This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Another Win32 Downloader [Solved]

53 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I first noticed a severe change in performance, then odd behavior.
I ran Malwarebytes and Spybot. Win32 downloader kept showing up,
As in previous posts, Spybot notified, but could not clear the problem.
Spybot did point out the location, but I could not access it to try and handle it
manually.
I researched a number of sites. None gave me the confidence I have gotten here. Sooo…
I faq'd the subject here. Taking your warnings to heart, I choose to throw myself into the capable
hands of those who know best! Please note, the "xxxxxxxxxx" is an attempt to redact my wife's name
in this post, only as a matter of comfort for her'

Thank you in advance for your assistance!

OTL logfile created on: 7/20/2013 2:39:04 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.97 Gb Total Physical Memory | 0.95 Gb Available Physical Memory | 48.22% Memory free
3.81 Gb Paging File | 2.79 Gb Available in Paging File | 73.18% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 120.11 Gb Free Space | 80.63% Space Free | Partition Type: NTFS
Drive E: | 1.89 Gb Total Space | 0.66 Gb Free Space | 34.96% Space Free | Partition Type: FAT
Drive G: | 14.53 Gb Total Space | 12.99 Gb Free Space | 89.39% Space Free | Partition Type: FAT32

Computer Name: XXXXX | User Name: xxxxxxxxxx | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe (AVG Secure Search)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\loggingserver.exe ()
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\9f22d07e9863e4e1bf4f47ef4c3862e6\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\ee96e3bb14f5b3f2fe95c57e46c2495d\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\faa947d3cf5ddf23a46cf292df004a35\System.EnterpriseServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Transactions\5ec5f80f35fbc6665e2eddb7711a8410\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8f3e54440f3742da409131428ad1bce1\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\6ea5ee4386d67f4b432a27c40fbff93c\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Data\a4ed72fdc7627f5b58f32b31694a8885\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\4787bb699ed4291859fb86f15d793add\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\91c185bd043af039dcdc93e3fcf87f3d\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\256b7bb1216345c5a66ced50c1cf239d\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\5326f0da29e8171624f520a81f6e3eb1\System.Core.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\8a6d1c8abeb8eb82f06c7d075130cc67\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\cf58670896c5313b9b52f026f4455a5d\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\16562c54978851e92db8fec6f759bba1\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\b14359470744c840c59fbe4e58034fd6\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll ()
MOD - C:\Program Files\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\log4cplusU.dll ()
MOD - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\SiteSafety.dll ()
MOD - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\loggingserver.exe ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\5.0.136.0__7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\5.0.136.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\3.1.26.0__540d4816ead86321\Intuit.Spc.Esd.Core.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.DataAccess.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.Common.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data.SQLite\1.0.61.0__db937bc2d44ff139\System.Data.SQLite.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\5.0.104.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\5.0.104.0__7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\log4net\1.2.10.0__1b44e1d426115821\log4net.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\2.0.445.0__540d4816ead86321\Intuit.Spc.Esd.Core.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.DataAccess.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.Common.dll ()
MOD - C:\Program Files\BillP Studios\WinPatrol\sqlite3.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (vToolbarUpdater15.3.0) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe (AVG Secure Search)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe (McAfee, Inc.)
SRV - (IntuitUpdateServiceV4) – C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit Inc.)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (sprtsvc_dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (IAANTMON) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (avgtp) – C:\WINDOWS\system32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\WINDOWS\system32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (IntcHdmiAddService) – C:\WINDOWS\system32\drivers\IntcHdmi.sys (Intel® Corporation)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Diag69xp) – C:\WINDOWS\system32\drivers\diag69xp.sys (Realtek Semiconductor Corporation)
DRV - (RTLVLAN) – C:\WINDOWS\system32\drivers\RTLVLAN.SYS (Realtek Semiconductor Corporation)
DRV - (LANPkt) – C:\WINDOWS\system32\drivers\LANPkt.sys (Realtek Semiconductor Corporation)
DRV - (DLADResM) – C:\WINDOWS\system32\drivers\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\drivers\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\drivers\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\drivers\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\drivers\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\drivers\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\drivers\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\drivers\DLAIFS_M.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (CCCP106) – C:\WINDOWS\system32\drivers\cccp106.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.msn.com/USSMB/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.msn.com/sphome.aspx
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://g.msn.com/USSMB/1
IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USSMB/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/sphome.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {1c9b96a0-cba2-482e-9c40-9200b547123a} - C:\Program Files\Productivity\prxtbPro2.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7ADRA_en
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={DF2D24E…mp;d=2012-09-29 10:09:33&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2856459
IE - HKCU\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://search.avg.com/route/?d=4b4fa847&am…=b&ychte=us
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:12.0.0.1912
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.23\npGoogleOneClick8.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\xxxxxxxxxx\Local Settings\Application Data\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\xxxxxxxxxx\Local Settings\Application Data\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/07/05 01:22:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11 [2013/06/27 06:33:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/03 20:47:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/06/09 20:00:46 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/07/05 01:22:00 | 000,000,000 | —D | M]

[2010/04/16 01:11:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\xxxxxxxxxx\Application Data\Mozilla\Extensions
[2012/05/06 01:50:38 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\xxxxxxxxxx\Application Data\Mozilla\Firefox\Profiles\pmnn103x.default\extensions
[2012/05/06 01:50:38 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\xxxxxxxxxx\Application Data\Mozilla\Firefox\Profiles\pmnn103x.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/24 19:00:26 | 000,000,000 | —D | M] (ShopAtHome Intelligent Shopping Toolbar) – C:\Documents and Settings\xxxxxxxxxx\Application Data\Mozilla\Firefox\Profiles\pmnn103x.default\extensions\[removed]
[2012/05/06 01:50:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/18 18:28:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/11 09:27:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
File not found (No name found) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2010/05/25 18:07:33 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2012/02/22 18:58:26 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/03 06:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/02/22 18:58:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2013/06/27 06:33:51 | 000,003,716 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml

========== Chrome ==========

CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://isearch.avg.com/search?cid={DF2D24E…mp;d=2012-09-29 10:09:33&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms}
CHR - default_search_provider: suggest_url = http://toolbar.avg.com/acp?q={searchTerms}&o=1
CHR - homepage: http://www.google.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\xxxxxxxxxx\Local Settings\Application Data\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\xxxxxxxxxx\Local Settings\Application Data\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\Application\28.0.1500.72\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\xxxxxxxxxx\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: E-centives Coupon Activator Netscape Plugin v. 4.0.0.0 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPcol400.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: QuickTime Plug-in 7.6.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: AVG Security Toolbar = C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\

O1 HOSTS File: ([2011/06/13 20:06:04 | 000,434,940 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14971 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Productivity Toolbar) - {1c9b96a0-cba2-482e-9c40-9200b547123a} - C:\Program Files\Productivity\prxtbPro2.dll (Conduit Ltd.)
O2 - BHO: (Productivity 1.12 Toolbar) - {30421e54-3b57-4e5b-947c-9b6beea57683} - C:\Program Files\Productivity_1.12\prxtbPro2.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\15.3.0.11\AVG Secure Search_toolbar.dll (AVG Secure Search)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Productivity Toolbar) - {1c9b96a0-cba2-482e-9c40-9200b547123a} - C:\Program Files\Productivity\prxtbPro2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Productivity 1.12 Toolbar) - {30421e54-3b57-4e5b-947c-9b6beea57683} - C:\Program Files\Productivity_1.12\prxtbPro2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\15.3.0.11\AVG Secure Search_toolbar.dll (AVG Secure Search)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Productivity Toolbar) - {1C9B96A0-CBA2-482E-9C40-9200B547123A} - C:\Program Files\Productivity\prxtbPro2.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Productivity 1.12 Toolbar) - {30421E54-3B57-4E5B-947C-9B6BEEA57683} - C:\Program Files\Productivity_1.12\prxtbPro2.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: assurant.com ([epic] * in Trusted sites)
O15 - HKCU\..Trusted Domains: phoenix.edu ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: yahoo.com ([search] http in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1347287372453 (MUWebControl Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DEF0AFCD-388F-428D-970E-07606476773F}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll File not found
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.3.0\ViProtocol.dll (AVG Secure Search)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 17:29:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/04/14 22:54:30 | 000,000,166 | —- | M] () - G:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/07/20 14:36:37 | 000,602,112 | —- | C] (OldTimer Tools) – C:\OTL.exe
[2013/07/20 13:18:14 | 000,000,000 | —D | C] – C:\Documents and Settings\xxxxxxxxxx\Local Settings\Application Data\Conduit
[2013/07/10 23:52:25 | 000,000,000 | —D | C] – C:\WINDOWS\System32\MRT
[2013/07/09 12:11:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG
[2011/06/14 21:22:33 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Program Files\OTL.exe
[2011/06/13 19:45:12 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Program Files\spybotsd162.exe
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\joycecrump\My Documents\*.tmp files -> C:\Documents and Settings\joycecrump\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/07/20 14:35:29 | 000,602,112 | —- | M] (OldTimer Tools) – C:\OTL.exe
[2013/07/20 14:32:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/07/20 14:30:00 | 000,000,998 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3746886026-3329410021-3030079851-1006UA.job
[2013/07/20 11:27:26 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/07/20 11:27:25 | 2110,767,104 | -HS- | M] () – C:\hiberfil.sys
[2013/07/19 22:30:00 | 000,000,946 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3746886026-3329410021-3030079851-1006Core.job
[2013/07/19 09:52:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/07/15 06:40:05 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/07/15 06:40:05 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/07/12 22:34:09 | 000,002,343 | —- | M] () – C:\Documents and Settings\xxxxxxxxxx\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/07/12 22:34:09 | 000,002,325 | —- | M] () – C:\Documents and Settings\xxxxxxxxxx\Desktop\Google Chrome.lnk
[2013/07/10 23:50:36 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/07/10 13:30:04 | 000,276,560 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/07/10 13:15:56 | 000,507,290 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/07/10 13:15:56 | 000,088,518 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/07/10 13:13:34 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/07/09 12:11:07 | 000,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2013.lnk
[2013/06/27 06:33:32 | 000,037,664 | —- | M] (AVG Technologies) – C:\WINDOWS\System32\drivers\avgtpx86.sys
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\xxxxxxxxxx\My Documents\*.tmp files -> C:\Documents and Settings\joycecrump\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/08/12 08:54:59 | 000,027,520 | —- | C] () – C:\Documents and Settings\xxxxxxxxxx\Local Settings\Application Data\dt.dat
[2012/02/29 01:20:15 | 001,200,175 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-3746886026-3329410021-3030079851-1006-0.dat
[2012/02/29 01:20:14 | 000,280,610 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/02/28 20:18:53 | 000,000,744 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2012/02/14 21:53:15 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/22 20:42:19 | 000,227,200 | —- | C] () – C:\WINDOWS\System32\drivers\cccp106.sys
[2012/01/22 20:42:18 | 002,093,106 | —- | C] () – C:\WINDOWS\select.exe
[2012/01/22 20:42:18 | 000,192,512 | —- | C] () – C:\WINDOWS\select2.exe
[2012/01/22 20:42:18 | 000,127,038 | —- | C] () – C:\WINDOWS\Clement.exe
[2012/01/22 20:42:18 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\dcccp106.dll
[2012/01/22 20:42:18 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\vcccp106.dll
[2012/01/22 20:42:18 | 000,036,864 | —- | C] () – C:\WINDOWS\JPGL.DLL
[2012/01/22 20:42:18 | 000,036,864 | —- | C] () – C:\WINDOWS\CleanDev.exe
[2012/01/22 20:42:18 | 000,032,768 | —- | C] () – C:\WINDOWS\DIV_IYUV.DLL
[2012/01/22 20:42:18 | 000,015,542 | —- | C] () – C:\WINDOWS\cccp106.ini
[2012/01/22 20:42:18 | 000,000,321 | —- | C] () – C:\WINDOWS\DC2110a.ini
[2011/08/08 00:40:14 | 000,027,166 | —- | C] () – C:\Program Files\WK+5+MGT+350+Team+Evaluation.odt
[2010/07/06 04:30:27 | 000,015,872 | —- | C] () – C:\Documents and Settings\xxxxxxxxxx\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2008/04/25 17:34:35 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2010/03/10 00:33:41 | 001,509,888 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 08:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/06/27 06:33:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2012/09/29 10:10:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2013
[2010/11/28 19:24:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/11/28 19:59:56 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2013/07/20 08:30:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/03/11 11:07:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2012/10/22 15:59:32 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2012/09/29 10:09:36 | 000,000,000 | —D | M] – C:\Documents and Settings\xxxxxxxxxx\Application Data\AVG Secure Search
[2012/09/29 10:12:14 | 000,000,000 | —D | M] – C:\Documents and Settings\xxxxxxxxxx\Application Data\AVG2013
[2010/03/30 16:57:25 | 000,000,000 | —D | M] – C:\Documents and Settings\xxxxxxxxxx\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/05/25 18:07:33 | 000,000,000 | —D | M] – C:\Documents and Settings\xxxxxxxxxx\Application Data\E-centives
[2013/07/20 14:35:39 | 000,000,000 | —D | M] – C:\Documents and Settings\xxxxxxxxxx\Application Data\PriceGong
[2012/09/29 10:09:45 | 000,000,000 | —D | M] – C:\Documents and Settings\xxxxxxxxxx\Application Data\TuneUp Software
[2009/03/11 11:02:24 | 000,000,000 | —D | M] – C:\Documents and Settings\xxxxxxxxxx\Application Data\Windows Desktop Search
[2010/01/03 19:52:53 | 000,000,000 | —D | M] – C:\Documents and Settings\xxxxxxxxxx\Application Data\Windows Search
[2010/01/14 18:25:53 | 000,000,000 | —D | M] – C:\Documents and Settings\xxxxxxxxxx\Application Data\WinPatrol

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EX_ >
[2008/04/14 08:00:00 | 000,356,615 | —- | M] () MD5=D7B59A7EC9CB1429FDCEC84A22228555 – C:\I386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/14 08:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe

< MD5 for: EXPLORER.SC_ >
[2008/04/14 08:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\I386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2008/04/14 08:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: EXPLORER.ZIP >
[2006/03/06 23:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.CH_ >
[2008/04/14 08:00:00 | 000,199,077 | —- | M] () MD5=1D662719AB9BB40BA7526B3973D3F626 – C:\I386\IEXPLORE.CH_

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2008/04/14 08:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EX_ >
[2008/04/14 08:00:00 | 000,037,887 | —- | M] () MD5=2B46169148FFD81CAE84572CD32BDF86 – C:\I386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2008/04/14 08:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie8\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe

< MD5 for: IEXPLORE.EXE.EXP.LOG >
[2011/04/09 21:16:12 | 000,105,325 | —- | M] () MD5=3B85B9AF6D0999D31C90872F163A123E – C:\Program Files\Internet Explorer\iexplore.exe.exp.log

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2013/07/20 14:35:13 | 000,103,146 | —- | M] () MD5=5D3CD4212DB5D0A1D19BB0A57C108DE2 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HL_ >
[2008/04/14 08:00:00 | 000,059,881 | —- | M] () MD5=D23388C8D5D82D4D1C3B0B6A256E3CB7 – C:\I386\IEXPLORE.HL_

< MD5 for: IEXPLORE.HLP >
[2008/04/14 08:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2008/04/14 08:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES._ >
[2008/04/14 08:00:00 | 000,001,989 | —- | M] () MD5=29BB3BBBE3D49156A42BFB3DD000F554 – C:\I386\SERVICES._

< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/05/11 06:37:26 | 000,558,990 | —- | M] () MD5=FE8FB005031C2574E990DAC1F9F5ACF8 – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.EX_ >
[2008/04/14 08:00:00 | 000,049,959 | —- | M] () MD5=EE4885163C0C0729A3C5F1416A6E5F48 – C:\I386\SERVICES.EX_

< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 08:00:00 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe

< MD5 for: SERVICES.HTML >
[2008/04/16 12:29:04 | 000,004,166 | —- | M] () MD5=DB0CABD236311DDEB186C9B8A13F39A6 – C:\Program Files\BillP Studios\WinPatrol\services.html

< MD5 for: SERVICES.LNK >
[2013/02/09 13:09:26 | 000,001,604 | —- | M] () MD5=667A6209A86C80BE4E81D4A257F3411D – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.LNK

< MD5 for: SERVICES.MS_ >
[2008/04/14 08:00:00 | 000,003,649 | —- | M] () MD5=64E9F61D2ED093C361862DE36433B5E1 – C:\I386\SERVICES.MS_

< MD5 for: SERVICES.MSC >
[2008/04/14 08:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: SERVICES.SBS >
[2013/07/16 13:21:30 | 000,034,818 | —- | M] () MD5=E2ACBC77020C8D5CE97CA61D0D859A44 – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs

< MD5 for: WINLOGON.EX_ >
[2008/04/14 08:00:00 | 000,265,069 | —- | M] () MD5=063EF1A46C58A731F78AE5AF47070D65 – C:\I386\WINLOGON.EX_

< MD5 for: WINLOGON.EXE >
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 08:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2012/12/22 13:18:21 | 000,015,564 | —- | M] () – C:\Address List Labels (pg1)update .docx
[2012/12/22 13:17:59 | 000,013,453 | —- | M] () – C:\Address List Labels (pg2).docx
[2008/04/25 17:29:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/01/03 19:35:04 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2008/04/25 17:29:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/02/05 16:04:20 | 000,021,575 | —- | M] () – C:\xxxxxxxxxxxx Resume- Customer Service Account Coordinator 081010.docx
[2010/08/10 23:34:49 | 000,021,599 | —- | M] () – C:\xxxxxxxxxxxx Resume- Customer Service Account Coordinator 081010b.docx
[2010/08/10 22:36:26 | 000,021,273 | —- | M] () – C:\xxxxxxxxxxxx Resume- Purchasing and Inventory Control 0808010.docx
[2010/07/14 00:11:52 | 000,021,822 | —- | M] () – C:\xxxxxxxxxxxx.docx
[2010/08/11 00:02:56 | 000,018,004 | —- | M] () – C:\Customer Service Account Coordinator Cover Letter 081010.docx
[2009/03/11 13:53:13 | 000,005,668 | RH– | M] () – C:\dell.sdr
[2013/07/20 11:27:25 | 2110,767,104 | -HS- | M] () – C:\hiberfil.sys
[2008/04/25 17:29:32 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2010/08/25 23:06:29 | 000,017,757 | —- | M] () – C:\Loan Operations Clerk Cover Letter 082510.docx
[2010/01/14 22:07:57 | 000,000,302 | —- | M] () – C:\lxbt.log
[2008/04/25 17:29:32 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2008/04/14 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 08:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/07/20 14:35:29 | 000,602,112 | —- | M] (OldTimer Tools) – C:\OTL.exe
[2013/07/20 11:27:24 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/08/10 22:47:10 | 000,018,009 | —- | M] () – C:\Purchasing and Inventory Control Cover Letter 081010 Staffmark.docx

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/04/25 17:29:00 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/04/16 15:08:20 | 000,312,832 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp70v.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2008/12/04 22:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2011/06/14 21:30:15 | 000,054,188 | —- | M] () – C:\Program Files\Extras.Txt
[2011/06/14 21:22:00 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Program Files\OTL.exe
[2011/06/14 21:30:10 | 000,071,978 | —- | M] () – C:\Program Files\OTL.Txt
[2011/06/13 19:45:10 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Program Files\spybotsd162.exe
[2011/08/08 00:40:08 | 000,027,166 | —- | M] () – C:\Program Files\WK+5+MGT+350+Team+Evaluation.odt

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is OS
Volume Serial Number is 80D1-0301
Directory of C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices
07/10/2013 01:12 PM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote
07/10/2013 01:12 PM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.ConfigUXv2
04/10/2010 06:24 PM 3.0.335.0__540d4816ead86321
03/13/2011 07:10 PM 3.1.31.0__540d4816ead86321
0 File(s) 0 bytes
Directory of C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.Update
04/10/2010 06:24 PM 3.0.335.0__540d4816ead86321
03/13/2011 07:10 PM 3.1.31.0__540d4816ead86321
0 File(s) 0 bytes
Directory of C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices
07/10/2013 01:16 PM v4.0_4.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\Microsoft.NET\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.ConfigUXv4
02/28/2012 08:24 PM v4.0_4.0.66.0__3ff6b78e2989595a
04/08/2013 07:59 PM v4.0_4.0.78.0__3ff6b78e2989595a
0 File(s) 0 bytes
Directory of C:\WINDOWS\Microsoft.NET\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.Update
02/28/2012 08:24 PM v4.0_4.0.66.0__3ff6b78e2989595a
04/08/2013 07:59 PM v4.0_4.0.78.0__3ff6b78e2989595a
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
11 Dir(s) 128,922,390,528 bytes free

< %systemroot%\System32\config\*.sav >
[2008/04/25 05:21:09 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/04/25 05:21:09 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/04/25 05:21:09 | 000,905,216 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/04/25 17:29:41 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/01/03 19:35:28 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\joycecrump\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/04/25 17:33:01 | 000,000,079 | —- | M] () – C:\Documents and Settings\joycecrump\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2003/02/18 15:48:08 | 000,013,023 | —- | M] () – C:\WINDOWS\cccp106.src

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-07-10 17:18:36

< End of report >
Hello Bob L,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.

=========================

1. Uninstall via Programs and Features

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • AVG Secure Search
=========================

2. Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    Note: You will need to locate the xxxxxxx where you redacted your wife's name in the script below and copy and paste the correct information back into the script prior to running it.

    :OTL
    PRC - C:\Program Files\AVG Secure Search\vprot.exe ()
    PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe (AVG Secure Search)
    PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\loggingserver.exe ()
    MOD - C:\Program Files\AVG Secure Search\vprot.exe ()
    MOD - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\log4cplusU.dll ()
    MOD - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\SiteSafety.dll ()
    MOD - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\loggingserver.exe ()
    IE - HKCU\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2856459
    IE - HKCU\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://search.avg.com/route/?d=4b4fa847&am…=b&ychte=us
    FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
    FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
    FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll ()
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11 [2013/06/27 06:33:50 | 000,000,000 | —D | M]
    [2010/07/24 19:00:26 | 000,000,000 | —D | M] (ShopAtHome Intelligent Shopping Toolbar) – C:\Documents and Settings\xxxxxxxxxx\Application Data\Mozilla\Firefox\Profiles\pmnn103x.default\extensions\[removed]
    [2013/06/27 06:33:51 | 000,003,716 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
    CHR - default_search_provider: AVG Secure Search (Enabled)
    CHR - default_search_provider: search_url = http://isearch.avg.com/search?cid={DF2D24E…mp;d=2012-09-29 10:09:33&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms}
    CHR - Extension: AVG Security Toolbar = C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\
    O2 - BHO: (Productivity Toolbar) - {1c9b96a0-cba2-482e-9c40-9200b547123a} - C:\Program Files\Productivity\prxtbPro2.dll (Conduit Ltd.)
    O2 - BHO: (Productivity 1.12 Toolbar) - {30421e54-3b57-4e5b-947c-9b6beea57683} - C:\Program Files\Productivity_1.12\prxtbPro2.dll (Conduit Ltd.)
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll File not found
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (no name) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No CLSID value found.
    O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\15.3.0.11\AVG Secure Search_toolbar.dll (AVG Secure Search)
    O3 - HKLM\..\Toolbar: (Productivity Toolbar) - {1c9b96a0-cba2-482e-9c40-9200b547123a} - C:\Program Files\Productivity\prxtbPro2.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Productivity 1.12 Toolbar) - {30421e54-3b57-4e5b-947c-9b6beea57683} - C:\Program Files\Productivity_1.12\prxtbPro2.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\15.3.0.11\AVG Secure Search_toolbar.dll (AVG Secure Search)
    O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (Productivity Toolbar) - {1C9B96A0-CBA2-482E-9C40-9200B547123A} - C:\Program Files\Productivity\prxtbPro2.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Productivity 1.12 Toolbar) - {30421E54-3B57-4E5B-947C-9B6BEEA57683} - C:\Program Files\Productivity_1.12\prxtbPro2.dll (Conduit Ltd.)
    O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
    O15 - HKCU\..Trusted Domains: assurant.com ([epic] * in Trusted sites)
    O15 - HKCU\..Trusted Domains: phoenix.edu ([]* in Trusted sites)
    O15 - HKCU\..Trusted Domains: yahoo.com ([search] http in Trusted sites)
    O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.3.0\ViProtocol.dll (AVG Secure Search)
    [2013/07/20 13:18:14 | 000,000,000 | —D | C] – C:\Documents and Settings\xxxxxxxxxx\Local Settings\Application Data\Conduit
    [2013/06/27 06:33:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Secure Search
    [2012/09/29 10:09:36 | 000,000,000 | —D | M] – C:\Documents and Settings\xxxxxxxxxx\Application Data\AVG Secure Search
    
    :Files
    C:\Program Files\Common Files\AVG Secure Search
    
    :Services
    vToolbarUpdater15.3.0
    
    :Reg
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptyjava]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

3. Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Right click SecurityCheck.exe, select "Run as Administrator" and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
=========================

4. aswMBR

Download aswMBR.exe and save it to your desktop.

Right click and select "Run as Administrator".
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
=========================

5. Re-run OTL (it should be located on your desktop).

Windows Vista and Windows 7 & 8 users Right Click and select "Run as Administrator" on the icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt. (No Extras.txt will be produced)
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
=========================

In your next post please provide the following:
  • OTL fix log
  • Extras.txt log from first run of OTL (it should be on your desktop)
  • checkup.txt
  • aswMBR.txt
  • attachMBR.zip
  • Fresh OTL.txt
  • How is the computer running at the moment?
Thank you, OCD for such a fast response! As it is nearly mid-night, I will proceed with your instructions in the morning. This looks like I'm going to need a clear head, fresh eyes, and strong coffee! I'll post as soon as possible in the A.M. Thanks, again.
Good morning, OCD. I started to perform the tasks as instructed. However, I cannot even get past #1. I do not have "Programs and Features" under the Control Panel. I do have "Add/Remove", but AVG Secure Search is not listed there. AVG 2013 and AVG Security ToolBar are listed. I did locate AVG Secure Search listed under "Programs" on the "C" drive, but I hesitate to delete it from there without your specific instruction. Thanks!
Hi Bob L, I apologize that my instructions were confusing. I did not notice you are running Windows XP, my instructions were for Windows 7. :huh: The steps are basically the same just double click the program to get it to run rather than right click and run as administrator. Please skip Step 1 and continue with the remainder of the steps and post the corresponding logs. I am off to work so I will pick back up later this evening.
Hi Bob L,

Replace these instructions with Step #5. This will generate and Extras.txt

5. Re-run OTL (it should be located on your desktop).

Windows Vista and Windows 7 & 8 users Right Click and select "Run as Administrator" on the icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Under Extra Registry section, select Use SafeList <– important
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
=========================

Now I'm off to work….
Hello, OCD Hope all went well at work. Here are the items you requested, in order I think. Please note, I could find no evidence of an Etras.txt log from the first OTL. OTL fix log: ========== OTL ========== Process vprot.exe killed successfully! Process ToolbarUpdater.exe killed successfully! Process loggingserver.exe killed successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Prefs.js: "AVG Secure Search" removed from browser.search.defaultenginename Prefs.js: "AVG Secure Search" removed from browser.search.selectedEngine Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin\ deleted successfully. File move failed. C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll scheduled to be moved on reboot. Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\avg@toolbar deleted successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\skin folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\zh-tw folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\zh-cn folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\tr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\th folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\sv folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\sr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\sk folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\ru folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\ro folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\pt-br folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\pt folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\pl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\nl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\nb folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\ms folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\ko folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\ja folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\it folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\id folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\hu folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\hi folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\fr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\fi folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\es-es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\en folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\el folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\de folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\da folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\cs folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale\af folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules\locale folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\modules folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\locale\en-US folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\locale folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\components folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11\chrome folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.3.0.11 folder moved successfully. C:\Documents and Settings\joycecrump\Application Data\Mozilla\Firefox\Profiles\pmnn103x.default\extensions\[removed]\defaults\preferences folder moved successfully. C:\Documents and Settings\joycecrump\Application Data\Mozilla\Firefox\Profiles\pmnn103x.default\extensions\[removed]\defaults folder moved successfully. C:\Documents and Settings\joycecrump\Application Data\Mozilla\Firefox\Profiles\pmnn103x.default\extensions\[removed]\chrome folder moved successfully. C:\Documents and Settings\joycecrump\Application Data\Mozilla\Firefox\Profiles\pmnn103x.default\extensions\[removed] folder moved successfully. C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml moved successfully. Use Chrome's Settings page to remove the default_search_provider items. Use Chrome's Settings page to remove the default_search_provider items. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\zh_TW folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\zh_CN folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\tr folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\sr folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\sk folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\ru folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\pt_PT folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\pt_BR folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\pl folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\nl folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\ko folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\ja folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\it folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\id folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\hu folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\fr folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\es_419 folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\es folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\en folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\de folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\da folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales\cs folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\_locales folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\content\tabs folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\content\lib folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\content\js folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\content\icons\search_box folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\content\icons\dnt_disabled folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\content\icons folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\content\css folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\content\bho folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\content folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0 folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1c9b96a0-cba2-482e-9c40-9200b547123a}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1c9b96a0-cba2-482e-9c40-9200b547123a}\ deleted successfully. C:\Program Files\Productivity\prxtbPro2.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30421e54-3b57-4e5b-947c-9b6beea57683}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30421e54-3b57-4e5b-947c-9b6beea57683}\ deleted successfully. C:\Program Files\Productivity_1.12\prxtbPro2.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully. C:\Program Files\AVG Secure Search\15.3.0.11\AVG Secure Search_toolbar.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{1c9b96a0-cba2-482e-9c40-9200b547123a} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1c9b96a0-cba2-482e-9c40-9200b547123a}\ not found. File C:\Program Files\Productivity\prxtbPro2.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{30421e54-3b57-4e5b-947c-9b6beea57683} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30421e54-3b57-4e5b-947c-9b6beea57683}\ not found. File C:\Program Files\Productivity_1.12\prxtbPro2.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found. File C:\Program Files\AVG Secure Search\15.3.0.11\AVG Secure Search_toolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1C9B96A0-CBA2-482E-9C40-9200B547123A} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1C9B96A0-CBA2-482E-9C40-9200B547123A}\ not found. File C:\Program Files\Productivity\prxtbPro2.dll not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{30421E54-3B57-4E5B-947C-9B6BEEA57683} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30421E54-3B57-4E5B-947C-9B6BEEA57683}\ not found. File C:\Program Files\Productivity_1.12\prxtbPro2.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\vProt deleted successfully. C:\Program Files\AVG Secure Search\vprot.exe moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\assurant.com\epic\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\phoenix.edu\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\yahoo.com\search\ deleted successfully. C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.3.0\ViProtocol.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol\ deleted successfully. Invalid CLSID key: C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.3.0\ViProtocol.dll File C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.3.0\ViProtocol.dll not found. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Conduit\Community Alerts\Log folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Conduit\Community Alerts\LanguagePacks folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Conduit\Community Alerts\Feeds folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Conduit\Community Alerts\Dialogs folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Conduit\Community Alerts folder moved successfully. C:\Documents and Settings\joycecrump\Local Settings\Application Data\Conduit folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\Toolbar folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\Logger folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\skin folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\zh-tw folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\zh-cn folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\tr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\th folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\sv folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\sr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\sk folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\ru folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\ro folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\pt-br folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\pt folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\pl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\nl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\nb folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\ms folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\ko folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\ja folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\it folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\id folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\hu folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\hi folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\fr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\fi folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\es-es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\en folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\el folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\de folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\da folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\cs folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale\af folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules\locale folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\modules folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\locale\en-US folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\locale folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\components folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5\chrome folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\15.2.0.5 folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\skin folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\zh-tw folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\zh-cn folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\tr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\th folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\sv folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\sr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\sk folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\ru folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\ro folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\pt-br folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\pt folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\pl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\nl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\nb folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\ms folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\ko folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\ja folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\it folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\id folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\hu folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\hi folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\fr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\fi folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\es-es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\en folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\el folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\de folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\da folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\cs folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale\af folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules\locale folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\modules folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\locale\en-US folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\locale folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\components folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1\chrome folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.2.0.1 folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\skin folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\zh-tw folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\zh-cn folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\tr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\th folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\sv folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\sr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\sk folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\ru folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\ro folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\pt-br folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\pt folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\pl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\nl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\nb folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\ms folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\ko folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\ja folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\it folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\id folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\hu folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\hi folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\fr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\fi folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\es-es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\en folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\el folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\de folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\da folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\cs folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale\af folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules\locale folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\modules folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\locale\en-US folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\locale folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\components folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10\chrome folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.1.0.10 folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\skin folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\zh-tw folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\zh-cn folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\tr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\th folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\sv folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\sr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\sk folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\ru folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\ro folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\pt-br folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\pt folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\pl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\nl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\nb folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\ms folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\ko folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\ja folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\it folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\id folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\hu folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\hi folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\fr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\fi folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\es-es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\en folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\el folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\de folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\da folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\cs folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale\af folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules\locale folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\modules folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\locale\en-US folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\locale folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\components folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14\chrome folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.2.14 folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\skin folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\zh-tw folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\zh-cn folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\tr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\sr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\sk folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\ru folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\pt-br folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\pt folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\pl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\nl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\ms folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\ko folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\ja folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\it folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\id folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\hu folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\fr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\es-es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\en folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\de folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\da folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale\cs folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules\locale folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\modules folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\locale\en-US folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\locale folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\components folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5\chrome folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\13.2.0.5 folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\15.3.0.11 folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\15.2.0.5 folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\14.2.0.1 folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\14.1.0.10 folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\14.0.2.14 folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\UninstallRes\ClientPackage\Images\uninstall folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\UninstallRes\ClientPackage\Images folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\UninstallRes\ClientPackage folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\UninstallRes folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\zh_TW folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\zh_CN folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\tr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\sr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\sk folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\ru folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\pt_PT folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\pt_BR folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\pl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\nl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\ko folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\ja folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\it folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\id folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\hu folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\fr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\es_419 folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\en folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\de folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\da folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales\cs folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\_locales folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\content\lib folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\content\js folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\content\icons folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\content\css folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome\content folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5\Chrome folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\13.2.0.5 folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt\12.2.5.34 folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\ChromeExt folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\skin folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\zh-tw folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\zh-cn folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\tr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\sr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\sk folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\ru folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\pt-br folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\pt folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\pl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\nl folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\ms folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\ko folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\ja folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\it folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\id folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\hu folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\fr folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\es-es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\es folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\en folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\de folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\da folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale\cs folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules\locale folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\modules folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\locale\en-US folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\locale folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\components folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34\chrome folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search\12.2.5.34 folder moved successfully. C:\Documents and Settings\All Users\Application Data\AVG Secure Search folder moved successfully. C:\Documents and Settings\joycecrump\Application Data\AVG Secure Search\cache\tmp folder moved successfully. C:\Documents and Settings\joycecrump\Application Data\AVG Secure Search\cache folder moved successfully. C:\Documents and Settings\joycecrump\Application Data\AVG Secure Search folder moved successfully. ========== FILES ========== C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.3.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.1.7 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.0.1 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\13.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ToolBandTlb\15.3.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ToolBandTlb\15.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ToolBandTlb\14.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ToolBandTlb\14.1.7 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ToolBandTlb\14.0.1 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ToolBandTlb\13.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ToolBandTlb\12.2.6 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ToolBandTlb folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.0.1 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\13.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ScriptHelperInstaller\15.3.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ScriptHelperInstaller\15.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ScriptHelperInstaller\14.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ScriptHelperInstaller\14.1.7 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ScriptHelperInstaller\14.0.1 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ScriptHelperInstaller\13.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ScriptHelperInstaller\12.2.6 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\ScriptHelperInstaller folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\RewardsInstaller\15.3.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\RewardsInstaller\15.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\RewardsInstaller\14.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\RewardsInstaller\14.1.7 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\RewardsInstaller\14.0.1 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\RewardsInstaller folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DriverInstaller\15.3.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DriverInstaller\15.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DriverInstaller\14.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DriverInstaller\14.1.7 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DriverInstaller\14.0.1 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DriverInstaller\13.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DriverInstaller\12.2.6 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DriverInstaller folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DNTInstaller\15.3.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DNTInstaller\15.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DNTInstaller\14.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DNTInstaller\14.1.7 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DNTInstaller\14.0.1 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DNTInstaller\13.2.0 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DNTInstaller\12.2.6 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\DNTInstaller folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\CommonInstaller\12.2.6 folder moved successfully. C:\Program Files\Common Files\AVG Secure Search\CommonInstaller folder moved successfully. C:\Program Files\Common Files\AVG Secure Search folder moved successfully. ========== SERVICES/DRIVERS ========== Service vToolbarUpdater15.3.0 stopped successfully! Service vToolbarUpdater15.3.0 deleted successfully! ========== REGISTRY ========== ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYJAVA] User: Administrator User: All Users User: applications User: Autoreply Materials & Purchasing Manager Opportunity Via Centennial Website - Inbox - 'AT&T Yahoo! Mail'_files User: Default User User: joycecrump ->Java cache emptied: 8205775 bytes User: LocalService User: Microsoft Office Discount for US Students -The Ultimate Steal- Office 2007 Software for $59_95_files User: misc User: My Pictures User: My pictures #2 User: NetworkService User: OJI User: OneNote Notebooks User: University of Phoenix User: view-attachment_files User: Week 9 Bus 210 Final Project Total Java Files Cleaned = 8.00 mb [EMPTYFLASH] User: Administrator ->Flash cache emptied: 321 bytes User: All Users User: applications User: Autoreply Materials & Purchasing Manager Opportunity Via Centennial Website - Inbox - 'AT&T Yahoo! Mail'_files User: Default User ->Flash cache emptied: 321 bytes User: joycecrump ->Flash cache emptied: 36528 bytes User: LocalService User: Microsoft Office Discount for US Students -The Ultimate Steal- Office 2007 Software for $59_95_files User: misc User: My Pictures User: My pictures #2 User: NetworkService User: OJI User: OneNote Notebooks User: University of Phoenix User: view-attachment_files User: Week 9 Bus 210 Final Project Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 07212013_124234 Files\Folders moved on Reboot… File\Folder C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll not found! PendingFileRenameOperations files… Registry entries deleted on Reboot..
checkup.txt:
Results of screen317's Security Check version 0.99.70
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
AVG AntiVirus Free Edition 2013
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
WinPatrol
WinPatrol 2009 (Outdated! Latest version is WinPatrol 2012)
MVPS Hosts File
Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.75.0.1300
Java version out of Date!
Adobe Flash Player 11.7.700.224
Adobe Reader XI
Mozilla Firefox (3.6.16) Firefox out of Date!
````````Process Check: objlist.exe by Laurent````````
WinPatrol winpatrol.exe
AVG avgwdsvc.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
BillP Studios WinPatrol winpatrol.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 1%
````````````````````End of Log``````````````````````
aswMBR.txt: aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-07-21 13:39:00 —————————– 13:39:00.968 OS Version: Windows 5.1.2600 Service Pack 3 13:39:00.968 Number of processors: 2 586 0x1706 13:39:00.968 ComputerName: JOYCE UserName: 13:39:01.625 Initialize success 13:40:00.796 The log file has been saved successfully to "C:\aswMBR.txt" aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-07-21 13:39:00 —————————– 13:39:00.968 OS Version: Windows 5.1.2600 Service Pack 3 13:39:00.968 Number of processors: 2 586 0x1706 13:39:00.968 ComputerName: JOYCE UserName: 13:39:01.625 Initialize success 13:40:00.796 The log file has been saved successfully to "C:\aswMBR.txt" 13:47:15.390 AVAST engine defs: 13072100 13:47:36.406 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 13:47:36.406 Disk 0 Vendor: ST316081 4.AD Size: 152587MB BusType: 3 13:47:36.656 Disk 0 MBR read successfully 13:47:36.656 Disk 0 MBR scan 13:47:36.687 Disk 0 Windows VISTA default MBR code 13:47:36.687 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 54 MB offset 63 13:47:36.703 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 152531 MB offset 112455 13:47:36.703 Disk 0 scanning sectors +312496380 13:47:36.765 Disk 0 scanning C:\WINDOWS\system32\drivers 13:47:44.812 Service scanning 13:48:01.890 Modules scanning 13:48:29.953 Disk 0 trace - called modules: 13:48:29.984 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 13:48:29.984 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a8b7030] 13:48:29.984 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8a885028] 13:48:30.359 AVAST engine scan C:\WINDOWS 13:48:41.515 AVAST engine scan C:\WINDOWS\system32 13:52:15.406 AVAST engine scan C:\WINDOWS\system32\drivers 13:52:29.656 AVAST engine scan C:\Documents and Settings\joycecrump 13:58:14.062 AVAST engine scan C:\Documents and Settings\All Users 14:01:44.093 Scan finished successfully 14:02:25.359 Disk 0 MBR has been saved successfully to "C:\MBR.dat" 14:02:25.359 The log file has been saved successfully to "C:\aswMBR.txt"
MBR.zip

? I've got the zip file, but I can't seem to load it here.
I guess you'll have to tell me how to do that.

Fresh OTL.txt

OTL logfile created on: 7/21/2013 2:13:47 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.97 Gb Total Physical Memory | 1.23 Gb Available Physical Memory | 62.70% Memory free
3.81 Gb Paging File | 3.11 Gb Available in Paging File | 81.65% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 119.95 Gb Free Space | 80.53% Space Free | Partition Type: NTFS
Drive E: | 1.89 Gb Total Space | 0.66 Gb Free Space | 34.94% Space Free | Partition Type: FAT
Drive G: | 14.53 Gb Total Space | 12.99 Gb Free Space | 89.39% Space Free | Partition Type: FAT32

Computer Name: JOYCE | User Name: joycecrump | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\9f22d07e9863e4e1bf4f47ef4c3862e6\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\ee96e3bb14f5b3f2fe95c57e46c2495d\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\faa947d3cf5ddf23a46cf292df004a35\System.EnterpriseServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Transactions\5ec5f80f35fbc6665e2eddb7711a8410\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8f3e54440f3742da409131428ad1bce1\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\6ea5ee4386d67f4b432a27c40fbff93c\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Data\a4ed72fdc7627f5b58f32b31694a8885\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\4787bb699ed4291859fb86f15d793add\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\91c185bd043af039dcdc93e3fcf87f3d\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\256b7bb1216345c5a66ced50c1cf239d\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\5326f0da29e8171624f520a81f6e3eb1\System.Core.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\8a6d1c8abeb8eb82f06c7d075130cc67\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\cf58670896c5313b9b52f026f4455a5d\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\16562c54978851e92db8fec6f759bba1\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\b14359470744c840c59fbe4e58034fd6\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\5.0.136.0__7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\5.0.136.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\3.1.26.0__540d4816ead86321\Intuit.Spc.Esd.Core.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.DataAccess.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.Common.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data.SQLite\1.0.61.0__db937bc2d44ff139\System.Data.SQLite.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\5.0.104.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\5.0.104.0__7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\log4net\1.2.10.0__1b44e1d426115821\log4net.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\2.0.445.0__540d4816ead86321\Intuit.Spc.Esd.Core.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.DataAccess.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.Common.dll ()
MOD - C:\Program Files\BillP Studios\WinPatrol\sqlite3.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe (McAfee, Inc.)
SRV - (IntuitUpdateServiceV4) – C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit Inc.)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (sprtsvc_dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (IAANTMON) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (aswMBR) – C:\DOCUME~1\JOYCEC~1\LOCALS~1\Temp\aswMBR.sys File not found
DRV - (avgtp) – C:\WINDOWS\system32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\WINDOWS\system32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (IntcHdmiAddService) – C:\WINDOWS\system32\drivers\IntcHdmi.sys (Intel® Corporation)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Diag69xp) – C:\WINDOWS\system32\drivers\diag69xp.sys (Realtek Semiconductor Corporation)
DRV - (RTLVLAN) – C:\WINDOWS\system32\drivers\RTLVLAN.SYS (Realtek Semiconductor Corporation)
DRV - (LANPkt) – C:\WINDOWS\system32\drivers\LANPkt.sys (Realtek Semiconductor Corporation)
DRV - (DLADResM) – C:\WINDOWS\system32\drivers\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\drivers\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\drivers\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\drivers\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\drivers\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\drivers\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\drivers\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\drivers\DLAIFS_M.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (CCCP106) – C:\WINDOWS\system32\drivers\cccp106.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.msn.com/USSMB/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.msn.com/sphome.aspx
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://g.msn.com/USSMB/1
IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USSMB/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/sphome.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {1c9b96a0-cba2-482e-9c40-9200b547123a} - No CLSID value found
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7ADRA_en
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={DF2D24E…mp;d=2012-09-29 10:09:33&v;=15.2.0.5&pid;=avg&sg;=0&sap;=dsp&q;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:12.0.0.1912
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.23\npGoogleOneClick8.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/07/05 01:22:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/03 20:47:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/06/09 20:00:46 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/07/05 01:22:00 | 000,000,000 | —D | M]

[2010/04/16 01:11:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\joycecrump\Application Data\Mozilla\Extensions
[2013/07/21 12:42:52 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\joycecrump\Application Data\Mozilla\Firefox\Profiles\pmnn103x.default\extensions
[2012/05/06 01:50:38 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\joycecrump\Application Data\Mozilla\Firefox\Profiles\pmnn103x.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/05/06 01:50:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/18 18:28:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/11 09:27:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
File not found (No name found) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2010/05/25 18:07:33 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2012/02/22 18:58:26 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/03 06:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/02/22 18:58:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll

========== Chrome ==========

CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://isearch.avg.com/search?cid={DF2D24E…mp;d=2012-09-29 10:09:33&v;=15.2.0.5&pid;=avg&sg;=0&sap;=dsp&q;={searchTerms}
CHR - default_search_provider: suggest_url = http://toolbar.avg.com/acp?q={searchTerms}&o;=1
CHR - homepage: http://www.google.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\Application\28.0.1500.72\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: E-centives Coupon Activator Netscape Plugin v. 4.0.0.0 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPcol400.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: QuickTime Plug-in 7.6.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\joycecrump\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

O1 HOSTS File: ([2011/06/13 20:06:04 | 000,434,940 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14971 more lines…
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1347287372453 (MUWebControl Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DEF0AFCD-388F-428D-970E-07606476773F}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 17:29:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/04/14 22:54:30 | 000,000,166 | —- | M] () - G:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/07/21 13:38:39 | 004,745,728 | —- | C] (AVAST Software) – C:\aswMBR.exe
[2013/07/21 12:42:34 | 000,000,000 | —D | C] – C:\_OTL
[2013/07/20 14:36:37 | 000,602,112 | —- | C] (OldTimer Tools) – C:\OTL.exe
[2013/07/10 23:52:25 | 000,000,000 | —D | C] – C:\WINDOWS\System32\MRT
[2013/07/09 12:11:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG
[2011/06/14 21:22:33 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Program Files\OTL.exe
[2011/06/13 19:45:12 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Program Files\spybotsd162.exe
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\joycecrump\My Documents\*.tmp files -> C:\Documents and Settings\joycecrump\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/07/21 14:03:01 | 000,000,557 | —- | M] () – C:\MBR.zip
[2013/07/21 14:02:25 | 000,000,512 | —- | M] () – C:\MBR.dat
[2013/07/21 13:38:55 | 004,745,728 | —- | M] (AVAST Software) – C:\aswMBR.exe
[2013/07/21 13:32:15 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/07/21 13:30:00 | 000,000,998 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3746886026-3329410021-3030079851-1006UA.job
[2013/07/21 12:45:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/07/21 12:45:34 | 2110,767,104 | -HS- | M] () – C:\hiberfil.sys
[2013/07/20 22:30:54 | 000,000,946 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3746886026-3329410021-3030079851-1006Core.job
[2013/07/20 14:35:29 | 000,602,112 | —- | M] (OldTimer Tools) – C:\OTL.exe
[2013/07/19 09:52:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/07/15 06:40:05 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/07/15 06:40:05 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/07/12 22:34:09 | 000,002,343 | —- | M] () – C:\Documents and Settings\joycecrump\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/07/12 22:34:09 | 000,002,325 | —- | M] () – C:\Documents and Settings\joycecrump\Desktop\Google Chrome.lnk
[2013/07/10 23:50:36 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/07/10 13:30:04 | 000,276,560 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/07/10 13:15:56 | 000,507,290 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/07/10 13:15:56 | 000,088,518 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/07/10 13:13:34 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/07/09 12:11:07 | 000,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2013.lnk
[2013/06/27 06:33:32 | 000,037,664 | —- | M] (AVG Technologies) – C:\WINDOWS\System32\drivers\avgtpx86.sys
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\joycecrump\My Documents\*.tmp files -> C:\Documents and Settings\joycecrump\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/07/21 14:03:01 | 000,000,557 | —- | C] () – C:\MBR.zip
[2013/07/21 14:02:25 | 000,000,512 | —- | C] () – C:\MBR.dat
[2012/08/12 08:54:59 | 000,027,520 | —- | C] () – C:\Documents and Settings\joycecrump\Local Settings\Application Data\dt.dat
[2012/02/29 01:20:15 | 001,200,175 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-3746886026-3329410021-3030079851-1006-0.dat
[2012/02/29 01:20:14 | 000,280,610 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/02/28 20:18:53 | 000,000,744 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2012/02/14 21:53:15 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/22 20:42:19 | 000,227,200 | —- | C] () – C:\WINDOWS\System32\drivers\cccp106.sys
[2012/01/22 20:42:18 | 002,093,106 | —- | C] () – C:\WINDOWS\select.exe
[2012/01/22 20:42:18 | 000,192,512 | —- | C] () – C:\WINDOWS\select2.exe
[2012/01/22 20:42:18 | 000,127,038 | —- | C] () – C:\WINDOWS\Clement.exe
[2012/01/22 20:42:18 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\dcccp106.dll
[2012/01/22 20:42:18 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\vcccp106.dll
[2012/01/22 20:42:18 | 000,036,864 | —- | C] () – C:\WINDOWS\JPGL.DLL
[2012/01/22 20:42:18 | 000,036,864 | —- | C] () – C:\WINDOWS\CleanDev.exe
[2012/01/22 20:42:18 | 000,032,768 | —- | C] () – C:\WINDOWS\DIV_IYUV.DLL
[2012/01/22 20:42:18 | 000,015,542 | —- | C] () – C:\WINDOWS\cccp106.ini
[2012/01/22 20:42:18 | 000,000,321 | —- | C] () – C:\WINDOWS\DC2110a.ini
[2011/08/08 00:40:14 | 000,027,166 | —- | C] () – C:\Program Files\WK+5+MGT+350+Team+Evaluation.odt
[2010/07/06 04:30:27 | 000,015,872 | —- | C] () – C:\Documents and Settings\joycecrump\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2008/04/25 17:34:35 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2010/03/10 00:33:41 | 001,509,888 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 08:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >

Extras. txt from last run:
OTL Extras logfile created on: 7/21/2013 2:13:47 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.97 Gb Total Physical Memory | 1.23 Gb Available Physical Memory | 62.70% Memory free
3.81 Gb Paging File | 3.11 Gb Available in Paging File | 81.65% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 119.95 Gb Free Space | 80.53% Space Free | Partition Type: NTFS
Drive E: | 1.89 Gb Total Space | 0.66 Gb Free Space | 34.94% Space Free | Partition Type: FAT
Drive G: | 14.53 Gb Total Space | 12.99 Gb Free Space | 89.39% Space Free | Partition Type: FAT32

Computer Name: JOYCE | User Name: joycecrump | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe" = C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe:*:Enabled:Managed Services Agent
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Program Files\Internet Explorer\iexplore.exe" = C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer – (Microsoft Corporation)
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer
"C:\Program Files\AVG\AVG2013\avgmfapx.exe" = C:\Program Files\AVG\AVG2013\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update v4 Shared Downloads Server – (Intuit Inc.)
"C:\Program Files\AVG\AVG2013\avgnsx.exe" = C:\Program Files\AVG\AVG2013\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2013\avgdiagex.exe" = C:\Program Files\AVG\AVG2013\avgdiagex.exe:*:Enabled:AVG Diagnostics 2013 – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{0A042C19-1F48-4952-B3B6-828E8028A187}" = B209a-m
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1EF082D0-2DEF-4D45-98C8-64365D58D240}" = TurboTax 2012 wohiper
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2B4C7E1E-E446-4740-ADB5-9842E742EE8A}" = Windows Live Toolbar
"{2C045D2C-667D-4494-9684-E4B071C2C7FF}" = TurboTax 2010 wohiper
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3BAC6780-EAA2-012B-AE74-000000000000}" = TurboTax 2009 wohiper
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{5E4339CF-F287-4DB9-BE23-D8460487B3A3}" = AVG 2013
"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{65C0F43C-5F3B-4AB5-BFC9-ABA1C8F4AA7D}" = TurboTax 2011 wohiper
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6EA78F57-89F2-4B2E-8ADB-3FA6865D32EF}" = AVG 2013
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{88253B77-33C9-4A9D-9E4C-4579E39D9158}" = Diagnostics Utility
"{89EC099E-958D-462E-972C-385591946978}" = TurboTax 2012 WinPerFedFormset
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ULTIMATER_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ULTIMATER_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ULTIMATER_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ULTIMATER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ULTIMATER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ULTIMATER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-002E-0000-0000-0000000FF1CE}" = Microsoft Office Ultimate 2007
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{993A352A-2957-4661-A1EF-2D8F6F3C9234}" = Belkin Wireless G Plus MIMO USB Network Adapter
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = iSEEK AnswerWorks English Runtime
"{9FEF1A18-8F26-4F49-A5A4-956C12210624}" = HP Photosmart Plus B209a-m All-In-One Driver Software 13.0 Rel .6
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{A8B1F076-965D-4663-A9D4-C2FB58A42AE4}" = TurboTax 2012 WinPerTaxSupport
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B2455727-ED8F-4643-8A6E-F4AB8DE3633D}" = Network
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B65759DD-26C6-4EA6-9014-CA798907EBFD}" = PS_AIO_06_B209a-m_SW_Min
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CAF5B770-082F-40C4-853D-3973BB81BDAA}" = TurboTax 2011 WinPerTaxSupport
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E463E171-4082-4744-A466-F7CBE8502789}" = TurboTax 2011 WinPerReleaseEngine
"{E83F5F27-43F3-4163-ABE5-F68C989286ED}" = TurboTax 2012 wrapper
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{EE556A3E-EB37-4392-9637-BAA8EC2F47FA}" = TurboTax 2011 wrapper
"{F014B696-28C5-4554-802F-A15380418F53}" = TurboTax 2012 WinPerReleaseEngine
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{FAD3D68B-2F9C-459B-AA79-C04B9090FD72}" = TurboTax 2011 WinPerFedFormset
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG" = AVG 2013
"AVG Secure Search" = AVG Security Toolbar
"CIF USB Camera (2110A)" = CIF USB Camera (2110A)
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"ie8" = Windows Internet Explorer 8
"InstallShield_{993A352A-2957-4661-A1EF-2D8F6F3C9234}" = Belkin Wireless G Plus MIMO USB Network Adapter
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"McAfee Security Scan" = McAfee Security Scan Plus
"MegaStat 9.1" = MegaStat 9.1
"MegaStat Excel 2007" = MegaStat Excel 2007
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"Productivity Toolbar" = Productivity Toolbar
"Productivity_1.12 Toolbar" = Productivity 1.12 Toolbar
"SelectRebatesUninstall" = ShopAtHome SelectRebates
"Shop for HP Supplies" = Shop for HP Supplies
"TurboTax 2009" = TurboTax 2009
"TurboTax 2010" = TurboTax 2010
"TurboTax 2011" = TurboTax 2011
"TurboTax 2012" = TurboTax 2012
"ULTIMATER" = Microsoft Office Ultimate 2007
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPatrol" = WinPatrol 2009
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 7/19/2013 10:32:14 PM | Computer Name = JOYCE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/19/2013 10:32:17 PM | Computer Name = JOYCE | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

Error - 7/20/2013 12:40:31 AM | Computer Name = JOYCE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/20/2013 12:40:38 AM | Computer Name = JOYCE | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

Error - 7/20/2013 11:07:11 AM | Computer Name = JOYCE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module pricegongie.dll, version 3.6.12.0, fault address 0x0000b078.

Error - 7/20/2013 11:06:41 PM | Computer Name = JOYCE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/21/2013 7:56:27 AM | Computer Name = JOYCE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/21/2013 7:56:27 AM | Computer Name = JOYCE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/21/2013 1:48:10 PM | Computer Name = JOYCE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 7/21/2013 1:48:10 PM | Computer Name = JOYCE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

[ Application Events ]
Error - 7/19/2013 10:32:14 PM | Computer Name = JOYCE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/19/2013 10:32:17 PM | Computer Name = JOYCE | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

Error - 7/20/2013 12:40:31 AM | Computer Name = JOYCE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/20/2013 12:40:38 AM | Computer Name = JOYCE | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

Error - 7/20/2013 11:07:11 AM | Computer Name = JOYCE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module pricegongie.dll, version 3.6.12.0, fault address 0x0000b078.

Error - 7/20/2013 11:06:41 PM | Computer Name = JOYCE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/21/2013 7:56:27 AM | Computer Name = JOYCE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/21/2013 7:56:27 AM | Computer Name = JOYCE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/21/2013 1:48:10 PM | Computer Name = JOYCE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 7/21/2013 1:48:10 PM | Computer Name = JOYCE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

[ OSession Events ]
Error - 1/9/2012 12:19:44 AM | Computer Name = JOYCE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 15663
seconds with 2400 seconds of active time. This session ended with a crash.

Error - 1/9/2012 12:20:49 AM | Computer Name = JOYCE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 55
seconds with 0 seconds of active time. This session ended with a crash.

Error - 8/9/2012 8:27:51 AM | Computer Name = JOYCE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1529
seconds with 360 seconds of active time. This session ended with a crash.

Error - 9/14/2012 1:00:21 AM | Computer Name = JOYCE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1906
seconds with 480 seconds of active time. This session ended with a crash.

Error - 4/25/2013 11:12:04 PM | Computer Name = JOYCE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 9612
seconds with 6480 seconds of active time. This session ended with a crash.

Error - 5/21/2013 9:32:06 PM | Computer Name = JOYCE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 3527
seconds with 1560 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 7/17/2013 11:51:51 PM | Computer Name = JOYCE | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gusvc with
arguments "" in order to run the server: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}

Error - 7/19/2013 5:35:44 AM | Computer Name = JOYCE | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gusvc with
arguments "" in order to run the server: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}

Error - 7/19/2013 5:43:39 AM | Computer Name = JOYCE | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 00219B2C3796. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 7/19/2013 11:45:17 AM | Computer Name = JOYCE | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.0.2 on
the Network Card with network address 00219B2C3796.

Error - 7/19/2013 9:19:12 PM | Computer Name = JOYCE | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.0.2 on
the Network Card with network address 00219B2C3796.

Error - 7/20/2013 5:43:58 AM | Computer Name = JOYCE | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gusvc with
arguments "" in order to run the server: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}

Error - 7/20/2013 10:30:52 PM | Computer Name = JOYCE | Source = DCOM | ID = 10010
Description = The server {F25AF245-4A81-40DC-92F9-E9021F207706} did not register
with DCOM within the required timeout.

Error - 7/20/2013 10:32:56 PM | Computer Name = JOYCE | Source = DCOM | ID = 10010
Description = The server {F25AF245-4A81-40DC-92F9-E9021F207706} did not register
with DCOM within the required timeout.

Error - 7/21/2013 6:32:56 AM | Computer Name = JOYCE | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gusvc with
arguments "" in order to run the server: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}

Error - 7/21/2013 12:42:36 PM | Computer Name = JOYCE | Source = Service Control Manager | ID = 7034
Description = The vToolbarUpdater15.3.0 service terminated unexpectedly. It has
done this 1 time(s).


< End of report >


Not sure yet, as to the 'puter's performance.
I'll go try a few things and report back later.
Hello, OCD! I'm not ready to declare victory, but what a difference! Speed seems to be back, mouse goes where I point it and not on some trek of its own. No security warnings when logging into my email, and no pop-ups regarding low virtual memory. The only issue I can point to right now is a problem with Task Manager. It still doesn't open fully. The only thing that shows are the bottom three buttons (end, switch, new task) and I can't get it to close with out re-booting. So rather than do that right now, I'll wait for your response in case I need to be where we left off. Thanks!
Hi Bob L,

Don't worry about the MBR.zip file right now. That scan looks OK so we probably won't need it, but hang onto it until we are done just in case.

Do you use McAfee Security Scan?

=========================

1. Uninstall via Add/Remove Programs

  • Please go to Start > Control Panel > Add Remove Programs.
    Locate the following programs: (if present)
    • AVG Security Toolbar
    • Productivity Toolbar
    • Productivity 1.12 Toolbar
    • ShopAtHome SelectRebates
  • Click Remove and allow Windows to completely remove each one in turn.
  • Then reboot your computer to complete this part of the process.
=========================

2. Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={DF2D24E…mp;d=2012-09-29 10:09:33&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms}
    CHR - default_search_provider: AVG Secure Search (Enabled)
    CHR - default_search_provider: search_url = http://isearch.avg.com/search?cid={DF2D24E…mp;d=2012-09-29 10:09:33&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms}
    CHR - default_search_provider: suggest_url = http://toolbar.avg.com/acp?q={searchTerms}&o=1
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

3. AdwCleaner

Download AdwCleaner to your desktop.

  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
=========================

4. Re-run OTL (it should be located on your desktop).

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt.
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
=========================

In your next post please provide the following:
  • Answer to the question about McAfee.
  • AdwCleaner[S1].txt
  • Fresh OTL.txt
Thanks, OCD. I'll get on these in the morning. As for McAfee Security Scan, I haven't used it in years. I think it came with this computer but it was disabled (I thought) and we went to AVG. My other half has a Norton license for two more computers (she was required to use it for her college stuff), so we've considered adding it to this one. Your opinion would be greatly appreciated. Thanks, "see you" tomorrow sometime.
Hi Bob L,

We will address the McAfee remnants in a subsequent step.

If you already have a paid subscription to any software I would recommend using it until the subscription runs out. No sense in throwing money away. There are many good FREE versions of Anti-Virus programs out there so if you happy with the FREE version I would stick with it.

Complete the previous steps as outlined and post the logs when you can.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI