This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Crashes and BSOD Appears [Closed]

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:56:35 PM, on 4/16/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe
C:\Documents and Settings\All Users\Application Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe
C:\Documents and Settings\Mommy\Application Data\DefaultTab\DefaultTab\DTUpdate.exe
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\Program Files\AVG\AVG2013\avgemcx.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Mommy\Forefront UAG Remote Access Agent\dhssharearkansasgov\sharepoint1\uagqecsvc.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Documents and Settings\All Users\Application Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Documents and Settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Mommy\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-search.com/?affID=119776&…000002275385e82
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchab.com/?aff=7&uid=07961db…a9-002275385e82
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, optimized for Bing and MSN
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: IncrediMail MediaBar 2 Toolbar - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files\IncrediMail_MediaBar_2\prxtbInc0.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Web Assistant Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (file missing)
O2 - BHO: EpicPlay - {56E4076B-A42B-4745-BA35-34DA8AC4C2F2} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: DefaultTabBHO - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Documents and Settings\Mommy\Application Data\DefaultTab\DefaultTab\DefaultTabBHO.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
O2 - BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.10.0\bh\delta.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll
O2 - BHO: IncrediMail MediaBar 2 - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files\IncrediMail_MediaBar_2\prxtbInc0.dll
O2 - BHO: WeCareReminder - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: IncrediMail MediaBar 2 Toolbar - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files\IncrediMail_MediaBar_2\prxtbInc0.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll" (file missing)
O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.10.0\deltaTlbr.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [B2C_AGENT] C:\Documents and Settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" –auto-start
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [PrivitizeVPN] C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe /autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_11_6_602_171_Plugin.exe -update plugin
O4 - Global Startup: Belkin N Wireless USB Adapter Client Utility.lnk = C:\Program Files\Belkin\F5D8053\v5\Belkinwcui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (file missing)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0\ViProtocol.dll
O20 - AppInit_DLLs: c:\docume~1\alluse~1\applic~1\browse~1\261095~1.52\{c16c1~1\browse~1.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: BrowserProtect - Unknown owner - C:\Documents and Settings\All Users\Application Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe
O23 - Service: DefaultTabUpdate - Unknown owner - C:\Documents and Settings\Mommy\Application Data\DefaultTab\DefaultTab\DTUpdate.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: vToolbarUpdater14.2.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe

–
End of file - 11618 bytes
Hello mt7059wct and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Please run these in the order instructed.

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.
  • run AdwCleaner and select Delete
  • when it has finished it will ask to reboot - allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.
===================================================

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    consrv.dll
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

AdwCleaner log
OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
2 - BHO: (no name) - {56E4076B-A42B-4745-BA35-34DA8AC4C2F2} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-789336058-1390067357-682003330-1004\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [B2C_AGENT] C:\Documents and Settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [PrivitizeVPN] C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe (OOO Industry)
O4 - HKLM..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe" File not found
O4 - HKU\S-1-5-21-789336058-1390067357-682003330-1004..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Belkin N Wireless USB Adapter Client Utility.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-789336058-1390067357-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{01980122-CC87-40E2-B33D-EB3BFD304CAD}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (c:\docume~1\alluse~1\applic~1\browse~1\261095~1.52\{c16c1~1\browse~1.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/12/07 18:49:34 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/02/02 22:48:43 | 000,000,045 | R— | M] () - D:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{68b5926b-6598-11e1-ba1c-002275385e82}\Shell - "" = AutoRun
O33 - MountPoints2\{68b5926b-6598-11e1-ba1c-002275385e82}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{68b5926b-6598-11e1-ba1c-002275385e82}\Shell\AutoRun\command - "" = F:\Startme.exe
O33 - MountPoints2\{ae34cbc9-7ab7-11e1-ba45-002275385e82}\Shell - "" = AutoRun
O33 - MountPoints2\{ae34cbc9-7ab7-11e1-ba45-002275385e82}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ae34cbc9-7ab7-11e1-ba45-002275385e82}\Shell\AutoRun\command - "" = F:\setup.exe -a
O33 - MountPoints2\{b26090c1-20e8-11e1-b9ca-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{b26090c1-20e8-11e1-b9ca-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b26090c1-20e8-11e1-b9ca-806d6172696f}\Shell\AutoRun\command - "" = D:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/05/07 10:53:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG
[2013/04/30 12:54:49 | 000,000,000 | —D | C] – C:\Program Files\Gophoto.it
[2013/04/30 12:53:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Mommy\Local Settings\Application Data\Updater21426
[2013/04/30 12:52:58 | 000,000,000 | —D | C] – C:\Program Files\Savings Addon
[2013/04/30 12:44:52 | 000,000,000 | -HSD | C] – C:\WINDOWS\System32\AI_RecycleBin
[2013/04/30 12:44:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Strongvault Online Backup
[2013/04/30 12:44:29 | 000,000,000 | -HSD | C] – C:\AI_RecycleBin
[2013/04/30 12:43:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Flash Player Pro
[2013/04/30 12:43:01 | 000,000,000 | —D | C] – C:\Program Files\Flash Player Pro
[2013/04/30 12:43:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Mommy\My Documents\Flash Player Pro
[2013/04/30 12:41:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Mommy\Start Menu\Programs\PrivitizeVPN
[2013/04/30 12:41:57 | 000,000,000 | —D | C] – C:\Program Files\PrivitizeVPN
[2013/04/26 16:07:48 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/04/18 13:50:11 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Mommy\Desktop\OTL.exe
[2013/04/16 13:55:27 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Mommy\Desktop\HiJackThis.exe
[2013/04/16 13:52:46 | 000,221,184 | R— | C] (Ralink Technology, Inc.) – C:\WINDOWS\System32\RaCoInst.dll
[2013/04/16 13:52:45 | 000,724,736 | R— | C] (Ralink Technology, Corp.) – C:\WINDOWS\System32\drivers\Drt2870.sys
[2013/03/23 15:22:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Mommy\Desktop\Free ed coarse
[2013/03/23 13:57:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Mommy\Desktop\Karens folder
[2013/03/21 15:59:15 | 000,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usb8023x.sys
[2013/03/21 15:59:15 | 000,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usb8023.sys
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/07 10:53:42 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2013.lnk
[2013/05/06 19:58:31 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0F28692D-4FBE-450B-9CCE-4E3531218440}.job
[2013/04/30 12:43:06 | 000,000,778 | —- | M] () – C:\Documents and Settings\Mommy\Desktop\Flash Player Pro.lnk
[2013/04/27 19:36:33 | 000,691,568 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/04/27 19:36:33 | 000,071,024 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/04/18 14:41:16 | 000,002,413 | —- | M] () – C:\WINDOWS\System32\lgAxconfig.ini
[2013/04/18 14:39:26 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/18 14:39:26 | 000,000,324 | —- | M] () – C:\WINDOWS\tasks\YourFile DownloaderUpdate.job
[2013/04/18 14:38:31 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/04/18 14:37:01 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/18 14:35:15 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/04/18 13:50:13 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mommy\Desktop\OTL.exe
[2013/04/18 13:46:11 | 000,613,083 | —- | M] () – C:\Documents and Settings\Mommy\Desktop\adwcleaner.exe
[2013/04/18 13:42:34 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/04/16 14:06:35 | 000,000,036 | —- | M] () – C:\WINDOWS\avgui.INI
[2013/04/16 13:55:28 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Mommy\Desktop\HiJackThis.exe
[2013/04/16 13:53:52 | 000,470,138 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/04/16 13:53:52 | 000,082,010 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/04/13 11:21:44 | 000,002,515 | —- | M] () – C:\Documents and Settings\Mommy\Desktop\Microsoft Office Word 2007.lnk
[2013/04/12 09:24:42 | 001,072,544 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2013/04/12 09:24:42 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2013/04/12 09:24:39 | 001,072,544 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2013/04/12 06:22:57 | 000,165,912 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/04/12 05:51:50 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/04/03 20:19:28 | 000,008,704 | —- | M] () – C:\Documents and Settings\Mommy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/03/30 13:21:40 | 003,687,369 | —- | M] () – C:\Documents and Settings\Mommy\Desktop\ppsspp.apk
[2013/03/24 14:38:57 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/01 08:07:58 | 000,000,324 | —- | C] () – C:\WINDOWS\tasks\YourFile DownloaderUpdate.job
[2013/04/30 12:43:06 | 000,000,778 | —- | C] () – C:\Documents and Settings\Mommy\Desktop\Flash Player Pro.lnk
[2013/04/18 13:46:09 | 000,613,083 | —- | C] () – C:\Documents and Settings\Mommy\Desktop\adwcleaner.exe
[2013/04/16 14:06:35 | 000,000,036 | —- | C] () – C:\WINDOWS\avgui.INI
[2013/04/16 13:52:46 | 000,013,931 | R— | C] () – C:\WINDOWS\System32\RaCoInst.dat
[2013/03/30 13:21:10 | 003,687,369 | —- | C] () – C:\Documents and Settings\Mommy\Desktop\ppsspp.apk
[2012/11/10 15:59:03 | 000,000,061 | —- | C] () – C:\Documents and Settings\Mommy\jagex_cl_runescape_LIVE.dat
[2012/11/10 15:59:03 | 000,000,024 | —- | C] () – C:\Documents and Settings\Mommy\random.dat
[2012/08/13 11:39:18 | 000,027,520 | —- | C] () – C:\Documents and Settings\Mommy\Local Settings\Application Data\dt.dat
[2012/08/01 10:55:58 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CommonDL.dll
[2012/08/01 10:55:58 | 000,002,413 | —- | C] () – C:\WINDOWS\System32\lgAxconfig.ini
[2012/07/03 18:00:22 | 000,008,704 | —- | C] () – C:\Documents and Settings\Mommy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/05/04 17:55:16 | 001,072,544 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2012/05/04 17:55:16 | 001,072,544 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2012/05/04 17:55:16 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2012/03/31 20:35:59 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2012/03/31 15:42:11 | 000,098,344 | —- | C] () – C:\WINDOWS\unTMV.exe
[2012/02/16 13:38:25 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/02/09 22:40:00 | 002,816,504 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2012/01/23 17:45:24 | 000,000,318 | —- | C] () – C:\WINDOWS\wininit.ini
[2012/01/02 12:11:16 | 000,000,064 | —- | C] () – C:\WINDOWS\GPlrLanc.dat
[2011/12/08 20:30:36 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe
[2011/12/08 20:08:27 | 000,180,624 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2011/12/08 20:03:01 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/07 19:21:17 | 000,003,948 | R— | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2011/12/07 18:51:34 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/12/07 18:46:37 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/12/07 10:34:08 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/12/07 10:32:50 | 000,165,912 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== ZeroAccess Check ==========

[2011/12/08 20:06:28 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 19:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 07:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/13 19:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/04 07:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/13 19:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 19:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2004/08/04 07:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/04 07:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/04 07:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: WDC WD16 00AAJS-22WAA SCSI Disk Device
Partitions: 1
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Generic- Multi-Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 149.00GB
Starting Offset: 32256
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction

========== Alternate Data Streams ==========

@Alternate Data Stream - 235 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4C71A42B
@Alternate Data Stream - 234 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D5CCCBAA
@Alternate Data Stream - 232 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:800FE171
@Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B86642C5
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B0456F0C
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C4A588B
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A5948878
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AE75CCC8
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F5E90ED3
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DF19F127
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B3606FCC
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9EF92A1A
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:20EB6823

< End of report >


OTL Extras logfile created on: 4/18/2013 2:45:51 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Mommy\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.42 Mb Total Physical Memory | 460.44 Mb Available Physical Memory | 51.48% Memory free
2.12 Gb Paging File | 1.61 Gb Available in Paging File | 76.19% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 123.99 Gb Free Space | 83.19% Space Free | Partition Type: NTFS
Drive D: | 57.06 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: MOM-38D5EC9FA4D | User Name: Mommy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-789336058-1390067357-682003330-1004\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer
"C:\Program Files\BYOND\bin\byond.exe" = C:\Program Files\BYOND\bin\byond.exe:*:Enabled:byond
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\BYOND\bin\dreamdaemon.exe" = C:\Program Files\BYOND\bin\dreamdaemon.exe:*:Disabled:dreamdaemon
"C:\Program Files\IncrediMail\Bin\IncMail.exe" = C:\Program Files\IncrediMail\Bin\IncMail.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\Bin\ImApp.exe" = C:\Program Files\IncrediMail\Bin\ImApp.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\Bin\ImpCnt.exe" = C:\Program Files\IncrediMail\Bin\ImpCnt.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)
"C:\WINDOWS\system32\javaw.exe" = C:\WINDOWS\system32\javaw.exe:*:Enabled:Java™ Platform SE binary – (Oracle Corporation)
"C:\Program Files\AVG\AVG2013\avgmfapx.exe" = C:\Program Files\AVG\AVG2013\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\CyberStep\GetAmped2_EU\ga2.exe" = C:\CyberStep\GetAmped2_EU\ga2.exe:*:Enabled:GetAmped2 Game Clients – ()
"C:\Program Files\YourFileDownloader\Downloader.exe" = C:\Program Files\YourFileDownloader\Downloader.exe:*:Enabled:YourFile Downloader
"C:\Program Files\YourFileDownloader\YourFile.exe" = C:\Program Files\YourFileDownloader\YourFile.exe:*:Enabled:YourFile Downloader
"C:\Program Files\AVG\AVG2013\avgnsx.exe" = C:\Program Files\AVG\AVG2013\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2013\avgdiagex.exe" = C:\Program Files\AVG\AVG2013\avgdiagex.exe:*:Enabled:AVG Diagnostics 2013 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2013\avgemcx.exe" = C:\Program Files\AVG\AVG2013\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{106B4413-ACBB-4CDE-8707-587DB9BD77EC}" = LogMeIn Hamachi
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{11e38883-6ec3-45c5-8287-5c1ff386f072}" = Buzzluck Casino
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail
"{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}" = Bing Bar
"{1CCF681C-C203-49B3-83F4-A54F0F944416}" = ASPCA TriMini Reminder by We-Care.com v5.0.5.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{241DBC8D-14E3-4240-8EE5-3AC35086B638}" = AVG 2013
"{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = Media Player Classic - Home Cinema v1.5.2.3456
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java™ 6 Update 29
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{297DCADA-86A1-4A42-8A13-66B7D7A09FD2}" = WeatherBug
"{2A3A4BD6-6CE0-4E2A-80D2-1D0FF6ACBFBA}" = LG United Mobile Driver
"{2f81db12-3b72-4740-81bb-f36edec9e70e}" = Lucky Club
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{48A5AB54-6327-43DC-A376-4AC74C5D40B0}" = AVG 2013
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames" = WildTangent Games App
"{788A0222-5690-4212-AA9C-C48FD0E1C9AE}" = Photo Notifier and Animation Creator
"{817662b3-3cff-40a0-97ac-1dc3bc0f14d7}" = WinPalace
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8c1a957c-3450-4960-b966-449e613e7c3c}" = Slot Madness Casino
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARDR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_STANDARDR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90327F59-EBD1-4246-A3F6-FC85C0BDD329}" = Belkin N Wireless USB Adapter Software
"{91120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{930240B3-F09F-4725-8820-7C7480104351}" = AVG 2012
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.02)
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BCF75973-29C2-4245-80E3-B3C2B7E7548B}" = AVG 2012
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3231459-574D-4F76-9F3D-6AA9DFBF1EE5}" = GetAmped2_EU
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"3DiceCasino" = 3Dice Casino
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Agere Systems Soft Modem" = Agere Systems PCI-SV92EX Soft Modem
"AVG" = AVG 2013
"BFG-7 Gates - The Path to Zamolxes" = 7 Gates: The Path to Zamolxes
"BFG-BVS Solitaire Collection" = BVS Solitaire Collection
"BFGC" = Big Fish Games: Game Manager
"BFG-Concentration" = Concentration
"BFG-Crime Solitaire" = Crime Solitaire
"BFG-Fairway" = Fairway™
"BFG-Solitaire Kingdom Quest" = Solitaire Kingdom Quest
"BFG-Solitaire Kingdom Supreme" = Solitaire Kingdom Supreme
"BFG-Solitaire Mystery - Stolen Power" = Solitaire Mystery: Stolen Power
"BFG-Surface - Mystery of Another World Collector's Edition" = Surface: Mystery of Another World Collector's Edition
"BFG-Wonderland Solitaire" = Wonderland Solitaire
"BFG-World Mosaics 5" = World Mosaics 5
"Casino.com" = Casino.com
"EpicPlay" = EpicPlay
"Flash Player Pro_is1" = Flash Player Pro V5.4
"ie8" = Windows Internet Explorer 8
"IncrediMail" = IncrediMail 2.0
"InternetHelper3 Firefox Toolbar" = InternetHelper3 Firefox Toolbar
"LogMeIn Hamachi" = LogMeIn Hamachi
"LSI Soft Modem" = LSI PCI-SV92EX Soft Modem
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 16.0.1 (x86 en-US)" = Mozilla Firefox 16.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"Photo Notifier and Animation Creator" = Photo Notifier and Animation Creator
"PrimoPDF" = PrimoPDF – brought to you by Nitro PDF Software
"PrivitizeVPN" = PrivitizeVPN
"STANDARDR" = Microsoft Office Standard 2007
"Ultimate Solitaire 1000" = Ultimate Solitaire 1000
"VLC media player" = VLC media player 1.1.11
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"WildTangent wildgames Master Uninstall" = WildTangent Games
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.20 (32-bit)
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WTA-d88c0ae6-80d0-4b96-8075-ffa66965cc62" = Diner Dash - Flo Through Time
"WTA-f1be7ce8-f4f1-40e2-9eba-4a46acdfb678" = Cooking Dash
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-789336058-1390067357-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{373B1718-8CC5-4567-8EE2-9033AD08A680}" = Roblox for Mommy
"JoinMe" = join.me
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 3/27/2013 6:15:55 PM | Computer Name = MOM-38D5EC9FA4D | Source = ESENT | ID = 490
Description = svchost (1792) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 3/29/2013 8:42:50 AM | Computer Name = MOM-38D5EC9FA4D | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 19.0.2.4814, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/29/2013 8:42:52 AM | Computer Name = MOM-38D5EC9FA4D | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 19.0.2.4814, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/29/2013 8:43:02 AM | Computer Name = MOM-38D5EC9FA4D | Source = Application Error | ID = 1000
Description = Faulting application plugin-container.exe, version 19.0.2.4814, faulting
module xul.dll, version 19.0.2.4814, fault address 0x0088e70d.

Error - 3/29/2013 2:01:29 PM | Computer Name = MOM-38D5EC9FA4D | Source = uagqecsvc | ID = 16
Description = Microsoft Forefront UAG Quarantine Enforcement Client cannot query
the NAP Agent service's status. System error 1115: A system shutdown is in progress.
(0x45b). The status needs to be queried to detect the NAP Agent's settings due to
the first run of the Microsoft Forefront UAG Quarantine Enforcement Client.

Error - 4/6/2013 7:46:13 AM | Computer Name = MOM-38D5EC9FA4D | Source = MSSHA | ID = 1008
Description = The Windows Security Health Agent failed to complete an offline scan.
Failure
Code: 80248007.

Error - 4/7/2013 10:43:23 PM | Computer Name = MOM-38D5EC9FA4D | Source = MSSHA | ID = 1008
Description = The Windows Security Health Agent failed to complete an offline scan.
Failure
Code: 80248007.
# AdwCleaner v2.200 - Logfile created 04/18/2013 at 14:36:33 # Updated 02/04/2013 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Mommy - MOM-38D5EC9FA4D # Boot Mode : Normal # Running from : C:\Documents and Settings\Mommy\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Deleted on reboot : C:\Documents and Settings\All Users\Application Data\AVG Secure Search Deleted on reboot : C:\Documents and Settings\All Users\Application Data\BrowserProtect Deleted on reboot : C:\Documents and Settings\Mommy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki Deleted on reboot : C:\Documents and Settings\Mommy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla Deleted on reboot : C:\Documents and Settings\Mommy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph Deleted on reboot : C:\Program Files\Common Files\AVG Secure Search File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software\DefaultTab Key Deleted : HKCU\Software\AppDataLow\Software\Freecause Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\DataMngr Key Deleted : HKCU\Software\DataMngr_Toolbar Key Deleted : HKCU\Software\Default Tab Key Deleted : HKCU\Software\DefaultTab Key Deleted : HKCU\Software\Delta Key Deleted : HKCU\Software\delta LTD Key Deleted : HKCU\Software\f2d9deb73be914 Key Deleted : HKCU\Software\IM Key Deleted : HKCU\Software\ImInstaller Key Deleted : HKCU\Software\IncrediMail_MediaBar_2 Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\BrowserProtect Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403A-B9D2-65C292C39087} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1083ECD8-9E5B-4D2E-B47A-3D87076C1ABB} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403A-B9D2-65C292C39087} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKCU\Software\PriceGong Key Deleted : HKCU\Software\SmartBar Key Deleted : HKCU\Software\StartSearch Key Deleted : HKCU\Software\Web Assistant Key Deleted : HKCU\Software\wecarereminder Key Deleted : HKCU\Software\YourFileDownloader Key Deleted : HKCU\Toolbar Key Deleted : HKLM\Software\AVG Secure Search Key Deleted : HKLM\Software\AVG Security Toolbar Key Deleted : HKLM\Software\Babylon Key Deleted : HKLM\Software\BabylonToolbar Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4FBBF769-ECEB-420A-B536-133B1D505C36} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1083ECD8-9E5B-4D2E-B47A-3D87076C1ABB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F773BB94-6C19-4643-A570-0E429103D1C3} Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaappCore Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaappCore.1 Key Deleted : HKLM\SOFTWARE\Classes\delta.deltadskBnd Key Deleted : HKLM\SOFTWARE\Classes\delta.deltadskBnd.1 Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaHlpr Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaHlpr.1 Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Key Deleted : HKLM\SOFTWARE\Classes\esrv.deltaESrvc Key Deleted : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1 Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1 Key Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder Key Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder.1 Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F773BB94-6C19-4643-A570-0E429103D1C3} Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2724386 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12920CF-BE13-4C09-890D-1B6EFFFE2FBE} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1 Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\DataMngr Key Deleted : HKLM\Software\Default Tab Key Deleted : HKLM\Software\Delta Key Deleted : HKLM\SOFTWARE\f2d9deb73be914 Key Deleted : HKLM\Software\Freeze.com Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jbpkiefagocgkmemidfngdkamloieekf Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph Key Deleted : HKLM\Software\ImInstaller Key Deleted : HKLM\Software\IncrediMail_MediaBar_2 Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0A226CF0-45B7-4877-BDC9-4C18A03B4831} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3B30CDFB-401E-4B55-A80D-2DB5B2A61879} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC5B6CDA-8F90-4740-9A8C-28AC5D3C73FE} Key Deleted : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DefaultTab Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta Chrome Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\IncrediMail_MediaBar_2 Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1083ECD8-9E5B-4D2E-B47A-3D87076C1ABB} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IncrediMail_MediaBar_2 Toolbar Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Deleted : HKLM\Software\Web Assistant Key Deleted : HKLM\Software\YourFileDownloader Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0}] Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{0F827075-B026-42F3-885D-98981EE7B1AE}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{82E1477C-B154-48D3-9891-33D83C26BCD3}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0}] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.delta-search.com/?affID=119776&babsrc=HP_ss&mntrId=d477375e000000000000002275385e82 –> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://www.delta-search.com/?affID=119776&babsrc=NT_ss&mntrId=d477375e000000000000002275385e82 –> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://searchab.com/?aff=7&uid=07961db0-b1bd-11e2-bca9-002275385e82 –> hxxp://www.google.com -\\ Mozilla Firefox v16.0.1 (en-US) File : C:\Documents and Settings\Mommy\Application Data\Mozilla\Firefox\Profiles\9v3zvbwo.default\prefs.js C:\Documents and Settings\Mommy\Application Data\Mozilla\Firefox\Profiles\9v3zvbwo.default\user.js … Deleted ! Deleted : user_pref("CT3277370.1000082.isPlayDisplay", "true"); Deleted : user_pref("CT3277370.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi…\",\"description[…] Deleted : user_pref("CT3277370.1000234.TWC_TMP_city", "GRAND RAPIDS"); Deleted : user_pref("CT3277370.1000234.TWC_TMP_country", "US"); Deleted : user_pref("CT3277370.1000234.TWC_country", "UNITED STATES"); Deleted : user_pref("CT3277370.1000234.TWC_locId", "USMI0344"); Deleted : user_pref("CT3277370.1000234.TWC_location", "Grand Rapids, MI"); Deleted : user_pref("CT3277370.1000234.TWC_region", "US"); Deleted : user_pref("CT3277370.1000234.TWC_temp_dis", "f"); Deleted : user_pref("CT3277370.1000234.TWC_wind_dis", "mph"); Deleted : user_pref("CT3277370.1000234.weatherData", "{\"icon\":\"11.png\",\"temperature\":\"37°F\",\"temperat[…] Deleted : user_pref("CT3277370.CT3277370ads1.enc", "JTdCJTIyYWRzJTIyJTNBJTVCJTdCJTIyYWlkJTIyJTNBJTIyMzY3MzIlMj[…] Deleted : user_pref("CT3277370.CT3277370current_term.enc", ""); Deleted : user_pref("CT3277370.CT3277370sdate.enc", "MTE="); Deleted : user_pref("CT3277370.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3277370.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[…] Deleted : user_pref("CT3277370.FF19Solved", "true"); Deleted : user_pref("CT3277370.FirstTime", "true"); Deleted : user_pref("CT3277370.FirstTimeFF3", "true"); Deleted : user_pref("CT3277370.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT327[…] Deleted : user_pref("CT3277370.UserID", "UN23024119126265181"); Deleted : user_pref("CT3277370.addressBarTakeOverEnabledInHidden", "true"); Deleted : user_pref("CT3277370.autoDisableScopes", -1); Deleted : user_pref("CT3277370.browser.search.defaultthis.engineName", "true"); Deleted : user_pref("CT3277370.defaultSearch", "true"); Deleted : user_pref("CT3277370.embeddedsData", "[{\"appId\":\"130021582164426878\",\"apiPermissions\":{\"cross[…] Deleted : user_pref("CT3277370.enableAlerts", "always"); Deleted : user_pref("CT3277370.enableFix404ByUser", "FALSE"); Deleted : user_pref("CT3277370.enableSearchFromAddressBar", "true"); Deleted : user_pref("CT3277370.firstTimeDialogOpened", "true"); Deleted : user_pref("CT3277370.fixPageNotFoundError", "true"); Deleted : user_pref("CT3277370.fixPageNotFoundErrorByUser", "true"); Deleted : user_pref("CT3277370.fixPageNotFoundErrorInHidden", "true"); Deleted : user_pref("CT3277370.fixUrls", true); Deleted : user_pref("CT3277370.homepageuserchanged", true); Deleted : user_pref("CT3277370.hxxp___pinterest_aot_im.isEnabled.enc", "WQ=="); Deleted : user_pref("CT3277370.installDate", "30/4/2013 12:43:24"); Deleted : user_pref("CT3277370.installId", "stub.exe"); Deleted : user_pref("CT3277370.installType", "conduitnsisintegration"); Deleted : user_pref("CT3277370.isCheckedStartAsHidden", true); Deleted : user_pref("CT3277370.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3277370.isFirstTimeToolbarLoading", "false"); Deleted : user_pref("CT3277370.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}"); Deleted : user_pref("CT3277370.keyword", "true"); Deleted : user_pref("CT3277370.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit[…] Deleted : user_pref("CT3277370.lastVersion", "10.14.65.43"); Deleted : user_pref("CT3277370.mam_gk_installer_preapproved.enc", "ZmFsc2U="); Deleted : user_pref("CT3277370.migrateAppsAndComponents", true); Deleted : user_pref("CT3277370.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"about[…] Deleted : user_pref("CT3277370.openThankYouPage", "false"); Deleted : user_pref("CT3277370.openUninstallPage", "true"); Deleted : user_pref("CT3277370.revertSettingsEnabled", "false"); Deleted : user_pref("CT3277370.search.searchAppId", "130021582164426878"); Deleted : user_pref("CT3277370.search.searchCount", "0"); Deleted : user_pref("CT3277370.searchFromAddressBarEnabledByUser", "true"); Deleted : user_pref("CT3277370.searchInNewTabEnabledByUser", "true"); Deleted : user_pref("CT3277370.searchInNewTabEnabledInHidden", "true"); Deleted : user_pref("CT3277370.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3277370.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[…] Deleted : user_pref("CT3277370.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[…] Deleted : user_pref("CT3277370.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[…] Deleted : user_pref("CT3277370.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[…] Deleted : user_pref("CT3277370.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[…] Deleted : user_pref("CT3277370.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[…] Deleted : user_pref("CT3277370.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1367343834156"); Deleted : user_pref("CT3277370.serviceLayer_services_appsMetadata_lastUpdate", "1367343834104"); Deleted : user_pref("CT3277370.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1367343833602"); Deleted : user_pref("CT3277370.serviceLayer_services_location_lastUpdate", "1367343832344"); Deleted : user_pref("CT3277370.serviceLayer_services_login_10.14.65.43_lastUpdate", "1363043573888"); Deleted : user_pref("CT3277370.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1367343833769"); Deleted : user_pref("CT3277370.serviceLayer_services_searchAPI_lastUpdate", "1367343832351"); Deleted : user_pref("CT3277370.serviceLayer_services_serviceMap_lastUpdate", "1367950846969"); Deleted : user_pref("CT3277370.serviceLayer_services_setupAPI_lastUpdate", "1367343834209"); Deleted : user_pref("CT3277370.serviceLayer_services_toolbarContextMenu_lastUpdate", "1367343833875"); Deleted : user_pref("CT3277370.serviceLayer_services_toolbarSettings_lastUpdate", "1367950848612"); Deleted : user_pref("CT3277370.serviceLayer_services_translation_lastUpdate", "1367950848382"); Deleted : user_pref("CT3277370.settingsINI", true); Deleted : user_pref("CT3277370.shouldFirstTimeDialog", "false"); Deleted : user_pref("CT3277370.smartbar.CTID", "CT3277370"); Deleted : user_pref("CT3277370.smartbar.Uninstall", "0"); Deleted : user_pref("CT3277370.smartbar.homepage", true); Deleted : user_pref("CT3277370.smartbar.isHidden", true); Deleted : user_pref("CT3277370.smartbar.toolbarName", "InternetHelper3 "); Deleted : user_pref("CT3277370.startPage", "true"); Deleted : user_pref("CT3277370.toolbarBornServerTime", "2-3-2013"); Deleted : user_pref("CT3277370.toolbarCurrentServerTime", "12-3-2013"); Deleted : user_pref("CT3277370.toolbarDisabled", "true"); Deleted : user_pref("CT3277370_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[…] Deleted : user_pref("Smartbar.ConduitHomepagesList", ""); Deleted : user_pref("Smartbar.ConduitSearchEngineList", ""); Deleted : user_pref("Smartbar.ConduitSearchUrlList", ""); Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://searchab.com/?aff=7&uid=07961db0-b1bd-11e[…] Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT3277370"); Deleted : user_pref("browser.search.defaultthis.engineName", "InternetHelper3 Customized Web Search"); Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3277370&Sea[…] Deleted : user_pref("browser.search.order.1", "Delta Search"); Deleted : user_pref("extensions.BabylonToolbar.autoRvrt", "false"); Deleted : user_pref("extensions.BabylonToolbar.newTab", false); Deleted : user_pref("extensions.BabylonToolbar.rvrt", "false"); Deleted : user_pref("extensions.BabylonToolbar_i.newTab", true); Deleted : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://www.delta-search.com/?affID=119776&babsrc[…] Deleted : user_pref("extensions.crossriderapp21426.21426.InstallationTime", 1367345222); Deleted : user_pref("extensions.crossriderapp21426.21426.cookie.InstallationTime.expiration", "Fri Feb 01 2030[…] Deleted : user_pref("extensions.crossriderapp21426.21426.cookie.InstallationTime.value", "1367345222"); Deleted : user_pref("extensions.crossriderapp21426.bic", "13e5c20518a52108180624e66f7a817a"); Deleted : user_pref("extensions.crossriderapp21426.firstrun", false); Deleted : user_pref("extensions.crossriderapp21426.installationdate", 1367345222); Deleted : user_pref("extensions.crossriderapp21426.lastcheck", 22799028); Deleted : user_pref("extensions.crossriderapp21426.lastcheckitem", 22717529); Deleted : user_pref("extensions.crossriderapp21426.reportInstall", true); Deleted : user_pref("extensions.defaulttab.config", "{\"status\": \"ok\", \"config\": {\"dns_error_handling\":[…] Deleted : user_pref("extensions.delta.admin", false); Deleted : user_pref("extensions.delta.aflt", "babsst"); Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); Deleted : user_pref("extensions.delta.autoRvrt", "false"); Deleted : user_pref("extensions.delta.babTrack", "affID=120022"); Deleted : user_pref("extensions.delta.bbDpng", "11"); Deleted : user_pref("extensions.delta.cntry", "US"); Deleted : user_pref("extensions.delta.dfltLng", "en"); Deleted : user_pref("extensions.delta.excTlbr", false); Deleted : user_pref("extensions.delta.hdrMd5", "C5E6709156F8C4F17175B6023A07E77A"); Deleted : user_pref("extensions.delta.id", "d477375e000000000000002275385e82"); Deleted : user_pref("extensions.delta.instlDay", "15825"); Deleted : user_pref("extensions.delta.instlRef", "sst"); Deleted : user_pref("extensions.delta.lastVrsnTs", "1.8.10.012:54:03"); Deleted : user_pref("extensions.delta.newTab", false); Deleted : user_pref("extensions.delta.prdct", "delta"); Deleted : user_pref("extensions.delta.prtnrId", "delta"); Deleted : user_pref("extensions.delta.rvrt", "false"); Deleted : user_pref("extensions.delta.sg", "azb"); Deleted : user_pref("extensions.delta.smplGrp", "none"); Deleted : user_pref("extensions.delta.tlbrId", "base"); Deleted : user_pref("extensions.delta.tlbrSrchUrl", ""); Deleted : user_pref("extensions.delta.vrsn", "[removed]"); Deleted : user_pref("extensions.delta.vrsnTs", "1.8.10.012:54:03"); Deleted : user_pref("extensions.delta.vrsni", "1.8.10.0"); Deleted : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3277370&SearchSource=2&CU[…] Deleted : user_pref("smartBar.searchInNewTabOwner", "CT3277370"); Deleted : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3277370&SearchSource=13[…] Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT[…] Deleted : user_pref("smartbar.originalHomepage", "hxxp://searchab.com/?aff=7&uid=07961db0-b1bd-11e2-bca9-00227[…] Deleted : user_pref("smartbar.originalSearchAddressUrl", "hxxp://searchab.com/?aff=7&uid=07961db0-b1bd-11e2-bc[…] Deleted : user_pref("smartbar.originalSearchEngine", "Privitize VPN"); File : C:\Documents and Settings\Mommy\Application Data\Mozilla\Firefox\Profiles\f92shba0.default\prefs.js Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search"); Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search"); Deleted : user_pref("browser.startup.homepage", "hxxp://isearch.avg.com/?cid={897BB805-C92B-4A8B-9E92-8F6ACF7A[…] Deleted : user_pref("keyword.URL", "hxxp://isearch.avg.com/search?cid={897BB805-C92B-4A8B-9E92-8F6ACF7AAB20}&m[…] -\\ Google Chrome v [Unable to get version] File : C:\Documents and Settings\Mommy\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [34051 octets] - [18/04/2013 13:47:43] AdwCleaner[R2].txt - [34112 octets] - [18/04/2013 13:48:45] AdwCleaner[R3].txt - [29492 octets] - [18/04/2013 14:36:12] AdwCleaner[S1].txt - [5178 octets] - [18/04/2013 13:50:12] AdwCleaner[S2].txt - [29371 octets] - [18/04/2013 14:36:33] ########## EOF - C:\AdwCleaner[S2].txt - [29432 octets] ##########
OTL logfile created on: 4/18/2013 2:45:51 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Mommy\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.42 Mb Total Physical Memory | 460.44 Mb Available Physical Memory | 51.48% Memory free
2.12 Gb Paging File | 1.61 Gb Available in Paging File | 76.19% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 123.99 Gb Free Space | 83.19% Space Free | Partition Type: NTFS
Drive D: | 57.06 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: MOM-38D5EC9FA4D | User Name: Mommy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/04/18 13:50:13 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mommy\Desktop\OTL.exe
PRC - [2013/03/19 22:26:44 | 003,289,208 | —- | M] (Skype Technologies S.A.) – C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2013/02/18 10:10:15 | 000,968,880 | —- | M] () – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
PRC - [2012/12/11 04:52:44 | 003,147,384 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2013\avgui.exe
PRC - [2012/12/10 18:29:44 | 001,435,568 | —- | M] (LogMeIn Inc.) – C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
PRC - [2012/10/22 14:05:08 | 000,196,664 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe
PRC - [2012/09/22 09:49:57 | 000,161,768 | —- | M] (Oracle Corporation) – C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/08/13 11:22:22 | 000,146,312 | —- | M] (Microsoft ® Corporation) – C:\Documents and Settings\Mommy\Forefront UAG Remote Access Agent\dhssharearkansasgov\sharepoint1\uagqecsvc.exe
PRC - [2012/07/02 17:19:07 | 000,439,792 | —- | M] (IncrediMail, Ltd.) – C:\Program Files\IncrediMail\Bin\IncMail.exe
PRC - [2012/07/02 17:19:07 | 000,280,048 | —- | M] (IncrediMail, Ltd.) – C:\Program Files\IncrediMail\Bin\ImApp.exe
PRC - [2012/06/11 16:22:16 | 000,193,616 | —- | M] (Microsoft Corporation.) – C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.EXE
PRC - [2012/03/28 02:53:14 | 000,404,568 | —- | M] (LG Electronics) – C:\Documents and Settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/12/11 14:15:04 | 000,012,800 | R— | M] (Agere Systems) – C:\WINDOWS\system32\agrsmsvc.exe


========== Modules (No Company Name) ==========

MOD - [2013/02/18 10:10:15 | 000,968,880 | —- | M] () – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
MOD - [2012/07/02 17:19:08 | 000,271,856 | —- | M] () – C:\Program Files\IncrediMail\Bin\ImLookExU.dll
MOD - [2012/07/02 17:19:08 | 000,071,152 | —- | M] () – C:\Program Files\IncrediMail\Bin\wlessfp1.dll
MOD - [2012/07/02 17:19:07 | 000,132,592 | —- | M] () – C:\Program Files\IncrediMail\Bin\ImComUtlU.dll
MOD - [2012/07/02 17:19:07 | 000,079,344 | —- | M] () – C:\Program Files\IncrediMail\Bin\ImAppRU.dll
MOD - [2012/07/02 17:19:07 | 000,032,168 | —- | M] () – C:\Program Files\IncrediMail\Bin\IMHttpComm.dll
MOD - [2012/06/04 16:33:36 | 000,107,928 | —- | M] () – C:\Program Files\IncrediMail\Bin\PMC.dll
MOD - [2011/02/28 17:37:32 | 000,180,624 | —- | M] () – C:\WINDOWS\system32\Primomonnt.dll


========== Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – %SystemRoot%\System32\hidserv.dll – (HidServ)
SRV - File not found [On_Demand | Stopped] – %SystemRoot%\System32\appmgmts.dll – (AppMgmt)
SRV - [2013/05/07 10:47:15 | 000,115,608 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2013/04/27 19:36:33 | 000,251,248 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/03/19 22:26:44 | 003,289,208 | —- | M] (Skype Technologies S.A.) [Auto | Running] – C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe – (Skype C2C Service)
SRV - [2013/02/18 10:10:15 | 000,968,880 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe – (vToolbarUpdater14.2.0)
SRV - [2012/12/10 18:29:44 | 001,435,568 | —- | M] (LogMeIn Inc.) [Auto | Running] – C:\Program Files\LogMeIn Hamachi\hamachi-2.exe – (Hamachi2Svc)
SRV - [2012/11/16 00:34:30 | 005,814,904 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG2013\avgidsagent.exe – (AVGIDSAgent)
SRV - [2012/10/22 14:05:08 | 000,196,664 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2013\avgwdsvc.exe – (avgwd)
SRV - [2012/09/22 09:49:57 | 000,161,768 | —- | M] (Oracle Corporation) [Auto | Running] – C:\Program Files\Java\jre7\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2012/09/05 10:56:44 | 000,234,776 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe – (McComponentHostService)
SRV - [2012/08/13 11:22:22 | 000,146,312 | —- | M] (Microsoft ® Corporation) [Auto | Running] – C:\Documents and Settings\Mommy\Forefront UAG Remote Access Agent\dhssharearkansasgov\sharepoint1\uagqecsvc.exe – (uagqecsvc)
SRV - [2012/06/11 16:22:16 | 000,240,208 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE – (BBUpdate)
SRV - [2012/06/11 16:22:16 | 000,193,616 | —- | M] (Microsoft Corporation.) [Auto | Running] – C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.EXE – (BBSvc)
SRV - [2012/06/07 19:12:14 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2010/10/12 12:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2008/06/27 19:24:34 | 000,467,028 | —- | M] (Atheros) [Disabled | Stopped] – C:\WINDOWS\system32\acs.exe – (ACS)
SRV - [2007/12/11 14:15:04 | 000,012,800 | R— | M] (Agere Systems) [Auto | Running] – C:\WINDOWS\system32\agrsmsvc.exe – (AgereModemAudio)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\WN111v2.sys – (WN111v2)
DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] – – (i2omgmt)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - [2013/02/18 10:10:15 | 000,033,112 | —- | M] (AVG Technologies) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgtpx86.sys – (avgtp)
DRV - [2012/11/16 00:33:26 | 000,094,048 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\avgmfx86.sys – (Avgmfx86)
DRV - [2012/10/22 14:02:46 | 000,179,936 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgidsdriverx.sys – (AVGIDSDriver)
DRV - [2012/10/15 04:48:52 | 000,055,776 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\avgidshx.sys – (AVGIDSHX)
DRV - [2012/10/02 04:30:38 | 000,159,712 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgldx86.sys – (Avgldx86)
DRV - [2012/09/21 04:46:06 | 000,164,832 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgtdix.sys – (Avgtdix)
DRV - [2012/09/21 04:46:00 | 000,177,376 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\avglogx.sys – (Avglogx)
DRV - [2012/09/21 04:45:54 | 000,019,936 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgidsshimx.sys – (AVGIDSShim)
DRV - [2012/09/14 04:05:20 | 000,035,552 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\avgrkx86.sys – (Avgrkx86)
DRV - [2012/04/19 13:47:44 | 000,025,512 | —- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ggsemc.sys – (ggsemc)
DRV - [2012/04/19 13:47:44 | 000,013,224 | —- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ggflt.sys – (ggflt)
DRV - [2012/03/06 05:40:00 | 000,070,400 | —- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lgandnetndis.sys – (andnetndis)
DRV - [2012/03/06 05:38:00 | 000,027,776 | —- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lgandnetmodem.sys – (ANDNetModem)
DRV - [2012/03/06 05:38:00 | 000,023,040 | —- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lgandnetdiag2.sys – (AndNetDiag2)
DRV - [2012/03/06 05:38:00 | 000,023,040 | —- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lgandnetdiag.sys – (AndNetDiag)
DRV - [2012/03/06 05:38:00 | 000,022,272 | —- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lgandnetgps.sys – (AndNetGps)
DRV - [2010/08/12 11:44:06 | 000,071,936 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\NVENETFD.sys – (NVENETFD)
DRV - [2010/04/28 07:44:02 | 000,054,760 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys – (fssfltr)
DRV - [2010/02/02 21:45:08 | 000,724,736 | R— | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Drt2870.sys – (rt2870)
DRV - [2010/01/26 17:38:06 | 001,163,328 | —- | M] (LSI Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2009/03/18 17:35:40 | 000,026,176 | -H– | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hamachi.sys – (hamachi)
DRV - [2009/03/05 04:09:14 | 000,450,944 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTL8192u.sys – (RTL8192u)
DRV - [2008/08/01 18:36:26 | 000,022,016 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nvnetbus.sys – (nvnetbus)
DRV - [2008/05/20 20:53:00 | 004,800,000 | R— | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService)
DRV - [2008/01/25 23:01:06 | 000,132,096 | R— | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\nvgts.sys – (nvgts)
DRV - [2007/12/14 07:31:00 | 000,057,408 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wsimd.sys – (WSIMD)
DRV - [2007/04/16 21:46:00 | 000,033,792 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdPPM.sys – (AmdPPM)
DRV - [2003/07/24 15:10:34 | 000,017,149 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\DNINDIS5.sys – (DNINDIS5)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{24382D2E-2592-4745-8C77-9CE5A2BDD67F}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = ${SEARCH_URL}{searchTerms}


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-789336058-1390067357-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE8HP&PC=B8MC
IE - HKU\S-1-5-21-789336058-1390067357-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-789336058-1390067357-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-21-789336058-1390067357-682003330-1004\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-789336058-1390067357-682003330-1004\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-789336058-1390067357-682003330-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-789336058-1390067357-682003330-1004\..\SearchScopes\{24382D2E-2592-4745-8C77-9CE5A2BDD67F}: "URL" = http://www.google.com/search?q={searchTerm…1I7ADFA_enUS461
IE - HKU\S-1-5-21-789336058-1390067357-682003330-1004\..\SearchScopes\{2E3D461D-8C7E-4A9D-9A5B-A56E46425558}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKU\S-1-5-21-789336058-1390067357-682003330-1004\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-789336058-1390067357-682003330-1004\..\SearchScopes\{931125FA-469A-4559-A314-3426D3807D94}: "URL" = http://www.mysearchresults.com/search?c=40…q={searchTerms}
IE - HKU\S-1-5-21-789336058-1390067357-682003330-1004\..\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}: "URL" = http://search.alot.com/web?q={searchTerms}…n=1.1.3001.0(B)
IE - HKU\S-1-5-21-789336058-1390067357-682003330-1004\..\SearchScopes\{AEB180E4-72BF-4C2B-B2FE-48F8E63D18EC}: "URL" = http://websearch.ask.com/redirect?client=i…BE-DEB3CD2BEBB4
IE - HKU\S-1-5-21-789336058-1390067357-682003330-1004\..\SearchScopes\{CF17F234-3B83-4D7B-A489-C43D97E32572}: "URL" = http://www.google.com/search?q={searchTerm…1I7ADFA_enUS461
IE - HKU\S-1-5-21-789336058-1390067357-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Privitize VPN"
FF - prefs.js..browser.search.defaultenginename: "Privitize VPN"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://hsrd.yahoo.com/_ylt=AkRp_pPpGOwyDrekONDNkx6bvZx4/RV=1/RE=1366898554/RH=aHNyZC55YWhvby5jb20-/RO=2/RU=aHR0cDovL3d3dy55YWhvby5jb20v/RS=%5EADAUzWNKeGtAMrhAR3M8gcjU3Wg3gg-"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@nsroblox.roblox.com/launcher: C:\Documents and Settings\Mommy\Local Settings\Application Data\RobloxVersions\version-eecd9135a67340ab\\NPRobloxProxy.dll ()
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Mommy\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/05/07 10:47:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/03/09 18:58:15 | 000,000,000 | —D | M]

[2012/01/19 19:04:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Mommy\Application Data\Mozilla\Extensions
[2013/04/18 13:51:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Mommy\Application Data\Mozilla\Firefox\Profiles\9v3zvbwo.default\extensions
[2013/04/18 13:51:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Mommy\Application Data\Mozilla\Firefox\Profiles\f92shba0.default\extensions
[2013/04/18 13:51:23 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/04/05 16:37:48 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/05/07 10:47:16 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/04/26 16:07:58 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/04/26 16:07:58 | 000,002,086 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://searchab.com/?aff=7&uid=07961db…a9-002275385e82
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://searchab.com/?aff=7&uid=07961db…a9-002275385e82
CHR - Extension: No name found = C:\Documents and Settings\Mommy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\iklfnijkecmmkjhjoamnpoemkpoppafe\1.22.44_0\crossrider
CHR - Extension: No name found = C:\Documents and Settings\Mommy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\iklfnijkecmmkjhjoamnpoemkpoppafe\1.22.44_0\
CHR - Extension: No name found = C:\Documents and Settings\Mommy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.12_0\
CHR - Extension: No name found = C:\Documents and Settings\Mommy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mjildcbkilmkddbbpbjljljdmmlfeppl\5.0_0\
CHR - Extension: No name found = C:\Documents and Settings\Mommy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pmfbdeonhcacfoakminfhhgllaelfhda\2.2_0\

O1 HOSTS File: ([2004/08/04 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll File not found
O2 - BHO: (no name) - {56E4076B-A42B-4745-BA35-34DA8AC4C2F2} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-789336058-1390067357-682003330-1004\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [B2C_AGENT] C:\Documents and Settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [PrivitizeVPN] C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe (OOO Industry)
O4 - HKLM..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe" File not found
O4 - HKU\S-1-5-21-789336058-1390067357-682003330-1004..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Belkin N Wireless USB Adapter Client Utility.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-789336058-1390067357-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{01980122-CC87-40E2-B33D-EB3BFD304CAD}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (c:\docume~1\alluse~1\applic~1\browse~1\261095~1.52\{c16c1~1\browse~1.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/12/07 18:49:34 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/02/02 22:48:43 | 000,000,045 | R— | M] () - D:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{68b5926b-6598-11e1-ba1c-002275385e82}\Shell - "" = AutoRun
O33 - MountPoints2\{68b5926b-6598-11e1-ba1c-002275385e82}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{68b5926b-6598-11e1-ba1c-002275385e82}\Shell\AutoRun\command - "" = F:\Startme.exe
O33 - MountPoints2\{ae34cbc9-7ab7-11e1-ba45-002275385e82}\Shell - "" = AutoRun
O33 - MountPoints2\{ae34cbc9-7ab7-11e1-ba45-002275385e82}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ae34cbc9-7ab7-11e1-ba45-002275385e82}\Shell\AutoRun\command - "" = F:\setup.exe -a
O33 - MountPoints2\{b26090c1-20e8-11e1-b9ca-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{b26090c1-20e8-11e1-b9ca-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b26090c1-20e8-11e1-b9ca-806d6172696f}\Shell\AutoRun\command - "" = D:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/05/07 10:53:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG
[2013/04/30 12:54:49 | 000,000,000 | —D | C] – C:\Program Files\Gophoto.it
[2013/04/30 12:53:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Mommy\Local Settings\Application Data\Updater21426
[2013/04/30 12:52:58 | 000,000,000 | —D | C] – C:\Program Files\Savings Addon
[2013/04/30 12:44:52 | 000,000,000 | -HSD | C] – C:\WINDOWS\System32\AI_RecycleBin
[2013/04/30 12:44:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Strongvault Online Backup
[2013/04/30 12:44:29 | 000,000,000 | -HSD | C] – C:\AI_RecycleBin
[2013/04/30 12:43:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Flash Player Pro
[2013/04/30 12:43:01 | 000,000,000 | —D | C] – C:\Program Files\Flash Player Pro
[2013/04/30 12:43:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Mommy\My Documents\Flash Player Pro
[2013/04/30 12:41:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Mommy\Start Menu\Programs\PrivitizeVPN
[2013/04/30 12:41:57 | 000,000,000 | —D | C] – C:\Program Files\PrivitizeVPN
[2013/04/26 16:07:48 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/04/18 13:50:11 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Mommy\Desktop\OTL.exe
[2013/04/16 13:55:27 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Mommy\Desktop\HiJackThis.exe
[2013/04/16 13:52:46 | 000,221,184 | R— | C] (Ralink Technology, Inc.) – C:\WINDOWS\System32\RaCoInst.dll
[2013/04/16 13:52:45 | 000,724,736 | R— | C] (Ralink Technology, Corp.) – C:\WINDOWS\System32\drivers\Drt2870.sys
[2013/03/23 15:22:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Mommy\Desktop\Free ed coarse
[2013/03/23 13:57:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Mommy\Desktop\Karens folder
[2013/03/21 15:59:15 | 000,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usb8023x.sys
[2013/03/21 15:59:15 | 000,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usb8023.sys
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/07 10:53:42 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2013.lnk
[2013/05/06 19:58:31 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0F28692D-4FBE-450B-9CCE-4E3531218440}.job
[2013/04/30 12:43:06 | 000,000,778 | —- | M] () – C:\Documents and Settings\Mommy\Desktop\Flash Player Pro.lnk
[2013/04/27 19:36:33 | 000,691,568 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/04/27 19:36:33 | 000,071,024 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/04/18 14:41:16 | 000,002,413 | —- | M] () – C:\WINDOWS\System32\lgAxconfig.ini
[2013/04/18 14:39:26 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/18 14:39:26 | 000,000,324 | —- | M] () – C:\WINDOWS\tasks\YourFile DownloaderUpdate.job
[2013/04/18 14:38:31 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/04/18 14:37:01 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/18 14:35:15 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/04/18 13:50:13 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mommy\Desktop\OTL.exe
[2013/04/18 13:46:11 | 000,613,083 | —- | M] () – C:\Documents and Settings\Mommy\Desktop\adwcleaner.exe
[2013/04/18 13:42:34 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/04/16 14:06:35 | 000,000,036 | —- | M] () – C:\WINDOWS\avgui.INI
[2013/04/16 13:55:28 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Mommy\Desktop\HiJackThis.exe
[2013/04/16 13:53:52 | 000,470,138 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/04/16 13:53:52 | 000,082,010 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/04/13 11:21:44 | 000,002,515 | —- | M] () – C:\Documents and Settings\Mommy\Desktop\Microsoft Office Word 2007.lnk
[2013/04/12 09:24:42 | 001,072,544 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2013/04/12 09:24:42 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2013/04/12 09:24:39 | 001,072,544 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2013/04/12 06:22:57 | 000,165,912 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/04/12 05:51:50 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/04/03 20:19:28 | 000,008,704 | —- | M] () – C:\Documents and Settings\Mommy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/03/30 13:21:40 | 003,687,369 | —- | M] () – C:\Documents and Settings\Mommy\Desktop\ppsspp.apk
[2013/03/24 14:38:57 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/01 08:07:58 | 000,000,324 | —- | C] () – C:\WINDOWS\tasks\YourFile DownloaderUpdate.job
[2013/04/30 12:43:06 | 000,000,778 | —- | C] () – C:\Documents and Settings\Mommy\Desktop\Flash Player Pro.lnk
[2013/04/18 13:46:09 | 000,613,083 | —- | C] () – C:\Documents and Settings\Mommy\Desktop\adwcleaner.exe
[2013/04/16 14:06:35 | 000,000,036 | —- | C] () – C:\WINDOWS\avgui.INI
[2013/04/16 13:52:46 | 000,013,931 | R— | C] () – C:\WINDOWS\System32\RaCoInst.dat
[2013/03/30 13:21:10 | 003,687,369 | —- | C] () – C:\Documents and Settings\Mommy\Desktop\ppsspp.apk
[2012/11/10 15:59:03 | 000,000,061 | —- | C] () – C:\Documents and Settings\Mommy\jagex_cl_runescape_LIVE.dat
[2012/11/10 15:59:03 | 000,000,024 | —- | C] () – C:\Documents and Settings\Mommy\random.dat
[2012/08/13 11:39:18 | 000,027,520 | —- | C] () – C:\Documents and Settings\Mommy\Local Settings\Application Data\dt.dat
[2012/08/01 10:55:58 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CommonDL.dll
[2012/08/01 10:55:58 | 000,002,413 | —- | C] () – C:\WINDOWS\System32\lgAxconfig.ini
[2012/07/03 18:00:22 | 000,008,704 | —- | C] () – C:\Documents and Settings\Mommy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/05/04 17:55:16 | 001,072,544 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2012/05/04 17:55:16 | 001,072,544 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2012/05/04 17:55:16 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2012/03/31 20:35:59 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2012/03/31 15:42:11 | 000,098,344 | —- | C] () – C:\WINDOWS\unTMV.exe
[2012/02/16 13:38:25 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/02/09 22:40:00 | 002,816,504 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2012/01/23 17:45:24 | 000,000,318 | —- | C] () – C:\WINDOWS\wininit.ini
[2012/01/02 12:11:16 | 000,000,064 | —- | C] () – C:\WINDOWS\GPlrLanc.dat
[2011/12/08 20:30:36 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe
[2011/12/08 20:08:27 | 000,180,624 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2011/12/08 20:03:01 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/07 19:21:17 | 000,003,948 | R— | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2011/12/07 18:51:34 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/12/07 18:46:37 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/12/07 10:34:08 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/12/07 10:32:50 | 000,165,912 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== ZeroAccess Check ==========

[2011/12/08 20:06:28 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 19:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 07:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/13 19:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/04 07:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/13 19:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 19:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2004/08/04 07:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/04 07:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/04 07:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: WDC WD16 00AAJS-22WAA SCSI Disk Device
Partitions: 1
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Generic- Multi-Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 149.00GB
Starting Offset: 32256
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction

========== Alternate Data Streams ==========

@Alternate Data Stream - 235 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4C71A42B
@Alternate Data Stream - 234 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D5CCCBAA
@Alternate Data Stream - 232 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:800FE171
@Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B86642C5
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B0456F0C
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C4A588B
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A5948878
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AE75CCC8
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F5E90ED3
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DF19F127
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B3606FCC
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9EF92A1A
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:20EB6823

< End of report >


Redoing aswmbr it froze on me
ok tried to rerun app BSOD came up and it said Server_IRQL_NOT_LESS_OR_EQUAL this has not appeared in over a month tried to run 2 times upload the error report that came up had to downsize pic of it hope you can see it…

Attachments:

I couldn’t read those attached screenshots.

Let’s try something else.

Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.


Download one of these to your desktop:


for a 32-bt system download this version.
for 64-bit use this one

.
  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the pre-scan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad
If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.
Please post the contents of the RKreport.txt in your next reply.

Satchfan
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-04-19 07:15:51 —————————– 07:15:51.234 OS Version: Windows 5.1.2600 Service Pack 3 07:15:51.234 Number of processors: 1 586 0x7F02 07:15:51.234 ComputerName: MOM-38D5EC9FA4D UserName: Mommy 07:15:52.687 Initialize success 07:16:25.796 AVAST engine defs: 13041800 07:16:29.531 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Scsi\nvgts1Port2Path1Target1Lun0 07:16:29.531 Disk 0 Vendor: WDC_WD16 58.0 Size: 152627MB BusType: 1 07:16:30.000 Disk 0 MBR read successfully 07:16:30.015 Disk 0 MBR scan 07:16:30.234 Disk 0 Windows XP default MBR code 07:16:30.250 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 152617 MB offset 63 07:16:30.281 Disk 0 scanning sectors +312560640 07:16:30.343 Disk 0 scanning C:\WINDOWS\system32\drivers 07:16:43.046 Service scanning 07:17:05.625 Modules scanning 07:17:11.406 Disk 0 trace - called modules: 07:17:11.437 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll SCSIPORT.SYS nvgts.sys 07:17:11.437 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x851f0ab8] 07:17:11.953 3 CLASSPNP.SYS[f74c7fd7] -> nt!IofCallDriver -> \Device\0000006d[0x852bd6d0] 07:17:11.953 5 ACPI.sys[f735e620] -> nt!IofCallDriver -> \Device\Scsi\nvgts1Port2Path1Target1Lun0[0x852907a0] 07:17:12.281 AVAST engine scan C:\WINDOWS 07:17:24.640 AVAST engine scan C:\WINDOWS\system32 07:20:38.437 AVAST engine scan C:\WINDOWS\system32\drivers 07:20:53.125 AVAST engine scan C:\Documents and Settings\Mommy 08:33:57.468 AVAST engine scan C:\Documents and Settings\All Users 08:36:42.609 Scan finished successfully 08:59:00.046 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Mommy\Desktop\MBR.dat" 08:59:00.046 The log file has been saved successfully to "C:\Documents and Settings\Mommy\Desktop\aswMBR1.txt" Finally got it to run took out usb and it worked the last post did not result in any report although one line came up…
RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Mommy [Admin rights]
Mode : Scan – Date : 04/19/2013 15:06:11
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 2 ¤¤¤
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[APPINIT][SUSP PATH] HKLM\[…]\Windows : AppInit_DLLs (c:\docume~1\alluse~1\applic~1\browse~1\261095~1.52\{c16c1~1\browse~1.dll) [x] -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD16 00AAJS-22WAA SCSI Disk Device +++++
— User —
[MBR] 275c8691de6e050c3c8eb7c609c8ba8c
[BSP] 6d4d6cd8bfb187826792d5ebc80042fa : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 152617 Mo
User = LL1 … OK!
Error reading LL2 MBR!

Finished : << RKreport[1]_S_04192013_02d1506.txt >>
RKreport[1]_S_04192013_02d1506.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI