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-12-16 14:13 . 2012-12-24 06:08 295424 —-a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-24 06:08 34304 —-a-w- c:\windows\system32\atmlib.dll
2012-12-15 00:49 . 2010-02-08 18:25 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-12-07 12:26 . 2013-01-09 10:53 308736 —-a-w- c:\windows\system32\Wpc.dll
2012-12-07 12:20 . 2013-01-09 10:53 2576384 —-a-w- c:\windows\system32\gameux.dll
2012-12-07 10:46 . 2013-01-09 10:53 43520 —-a-w- c:\windows\system32\csrr.rs
2012-12-07 10:46 . 2013-01-09 10:53 30720 —-a-w- c:\windows\system32\usk.rs
2012-12-07 10:46 . 2013-01-09 10:53 45568 —-a-w- c:\windows\system32\oflc-nz.rs
2012-12-07 10:46 . 2013-01-09 10:53 44544 —-a-w- c:\windows\system32\pegibbfc.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi-pt.rs
2012-12-07 10:46 . 2013-01-09 10:53 23552 —-a-w- c:\windows\system32\oflc.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi-fi.rs
2012-12-07 10:46 . 2013-01-09 10:53 46592 —-a-w- c:\windows\system32\fpb.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi.rs
2012-12-07 10:46 . 2013-01-09 10:53 21504 —-a-w- c:\windows\system32\grb.rs
2012-12-07 10:46 . 2013-01-09 10:53 40960 —-a-w- c:\windows\system32\cob-au.rs
2012-12-07 10:46 . 2013-01-09 10:53 15360 —-a-w- c:\windows\system32\djctq.rs
2012-12-07 10:46 . 2013-01-09 10:53 51712 —-a-w- c:\windows\system32\esrb.rs
2012-12-07 10:46 . 2013-01-09 10:53 55296 —-a-w- c:\windows\system32\cero.rs
2013-02-25 20:22 . 2013-01-10 19:10 263064 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2008-10-24 206112]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-21 719672]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
"cdloader"="c:\users\Dave\AppData\Roaming\mjusbsp\cdloader2.exe" [2010-12-03 50592]
"googletalk"="c:\users\Dave\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-01-25 39408]
"Spotify Web Helper"="c:\users\Dave\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-11-15 1199576]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2012-12-18 16328976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2008-10-24 79136]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"HP LaserJet M1522 MFP Series Fax"="c:\program files\HP\hp LaserJet M1522\hppfaxprintersrv.exe" [2009-09-23 2453504]
"HPUsageTracking"="c:\program files\HP\HP UT\bin\hppusg.exe" [2007-08-31 36864]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2012-12-15 824232]
"LockStatusTray"="c:\windows\LockStatusTray.exe" [2008-02-19 192512]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-23 150528]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552]
"OEM13Mon.exe"="c:\windows\OEM13Mon.exe" [2008-01-08 36864]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-10-06 59240]
"DNS7reminder"="c:\program files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" [2007-04-16 259624]
"Cobian Backup 10 Interface"="c:\program files\Cobian Backup 10\cbInterface.exe" [2010-09-24 3154432]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2009-08-31 996616]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"ToolboxFX"="c:\program files\HP\ToolboxFX\bin\HPTLBXFX.exe" [2010-10-25 58936]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1313640]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-12-12 152544]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2012-11-29 63048]
.
c:\users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\microsoft office\Office14\ONENOTEM.EXE [2011-9-2 227712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-23 270336]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-4-20 813584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 19:28 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux5"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 CrossLoopService;CrossLoop Service;c:\users\Dave\AppData\Local\CrossLoop\CrossLoopService.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [x]
R3 HPFXBULKLEDM;HPFXBULKLEDM;c:\windows\system32\drivers\hppcbulkio.sys [x]
R3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [x]
R3 libusb0;Jawbone LibUsb-Win32 - Kernel Driver 09/22/2011,1.2.5.0;c:\windows\system32\DRIVERS\libusb0.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 SIUSBXP;SIUSBXP;c:\windows\system32\drivers\SiUSBXp.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 Zoho Assist;Zoho Assist;c:\users\Dave\Documents\ZohoMeeting\ZohoMeeting.exe [x]
S0 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [x]
S2 BthFilterHelper;Bluetooth Feature Support;c:\program files\CSR\Vista Profile Pack\BthFilterHelper.exe [x]
S2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service;c:\program files\Cobian Backup 10\cbVSCService.exe [x]
S2 CobianBackup10;Cobian Backup 10;c:\program files\Cobian Backup 10\cbService.exe [x]
S2 DragonSvc;Dragon Service;c:\program files\Common Files\Nuance\dgnsvc.exe [x]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files\HP\HPLaserJetService\HPLaserJetService.exe [x]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [x]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x]
S3 OEM13Vfx;Creative Camera OEM013 Video VFX Driver;c:\windows\system32\DRIVERS\OEM13Vfx.sys [x]
S3 OEM13Vid;Creative Camera OEM013 Driver;c:\windows\system32\DRIVERS\OEM13Vid.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPService REG_MULTI_SZ HPSLPSVC
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-02-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]
.
2013-02-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 20:25]
.
2013-02-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 05:19]
.
2013-02-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 05:19]
.
2013-02-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2557060353-3338967487-1032703843-1000Core.job
- c:\users\Dave\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-25 06:29]
.
2013-02-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2557060353-3338967487-1032703843-1000UA.job
- c:\users\Dave\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-25 06:29]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uStart Page = https://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //FWEvent.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\qln39cgr.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - ExtSQL: !HIDDEN! 2010-08-15 23:37; [removed]; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.download\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariDownload"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.safariextz\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariExtension"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webarchive\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(5616)
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll
.
Completion time: 2013-02-28 10:21:14
ComboFix-quarantined-files.txt 2013-02-28 18:21
ComboFix2.txt 2013-02-26 19:57
ComboFix3.txt 2012-10-26 04:12
.
Pre-Run: 95,909,732,352 bytes free
Post-Run: 96,036,212,736 bytes free
.
- - End Of File - - F0EB5AE7229C619FBCA90FA45D7F8639
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

Firefox::
FF - ProfilePath - c:\users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\qln39cgr.default\
FF - ExtSQL: !HIDDEN! 2010-08-15 23:37; [removed]; c:\program files\hp\digital imaging\smart web printing\MozillaAddOn3

ClearJavaCache::


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe. ComboFix may request an update; please allow it.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


Please reboot the computer and check to see if the ads persist. Please let me know. If they do, can you please tell me if you are using a router?
Hi Doris, I can't recall if I had sent this to you yet. Here is the Combofix log:

ComboFix 13-03-01.01 - Dave 03/01/2013 18:39:05.6.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3062.1590 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Dave\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Dave\AppData\Local\assembly\tmp
c:\users\Dave\AppData\Local\Temp\_MEI51442\_ctypes.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\_elementtree.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\_hashlib.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\_socket.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\_ssl.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\pyexpat.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\pysqlite2._sqlite.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\python26.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\pythoncom26.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\PyWinTypes26.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\select.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\unicodedata.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32api.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32com.shell.shell.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32crypt.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32event.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32file.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32inet.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32pdh.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32process.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32profile.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32security.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32ts.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\windows._cacheinvalidation.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wx._controls_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wx._core_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wx._gdi_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wx._html2.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wx._misc_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wx._windows_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wx._wizard.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wxbase293u_net_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\wxbase293u_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\wxmsw293u_adv_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\wxmsw293u_core_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\wxmsw293u_html_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\wxmsw293u_webview_vc.dll
.
.
((((((((((((((((((((((((( Files Created from 2013-02-02 to 2013-03-02 )))))))))))))))))))))))))))))))
.
.
2013-03-02 02:55 . 2013-03-02 02:55 ——– d—–w- c:\users\Public\AppData\Local\temp
2013-03-02 02:55 . 2013-03-02 02:55 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-03-02 02:55 . 2013-03-02 02:55 ——– d—–w- c:\users\Administrator\AppData\Local\temp
2013-03-01 03:48 . 2013-02-08 00:45 6954968 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AD4A05E8-BF32-4014-9E14-52E7ABF56F14}\mpengine.dll
2013-02-28 22:28 . 2013-02-08 00:45 6954968 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-02-27 22:34 . 2013-02-27 22:34 ——– d—–w- C:\FRST
2013-02-27 21:48 . 2013-02-27 21:48 ——– d—–w- c:\users\Dave\AppData\Local\Proxure
2013-02-27 21:46 . 2013-02-27 21:46 ——– d—–w- c:\programdata\ClubSanDisk
2013-02-19 11:07 . 2013-01-08 22:01 768000 —-a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-19 04:22 . 2013-01-05 05:00 3967848 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-02-19 04:22 . 2013-01-05 05:00 3913064 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-02-19 04:22 . 2013-01-03 05:05 1293672 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-02-19 04:22 . 2013-01-03 05:04 187752 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-15 22:04 . 2013-02-15 22:04 208448 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2013-02-15 22:04 . 2013-02-15 22:04 208448 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
2013-02-12 06:49 . 2013-02-12 06:49 ——– d—–w- c:\program files\ESET
2013-02-12 05:50 . 2013-02-12 05:50 ——– d—–w- c:\windows\ERUNT
2013-02-12 05:50 . 2013-02-12 05:52 ——– d—–w- C:\JRT
2013-02-08 07:51 . 2013-02-08 07:51 ——– d—–w- c:\users\Dave\AppData\Local\LogMeIn
2013-02-08 07:51 . 2013-01-26 00:37 53096 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2013-02-08 07:51 . 2013-01-26 00:37 31592 —-a-w- c:\windows\system32\LMIport.dll
2013-02-08 07:51 . 2013-01-26 00:37 84352 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2013-02-08 07:51 . 2012-11-29 19:56 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2013-02-08 07:51 . 2013-01-26 00:37 92520 —-a-w- c:\windows\system32\LMIinit.dll
2013-02-08 07:51 . 2013-03-01 14:55 ——– d—–w- c:\programdata\LogMeIn
2013-02-08 07:50 . 2013-02-08 07:55 ——– d—–w- c:\program files\LogMeIn
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-28 19:16 . 2012-03-31 19:00 691568 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-28 19:16 . 2011-06-23 17:40 71024 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-28 18:55 . 2013-02-28 18:56 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-02-28 18:55 . 2012-06-01 19:57 861088 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-02-28 18:55 . 2010-05-10 16:51 782240 —-a-w- c:\windows\system32\deployJava1.dll
2013-01-30 10:53 . 2010-01-25 02:56 232336 ——w- c:\windows\system32\MpSigStub.exe
2013-01-20 23:59 . 2013-01-20 23:59 195296 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2013-01-20 23:59 . 2012-03-21 03:44 100328 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2013-01-13 19:53 . 2013-02-28 11:01 207872 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-01-13 19:53 . 2013-02-28 11:01 187392 —-a-w- c:\windows\system32\UIAnimation.dll
2013-01-13 19:43 . 2013-02-28 11:01 1230336 —-a-w- c:\windows\system32\WindowsCodecs.dll
2013-01-13 19:02 . 2013-02-28 11:01 417792 —-a-w- c:\windows\system32\WMPhoto.dll
2013-01-13 18:34 . 2013-02-28 11:01 364544 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2013-01-13 17:26 . 2013-02-28 11:01 1158144 —-a-w- c:\windows\system32\XpsPrint.dll
2013-01-08 22:03 . 2013-02-19 11:08 1129472 —-a-w- c:\windows\system32\wininet.dll
2013-01-08 21:58 . 2013-02-19 11:08 420864 —-a-w- c:\windows\system32\vbscript.dll
2013-01-04 04:50 . 2013-02-19 04:22 169984 —-a-w- c:\windows\system32\winsrv.dll
2013-01-04 03:00 . 2013-02-19 04:22 2347008 —-a-w- c:\windows\system32\win32k.sys
2012-12-16 14:13 . 2012-12-24 06:08 295424 —-a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-24 06:08 34304 —-a-w- c:\windows\system32\atmlib.dll
2012-12-15 00:49 . 2010-02-08 18:25 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-12-07 12:26 . 2013-01-09 10:53 308736 —-a-w- c:\windows\system32\Wpc.dll
2012-12-07 12:20 . 2013-01-09 10:53 2576384 —-a-w- c:\windows\system32\gameux.dll
2012-12-07 10:46 . 2013-01-09 10:53 43520 —-a-w- c:\windows\system32\csrr.rs
2012-12-07 10:46 . 2013-01-09 10:53 30720 —-a-w- c:\windows\system32\usk.rs
2012-12-07 10:46 . 2013-01-09 10:53 45568 —-a-w- c:\windows\system32\oflc-nz.rs
2012-12-07 10:46 . 2013-01-09 10:53 44544 —-a-w- c:\windows\system32\pegibbfc.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi-pt.rs
2012-12-07 10:46 . 2013-01-09 10:53 23552 —-a-w- c:\windows\system32\oflc.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi-fi.rs
2012-12-07 10:46 . 2013-01-09 10:53 46592 —-a-w- c:\windows\system32\fpb.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi.rs
2012-12-07 10:46 . 2013-01-09 10:53 21504 —-a-w- c:\windows\system32\grb.rs
2012-12-07 10:46 . 2013-01-09 10:53 40960 —-a-w- c:\windows\system32\cob-au.rs
2012-12-07 10:46 . 2013-01-09 10:53 15360 —-a-w- c:\windows\system32\djctq.rs
2012-12-07 10:46 . 2013-01-09 10:53 51712 —-a-w- c:\windows\system32\esrb.rs
2012-12-07 10:46 . 2013-01-09 10:53 55296 —-a-w- c:\windows\system32\cero.rs
2013-02-25 20:22 . 2013-01-10 19:10 263064 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2008-10-24 206112]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-21 719672]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
"cdloader"="c:\users\Dave\AppData\Roaming\mjusbsp\cdloader2.exe" [2010-12-03 50592]
"googletalk"="c:\users\Dave\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-01-25 39408]
"Spotify Web Helper"="c:\users\Dave\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-11-15 1199576]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2012-12-18 16328976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2008-10-24 79136]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"HP LaserJet M1522 MFP Series Fax"="c:\program files\HP\hp LaserJet M1522\hppfaxprintersrv.exe" [2009-09-23 2453504]
"HPUsageTracking"="c:\program files\HP\HP UT\bin\hppusg.exe" [2007-08-31 36864]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2012-12-15 824232]
"LockStatusTray"="c:\windows\LockStatusTray.exe" [2008-02-19 192512]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-23 150528]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552]
"OEM13Mon.exe"="c:\windows\OEM13Mon.exe" [2008-01-08 36864]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-10-06 59240]
"DNS7reminder"="c:\program files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" [2007-04-16 259624]
"Cobian Backup 10 Interface"="c:\program files\Cobian Backup 10\cbInterface.exe" [2010-09-24 3154432]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2009-08-31 996616]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"ToolboxFX"="c:\program files\HP\ToolboxFX\bin\HPTLBXFX.exe" [2010-10-25 58936]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1313640]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-12-12 152544]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2012-11-29 63048]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352]
.
c:\users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\microsoft office\Office14\ONENOTEM.EXE [2011-9-2 227712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-23 270336]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-4-20 813584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 19:28 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux5"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [x]
R3 HPFXBULKLEDM;HPFXBULKLEDM;c:\windows\system32\drivers\hppcbulkio.sys [x]
R3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [x]
R3 libusb0;Jawbone LibUsb-Win32 - Kernel Driver 09/22/2011,1.2.5.0;c:\windows\system32\DRIVERS\libusb0.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 SIUSBXP;SIUSBXP;c:\windows\system32\drivers\SiUSBXp.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 Zoho Assist;Zoho Assist;c:\users\Dave\Documents\ZohoMeeting\ZohoMeeting.exe [x]
S0 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [x]
S2 BthFilterHelper;Bluetooth Feature Support;c:\program files\CSR\Vista Profile Pack\BthFilterHelper.exe [x]
S2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service;c:\program files\Cobian Backup 10\cbVSCService.exe [x]
S2 CobianBackup10;Cobian Backup 10;c:\program files\Cobian Backup 10\cbService.exe [x]
S2 CrossLoopService;CrossLoop Service;c:\users\Dave\AppData\Local\CrossLoop\CrossLoopService.exe [x]
S2 DragonSvc;Dragon Service;c:\program files\Common Files\Nuance\dgnsvc.exe [x]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files\HP\HPLaserJetService\HPLaserJetService.exe [x]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [x]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x]
S3 OEM13Vfx;Creative Camera OEM013 Video VFX Driver;c:\windows\system32\DRIVERS\OEM13Vfx.sys [x]
S3 OEM13Vid;Creative Camera OEM013 Driver;c:\windows\system32\DRIVERS\OEM13Vid.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPService REG_MULTI_SZ HPSLPSVC
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]
.
2013-03-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 19:16]
.
2013-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 05:19]
.
2013-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 05:19]
.
2013-03-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2557060353-3338967487-1032703843-1000Core.job
- c:\users\Dave\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-25 06:29]
.
2013-03-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2557060353-3338967487-1032703843-1000UA.job
- c:\users\Dave\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-25 06:29]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uStart Page = https://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
FF - ProfilePath - c:\users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\qln39cgr.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - ExtSQL: !HIDDEN! 2010-08-15 23:37; [removed]; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.download\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariDownload"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML".
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.safariextz\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariExtension"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webarchive\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(5432)
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\System32\WUDFHost.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Microsoft IntelliPoint\dpupdchk.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Microsoft Office\Office14\OUTLOOK.EXE
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2013-03-01 19:10:01 - machine was rebooted
ComboFix-quarantined-files.txt 2013-03-02 03:09
ComboFix2.txt 2013-02-28 18:21
ComboFix3.txt 2013-02-26 19:57
ComboFix4.txt 2012-10-26 04:12
.
Pre-Run: 97,701,236,736 bytes free
Post-Run: 98,030,432,256 bytes free
.
- - End Of File - - 861DE45276396E3BA824DF20A2F6FCA6

And yes, I am using a router.
There is a small chance it couldl be a router infection causing the problem, but I'd really expect the ads on all browsers, not just one. Let's go ahead and reset your router to be safe anyway though. After resetting, please test all the different browsers for a few minutes and just make sure Firefox is the only one that seems to have the problem please, or see if the problem is resolved.

I would like to have you reset your router. Most routers have a reset pin hole on the back.

1. With the unit on, place an straightend paperclip into the hole on the back on the unit labeled Reset.
2. Hold the paperclip/reset down for 10 seconds and then release it.
3. The unit will reboot on its own.
4. As soon as the lights stop blinking, the unit is ready.
5. You may need to reinstall the router to regain your internet access.

Note: If you changed your password, it will be gone so refer to your user's guide for your router.

If you have not already done so after doing this, please go into your router's settings and change the default password to a stronger one.


If the problem persists, let's get another scan from a different tool that let's me look in some addition places:

Since I'm not seeing anything in the logs we are using, let's get a more detailed scan from another diagnostic tool. Again, this isn't going to fix anything, but it will give me a much more detailed report of possible locations something may be hiding. If the report is too long for one post, feel free to break it up into two separate posts, that's just fine.

OTL Custom Scan

  • Download OTL to your desktop.
  • Right-click and choose Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    services.*
    /md5stop
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.

Hi Doris, I'm sorry but I was on travel. Is there any way that we can pick up the project? I have done the testing and have the logs.

Here's the log info that you requested:

OTL logfile created on: 3/13/2013 6:08:36 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dave\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.99 Gb Total Physical Memory | 1.39 Gb Available Physical Memory | 46.49% Memory free
5.98 Gb Paging File | 3.39 Gb Available in Paging File | 56.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.29 Gb Total Space | 89.05 Gb Free Space | 30.89% Space Free | Partition Type: NTFS
Drive E: | 14.90 Gb Total Space | 14.55 Gb Free Space | 97.66% Space Free | Partition Type: FAT32

Computer Name: DAVE-PC | User Name: Dave | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Dave\Desktop\OTL.exe (OldTimer Tools)
PRC - c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Google\Drive\googledrivesync.exe (Google)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Users\Dave\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\microsoft office\Office14\MSOSYNC.EXE (Microsoft Corporation)
PRC - C:\Program Files\microsoft office\Office14\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe (Google)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe (HP)
PRC - C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Cobian Backup 10\cbInterface.exe (Luis Cobian, CobianSoft)
PRC - C:\Program Files\Cobian Backup 10\cbService.exe (Luis Cobian, CobianSoft)
PRC - C:\Program Files\Cobian Backup 10\cbVSCService.exe (CobianSoft, Luis Cobian)
PRC - C:\Program Files\Common Files\Nuance\dgnsvc.exe (Nuance Communications, Inc.)
PRC - C:\Users\Dave\AppData\Local\CrossLoop\CrossLoopService.exe (CrossLoop Inc)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Windows\LockStatusTray.exe (Logitech, Inc.)
PRC - C:\Windows\OEM13Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\HP\HP UT\bin\hppusg.exe ()
PRC - C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation)
PRC - C:\Users\Dave\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
PRC - C:\Program Files\CSR\Vista Profile Pack\BthFilterHelper.exe (CSR, plc)


========== Modules (No Company Name) ==========

MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\win32api.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\_elementtree.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\_socket.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\win32ts.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\windows._cacheinvalidation.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\wx._gdi_.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\pysqlite2._sqlite.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\win32com.shell.shell.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\pyexpat.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\wx._html2.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\win32crypt.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\pythoncom26.dll ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\_ctypes.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\win32profile.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\wx._misc_.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\win32security.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\PyWinTypes26.dll ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\wx._core_.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\_ssl.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\_hashlib.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\win32process.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\win32pdh.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\wx._windows_.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\wx._wizard.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\win32file.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\win32inet.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\wx._controls_.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\unicodedata.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\win32event.pyd ()
MOD - C:\Users\Dave\AppData\Local\Temp\_MEI48602\select.pyd ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\7366a39c36523a084bc11c230929ff92\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\7ff638de44686eab4afaa8b3c8a9cfca\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\4976e150a5d096db3981d4d56dda5a8e\System.Deployment.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Extensibility\40ae80b5416554417d40f6fd4df4c62a\Extensibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\eb4fa29ea9ab56d453b36696edbe6423\System.Runtime.Serialization.Formatters.Soap.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\HP\ToolboxFX\bin\NativeUtils.dll ()
MOD - C:\Program Files\microsoft office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Microsoft.Office.Interop.Outlook\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\office\14.0.0.0__71e9bce111e9429c\office.dll ()
MOD - C:\Windows\assembly\GAC\Interop.hpqusg\3.0.0.0__a53cf5803f4c3827\Interop.hpqusg.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Logitech\SetPoint\khalwrapper.dll ()
MOD - C:\Program Files\Lavasoft\Ad-Aware\Resources.dll ()
MOD - C:\Program Files\Lavasoft\Ad-Aware\ShellExt.dll ()
MOD - C:\Program Files\HP\HP UT\bin\HPUsageTracking.dll ()
MOD - C:\Program Files\HP\HP UT\bin\hppusg.exe ()
MOD - C:\Program Files\HP\HP UT\bin\HPToolkit.dll ()
MOD - C:\Program Files\HP\HP UT\bin\Enumeration.dll ()
MOD - C:\Program Files\HP\HP UT\bin\HPTools.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (Zoho Assist) – C:\Users\Dave\Documents\ZohoMeeting\ZohoMeeting.exe ()
SRV - (HP LaserJet Service) – C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (CobianBackup10) – C:\Program Files\Cobian Backup 10\cbService.exe (Luis Cobian, CobianSoft)
SRV - (cbVSCService) – C:\Program Files\Cobian Backup 10\cbVSCService.exe (CobianSoft, Luis Cobian)
SRV - (DragonSvc) – C:\Program Files\Common Files\Nuance\dgnsvc.exe (Nuance Communications, Inc.)
SRV - (CrossLoopService) – C:\Users\Dave\AppData\Local\CrossLoop\CrossLoopService.exe (CrossLoop Inc)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (BthFilterHelper) – C:\Program Files\CSR\Vista Profile Pack\BthFilterHelper.exe (CSR, plc)


========== Driver Services (SafeList) ==========

DRV - (VGPU) – System32\drivers\rdvgkmd.sys File not found
DRV - (tsusbhub) – system32\drivers\tsusbhub.sys File not found
DRV - (Synth3dVsc) – System32\drivers\synth3dvsc.sys File not found
DRV - (dgderdrv) – System32\drivers\dgderdrv.sys File not found
DRV - (catchme) – C:\Users\Dave\AppData\Local\Temp\catchme.sys File not found
DRV - (LMIRfsClientNP) – C:\Windows\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (LMIRfsDriver) – C:\Windows\System32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (SIUSBXP) – C:\Windows\System32\drivers\SiUSBXp.sys (Silicon Laboratories)
DRV - (libusb0) – C:\Windows\System32\drivers\libusb0.sys (http://libusb-win32.sourceforge.net)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (HPFXBULKLEDM) – C:\Windows\System32\drivers\hppcbulkio.sys (Hewlett Packard)
DRV - (FsUsbExDisk) – C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (ssadmdm) – C:\Windows\System32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (ssadbus) – C:\Windows\System32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (ssadmdfl) – C:\Windows\System32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (LMouFilt) – C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (OEM13Vid) – C:\Windows\System32\drivers\OEM13Vid.sys (Creative Technology Ltd.)
DRV - (HPFXFAX) – C:\Windows\System32\drivers\hpfxfax.sys (Hewlett Packard)
DRV - (HPFXBULK) – C:\Windows\System32\drivers\hpfxbulk.sys (Hewlett Packard)
DRV - (OEM13Vfx) – C:\Windows\System32\drivers\OEM13Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (CSRBC) – C:\Windows\System32\drivers\csrbcxp.sys (CSR, plc)
DRV - (O2MDRDR) – C:\Windows\System32\drivers\o2media.sys (O2Micro )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.msn.com/USSMB/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://g.msn.com/USSMB/1
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {90A0F646-00FC-459E-A081-6C88CDAF5D14}
IE - HKCU\..\SearchScopes\{2374376D-5BA2-430B-8F94-7B92B077B364}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3220468
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{90A0F646-00FC-459E-A081-6C88CDAF5D14}: "URL" = http://www.google.com/search?q={searchTerm…1I7WZPC_enUS363
IE - HKCU\..\SearchScopes\{E93DDF9A-9205-45E3-BA73-EBAF3C7FCCC5}: "URL" = http://www.bing.com/search?q={searchTerms}&form;=OSDSRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: %7B5C46D283-ABDE-4dce-B83C-08881401921C%7D:[removed]
FF - prefs.js..extensions.enabledAddons: autofillForms%40blueimp.net:0.9.9.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.15.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.15.2: C:\Program Files\java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@logitech.com/HarmonyRemote,version=1.0.0: C:\Program Files\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2010/06/21 21:44:03 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@doubletwist.com/NPPodcast: C:\Program Files\Common Files\doubleTwist\NPPodcast.dll File not found
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Dave\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Dave\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Dave\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Dave\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Dave\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Dave\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/08/15 23:35:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\fbphotozoom\fbphotozoom13.xpi
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/03/11 09:44:13 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/02/28 12:13:46 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/08/15 23:35:18 | 000,000,000 | —D | M]

[2010/01/24 23:26:39 | 000,000,000 | —D | M] (No name found) – C:\Users\Dave\AppData\Roaming\Mozilla\Extensions
[2010/01/24 22:30:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Dave\AppData\Roaming\Mozilla\Extensions\[removed]
[2013/02/11 22:55:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\qln39cgr.default\extensions
[2012/12/08 16:23:34 | 000,149,045 | —- | M] () (No name found) – C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\qln39cgr.default\extensions\[removed]
[2012/12/05 20:24:47 | 000,213,444 | —- | M] () (No name found) – C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\qln39cgr.default\extensions\[removed]
[2011/10/17 09:48:28 | 000,372,140 | —- | M] () (No name found) – C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\qln39cgr.default\extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}.xpi
[2011/03/31 17:00:05 | 000,002,059 | —- | M] () – C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\qln39cgr.default\searchplugins\daemon-search.xml
[2013/01/10 12:10:09 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/01/10 12:10:09 | 000,000,000 | —D | M] (Click to call with Skype) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/03/11 09:44:13 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/08/29 11:06:15 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/02/25 13:22:23 | 000,002,086 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}
{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://search.conduit.com/?ctid=CT3220468&…SearchSource=48
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Dave\AppData\Local\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Dave\AppData\Local\Google\Chrome\Application\25.0.1364.172\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Dave\AppData\Local\Google\Chrome\Application\25.0.1364.172\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: ActiveTouch General Plugin Container (Enabled) = C:\Users\Dave\AppData\Local\Google\Chrome\Application\plugins\npatgpc.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Dave\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Dave\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Microsoft Lync 2010 Attendee Meeting Join Plug-in (Enabled) = C:\Users\Dave\AppData\Roaming\Mozilla\plugins\npMeetingJoinPluginAOCUser.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Harmony Firefox Plugin (Enabled) = C:\Program Files\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Java™ Platform SE 7 U7 (Disabled) = C:\Program Files\java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\Dave\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll
CHR - plugin: Java Deployment Toolkit 7.0.70.11 (Disabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google Search = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Click to call with Skype = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.8013_0\
CHR - Extension: Docs PDF/PowerPoint Viewer (by Google) = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnbmlagghjjcbdhgmkedmbmedengocbn\3.10_0\
CHR - Extension: Google Chrome to Phone Extension = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco\2.3.1_0\
CHR - Extension: Gmail = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2013/03/01 19:58:45 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\microsoft office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\microsoft office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Cobian Backup 10 Interface] C:\Program Files\Cobian Backup 10\cbInterface.exe (Luis Cobian, CobianSoft)
O4 - HKLM..\Run: [DNS7reminder] C:\Program Files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [HP LaserJet M1522 MFP Series Fax] C:\Program Files\HP\hp LaserJet M1522\hppfaxprintersrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPUsageTracking] C:\Program Files\HP\HP UT\bin\hppusg.exe ()
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LockStatusTray] C:\Windows\LockStatusTray.exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OEM13Mon.exe] C:\Windows\OEM13Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [ToolboxFX] C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation)
O4 - HKCU..\Run: [cdloader] C:\Users\Dave\AppData\Roaming\mjusbsp\cdloader2.exe (magicJack L.P.)
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)
O4 - HKCU..\Run: [googletalk] C:\Users\Dave\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKCU..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\Dave\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKCU..\RunOnce: [HPSoftwareUpdate] C:\Program Files\HP\HP Software Update\hpwucli.exe (Hewlett-Packard)
O4 - Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\microsoft office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\microsoft office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\microsoft office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\microsoft office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\microsoft office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\microsoft office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\microsoft office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6FD2D014-3DEE-49C5-BAC4-5EFC7C823EDC}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{79EE02E4-39BE-4C39-881D-F5B949F8BF5E}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\microsoft office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2011/08/04 18:13:52 | 000,000,110 | -H– | M] () - E:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = ComFile] – Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.divxa32 - C:\Windows\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.pspgru - C:\Windows\System32\PSPGRU.acm (Philips Austria GmbH - Speech Processing)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/03/13 18:05:21 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Dave\Desktop\OTL.exe
[2013/03/01 19:58:50 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2013/03/01 19:36:16 | 000,000,000 | —D | C] – C:\ComboFix
[2013/02/28 11:56:54 | 000,262,560 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2013/02/28 11:56:09 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/02/28 11:56:09 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/02/28 11:56:09 | 000,094,112 | —- | C] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/02/28 11:41:49 | 031,512,992 | —- | C] (Oracle Corporation) – C:\Users\Dave\Desktop\jre-7u15-windows-i586.exe
[2013/02/28 04:01:45 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/02/28 04:01:25 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/02/28 04:01:14 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/02/28 04:01:14 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/02/28 04:01:14 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/02/28 04:01:13 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/02/28 04:01:11 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/02/28 04:01:11 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/02/28 04:01:11 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/02/28 04:01:11 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/02/28 04:01:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/02/28 04:01:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/02/28 04:01:10 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/02/28 04:01:09 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/02/28 04:01:09 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/02/28 04:01:08 | 001,504,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/02/28 04:01:08 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/02/28 04:01:08 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/02/28 04:01:08 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/02/28 04:01:08 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/02/28 04:01:07 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/02/28 04:01:06 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/02/28 04:01:06 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/02/28 04:01:06 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/02/28 04:01:04 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/02/27 15:34:02 | 000,000,000 | —D | C] – C:\FRST
[2013/02/27 14:48:39 | 000,000,000 | —D | C] – C:\Users\Dave\AppData\Local\Proxure
[2013/02/27 14:46:21 | 000,000,000 | —D | C] – C:\ProgramData\ClubSanDisk
[2013/02/26 12:33:06 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/02/26 12:33:06 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/02/26 12:33:06 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/02/26 12:29:26 | 000,000,000 | —D | C] – C:\Qoobox
[2013/02/26 12:25:49 | 005,035,876 | R— | C] (Swearware) – C:\Users\Dave\Desktop\ComboFix.exe
[2013/02/19 04:08:24 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/02/19 04:08:21 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/02/19 04:08:21 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/02/19 04:08:20 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/02/19 04:08:19 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/02/19 04:08:17 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/02/19 04:08:17 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/02/19 04:08:14 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/02/18 21:22:50 | 002,347,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/02/18 21:22:27 | 003,967,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/02/18 21:22:26 | 003,913,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/02/18 21:22:22 | 000,187,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\FWPKCLNT.SYS
[2013/02/18 21:22:18 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2013/02/11 23:49:49 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2013/02/11 23:02:07 | 010,156,424 | —- | C] (Malwarebytes Corporation ) – C:\Users\Dave\Desktop\mbam-setup.exe
[2013/02/11 22:50:57 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/02/11 22:50:27 | 000,000,000 | —D | C] – C:\JRT
[2013/02/11 22:49:46 | 000,547,275 | —- | C] (Oleg N. Scherbakov) – C:\Users\Dave\Desktop\JRT.exe

========== Files - Modified Within 30 Days ==========

[2013/03/13 18:15:03 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/13 18:05:21 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Dave\Desktop\OTL.exe
[2013/03/13 17:26:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2557060353-3338967487-1032703843-1000UA.job
[2013/03/13 17:25:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/13 16:26:00 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2557060353-3338967487-1032703843-1000Core.job
[2013/03/13 12:04:34 | 000,000,181 | —- | M] () – C:\Users\Dave\AppData\Local\CATSWord.ini
[2013/03/13 07:41:36 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/03/12 20:15:00 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/12 12:25:21 | 000,693,976 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/03/12 12:25:21 | 000,073,432 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/03/11 09:44:20 | 000,001,996 | —- | M] () – C:\Users\Dave\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/03/11 09:36:48 | 000,000,472 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2013/03/06 18:09:29 | 000,674,024 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/03/06 18:09:29 | 000,125,122 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/03/05 03:05:56 | 000,013,760 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/05 03:05:56 | 000,013,760 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/02 12:33:24 | 2408,390,656 | -HS- | M] () – C:\hiberfil.sys
[2013/03/01 19:58:45 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2013/03/01 19:34:47 | 005,035,876 | R— | M] (Swearware) – C:\Users\Dave\Desktop\ComboFix.exe
[2013/02/28 23:04:13 | 000,000,987 | —- | M] () – C:\Users\Dave\Desktop\ResetTrusted.reg
[2013/02/28 12:13:46 | 000,001,991 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2013/02/28 11:55:56 | 000,094,112 | —- | M] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/02/28 11:55:54 | 000,861,088 | —- | M] (Oracle Corporation) – C:\Windows\System32\npDeployJava1.dll
[2013/02/28 11:55:54 | 000,782,240 | —- | M] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll
[2013/02/28 11:55:54 | 000,262,560 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2013/02/28 11:55:54 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/02/28 11:55:54 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/02/28 11:41:55 | 031,512,992 | —- | M] (Oracle Corporation) – C:\Users\Dave\Desktop\jre-7u15-windows-i586.exe
[2013/02/27 17:55:00 | 000,004,367 | —- | M] () – C:\Users\Dave\Desktop\DDS results zipped.rar
[2013/02/27 13:50:13 | 000,001,268 | —- | M] () – C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2013/02/27 13:26:53 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2013/02/23 11:41:43 | 000,001,294 | —- | M] () – C:\Users\Dave\Desktop\Party invitees 12-2012 Cleaned up.csv
[2013/02/19 04:37:52 | 000,497,088 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/02/11 23:03:07 | 000,001,073 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/11 23:02:27 | 010,156,424 | —- | M] (Malwarebytes Corporation ) – C:\Users\Dave\Desktop\mbam-setup.exe
[2013/02/11 22:50:26 | 000,547,275 | —- | M] (Oleg N. Scherbakov) – C:\Users\Dave\Desktop\JRT.exe

========== Files Created - No Company Name ==========

[2013/02/28 23:04:13 | 000,000,987 | —- | C] () – C:\Users\Dave\Desktop\ResetTrusted.reg
[2013/02/28 12:13:46 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013/02/28 12:13:46 | 000,001,991 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2013/02/27 17:55:00 | 000,004,367 | —- | C] () – C:\Users\Dave\Desktop\DDS results zipped.rar
[2013/02/27 13:50:13 | 000,001,268 | —- | C] () – C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2013/02/26 12:33:06 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/02/26 12:33:06 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/02/26 12:33:06 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/02/26 12:33:06 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/02/26 12:33:06 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/02/11 23:03:07 | 000,001,073 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/20 09:39:11 | 000,015,688 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2011/08/10 16:30:45 | 000,000,001 | —- | C] () – C:\Users\Dave\AppData\Roaming\FrontEndCD.ini
[2011/07/07 11:42:30 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2011/07/07 11:40:04 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/06/02 15:49:29 | 000,000,495 | —- | C] () – C:\Windows\iScreensaver.ini
[2011/01/30 09:58:37 | 000,014,848 | —- | C] () – C:\Users\Dave\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/03 22:12:22 | 000,000,181 | —- | C] () – C:\Users\Dave\AppData\Local\CATSWord.ini
[2010/10/26 11:29:10 | 000,000,183 | —- | C] () – C:\Users\Dave\AppData\Local\CATSOutlook.ini
[2010/09/28 16:02:35 | 000,003,079 | —- | C] () – C:\Users\Dave\AppData\Roaming\SAS7_000.DAT
[2010/08/23 10:42:48 | 000,038,462 | —- | C] () – C:\Users\Dave\AppData\Roaming\Comma Separated Values (Windows).ADR
[2010/06/08 07:55:04 | 00


——————–
Thanks,

Dpennmaas


Give me a bit to look over this log and I'll be back with you shortly. I'll be glad to leave logs open when you are travelling if you just let me know you'll be away :)
Run OTL.exe by right-clicking and choosing Run as Administrator on the icon.
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    :OTL
    IE - HKCU\..\SearchScopes,DefaultScope = {90A0F646-00FC-459E-A081-6C88CDAF5D14}
    IE - HKCU\..\SearchScopes\{2374376D-5BA2-430B-8F94-7B92B077B364}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3220468
    IE - HKCU\..\SearchScopes\{90A0F646-00FC-459E-A081-6C88CDAF5D14}: "URL" = http://www.google.com/search?q={searchTerm…1I7WZPC_enUS363
    IE - HKCU\..\SearchScopes\{E93DDF9A-9205-45E3-BA73-EBAF3C7FCCC5}: "URL" = http://www.bing.com/search?q={searchTerms}&form=OSDSRC
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [emptyjava]
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the resulting OTL log


This tool does not effectively handle Chrome. The only thing I see there is that you should probably change your homepage away from http://search.conduit.com in Chrome as this is definitely not a site you want to be using as a default search engine. You can do this in your Chrome settings.

Let me know if the ads are still persisting after this fix please.
Hi Doris, here are the new logs… and yes, the problem is persisting in Firefox. And I'm apparently also sending out those spam emails from my [removed] email account. I wonder if you have any insight into that? All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2374376D-5BA2-430B-8F94-7B92B077B364}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2374376D-5BA2-430B-8F94-7B92B077B364}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{90A0F646-00FC-459E-A081-6C88CDAF5D14}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90A0F646-00FC-459E-A081-6C88CDAF5D14}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E93DDF9A-9205-45E3-BA73-EBAF3C7FCCC5}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E93DDF9A-9205-45E3-BA73-EBAF3C7FCCC5}\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Dave ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 418605368 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 429155449 bytes ->Google Chrome cache emptied: 216420407 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 104461 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 19552533 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 154956 bytes Total Files Cleaned = 1,034.00 mb [EMPTYFLASH] User: Administrator User: All Users User: Dave ->Flash cache emptied: 0 bytes User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: Public Total Flash Files Cleaned = 0.00 mb [EMPTYJAVA] User: Administrator User: All Users User: Dave ->Java cache emptied: 0 bytes User: Default User: Default User User: Public Total Java Files Cleaned = 0.00 mb Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.69.0 log created on 03142013_175429 Files\Folders moved on Reboot… C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully. File\Folder C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RM9VQ2HU\86;grp=2925684;grp=1976445;grp=128857;grp=59531;grp=898417;grp=2724480;grp= 42116;grp=1830832;grp=107041;sjt=6;fos=101406;dcopt=ist;extra=null;s=0;ord=814947 912[1].htm not found! C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OBM5M2L6\frame[2].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OBM5M2L6\frame[3].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NEQB24AU\contact-us[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L2ONRFGQ\frame[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JKM2WA5H\cJZKeOuBrn4kERxqtaUH3fY6323mHUZFJMgTvxaG2iE[1].eot moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JKM2WA5H\DXI1ORHCpsQm3Vp6mXoaTXZ2MAKAc2x4R1uOSeegc5U[1].eot moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J5LKK1L3\iframe[1].htm moved successfully. File\Folder C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DT9PB5L8\56;grp=42286;grp=2925684;grp=1976445;grp=128857;grp=59531;grp=898417;grp=27 24480;grp=42116;grp=1830832;grp=107041;sjt=6;fos=101406;extra=null;s=0;ord=814947 912[1].htm not found! File\Folder C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DT9PB5L8\nhome[1].htm not found! C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DT9PB5L8\search[1].htm moved successfully. File\Folder C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B8Q7IYAH\771009[1].htm not found! File\Folder C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B8Q7IYAH\ads[1].htm not found! C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B8Q7IYAH\gplus_notifications_gadget[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B8Q7IYAH\watch[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\66ZFPA6Q\frame[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\66ZFPA6Q\login[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4GDNVEZ9\frame[1].htm moved successfully. PendingFileRenameOperations files… Registry entries deleted on Reboot…
For the spam emails, change your Yahoo password. Let me review the latest Firefox log again. I'm going to take a look at all the items I show that should be ok once again and re-verify those.
Run OTL.exe by right-clicking and choosing Run as Administrator on the icon.
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    :OTL
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\fbphotozoom\fbphotozoom13.xpi
    [2012/12/05 20:24:47 | 000,213,444 | —- | M] () (No name found) – C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\qln39cgr.default\extensions\[removed]
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [emptyjava]
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the resulting OTL log


I'd also recommend adding Ad-block Plus and NoScript to your FireFox.


Please let me know how things are after the fix but before adding Ad-block or NoScript please.
Hi Doris, here is the latest log: All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed] deleted successfully. File C:\Program Files\fbphotozoom\fbphotozoom13.xpi not found. C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\qln39cgr.default\extensions\[removed] moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Dave ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 155557193 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 66822440 bytes ->Google Chrome cache emptied: 34468198 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 2114 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2119276 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 247.00 mb [EMPTYFLASH] User: Administrator User: All Users User: Dave ->Flash cache emptied: 0 bytes User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: Public Total Flash Files Cleaned = 0.00 mb [EMPTYJAVA] User: Administrator User: All Users User: Dave ->Java cache emptied: 0 bytes User: Default User: Default User User: Public Total Java Files Cleaned = 0.00 mb Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.69.0 log created on 03162013_162655 Files\Folders moved on Reboot… C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NK47D8ML\0RJmOgjf3j_1848799865[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NK47D8ML\0RV62QfSEp_1001681529[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NK47D8ML\ads[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NK47D8ML\audmeasure[1].gif moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NK47D8ML\context_sync[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NK47D8ML\pixel[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NK47D8ML\search[2].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NK47D8ML\zrt_lookup[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NIWHLYRV\cl[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NIWHLYRV\cs[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NIWHLYRV\frame[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NIWHLYRV\frame[2].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NIWHLYRV\gplus_notifications_gadget[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NIWHLYRV\p-01-0VIaSjnOLg[1].gif moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEFPXDLE\cl[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEFPXDLE\cms-2c[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEFPXDLE\cms-2c[2].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEFPXDLE\cse[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEFPXDLE\cse[2].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEFPXDLE\ddc[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEFPXDLE\frame[2].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEFPXDLE\frame[3].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEFPXDLE\frame[4].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEFPXDLE\iframe[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEFPXDLE\latest[2].xml moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEFPXDLE\push[1].htm moved successfully. File move failed. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85CNL7PD\445;grp=128857;grp=59531;grp=898417;grp=2724480;grp=42116;grp=1830832;grp=1 07041;sjt=6;fos=101406;uprofile=239140845;company=164367;pcntry=us;ord=1436932004 240[1].htm scheduled to be moved on reboot. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85CNL7PD\bridge_over_troubled_water_crd[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85CNL7PD\fif[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85CNL7PD\frame[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85CNL7PD\visitormatch[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85CNL7PD\watch[1].htm moved successfully. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85CNL7PD\watch[2].htm moved successfully. PendingFileRenameOperations files… Registry entries deleted on Reboot… As of right now, I can't see the crazy ads in Linked IN. Maybe you cured it!!
Fantastic! Let's run another scan to be sure nothing else is lurking around before we clean up our tools.



This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


Go here to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

If it doesn't find anything there will be no log to post.
Hi Doris, Here is what the log stated: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK But there's a window that opened that said Threats found! Infected files=4 Cleaned files=0 C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP277\A0081572.msi a variant of Win32/Bundled.Toolbar.Ask.A application C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP278\A0081612.rbf a variant of Win32/Bundled.Toolbar.Ask.A application C:\Users\Dave\AppData\Roaming\FrostWire\.AppSpecialShare\frostwire-5.0.8.windows.exe multiple threats C:\Users\Dave\Downloads\SoftonicDownloader_for_somud.exe a variant of Win32/SoftonicDownloader.E application And on a seperate subject, I bought a new PC and it looks like it might have the same thing. If that's the case, should I open another case? Thank you! Dave

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI