This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"You Do Not Have Sufficient Access to Uninstall Microsoft Securit

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been running Microsoft Security Essentials on this laptop, but the icon is NOT visible on the lower right corner of the toolbar anymore, and when trying to open the MSE program file, it says that I may not have "appropriate permission to run the file". So I thought I'd uninstall and re-install the program….when I try this, I can the following error message: "You do not have sufficient access to uninstall Microsft Security Essentials. Please contact your system administrator."

Now when trying to download OTL and Hijack This, I get a message that there is a virus and it rejects the download. So I downloaded both files on a USB Drive from another computer to run on this one. I could not run HiJack This, it gave me the following error message: "For some reason your system denied write access to the Hosts file. If any hijacked domains are in this file, HijackThis may NOT be able to fix this….."

Thank you so much for your help, in advance….


Below are the results for OTL and OTL Extra:

OTL:

OTL logfile created on: 7/30/2013 5:18:35 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Valued Customer\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.93 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.91% Memory free
4.10 Gb Paging File | 3.04 Gb Available in Paging File | 73.99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69.65 Gb Total Space | 27.36 Gb Free Space | 39.28% Space Free | Partition Type: NTFS
Drive D: | 69.64 Gb Total Space | 69.54 Gb Free Space | 99.87% Space Free | Partition Type: NTFS
Drive F: | 14.90 Gb Total Space | 7.00 Gb Free Space | 47.00% Space Free | Partition Type: FAT32

Computer Name: VALUEDCUSTOM-PC | User Name: Valued Customer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Valued Customer\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe (Adobe Systems Incorporated)
PRC - C:\Users\Valued Customer\AppData\Roaming\Yontoo\YontooDesktop.exe (Yontoo LLC)
PRC - C:\Program Files\Yontoo\Y2Desktop.Updater.exe (Microsoft)
PRC - C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Users\Valued Customer\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\CouponAlert_2p\bar\1.bin\2pbarsvc.exe (COMPANYVERS_NAME)
PRC - C:\Program Files\CouponAlert_2p\bar\1.bin\2pbrmon.exe (VER_COMPANY_NAME)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
PRC - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
PRC - C:\Acer\Mobility Center\MobilityService.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Users\Valued Customer\AppData\Roaming\Yontoo\dat\Desktop.OS.Plugin.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\798504f7455735fbc9abe8d6ebe73f03\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\4a249ccdc8817127b91bc36d1aa52b5e\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f58a8a55eda29b5a43af20c4568f7f91\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6ac6cab47b69e44769c726610e7f29bc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\e3cc2cbffd5fb21da64e93d9b6c27c7c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\6a938df70a8b7996a3890b4f34c83906\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll ()


========== Services (SafeList) ==========

SRV - (Yontoo Desktop Updater) – C:\Program Files\Yontoo\Y2Desktop.Updater.exe C:\Users\Valued Customer\AppData\Roaming\Yontoo\YontooDesktop.exe File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (NisSrv) – C:\Program Files\Microsoft Security Client\NisSrv.exe ()
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\MsMpEng.exe ()
SRV - (CouponAlert_2pService) – C:\Program Files\CouponAlert_2p\bar\1.bin\2pbarsvc.exe (COMPANYVERS_NAME)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (eDataSecurity Service) – C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
SRV - (ETService) – C:\Program Files\Acer\Empowering Technology\Service\ETService.exe ()
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll ()
SRV - (CLHNService) – C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe ()
SRV - (MobilityService) – C:\Acer\Mobility Center\MobilityService.exe ()


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) – C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl (Cyberlink Corp.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (int15) – C:\Windows\System32\drivers\int15.sys (Acer, Inc.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (NTIPPKernel) – C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys (Cyberlink Corp.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.glarysoft.com/?src=iehome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.coupons.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\SearchScopes,DefaultScope = {c1d89ae7-449d-4929-b24b-fded04adbe06}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{5a1d0d31-749c-4186-a295-4106e6e7b26a}: "URL" = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
IE - HKLM\..\SearchScopes\{c1d89ae7-449d-4929-b24b-fded04adbe06}: "URL" = http://isearch.glarysoft.com/?q={searchTer…mp;src=iesearch

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.glarysoft.com/?src=iehome
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://isearch.glarysoft.com/?src=iehome
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {7b9f8c21-46ec-4c0b-8683-e755ef84577a} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.delta-search.com/?q={searchTerm…40E001D72CEDA2D
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…38-1560FFAC2ADB
IE - HKCU\..\SearchScopes\{5a1d0d31-749c-4186-a295-4106e6e7b26a}: "URL" = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://search.coupons.com/search.asp?p=df&…q={searchTerms}
IE - HKCU\..\SearchScopes\{9E4F7F41-EDE2-4E4F-93EB-18CF2FE9C8DE}: "URL" = http://delicious.com/search?p={searchTerms}
IE - HKCU\..\SearchScopes\{B7EE063B-EFD9-4263-8DAD-0E51D357732A}: "URL" = http://addons.alltheinternet.com/texis/ope…q={searchTerms}
IE - HKCU\..\SearchScopes\{c1d89ae7-449d-4929-b24b-fded04adbe06}: "URL" = http://isearch.glarysoft.com/?q={searchTer…mp;src=iesearch
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?p={searchTerms}
IE - HKCU\..\SearchScopes\{F6B6724D-4318-44BC-BC2D-C1672ADCFDD1}: "URL" = http://websearch.shopathome.com?user_id=%g…q={searchTerms}
IE - HKCU\..\SearchScopes\{F7EFB045-B4C2-4B79-AD41-0F248DDD90B2}: "URL" = http://www.flickr.com/search/?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@CouponAlert_2p.com/Plugin: C:\Program Files\CouponAlert_2p\bar\1.bin\NP2pStub.dll (MindSpark)
FF - HKLM\Software\MozillaPlugins\@ei.WeatherBlink.com/Plugin: C:\Program Files\WeatherBlinkEI\Installr\1.bin\NPgcEISB.dll (WeatherBlink)
FF - HKLM\Software\MozillaPlugins\@funwebproducts.com/Plugin: C:\Program Files\FunWebProducts\Installr\1.bin\NPFunWeb.dll (Fun Web Products, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Valued Customer\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Valued Customer\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/10/27 09:15:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\2pffxtbr@CouponAlert_2p.com: C:\Program Files\CouponAlert_2p\bar\1.bin [2011/09/14 14:50:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{a131ab52-77f3-4bd7-acc7-e2dfdfd298f0}: C:\Users\Valued Customer\AppData\Roaming\Mozilla\FireFox\{a131ab52-77f3-4bd7-acc7-e2dfdfd298f0}.xpi

[2013/04/06 19:02:54 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Delta Search (Enabled)
CHR - default_search_provider: search_url = http://www.delta-search.com/?q={searchTerm…40E001D72CEDA2D
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.delta-search.com/?affID=119842&…40E001D72CEDA2D
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Valued Customer\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Valued Customer\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Valued Customer\AppData\Local\Google\Chrome\Application\28.0.1500.72\gcswf32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Users\Valued Customer\AppData\Local\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files\CouponAlert_2p\bar\1.bin\NP2pStub.dll
CHR - plugin: Fun Web Products Plugin Stub (Enabled) = C:\Program Files\FunWebProducts\Installr\1.bin\NPFunWeb.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: WeatherBlink Installer Plugin Stub (Enabled) = C:\Program Files\WeatherBlinkEI\Installr\1.bin\NPgcEISB.dll
CHR - plugin: Windows Live0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Valued Customer\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Entanglement = C:\Users\Valued Customer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: Poppit = C:\Users\Valued Customer\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: Yontoo = C:\Users\Valued Customer\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.3_1\

O1 HOSTS File: ([2010/10/25 12:02:42 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Toolbar BHO) - {3a421c8f-e238-4aeb-8874-b8b5f2cc4772} - C:\Program Files\CouponAlert_2p\bar\1.bin\2pbar.dll (MindSpark)
O2 - BHO: (Search Assistant BHO) - {60e91567-ef8a-4520-bce2-83aba5256799} - C:\Program Files\CouponAlert_2p\bar\1.bin\2pSrcAs.dll (COMPANYVERS_NAME)
O2 - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (Egis)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (TBSB07898 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll ()
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll (Yontoo LLC)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Coupon Alert) - {3462c343-be19-4143-af70-cefb56f46fc6} - C:\Program Files\CouponAlert_2p\bar\1.bin\2pbar.dll (MindSpark)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (Coupons.com CouponBar) - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKCU\..\Toolbar\WebBrowser: (Coupons.com CouponBar) - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [CouponAlert_2p Browser Plugin Loader] C:\Program Files\CouponAlert_2p\bar\1.bin\2pbrmon.exe (VER_COMPANY_NAME)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [Yontoo Desktop] C:\Users\Valued Customer\AppData\Roaming\Yontoo\YontooDesktop.exe (Yontoo LLC)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0824A661-8432-4D45-BB0E-EDDD2CED57A8}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B8D97734-E4BF-4B74-95C3-84583F32ED4D}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Valued Customer\Pictures\232323232fp54436_nu=3354__72_6;9_WSNRCG=38_2493593337nu0mrj.jpg
O24 - Desktop BackupWallPaper: C:\Users\Valued Customer\Pictures\232323232fp54436_nu=3354__72_6;9_WSNRCG=38_2493593337nu0mrj.jpg
O30 - LSA: Authentication Packages - (ows\s) - File not found
O30 - LSA: Security Packages - (X2嘀㬪蘁 獭ㅶた搮汬) - File not found
O30 - LSA: Security Packages - (>뻯㭐線㭐線&) - File not found
O30 - LSA: Security Packages - (풳) - File not found
O30 - LSA: Security Packages - () - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: wuauserv - File not found
NetSvcs: BITS - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/07/30 17:16:36 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Valued Customer\Desktop\OTL.exe
[2013/07/30 17:16:36 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Valued Customer\Desktop\HiJackThis.exe
[2013/07/25 19:54:08 | 000,000,000 | —D | C] – C:\Users\Valued Customer\AppData\Local\LogMeIn Rescue Applet
[2013/07/24 21:14:06 | 000,000,000 | -HSD | C] – C:\Windows\System32\%APPDATA%
[2013/07/24 03:00:53 | 000,000,000 | —D | C] – C:\Windows\System32\MRT
[2013/07/11 21:16:09 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/11 21:16:07 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/11 21:16:07 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/11 21:16:06 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/11 21:16:06 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/11 21:16:04 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/11 21:16:04 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/11 21:16:02 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/11 03:05:14 | 000,505,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2013/07/11 03:05:11 | 001,548,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVDECOD.DLL
[2013/07/11 03:04:21 | 002,049,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/07/11 03:04:16 | 001,069,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/07/11 03:04:16 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/11 03:04:16 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/11 03:04:16 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/11 03:04:15 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/11 03:04:15 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/11 03:04:15 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/11 03:04:15 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/07/30 17:17:14 | 000,616,164 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/07/30 17:17:14 | 000,108,172 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/07/30 17:15:08 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Valued Customer\Desktop\HiJackThis.exe
[2013/07/30 17:14:36 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Valued Customer\Desktop\OTL.exe
[2013/07/30 16:50:11 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/30 16:49:48 | 000,000,000 | —- | M] () – C:\Windows\System32\LogConfigTemp.xml
[2013/07/30 16:49:24 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/30 16:49:23 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/30 16:49:23 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/30 16:49:18 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/26 20:25:00 | 000,000,948 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-419784182-1888270494-198414776-1000UA.job
[2013/07/26 19:55:48 | 000,002,057 | —- | M] () – C:\Windows\epplauncher.mif
[2013/07/26 19:55:39 | 011,088,872 | —- | M] (Microsoft Corporation) – C:\Users\Valued Customer\Desktop\mseinstall.exe
[2013/07/26 19:43:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/26 18:00:00 | 000,000,464 | —- | M] () – C:\Windows\tasks\ParetoLogic Registration3.job
[2013/07/25 09:25:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-419784182-1888270494-198414776-1000Core.job
[2013/07/24 21:32:09 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/07/24 21:32:09 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/07/24 21:15:12 | 000,001,786 | —- | M] () – C:\Users\Valued Customer\Desktop\Microsoft Security Essentials.lnk
[2013/07/16 09:31:03 | 000,002,096 | —- | M] () – C:\Users\Valued Customer\Desktop\Google Chrome.lnk
[2013/07/11 21:35:25 | 000,299,568 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/07/24 21:15:12 | 000,001,786 | —- | C] () – C:\Users\Valued Customer\Desktop\Microsoft Security Essentials.lnk
[2013/03/10 17:21:34 | 000,108,308 | —- | C] () – C:\ProgramData\eiffmbrvgphbbfn
[2010/07/02 20:33:08 | 000,009,216 | —- | C] () – C:\Users\Valued Customer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2013/07/24 18:17:19 | 000,002,048 | -HS- | M] () – C:\$RECYCLE.BIN\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\@
[2013/07/24 18:17:19 | 000,029,696 | -HS- | M] () – C:\$RECYCLE.BIN\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\n
[2013/07/24 21:30:21 | 000,000,000 | -HSD | M] – C:\$RECYCLE.BIN\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\L
[2013/07/24 21:08:41 | 000,000,000 | -HSD | M] – C:\$RECYCLE.BIN\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U
[2013/07/24 21:08:42 | 000,000,804 | —- | M] () – C:\$RECYCLE.BIN\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\L\00000004.@
[2013/07/24 21:08:39 | 000,002,048 | —- | M] () – C:\$RECYCLE.BIN\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\00000004.@
[2013/07/24 21:08:39 | 000,001,024 | —- | M] () – C:\$RECYCLE.BIN\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\00000008.@
[2013/07/24 21:08:39 | 000,001,632 | —- | M] () – C:\$RECYCLE.BIN\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\000000cb.@
[2013/07/24 21:08:39 | 000,011,776 | —- | M] () – C:\$RECYCLE.BIN\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\80000000.@
[2013/07/24 21:08:41 | 000,091,648 | —- | M] () – C:\$RECYCLE.BIN\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\80000032.@
[2006/11/02 08:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[2013/07/24 21:08:34 | 000,005,120 | -HS- | M] () – C:\Windows\assembly\GAC\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 13:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 02:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2008/08/31 02:40:45 | 000,000,000 | —D | M] – C:\Users\Valued Customer\AppData\Roaming\Acer
[2008/04/30 05:52:47 | 000,000,000 | —D | M] – C:\Users\Valued Customer\AppData\Roaming\Acer GameZone Console
[2013/04/06 19:02:26 | 000,000,000 | —D | M] – C:\Users\Valued Customer\AppData\Roaming\Babylon
[2010/11/23 11:52:05 | 000,000,000 | —D | M] – C:\Users\Valued Customer\AppData\Roaming\DriverCure
[2012/01/08 17:17:04 | 000,000,000 | —D | M] – C:\Users\Valued Customer\AppData\Roaming\GlarySoft
[2008/08/31 02:40:45 | 000,000,000 | —D | M] – C:\Users\Valued Customer\AppData\Roaming\Leadertech
[2013/04/08 08:27:48 | 000,000,000 | —D | M] – C:\Users\Valued Customer\AppData\Roaming\Open Download Manager
[2010/11/23 11:52:05 | 000,000,000 | —D | M] – C:\Users\Valued Customer\AppData\Roaming\ParetoLogic
[2011/10/05 14:57:14 | 000,000,000 | —D | M] – C:\Users\Valued Customer\AppData\Roaming\PC Cleaners
[2011/03/14 17:03:27 | 000,000,000 | —D | M] – C:\Users\Valued Customer\AppData\Roaming\Windows Live Writer
[2013/07/26 17:49:56 | 000,000,000 | —D | M] – C:\Users\Valued Customer\AppData\Roaming\Yontoo

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2008/10/29 02:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 02:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 23:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 22:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 22:24:24 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2006/11/02 08:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\en-US\explorer.exe.mui
[2006/11/02 08:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20\explorer.exe.mui

< MD5 for: IEXPLORE.EXE >
[2012/05/17 19:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16446_none_5898f8e3ebb5c47b\iexplore.exe
[2008/09/16 07:02:34 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=07ED775D6DB4BFA96D7CFB09EB228418 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16681_none_2d26424d1d17e8b7\iexplore.exe
[2009/01/15 00:14:36 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=0844F5B9CB3BB85A917D347EF1565B6C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16809_none_2d84c7c91ccfce35\iexplore.exe
[2012/11/13 22:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16457_none_588f2941ebbcf9c3\iexplore.exe
[2008/06/26 23:54:09 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=157F8DE991396C536820D7FA5C8DCF7D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16711_none_2d71f3a71cdf2247\iexplore.exe
[2008/09/16 07:00:39 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=182CAF7403705ACCB51211A761080B8F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20777_none_2dc0b0c03628049a\iexplore.exe
[2008/10/01 23:50:01 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=19403B64906C9EAC627E3C10847B0FDA – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16757_none_2d4cb5b31cfa2a15\iexplore.exe
[2009/11/21 02:42:38 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=1B6362BB14FCEB9E76BCF9A953B04788 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18865_none_120f459f2ff7e1f8\iexplore.exe
[2009/07/18 08:16:49 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=1D5A01AA2DE47C052AF46D7EBCB003A3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16890_none_2d1a75e31d20e59f\iexplore.exe
[2009/07/18 17:39:09 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=1D8163DBFECAEDB9C48C5F55084BC491 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18294_none_2f04b5b11a43dbec\iexplore.exe
[2009/03/03 00:18:52 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=1DD66A2851DACDEC32EAE8F9A8865ABD – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21023_none_2df29b2236034119\iexplore.exe
[2009/04/24 12:25:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=1F44940EF1D07D0BDAF80E55853DFBD0 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16851_none_2d46b5dd1cff8f32\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16450_none_5888273bebc34862\iexplore.exe
[2010/02/23 11:06:13 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=25DB705A7DC85C208B3CF2D20F118AA7 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22995_none_127872a6492dd595\iexplore.exe
[2012/05/17 18:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20551_none_5912c45104e00183\iexplore.exe
[2012/10/08 04:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16455_none_588d28adebbec715\iexplore.exe
[2009/04/11 02:27:44 | 000,636,080 | —- | M] (Microsoft Corporation) MD5=2C5168C856455CC43C4B4E1CC1920001 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\iexplore.exe
[2009/08/27 01:23:17 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=2E48756F12C21F46895036AC089AAD97 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18828_none_123d862d2fd4be39\iexplore.exe
[2013/02/22 00:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16476_none_5878891febce184e\iexplore.exe
[2013/05/28 23:32:47 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=33E62E4EFC2ACA8EC63A8926F26D3889 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20606_none_594dd74504b2f1a8\iexplore.exe
[2012/06/02 05:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16447_none_5899f92debb4ddd2\iexplore.exe
[2010/01/02 10:58:26 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=3D8DA00B028DEA9517066F1CECBFC4A2 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22973_none_128c11ea491f6b05\iexplore.exe
[2013/04/04 18:47:49 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=3F00BE80B9CEA20B7FE7363D15EDDB94 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16483_none_586ab855ebd8e83a\iexplore.exe
[2013/02/22 00:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20586_none_58f755ff04f3d409\iexplore.exe
[2010/05/04 02:32:18 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=48A6109E8DF0365195298CC527B7426A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23019_none_12d2cb5048e98eab\iexplore.exe
[2010/09/08 02:26:34 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4A719476A6393B1DCACFEB4F3AC6599C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23067_none_129abb204913e7b2\iexplore.exe
[2008/10/16 00:27:53 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=4CBA2F58668F2D5F3259CBE73E227F25 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20937_none_2debf43c36078f24\iexplore.exe
[2008/06/26 21:41:30 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=4DBD95312B1C96C5285D38F1D748CD4D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20868_none_2dcc82dc361eff27\iexplore.exe
[2010/11/02 02:03:13 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=5AB037B17F8A87D052F5A88E0D29A3C8 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18999_none_11f2d8e9300c984e\iexplore.exe
[2008/01/20 22:23:50 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=5B92133D3E7FB2644677686305E29E81 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\iexplore.exe
[2010/05/04 02:00:35 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=5C9B1062EA7A44E8F6BFDE994B68C7AA – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18928_none_123d88132fd4bb60\iexplore.exe
[2012/08/24 03:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20557_none_5918c60d04da998d\iexplore.exe
[2008/10/01 23:32:01 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=6655B851D9EEF7C83395EE52D551B448 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20927_none_2df6c42835ff7333\iexplore.exe
[2013/05/16 19:34:33 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16490_none_585ce78bebe3b826\iexplore.exe
[2013/01/08 18:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16464_none_58815877ebc7c9af\iexplore.exe
[2010/06/26 02:06:48 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7420BE0E7D3D1320054F7ACA0594953D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18943_none_1222e6c92fe9748f\iexplore.exe
[2010/12/18 03:19:44 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7852371DA9EFBC17B645558E23780EAC – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23111_none_12cacae648f0c11a\iexplore.exe
[2009/08/27 09:31:08 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=7DD482E4A2E3CBB0A72F718C342F5B75 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22918_none_12d1f2e448ea4212\iexplore.exe
[2009/07/18 08:16:45 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=7FCF4E704A48D95202F3E7A1E1A21412 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21089_none_2db7bd56362e80c9\iexplore.exe
[2010/01/02 02:40:20 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=88BD42DAE7CFFEB256CA7145A15E4843 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18882_none_11f6a4e9300acdd5\iexplore.exe
[2009/03/03 00:32:44 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=8BA2B7A05F88BE0D45237A0994AD8366 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22389_none_2f9e23da3354de78\iexplore.exe
[2011/04/18 17:12:30 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16421_none_58a99749ebaa0de6\iexplore.exe
[2010/11/02 03:13:47 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=92A17B0A89D14815AACC62CD190B6CE3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23091_none_127449a04931a37b\iexplore.exe
[2012/06/28 21:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16448_none_589af977ebb3f729\iexplore.exe
[2008/09/16 07:00:39 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9437CA21CD48C9B6BFD6F5AC0143D251 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16643_none_2d5382911cf5aba1\iexplore.exe
[2011/02/22 03:18:28 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=9CE5543464432CA73134F170FA2BF823 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23143_none_12ac5bb64907479b\iexplore.exe
[2009/08/27 10:04:53 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=9E45866CD349219784CD5A7620DBEB8A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16916_none_2d76f8e51cda9b48\iexplore.exe
[2009/03/03 00:40:22 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=9E6C1527D9A2C64BFD780AA23075380F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18226_none_2f5265b91a094b03\iexplore.exe
[2008/09/16 07:02:34 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9F1427F203CA078005C9943800929640 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20823_none_2df2c11a360310b0\iexplore.exe
[2010/02/23 02:39:16 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=9F52FBE99C749E3F32C75124F09F1B03 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18904_none_124f26c32fc81e22\iexplore.exe
[2013/02/02 00:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20580_none_58f1544304f93bff\iexplore.exe
[2009/08/27 09:43:41 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=A76AFC309AA55CD607A28AC41C7D7603 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21116_none_2e006dd235f86e54\iexplore.exe
[2013/05/16 18:27:11 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=A8732CEDB2C0EE7AFC08F867A47BB3EC – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20600_none_5947d58904b8599e\iexplore.exe
[2009/03/08 17:09:24 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\iexplore.exe
[2010/12/18 02:28:35 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=B988D7F127B94BD5BF8356FE81B985C4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19019_none_1249306b2fcbec08\iexplore.exe
[2009/08/27 09:38:13 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=BBF84F317553520BB78AEF7B047325C1 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18319_none_2f60386919fe783e\iexplore.exe
[2012/06/02 04:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20553_none_5914c4e504de3431\iexplore.exe
[2013/04/04 17:55:02 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=C036AB1ED8BAC04FE4A349BA263077BB – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20593_none_58e9853504fea3f5\iexplore.exe
[2011/02/22 02:21:12 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=C1D36A2CBE0CEC4DF593DB1288CF586E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19048_none_1227c05d2fe52684\iexplore.exe
[2012/10/08 04:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20562_none_5908f4af04e736cb\iexplore.exe
[2009/04/24 12:03:18 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=D5271AC4A06AD9D1E2EA0151B79B2657 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21046_none_2ddffc283610c500\iexplore.exe
[2010/09/08 02:02:42 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=D5A730DFDEAE005373E62BC2A866E3BB – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18975_none_120477992ffffb10\iexplore.exe
[2009/04/24 12:01:36 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=D6157423C117F24D24695866A1D0A93F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22418_none_2fe8d4ea331cfeb1\iexplore.exe
[2008/10/16 00:42:58 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=D762642A109433EEDCD332B0A9511137 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16764_none_2d3ee4e91d04fa01\iexplore.exe
[2013/02/02 00:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16470_none_58728763ebd38044\iexplore.exe
[2009/11/21 11:05:17 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=E7F8DF50E483D165BB01F367D3519AA7 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22956_none_12a4b2a0490c7f28\iexplore.exe
[2009/03/03 00:22:10 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=EA4BE33726155F89D89A3FE7142878E0 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16830_none_2d5b556b1cf03df9\iexplore.exe
[2012/06/28 19:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20554_none_5915c52f04dd4d88\iexplore.exe
[2009/07/18 07:55:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=EBEE9E4421F35CD861107DDA0266FBB1 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22475_none_2fa4f48433505a52\iexplore.exe
[2013/05/28 22:24:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=EE12BA876C4190532A4085994BA9B616 – C:\Program Files\Internet Explorer\iexplore.exe
[2013/05/28 22:24:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=EE12BA876C4190532A4085994BA9B616 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16496_none_5862e947ebde5030\iexplore.exe
[2013/01/08 17:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20573_none_58ff250d04ee6c13\iexplore.exe
[2010/06/26 02:52:42 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=F05B3A2C6CB319DD1377AD566CF5ECE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23040_none_12a958f24909fe6f\iexplore.exe
[2009/01/15 00:18:47 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=F0B1CA517977BA2FF6DA33F1B966C488 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20996_none_2daa146a36391d73\iexplore.exe
[2009/04/24 12:08:04 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=F294D8EEB05C835EC44A12CE0A1DFE7A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18248_none_2f3ec6751a17b593\iexplore.exe
[2012/11/13 22:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20565_none_590bf58d04e482d0\iexplore.exe
[2009/08/27 09:19:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=FE2DFF83B7753AC47C553EF7D5289BEE – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22508_none_2ff3a6bc3314dfe7\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2006/11/02 08:41:15 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590\iexplore.exe.mui
[2011/04/18 17:12:33 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011/04/18 17:12:33 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.1.8112.16421_en-us_52562cc123574ecd\iexplore.exe.mui
[2009/03/08 17:27:11 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_8.0.6001.18702_en-us_207795706a90d6c1\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-908C99F8.PF >
[2013/07/30 17:11:02 | 000,310,524 | —- | M] () MD5=14408585220311D579D54CCC0FD0AFE4 – C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf

< MD5 for: SERVICES >
[2006/09/18 17:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\System32\drivers\etc\services
[2006/09/18 17:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services

< MD5 for: SERVICES.EXE >
[2008/01/20 22:24:48 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\System32\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2006/11/02 08:40:53 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\System32\en-US\services.exe.mui
[2006/11/02 08:40:53 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui

< MD5 for: SERVICES.LNK >
[2008/01/20 22:42:58 | 000,001,688 | —- | M] () MD5=C50AE46E57C3F3FB61A3B3A1E5D9C412 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2008/01/20 22:42:58 | 000,001,688 | —- | M] () MD5=C50AE46E57C3F3FB61A3B3A1E5D9C412 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2006/09/18 17:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2006/09/18 17:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.mof
[2006/09/18 17:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.mof

< MD5 for: SERVICES.MSC >
[2006/11/02 08:41:29 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2006/09/18 17:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2006/11/02 08:41:29 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a2085506ff73b6e0\services.msc
[2006/09/18 17:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_cf63e2a445bae4e3\services.msc

< MD5 for: WINLOGON.EXE >
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 22:24:49 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2008/01/20 22:25:40 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\System32\en-US\winlogon.exe.mui
[2008/01/20 22:25:40 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_en-us_caf8918b0416723a\winlogon.exe.mui
[2006/11/02 08:40:50 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c8c1cf8f072b6166\winlogon.exe.mui

< MD5 for: WINLOGON.MOF >
[2006/09/18 17:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\System32\wbem\winlogon.mof
[2006/09/18 17:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_7e0207d478fccc94\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2011/07/25 15:12:18 | 000,000,485 | —- | M] () – C:\0
[2011/12/02 13:16:55 | 000,000,490 | —- | M] () – C:\0.bak
[2006/09/18 17:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 02:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/02/05 19:25:41 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2012/10/23 19:41:25 | 000,000,000 | —- | M] () – C:\install.rdf
[2013/07/30 16:49:12 | 2386,681,856 | -HS- | M] () – C:\pagefile.sys
[2008/08/27 23:34:46 | 000,002,623 | -HS- | M] () – C:\Patch.rev
[2008/08/18 05:45:59 | 000,000,151 | RHS- | M] () – C:\preload.rev
[2010/10/25 12:02:42 | 000,000,000 | -H– | M] () – C:\ProgramData.LOG1
[2010/10/25 12:02:42 | 000,000,000 | -H– | M] () – C:\ProgramData.LOG2
[2008/09/16 06:19:53 | 000,000,426 | —- | M] () – C:\RHDSetup.log
[1 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2006/11/02 08:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/02/16 13:49:18 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 17:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/12/17 18:05:32 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2006/11/02 08:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 22:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 03:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 22:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is ACER
Volume Serial Number is 240E-99D1
Directory of C:\
11/02/2006 09:02 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\Program Files\Microsoft Security Client
11/03/2012 07:36 PM Backup [c:\windows\system32\config]
05/23/2012 10:25 AM DbgHelp.dll [c:\windows\system32\config]
03/06/2013 04:02 AM Drivers [c:\windows\system32\config]
03/06/2013 04:02 AM en-us [c:\windows\system32\config]
01/27/2013 03:37 PM EppManifest.dll [c:\windows\system32\config]
01/27/2013 01:25 PM MpAsDesc.dll [c:\windows\system32\config]
01/27/2013 12:12 PM MpClient.dll [c:\windows\system32\config]
01/27/2013 12:11 PM MpCmdRun.exe [c:\windows\system32\config]
01/27/2013 12:12 PM MpCommu.dll [c:\windows\system32\config]
01/27/2013 01:05 PM mpevmsg.dll [c:\windows\system32\config]
01/27/2013 12:12 PM MpOAv.dll [c:\windows\system32\config]
01/27/2013 12:12 PM MpRTP.dll [c:\windows\system32\config]
01/27/2013 12:12 PM MpSvc.dll [c:\windows\system32\config]
01/27/2013 12:12 PM MsMpCom.dll [c:\windows\system32\config]
01/27/2013 12:11 PM MsMpEng.exe [c:\windows\system32\config]
01/27/2013 12:11 PM MsMpLics.dll [c:\windows\system32\config]
01/27/2013 12:08 PM MsMpRes.dll [c:\windows\system32\config]
01/27/2013 12:11 PM msseces.exe [c:\windows\system32\config]
01/27/2013 12:11 PM MsseWat.dll [c:\windows\system32\config]
01/27/2013 12:12 PM NisIpsPlugin.dll [c:\windows\system32\config]
01/27/2013 12:12 PM NisLog.dll [c:\windows\system32\config]
01/27/2013 12:11 PM NisSrv.exe [c:\windows\system32\config]
01/27/2013 12:12 PM NisWFP.dll [c:\windows\system32\config]
01/27/2013 12:11 PM Setup.exe [c:\windows\system32\config]
01/27/2013 12:08 PM SetupRes.dll [c:\windows\system32\config]
01/27/2013 12:08 PM shellext.dll [c:\windows\system32\config]
02/08/2012 04:06 PM SqmApi.dll [c:\windows\system32\config]
05/23/2012 10:25 AM SymSrv.dll [c:\windows\system32\config]
04/06/2012 09:59 AM SymSrv.yes [c:\windows\system32\config]
26 File(s) 7,943,785 bytes
Directory of C:\Program Files\Microsoft Security Client\Backup\systemprofile
09/16/2008 06:11 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
09/16/2008 06:11 AM Cookies [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies]
09/16/2008 06:11 AM Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
09/16/2008 06:11 AM My Documents [C:\Windows\system32\config\systemprofile\Documents]
09/16/2008 06:11 AM NetHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
09/16/2008 06:11 AM PrintHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
09/16/2008 06:11 AM Recent [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent]
09/16/2008 06:11 AM SendTo [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo]
09/16/2008 06:11 AM Start Menu [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu]
09/16/2008 06:11 AM Templates [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Program Files\Microsoft Security Client\Backup\systemprofile\AppData\Local
09/16/2008 06:11 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
09/16/2008 06:11 AM History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
09/16/2008 06:11 AM Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Program Files\Microsoft Security Client\Backup\systemprofile\Documents
09/16/2008 06:11 AM My Music [C:\Windows\system32\config\systemprofile\Music]
09/16/2008 06:11 AM My Pictures [C:\Windows\system32\config\systemprofile\Pictures]
09/16/2008 06:11 AM My Videos [C:\Windows\system32\config\systemprofile\Videos]
0 File(s) 0 bytes
Directory of C:\Program Files\Microsoft Security Client\Drivers\systemprofile
09/16/2008 06:11 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
09/16/2008 06:11 AM Cookies [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies]
09/16/2008 06:11 AM Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
09/16/2008 06:11 AM My Documents [C:\Windows\system32\config\systemprofile\Documents]
09/16/2008 06:11 AM NetHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
09/16/2008 06:11 AM PrintHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
09/16/2008 06:11 AM Recent [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent]
09/16/2008 06:11 AM SendTo [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo]
09/16/2008 06:11 AM Start Menu [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu]
09/16/2008 06:11 AM Templates [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Program Files\Microsoft Security Client\Drivers\systemprofile\AppData\Local
09/16/2008 06:11 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
09/16/2008 06:11 AM History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
09/16/2008 06:11 AM Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Program Files\Microsoft Security Client\Drivers\systemprofile\Documents
09/16/2008 06:11 AM My Music [C:\Windows\system32\config\systemprofile\Music]
09/16/2008 06:11 AM My Pictures [C:\Windows\system32\config\systemprofile\Pictures]
09/16/2008 06:11 AM My Videos [C:\Windows\system32\config\systemprofile\Videos]
0 File(s) 0 bytes
Directory of C:\Program Files\Microsoft Security Client\en-us\systemprofile
09/16/2008 06:11 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
09/16/2008 06:11 AM Cookies [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies]
09/16/2008 06:11 AM Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
09/16/2008 06:11 AM My Documents [C:\Windows\system32\config\systemprofile\Documents]
09/16/2008 06:11 AM NetHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
09/16/2008 06:11 AM PrintHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
09/16/2008 06:11 AM Recent [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent]
09/16/2008 06:11 AM SendTo [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo]
09/16/2008 06:11 AM Start Menu [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu]
09/16/2008 06:11 AM Templates [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Program Files\Microsoft Security Client\en-us\systemprofile\AppData\Local
09/16/2008 06:11 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
09/16/2008 06:11 AM History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
09/16/2008 06:11 AM Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Program Files\Microsoft Security Client\en-us\systemprofile\Documents
09/16/2008 06:11 AM My Music [C:\Windows\system32\config\systemprofile\Music]
09/16/2008 06:11 AM My Pictures [C:\Windows\system32\config\systemprofile\Pictures]
09/16/2008 06:11 AM My Videos [C:\Windows\system32\config\systemprofile\Videos]
0 File(s) 0 bytes
Directory of C:\Program Files\Windows Defender
11/02/2006 08:42 AM en-US [c:\windows\system32\config]
11/02/2006 08:34 AM MpAsDesc.dll [c:\windows\system32\config]
01/20/2008 10:23 PM MpClient.dll [c:\windows\system32\config]
01/20/2008 10:23 PM MpCmdRun.exe [c:\windows\system32\config]
11/02/2006 08:34 AM MpEvMsg.dll [c:\windows\system32\config]
01/20/2008 10:23 PM MpOAV.dll [c:\windows\system32\config]
01/20/2008 10:23 PM MpRtMon.dll [c:\windows\system32\config]
01/20/2008 10:23 PM MpRtPlug.dll [c:\windows\system32\config]
01/20/2008 10:23 PM MpSigDwn.dll [c:\windows\system32\config]
04/11/2009 02:27 AM MpSoftEx.dll [c:\windows\system32\config]
01/20/2008 10:23 PM MpSvc.dll [c:\windows\system32\config]
01/20/2008 10:23 PM MSASCui.exe [c:\windows\system32\config]
01/20/2008 10:23 PM MsMpCom.dll [c:\windows\system32\config]
11/02/2006 08:34 AM MsMpLics.dll [c:\windows\system32\config]
11/02/2006 08:34 AM MsMpRes.dll [c:\windows\system32\config]
14 File(s) 4,344,192 bytes
Directory of C:\Program Files\Windows Defender\en-US\systemprofile
09/16/2008 06:11 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
09/16/2008 06:11 AM Cookies [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies]
09/16/2008 06:11 AM Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
09/16/2008 06:11 AM My Documents [C:\Windows\system32\config\systemprofile\Documents]
09/16/2008 06:11 AM NetHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
09/16/2008 06:11 AM PrintHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
09/16/2008 06:11 AM Recent [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent]
09/16/2008 06:11 AM SendTo [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo]
09/16/2008 06:11 AM Start Menu [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu]
09/16/2008 06:11 AM Templates [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Program Files\Windows Defender\en-US\systemprofile\AppData\Local
09/16/2008 06:11 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
09/16/2008 06:11 AM History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
09/16/2008 06:11 AM Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Program Files\Windows Defender\en-US\systemprofile\Documents
09/16/2008 06:11 AM My Music [C:\Windows\system32\config\systemprofile\Music]
09/16/2008 06:11 AM My Pictures [C:\Windows\system32\config\systemprofile\Pictures]
09/16/2008 06:11 AM My Videos [C:\Windows\system32\config\systemprofile\Videos]
0 File(s) 0 bytes
Directory of C:\ProgramData
11/02/2006 09:02 AM Application Data [C:\ProgramData]
11/02/2006 09:02 AM Desktop [C:\Users\Public\Desktop]
11/02/2006 09:02 AM Documents [C:\Users\Public\Documents]
11/02/2006 09:02 AM Favorites [C:\Users\Public\Favorites]
11/02/2006 09:02 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 09:02 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
11/02/2006 09:02 AM All Users [C:\ProgramData]
11/02/2006 09:02 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
11/02/2006 09:02 AM Application Data [C:\ProgramData]
11/02/2006 09:02 AM Desktop [C:\Users\Public\Desktop]
11/02/2006 09:02 AM Documents [C:\Users\Public\Documents]
11/02/2006 09:02 AM Favorites [C:\Users\Public\Favorites]
11/02/2006 09:02 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 09:02 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
11/02/2006 09:02 AM Application Data [C:\Users\Default\AppData\Roaming]
11/02/2006 09:02 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
11/02/2006 09:02 AM Local Settings [C:\Users\Default\AppData\Local]
11/02/2006 06:23 AM Music [C:\Users\Default\Music]
11/02/2006 09:02 AM My Documents [C:\Users\Default\Documents]
11/02/2006 09:02 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
11/02/2006 06:23 AM Pictures [C:\Users\Default\Pictures]
11/02/2006 09:02 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
11/02/2006 09:02 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
11/02/2006 09:02 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
11/02/2006 09:02 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
11/02/2006 09:02 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
11/02/2006 06:23 AM Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
11/02/2006 09:02 AM Application Data [C:\Users\Default\AppData\Local]
11/02/2006 09:02 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
11/02/2006 09:02 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local\Microsoft\Windows
11/02/2006 09:02 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
11/02/2006 09:02 AM My Music [C:\Users\Default\Music]
11/02/2006 09:02 AM My Pictures [C:\Users\Default\Pictures]
11/02/2006 09:02 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public
11/02/2006 09:02 AM Favorites [C:\Users\Public\Favorites]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
11/02/2006 09:02 AM My Music [C:\Users\Public\Music]
11/02/2006 09:02 AM My Pictures [C:\Users\Public\Pictures]
11/02/2006 09:02 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Valued Customer
08/31/2008 02:39 AM Application Data [C:\Users\Valued Customer\AppData\Roaming]
08/31/2008 02:39 AM Cookies [C:\Users\Valued Customer\AppData\Roaming\Microsoft\Windows\Cookies]
08/31/2008 02:39 AM Local Settings [C:\Users\Valued Customer\AppData\Local]
08/31/2008 02:39 AM My Documents [C:\Users\Valued Customer\Documents]
08/31/2008 02:39 AM NetHood [C:\Users\Valued Customer\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
08/31/2008 02:39 AM PrintHood [C:\Users\Valued Customer\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
08/31/2008 02:39 AM Recent [C:\Users\Valued Customer\AppData\Roaming\Microsoft\Windows\Recent]
08/31/2008 02:39 AM SendTo [C:\Users\Valued Customer\AppData\Roaming\Microsoft\Windows\SendTo]
08/31/2008 02:39 AM Start Menu [C:\Users\Valued Customer\AppData\Roaming\Microsoft\Windows\Start Menu]
08/31/2008 02:39 AM Templates [C:\Users\Valued Customer\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Valued Customer\AppData\Local
08/31/2008 02:39 AM Application Data [C:\Users\Valued Customer\AppData\Local]
08/31/2008 02:39 AM History [C:\Users\Valued Customer\AppData\Local\Microsoft\Windows\History]
08/31/2008 02:39 AM Temporary Internet Files [C:\Users\Valued Customer\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile
09/16/2008 06:11 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
09/16/2008 06:11 AM Cookies [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies]
09/16/2008 06:11 AM Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
09/16/2008 06:11 AM My Documents [C:\Windows\system32\config\systemprofile\Documents]
09/16/2008 06:11 AM NetHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
09/16/2008 06:11 AM PrintHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
09/16/2008 06:11 AM Recent [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent]
09/16/2008 06:11 AM SendTo [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo]
09/16/2008 06:11 AM Start Menu [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu]
09/16/2008 06:11 AM Templates [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile\AppData\Local
09/16/2008 06:11 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
09/16/2008 06:11 AM History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
09/16/2008 06:11 AM Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile\Documents
09/16/2008 06:11 AM My Music [C:\Windows\system32\config\systemprofile\Music]
09/16/2008 06:11 AM My Pictures [C:\Windows\system32\config\systemprofile\Pictures]
09/16/2008 06:11 AM My Videos [C:\Windows\system32\config\systemprofile\Videos]
0 File(s) 0 bytes
Total Files Listed:
40 File(s) 12,287,977 bytes
136 Dir(s) 28,944,326,656 bytes free

< %systemroot%\System32\config\*.sav >
[2008/01/20 23:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 23:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 23:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/18 17:16:54 | 000,000,422 | -HS- | M] () – C:\Users\Valued Customer\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/07/30 17:15:08 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Valued Customer\Desktop\HiJackThis.exe
[2013/07/26 19:55:39 | 011,088,872 | —- | M] (Microsoft Corporation) – C:\Users\Valued Customer\Desktop\mseinstall.exe
[2013/07/30 17:14:36 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Valued Customer\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-07-25 01:06:14

========== Alternate Data Streams ==========

@Alternate Data Stream - 3553 bytes -> C:\Users\Valued Customer\Documents\important information.eml:OECustomProperty
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:C46995DA

< End of report >


OTL - Extras

OTL Extras logfile created on: 7/30/2013 5:18:35 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Valued Customer\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.93 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.91% Memory free
4.10 Gb Paging File | 3.04 Gb Available in Paging File | 73.99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69.65 Gb Total Space | 27.36 Gb Free Space | 39.28% Space Free | Partition Type: NTFS
Drive D: | 69.64 Gb Total Space | 69.54 Gb Free Space | 99.87% Space Free | Partition Type: NTFS
Drive F: | 14.90 Gb Total Space | 7.00 Gb Free Space | 47.00% Space Free | Partition Type: FAT32

Computer Name: VALUEDCUSTOM-PC | User Name: Valued Customer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"AutoUpdateDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

========== Firewall Settings ==========

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0BE495BB-D6AB-4436-BBFB-67BFBB10909A}" = Getting Started with Windows Vista™ and 2007 Microsoft® Office System
"{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{13D85C14-2B85-419F-AC41-C7F21E68B25D}" = Acer eSettings Management
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"{26A24AE4-039D-4CA4-87B4-2F83216027FF}" = Java™ 6 Update 29
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{31B2D73B-4311-4D95-A131-32FB2194D1CB}" = Microsoft UI Engine
"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{390DD8BB-BB57-4942-A029-2D913E4E9D74}" = Microsoft Security Client
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
"{5B63A470-9334-44D1-AF61-6CE2DB565AE9}" = Orion
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 2.051
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F1B6239-FEA0-450A-A950-B05276CE177C}" = Acer Empowering Technology
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Acer GameZone Console_is1" = Acer GameZone Console 2.0.1.1
"Acer Registration" = Acer Registration
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"bSaving" = bSaving
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"CouponAlert_2pbar Uninstall" = Coupon Alert
"CouponBar5.0.0.5" = CouponBar
"GridVista" = Acer GridVista
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"LManager" = Launch Manager
"Marvell Miniport Driver" = Marvell Miniport Driver
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"PokerStars.net" = PokerStars.net
"Registry Repair" = Registry Repair 4.1.0.388
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinLiveSuite" = Windows Live Essentials
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater
"CarbonPoker" = CarbonPoker
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/5/2011 1:35:37 PM | Computer Name = ValuedCustom-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/6/2011 3:09:14 PM | Computer Name = ValuedCustom-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/6/2011 3:39:37 PM | Computer Name = ValuedCustom-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/7/2011 9:33:03 AM | Computer Name = ValuedCustom-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/8/2011 10:30:21 AM | Computer Name = ValuedCustom-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/9/2011 4:19:56 PM | Computer Name = ValuedCustom-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/11/2011 10:18:40 AM | Computer Name = ValuedCustom-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/12/2011 5:11:59 PM | Computer Name = ValuedCustom-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/13/2011 5:08:08 PM | Computer Name = ValuedCustom-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/15/2011 5:45:05 PM | Computer Name = ValuedCustom-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 7/26/2013 5:49:41 PM | Computer Name = ValuedCustom-PC | Source = Service Control Manager | ID = 7003
Description =

Error - 7/26/2013 7:34:25 PM | Computer Name = ValuedCustom-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 7/30/2013 4:49:47 PM | Computer Name = ValuedCustom-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/30/2013 4:49:47 PM | Computer Name = ValuedCustom-PC | Source = Service Control Manager | ID = 7023
Description =

Error - 7/30/2013 4:49:47 PM | Computer Name = ValuedCustom-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/30/2013 4:49:47 PM | Computer Name = ValuedCustom-PC | Source = Service Control Manager | ID = 7023
Description =

Error - 7/30/2013 4:49:47 PM | Computer Name = ValuedCustom-PC | Source = Service Control Manager | ID = 7003
Description =

Error - 7/30/2013 4:49:47 PM | Computer Name = ValuedCustom-PC | Source = Service Control Manager | ID = 7003
Description =

Error - 7/30/2013 4:49:47 PM | Computer Name = ValuedCustom-PC | Source = Service Control Manager | ID = 7003
Description =

Error - 7/30/2013 4:58:28 PM | Computer Name = ValuedCustom-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description =


< End of report >
Hi Shawbuck, I must warn you that you have been infected with a variant of ZA that you might not be able to install or use MSE back again even if we can remove the bad files. As much as I hate to say this, my best advice to you is to reformat and reinstall your computer because I cannot guarantee that you would be able to regain your admin permission after going through cleaning process. Do you still want me to try clean up for you? The choice is yours.
Thanks for responding, Conspire….although that was not the news I wanted to hear. Anyway, this is my brother-in-laws laptop. I was the one who recommended him to use MSE a few months ago, and then they called saying they are having computer problems last week….so I feel pretty bad right now. He left on vacation for the week and I told them I would see what I could do…he is not very computer literate, so I'm not sure if they even have the original disks. So if it's not too much trouble, I would like to see if we can get it cleaned up…and if it doesn't work, then I'll reformat if it doesn't work. But could it make things worse if we try?? Also, what exactly is the ZA virus? Thanks again for your help…let me know what you think…
It's not your fault for recommending him to use MSE, which is a great AV to use for its user friendliness and effectiveness. I believe a person get infected is due to their surfing habits and the lack of know-how on practicing safe surfing. Usually a laptop comes with a recovery partition which you could use it to restore to original factory condition with ease. However, this process is different from manufacturers so a bit more on that later if we were to go this path.

ZA virus is short for Zero Access. It comes in the form of rootkit that injects malicious file into your legit system file that controls browser redirects to generate revenues in advertising. It's quite complicated to explain this because this guy is quite sophisticated on its own merits and I have dealt several cases like this and none of them are successful. Some of them reformat it and some of them went for alternative anti virus program.

I'm sorry that this isn't the news you wanted to hear.. but this is just how bad the malware is. It's a nightmare for victims.

Let's get things started.

Please download Farbar Recovery Scan Tool and save it to your desktop. Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
Thanks again, Conspire…I really appreciate your help! Here are the two logs you requested:

FRST.txt

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-07-2013 04
Ran by [removed] (administrator) on 01-08-2013 00:27:06
Running from C:\Users\[removed]\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Agere Systems) C:\Windows\system32\agrsmsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
() C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
(COMPANYVERS_NAME) C:\PROGRA~1\COUPON~2\bar\1.bin\2pbarsvc.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Realtek Semiconductor Corp.) C:\Users\VALUED~1\AppData\Local\Temp\RtkBtMnt.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(VER_COMPANY_NAME) C:\Program Files\CouponAlert_2p\bar\1.bin\2pbrmon.exe
(Ask) C:\Program Files\Ask.com\Updater\Updater.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Yontoo LLC) C:\Users\Valued Customer\AppData\Roaming\Yontoo\YontooDesktop.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Egis Incorporated) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
() C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Acer\Mobility Center\MobilityService.exe
(NewTech InfoSystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
() C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
() C:\Program Files\Cyberlink\Shared files\RichVideo.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft) C:\Program Files\Yontoo\Y2Desktop.Updater.exe
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1049896 2008-04-25] (Synaptics, Inc.)
HKLM\…\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6183456 2008-06-13] (Realtek Semiconductor)
HKLM\…\Run: [Skytel] - C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.)
HKLM\…\Run: [Microsoft Default Manager] - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation)
HKLM\…\Run: [CouponAlert_2p Browser Plugin Loader] - C:\PROGRA~1\COUPON~2\bar\1.bin\2pbrmon.exe [30096 2011-09-14] (VER_COMPANY_NAME)
HKLM\…\Run: [ApnUpdater] - C:\Program Files\Ask.com\Updater\Updater.exe [1391272 2012-01-03] (Ask)
HKLM\…\Run: [] - [x]
HKLM\…\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [947152 2013-01-27] ()
HKLM\…D6A79037F57F\InprocServer32: [Default-fastprox] ATTENTION! ====> ZeroAccess?
HKLM\…\InprocServer32: [Default-cscui] <==== ATTENTION!
HKCU\…\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
HKCU\…\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKCU\…\Run: [Google Update] - C:\Users\Valued Customer\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2010-12-03] (Google Inc.)
HKCU\…\Run: [Yontoo Desktop] - C:\Users\Valued Customer\AppData\Roaming\Yontoo\YontooDesktop.exe [42784 2013-03-22] (Yontoo LLC)
HKU\Default\…\RunOnce: [AcerScrSav] - [x]
HKU\Default User\…\RunOnce: [AcerScrSav] - [x]

==================== Internet (Whitelisted) ====================

ProxyEnable: Internet Explorer proxy is enabled.
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.glarysoft.com/?src=iehome
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.glarysoft.com/?src=iehome
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.coupons.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.glarysoft.com/?src=iehome
URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
URLSearchHook: (No Name) - {7b9f8c21-46ec-4c0b-8683-e755ef84577a} - C:\Program Files\CouponAlert_2p\bar\1.bin\2pSrcAs.dll (COMPANYVERS_NAME)
SearchScopes: HKLM - DefaultScope {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = http://isearch.glarysoft.com/?q={searchTer…mp;src=iesearch
SearchScopes: HKLM - {5a1d0d31-749c-4186-a295-4106e6e7b26a} URL = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
SearchScopes: HKLM - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = http://isearch.glarysoft.com/?q={searchTer…mp;src=iesearch
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchTerm…40E001D72CEDA2D
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchTerm…40E001D72CEDA2D
SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=i…38-1560FFAC2ADB
SearchScopes: HKCU - {5a1d0d31-749c-4186-a295-4106e6e7b26a} URL = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
SearchScopes: HKCU - {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = http://search.coupons.com/search.asp?p=df&…q={searchTerms}
SearchScopes: HKCU - {9E4F7F41-EDE2-4E4F-93EB-18CF2FE9C8DE} URL = http://delicious.com/search?p={searchTerms}
SearchScopes: HKCU - {B7EE063B-EFD9-4263-8DAD-0E51D357732A} URL = http://addons.alltheinternet.com/texis/ope…q={searchTerms}
SearchScopes: HKCU - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = http://isearch.glarysoft.com/?q={searchTer…mp;src=iesearch
SearchScopes: HKCU - {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = http://search.yahoo.com/search?p={searchTerms}
SearchScopes: HKCU - {F6B6724D-4318-44BC-BC2D-C1672ADCFDD1} URL = http://websearch.shopathome.com?user_id=%g…q={searchTerms}
SearchScopes: HKCU - {F7EFB045-B4C2-4B79-AD41-0F248DDD90B2} URL = http://www.flickr.com/search/?q={searchTerms}
BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Toolbar BHO - {3a421c8f-e238-4aeb-8874-b8b5f2cc4772} - C:\PROGRA~1\COUPON~2\bar\1.bin\2pbar.dll (MindSpark)
BHO: Search Assistant BHO - {60e91567-ef8a-4520-bce2-83aba5256799} - C:\Program Files\CouponAlert_2p\bar\1.bin\2pSrcAs.dll (COMPANYVERS_NAME)
BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (Egis)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: TBSB07898 Class - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll No File
BHO: Yontoo - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll (Yontoo LLC)
BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
Toolbar: HKLM - No Name - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
Toolbar: HKLM - Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
Toolbar: HKLM - Coupon Alert - {3462c343-be19-4143-af70-cefb56f46fc6} - C:\Program Files\CouponAlert_2p\bar\1.bin\2pbar.dll (MindSpark)
Toolbar: HKLM - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKLM - Coupons.com CouponBar - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKCU -Coupons.com CouponBar - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll No File
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Winsock: Catalog5 01 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Winsock: Catalog9 01 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 02 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 03 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 04 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 05 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 06 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 07 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 08 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 09 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 10 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 12 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 13 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 14 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 15 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 16 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 17 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 18 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 19 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 20 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 21 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 22 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 23 mswsock.dll File Not found (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]

Chrome:
=======
CHR HomePage: hxxp://www.delta-search.com/?affID=119842&babsrc;=HP_ss&mntrId;=240E001D72CEDA2D
CHR RestoreOnStartup: "hxxp://www.delta-search.com/?affID=119842&babsrc;=HP_ss&mntrId;=240E001D72CEDA2D"
CHR DefaultSearchURL: (Delta Search) - http://www.delta-search.com/?q={searchTerm…40E001D72CEDA2D
CHR DefaultSuggestURL: (Delta Search) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Valued Customer\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Valued Customer\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Valued Customer\AppData\Local\Google\Chrome\Application\28.0.1500.72\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.290.11) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java™ Platform SE 6 U29) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Coupons Inc., Coupon Printer Manager ) - C:\Users\Valued Customer\AppData\Local\Google\Chrome\Application\plugins\npMozCouponPrinter.dll No File
CHR Plugin: (MindSpark Toolbar Platform Plugin Stub) - C:\Program Files\CouponAlert_2p\bar\1.bin\NP2pStub.dll (MindSpark)
CHR Plugin: (Fun Web Products Plugin Stub) - C:\Program Files\FunWebProducts\Installr\1.bin\NPFunWeb.dll (Fun Web Products, Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (WeatherBlink Installer Plugin Stub) - C:\Program Files\WeatherBlinkEI\Installr\1.bin\NPgcEISB.dll (WeatherBlink)
CHR Plugin: (Windows Live0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\Valued Customer\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Entanglement) - C:\Users\VALUED~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0
CHR Extension: (Poppit) - C:\Users\VALUED~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0
CHR Extension: (Yontoo) - C:\Users\VALUED~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.3_1
CHR HKLM\…\Chrome\Extension: [cnpkmcjgpcihgfnkcjapiaabbbplkcmf] - C:\Program Files\Coupons.com CouponBar\chrome\Coupons.com.crx
CHR HKLM\…\Chrome\Extension: [niapdbllcanepiiimjjndipklodoedlc] - C:\Program Files\Yontoo\YontooLayers.crx

========================== Services (Whitelisted) =================

R2 BUNAgentSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [16384 2008-03-03] (NewTech Infosystems, Inc.)
R2 CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [81504 2008-01-16] ()
R2 CouponAlert_2pService; C:\PROGRA~1\COUPON~2\bar\1.bin\2pbarsvc.exe [42504 2011-09-14] (COMPANYVERS_NAME)
R2 ETService; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [24576 2008-03-21] ()
R2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-12-06] ()
S2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [20456 2013-01-27] ()
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [295232 2013-01-27] ()
R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [131072 2008-04-04] ()
R2 RichVideo; C:\Program Files\Cyberlink\Shared files\RichVideo.exe [272024 2007-01-09] ()
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] ()
R2 Yontoo Desktop Updater; C:\Users\Valued Customer\AppData\Roaming\Yontoo\YontooDesktop.exe [42784 2013-03-22] (Yontoo LLC)

==================== Drivers (Whitelisted) ====================

R2 int15; C:\Windows\system32\drivers\int15.sys [15392 2008-03-21] (Acer, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [195296 2013-01-20] (Microsoft Corporation)
R2 NTIPPKernel; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [122368 2008-01-16] (Cyberlink Corp.)
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl [61424 2008-04-18] (Cyberlink Corp.)
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
U2 TMAgent;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-01 00:26 - 2013-08-01 00:26 - 00000000 ____D C:\FRST
2013-08-01 00:25 - 2013-08-01 00:24 - 01781589 _____ (Farbar) C:\Users\Valued Customer\Desktop\FRST64.exe
2013-08-01 00:25 - 2013-08-01 00:23 - 01222064 _____ (Farbar) C:\Users\Valued Customer\Desktop\FRST.exe
2013-07-30 17:47 - 2013-07-30 17:47 - 00011257 _____ C:\Users\Valued Customer\Desktop\hijackthis.log
2013-07-30 17:31 - 2013-07-30 17:31 - 00034306 _____ C:\Users\Valued Customer\Desktop\Extras.Txt
2013-07-30 17:30 - 2013-07-30 17:30 - 00180370 _____ C:\Users\Valued Customer\Desktop\OTL.Txt
2013-07-30 17:16 - 2013-07-30 17:16 - 00000795 _____ C:\Windows\setupact.log
2013-07-30 17:16 - 2013-07-30 17:16 - 00000000 _____ C:\Windows\setuperr.log
2013-07-30 17:16 - 2013-07-30 17:15 - 00388608 _____ (Trend Micro Inc.) C:\Users\Valued Customer\Desktop\HiJackThis.exe
2013-07-30 17:16 - 2013-07-30 17:14 - 00602112 _____ (OldTimer Tools) C:\Users\Valued Customer\Desktop\OTL.exe
2013-07-25 19:54 - 2013-07-26 17:49 - 00000000 ____D C:\Users\VALUED~1\AppData\Local\LogMeIn Rescue Applet
2013-07-24 21:15 - 2013-07-24 21:15 - 00001786 _____ C:\Users\Valued Customer\Desktop\Microsoft Security Essentials.lnk
2013-07-24 21:14 - 2013-07-24 21:14 - 00000000 __SHD C:\Windows\system32\%APPDATA%
2013-07-24 03:00 - 2013-07-24 03:02 - 00000000 ____D C:\Windows\system32\MRT
2013-07-11 21:16 - 2013-05-28 21:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-11 21:16 - 2013-05-28 21:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-11 21:16 - 2013-05-28 21:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-11 21:16 - 2013-05-28 21:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-07-11 21:16 - 2013-05-28 21:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-11 21:16 - 2013-05-28 21:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-11 21:16 - 2013-05-28 21:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-07-11 21:16 - 2013-05-28 21:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-11 21:16 - 2013-05-28 21:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-07-11 21:16 - 2013-05-28 21:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-07-11 21:16 - 2013-05-28 21:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-11 21:16 - 2013-05-28 21:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-11 21:16 - 2013-05-28 21:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-11 21:16 - 2013-05-28 21:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-11 21:16 - 2013-05-28 21:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-07-11 21:16 - 2013-05-28 21:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-11 03:05 - 2013-06-01 00:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 03:05 - 2013-05-08 00:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 03:04 - 2013-06-03 21:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-11 03:04 - 2013-04-17 07:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-07-11 03:04 - 2013-04-17 07:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-07-11 03:04 - 2013-04-17 07:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-07-11 03:04 - 2013-04-17 07:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-07-11 03:04 - 2013-04-17 06:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-07-11 03:04 - 2013-04-17 06:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-07-11 03:04 - 2013-04-17 06:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-07-11 03:04 - 2013-04-17 06:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-11 03:04 - 2013-04-17 06:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll

==================== One Month Modified Files and Folders =======

2013-08-01 00:26 - 2013-08-01 00:26 - 00000000 ____D C:\FRST
2013-08-01 00:26 - 2006-11-02 08:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-01 00:26 - 2006-11-02 08:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-01 00:25 - 2010-12-03 13:25 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-419784182-1888270494-198414776-1000UA.job
2013-08-01 00:24 - 2013-08-01 00:25 - 01781589 _____ (Farbar) C:\Users\Valued Customer\Desktop\FRST64.exe
2013-08-01 00:23 - 2013-08-01 00:25 - 01222064 _____ (Farbar) C:\Users\Valued Customer\Desktop\FRST.exe
2013-08-01 00:22 - 2012-08-26 19:06 - 00000904 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-01 00:22 - 2012-03-30 11:29 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-31 23:00 - 2010-12-03 13:32 - 00002096 _____ C:\Users\Valued Customer\Desktop\Google Chrome.lnk
2013-07-31 22:56 - 2012-08-26 19:06 - 00000900 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-31 22:40 - 2013-04-06 19:03 - 00000000 ____D C:\Users\Valued Customer\AppData\Roaming\Yontoo
2013-07-31 18:21 - 2010-11-23 11:52 - 00000464 _____ C:\Windows\Tasks\ParetoLogic Registration3.job
2013-07-31 12:46 - 2010-12-03 13:25 - 00000896 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-419784182-1888270494-198414776-1000Core.job
2013-07-30 17:47 - 2013-07-30 17:47 - 00011257 _____ C:\Users\Valued Customer\Desktop\hijackthis.log
2013-07-30 17:31 - 2013-07-30 17:31 - 00034306 _____ C:\Users\Valued Customer\Desktop\Extras.Txt
2013-07-30 17:30 - 2013-07-30 17:30 - 00180370 _____ C:\Users\Valued Customer\Desktop\OTL.Txt
2013-07-30 17:17 - 2006-11-02 06:33 - 00718722 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-30 17:16 - 2013-07-30 17:16 - 00000795 _____ C:\Windows\setupact.log
2013-07-30 17:16 - 2013-07-30 17:16 - 00000000 _____ C:\Windows\setuperr.log
2013-07-30 17:15 - 2013-07-30 17:16 - 00388608 _____ (Trend Micro Inc.) C:\Users\Valued Customer\Desktop\HiJackThis.exe
2013-07-30 17:14 - 2013-07-30 17:16 - 00602112 _____ (OldTimer Tools) C:\Users\Valued Customer\Desktop\OTL.exe
2013-07-30 16:49 - 2008-09-16 06:23 - 00000000 _____ C:\Windows\system32\LogConfigTemp.xml
2013-07-30 16:49 - 2008-04-30 05:54 - 00000147 _____ C:\Windows\system32\agent.log
2013-07-30 16:49 - 2008-01-20 22:47 - 05126466 _____ C:\Windows\PFRO.log
2013-07-30 16:49 - 2006-11-02 09:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-26 20:38 - 2006-11-02 09:01 - 00032580 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-26 19:55 - 2012-11-03 19:36 - 00002057 _____ C:\Windows\epplauncher.mif
2013-07-26 19:55 - 2012-11-03 19:31 - 11088872 _____ (Microsoft Corporation) C:\Users\Valued Customer\Desktop\mseinstall.exe
2013-07-26 17:49 - 2013-07-25 19:54 - 00000000 ____D C:\Users\VALUED~1\AppData\Local\LogMeIn Rescue Applet
2013-07-25 19:53 - 2010-12-03 13:21 - 00000000 ____D C:\Users\VALUED~1\AppData\Local\Deployment
2013-07-24 21:32 - 2012-03-30 11:29 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-07-24 21:32 - 2011-06-08 18:31 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-07-24 21:15 - 2013-07-24 21:15 - 00001786 _____ C:\Users\Valued Customer\Desktop\Microsoft Security Essentials.lnk
2013-07-24 21:14 - 2013-07-24 21:14 - 00000000 __SHD C:\Windows\system32\%APPDATA%
2013-07-24 21:07 - 2008-09-16 06:09 - 01466529 _____ C:\Windows\WindowsUpdate.log
2013-07-24 03:02 - 2013-07-24 03:00 - 00000000 ____D C:\Windows\system32\MRT
2013-07-16 10:59 - 2006-11-02 07:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-07-11 21:59 - 2008-10-13 22:39 - 00000000 ____D C:\Users\VALUED~1\AppData\Local\Adobe
2013-07-11 21:35 - 2006-11-02 08:47 - 00299568 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-11 21:32 - 2006-11-02 08:37 - 00000000 ____D C:\Windows\system32\XPSViewer
2013-07-11 21:18 - 2008-04-30 05:38 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-07-11 03:18 - 2010-08-13 16:54 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-10 09:02 - 2006-11-02 08:37 - 00000000 ____D C:\Program Files\Windows Journal

ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\n
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\00000004.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\00000008.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\000000cb.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\80000000.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\80000032.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\L\00000004.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\L\6715e287
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\L\76603ac3

ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\n
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\00000004.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\00000008.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\000000cb.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\80000000.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\80000032.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\L\00000004.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\L\6715e287
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\L\76603ac3

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-419784182-1888270494-198414776-1000\$cced714b348e29baf6a11cacf2a4ea0f

ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\n
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\00000004.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\00000008.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\000000cb.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\80000000.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\80000032.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\L\00000004.@
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\L\6715e287
C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\L\76603ac3

ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
C:\Program Files\Windows Defender\mpsvc.dll => ATTENTION: ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
C:\Program Files\Microsoft Security Client\MsMpEng.exe => ATTENTION: ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Microsoft Security Client


LastRegBack: 2013-07-30 16:55

==================== End Of Log ============================


Addition.txt

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 30-07-2013 04
Ran by [removed] at 2013-08-01 00:27:36
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

Update for Microsoft Office 2007 (KB2508958)
Acer Arcade Deluxe (Version: 2.0.5225)
Acer eDataSecurity Management (Version: 3.0.3062)
Acer Empowering Technology (Version: 3.0.3006)
Acer ePower Management (Version: 3.0.3012)
Acer eRecovery Management (Version: 3.0.3013)
Acer eSettings Management (Version: 3.0.3007)
Acer GameZone Console 2.0.1.1
Acer GridVista (Version: 2.72.317)
Acer Mobility Center Plug-In (Version: 3.0.3000)
Acer Registration
Activation Assistant for the 2007 Microsoft Office suites
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0)
Adobe Flash Player 11 ActiveX (Version: 11.8.800.94)
Adobe Flash Player 11 Plugin (Version: 11.8.800.94)
Adobe Reader 8.1.3 (Version: 8.1.3)
Apple Application Support (Version: 2.0.1)
Apple Mobile Device Support (Version: 3.4.1.2)
Apple Software Update (Version: 2.1.3.127)
Ask Toolbar (Version: 1.14.1.0)
Ask Toolbar Updater (HKCU Version: 1.2.1.22229)
Bing Bar (Version: 7.0.609.0)
Bing Rewards Client Installer (Version: 16.0.345.0)
Bonjour (Version: 3.0.0.2)
bSaving (Version: 1)
CarbonPoker (HKCU Version: 6.0)
Coupon Alert
Coupon Printer for Windows (Version: 4.0)
CouponBar (Version: 5.0.0.5)
D3DX10 (Version: 15.4.2368.0902)
eSobi v2 (Version: 2.0.3.000189)
Getting Started with Windows Vista™ and 2007 Microsoft® Office System (Version: 1.0.0)
Google Chrome (HKCU Version: 28.0.1500.95)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.5.4209.2358)
Google Update Helper (Version: 1.3.21.153)
Intel® Graphics Media Accelerator Driver
iTunes (Version: 10.4.1.10)
Java Auto Updater (Version: 2.0.6.1)
Java™ 6 Update 29 (Version: 6.0.290)
Junk Mail filter update (Version: 15.4.3502.0922)
Launch Manager
LightScribe 1.4.142.1 (Version: 1.4.142.1)
Marvell Miniport Driver (Version: 10.55.3.3)
Mesh Runtime (Version: 15.4.5722.2)
Messenger Companion (Version: 15.4.3502.0922)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Default Manager (Version: 2.2.114.0)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Security Client (Version: 4.2.0223.1)
Microsoft Security Essentials (Version: 4.2.223.1)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft UI Engine (Version: 6.3.2348.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Works (Version: 08.05.0818)
MSVCRT (Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0)
MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 4.0 SP2 and SOAP Toolkit 3.0 (Version: 1.0.0.0)
NTI Backup Now 5 (Version: 5.1.2.503)
NTI Backup Now Standard (Version: 5.1.2.503)
NTI Media Maker 8 (Version: 8.0.2.6322)
OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0)
Orion (Version: 2.0.1)
PhotoNow! (Version: 1.1.4619)
PokerStars.net
PowerDirector (Version: 6.5.2713)
QuickTime (Version: 7.70.80.34)
Realtek High Definition Audio Driver (Version: 6.0.1.5643)
Realtek USB 2.0 Card Reader (Version: )
Registry Repair 4.1.0.388 (Version: 4.1.0.388)
Segoe UI (Version: 15.4.2271.0615)
Spelling Dictionaries Support For Adobe Reader 8 (Version: 8.0.0)
Synaptics Pointing Device Driver (Version: 11.1.4.0)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB2836940) (Version: 1)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3508.1109)
Windows Live Family Safety (Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Mesh (Version: 15.4.3502.0922)
Windows Live Mesh ActiveX Control for Remote Connections (Version: 15.4.5722.2)
Windows Live Messenger (Version: 15.4.3502.0922)
Windows Live Messenger Companion Core (Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
Yahoo! Software Update
Yahoo! Toolbar
Yontoo 2.051 (Version: 2.051)


==================== Restore Points =========================

19-07-2013 14:51:34 Windows Update
22-07-2013 17:26:35 Windows Update
24-07-2013 07:00:17 Windows Update
24-07-2013 23:00:47 Scheduled Checkpoint
25-07-2013 01:02:23 Windows Update
25-07-2013 01:05:25 Windows Update
26-07-2013 23:34:54 Scheduled Checkpoint
30-07-2013 21:20:28 OTL Restore Point - 7/30/2013 5:20:28 PM
31-07-2013 20:56:18 Scheduled Checkpoint

==================== Hosts content: ==========================

2006-11-02 06:23 - 2010-10-25 12:02 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {3D834B4D-4F12-4F21-96B3-4D4146621AE0} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-20] (Microsoft Corporation)
Task: {4AABAE7C-DC54-45C0-8869-60A215566747} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-419784182-1888270494-198414776-1000Core => C:\Users\Valued Customer\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-03] (Google Inc.)
Task: {5DF30A2C-67A8-4E01-BF70-22245F4CCFC9} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-20] (Microsoft Corporation)
Task: {6A458E25-1C31-45BD-BC77-1BCE5EC21106} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {6DDA6D2B-E291-4FC1-B019-012BF82BAC6C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-08-26] (Google Inc.)
Task: {74930147-4BEF-4A0B-B09C-80F10EF3D7F2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-08-26] (Google Inc.)
Task: {74DA1967-316B-45AA-BCD2-E937420CAD66} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-24] (Adobe Systems Incorporated)
Task: {7AC79D04-5E48-4120-B786-FF07357B80F2} - System32\Tasks\User_Feed_Synchronization-{93396239-093E-4D25-ADE3-36F335D40009} => C:\Windows\system32\msfeedssync.exe [2011-04-18] (Microsoft Corporation)
Task: {7B654223-73ED-4441-BFF2-FE2BEAF390B7} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-419784182-1888270494-198414776-1000UA => C:\Users\Valued Customer\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-03] (Google Inc.)
Task: {90D05C5C-C83A-4578-9224-DFB632A0E5CA} - System32\Tasks\ParetoLogic Registration3 => C:\Windows\system32\rundll32.exe [2006-11-02] (Microsoft Corporation)
Task: {A5B89072-36EF-4F76-AFFB-579B53115953} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Valued Customer => C:\Program Files\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation)
Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-20] (Microsoft Corporation)
Task: {B08D143E-5CFC-4D5B-B272-4EE6C35730FE} - System32\Tasks\GorillaPrice => C:\Program No File
Task: {B0E2A4DA-B37A-4F97-B7E4-30EFC755E50E} - System32\Tasks\Microsoft\Windows\Defrag\ManualDefrag => C:\Windows\system32\defrag.exe [2008-01-20] (Microsoft Corp.)
Task: {B40450F3-233E-4776-A7A5-A1EF8A0AEC8D} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files\Ask.com\UpdateTask.exe [2012-01-03] ()
Task: {B6FCDE8B-1AC8-4E3A-A020-D8D2C4523CAD} - System32\Tasks\ParetoLogic Update Version3 => C:\Program Files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2009-10-12] (ParetoLogic Inc.)
Task: {DCD1C267-6E47-4855-A782-17A7D2314BF8} - System32\Tasks\Poppet => C:\Users\Valued No File
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-20] ()
Task: {ED9D6E96-9966-4D61-B257-97697E25EBA3} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\MpCmdRun.exe [2013-01-27] ()
Task: {FD158C2D-AE29-4023-A135-90696945AFBA} - System32\Tasks\Acer\Acer Assist\New Message Check - Valued Customer => C:\Program Files\Acer\Acer Assist\AcerAssist.exe No File
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-419784182-1888270494-198414776-1000Core.job => C:\Users\Valued Customer\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-419784182-1888270494-198414776-1000UA.job => C:\Users\Valued Customer\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ParetoLogic Registration3.job => C:\Windows\system32\rundll32.exe
Task: C:\Windows\Tasks\ParetoLogic Update Version3.job => C:\Program Files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe

==================== Faulty Device Manager Devices =============

Name: Microsoft ISATAP Adapter #90
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver


==================== Event log errors: =========================

Application errors:
==================
Error: (07/31/2013 04:56:19 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service WinDefend since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (07/31/2013 04:56:19 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service NisSrv since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (07/30/2013 05:20:35 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service WinDefend since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (07/30/2013 05:20:35 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service NisSrv since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (07/30/2013 04:49:47 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/26/2013 07:55:48 PM) (Source: Microsoft Security Client Setup) (User: ValuedCustom-PC)
Description: HRESULT:0x8004FF06
Description:Microsoft Security Essentials is already installed. A newer version of Security Essentials is already installed on your computer. Error code:0x8004FF06.

Error: (07/26/2013 07:34:55 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service WinDefend since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (07/26/2013 07:34:55 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service NisSrv since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (07/26/2013 05:49:41 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/25/2013 09:24:28 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (07/30/2013 04:58:28 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT AUTHORITY)
Description: C:\Windows\system32\athihvs.dll126

Error: (07/30/2013 04:49:47 PM) (Source: Service Control Manager) (User: )
Description: IPsec Policy AgentBFE

Error: (07/30/2013 04:49:47 PM) (Source: Service Control Manager) (User: )
Description: Microsoft Network Inspection SystemBFE

Error: (07/30/2013 04:49:47 PM) (Source: Service Control Manager) (User: )
Description: IKE and AuthIP IPsec Keying ModulesBFE

Error: (07/30/2013 04:49:47 PM) (Source: Service Control Manager) (User: )
Description: Computer Browser%%1060

Error: (07/30/2013 04:49:47 PM) (Source: Service Control Manager) (User: )
Description: Parallel port driver%%1058

Error: (07/30/2013 04:49:47 PM) (Source: Service Control Manager) (User: )
Description: WinDefend%%5

Error: (07/30/2013 04:49:47 PM) (Source: Service Control Manager) (User: )
Description: Microsoft Antimalware Service%%5

Error: (07/26/2013 07:34:25 PM) (Source: Service Control Manager) (User: )
Description: 30000Netman

Error: (07/26/2013 05:49:41 PM) (Source: Service Control Manager) (User: )
Description: IPsec Policy AgentBFE


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
Date: 2013-08-01 00:27:22.066
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-08-01 00:27:21.614
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-08-01 00:27:21.161
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-08-01 00:27:20.709
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-07-30 17:47:33.200
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-07-30 17:47:32.661
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-07-30 17:47:32.201
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-07-30 17:47:31.521
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-07-30 17:22:14.316
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-07-30 17:22:13.848
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 50%
Total physical RAM: 1976.12 MB
Available physical RAM: 972.97 MB
Total Pagefile: 4201.53 MB
Available Pagefile: 2994.07 MB
Total Virtual: 2047.88 MB
Available Virtual: 1908.7 MB

==================== Drives ================================

Drive c: (ACER) (Fixed) (Total:69.65 GB) (Free:26.18 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:69.64 GB) (Free:69.54 GB) NTFS
Drive f: () (Removable) (Total:14.9 GB) (Free:7 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 149 GB) (Disk ID: F2510514)
Partition 1: (Not Active) - (Size=10 GB) - (Type=27)
Partition 2: (Active) - (Size=70 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=70 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 15 GB) (Disk ID: 00000000)
Partition 1: (Not Active) - (Size=15 GB) - (Type=0C)

==================== End Of Log ============================
You're welcome. :)

The damage is quite extensive here.

Download attached fixlist.txt 📎fixlist.txt file and save it to the Desktop. NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart. The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

Note: If the tool warned you about the outdated version please download and run the updated version.
Okay…I think we are making some headway. I rebooted and can now see the green MSE icon on the lower right toolbar. I'm assuming that's a good sign. Here is the Fixlog.txt log you requested… Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 30-07-2013 04 Ran by [removed] at 2013-08-01 01:32:26 Run:1 Running from C:\Users\[removed]\Desktop Boot Mode: Normal ============================================== HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\CouponAlert_2p Browser Plugin Loader => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\Default => Value was restored successfully. HKLM\Software\Classes\CLSID\{750fdf10-2a26-11d1-a3ea-080036587f03}\InprocServer32\\Default => Value was restored successfully. Yontoo Desktop Updater => Service deleted successfully. CouponAlert_2pService => Service deleted successfully. C:\$Recycle.Bin\S-1-5-21-419784182-1888270494-198414776-1000\$cced714b348e29baf6a11cacf2a4ea0f => Directory moved successfully. C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f => Moved successfully. "C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\@" => File/Directory not found. "C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\n" => File/Directory not found. "C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\00000004.@" => File/Directory not found. "C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\00000008.@" => File/Directory not found. "C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\000000cb.@" => File/Directory not found. "C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\80000000.@" => File/Directory not found. "C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\U\80000032.@" => File/Directory not found. "C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\L\00000004.@" => File/Directory not found. "C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\L\6715e287" => File/Directory not found. "C:\$Recycle.Bin\S-1-5-18\$cced714b348e29baf6a11cacf2a4ea0f\L\76603ac3" => File/Directory not found. C:\Windows\assembly\GAC\Desktop.ini => Moved successfully. "C:\Program Files\Windows Defender" => Deleting reparse point and unlocking started. "C:\Program Files\Windows Defender\en-US" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpAsDesc.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpClient.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpCmdRun.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpEvMsg.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpOAV.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpRtMon.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpRtPlug.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpSigDwn.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpSoftEx.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpSvc.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MSASCui.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MsMpCom.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MsMpLics.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MsMpRes.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender" => Deleting reparse point and unlocking completed. "C:\Program Files\Microsoft Security Client" => Deleting reparse point and unlocking started. "C:\Program Files\Microsoft Security Client\Backup" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\DbgHelp.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\Drivers" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\en-us" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\EppManifest.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MpAsDesc.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MpClient.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MpCmdRun.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MpCommu.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\mpevmsg.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MpOAv.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MpRTP.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MpSvc.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MsMpCom.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MsMpEng.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MsMpLics.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MsMpRes.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\msseces.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MsseWat.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\NisIpsPlugin.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\NisLog.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\NisSrv.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\NisWFP.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\Setup.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\SetupRes.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\shellext.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\SqmApi.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\SymSrv.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\SymSrv.yes" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client" => Deleting reparse point and unlocking completed. The system needs a manual reboot. ==== End of Fixlog ====
Good to hear that. Moving on.

-AdwCleaner-

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
===================================================

Please download Junkware Removal Tool to your desktop.
  • Shutdown your antivirus to avoid any conflicts.
  • Right-mouse click JRT.exe and select Run as administrator
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message
===================================================
Please read through these instructions to familiarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
===================================================

On your next reply please post :
AdwCleaner log
JRT log
Combofix log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Things are appearing to be getting better, but some wierd things are happening. First, after running AdwCleaner, the MSE icon in the lower right toolbar and main icon on my screen disappeared. However, I was able to disable the program going through the menu button on the lower left toolbar. The icon seemed to have returned after running JRT…

Next, I ran AdwCleaner and JRT, but ran into problems with ComboFix. I disabled MSE, as instructed, but got a warning indicating that the MSE realtime scanners were still active…so I opened MSE and verified it was turned off…and also have the red MSE icon with an "x" on it in the lower right hand toolbar. I hit okay and got another warning message indicating that MSE was still active, but will continue to run, but at my own risk. So I stopped and did not continue to run it, per your instructions. This window is still open on the laptop…should I hit OK and run, or "X" to get out??


Below are 2 of the logfiles your requested:


AdwCleaner

# AdwCleaner v2.306 - Logfile created 08/01/2013 at 02:03:35
# Updated 19/07/2013 by Xplode
# Operating system : Windows Vista ™ Home Premium Service Pack 2 (32 bits)
# User : Valued Customer - VALUEDCUSTOM-PC
# Boot Mode : Normal
# Running from : C:\Users\Valued Customer\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Program Files\Ask.com
Folder Deleted : C:\Program Files\bSaving
Folder Deleted : C:\Program Files\Common Files\ParetoLogic
Folder Deleted : C:\Program Files\CouponAlert_2p
Folder Deleted : C:\Program Files\FunWebProducts
Folder Deleted : C:\Program Files\NetNucleous
Folder Deleted : C:\Program Files\Yontoo
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\ParetoLogic
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\Users\Valued Customer\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc
Folder Deleted : C:\Users\Valued Customer\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Valued Customer\AppData\LocalLow\delta
Folder Deleted : C:\Users\Valued Customer\AppData\LocalLow\Toolbar4
Folder Deleted : C:\Users\Valued Customer\AppData\Roaming\Babylon
Folder Deleted : C:\Users\Valued Customer\AppData\Roaming\DriverCure
Folder Deleted : C:\Users\Valued Customer\AppData\Roaming\ParetoLogic
Folder Deleted : C:\Users\Valued Customer\AppData\Roaming\Yontoo
Folder Deleted : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registry] *****

Key Deleted : HKCU\Software\592de8cbd35b840
Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\CouponAlert_2p
Key Deleted : HKCU\Software\AppDataLow\Software\NetNucleous
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\BabylonToolbar
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\CouponAlert_2pbar Uninstall
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3462C343-BE19-4143-AF70-CEFB56F46FC6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{60E91567-EF8A-4520-BCE2-83ABA5256799}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{23B38049-323F-443D-9732-F454E5B15B72}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3462C343-BE19-4143-AF70-CEFB56F46FC6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{60E91567-EF8A-4520-BCE2-83ABA5256799}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\NetNucleous
Key Deleted : HKCU\Software\TBSB07898
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\Software\APN
Key Deleted : HKLM\Software\AskToolbar
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0BDF6C42-132C-45F5-92DE-DC13F40C6DAB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{16FE2505-F2A0-4782-B035-AF0E5188C02C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1948934A-1C68-4B2B-9A1F-D12E2A062A1A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1F0A2185-DA7E-4614-91C0-DD5F4A76CB1B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{23B0AE65-17D2-4491-98E5-B1AA6228DDA2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{23B38049-323F-443D-9732-F454E5B15B72}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2D205ADF-C992-4EDA-99C3-096E13F38AB4}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3462C343-BE19-4143-AF70-CEFB56F46FC6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{411B1946-3277-4A7F-9F60-745266360613}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{457A4CB8-0391-409D-98B4-C4CCB2849670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4D8EACBC-E293-4462-B91E-42EA5B54B743}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{60E91567-EF8A-4520-BCE2-83ABA5256799}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7717F4B3-397F-4CE5-9192-6EFFDE3AC999}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{84576F6E-0660-4B4F-8918-BC6C975044D4}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{86D02BCF-0E0E-444F-8A8D-2D5C4A9E6578}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8867AC9B-4426-44A2-A693-C95850D3405C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B3F577-D54A-4831-B2B4-8AACEEDA85CF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C2DF3856-676C-41DC-A73B-FACBDF8E81E9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CF9D6D4E-5496-438E-BA24-5A580A59F5A3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D433A9D0-8267-40CB-8AD5-24F22FA5373F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DEF07ACD-BCEA-4269-933A-4087D20842BB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBBC4E43-292A-40DF-88E3-3262B7521460}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Deleted : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler
Key Deleted : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler.1
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.DynamicBarButton
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.DynamicBarButton.1
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.FeedManager
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.FeedManager.1
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.HTMLMenu
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.HTMLMenu.1
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.HTMLPanel
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.HTMLPanel.1
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.MultipleButton
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.MultipleButton.1
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.PseudoTransparentPlugin
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.PseudoTransparentPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.Radio
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.Radio.1
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.RadioSettings
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.RadioSettings.1
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.ScriptButton
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.ScriptButton.1
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.SettingsPlugin
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.SettingsPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.ThirdPartyInstaller
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.ThirdPartyInstaller.1
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.ToolbarPlugin
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.ToolbarPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.UrlAlertButton
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.UrlAlertButton.1
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.XMLSessionPlugin
Key Deleted : HKLM\SOFTWARE\Classes\CouponAlert_2p.XMLSessionPlugin.1
Key Deleted : HKLM\SOFTWARE\Classes\FunWebProductsInstaller.Start
Key Deleted : HKLM\SOFTWARE\Classes\FunWebProductsInstaller.Start.1
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{004EB151-885B-4A9E-A22D-CA98DD998D75}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{041278C7-DF92-486D-AE85-921BDFC75A43}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0F1794F2-900B-4C81-8146-9234E5CC5BE2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1116A14B-F6A3-4FD9-A00E-FF8CF270EE48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{21D9997E-5D2A-4737-BCBA-C958C0590295}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{36A7148B-639E-423C-90BB-30B6E1A40BD7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{56965DCF-718F-4148-BECF-5A2B466F4556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{58E64AEE-516A-4DFC-AC38-31C50E8AF0F1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5F701D7D-C869-41F0-B0E2-8136F02B539C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{61DAB0AD-AD23-4E40-84AC-7C6CE64D4EB3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{65D8E17B-312E-4E12-913B-A841A8631143}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6BDA50D2-5597-4C68-A842-9B857FCCDA49}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6CA3D0AB-F807-462C-BA7F-E27F07F91E32}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6F99D2AE-5C90-43C2-A2FE-81DBE512E2FC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{860AF5D1-0735-409D-8E5F-E3E99356D7E9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8997561D-CF0B-42C7-AAE6-78801B3ADC7F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{92580E8C-88F5-4551-9D9E-8147E7EE2C32}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A0636D37-97D0-4DC4-95A6-93AABA07437F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A786F51D-B3C7-4F52-91EF-E1A892C2A2AE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D244EAC5-A0F5-4859-A1F8-18ABC0AC3A00}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8AF87C1-0B1E-494B-AAF0-CECC3FFEDF99}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC4DAE-7794-4E16-9A98-F6001303DCD0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAB77009-B974-48DF-8229-E70CFAA11C69}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EBAA6283-B61F-4DDD-9659-56635433A307}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFB0C189-5077-4340-9838-AF7B8E792A54}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFB4F034-3EB5-48D5-84DD-89BBCF9A182F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F9D45087-1CF1-452E-9649-FDFDAC578E03}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FF2EBC1C-6579-41DB-91DD-945A1C8DB2D2}
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils
Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1
Key Deleted : HKLM\SOFTWARE\Classes\TBSB07898.IEToolbar
Key Deleted : HKLM\SOFTWARE\Classes\TBSB07898.IEToolbar.1
Key Deleted : HKLM\SOFTWARE\Classes\TBSB07898.TBSB07898
Key Deleted : HKLM\SOFTWARE\Classes\TBSB07898.TBSB07898.3
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.TBSB07898
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.TBSB07898.1
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D4DB7D0-6EC9-47A3-BD87-1E41684E07BB}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{20BCCE5A-C687-46FF-8DD2-AD8235F5F2B4}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3276E8A8-A233-449B-A7EB-FCEE21246018}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{53CA18E7-5223-4358-9FD9-97C62C66C5BD}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{60FC9013-4A5A-4306-9695-FCE0A6617F22}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{7924FD2B-877C-4395-A063-A88AB887EA6D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{79583DE9-D0C2-44EF-AE0D-CBFA16C2A785}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8542E415-0E53-4261-8BE4-0D1598229D90}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A4116F8C-A634-4536-B9EF-6B9EBCC5BAE1}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C7E7FB02-C4FD-446E-8F5B-463A049935BF}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7CE22AF-CCB3-423F-84D5-4D77152181F3}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EBAF2B4F-510A-47C7-86BA-E7D94D1162F6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EC4085F2-8DB3-45A6-AD0B-CA289F3C5D7E}
Key Deleted : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook
Key Deleted : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook.1
Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers
Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1
Key Deleted : HKLM\Software\CouponAlert_2p
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\FunWebProducts
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16FE2505-F2A0-4782-B035-AF0E5188C02C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2AF08E71-3657-462F-898C-F7E791948F94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56965DCF-718F-4148-BECF-5A2B466F4556}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6F99D2AE-5C90-43C2-A2FE-81DBE512E2FC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7225F6C9-CF64-4D6D-AE8A-169779FD7B4D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{60E91567-EF8A-4520-BCE2-83ABA5256799}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0BDF6C42-132C-45F5-92DE-DC13F40C6DAB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{23B38049-323F-443D-9732-F454E5B15B72}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8867AC9B-4426-44A2-A693-C95850D3405C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{95B3F577-D54A-4831-B2B4-8AACEEDA85CF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C2DF3856-676C-41DC-A73B-FACBDF8E81E9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CF9D6D4E-5496-438E-BA24-5A580A59F5A3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\120DFADEB50841F408F04D2A278F9509
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2BDF3E992C0908741B7C11F4B4E0F775
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B3BC4CF5ECE1F54BBA174C13A1AB907
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B5BAE2ED018083A4C8DA86D6E3F4B024
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BEABAA33A5E68374DBF197F2A00CD011
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB61AF52AD64B6B45930BE969F316720
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CouponAlert_2pbar Uninstall
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@CouponAlert_2p.com/Plugin
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@funwebproducts.com/Plugin
Key Deleted : HKLM\Software\Tarma Installer
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{7B9F8C21-46EC-4C0B-8683-E755EF84577A}]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Yontoo Desktop]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{3462C343-BE19-4143-AF70-CEFB56F46FC6}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [2pffxtbr@CouponAlert_2p.com]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16496

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://isearch.glarysoft.com/?src=iehome –> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://isearch.glarysoft.com/?src=iehome –> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://isearch.glarysoft.com/?src=iehome –> hxxp://www.google.com

-\\ Google Chrome v28.0.1500.95

File : C:\Users\Valued Customer\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.43] : icon_url = "hxxp://www.delta-search.com/favicon.ico",
Deleted [l.46] : keyword = "delta-search.com",
Deleted [l.50] : search_url = "hxxp://www.delta-search.com/?q={searchTerms}&affID=119842&babsrc=SP_ss&mntrId=2[…]
Deleted [l.2104] : homepage = "hxxp://www.delta-search.com/?affID=119842&babsrc=HP_ss&mntrId=240E001D72CEDA2D",
Deleted [l.2326] : urls_to_restore_on_startup = [ "hxxp://www.delta-search.com/?affID=119842&babsrc=HP_ss&mntrId[…]

*************************

AdwCleaner[S1].txt - [28359 octets] - [01/08/2013 02:03:35]

########## EOF - C:\AdwCleaner[S1].txt - [28420 octets] ##########



JRT logfile

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.2.9 (07.30.2013:1)
OS: Windows Vista ™ Home Premium x86
Ran by [removed] on Thu 08/01/2013 at 2:10:36.18
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\yt.ytnavassistplugin
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\yt.ytnavassistplugin.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\windows\currentversion\ext\preapproved\{4623a8c4-150d-4983-8982-68c01e7d6541}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5a1d0d31-749c-4186-a295-4106e6e7b26a}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{F6B6724D-4318-44BC-BC2D-C1672ADCFDD1}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{5a1d0d31-749c-4186-a295-4106e6e7b26a}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\ammyy"
Successfully deleted: [Folder] "C:\ProgramData\coupon savings"
Successfully deleted: [Folder] "C:\ProgramData\pc1data"
Successfully deleted: [Folder] "C:\Users\Valued Customer\AppData\Roaming\pc cleaners"
Successfully deleted: [Folder] "C:\Users\Valued Customer\appdata\locallow\couponalert_2pei"
Successfully deleted: [Folder] "C:\Program Files\couponalert_2pei"
Successfully deleted: [Folder] "C:\Program Files\coupons.com couponbar"
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{0277E706-AB22-47B6-99DE-B1B0C5BA55F0}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{0D1D6192-E42D-483E-B8BC-0064C523D5D8}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{11709CD0-97A0-4ED8-8CFC-8A80F0C2378B}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{2645DBD0-3BEB-4325-98F5-C1F83AFECDD4}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{30AFB819-F0A0-4F26-9611-3B7CC15AB78A}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{514E0227-9386-4A83-970F-5FB8FA8C8BFF}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{62BF23A7-62BD-45CC-B9AA-813555795438}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{6D499834-6F2B-44FB-9BDC-9E6579218112}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{865B057A-279C-49B2-BBD5-1F14B352D3F0}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{926A978E-3B31-41A3-A33A-5174C86CBD22}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{9F0756B1-C3C4-4E36-B4B6-DA17C88B248A}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{A64E708C-3F2A-443B-B768-B7309C2119D9}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{C25B3680-55E9-4D6C-84A8-13952C8EEEA7}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{C783FBF8-8506-4F51-844A-56C39B645925}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{E3873E67-A5AD-408E-8434-83297018BA75}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{E720ECA0-E2BB-4B75-8612-501A2BDB7F87}
Successfully deleted: [Empty Folder] C:\Users\Valued Customer\appdata\local\{F5A880B5-DCAF-4265-82D7-B8B0DA3F1CA8}



~~~ Chrome

Successfully deleted: [Folder] C:\Users\Valued Customer\appdata\local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 08/01/2013 at 2:12:27.41
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Sorry that I didn't manage to answer you earlier.

Please run ComboFix in safe mode.

Reboot your computer in Safe Mode
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
Tutorial if you need it How to boot into Safemode
Thanks again for all your help…I'm getting some error messages running ComboFix in Safe Mode, and have paused until I hear from you. Here are the messages: 1. Error saving file - C:\Windows\erdnt\Hiv-backup\security ! 2. Error saving file - C:\Windows\erdnt\Hiv-backup\software ! 3. Error saving file - C:\Windows\erdnt\Hiv-backup\system ! 4. Error saving file - C:\Windows\erdnt\Hiv-backup\default ! 5. Error saving file - C:\Windows\erdnt\Hiv-backup\sam ! 6. Error saving file - C:\Windows\erdnt\Hiv-backup\COMPON~3 ! 7. Error saving file - C:\Windows\erdnt\Hiv-backup\BCD ! 8. Error saving file - C:\Windows\erdnt\Hiv-backup\00000001\ntuser.dat ! 9. Error saving file - C:\Windows\erdnt\Hiv-backup\00000002\ntuser.dat ! 10. Error saving file - C:\Windows\erdnt\Hiv-backup\00000003\ntuser.dat ! Each of the above errors were separate, and also said [RegCreateKeyEx:5 - Access is denied} After this, I got a message that ComboFix detected MSE to be active still. Since MSE cannot run in SafeMode, should I continue to run the program? This is where I stopped…please advise on how to proceed… Thanks again…
Uh oh…not good. I ran ComboFix, and the logfile appeared….I tried to open internet explorer to post the results and I get the following error message: C:\Program Files\Internet Explorer\iexplore.exe Illegal operation attempted on a registry key that has been marked for deletion. The same thing came up for the Chrome browser… Hopefully this is not as major a deal as it seems…..

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI