This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

C Documents and settings system 32 [Solved]

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi I followed the instructions, but fear that the scan did not catch my virus because the problem has been going on for more than 30 days. What occurs is a black box appears with a message system unavailable or something of that nature for C Documents and Settings System 32

I sure wish the box would not go away so fast so I could Snag it.
I am wondering if I should have changed the date to more than 30 days on tool 1. I also used tool 2 and can send those results if needed.

Here are the results of tool 1

OTL logfile created on: 8/21/2013 1:07:07 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Tracy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.03 Gb Available Physical Memory | 51.68% Memory free
4.85 Gb Paging File | 3.89 Gb Available in Paging File | 80.34% Paging File free
Paging file location(s): c:\pagefile.sys 3069 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.47 Gb Total Space | 35.98 Gb Free Space | 48.32% Space Free | Partition Type: NTFS

Computer Name: DDHFR351 | User Name: Tracy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Tracy\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Google\Drive\googledrivesync.exe (Google)
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe (Carbonite, Inc. (www.carbonite.com))
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
PRC - C:\Program Files\iYogi Support Dock\iYogiSupportDock.exe ()
PRC - C:\Program Files\iYogi Support Dock\Services\CommAgent\SupportDockService.exe (iYogi Technical Services)
PRC - C:\Documents and Settings\Tracy\Application Data\mjusbsp\magicJack.exe (magicJack L.P.)
PRC - C:\Program Files\iYogi Support Dock\pccare\iysoDefragSrv.exe (iYogi., (www.iyogi.net))
PRC - C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\5.2.2.3\ccsvchst.exe (Symantec Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\agent.exe (Acresso Corporation)
PRC - C:\Program Files\ArcSoft\TotalMedia Extreme\BackUp & Recorder\uBBMonitor.exe (ArcSoft, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\NewSoft\Presto! PageManager 6\NetGroup.exe (NewSoft Technology Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\wx._gdi_.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\wx._misc_.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\pysqlite2._sqlite.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\windows._cacheinvalidation.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\pythoncom27.dll ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\win32com.shell.shell.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\_elementtree.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\win32api.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\_ctypes.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\wx._html2.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\_socket.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\_multiprocessing.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\win32ts.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\win32profile.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\win32crypt.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\wx._core_.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\_ssl.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\wx._windows_.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\_hashlib.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\wx._wizard.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\win32file.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\PyWinTypes27.dll ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\win32security.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\win32inet.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\win32process.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\win32pdh.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\wx._controls_.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\unicodedata.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\pyexpat.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\win32event.pyd ()
MOD - C:\Documents and Settings\Tracy\Local Settings\Temp\_MEI36082\select.pyd ()
MOD - C:\Program Files\iYogi Support Dock\iYogiSupportDock.exe ()
MOD - C:\Program Files\iYogi Support Dock\Services\CommAgent\IYogiToolbar.SupportDock.Client.Common.dll ()
MOD - C:\Program Files\iYogi Support Dock\Services\CommAgent\IYogiToolbar.SupportDock.Client.Logging.dll ()
MOD - C:\Program Files\iYogi Support Dock\Services\CommAgent\Cryptography.dll ()
MOD - C:\Documents and Settings\Tracy\Application Data\mjusbsp\octvqem_apiw.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\1f61bccb700d687775cf778dd77752e9\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\e182695d05ea57257568bc5f3208aca7\System.ServiceModel.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\2c208e4c5521f31057ea7d6e93c6a567\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\7c743462baccf29b3567b0e3ec9ac134\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\7602d7687fb9bd21cd9ae60d2b187c99\SMDiagnostics.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\06d6eab93282d2b136a377bd50b7c5a9\System.ServiceModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\67ad55827f2542552b576170f0a7dc56\System.Runtime.Serialization.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\5913d3f81e77194ec833991b1047a532\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Core\c0a42d2ad8a4078040b334f6770ea11f\System.Core.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\3de5bd01124463d7862bd173af90bc83\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\ArcSoft\TotalMedia Extreme\BackUp & Recorder\fpxlib.dll ()


========== Services (SafeList) ==========

SRV - (iyogi-scc-1358313302) – C:\Documents and Settings\All Users\Application Data\iyogi-scc-50F63756\iyogi-scc.exe File not found
SRV - (Basics Service) – C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe File not found
SRV - (ADExchange) – C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (CarboniteService) – C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe (Carbonite, Inc. (www.carbonite.com))
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SDiManage) – C:\Program Files\SDC\SDiManage\IYogiMonitoringSvc.exe ()
SRV - (SupportDockService.exe) – C:\Program Files\iYogi Support Dock\Services\CommAgent\SupportDockService.exe (iYogi Technical Services)
SRV - (IYSODiskOptimizer) – C:\Program Files\iYogi Support Dock\pccare\iysoDefragSrv.exe (iYogi., (www.iyogi.net))
SRV - (PenCommService) – C:\Program Files\Common Files\Livescribe\PenComm\PenCommService.exe (Livescribe)
SRV - (N360) – C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe (Symantec Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (DragonSvc) – C:\Program Files\Common Files\Nuance\dgnsvc.exe (Nuance Communications, Inc.)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (Norton Ghost) – C:\Program Files\Norton Ghost\Agent\VProSvc.exe (Symantec Corporation)
SRV - (SymSnapService) – C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe (Symantec)
SRV - (sprtsvc_dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (EpsonBidirectionalService) – C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (wanatw) – System32\DRIVERS\wanatw4.sys File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys File not found
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (pbfilter) – C:\Program Files\PeerBlock\pbfilter.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (KMW_KBD) – System32\DRIVERS\KMW_KBD.sys File not found
DRV - (EraserUtilDrv11110) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11110.sys File not found
DRV - (Changer) – File not found
DRV - (ccHP) – C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys File not found
DRV - (aeaudio) – system32\drivers\aeaudio.sys File not found
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilDrv11310) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11310.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20130820.001\IDSXpx86.sys (Symantec Corporation)
DRV - (MBAMSwissArmy) – C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20130715.001\BHDrvx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20130821.002\NAVEX15.SYS (Symantec Corporation)
DRV - (EraserUtilDrv11220) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11220.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20130821.002\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0502020.003\symtdi.sys (Symantec Corporation)
DRV - (SymIMMP) – C:\WINDOWS\SYSTEM32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (SymIM) – C:\WINDOWS\SYSTEM32\DRIVERS\SymIM.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0502020.003\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0502020.003\srtspx.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0502020.003\symefa.sys (Symantec Corporation)
DRV - (npf) – C:\WINDOWS\SYSTEM32\DRIVERS\npf.sys (CACE Technologies, Inc.)
DRV - (SymDS) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0502020.003\symds.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\SYSTEM32\DRIVERS\N360\0502020.003\ironx86.sys (Symantec Corporation)
DRV - (PulseUsb) – C:\WINDOWS\SYSTEM32\DRIVERS\PulseUsb.sys (Windows ® Win 7 DDK provider)
DRV - (ssmirrdr) – C:\WINDOWS\SYSTEM32\DRIVERS\ssmirrdr.sys (support.com, Inc)
DRV - (Revoflt) – C:\WINDOWS\SYSTEM32\DRIVERS\revoflt.sys (VS Revo Group)
DRV - (archlp) – C:\WINDOWS\SYSTEM32\DRIVERS\ArcHlp.sys ()
DRV - (WDC_SAM) – C:\WINDOWS\SYSTEM32\DRIVERS\wdcsam.sys (Western Digital Technologies)
DRV - (WimFltr) – C:\WINDOWS\SYSTEM32\DRIVERS\WimFltr.sys (Microsoft Corporation)
DRV - (v2imount) – C:\WINDOWS\SYSTEM32\DRIVERS\v2imount.sys (Symantec Corporation)
DRV - (VProEventMonitor) – C:\WINDOWS\SYSTEM32\DRIVERS\vproeventmonitor.sys (Symantec Corporation)
DRV - (symsnap) – C:\WINDOWS\SYSTEM32\DRIVERS\symsnap.sys (StorageCraft)
DRV - (ArcCD) – C:\WINDOWS\System32\drivers\ArcCD.sys (ArcSoft Inc.)
DRV - (ArcUdfs) – C:\WINDOWS\System32\drivers\ArcUdfs.sys (ArcSoft Inc.)
DRV - (ArcRec) – C:\WINDOWS\System32\drivers\ArcRec.sys (ArcSoft Inc.)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (Afc) – C:\WINDOWS\SYSTEM32\DRIVERS\afc.sys (Arcsoft, Inc.)
DRV - (senfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\senfilt.sys (Creative Technology Ltd.)
DRV - (KMW_USB) – C:\WINDOWS\SYSTEM32\DRIVERS\KMW_USB.sys (Kensington Technology Group)
DRV - (HSFHWBS2) – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {90FA5274-76D8-4C10-B663-49E7716E4901}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{8684a7c7-3ade-4208-ad43-ad57a1af352c}: "URL" = http://search.tb.ask.com/search/GGmain.jht…r={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {79F78DE4-FD56-4010-8369-0176888B3064}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searcSearchScopes
IE - HKCU\..\SearchScopes\{79F78DE4-FD56-4010-8369-0176888B3064}: "URL" = http://search.yahoo.com/search?fr=chr-gree…p={searchTerms}
IE - HKCU\..\SearchScopes\{8684a7c7-3ade-4208-ad43-ad57a1af352c}: "URL" = http://search.tb.ask.com/search/GGmain.jht…r={searchTerms}
IE - HKCU\..\SearchScopes\{90FA5274-76D8-4C10-B663-49E7716E4901}: "URL" = http://search.conduit.com/ResultsExt.aspx?…087135&UM;=2
IE - HKCU\..\SearchScopes\{F3E02D00-CE65-4BC7-96E7-4FF65DDAE24B}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..CT3287822.browser.search.defaultthis.engineName: "true"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "MixiDJ V8 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3287822&CUI;=UN20841189803632180&UM;=2&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc;=12&type;=994519"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search.yahoo.com?type=994519&fr;=spigot-yhp-ff"
FF - prefs.js..extensions.enabledAddons: %7BBBDA0591-3099-440a-AA10-41764D9DB4DB%7D:11.4.0.6%20-%201
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&ilc;=12&type;=994519&p;="
FF - prefs.js..searchreset.backup.browser.search.defaultenginename: "iYogi"
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT3287822&CUI;=UN20841189803632180&UM;=2&SearchSource;=13"
FF - prefs.js..searchreset.backup.keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3287822&SearchSource;=2&CUI;=UN20841189803632180&UM;=2&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll File not found
FF - HKLM\Software\MozillaPlugins\@funwebproducts.com/Plugin: C:\Program Files\FunWebProducts\Installr\1.bin\NPFunWeb.dll File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2852: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2910: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1662: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Documents and Settings\Tracy\Application Data\Mozilla\Firefox\Profiles\m3exjy1b.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Tracy\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2013/07/25 23:45:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_9_4 [2013/08/17 10:48:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2010/07/14 13:11:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tracy\Application Data\Mozilla\Extensions
[2013/08/06 09:50:34 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tracy\Application Data\Mozilla\Firefox\Profiles\m3exjy1b.default\extensions
[2011/12/23 21:27:47 | 000,000,000 | —D | M] () – C:\Documents and Settings\Tracy\Application Data\Mozilla\Firefox\Profiles\m3exjy1b.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
[2013/05/06 09:39:25 | 000,001,294 | —- | M] () – C:\Documents and Settings\Tracy\Application Data\Mozilla\Firefox\Profiles\m3exjy1b.default\searchplugins\delta.xml
[2011/06/07 16:56:23 | 000,002,468 | —- | M] () – C:\Documents and Settings\Tracy\Application Data\Mozilla\Firefox\Profiles\m3exjy1b.default\searchplugins\safesearch.xml
[2013/07/24 22:33:36 | 000,000,904 | —- | M] () – C:\Documents and Settings\Tracy\Application Data\Mozilla\Firefox\Profiles\m3exjy1b.default\searchplugins\yahoo.xml
[2013/05/31 11:20:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/08/09 11:25:02 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/07/25 23:45:48 | 000,000,000 | —D | M] (Symantec Intrusion Prevention) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPLGN

========== Chrome ==========

CHR - homepage: {negative_upload_rate:1.0,positive_upload_rate:1.0},bookmark_bar:{show_on_all_ta
bs:true},browser:{check_default_browser:false,clear_lso_data_enabled:true,last_kn
own_google_url:https://www.google.com/,last_prompted_google_url:https://www.google.com/,pepper_flash_settings_enabled:true,window_placement:{bottom:734,left:12,maximiz
ed:false,right:1016,top:20,work_area_bottom:734,work_area_left:0,work_area_right:
1024,work_area_top:0}},cloud_print:{email:},countryid_at_install:21843,default_ap
ps_install_state:3,default_search_provider:{enabled:true,encodings:UTF-8,icon_url:http://www.babylon.com/favicon.ico,id:8,instant_url:,keyword:babylon.com,name:Search the web (Babylon),prepopulate_id:0,search_terms_replacement_key:,search_url:http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch⁡=14542,suggest_url:},distribution:{create_all_shortcuts:true,do_not_launch
_chrome:true,import_history:false,import_search_engine:false,make_chrome_default:
false,ping_delay:-60,skip_first_run_ui:false,verbose_logging:false},dns_prefetching:{host_referral
_list:[2,[http://a.rfihub.com/,[http://a.rfihub.com/,0.2049925124315464,http://ad.doubleclick.net/,0.2049925124315464,http://b.scorecardresearch.com/,0.2309990252027127,http://c1.rfihub.net/,0.17898599966038006,http://cm.g.doubleclick.net/,0.17898599966038006,http://ib.adnxs.com/,0.17898599966038006,http://p.rfihub.com/,0.17898599966038006,http://s0.2mdn.net/,0.17898599966038006,http://secure-us.imrworldwide.com/,0.17898599966038006]],[http://ad.doubleclick.net/,[http://amch.questionmarket.com/,1.5309457746093675,http://aperture.displaymarketplace.com/,1.336721310666388,http://d.p-td.com/,0.7635999411921651,http://l.betrad.com/,0.503975961186829,http://r1.ace.advertising.com/,0.05462740600327398,http://s.amazon-adsystem.com/,0.8745503599978645,http://s0.2mdn.net/,1.1338526061182344,http://uac.advertising.com/,0.05462740600327398,http://view.atdmt.com/,0.05462740600327398]],[http://ad.turn.com/,[http://cdn.turn.com/,0.4856000049606466]],[http://ad.yieldmanager.com/,[http://ad.yieldmanager.com/,3.026519823738891,http://ib.adnxs.com/,1.752984254343813,http://pixel.invitemedia.com/,2.007691368222829,http://t.invitemedia.com/,1.752984254343813,http://ums.adtechus.com/,2.007691368222829,http://view.atdmt.com/,2.007691368222829]],[http://ads.pubmatic.com/,[http://adadvisor.net/,1.752984254343813,http://b.scorecardresearch.com/,1.752984254343813,http://connexity.net/,1.752984254343813,http://image2.pubmatic.com/,2.299038944756858,http://match.rtbidder.net/,1.752984254343813,http://pixel.ad.mlnadvertising.com/,2.007691368222829,http://pixel.sitescout.com/,0.8745503599978646,http://px.owneriq.net/,1.752984254343813,http://soundwave.bnmla.com/,1.752984254343813,http://sync.atomex.net/,1.752984254343813]],[http://amch.questionmarket.com/,[http://amch.questionmarket.com/,1.7377129222639303]],[http://an.tacoda.net/,[http://an.tacoda.net/,1.0987620868794294,http://ar.atwola.com/,0.9384304210089309,http://d.audienceiq.com/,2.0846863392705286,http://leadback.advertising.com/,0.806879104499641,http://rt.legolas-media.com/,0.5007308295434576,http://tacoda.at.atwola.com/,0.9878116680737301,http://tags.bluekai.com/,0.7635999411921651]],[http://assets.pinterest.com/,[http://widgets.pinterest.com/,0.8981931012779276]],[http://blackherald.egoong.com/,[http://blackherald.egoong.com/,0.455581398089532]],[http://bnw.xp1.ru4.com/,[http://ad.doubleclick.net/,1.5172568052602977]],[http://c.www.endless.com/,[http://s.amazon-adsystem.com/,1.752984254343813]],[http://cdn.interclick.com/,[http://cdn.interclick.com/,0.27364970614742545,http://d.agkn.com/,0.11813075977585069,http://dpm.demdex.net/,0.13529505820482057,http://e.nexac.com/,0.2049925124315464,http://osmsync.interclick.com/,0.1441372725470171,http://tags.bluekai.com/,0.17898599966038006]],[http://cdn.turn.com/,[http://image2.pubmatic.com/,0.21956445411851094,http://pixel.rubiconproject.com/,1.752984254343813,http://tag.admeld.com/,0.14491253971821716]],[http://cm.g.doubleclick.net/,[http://cm.g.doubleclick.net/,0.0690141584092036,http://dclk-match.dotomi.com/,0.384302029931344,http://gpush.cogocast.net/,0.06311455137151778]],[http://cmap.uac.ace.advertising.com/,[http://ckm-m.xp1.ru4.com/,1.0013894914717965,http://cmap.an.ace.advertising.com/,1.0268742185974162,http://cmap.at.ace.advertising.com/,1.0013894914717965,http://cmap.rm.ace.advertising.com/,0.6609170643713856,http://d.p-td.com/,1.0013894914717965,http://dpm.demdex.net/,1.0013894914717965,http://ib.adnxs.com/,1.2218456084754288,http://tacoda.at.atwola.com/,1.146890528694194,http://tag.admeld.com/,1.0013894914717965,http://tags.bluekai.com/,1.0013894914717965]],[http://connexity.net/,[http://connexity.net/,1.752984254343813,http://image2.pubmatic.com/,1.752984254343813,http://s.cxt.ms/,1.752984254343813,http://t.cxt.ms/,1.752984254343813,https://connexity.net/,1.752984254343813]],[http://ct1.addthis.com/,[http://addthis.acxiom-online.com/,0.0779663014520615,http://addthis.mathtag.com/,0.0779663014520615,http://addthis.nexac.com/,0.0779663014520615,http://cspix.media6degrees.com/,0.0779663014520615,http://d.turn.com/,0.16859379715702189,http://dpm.demdex.net/,0.0779663014520615,http://ds.reson8.com/,0.08929473841518155,http://m.addthisedge.com/,0.1441372725470171,http://segment-pixel.invitemedia.com/,0.0779663014520615,http://su.addthis.com/,0.1572653601939019]],[http://cti.w55c.net/,[http://ad.360yield.com/,0.11813075977585087,http://ad.crwdcntrl.net/,0.11813075977585087,http://cti.w55c.net/,0.11813075977585087,http://dx3723.tinyurl.com/,0.11813075977585087,http://e.nexac.com/,0.13529505820482057,http://i.w55c.net/,0.16962365506276003,http://ih.adscale.de/,0.11813075977585087,http://pix.bit.ly/,0.11813075977585087,http://pixel.rubiconproject.com/,0.11813075977585087,http://r.casalemedia.com/,0.11813075977585087]],[http://d37x6ru616myg2.cloudfront.net/,[http://d37x6ru616myg2.cloudfront.net/,0.11813075977585087]],[http://dap.criteo.com/,[http://ad.yieldmanager.com/,2.3875894825833406,http://ap.lijit.com/,2.0846863392705286,http://cm.g.doubleclick.net/,2.0846863392705286,http://dis.criteo.com/,2.993395769208965,http://googleads.g.doubleclick.net/,2.0846863392705286,http://ib.adnxs.com/,2.3875894825833406,http://pixel.rubiconproject.com/,2.0846863392705286,http://r.openx.net/,2.3875894825833406,http://tag.admeld.com/,2.0846863392705286,http://www.googleadservices.com/,2.0846863392705286]],[http://dis.sv.us.criteo.com/,[http://ap.lijit.com/,1.752984254343813,http://cm.g.doubleclick.net/,2.262398482101845,http://dis.criteo.com/,2.771812709859876,http://googleads.g.doubleclick.net/,1.752984254343813,http://ib.adnxs.com/,2.007691368222829,http://pixel.rubiconproject.com/,1.752984254343813,http://tag.admeld.com/,2.007691368222829,http://www.facebook.com/,1.752984254343813,http://www.googleadservices.com/,1.752984254343813,https://simage2.pubmatic.com/,1.752984254343813]],[http://disqus.com/,[http://disqus.com/,0.051443838678837346,http://mediacdn.disqus.com/,0.10936074315170063]],[http://education.yahoo.com/,[http://l.yimg.com/,0.1065704144952512]],[http://eec.rtb.prod2.invitemedia.com/,[http://cm.g.doubleclick.net/,0.17898599966038006,http://eec.pixel.prod2.invitemedia.com/,0.17898599966038006,http://g-pixel.invitemedia.com/,0.17898599966038006,http://pixel.invitemedia.com/,0.17898599966038006,http://view.atdmt.com/,0.17898599966038006]],[http://gmail.com/,[https://accounts.google.com/,0.08372992214784244,https://gmail.com/,0.08372992214784244,https://mail.google.com/,0.08372992214784244]],[http://googleads.g.doubleclick.net/,[http://ad.doubleclick.net/,0.8822360650398164,http://cm.g.doubleclick.net/,0.48839398333154466,http://pagead2.googlesyndication.com/,3.698698764135407,http://www.google.com/,1.010424211242183,https://googleads.g.doubleclick.net/,1.010424211242183]],[http://ip.casalemedia.com/,[http://ad.afy11.net/,0.17898599966038006]],[http://jdn.monster.com/,[http://cdn.atdmt.com/,0.17898599966038006,http://jdn.monster.com/,0.2830120507450454,http://view.atdmt.com/,0.17898599966038006]],[http://js.bizographics.com/,[http://an.tacoda.net/,0.40908167525933486,http://cs.specificclick.net/,1.336721310666388,http://js.bizographics.com/,0.953029327716125,http://load.exelator.com/,0.4645747079604981,http://tags.bluekai.com/,0.27347278539790526,http://www.bkrtx.com/,0.20861162128754374]],[http://kvsync.com/,[http://present.knowledgevision.com/,0.059219153976855746]],[http://lax1.ib.adnxs.com/,[http://a.collective-media.net/,2.007691368222829,http://b.collective-media.net/,1.752984254343813,http://b.scorecardresearch.com/,1.752984254343813,http://c.betrad.com/,2.262398482101845,http://d37x6ru616myg2.cloudfront.net/,4.045348279254953,http://ib.adnxs.com/,1.752984254343813,http://ib.mookie1.com/,1.752984254343813,http://l.collective-media.net/,2.007691368222829,http://r.nexac.com/,1.752984254343813,http://view.atdmt.com/,1.752984254343813]],[http://load.exelator.com/,[http://load.s3.amazonaws.com/,1.685010179254655,http://loadm.exelator.com/,1.979289670077351,http://p.adsymptotic.com/,2.025335319191497,http://p.rfihub.com/,0.7635999411921651,http://pixel.jumptap.com/,2.025335319191497,http://segments.adap.tv/,2.025335319191497,http://www.wtp101.com/,2.025335319191497,https://load.s3.amazonaws.com/,0.7635999411921651,https://loadm.exelator.com/,0.7635999411921651,https://t.mookie1.com/,0.7635999411921651]],[http://loadus.exelator.com/,[http://a64.korrelate.net/,0.17898599966038006,http://load.s3.amazonaws.com/,0.3389075365659596,http://loadm.exelator.com/,0.3278056683421018,http://match.adsrvr.org/,0.17898599966038006,http://p.adsymptotic.com/,0.17898599966038006,http://p.raasnet.com/,0.2049925124315464,http://rtd.tubemogul.com/,0.11813075977585069,http://segments.adap.tv/,0.11813075977585069,http://tacoda.at.atwola.com/,0.11813075977585069,http://www.wtp101.com/,0.17898599966038006]],[http://m.xp1.ru4.com/,[http://d.xp1.ru4.com/,0.11813075977585087,http://http.content.ru4.com/,0.3900021720838362,http://ib.adnxs.com/,0.11813075977585087,http://idsync.rlcdn.com/,0.15245935663379043,http://image2.pubmatic.com/,0.11813075977585087,http://loadus.exelator.com/,0.3728378736548665,http://m.xp1.ru4.com/,0.6618735843918218,http://r.nexac.com/,1.752984254343813,http://r.openx.net/,0.13529505820482057,http://tags.bluekai.com/,0.3728378736548665]],[http://mf.sitescout.com/,[http://cdn2sitescout.edgesuite.net/,2.6037003999999997,http://mfcdn.s3.amazonaws.com/,2.6037003999999997]],[http://pixel.invitemedia.com/,[http://ad.yieldmanager.com/,0.7635999411921652,http://googleads.g.doubleclick.net/,0.7635999411921652,http://pixel.rubiconproject.com/,0.26950101374850843,http://segment-pixel.invitemedia.com/,0.13336541860796114,http://tags.bluekai.com/,0.13336541860796114,http://tap.rubiconproject.com/,0.26950101374850843]],[http://platform.twitter.com/,[http://cdn.api.twitter.com/,0.5527177575502866,http://p.twitter.com/,0.5344028865957582,https://r.twimg.com/,0.5344028865957582]],[http://puma.vizu.com/,[http://cheetah.vizu.com/,1.0377401890316942,http://puma.vizu.com/,1.0377401890316942]],[http://r.turn.com/,[http://cdn.turn.com/,0.3728378736548665]],[http://reddevnews.com/,[http://ad.doubleclick.net/,0.14411088583541853,http://amch.questionmarket.com/,0.08619398136255531,http://bs.serving-sys.com/,0.051443838678837346,http://ds.serving-sys.com/,0.05723552912612365,http://pagead2.googlesyndication.com/,0.06881891002069625,http://reddevnews.com/,0.1672776476245636]],[http://resources.infoworld.com/,[http://computerworld.com.edgesuite.net/,0.06302721957341005,http://now.eloqua.com/,0.06881891002069625,http://reg.idgenterprise.com/,0.10356905270441422,http://secure-us.imrworldwide.com/,0.06881891002069625]],[http://rs.gwallet.com/,[http://ib.adnxs.com/,0.17898599966038006,http://pixel.rubiconproject.com/,0.17898599966038006,http://po.st/,0.17898599966038006,http://rp.gwallet.com/,0.17898599966038006,http://tag.admeld.com/,0.17898599966038006]],[http://s.amazon-adsystem.com/,[http://sis.amazon.com/,1.752984254343813]],[http://search.babylon.com/,[http://acz.babsrv.com/,0.2218218086752541,http://b.scorecardresearch.com/,0.10497482776744418,http://nrissy.com/,0.0731074693380415,http://usw.cdn-services.com/,0.10497482776744418,http://www.google-analytics.com/,0.09435237495764333]],[http://sis.amazon.com/,[http://c.www.endless.com/,1.752984254343813]],[http://static.knowledgevision.com/,[http://static.knowledgevision.com/,0.06881891002069625]],[http://swz.salary.com/,[http://a.collective-media.net/,0.17898599966038006,http://ar.voicefive.com/,0.2049925124315464,http://b.scorecardresearch.com/,0.17898599966038006,http://b.voicefive.com/,0.17898599966038006,http://beacon.krxd.net/,0.17898599966038006,http://d37x6ru616myg2.cloudfront.net/,0.2309990252027127,http://l.betrad.com/,0.17898599966038006,http://l.collective-media.net/,0.2049925124315464,http://swz.salary.com/,1.288423834478334,http://tag.admeld.com/,0.2049925124315464]],[http://tag.audiencetv.hiro.tv/,[http://9a67fb49–b1–k.tlm100.net/,0.2830120507450454,http://cdn454.telemetryverification.net/,0.2049925124315464,http://is1.j.tv2n.net/,0.17898599966038006,http://pixel.quantserve.com/,0.17898599966038006,http://search.spotxchange.com/,0.3090185635162116,http://sos.skipit.com/,0.2309990252027127,http://spc.cegfkfcglefhdhjcghahgene.carousel.telemetryverification.net/,0.2049925124315464,http://spotxchange-pubnet.usa.telemetryverification.net/,0.2049925124315464,http://www.skipitcdn.com/,0.2309990252027127,https://api.skipit.com/,0.2309990252027127]],[http://tag.crsspxl.com/,[http://a.collective-media.net/,2.0846863392705286,http://ad.yieldmanager.com/,2.3875894825833406,http://cm.g.doubleclick.net/,2.0846863392705286,http://ib.mookie1.com/,1.336721310666388,http://match.adsrvr.org/,1.336721310666388,http://p.nexac.com/,2.0846863392705286,http://segment-pixel.invitemedia.com/,2.3875894825833406,http://tag.crsspxl.com/,2.175065793405184,https://t.mookie1.com/,1.336721310666388,https://tag.crsspxl.com/,1.336721310666388]],[http://tags.bluekai.com/,[http://ad.yieldmanager.com/,2.319614810014193,http://d.p-td.com/,1.1569696078669172,http://d.turn.com/,1.1569696078669172,http://match.adsrvr.org/,0.7635999411921651,http://pixel.mathtag.com/,0.38095413681506957,http://segment-pixel.invitemedia.com/,2.025335319191497,http://sync.adap.tv/,0.7635999411921651,http://sync.tidaltv.com/,1.1569696078669172,http://tags.bluekai.com/,0.6843031254817719,http://www.facebook.com/,0.3326241343833072]],[http://tap2-cdn.rubiconproject.com/,[http://ad.turn.com/,1.1569696078669172,http://ib.adnxs.com/,1.752984254343813,http://map.media6degrees.com/,0.7635999411921652,http://p.rfihub.com/,1.1569696078669172,http://pixel.invitemedia.com/,1.752984254343813,http://pixel.rubiconproject.com/,2.089197644664114,http://sync.mathtag.com/,1.752984254343813,http://tags.bluekai.com/,1.1569696078669172,http://tap.rubiconproject.com/,1.752984254343813,http://um.simpli.fi/,1.752984254343813]],[http://view.atdmt.com/,[http://cdn.atdmt.com/,0.7102597332839485,http://cdn.doubleverify.com/,0.12674680594291293,http://choices.truste.com/,0.3970490994717991,http://swa.demdex.net/,0.1254072681434205,https://choices.truste.com/,0.053519529531151445]],[http://voices.yahoo.com/,[http://ad.yieldmanager.com/,2.262398482101845,http://analytics.query.yahoo.com/,1.752984254343813,http://csc.beap.bc.yahoo.com/,2.262398482101845,http://d.yimg.com/,2.517105595980861,http://l.yimg.com/,2.771812709859876,http://scripts.chitika.net/,2.007691368222829,http://static.adsafeprotected.com/,1.752984254343813,http://us.adserver.yahoo.com/,3.281226937617907,http://us.bc.yahoo.com/,2.262398482101845,http://voices.yahoo.com/,2.007691368222829]],[http://widgets.outbrain.com/,[http://b.scorecardresearch.com/,0.5963117590539219]],[http://windows.microsoft.com/,[http://js.microsoft.com/,0.051443838678837346,http://m.webtrends.com/,0.051443838678837346,http://res1.windows.microsoft.com/,0.08619398136255531,http://res2.windows.microsoft.com/,0.08619398136255531,http://windows.microsoft.com/,0.05723552912612365]],[http://www.addresses.com/,[http://d2fecy32wxp83c.cloudfront.net/,0.0594895358301776,http://ecn.dev.virtualearth.net/,0.08682256580620507,http://ecn.t2.tiles.virtualearth.net/,0.05402292983497205,http://ecn.t3.tiles.virtualearth.net/,0.06495614182538301]],[http://www.btobonline.com/,[http://ib.adnxs.com/,0.05402292983497205,http://www.btobonline.com/,0.17428826172949333,https://www.facebook.com/,0.05402292983497205]],[http://www.cio.com/,[http://a0.twimg.com/,0.08040229091526895,http://idg-cio.disqus.com/,0.05723552912612365,http://mediacdn.disqus.com/,0.05723552912612365,http://www.cio.com/,0.4510704795415931,https://plusone.google.com/,0.05723552912612365]],[http://www.doctoroz.com/,[http://ping.chartbeat.net/,1.5172568052602977,http://s.doctoroz.com/,5.40169358686431,http://static.ak.facebook.com/,1.7377129222639303,http://static.chartbeat.com/,1.5172568052602977,http://static.doctoroz.com/,19.841569250602262,http://themes.googleusercontent.com/,2.6195373902784627,http://widgets.outbrain.com/,2.6195373902784627,http://www.facebook.com/,1.5172568052602977,https://s-static.ak.facebook.com/,1.5172568052602977,https://www.facebook.com/,1.7377129222639303]],[http://www.dummies.com/,[http://ct1.addthis.com/,0.07461060046798262,http://media.wiley.com/,0.3062782183594353,http://mediacdn.disqus.com/,0.05723552912612365,http://s0.2mdn.net/,0.051443838678837346,https://plusone.google.com/,0.05723552912612365]],[http://www.everestjs.net/,[http://tag.admeld.com/,0.3728378736548665,http://www.everestjs.net/,0.3728378736548665]],[http://www.facebook.com/,[http://static.ak.fbcdn.net/,0.3669842410420373]],[http://www.google.com/,[http://ssl.gstatic.com/,0.1173370470513878,http://www.google.com/,0.2364253933124978,https://www.google.com/,0.3988458920458748]],[http://www.goyachats.com/,[http://ajax.googleapis.com/,1.2395173340042034,http://www.adobe.com/,1.2395173340042034,http://www.google-analytics.com/,1.4196181432184896,http://www.goyachats.com/,9.704255367075643,http://wwwimages.adobe.com/,1.2395173340042034]],[http://www.infoworld.com/,[http://ad.doubleclick.net/,0.06881891002069625,http://ak1.abmr.net/,0.051443838678837346,http://p.acxiom-online.com/,0.051443838678837346,http://rc.rlcdn.com/,0.051443838678837346,http://www.infoworld.com/,0.2831114565702904]],[http://www.kadquest.com/,[http://www.kadquest.com/,0.06881891002069625]],[http://www.knowledgevaultx.com/,[http://edge.sharethis.com/,0.05723552912612365,http://platform.twitter.com/,0.5138524039901776,http://seg.sharethis.com/,0.1607909543236031,http://wd.sharethis.com/,0.06302721957341005,http://www.knowledgevaultx.com/,0.4535029895294536,http://www.linkedin.com/,0.13959336728653518,https://platform.twitter.com/,0.15314592293318505]],[http://www.pedowitzgroup.com/,[http://ib.adnxs.com/,0.05402292983497205,http://search.twitter.com/,0.06495614182538301,http://www.pedowitzgroup.com/,0.11415559578223257]],[http://www.taipei-101.com.tw/,[http://www.taipei-101.com.tw/,0.20471179675498957]],[http://www.youtube.com/,[http://csi.gstatic.com/,1.2395173340042034,http://r3—sn-jvhj5nu-nwjl.c.youtube.com/,2.493018966135634,http://r3—sn-o097zued.c.youtube.com/,1.2935475767684885,http://r9—sn-nwj7kner.c.youtube.com/,1.779819761647061,http://s.youtube.com/,1.5348826611156317,http://s.ytimg.com/,2.6623137267970622,http://www.youtube.com/,2.4894169499513477,https://clients1.google.com/,1.1782830588713462,https://lh4.googleusercontent.com/,1.1746810426870604,https://plus.google.com/,1.1170487837384881]],[http://www1.salary.com/,[http://ar.voicefive.com/,0.17898599966038006,http://connect.facebook.net/,0.17898599966038006,http://es.afy11.net/,0.17898599966038006,http://platform.twitter.com/,0.2049925124315464,http://static.ak.facebook.com/,0.17898599966038006,http://www.salary.com/,1.435100566507713,http://www1.salary.com/,1.5380863570815302,https://apis.google.com/,0.2049925124315464,https://plusone.google.com/,0.17898599966038006,https://s-static.ak.facebook.com/,0.17898599966038006]],[http://www2.delta-search.com/,[http://b.scorecardresearch.com/,2.6037003999999997,http://pagead2.googlesyndication.com/,2.2733802,http://partner.googleadservices.com/,2.2733802,http://www.google-analytics.com/,2.6037003999999997,http://www.googletagservices.com/,2.2733802,http://www2.delta-search.com/,2.6037003999999997]],[https://accounts.google.com/,[https://accounts.google.com/,0.5399337506922309,https://accounts.youtube.com/,0.10062271551479751,https://ssl.gstatic.com/,0.5988919802521244]],[https://apis.google.com/,[https://apis.google.com/,0.09435237495764333]],[https://do.com/,[https://d1vk1po2s93fx0.cloudfront.net/,0.11086648423717017]],[https://email01.secureserver.net/,[https://email01.secureserver.net/,0.4555157704908735,https://imagesak.secureserver.net/,0.1899544502458513,https://img3.wsimg.com/,0.0731074693380415]],[https://login.secureserver.net/,[https://login.secureserver.net/,0.12986111021024574]],[https://mail.google.com/,[https://apis.google.com/,0.10497482776744418,https://chatenabled.mail.google.com/,0.0731074693380415,https://clients2.google.com/,0.0731074693380415,https://lh5.googleusercontent.com/,0.0731074693380415,https://mail-attachment.googleusercontent.com/,0.0731074693380415,https://mail.google.com/,0.6254750154476879,https://pagead2.googleadservices.com/,0.0731074693380415,https://plus.google.com/,0.11559728057724518,https://ssl.gstatic.com/,0.28555652553405986,https://www.google.com/,0.0731074693380415]],[https://plus.google.com/,[https://apis.google.com/,0.4193661733159466,https://plus.google.com/,0.3756115175798035]],[https://plusone.google.com/,[https://plusone.google.com/,0.18730808374715327,https://ssl.gstatic.com/,0.17898599966038006]],[https://twitter.com/,[https://abs.twimg.com/,0.2616854833920826,https://o.twimg.com/,0.12677583904575063,https://platform.twitter.com/,0.05588145536885069,https://si0.twimg.com/,0.14497310602924585,https://ssl.google-analytics.com/,0.15195133654528822,https://twitter.com/,0.12370479092617569]],[https://www.google.com/,[https://apis.google.com/,0.2168561134307218,https://encrypted-tbn0.gstatic.com/,0.16185040589450003,https://lh4.googleusercontent.com/,0.19863454455518198,https://plus.google.com/,0.694394375704277,https://ssl.gstatic.com/,0.2951937977885423,https://www.google.com/,3.279683606036538]],[https://www.surveymonkey.com/,[https://secure.surveymonkey.com/,0.051443838678837346]]],startup_list:[1,http://b.scorecardresearch.com/,http://cdn2sitescout.edgesuite.net/,http://mf.sitescout.com/,http://mfcdn.s3.amazonaws.com/,http://pagead2.googlesyndication.com/,http://partner.googleadservices.com/,http://pubads.g.doubleclick.net/,http://www.google-analytics.com/,http://www.googletagservices.com/,http://www2.delta-search.com/]},download:{directory_upgrade:true,extensions_to_open:,prompt_for_download:true
},extensions:{autoupdate:{last_check:13012104525987250,next_check:130123483661401
25},blacklistupdate:{lastpingday:13012038022982250,version:0.0.0.147},chrome_url_
overrides:{bookmarks:[chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html]},last_chrome_version:26.0.1410.64,settings:{aakhlmakppmkkmfkoibponkmm
pgpmjgl:{blacklist:true},aandpgohbohmlknpjbblpmoladhoochg:{blacklist:true},aangdc
fipmfploijfkoonkajgpdkfmbm:{blacklist:true},abciiempgohamehppammbkhkicmkgkob:{bla
cklist:true},abfclfmhaemoockhhinpplncjehfpdbd:{blacklist:true},abidmaanmbfeddegma
pgpjhdmgjaloen:{blacklist:true},acchaoeabgiclhngknbkegekbfphgndl:{blacklist:true}
,acmpfcamncegnhjdeiodgilikjafcamg:{blacklist:true},acomnmbomlajgjbcijkflekoojdfcl
dj:{blacklist:true},aconhjfogglfnkjhkjipaifepjklolog:{blacklist:true},aebfkgcamgn
imcbnbiopgdakknjgggnm:{blacklist:true},aemcjbfajnnmhblifaejadoecfoaebld:{blacklis
t:true},afenhmponmfmdmbmccbmglppcmjhmhmh:{blacklist:true},aglmapjbjphdidmnileogpj
kgpdoliep:{blacklist:true},agmhonoepgcnakccfpidhjehlocaeaaj:{blacklist:true},agod
bcffjkjcnceklapkjfcmkfepmbgm:{blacklist:true},ahfgeienlihckogmohjhadlkjgocpleb:{a
ctive_permissions:{api:[appNotifications,management,webstorePrivate]},app_launche
r_ordinal:n,creation_flags:1,from_bookmark:false,from_webstore:false,install_time
:13006296702500000,location:5,manifest:{app:{launch:{web_url:https://chrome.google.com/webstore},urls:[https://chrome.google.com/webstore]},description:Web Store,icons:{128:webstore_icon_128.png,16:webstore_icon_16.png},key:MIGfMA0GCSqG
SIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB,name
:Chrome Web Store,permissions:[appNotifications,webstorePrivate,management],version:0.1},pag
e_ordinal:n,path:C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.97\\resources\\web_store,was_installed_by_default:false},ahjfgnikolodijnpakeknpilnemojlhc:
{blacklist:true},aieglpnmmhleoenpbmfaffppfomgjmba:{blacklist:true},aieihijcjcccdi
epockaiekhpflicdii:{blacklist:true},aifmjmboebdkdelpjenakhaodgneempp:{blacklist:t
rue},ajlkjjdbgcjdiklbcomhnfghjigfccoh:{blacklist:true},ajneiojjdhceikkgmhnjhgaacp
fhldpi:{blacklist:true},akadaakimgegecohlifeejdnnjbnobop:{blacklist:true},akbdoji
ajlefghcdclgkgmbbljamgehd:{blacklist:true},alcbnnpmipohgdllkkglhkbncijplago:{blac
klist:true},aldalonecchncedclgcndcndgilaclnk:{blacklist:true},alfahpoknocfdebmicl
onikapcnljlob:{blacklist:true},aljdncnajablgppdcfbehhmidlmbndda:{blacklist:true},
amfgdngndpfldigimkcindjalokfnmem:{blacklist:true},amoobcjlpgloocplpikcldcpjjdnoei
i:{blacklist:true},anmjpohfnlopdfaojooicpemopnliimn:{blacklist:true},aofechiiopol
negcjcddgedjabmkemhf:{blacklist:true},aojicjocmihiopalnhjikigammkhgckb:{blacklist
:true},aokenbhllkgpooaacldiamnpmmgkjblo:{blacklist:true},apdebchnkegjokdjplmfmepc
dgneemhe:{blacklist:true},apdfllckaahabafndbhieahigkjlhalf:{active_permissions:{a
pi:[background,clipboardRead,clipboardWrite,notifications,unlimitedStorage]},app_
launcher_ordinal:y,creation_flags:1,from_bookmark:false,from_webstore:false,insta
ll_time:13012095784749000,lastpingday:13012038022983250,location:3,manifest:{app:
{launch:{web_url:https://drive.google.com/?usp=chrome_app},urls:[http://docs.google.com/,http://drive.google.com/,https://docs.google.com/,https://drive.google.com/]},background:{allow_js_access:false},current_locale:en_US,default_locale:en_US,
description:Google Drive: create, share and keep all your stuff in one place.,icons:{128:128.png},key:MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIl5KlKwL2T
SkntkpY3naLLz5jsN0YwjhZyObcTOK6Nda4Ie21KRqZau9lx5SHcLh7pE2/S9OiArb+na2dn7YK5EvH+aRXS1ec3uxVlBhqLdnleVgwgwlg5fH95I52IeHcoeK6pR4hW/Nv39GNlI/Uqk6O6GBCCsAxYrdxww9BiQIDAQAB,manifest_version:2,name:Google Drive,offline_enabled:true,options_page:https://drive.google.com/settings,permissions:[background,clipboardRead,clipboardWrite,notifications,unli
mitedStorage],update_url:http://clients2.google.com/service/update2/crx,version:6.3},page_ordinal:n,path:apdfllckaahabafndbhieahigkjlhalf\\6.3_0,state:1,was_installed_by_default:false},apdmgffkfhjfeejmbjidennfjdkmm
mbl:{blacklist:true},aphncaagnlabkeipnbbicmcahnamibgb:{blacklist:true},bccdgfmbcj
kfkinkkagaflgdaoaamogo:{blacklist:true},bcddmcejgphfgofbpoocakaeapfomlek:{blackli
st:true},bckhfnghfdponbaldednpnljadgfjecj:{blacklist:true},bdgijcibmhjjccgbdohofn
cdjcophknj:{blacklist:true},benclngoadbppljglhphhnfknoppmjoa:{blacklist:true},bhd
kpmneahdelgdgfhddianklldfoell:{blacklist:true},bhkdpodceenlocjmmgodpbbpkafkpljc:{
blacklist:true},bhmahaiplmeodpakkcchmolaihbhkpdl:{blacklist:true},biiponhbbifajap
mbggbgaepiedinifm:{blacklist:true},bilgncckogfgfipdlejkffnbkgjkmflh:{blacklist:tr
ue},bioeopenmokdgbekbgpgnacecjmpckbb:{blacklist:true},bjihddggcgnblgojnmhpnngonof
bnkaj:{blacklist:true},bkhafliomebnpccanacmlfaemgfiofko:{blacklist:true},bkkchglo
lnigbfncnbnnbhhempjkdpkf:{blacklist:true},bkplhcigeaiiliajeehehiikokgocbhb:{black
list:true},bldgnkigdcpgnbfehgbameigoohecdfl:{blacklist:true},blpcfgokakmgnkcojhhk
bfbldkacnbeo:{ack_external:true,active_permissions:{api:[appNotifications]},app_l
auncher_ordinal:t,creation_flags:153,exclude_from_sideload_wipeout:true,from_book
mark:true,from_webstore:true,granted_permissions:{api:[appNotifications]},install
_time:13011834326661000,lastpingday:13012038022983250,location:1,manifest:{app:{l
aunch:{container:tab,web_url:http://www.youtube.com/?feature=ytca},web_content:{enabled:true,origin:http://www.youtube.com}},current_locale:en_US,default_locale:en,description:The world's most popular online video community.,icons:{128:128.png},key:MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDC/HotmFlyuz5FaHaIbVBhhL4BwbcUtsfWwzgUMpZt5ZsLB2nW/Y5xwNkkPANYGdVsJkT2GPpRRIKBO5QiJ7jPMa3EZtcZHpkygBlQLSjMhdrAKevpKgIl6YTkwzNvExY6r
zVDzeE9zqnIs33eppY4S5QcoALMxuSWlMKqgFQjHQIDAQAB,manifest_version:2,name:YouTube,p
ermissions:[appNotifications],update_url:http://clients2.google.com/service/update2/crx,version:4.2.6},page_ordinal:n,path:blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0,state:1,was_installed_by_default:true},bmjhmeeepkkbmjdajachipfgihmp
okpd:{blacklist:true},bndahdijlcnncjbpammoedeapmlobllc:{blacklist:true},bnffnggkp
hadlnoopcoakdnkellnifjp:{blacklist:true},boaoagnmpennjoigkkmnjhecapibhfko:{blackl
ist:true},boclfockfmgcppbajihcgajhpggaakgl:{blacklist:true},bokkificjhapflinbdeje
gngffgkcgfe:{blacklist:true},bpfadpmhabiajakhgnaipdplkcjaklnj:{blacklist:true},ca
nhmdgddepdjikkjhpmhcfdkkjdbppi:{blacklist:true},caphkimknlmnhpjoneddiaakmcaajagb:
{blacklist:true},cbbbpmlnlpnjojeplppgeilanlihoojg:{blacklist:true},cbbjhegipokkof
hhicbckicchjpcpeni:{blacklist:true},cbhhdkemlehgodemcigfabmcdnohhhef:{blacklist:t
rue},cbjlfaogacjpkplebfbijaakaifoflno:{blacklist:true},cconecmbohgadkjghlfbchmjpg
bobkaf:{blacklist:true},cdogaeccgljmkecjmoedambgiekkllij:{blacklist:true},cedclbo
kcakighlpbnbhfjffdjeihfdp:{blacklist:true},cekdjgnecpoooikhmceokdhojckkkhmh:{blac
klist:true},cepfogmgfkddnllaopgknbdfkceejmhk:{blacklist:true},cfbdodejdeejbkffcmi
aknpmojjeibpn:{blacklist:true},cfdedhfmaeiheeklgodcmcgfpedooocj:{blacklist:true},
cfnfobbpdaccoljfahpmfjdmbfmmkeof:{blacklist:true},cfogpbanfnocakdckmgafapdlmclpil
n:{blacklist:true},cgnegjfmdfenjojhjffejinpnpoglmlh:{blacklist:true},cgnkbnaiipmf
bakpmhllalggoepniemh:{blacklist:true},chhniecmnighakmlnhkifeogjddhoajn:{blacklist
:true},chlplighidmhpgmidehfmjfdlahakjog:{blacklist:true},cidnoinjdbalndcidafahfno
eehfblfl:{blacklist:true},cihlkpohodpdkdnfalhdkhhlhmhffmbe:{blacklist:true},cjhkl
hdjonhcohlacgggcbklpnldleck:{blacklist:true},cjohbbapkbkkhpohinffggbphnhoblea:{bl
acklist:true},ckckpgefkpjfopjppjfcikppehdhceah:{blacklist:true},ckphhghhpjbfddcgk
pfbelfeojcciglo:{blacklist:true},clapnamcglekekmamicmbahkghdcjaeh:{blacklist:true
},clfhanhcjmgjnbpjfopldmnabimhmcmp:{blacklist:true},cmjphjljejnfgdbkdgdlclaabimpk
nna:{blacklist:true},cmlokmkdolieoaoddlfhaidnlmiadhik:{blacklist:true},cmnfphnmpe
deolmelllmgkghmjcnlajp:{blacklist:true},cnimdnlablahacgompaahbgohcokcclp:{blackli
st:true},cniodhfhdiidogekcjkplecimemfocpn:{blacklist:true},coajchbkdbfhmhbgcjepio
fllfjjcpfp:{blacklist:true},coobgpohoikkiipiblmjeljniedjpjpf:{ack_external:true,a
ctive_bit:false,app_launcher_ordinal:x,creation_flags:25,exclude_from_sideload_wi
peout:true,from_bookmark:true,from_webstore:true,install_time:13010007215363875,l
ast_active_pingday:13007631610432125,lastpingday:13012038022983250,location:1,man
ifest:{app:{launch:{web_url:http://www.google.com/webhp?source=search_app},urls:[*://www.google.com/search,*://www.google.com/webhp,*://www.google.com/imgres]},current_locale:en_US,default_locale:en,description:The fastest way to search the web.,icons:{128:128.png,16:16.png,32:32.png,48:48.png},key:MIGfMA0GCSqGSIb3DQEBA
QUAA4GNADCBiQKBgQDIiso3Loy5VJHL40shGhUl6it5ZG55XB9q/2EX6aa88jAxwPutbCgy5d9bm1YmBzLfSgpX4xcpgTU08ydWbd7b50fbkLsqWl1mRhxoqnN01kuNfv9Hb
z9dWWYd+O4ZfD3L2XZs0wQqo0y6k64n+qeLkUMd1MIhf6MR8Xz1SOA8pwIDAQAB,manifest_version:
2,name:Google Search,update_url:http://clients2.google.com/service/update2/crx,version:0.0.0.20},page_ordinal:n,path:coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0,state:1,was_installed_by_default:false},copjbedljgpkaakkmbhgkpoaad
eahido:{blacklist:true},cpiiakoibaohkfoaijaigdnocfolnmll:{blacklist:true},dadcalg
appognjbjpalfophhcfakoeac:{blacklist:true},danapgfidmepmcfbjjacceiaiiioieio:{blac
klist:true},dbanhghadfmjndnjmmejdgfdmgidlbpm:{blacklist:true},dbiblcmlcgdjjbdpbmb
cpineegngkiip:{blacklist:true},dbmdicehacbaohlockjgdglcobimmjkh:{blacklist:true},
dcfefnkefopibnlcjhjcfegckhanekld:{blacklist:true},dcpjokbfgfnbaekphjgehhjaokkcifb
j:{blacklist:true},dejippphmhbpgckbhdidnjmdcpfccbaj:{blacklist:true},deocpjmfifpl
hepinpkmpinpnbiemfje:{blacklist:true},deonbedlmakdddidplniclflladdjoep:{blacklist
:true},dfafokiagoiocidlpglcanjkcdbdnioi:{blacklist:true},dfjhgoeofgmepmcngkhnaiph
bhdbonhp:{blacklist:true},dfoegfajplmijblljfancdapbdaopebb:{blacklist:true},dgaeh
aeahdegbdlenicbmkbakhdgoeml:{blacklist:true},dgcfmgdfbfbgcpbendbhbkfjppboebed:{bl
acklist:true},dgkemngdheppgohkjjelnkjmdeimmfml:{blacklist:true},dhclobcklknojlioj
kkclgjndemadnig:{blacklist:true},dhdepfaagokllfmhfbcfmocaeigmoebo:{blacklist:true
},dhmghpedmigfknfpolfmkihcaeiccjgf:{blacklist:true},dibljdngacjhpccjckmlmeklpgjei
njd:{blacklist:true},digmihafmlfkgdbjjdgbcojghcgcoeoa:{blacklist:true},diinokaoic
gobepmadnmedlhdfnpehcj:{blacklist:true},dinhjcapnfbffhiihdlnbdfjdjjfhcbk:{blackli
st:true},djnahdkbfgnhgpakidinfonfcjbagkgp:{blacklist:true},djpnjilhooodipllnjedje
iabkboakok:{blacklist:true},dkhkecikbdfpoiopnnpoeglbdphgflmf:{blacklist:true},dkp
dmjefniplpkalcgnainfmmclllpnn:{blacklist:true},dlobhinihbmedmheccecfnkcadpehmbf:{
blacklist:true},dlopielgodpjhkbapdlbbicpiefpaack:{blacklist:true},dmabikjmolgegja
jdhmgpmgffajlmmkb:{blacklist:true},dmhgenmamfphbclmhdgmffajkfommkom:{blacklist:tr
ue},dmhjdbigobajgnfoabodjgmcdgoeoljm:{blacklist:true},dmkdhgkknhnfpdjeicefnpmhcpb
imden:{blacklist:true},dnemhlkdpajbbniphgkgceplmnkfnhfo:{blacklist:true},doneghbo
glgnflpdicnkaojmmljgejkj:{blacklist:true},dpaphgcjeeochbiafgbochohgmpcmlbj:{black
list:true},dpcdiabehkofdddfhdmkgkndjilfoppd:{blacklist:true},dpfanoongnoofcdhgijj
djmbnfekdejj:{blacklist:true},dpgenihgggagjjggfocjceeobjkadcbc:{blacklist:true},d
pmloehicimdjkibmobhmpgdndgbcced:{blacklist:true},eagmciolnojfofmggkffclbonhleeank
:{blacklist:true},ebdcdchjcndpjhehacedepnggfdbfkpn:{blacklist:true},ebhdpnhjbfkch
famjcpebpeddhhicnab:{blacklist:true},echjhfifjidfhoappglfmoffcpmpkigb:{blacklist:
true},echngajnlpjeacbanjejlhcajjfoedcc:{blacklist:true},ecinfbhalenfhdhnljmkglajf
jjfehoj:{blacklist:true},edmnikahahfkfilbbjbdoiabnghbkmjc:{blacklist:true},eemcgd
kfndhakfknompkggombfjjjeno:{active_permissions:{api:[bookmarks,bookmarkManagerPri
vate,metricsPrivate,systemPrivate,tabs],explicit_host:[chrome://favicon/*,chrome://resources/*]},creation_flags:1,from_bookmark:false,from_webstore:false,install_time:130062
96702500000,location:5,manifest:{chrome_url_overrides:{bookmarks:main.html},conte
nt_security_policy:object-src 'none'; script-src chrome://resources 'self',description:Bookmark Manager,incognito:split,key:MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+eN9jzaz
WF/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB,manifest_
version:2,name:Bookmark Manager,permissions:[bookmarks,bookmarkManagerPrivate,systemPrivate,tabs,chrome://favicon/,chrome://resources/],version:0.1},path:C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.97\\resources\\bookmark_manager,was_installed_by_default:false},efbeabpbbkahnnjalakldjfhlj
boclkf:{blacklist:true},efcnjdcimjmggfdkahncpoikhehcfgnh:{blacklist:true},efhjelc
ghjkfigiagdfbfilndaffpmdj:{blacklist:true},efnaljpgehfilpmkhobibbjceeeondmn:{blac
klist:true},efonemhbokfedckpfpohpmcamfihnnlm:{blacklist:true},egljdhfnbjahogjahni
gfnbpidlmdagi:{blacklist:true},ehgoiaffgjoinpkllmmnikghgpghnabc:{blacklist:true},
ehmjnpjodmgeocfphkjjnheiheehcoid:{blacklist:true},ehomcoocpagnlcakcbecdaknmacmedl
d:{blacklist:true},eiflkkehgogioennialfbilppmegcpoa:{blacklist:true},eihjeehdobnp
konebmpanonopghepfle:{blacklist:true},eijbdinddjecmebnlienfoijpjjobkjh:{blacklist
:true},einmhcleeonenkkldjlmhhcmgolhblhh:{blacklist:true},ejakhnjbomgngodiidgbkapj
gbdckhnh:{blacklist:true},ejijgghlncnaphklndknkbkclebfboca:{blacklist:true},ejlek
amipdcfcfpgfepjmklllbpeecaj:{blacklist:true},ekikoahmboikmmclhnijlmldpmleahnh:{bl
acklist:true},elcaigjcaijbfpjngaekbblphmfjdhfo:{blacklist:true},emcdpbapjmnjgoann
clkongdfboaabho:{blacklist:true},ennkphjdgehloodpbhlhldgbnhmacadg:{active_permiss
ions:{api:[app.currentWindowInternal,app.runtime,app.window],explicit_host:[chrom
e://settings-frame/*]},app_launcher_ordinal:y,creation_flags:1,from_bookmark:false,from_webstore:fa
lse,install_time:13006296702500000,location:5,manifest:{app:{background:{scripts:
[settings_app.js]}},description:Settings,display_in_launcher:true,display_in_new_
tab_page:false,icons:{128:settings_app_icon_128.png,16:settings_app_icon_16.png,3
2:settings_app_icon_32.png,48:settings_app_icon_48.png},key:MIGfMA0GCSqGSIb3DQEBA
QUAA4GNADCBiQKBgQDoVDPGX6fvKPVVgc+gnkYlGqHuuapgFDyKhsy4z7UzRLO/95zXPv8h8e5EacqbAQJLUbP6DERH5jowyNEYVxq9GJyntJMwP1ejvoz/52hnY3CCGGCmttmKzzpp5zwLuq3iZf8bslwywfflNUYtaCFSDa0TtrBZz0aOPrAAd/AhNwIDAQAB,manifest_version:2,name:Settings,permissions:[chrome://settings-frame/],version:0.1},page_ordinal:n,path:C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.97\\resources\\settings_app,running:false,was_installed_by_default:false},eofejpelggimkode
ojpeojnbijgiglgh:{blacklist:true},eopmhecjnginkckggjmhombbopmkjpam:{blacklist:tru
e},epbmnbdplhcomkedpjfceakddnbgfjmf:{blacklist:true},fafoohpbicgbcejffcplajonhhoo
ddle:{blacklist:true},fakdahljemjliginkgdehfoocmjgloam:{blacklist:true},fbhiehmng
ojjcmljddjmgpmcockbccmo:{blacklist:true},fbjjhbijaiopkcdolheliknnjlkaekeb:{blackl
ist:true},fbmgoajoadbjhoachcdiplofcblaihdc:{blacklist:true},fbmimoidopbghbcmdmpkj
affffmcbmbg:{blacklist:true},fcfepemfihgibdacjlnlecebknaaepmj:{blacklist:true},fc
ijaeofmfihkldhkofkjoibdoeoflha:{blacklist:true},fclheclkknbgfndeahkfdomollhmfkcn:
{blacklist:true},febmhchodibcbchcofonaamfglbjhggg:{blacklist:true},fekjidlkjnecep
nlmdmjohmgpkdlbegi:{blacklist:true},ffgfbfakpcnngelphjnppokmoicdollk:{blacklist:t
rue},fhlkffpjoajppmhcakbkjndbjfljccpi:{blacklist:true},fhpclkemjlhmbfbjakbmdjihoc
inkmim:{blacklist:true},fiapkdjniadkodmdibdnchoifkpfoiid:{blacklist:true},fibgplo
apkhokkbncddlkcmbmiengcfp:{blacklist:true},fihepkmlkmciffbhijldnpmifhbkiinp:{blac
klist:true},fiiblakkkkgeljngobmpeljjapemenhi:{blacklist:true},fjhfnfakmfcejgmfkmn
apemgblmehppf:{blacklist:true},fjjeecfjmgfnleghoellhldedkaocjfc:{blacklist:true},
fjpofaghniailakahnhkjjfbfonpfglo:{blacklist:true},flalbhkmnijcnpialgakicllnabckmh
i:{blacklist:true},fleljamdchegbjeiipbnmiebnhgheeld:{blacklist:true},flmmgcfcpbfd
denepkfmgfpbaceolcoe:{blacklist:true},fmcccidacjgnfiafddkngmeolkoiihil:{blacklist
:true},fmonlemffgbabjifjfaoamdflijecdbk:{blacklist:true},fngolbdmkneakeaoiieafkil
nogbocda:{blacklist:true},fnhcgnmfccojojojacgeiaaeacefdohb:{blacklist:true},fnihp
enllbnplcglabekelhhblcdndbb:{blacklist:true},fnkaadkanmfgpfbmdcllhjdgmdbgljpi:{bl
acklist:true},fnnmbghphdnmmjdapccfobgjemjadeli:{blacklist:true},fnoadkjdjfgafomgm
ablhmffooijcfbn:{blacklist:true},foenbafkkmajnmfnlcmejonkfaipdmme:{blacklist:true
},folhciaicehdnoalhbkbgkakfcockopc:{blacklist:true},fomljmklmcefndkgpakgifbiiidgb
jej:{blacklist:true},fommcgokigkhmnhlhlkckfjhefnmfohd:{blacklist:true},fopgndklnk
ecillfbdmfknhmadmenikm:{blacklist:true},fpbippbofbmgmbojjmgfcifpmdaelcmd:{blackli
st:true},fpbkafpphnhlpakobppekmkebmbhkoco:{blacklist:true},fpjdackpllilinpkgmhkpi
dkanmccblc:{blacklist:true},fpmajanjndhgpifbcbnklbiehgnpkgmf:{blacklist:true},fpo
ajjnnpmledpmohlgpgbmlhbgkgahg:{blacklist:true},fpokembamndopkflopmplkklbdngnknd:{
blacklist:true},gagalgomhifgcmeciklindhpaihmecgi:{blacklist:true},gaicmfjflflabag
obdiodejfpjikheeo:{blacklist:true},gandihaiobadcggbfkhpbkocmiemjlnf:{blacklist:tr
ue},gbenikfjhilhpgagllmfgggdjaflbmbi:{blacklist:true},gchbiabnbdikkgfhnkclecjncoj
nkmhb:{blacklist:true},gdggdkkjecogagaffaemnbfmllcoihjp:{blacklist:true},gdlgbpbm
iiagaikjbednkikinokbkbcb:{blacklist:true},geggofhlfbcmanadhknllmlajiafopoh:{black
list:true},gekkhpjigmckhgmgngadbeknekgpgolb:{blacklist:true},gfjfhihpkmehdmblhfai
kkipeplpdcla:{blacklist:true},gfmmoiakbmdohkgeoekiokjgljcminig:{blacklist:true},g
gkpicnfnljflddbdoeeaajjgepapcbf:{blacklist:true},ghgphbmpcfgkfneodjpbdanmdoemklio
:{blacklist:true},ghmaokcegalalefnhlfcnjhnpdbanjkj:{blacklist:true},gifglngcdbggm
lgkcombebegdaoknkho:{blacklist:true},gjkbghdignnlcknknflbigpammebiolo:{blacklist:
true},gjmhdmobkhfhkpfmfegnkkimlamjdldi:{blacklist:true},gkcfodgjdcijjlliehfhgohlk
emcbobl:{blacklist:true},gkhbgnodbilglgholifcjdblbgdaieah:{blacklist:true},gkjecc
pmibljcfpfapfljciimedljpnm:{blacklist:true},gkjmgdpdndoaiholejnmdbbpdaafahmm:{bla
cklist:true},gklphmokmaaepjgandocpneomjlidjag:{blacklist:true},glhhlafadlhkgbklgb
jnmblfhnkfknbm:{blacklist:true},gmghjgfdialcnhadahmjefeflgnhcjeb:{blacklist:true}
,gnapdhmknipknfmhhnhdmhakdfhgeing:{blacklist:true},gncfgndgeoddelbfhlndhljnecoedn
aa:{blacklist:true},gngfmjidncdccdlfjcjbnngeaaclfgpl:{blacklist:true},gngmkbiihfl
pghldjnbpemaicedhdddk:{blacklist:true},gobjcjhhebpjbmjdgmejhebbleadnceo:{blacklis
t:true},goedioiidkokkbobdnopnlnaaalniegm:{blacklist:true},gomkbnfeifchddfokcicibj
nlgbolhol:{blacklist:true},gompblemgafijijmlgbaepcijfgfgljf:{blacklist:true},gpdc
odmabpgmncbkhpipakhehepmpopk:{blacklist:true},gpgehbjbkfhngdlfpfeokjgbkmmokjhe:{b
lacklist:true},gplgjmecjpbfcdikpbicknafcnfcidek:{blacklist:true},hbaajkahagmlkdek
mbdabikbopdgpaac:{blacklist:true},hbdhabpmbbanaopgkbaondabkkepjfaf:{blacklist:tru
e},hbmlheccjkodhfejcmblndjodllmnlnl:{blacklist:true},hcapokajkngndbglnfglpfdpoeid
mpha:{blacklist:true},hcpndbchnlgojmnijaldkicigmihmdca:{blacklist:true},hdijkiond
gomjpehfhopomicjbiodmcm:{blacklist:true},hdnbmmfjbblajkjkcaeofolgfnljpnim:{blackl
ist:true},hecijapnccjhonbmacmkmffooodfokoo:{blacklist:true},hefmoncdemhjembgbnkgg
lhlookbipdc:{blacklist:true},hfcgbiofoebieldldghfocjfnnajmpej:{blacklist:true},hf
jpjodbolkmheaehcnmfhjakjileoof:{blacklist:true},hfpfbhnmbbigpmoodjemilggabklpopj:
{blacklist:true},hgbaomphocgmdpmiohjclchaaljpaelp:{blacklist:true},hgboiaecclcbjp
hldpbgfgggcbihmnai:{blacklist:true},hgjgaeknhmidehalnmokomhpfhbfmpcm:{blacklist:t
rue},hhbihfbjoifhhebcnchglobmkmapgjkm:{blacklist:true},hhfffemhgkginfafaoapljdllo
dppana:{blacklist:true},hhfiljkpjapjjphcocclhhaldpfkkjbi:{blacklist:true},hhjmkij
kgojfifipdgmiemghfikbohcm:{blacklist:true},hhlgbfcfbkhlmajakkcjippgpcmejkko:{blac
klist:true},hhommgjjeekpmpcbdmfnhpchijdkgaei:{blacklist:true},hilncbjbdpnfepdidfc
hmdclhpnlegpj:{blacklist:true},himgjpdejpikenoibmolgmfblolpahno:{blacklist:true},
hjkhligcnpfjhjlapmejaiaiigibofif:{blacklist:true},hjnigaibahdeadcdnpnommdehajodlh
c:{blacklist:true},hkbgccpdcpbdckohbknjlamamelcnlki:{blacklist:true},hkjcejgfmaan
pncnpoidgbhoikcaeepd:{blacklist:true},hkjfdgjkgpbbdmadbglcgljjjddkcdha:{blacklist
:true},hmmoglffhpmacaacfbbmbbkcbdkjphnc:{blacklist:true},hnbcdmfeoldeppcbnnjmjkdo
fohaljbn:{blacklist:true},hncomkjbbkchfjelocejkbbflmjhlhfp:{blacklist:true},hnipg
ljcblpgnnojcfldehpeknhakbgj:{blacklist:true},hnkcpoijaeegompjgbjjhkdmljldaccg:{bl
acklist:true},hnnebfeppcbhhbhiifeaajgcjnkljlld:{blacklist:true},hnonhhpgjnjcjfbkj
dpfbkfpaodcmncb:{blacklist:true},hnpgphegniamplngojaffllhjahkgbfl:{blacklist:true
},hpcdoodjfcmpcpkeendjnjkeinimhkih:{blacklist:true},hphibigbodkkohoglgfkddblldpfo
hjl:{blacklist:true},hpibmhghjndideebpackbdlpncgkcppp:{blacklist:true},iablioliie
lnhdianpbiijaoncbmfend:{blacklist:true},ibnhidklhjoopebonemhliklfbhndjjd:{blackli
st:true},iccblehkchfmjgfafjcpjlkjcponhdhl:{blacklist:true},icihfeaofpcfehanhbnjig
dlpfahjlee:{blacklist:true},idbdlnkdnaodonmgnimcfelpngbmcpjk:{blacklist:true},ied
ogbkombgmapifenoojnmpcnjighfm:{blacklist:true},iemfpgbdjfoihicbocpbjppipdbfimeh:{
blacklist:true},ifbkndkaolfbjjhnnhfmkbkoclpdkpli:{blacklist:true},ifeijfpkjckedpc
lgncedmgdiaoeahmk:{blacklist:true},igaajdmlejbjcbmpmnigopikfdaccdcm:{blacklist:tr
ue},igbaoknfddliiaoimhehfbkfekpmmfll:{blacklist:true},igghanohiioehififjoalfkdoic
afjof:{blacklist:true},iggjepemmdkieakihpomccndhdfcljdp:{blacklist:true},igjhgaoa
jaccjllfkfffboldnmncmhoh:{blacklist:true},igjjkeeamkpihpncmmbgdkhdnjpcfmfb:{ack_e
xternal:true},igkdgkdiiolilocklmiolkpoohacojop:{blacklist:true},ihnembcpodnfgkafm
iojebccomjekopm:{blacklist:true},iiiinekimabooeihccihfopoadcaaphn:{blacklist:true
},ijecjbcgpblkacpijljpaienknanaloa:{blacklist:true},ijenlpgidnapbndonoinbkhekgjon
ojg:{blacklist:true},ijjmbbddenkbenbcfldgghhjgjmcnioo:{blacklist:true},ilhjicgcgl
hjigdehkcehjdokmkahbjl:{blacklist:true},iljfgjkppapinhcgonhjnipfppfmfedh:{blackli
st:true},ilmknaabackgdbnkgbihgpgiopnlkjek:{blacklist:true},imfbomjbodpfgfhfahlgkk
cllmhbelhk:{blacklist:true},imkffpjpdngdkpgadcmnlkhhmhdocijn:{blacklist:true},inb
hlfpapeikbbgpfionabkigakepbbm:{blacklist:true},indfhnliadamglhalanplbajgenpjdml:{
blacklist:true},iobnpmeeecphddicmhhmdjbnlbdhjlne:{blacklist:true},iomejadoamfilgl
ofmeaffghddcgapmf:{blacklist:true},jabpdgllijbnknhkgjideeajfofafckp:{blacklist:tr
ue},jaejgaoiipdjjlbnapngknalafalbkej:{blacklist:true},jafnimahlamccccjbkhjjpeiipi
edpik:{blacklist:true},janhdpmhnighonkkbkdpnljcoenpfkbh:{blacklist:true},jaoiiahd
oamhobamdkmcmielddmnelko:{blacklist:true},jbfebbkjjmkcoldeaeelhpconkmgjhbg:{black
list:true},jbmbiepnidbnhbbfdbgioomdkgnbcacj:{blacklist:true},jbnafcjbcfgejacaanog
ofkkehcomamp:{blacklist:true},jcmipejepoimfflnoapdmkdephgjinck:{blacklist:true},j
ddbdddmbfencninofcgnodekclofpaj:{blacklist:true},jdiakcmbpmcnniggjcmcjknnklpdlogc
:{blacklist:true},jeehjhnmgohgpfpjneglogiholalkeip:{blacklist:true},jfalnphfjdoal
cdhlnhdpekbmmopkgkj:{blacklist:true},jfhmafmjfdblceidmfdmoihamolaaeco:{blacklist:
true},jfjagidcpadkoaonbogmbgfimmnefeie:{blacklist:true},jgdkappiifgomhgikcjbanhnm
lekpeje:{blacklist:true},jgmpapdckakiohhebmeoemejibommimi:{blacklist:true},jgoljh
cbgajhbhnchplgjdkknendhjnn:{blacklist:true},jhhabiomopkibeecgngiggmopkeofacl:{bla
cklist:true},jihmekmccilkocefjpejdebpapohlhjb:{blacklist:true},jiiccolbjkhpgockod
neljpejdeaaodf:{blacklist:true},jindbcpkhnnnjgcjgmkjedbibibiojjf:{blacklist:true}
,jiofcofpcbijcnlpekdkpmgjdppajbjb:{blacklist:true},jjahldbngdicbnejidklgkienpkdcp
ba:{blacklist:true},jjhackoobdibnnndjopfjldbjmohkpdk:{blacklist:true},jjnkfllhcgk
gnfbekpnmoikpfihpjfli:{blacklist:true},jkihmglffmfjedfbpbpdbbimcodjbmdh:{blacklis
t:true},jkkfmenldnihjkgnolhlakhaepomhoob:{blacklist:true},jkmhalpofmlfeglboejbchp
oijnkmcgh:{blacklist:true},jljfnkmkkdkppfndippkedacgfkafped:{blacklist:true},jmbk
hogpjgjpfjhpdikloblkbkljkgao:{blacklist:true},jmeanodbelbflfmnkfdjgpikmldgjjko:{b
lacklist:true},jmifipgdcllamghkhdplfjffkciekbgo:{blacklist:true},jnehbnhjkefckolj
kcmjfgkkeejhipgi:{blacklist:true},jokbafidjfknjbchmcakabjgdiiacgek:{blacklist:tru
e},jolgdmpdhloiienhblmiimamomhdphlk:{blacklist:true},jpehgolpfgnknboibogccapmdcad
jkbd:{blacklist:true},jpeijjbllejgmokmahkeommcodahoobm:{blacklist:true},jpgidahfc
giajlcbleeiaibpmmblcmnb:{blacklist:true},jpiedgcdjigcoeagojmlokclbljokpon:{blackl
ist:true},jpkdlckejfjidmplieobnhijmoiecbhl:{blacklist:true},kbipembkfhbdmkkkfbigm
ohilmknjnof:{blacklist:true},kbmkecfipofebpaikgifajmahdmadlnb:{blacklist:true},kc
anfkmhccbaheheaackijegkclkaeic:{blacklist:true},kcfnnanmpghdnoompcfclakpacapnfbn:
{blacklist:true},kcgplbmkmfcpngilmhjmebdgkkpbdemp:{blacklist:true},kcmnkpehkjhodo
odchlmgnicaifckhdj:{blacklist:true},kdchmeaiapjkejkcbeclgjklemecieeg:{blacklist:t
rue},kdcnnmifdmlmjffdgeieikcokcogpbej:{blacklist:true},kdfahjokahcbmecgaandpobmgi
iknagf:{blacklist:true},kdicckonacionpoompfoopggkgimjpcb:{blacklist:true},kdjhalk
lkkcmodeicjiaekcgifkcepaf:{blacklist:true},kdpcgcpfnkolljkhgdbbgimplfkhakec:{blac
klist:true},keknhkokjnjhgpcofobpcbelddppeolp:{blacklist:true},kelcbonmemlciepjdmf
cifnhloeammhj:{blacklist:true},kelljdoinjlkmkncffgadbebgpmlcang:{blacklist:true},
keoimpnicgbcjamfdgpcecihicnbmhej:{blacklist:true},kffhenjbibjnbnjhlkcdlmpeccpaohi
o:{blacklist:true},kfodnkhdfdgeaegehjjnkjkieloddelg:{blacklist:true},kgbkdabomfdp
foibliicpmibceaoohgh:{blacklist:true},kgbmmcjgkkecjcafigegjphkmkdpnggo:{blacklist
:true},kgdhnhadbnpeibkghaebmhmngobdafag:{blacklist:true},kgdkcodealpfjolmiagcogfb
gmaamegh:{blacklist:true},kgdmldjagfciieddcnlhampgkajkpanc:{blacklist:true},khgjo
mcpjblpoaipanicbfjfgcfbpegp:{blacklist:true},kibgmcdcfmcglajcfbecilngejnfppjp:{bl
acklist:true},kiipngoehgkgkackngaidmhmnchfbmio:{blacklist:true},kincjchfokkeneeof
peefomkikfkiedl:{blacklist:true},kinhljbhjmcmoddhdoodekeklmjapjff:{blacklist:true
},kkhejjmlcfbcleolhadhekjbcanoopna:{blacklist:true},kkhomejdleoonmbdhcigkhkjcghng
ncf:{blacklist:true},kkkeikdkpjenmoiicggnnodbkebafgpc:{blacklist:true},kleaapgdka
haekcocmkbgfainbhihccj:{blacklist:true},kljhmdlkclaglodecegamnpioaflmage:{blackli
st:true},kmlebjoghkhpapfhbdikannggmmffnco:{blacklist:true},kojkdbedffnppdoalcfkke
elbhbklhgp:{blacklist:true},kolbbghckjilleabphhgeggcgpfidofi:{blacklist:true},kpb
fifeiomkhocgkkffocfinoedcjebg:{blacklist:true},laicaenbonaajhkmfhhbpiapobdieffm:{
blacklist:true},lambangeielkjcnmioccboaphdfcffib:{blacklist:true},lbaddolhebpnhdc
dkicpcflhnfamcemn:{blacklist:true},lbcmmpmjjaockhkcofljpakjcbmjmgla:{blacklist:tr
ue},lbficnmfealeidppcbgdcbemgfjodbkg:{blacklist:true},lcbfjcekjncehfbcimlogajbekm
oeblm:{blacklist:true},lcccggoiffkhgfkefgbicjdgdnfpoihn:{blacklist:true},lceaiepe
hinnomgijphkmjccbigkljkj:{blacklist:true},lcfkojlnjnedeoepfemhdgkhiabkeadc:{black
list:true},lcmpleboacinanffcdgenhhbkboclkjb:{blacklist:true},ldgfapfmnplpaohbbadn
ecegcpfkfall:{blacklist:true},ldmoahefokhfelhpbgfjpelcdbahdofk:{blacklist:true},l
eccghfplhenabeogpibljliijgapfgb:{blacklist:true},lfechjkgjjijfjoandhakaghdeimjcod
:{blacklist:true},lfggokjjaanlfikbbapgnfemifmddalf:{blacklist:true},lgalokbapphhk
lmilicdefmgbjkcmldf:{blacklist:true},lgcnahanhlfpceencjmlehpfklokhojk:{blacklist:
true},lhajoamjgchgljkdjigcgmmcehjkagan:{blacklist:true},lhgbajoidigcpmgbnnonllfkn
dhahmie:{blacklist:true},likifpgnijjfbdegfepoalpamlgnfofi:{blacklist:true},liomof
jeffddiiccaolcnllbhnipbkhe:{blacklist:true},ljcicfibknpmlcmcecddjlbgkejehhpa:{bla
cklist:true},ljeihpebkahejeacdalhkhmckmggppif:{blacklist:true},ljlppmpjdogefnanek
ncklkjgpnhpcpd:{blacklist:true},ljmjoloiepllcndinchenhomcdcgbgef:{blacklist:true}
,lkdimamelhbiijkiljlnedmhnnkkmlbl:{blacklist:true},lkfdchejjogilmloogbbjlnlpbhgjf
ab:{blacklist:true},lkhcbijhgfchgdmklonlobkfbcadbokg:{blacklist:true},lljnngafekb
nkpdfophmcdlbfebcbcld:{blacklist:true},lmhdacagnmfmomeodbgmlghejdbmldge:{blacklis
t:true},lnahlgmhpghkhmafjppdidhcoaomipfg:{blacklist:true},lnbeebaenahmkbffnimghce
ldeeihfak:{blacklist:true},lncjcfkpannmofmpgdfoonkniofdnaba:{blacklist:true},lnde
mpehphjoeimfchjflohpmhamiamf:{blacklist:true},lnjgjionmhobdfdegbciceafphgemjnc:{b
lacklist:true},lnlaeblencbjjjeaanegaldcjfekeled:{blacklist:true},lodollblmkailkkd
iijmoccefdfjohgk:{blacklist:true},loggadfheaoeabmkgolecncpfdfioefa:{blacklist:tru
e},lojppnndedobolgfepahepphhloediji:{blacklist:true},loldehkdjdncebfnncknlkdchjcl
ifbn:{blacklist:true},lookpbabilcplifjdeifacodednpacmk:{blacklist:true},lpgiafapd
mlapiokjnmpbbfkomiceoml:{blacklist:true},lplmcpcnhpbffpcfiaddbeaplhhbengd:{blackl
ist:true},maakimnachffhlgdhfomaejeeaikgjap:{blacklist:true},mafccdbbhekjhemajjejk
aidndokeena:{blacklist:true},magllcifjcllaafcdplnajmobccbcdlo:{blacklist:true},ma
mfageekafifnickhgkibkofcclfefe:{blacklist:true},mandondadnlimicalgkbkaohmeopdojj:
{blacklist:true},mbifidpgmfiielflaipknojhpfcljmgo:{blacklist:true},mbmdaiddhfoljp
lpdhohimgieioblfif:{blacklist:true},mcbkimglepddodbiongpohpeidioafgk:{blacklist:t
rue},mcknnlhkkdbcppajgefagceglahcafjd:{blacklist:true},mdiehnlecbjlppbpaaipmlnhhj
gepfcg:{blacklist:true},mdngbiejioalifclonjepjjfppmbgned:{blacklist:true},megkcfp
bmemnpkgadkoompnoajcolpni:{blacklist:true},mfehgcgbbipciphmccgaenjidiccnmng:{acti
ve_permissions:{api:[cloudPrintPrivate]},creation_flags:1,from_bookmark:false,fro
m_webstore:false,install_time:13006296702500000,location:5,manifest:{app:{launch:
{web_url:https://www.google.com/cloudprint},urls:[https://www.google.com/cloudprint,https://www.google.com/cloudprint/enable_chrome_connector]},description:Cloud Print,display_in_launcher:false,key:MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqOhnw
k4+HXVfGyaNsAQdU/js1Na56diW08oF1MhZiwzSnJsEaeuMN9od9q9N4ZdK3o1xXOSARrYdE+syV7Dl31nf6qz3A6K+D5NHe6
sSB9yvYlIiN37jdWdrfxxE0pRYEVYZNTe3bzq3NkcYJlOdt1UPcpJB+isXpAGUKUvt7EQIDAQAB,name:
Cloud Print,permissions:[cloudPrintPrivate],version:0.1},path:C:\\Program Files\\Google\\Chrome\\Application\\25.0.1364.97\\resources\\cloud_print,was_installed_by_default:false},mfffdpnblflpobcnekhekiahepofaan
e:{blacklist:true},mfgkkephjfnkggbmahehnjhdcmkioaff:{blacklist:true},mfhfkclojmdo
cagbmecgcnlofppebebd:{blacklist:true},mfncimdpmknolnnnccdmkpnpkaofonkc:{blacklist
:true},mfooalpniplhaaealemjpchkchmmgdko:{blacklist:true},mgdgiplcofghdmpekdeeceol
epakodcb:{blacklist:true},mgndgikekgjfcpckkfioiadnlibdjbkf:{app_launcher_ordinal:
y,creation_flags:1,from_bookmark:false,from_webstore:false,install_time:130093367
29789500,location:5,manifest:{app:{launch:{web_url:http://THIS-WILL-BE-REPLACED}},description:Chrome as an app,display_in_launcher:true,display_in_new_tab_page:false,icons:{128:product_lo
go_128.png,16:product_logo_16.png},key:MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNuY
LEQ1QPMcc5HfWI/9jiEf6FdJWqEtgRmIeI7qtjPLBM5oje+Ny2E2mTAhou5qdJiO2CHWdU1DQXY2F7Zu2gZaKZgHLfK4Wim
HxUT5Xd9/aro/R9PCzjguM1BLusiWYc9xlj1IsZpyiN1hcjU7SCnBhv1feQlv2WSB5KRiXwhQIDAQAB,name:Chrome,v
ersion:0.1},page_ordinal:n,path:C:\\Program Files\\Google\\Chrome\\Application\\26.0.1410.43\\resources\\chrome_app,was_installed_by_default:false},mhbffdldpckobeihgebaamjalehefnia
:{blacklist:true},mhldlgmggplfkkjgpgjjpebflplpgekg:{blacklist:true},mickhiflmjglh
pdpfigpkpjiipfdlphj:{blacklist:true},mikpklndmiopinkkmalgoophegfnmmfh:{blacklist:
true},mjalegijammcloleihdmooifidcjggjp:{blacklist:true},mjgobkikdipfikmaoakdcdbic
pioljgg:{blacklist:true},mjhlngjakabhonjagnlimeicooahajpl:{blacklist:true},mjolna
dmlahbpepjaemohnkhpjkbhmef:{blacklist:true},mknjbohhleiicbpagpgmhoaigbblmnic:{bla
cklist:true},mkobblpffgbncfhijabakfafmkjdmmnm:{blacklist:true},mlmegahemifabfmdnn
dafagnncfbnahn:{blacklist:true},mlmmbepkgelpbenpobinockmiehdahai:{blacklist:true}
,mlnndjkcclbekgoebkenkdgiggaomaed:{blacklist:true},mlnoedbhndgbjcbeadjfnmjloejlgo
jk:{blacklist:true},mmjodihhmnpkldljaifiajmlnpflfhpm:{blacklist:true},mndoohjdoec
hinpkfbkolflbonciahfo:{blacklist:true},mnhcgaghminpdabllkbkecahjfkdiabk:{blacklis
t:true},mnichagcickblneeijmfnmoiakigmmhf:{blacklist:true},mnllienogacopjnkmhgnnio
pjpgjpopp:{blacklist:true},mogepbcllienegdibkfpmombhefhcoic:{blacklist:true},mokd
lfbphidpiopnlfejpcmadcbomckn:{blacklist:true},mpcglemopeoeapmagdbeenepkdbajape:{b
lacklist:true},mpgehpkneknbopplhmmkfijfiniddipf:{blacklist:true},mplhbhmkccidaokc
elbcbcmhhedebcng:{blacklist:true},mplpabdbfbloeiboikmdbnggfnjbjmlh:{blacklist:tru
e},naopgnjebjeeedbbhcadkhkmeefmloho:{blacklist:true},nbfcehkihbmpebblmfkihadebllg
fmgl:{blacklist:true},nbieffehfdniifkgdckbndjhojohbfjj:{blacklist:true},nckmikoho
ilfkcoahbjpbgbpegcjgngm:{blacklist:true},ncpdanjmicnihdlijomcggnnekloephc:{blackl
ist:true},ndhkiimgbjnendpcfbiadlifmangejoa:{blacklist:true},ndiogongcmocdgjciemha
gfhpjamehpe:{blacklist:true},negkalblfongjbphdcbbhddlickhlamd:{blacklist:true},ne
pfiodmbijheamafkiglonfkjebdjmf:{blacklist:true},nfecfkjnlkbphobjbcnphimihniieehc:
{blacklist:true},nhbfbnmmdjkjahhfdeklgphihfodfgnb:{blacklist:true},nhboiakpmibkbk
beehchlfkggmhphpnk:{blacklist:true},nhkmojkfnknbbmhbnacjdlodokeophkl:{blacklist:t
rue},nhooocacdhkpbmoocdclodjlddcebfoe:{blacklist:true},nibohffepnilngkecenfdgnokf
hmnkod:{blacklist:true},nidmbljkkcbdfklgdkklgjgmhejmbojn:{blacklist:true},nidodbf
omffkfabciljelkbdiabkeehe:{blacklist:true},nifbebeekindefklojhchehidpikbjfc:{blac
klist:true},nihhbeikpchdddoillfdcdinnnnllmna:{blacklist:true},nlefocohkhlgmjdhgkj
gdodobmffjbod:{blacklist:true},nlgapikcofpablcmfgaoodlhiejiehhh:{blacklist:true},
nloaaepkhcnmoakooihnefhhggbmemed:{blacklist:true},nmgpbidjnaebdlbdbpjggenmbaolmfo
i:{blacklist:true},nmmnodocfckpoddcgihiihcdinaonckb:{blacklist:true},nmphbnbmgfcc
fhcmibikmhcgajjpelpf:{blacklist:true},nnioepmjbjjlflmdgjanlcmbjahljeeo:{blacklist
:true},nochkknnbahbhmmknnmdhagelcnfagom:{blacklist:true},noefghcilkpcabnhhilojimk
kjplhcnd:{blacklist:true},npadaghbcdejfngcjpbnoikajdnongca:{blacklist:true},npfpm
gjnfcklmaipcffpjhapedmpjggj:{blacklist:true},npolaghondefgiomhkbiiompikfjneep:{bl
acklist:true},oafccdmmjdpialdmgenjfhijoondgncj:{blacklist:true},oakhllhnbcpgagdaf
gbninlpjdemdmjk:{blacklist:true},oanjogmonneelfpnfmdlalfddkeckdej:{blacklist:true
},obfnipbbnnhkbafmdbbfpgfgbjmmkgpm:{blacklist:true},obgljnmbldahelaakfdbjkplokjon
eip:{blacklist:true},obhplmafmpmelgapjjbfhcdkicnhakhf:{blacklist:true},oblicopoai
onpjoapgjmmoncjadpdioh:{blacklist:true},ochmdkhojipfibbplgpeeggeimnagcfd:{blackli
st:true},ocmhjnhildbnglmlfimkjnnfgddelacb:{blacklist:true},ocnlnkjmfnolmbclblfhfh
cakldceiec:{blacklist:true},odeckaficnaplobiiaomegfbokokehhb:{blacklist:true},ode
fpckfdnfkeandbeccopcpncnbkonn:{blacklist:true},odnamglmogfldajnhkfodmloofeokcmm:{
blacklist:true},oebmjchahlpmalnjpeagiibojcbfmema:{blacklist:true},oelhhkgiajkjfbc
cafjgggcpkbkjgpij:{blacklist:true},oghphhcagopecifjblgdcfihjnlcbcfc:{blacklist:tr
ue},ogjbodghhojomghbdfnlkppdagkfjede:{blacklist:true},oidjdpbndkjhmhmgdoggibcjnip
pkcgo:{blacklist:true},oilfokmpgejhjhecdjjpikloibggpenf:{blacklist:true},oimplfcc
ampifgkgndlamabnkcibkngc:{blacklist:true},ojglppmhgfohhfeinlhklglifnbfebak:{black
list:true},ojmdhklabgbnnkkilmkcfcemdhognifc:{blacklist:true},omceiakkomngangmllpg
bjcoeloglald:{blacklist:true},omnicnmbagoinlpamknknbcgopadcoci:{blacklist:true},o
ncmkbmjpjlihkpbohlpmjghiiogmoie:{blacklist:true},onfbaaifbbahonepmednhkjbhdgogkbl
:{blacklist:true},onjaecbdddgibdijafoemfiachlbcgkj:{blacklist:true},onpnpccdagnci
pgnoofbhchlbajcjnkd:{blacklist:true},oocfbmollajebjjpkahmlnclfhkjijea:{blacklist:
true},ookcgejbfhcmcanfkfmmmpahflnlajbl:{blacklist:true},oomelpjfeldbopnleifpjibbp
ekflhlg:{blacklist:true},opnnngnphijodjhemhdafpnnpdjggofe:{blacklist:true},pajgid
dgjidlcajihkjoacjbplimkgfe:{blacklist:true},pbdgmppmccanplobanhfkjndjkmmabgk:{bla
cklist:true},pbekednmpdekknlffkiopooofokfmkla:{blacklist:true},pbglijbamgmlcpnnpb
fjkbdeheejjloj:{blacklist:true},pbipaboekjdfhkfifpkofbfnpbnlolji:{blacklist:true}
,pcaedgdgamlfffkfblocmakhgieggoak:{blacklist:true},pcojpoljjgnicbhaffkiphphplijgb
cc:{blacklist:true},pdhjoamffhjhlkiiminjhmihalkfjaee:{blacklist:true},peahabnpipm
mfiajjjhgfggbeigbmbgp:{blacklist:true},peiijdmlgbelnnmnkighhkpeihmmamio:{blacklis
t:true},pfaooklcbjnkgconjjepimkohgcjmdji:{blacklist:true},pfcelnbmkeoaeicedjomcjk
cammlkdbk:{blacklist:true},pfckhplmfbblecglndaigpojefidapai:{blacklist:true},pfgm
gcnbngcnhjddppmnloflcidemopc:{blacklist:true},pfhlnanelpgjbhndafjamnpfhkjadoip:{b
lacklist:true},pfoiaildicnbcjojocjlpcibenphhbln:{blacklist:true},pfonklmafadkmced
jlodommcoipgbcde:{blacklist:true},pgelifedkjaohmjehecojkfldinjlamn:{blacklist:tru
e},pgjpnfpidejcmjibaaohcmehfohacckf:{blacklist:true},pgldfhecfiofkhnbgcncepnkjkeo
ahlk:{blacklist:true},pgmfkblbflahhponhjmkcnpjinenhlnc:{blacklist:true},pgmpnhbch
haningbkefchpdalnimjijd:{blacklist:true},phkpgooenaonkpnabopdbjjfmphclela:{blackl
ist:true},pihcfdffalbcnmbghijdfcaanagapelf:{blacklist:true},pjdhkkcnlbfebiokpeghf
ffajaabahfo:{blacklist:true},pjgbfgdpkbfimabdalhjmmeeelbmkcac:{blacklist:true},pj
kljhegncpnkpknbcohdijeoejaedia:{ack_external:true,active_bit:false,active_permiss
ions:{api:[notifications]},app_launcher_ordinal:w,creation_flags:137,exclude_from
_sideload_wipeout:true,from_bookmark:false,from_webstore:true,granted_permissions
:{api:[notifications]},install_time:13005338651013375,last_active_pingday:1300763
1610432125,lastpingday:13012038022983250,location:1,manifest:{app:{launch:{contai
ner:tab,web_url:https://mail.google.com/mail/ca},urls:[*://mail.google.com/mail/ca]},current_locale:en_US,default_locale:en,description:Fast, searchable email with less spam.,icons:{128:128.png},key:MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCuGglK43iAz
3J9BEYK/Mz6ZhloIMMDqQSAaf3vJt4eHbTbSDsu4WdQ9dQDRcKlg8nwQdePBt0C3PSUBtiSNSS37Z3qEGfS7LCju
3h6pI1Yr9MQtxw+jUa7kXXIS09VV73pEFUT/F7c6Qe8L5ZxgAcBvXBh1Fie63qb02I9XQ/CQIDAQAB,name:Gmail,options_page:https://mail.google.com/mail/ca/#settings,permissions:[notifications],update_url:http://clients2.google.com/service/update2/crx,version:7},page_ordinal:n,path:pjkljhegncpnkpknbcohdijeoejaedia\\7_1,state:1,was_installed_by_default:true},pjloefkigphblpjminnlpbhjchjafcfc
:{blacklist:true},pkbbbncikcipejaiiiioboongndhmjgl:{blacklist:true},pkbkgagehkkoa
jkpgnmjegibihpalfdk:{blacklist:true},pkbkkendemaimikinaefldfljliecapm:{blacklist:
true},pkcbihpffghlanbclfmkegjmbijcpobj:{blacklist:true},pkdlpbfmpolnhligegklimbcc
minkioc:{blacklist:true},pkhidkonipdjidjglnkfcfhnkfnlefbk:{blacklist:true},plfijd
dblbcdcnammpdmfccchkbdekmm:{blacklist:true},pmbjemmaclljifpmnlagkcgpbcipdldb:{bla
cklist:true},pnaaalnkbgjaphhmahecamecmaldknkc:{blacklist:true},pnaiiipilbpcceggea
nphcpkkihnojan:{blacklist:true},pndadpldhngimdmhnajebjldbmcbpjol:{blacklist:true}
,pnnbdjcjeiobikdfikegpclkcimgafpp:{blacklist:true},pnpfkfanlgljpkpilhgiimfadggfmh
cd:{blacklist:true},pnpgiaejfbdapllkchhgchjpdbcpiooa:{blacklist:true},pobponmhkpm
phbnfhpjdagklbkmjhked:{blacklist:true},ppmfajacidhcjbddpgmcmigffpppcadd:{blacklis
t:true},oajgghejjpgkmpgbchgjieahoefimdle:{ack_external:true}},sideload_wipeout_do
ne:true},first_run_tabs:[http://www.google.com/,http://welcome_page],google:{services:{last_username:[removed],signin:{LSID:DQA
AAM0AAACNu13Ssaw4_MyoOLMMMLUcunftYJVo-9ojBz_Sg5dJXQRxqMTCEoOLcnAElsCcYmxqs7fQ-Qi3iYVqnXWqPh3ZLtInErM9RJQBKdJXVhFhLT2P4Hyh20ckLxnv7o427HlL5kceR0WKivpgpZm8AxKCe
lluLem9aNoYpGOwNJdsxh8QpVWjh8x8DOXYKlyYPYgfkd0i95h2aaVdu-xvhv7HYgw0hFAw5H34LXNSb5UOn9nGoe3PkVUZ4m8WpirKsEnDmMj_csgp-_hskjDjsjMb,SID:DQAAAMAAAAC6QZre_10NyFp6_Sqokon7qyluwQEKZS1fkn7ijxcFKcjHASADW2Mi
CDyForZoiHDhiDqtO5SvzAuayxy_YsX0WnuY8y3QyKHaiPgRwunCnoCZ7TNd6xMZ6Xqm8oJAPsfYfeYtP
sx6R5pz6YWJvDAA1c-QPq5BaZ9EdQ7FigN6HoQiR9aMXpujTZ1PBTO1PgEariPEfw2jSZNY8wGInS0u4VsoxNYOgidbjojghuz
Gnb13ANNAy34v5SBx5Lo6joM,tokens:{chromiumsync:{status:Successful,value:DQAAAMUAAA
DOPIXNtMEdgeRayFpRltRfXfKRwNUO1zQQyOWpbFf5TrCce8rT23PG0aqgQ0uJHdyKLym6XKtu4zfBb7T
fxkDau7Rs4Px8nicqowx-SbuulNltEsw7YhpMDwql0J1jA8vLC0YvWJuZNwskMrUqqP3TyOHfdTnNReBB3uu1eeAhdriWPTliWuBR
voYEPwt8nwACjLZ461Zo7tKzpjeQ15PX7wCaL1MeobSmK1iwPJo6sinILqY9VTRepgQHHu-SOLr6aZYhm1_6MVOC9XrlTs7u},lso:{status:Successful,value:DQAAAMMAAADOPIXNtMEdgeRa
yFpRltRfjR2jMTkQZ7ygKyEfkKQQWOrWJAWYdrknYYk6AfKreviyaNDr111sknfX1VXtsSdUeL5PmU-LZRqhVMkSXV-bqX_THyEDLWEz36ouDckvh6aXE-BYrrGw8F44zlPmlCuXbcPPuBWBYDp3eHXe4ToIWBafev4nvw73hozWyTre5gDlUN5KDkDk5kiB-I7suyxURy5BUw0-PqXOWtSyy5UU4Isu3Dxo20L87VjVAMyGaSj6mgAnVB6ry4Fdh3kNufuK\n},mobilesync:{status:Successful,value:DQAAAMMAAADOPIXNtMEdgeRayFpRltRfjR2j
MTkQZ7ygKyEfkKQQWOrWJAWYdrknYYk6AfKreviL7o7cn9touMd4oqusm6WRI4_NuDh7czh8Mdc7jjpAw
Jg4a2_O71q-i7qPdozQTRPzXINtcuVX1FUmxcfPRdwRWFzaLmxXRMTbT8TeHBTlVW8hGa2zbNqUG5IlJrJBXEg4EuSV
NLFASG6pwpNbSKN7I-bK6PRHbvhpDnj55POU8RZlFxdwrl3WkMI28iWXPZQ58ivVRlFElN8aIqJk0UwT\n},oauth2LoginAccessToken:{status:Successful,value:ya29.AHES6ZTJTPKPu__F8It-FTTYnCqfzy_WT0gwRtSc5TA83II},oauth2LoginRefreshToken:{status:Successful,value:1/0YA0EHkPcgRxpxO2fDIaFrfxb05ejllGx2oAHU3g6FQ}}},username:[removed]}},home
page:http://search.conduit.com/?ctid=CT3287822&SearchSource;=48&CUI;=UN15030168692475115&UM;=2,homepage_is_newtabpage:false,is_google_plus_user:false,net:{http_server
_properties:{servers:{0.drive.google.com:443:{settings:{4:100,5:16},supports_spdy
:true},2542116.fls.doubleclick.net:443:{settings:{4:100,5:10,6:0},supports_spdy:t
rue},accounts.google.com:443:{settings:{4:100,5:13,6:0},supports_spdy:true},accou
nts.youtube.com:443:{settings:{4:100,5:16,6:0},supports_spdy:true},ad-g.doubleclick.net:443:{settings:{4:100},supports_spdy:true},ad.doubleclick.net:4
43:{settings:{4:100,5:10},supports_spdy:true},ajax.googleapis.com:443:{settings:{
4:100},supports_spdy:true},apis.google.com:443:{settings:{4:100,5:23,6:0},support
s_spdy:true},calendar.google.com:443:{settings:{4:100,5:32,6:0},supports_spdy:tru
e},cbks0.google.com:443:{settings:{4:100},supports_spdy:true},cbks1.google.com:44
3:{settings:{4:100},supports_spdy:true},chart.googleapis.com:443:{settings:{4:100
,5:32,6:0},supports_spdy:true},chatenabled.mail.google.com:443:{settings:{4:10,5:
10,6:0},supports_spdy:true},clients1.google.com:443:{settings:{4:100,5:16,6:0},su
pports_spdy:true},clients2.google.com:443:{settings:{4:100,5:16,6:0},supports_spd
y:true},clients2.googleusercontent.com:443:{settings:{4:100,5:22,6:0},supports_sp
dy:true},clients4.google.com:443:{settings:{4:100,5:16,6:0},supports_spdy:true},c
si.gstatic.com:443:{settings:{4:100,5:16,6:0},supports_spdy:true},docs.google.com
:443:{settings:{4:100,5:60,6:0},supports_spdy:true},drive.google.com:443:{setting
s:{4:100,5:16,6:0},supports_spdy:true},encrypted-tbn0.gstatic.com:443:{settings:{4:100,5:16,6:0},supports_spdy:true},encrypted-tbn2.gstatic.com:443:{settings:{4:100,5:32,6:0},supports_spdy:true},fls.doublecl
ick.net:443:{settings:{4:100,5:10,6:0},supports_spdy:true},fonts.googleapis.com:4
43:{settings:{4:100,5:10,6:0},supports_spdy:true},gg.google.com:443:{settings:{4:
100,5:10,6:0},supports_spdy:true},gmail.com:443:{settings:{4:10,5:32,6:0},support
s_spdy:true},googleads.g.doubleclick.net:443:{settings:{4:100,5:16,6:0},supports_
spdy:true},gp3.googleusercontent.com:443:{settings:{4:100,5:32,6:0},supports_spdy
:true},gp4.googleusercontent.com:443:{settings:{4:100,5:32,6:0},supports_spdy:tru
e},i1.ytimg.com:443:{settings:{4:100},supports_spdy:true},i3.ytimg.com:443:{setti
ngs:{4:100},supports_spdy:true},i4.ytimg.com:443:{settings:{4:100},supports_spdy:
true},id.google.com:443:{settings:{4:100},supports_spdy:true},lh3.googleuserconte
nt.com:443:{settings:{4:100,5:32,6:0},supports_spdy:true},lh4.googleusercontent.c
om:443:{settings:{4:100,5:16,6:0},supports_spdy:true},lh5.googleusercontent.com:4
43:{settings:{4:100,5:16,6:0},supports_spdy:true},lh6.googleusercontent.com:443:{
settings:{4:100,5:18,6:0},supports_spdy:true},mail.google.com:443:{settings:{4:10
,5:10,6:0},supports_spdy:true},maps.google.com:443:{settings:{4:100,5:10,6:0},sup
ports_spdy:true},maps.gstatic.com:443:{settings:{4:100,5:42,6:0},supports_spdy:tr
ue},mts0.google.com:443:{settings:{4:100,5:10,6:0},supports_spdy:true},mts1.googl
e.com:443:{settings:{4:100,5:52,6:0},supports_spdy:true},mw2.google.com:443:{sett
ings:{4:100},supports_spdy:true},pagead2.googleadservices.com:443:{settings:{4:10
0,5:32,6:0},supports_spdy:true},platform.harvestapp.com:443:{settings:{4:100},sup
ports_spdy:true},plus.google.com:443:{settings:{4:100,5:23,6:0},supports_spdy:tru
e},plusone.google.com:443:{settings:{4:100,5:34,6:0},supports_spdy:true},profile-a.xx.fbcdn.net:443:{supports_spdy:true},r.twimg.com:443:{supports_spdy:true},s.y
timg.com:443:{settings:{4:100},supports_spdy:true},secure.gravatar.com:443:{setti
ngs:{4:100,5:16},supports_spdy:true},services.google.com:443:{settings:{4:100,5:3
2,6:0},supports_spdy:true},ssl.google-analytics.com:443:{settings:{4:100,5:10,6:11},supports_spdy:true},ssl.gstatic.co
m:443:{settings:{4:100,5:18,6:0},supports_spdy:true},static.doubleclick.net:443:{
settings:{4:100},supports_spdy:true},themes.googleusercontent.com:443:{settings:{
4:100,5:76,6:0},supports_spdy:true},tools.google.com:443:{settings:{4:100,5:32,6:
0},supports_spdy:true},tpc.googlesyndication.com:443:{settings:{4:100},supports_s
pdy:true},twitter.com:443:{supports_spdy:true},www.facebook.com:443:{settings:{4:
100,5:10,7:16384},supports_spdy:true},www.google.com:443:{settings:{4:100,5:16,6:
0},supports_spdy:true},www.googleadservices.com:443:{settings:{4:100,5:10,6:0},su
pports_spdy:true},www.googletagmanager.com:443:{settings:{4:100},supports_spdy:tr
ue},www.googletagservices.com:443:{settings:{4:100,5:10,6:0},supports_spdy:true},
www.gstatic.com:443:{settings:{4:100,5:18,6:0},supports_spdy:true},www.youtube.co
m:443:{settings:{4:100,5:16,6:0},supports_spdy:true}},version:1}},plugins:{enable
d_internal_pdf3:true,enabled_nacl:true,last_internal_directory:C:\\Program Files\\Google\\Chrome\\Application\\26.0.1410.64,migrated_to_pepper_flash:true,plugins_list:[{enabled:true,name
:Shockwave Flash,path:C:\\Program Files\\Google\\Chrome\\Application\\26.0.1410.64\\PepperFlash\\pepflashplayer.dll,version:11.4.31.110},{enabled:true,name:Shockwave Flash,path:C:\\WINDOWS\\system32\\Macromed\\Flash\\NPSWF32_11_4_402_287.dll,version:11,4,402,287},{enabled:true,name:Flash},{e
nabled:true,name:Chrome Remote Desktop Viewer,path:internal-remoting-viewer,version:},{enabled:true,name:Chrome Remote Desktop Viewer},{enabled:true,name:Native Client,path:C:\\Program Files\\Google\\Chrome\\Application\\26.0.1410.64\\ppGoogleNaClPluginChrome.dll,version:},{enabled:true,name:Native Client},{enabled:true,name:Chrome PDF Viewer,path:C:\\Program Files\\Google\\Chrome\\Application\\26.0.1410.64\\pdf.dll,version:},{enabled:true,name:Chrome PDF Viewer},{enabled:true,name:Adobe Acrobat,path:C:\\Program Files\\Adobe\\Reader 10.0\\Reader\\Browser\\nppdf32.dll,version:10.1.4.38},{enabled:false,name:Adobe Acrobat},{enabled:true,name:Java Deployment Toolkit 6.0.200.2,path:C:\\Program Files\\Java\\jre6\\bin\\new_plugin\\npdeployJava1.dll,version:6.0.200.2},{enabled:true,name:Java™ Platform SE 6 U20,path:C:\\Program Files\\Java\\jre6\\bin\\new_plugin\\npjp2.dll,version:6.0.200.2},{enabled:true,name:Java},{enabled:true,name:20
07 Microsoft Office system,path:C:\\Program Files\\Mozilla Firefox\\plugins\\NPOFF12.DLL,version:12.0.4518.1014},{enabled:true,name:Microsoft Office},{enabled:true,name:QuickTime Plug-in 7.7,path:C:\\Program Files\\Mozilla Firefox\\plugins\\npqtplugin.dll,version:7.7 (1680.34)},{enabled:true,name:QuickTime Plug-in 7.7,path:C:\\Program Files\\Mozilla Firefox\\plugins\\npqtplugin2.dll,version:7.7 (1680.34)},{enabled:true,name:QuickTime Plug-in 7.7,path:C:\\Program Files\\Mozilla Firefox\\plugins\\npqtplugin3.dll,version:7.7 (1680.34)},{enabled:true,name:QuickTime Plug-in 7.7,path:C:\\Program Files\\Mozilla Firefox\\plugins\\npqtplugin4.dll,version:7.7 (1680.34)},{enabled:true,name:QuickTime Plug-in 7.7,path:C:\\Program Files\\Mozilla Firefox\\plugins\\npqtplugin5.dll,version:7.7 (1680.34)},{enabled:true,name:QuickTime Plug-in 7.7,path:C:\\Program Files\\Mozilla Firefox\\plugins\\npqtplugin6.dll,version:7.7 (1680.34)},{enabled:true,name:QuickTime Plug-in 7.7,path:C:\\Program Files\\Mozilla Firefox\\plugins\\npqtplugin7.dll,version:7.7 (1680.34)},{enabled:true,name:QuickTime},{enabled:true,name:Microsoft\u00AE DRM,path:C:\\Program Files\\Windows Media Player\\npdrmv2.dll,version:9.00.00.4503},{enabled:true,name:Microsoft\u00AE DRM,path:C:\\Program Files\\Windows Media Player\\npwmsdrm.dll,version:9.00.00.4503},{enabled:true,name:Microsoft\u00AE DRM},{enabled:true,name:Windows Media Player Plug-in Dynamic Link Library,path:C:\\Program Files\\Windows Media Player\\npdsplay.dll,version:3.0.2.629},{enabled:true,name:Windows Media Player},{enabled:true,name:SOE Web Installer,path:C:\\Documents and Settings\\Tracy\\Application Data\\Mozilla\\Firefox\\Profiles\\m3exjy1b.default\\extensions\\{000F1EA4-5E08-4564-A29B-29076F63A37A}\\plugins\\npsoe.dll,version:1, 0, 3, 159},{enabled:true,name:SOE Web Installer},{enabled:true,name:Unity Player,path:C:\\Documents and Settings\\Tracy\\Local Settings\\Application Data\\Unity\\WebPlayer\\loader\\npUnity3D32.dll,version:2.6.1.31223},{enabled:true,name:Unity Player},{enabled:true,name:Google Update,path:C:\\Program Files\\Google\\Update\\1.3.21.115\\npGoogleUpdate3.dll,version:1.3.21.115},{enabled:true,name:Google Update},{enabled:true,name:RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ,path:C:\\Program Files\\Real\\RealPlayer\\Netscape6\\nppl3260.dll,version:6.0.11.2852},{enabled:true,name:RealPlayer Version Plugin,path:C:\\Program Files\\Real\\RealPlayer\\Netscape6\\nprpjplug.dll,version:6.0.12.1662},{enabled:true,name:RealPlayer},{enabled:
true,name:RealJukebox NS Plugin,path:C:\\Program Files\\Real\\RealPlayer\\Netscape6\\nprjplug.dll,version:1.0.2.2910},{enabled:true,name:RealJukebox NS Plugin},{enabled:true,name:MetaStream 3 Plugin,path:C:\\Program Files\\Viewpoint\\Viewpoint Experience Technology\\npViewpoint.dll,version:3, 0, 14, 163},{enabled:true,name:MetaStream 3 Plugin},{enabled:true,name:iTunes Application Detector,path:C:\\Program Files\\iTunes\\Mozilla Plugins\\npitunes.dll,version:1.0.1.1},{enabled:true,name:iTunes Application Detector},{enabled:true,name:Windows Presentation Foundation,path:C:\\WINDOWS\\Microsoft.NET\\Framework\\v3.5\\Windows Presentation Foundation\\NPWPF.dll,version:3.5.30729.1 built by: SP},{enabled:true,name:Windows Presentation Foundation}],removed_old_component_pepper_flash_settings:true},profile:{avatar_i
ndex:0,content_settings:{clear_on_exit_migrated:true,pref_version:1},exit_type:No
rmal,exited_cleanly:true,is_managed:false,name:First user},reverse_autologin:{enabled:false},selectfile:{last_directory:C:\\Documents and Settings\\Tracy\\Desktop\\Desktop},session:{restore_on_startup:4,restore_on_startup_migrated:true,url
s_to_restore_on_startup:[http://search.conduit.com/?ctid=CT3287822&SearchSource;=48&CUI;=UN15030168692475115&UM;=2]},sync_promo:{show_on_first_run_allowed:fals
CHR - homepage: http://search.yahoo.com?type=994519&fr;=spigot-yhp-ch
CHR - Extension: No name found = C:\Documents and Settings\Tracy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Documents and Settings\Tracy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Documents and Settings\Tracy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Documents and Settings\Tracy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2012/06/25 20:37:47 | 000,000,726 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HelperObject Class) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Protect My Choices (Beta)) - {3DFCDCA1-AEAC-4302-A690-BFB683568BAA} - C:\Program Files\DigitalAdvertisingAlliance\Protect My Choices\pmc.dll (Digital Advertising Alliance)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O2 - BHO: (no name) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - No CLSID value found.
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\5.2.2.3\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (no name) - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - No CLSID value found.
O2 - BHO: (Advertising Cookie Opt-out) - {8E425EB4-ADBD-4816-B1E8-49BB9DECF034} - C:\Program Files\Google\Advertising Cookie Opt-out\opt_out.dll (Google Inc)
O2 - BHO: (no name) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - No CLSID value found.
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [DNS7reminder] C:\Program Files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [iYogi Support Dock] C:\Program Files\iYogi Support Dock\iYogiSupportDock.exe ()
O4 - HKCU..\Run: [CB453CAA6E1138CBF54EDB4C92B9390591ABCBF6._service_run] "C:\Program Files\Google\Chrome\Application\chrome.exe" –type=service File not found
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil32_11_5_502_110_ActiveX.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O9 - Extra 'Tools' menuitem : GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: download.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4A24598C-1F88-4A6D-AE90-F85626456603}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Tracy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tracy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/03/20 10:58:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{11b86e27-0504-11e2-9710-000f1f59742b}\Shell - "" = AutoRun
O33 - MountPoints2\{11b86e27-0504-11e2-9710-000f1f59742b}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{11b86e27-0504-11e2-9710-000f1f59742b}\Shell\AutoRun\command - "" = F:\Setup.exe
O33 - MountPoints2\{a4e522e0-02f1-11e0-aebf-000f1f59742b}\Shell\Setup FlipShare\command - "" = G:\Setup_FlipShare.exe
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: ()
O34 - HKLM BootExecute: ()
O34 - HKLM BootExecute: ()
O34 - HKLM BootExecute: ()
O34 - HKLM BootExecute: (_?)
O34 - HKLM BootExecute: ()
O34 - HKLM BootExecute: (a?)
O34 - HKLM BootExecute: (.)
O34 - HKLM BootExecute: (????????)
O34 - HKLM BootExecute: (sasnative32)
O34 - HKLM BootExecute: (2\H\)
O34 - HKLM BootExecute: (h)
O34 - HKLM BootExecute: (l)
O34 - HKLM BootExecute: (untPoints2\G\Shell)
O34 - HKLM BootExecute: (l)
O34 - HKLM BootExecute: (38a000015}\)
O34 - HKLM BootExecute: (h)
O34 - HKLM BootExecute: (l)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.pspgru - C:\WINDOWS\System32\PSPGRU.acm (Philips Austria GmbH - Speech Processing)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\SERWVDRV.DLL (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/08/21 13:04:28 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Tracy\Desktop\OTL.exe
[2013/08/21 11:46:31 | 000,000,000 | –SD | C] – C:\Documents and Settings\Tracy\My Documents\My PageManager
[2013/08/16 09:26:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracy\Desktop\Heather Eighth grade
[2013/08/09 11:25:05 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2013/08/08 02:03:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracy\Desktop\SPC_Report
[2013/08/05 18:10:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracy\Local Settings\Application Data\IAC
[2013/08/05 17:51:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\VS Revo Group
[2013/08/03 08:09:01 | 000,040,776 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2013/07/24 22:44:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracy\My Documents\Vuze Downloads
[2013/07/24 22:34:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracy\.swt
[2013/07/24 22:32:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracy\Application Data\Azureus
[15 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/08/21 13:15:00 | 000,000,436 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{163BEBF5-21BC-458F-A016-A747DECFA5D3}.job
[2013/08/21 13:04:28 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Tracy\Desktop\OTL.exe
[2013/08/21 12:45:15 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/08/21 12:38:31 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{D4373AF6-61AF-41F4-B911-DBFA37C2838B}.job
[2013/08/21 12:32:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/21 12:04:06 | 000,000,184 | -H– | M] () – C:\WINDOWS\NsNetScan.ini
[2013/08/21 10:32:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/08/20 22:17:58 | 000,001,205 | —- | M] () – C:\Documents and Settings\Tracy\Desktop\ecampus Login.url
[2013/08/20 16:32:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/20 01:10:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\PC TuneUp Maestro Disk Defrag Analysis.job
[2013/08/18 10:40:06 | 000,000,448 | —- | M] () – C:\WINDOWS\tasks\IYSO-IYSOPrivacyProtector.job
[2013/08/18 09:34:27 | 000,000,408 | —- | M] () – C:\WINDOWS\tasks\IYSO-IYSOOneClickCare.job
[2013/08/18 01:01:00 | 000,000,384 | —- | M] () – C:\WINDOWS\tasks\PC TuneUp Maestro Scan.job
[2013/08/17 22:40:05 | 000,000,442 | —- | M] () – C:\WINDOWS\tasks\IYSO-IYSODiskOptimizer.job
[2013/08/17 22:40:01 | 000,000,436 | —- | M] () – C:\WINDOWS\tasks\IYSO-IYSOSystemCleaner.job
[2013/08/17 17:56:12 | 000,000,984 | —- | M] () – C:\Documents and Settings\Tracy\Desktop\magicJack.lnk
[2013/08/17 17:48:44 | 000,002,278 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2013/08/17 10:47:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2013/08/17 10:47:43 | 2145,456,128 | -HS- | M] () – C:\hiberfil.sys
[2013/08/17 10:47:06 | 000,002,576 | —- | M] () – C:\WINDOWS\System32\ASOROSet.bin
[2013/08/17 10:41:20 | 000,000,454 | —- | M] () – C:\WINDOWS\tasks\IYSO-IYSORegistryOptimizer.job
[2013/08/17 10:41:20 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\IYSO-IYSORegistryCleaner.job
[2013/08/12 09:18:40 | 000,088,288 | —- | M] () – C:\Documents and Settings\Tracy\Desktop\marijuana and alcohol.pdf
[2013/08/09 11:25:08 | 000,000,742 | —- | M] () – C:\Documents and Settings\Tracy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/08/05 17:51:42 | 000,000,925 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Revo Uninstaller Pro.lnk
[2013/08/05 17:33:12 | 000,505,850 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2013/08/05 17:33:12 | 000,087,308 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2013/08/03 08:09:32 | 000,040,776 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[15 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/08/12 09:18:40 | 000,088,288 | —- | C] () – C:\Documents and Settings\Tracy\Desktop\marijuana and alcohol.pdf
[2013/08/09 11:25:08 | 000,000,742 | —- | C] () – C:\Documents and Settings\Tracy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/08/09 11:25:07 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2013/08/05 17:51:41 | 000,000,925 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Revo Uninstaller Pro.lnk
[2013/05/06 10:18:51 | 000,000,120 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2013/02/28 16:24:05 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2012/09/22 23:35:42 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\xmltok.dll
[2012/09/22 23:35:42 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\xmlparse.dll
[2012/09/22 23:06:31 | 000,127,744 | —- | C] () – C:\WINDOWS\System32\drivers\ArcHlp.sys
[2012/02/05 18:06:22 | 000,002,955 | —- | C] () – C:\Documents and Settings\Tracy\Application Data\SAS7_000.DAT
[2011/11/28 11:35:05 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/09/13 16:43:25 | 000,000,000 | —- | C] () – C:\Documents and Settings\Tracy\Application Data\bibstats
[2011/05/17 10:37:35 | 000,013,004 | —- | C] () – C:\Documents and Settings\Tracy\Application Data\Comma Separated Values (Windows).CAL
[2011/05/12 11:55:19 | 000,001,940 | —- | C] () – C:\Documents and Settings\Tracy\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/12 11:49:50 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/06 08:13:56 | 000,061,440 | —- | C] () – C:\Documents and Settings\Tracy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/12 19:00:13 | 000,756,568 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/01/15 10:14:36 | 000,060,304 | —- | C] () – C:\Documents and Settings\Tracy\g2mdlhlpx.exe
[2009/11/17 13:09:00 | 000,029,880 | —- | C] () – C:\Documents and Settings\Tracy\Application Data\Comma Separated Values (Windows).ADR
[2008/01/07 06:29:19 | 000,103,832 | —- | C] () – C:\Documents and Settings\Tracy\GoToAssistDownloadHelper.exe
[2006/11/05 00:11:11 | 021,290,704 | —- | C] ( ) – C:\Program Files\AdbeRdr708_en_US.exe
[2004/07/02 16:55:10 | 000,061,678 | —- | C] () – C:\Documents and Settings\Tracy\Application Data\PFP110JPR.{PB
[2004/07/02 16:55:10 | 000,012,358 | —- | C] () – C:\Documents and Settings\Tracy\Application Data\PFP110JCM.{PB

========== ZeroAccess Check ==========

[2004/06/23 05:03:15 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2009/09/24 22:49:02 | 001,509,888 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\fastprox.dll – [2009/02/09 03:20:33 | 000,473,088 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll – [2004/08/04 00:56:46 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/05/06 11:21:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AMMYY
[2012/06/25 19:22:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor
[2009/11/17 12:56:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Applications
[2013/05/06 09:38:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Babylon
[2012/04/23 08:38:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\blekko toolbars
[2011/12/16 23:08:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\bomgar-scc-4EEC0E17
[2011/12/16 23:08:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\bomgar-scc-4EEC2223
[2012/12/01 13:30:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Carbonite
[2012/03/31 11:58:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2008/01/07 06:31:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2010/04/12 14:06:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2013/05/06 15:41:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CompuClever
[2012/10/07 12:05:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2012/12/03 23:20:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2013/01/12 14:10:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iYogi
[2012/12/02 19:51:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iyogi-scc-50BBF401
[2010/10/27 12:02:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Livescribe
[2011/10/10 14:29:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\magicJack
[2012/02/05 17:20:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2010/10/28 01:49:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SafeNet Sentinel
[2005/03/25 15:44:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2008/08/23 14:53:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2011/09/16 10:39:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartPCScan
[2010/04/12 14:21:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 11
[2008/01/24 21:38:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2012/12/01 05:58:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2004/07/17 18:26:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\The Learning Company
[2004/06/23 05:08:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/10/28 01:49:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vision Objects
[2013/08/05 17:51:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VS Revo Group
[2011/12/16 23:08:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2010/07/14 13:14:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WidgetServer
[2009/06/07 23:23:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
[2011/12/16 14:56:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2010/10/26 09:49:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{C3243856-7746-4A05-8837-51A28C1CDD82}
[2013/07/25 23:42:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Azureus
[2013/05/06 09:38:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Babylon
[2011/01/13 16:43:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Barnes & Noble
[2012/04/17 00:38:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\blekkotb_019
[2010/05/31 14:51:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Canon
[2010/03/23 15:01:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/11/07 08:42:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\com.livescribe.LivescribeConnect
[2013/05/06 15:41:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\CompuClever
[2013/05/06 09:38:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Delta
[2009/06/03 12:34:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Design Science
[2011/09/12 21:14:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\ElevatedDiagnostics
[2012/09/22 17:23:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Epson
[2010/02/19 22:39:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\GetRightToGo
[2009/07/25 16:53:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\GlarySoft
[2007/04/13 13:44:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\ICAClient
[2010/04/15 13:50:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\iolo
[2011/11/30 11:33:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\iYogi
[2006/10/09 21:11:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Jasc
[2006/11/11 16:16:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Kensington
[2010/10/31 15:35:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Leader Technologies
[2006/07/22 14:00:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Leadertech
[2013/08/17 17:56:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\mjusbsp
[2005/12/11 23:37:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\NewSoft
[2012/02/05 17:45:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Nuance
[2013/01/15 22:27:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Optimize
[2010/11/26 09:48:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Participatory Culture Foundation
[2011/02/19 22:29:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\PCDr
[2010/11/26 09:55:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\PCF-VLC
[2013/05/06 14:04:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\PriceGong
[2011/09/04 18:55:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Riverpoint Writer
[2004/07/02 16:10:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\ScanSoft
[2009/07/17 23:28:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Simple Star
[2010/11/02 22:19:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Singlesnet
[2011/09/13 18:17:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\SmartDraw
[2012/12/14 13:51:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Sony Online Entertainment
[2010/10/24 15:07:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\supportdotcom
[2012/05/14 12:39:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\TeamViewer
[2010/10/27 11:52:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Temp
[2010/04/30 13:53:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Tific
[2009/10/04 10:02:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Viewpoint
[2010/10/30 20:52:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\W Photo Studio Viewer
[2011/11/09 10:47:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\webex
[2008/08/23 17:41:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Windows Desktop Search
[2008/09/08 11:43:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracy\Application Data\Windows Search

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EX_ >
[2004/03/19 15:37:14 | 000,351,603 | —- | M] () MD5=2690171B51B4DBA59C02E89DB7FE6C9B – C:\I386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/13 17:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 04:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 03:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2007/06/13 03:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\explorer.exe
[2004/03/19 15:37:14 | 001,004,032 | —- | M] (Microsoft Corporation) MD5=A82B28BFC2E4455FE43022A498C0EF0A – C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\explorer.exe

< MD5 for: EXPLORER.EXE.000 >
[2004/08/04 00:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe.000

< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2013/08/17 17:48:50 | 000,096,570 | —- | M] () MD5=03C860034E03B20C5A6A4B9CB00CA54A – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf

< MD5 for: EXPLORER.SC_ >
[2004/03/19 15:37:14 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\I386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2004/03/19 15:37:14 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\EXPLORER.SCF

< MD5 for: EXPLORER.ZIP >
[2006/03/06 23:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.CHM >
[2004/03/19 15:38:02 | 000,167,956 | —- | M] () MD5=13A43EAD75BC03C50815444AC3018010 – C:\I386\IEXPLORE.CHM
[2004/03/19 15:38:02 | 000,167,956 | —- | M] () MD5=13A43EAD75BC03C50815444AC3018010 – C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\iexplore.chm
[2009/02/21 02:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\6da4424d72753c091c7e676b6e8a\iexplore.chm
[2009/02/21 02:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/07/17 11:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2004/07/17 11:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ServicePackFiles\i386\iexplore.chm
[2006/09/01 09:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EX_ >
[2004/03/19 15:38:02 | 000,036,925 | —- | M] () MD5=BAC737FDAA9B648A6EBFF76BFAEC7501 – C:\I386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2008/12/18 22:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/14 23:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2008/12/18 22:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/04/22 01:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2008/08/22 22:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2008/04/22 00:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
[2008/02/29 01:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
[2004/03/19 15:38:02 | 000,091,136 | —- | M] (Microsoft Corporation) MD5=418D301C3B1FA94B19584AEEB3D65166 – C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\iexplore.exe
[2007/08/17 03:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[2008/04/13 17:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2007/10/10 01:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[2008/06/23 02:20:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2007/02/21 01:00:58 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=683DDE71BCF03B501B912D20CB93B549 – C:\WINDOWS\ie7updates\KB933566-IE7\iexplore.exe
[2008/02/22 02:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2007/12/06 01:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2007/04/24 07:20:41 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=9B3516C1F30DA17ADD3818573047D63C – C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[2008/10/15 00:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/27 21:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 15:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 15:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
[2009/02/27 21:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2007/06/27 02:16:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[2009/04/24 22:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2008/06/23 01:23:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[2007/02/27 23:51:34 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=D321092F8529CDAE843D6E24E3CAC6CB – C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[2007/08/13 19:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie8\iexplore.exe
[2004/08/04 00:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
[2004/08/04 00:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2008/08/22 22:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2007/10/10 03:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 15:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 15:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 19:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2013/08/21 13:01:16 | 000,074,916 | —- | M] () MD5=A4E6473AC65F802A4DE0F6216805B79F – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HLP >
[2004/03/19 15:38:02 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\I386\IEXPLORE.HLP
[2004/03/19 15:38:02 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\IEXPLORE.HLP

< MD5 for: SERVICES >
[2004/03/19 15:42:30 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\I386\SERVICES
[2004/03/19 15:42:30 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\SYSTEM32\DRIVERS\ETC\SERVICES

< MD5 for: SERVICES.CFG >
[2012/07/27 13:51:34 | 000,586,083 | —- | M] () MD5=6DE4EA437EC1FE6DB27CADB0A7EA8DC2 – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.CSS >
[2011/03/10 16:57:40 | 000,000,093 | —- | M] () MD5=F15FB82C578490B209442B8C1D5076CC – C:\Documents and Settings\All Users\Application Data\Intuit\Quicken\Inet\Common\Localweb\Services\Services.css

< MD5 for: SERVICES.EXE >
[2009/02/06 04:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 17:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 10:14:03 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=37561F8D4160D62DA86D24AE41FAE8DE – C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2009/02/06 03:22:21 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=4712531AB7A01B7EE059853CA17D39BD – C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\services.exe
[2009/02/06 04:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 04:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\SYSTEM32\DLLCACHE\services.exe
[2009/02/06 04:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\SYSTEM32\services.exe
[2004/03/19 15:42:30 | 000,101,376 | —- | M] (Microsoft Corporation) MD5=E3DF4A0252D287C44606EE55355E1623 – C:\I386\SERVICES.EXE
[2004/03/19 15:42:30 | 000,101,376 | —- | M] (Microsoft Corporation) MD5=E3DF4A0252D287C44606EE55355E1623 – C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\services.exe

< MD5 for: SERVICES.EXE.000 >
[2004/08/04 00:56:55 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe.000

< MD5 for: SERVICES.INI >
[2011/03/10 16:57:40 | 000,000,012 | —- | M] () MD5=810C4D394B59FF7116A0CD6052286C41 – C:\Documents and Settings\All Users\Application Data\Intuit\Quicken\Inet\Common\Localweb\Services\Services.ini

< MD5 for: SERVICES.LNK >
[2010/12/08 10:56:45 | 000,001,602 | —- | M] () MD5=8EDABAA8E9C7247933ADC056F3CE31DE – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2004/03/19 15:42:30 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\I386\SERVICES.MSC
[2004/03/19 15:42:30 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\SYSTEM32\SERVICES.MSC

< MD5 for: WINLOGON.EXE >
[2004/08/04 00:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2004/08/04 00:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\SYSTEM32\winlogon.exe
[2004/03/19 15:44:38 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=2246D8D8F4714A2CEDB21AB9B1849ABB – C:\I386\WINLOGON.EXE
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2004/05/26 18:38:46 | 000,483,328 | —- | M] (Microsoft Corporation) MD5=E7F9D2E4E4A94A6F58014E5FFA16A65E – C:\WINDOWS\SoftwareDistribution\Download\cb54485933aa009855d78885e4c31c64\sp1qfe\winlogon.exe
[2004/05/26 18:38:46 | 000,483,328 | —- | M] (Microsoft Corporation) MD5=E7F9D2E4E4A94A6F58014E5FFA16A65E – C:\WINDOWS\SoftwareDistribution\Download\cf113cf67754a276d1983478748b20da\sp1qfe\winlogon.exe
[2004/05/26 18:38:46 | 000,483,328 | —- | M] (Microsoft Corporation) MD5=E7F9D2E4E4A94A6F58014E5FFA16A65E – C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\winlogon.exe
[2008/04/13 17:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2009/04/17 12:02:11 | 000,010,920 | —- | M] () – C:\aolconnfix.exe
[2009/04/17 12:02:11 | 000,001,039 | —- | M] () – C:\aolconnfix.txt
[2004/03/20 10:58:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2013/01/12 14:48:51 | 000,000,210 | RHS- | M] () – C:\boot.ini
[2004/03/20 10:58:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/04/28 12:35:49 | 000,000,081 | —- | M] () – C:\CTX.DAT
[2004/06/23 04:43:22 | 000,005,005 | RH– | M] () – C:\DELL.SDR
[2013/03/16 09:37:24 | 000,011,210 | —- | M] () – C:\drwtsn32.log
[2013/05/06 13:54:08 | 000,000,009 | —- | M] () – C:\END
[2013/08/17 10:47:43 | 2145,456,128 | -HS- | M] () – C:\hiberfil.sys
[2004/03/20 10:58:32 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2009/07/13 23:12:15 | 000,000,321 | -H– | M] () – C:\IPH.PH
[2012/10/07 09:20:09 | 000,001,720 | —- | M] () – C:\log.txt
[2004/03/20 10:58:32 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2008/07/04 15:55:47 | 000,001,049 | —- | M] () – C:\net_save.dna
[2005/09/20 15:05:22 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/12/09 19:54:40 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2012/12/01 13:32:28 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2013/08/21 12:44:34 | 000,001,024 | -H– | M] () – C:\ntuser.dat.LOG
[2013/08/17 10:47:42 | 3218,079,744 | -HS- | M] () – C:\pagefile.sys
[2010/04/30 13:08:10 | 000,003,847 | —- | M] () – C:\PCJumpStart.log
[2011/11/27 13:41:56 | 127,982,222 | —- | M] () – C:\reg.reg
[2004/06/23 05:09:38 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2011/05/05 10:36:04 | 000,055,896 | —- | M] () – C:\TDSSKiller.2.5.0.0_05.05.2011_10.34.56_log.txt
[2010/03/31 10:34:22 | 001,597,780 | —- | M] () – C:\VRQScanner.log
[2010/03/31 10:34:35 | 000,001,506 | —- | M] () – C:\VRQTool.log
[2012/09/01 11:24:51 | 000,004,096 | -HS- | M] () – C:\VSNAP.IDX

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2011/05/05 00:04:57 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/03/16 22:00:00 | 000,022,528 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD7W.DLL
[2002/09/29 13:00:00 | 000,013,824 | R— | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPDya.DLL
[2006/03/16 22:00:00 | 000,065,024 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP7W.DLL
[2002/09/29 13:00:00 | 000,046,080 | R— | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPPya.DLL
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/08/12 10:58:10 | 000,314,880 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp082.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2004/06/01 11:35:20 | 000,417,792 | —- | M] () – C:\WINDOWS\PhotoShow.scr
[15 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2006/11/05 00:13:47 | 021,290,704 | —- | M] ( ) – C:\Program Files\AdbeRdr708_en_US.exe
[2010/09/13 21:42:24 | 000,005,632 | -HS- | M] () – C:\Program Files\Thumbs.db

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 7C07-CCF1
Directory of C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices
10/15/2009 03:18 AM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote
10/15/2009 03:18 AM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices
08/05/2013 05:27 PM v4.0_4.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
3 Dir(s) 38,605,029,376 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/12/09 20:07:14 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/05 00:05:13 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Tracy\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2004/07/02 13:13:46 | 000,000,079 | —- | M] () – C:\Documents and Settings\Tracy\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2013/01/21 10:21:28 | 005,077,800 | —- | M] () – C:\Documents and Settings\Tracy\Desktop\HPPSdr.exe
[2011/06/27 09:55:45 | 007,622,112 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Tracy\Desktop\mwamsetup.exe
[2013/08/21 13:04:28 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Tracy\Desktop\OTL.exe
[2013/01/15 17:27:21 | 001,369,280 | —- | M] () – C:\Documents and Settings\Tracy\Desktop\pcoptimization.exe
[2012/10/07 13:10:53 | 001,297,552 | —- | M] (iYogi ) – C:\Documents and Settings\Tracy\Desktop\renewspc.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-07-12 01:01:39

< >
[2004/03/19 15:40:06 | 000,000,065 | RH– | C] () – C:\WINDOWS\Tasks\DESKTOP.INI
[2004/06/23 04:54:20 | 000,000,006 | -H– | C] () – C:\WINDOWS\Tasks\SA.DAT
[2011/09/16 13:41:21 | 000,000,284 | —- | C] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2011/12/13 02:41:03 | 000,000,408 | —- | C] () – C:\WINDOWS\Tasks\IYSO-IYSOOneClickCare.job
[2011/12/13 02:41:29 | 000,000,436 | —- | C] () – C:\WINDOWS\Tasks\IYSO-IYSOSystemCleaner.job
[2011/12/13 02:42:01 | 000,000,454 | —- | C] () – C:\WINDOWS\Tasks\IYSO-IYSORegistryOptimizer.job
[2011/12/13 02:42:47 | 000,000,442 | —- | C] () – C:\WINDOWS\Tasks\IYSO-IYSODiskOptimizer.job
[2011/12/13 02:43:05 | 000,000,430 | —- | C] () – C:\WINDOWS\Tasks\IYSO-IYSORegistryCleaner.job
[2011/12/13 02:43:14 | 000,000,448 | —- | C] () – C:\WINDOWS\Tasks\IYSO-IYSOPrivacyProtector.job
[2012/03/31 10:59:31 | 000,000,830 | —- | C] () – C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012/09/30 08:39:06 | 000,000,436 | -H– | C] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{163BEBF5-21BC-458F-A016-A747DECFA5D3}.job
[2012/10/07 09:49:02 | 000,000,422 | -H– | C] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{D4373AF6-61AF-41F4-B911-DBFA37C2838B}.job
[2012/11/12 13:02:14 | 000,000,880 | —- | C] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2012/11/12 13:02:14 | 000,000,884 | —- | C] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2013/05/06 15:41:25 | 000,000,384 | —- | C] () – C:\WINDOWS\Tasks\PC TuneUp Maestro Scan.job
[2013/05/06 15:41:27 | 000,000,396 | —- | C] () – C:\WINDOWS\Tasks\PC TuneUp Maestro Disk Defrag Analysis.job

========== Alternate Data Streams ==========

@Alternate Data Stream - 242 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0FF263E8
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9

< End of report >

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, tletch

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.

—————————————————————————————————

Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
===================================================

Download TDSSKiller.exe and save it to your desktop

Execute TDSSKiller.exe by doubleclicking on it.
Press Start Scan
If Malicious objects are found, do NOT select Cure. Change the action to Skip, and save the log.
Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.log.txt

===================================================

On your next reply please post :
aswMBR log
MBR.dat (attached)
TDSS Killer log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!

—————————————————————————————————
Hi Thanks Conspire, I am downloading now, but won't finish until real late. Computer says estimated download time left 1 hr. It's nearly 4AM so I will finish up and post my log files tomorrow. Really appreciate the help. Thanks again, tletch
Hi Conspire here are my files I had trouble uploading the MBR.dat even when I zipped it. I can't even seem to upload a word document So, I am sorry, but here it is I forgot to mention that sometimes when I try to open Outllook I get a message file inacessable in use check to make sure the disk is not full, write proteced or in use. close all programs Something like that. I hope I included everything you need. Thank you tletch aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-08-22 08:52:36 —————————– 08:52:36.512 OS Version: Windows 5.1.2600 Service Pack 3 08:52:36.512 Number of processors: 1 586 0x209 08:52:36.512 ComputerName: DDHFR351 UserName: Tracy 08:52:39.215 Initialize success 08:56:26.278 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 08:56:26.278 Disk 0 Vendor: WDC_WD800BB-75FJA1 14.03G14 Size: 76293MB BusType: 3 08:56:26.465 Disk 0 MBR read successfully 08:56:26.465 Disk 0 MBR scan 08:56:26.465 Disk 0 Windows XP default MBR code 08:56:26.465 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 31 MB offset 63 08:56:26.465 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 76253 MB offset 64260 08:56:26.481 Disk 0 scanning sectors +156232125 08:56:26.762 Disk 0 scanning C:\WINDOWS\system32\drivers 08:56:48.809 Service scanning 08:57:32.668 Modules scanning 08:57:57.887 Disk 0 trace - called modules: 08:57:58.059 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys 08:57:58.075 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a823ab8] 08:57:58.106 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a7f7d98] 08:57:58.106 Scan finished successfully 08:58:19.075 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Tracy\Desktop\MBR.dat" 08:58:19.090 The log file has been saved successfully to "C:\Documents and Settings\Tracy\Desktop\aswMBR.txt" aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-08-22 09:32:46 —————————– 09:32:46.825 OS Version: Windows 5.1.2600 Service Pack 3 09:32:46.825 Number of processors: 1 586 0x209 09:32:46.825 ComputerName: DDHFR351 UserName: Tracy 09:32:47.622 Initialize success 09:35:22.465 AVAST engine defs: 13082200 09:35:26.231 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 09:35:26.231 Disk 0 Vendor: WDC_WD800BB-75FJA1 14.03G14 Size: 76293MB BusType: 3 09:35:26.512 Disk 0 MBR read successfully 09:35:26.512 Disk 0 MBR scan 09:35:26.559 Disk 0 Windows XP default MBR code 09:35:26.575 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 31 MB offset 63 09:35:26.606 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 76253 MB offset 64260 09:35:26.637 Disk 0 scanning sectors +156232125 09:35:26.997 Disk 0 scanning C:\WINDOWS\system32\drivers 09:35:57.293 Service scanning 09:36:54.653 Modules scanning 09:37:18.418 Disk 0 trace - called modules: 09:37:18.465 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 09:37:18.465 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a823ab8] 09:37:18.481 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a7f7d98] 09:37:18.981 AVAST engine scan C:\WINDOWS 09:37:33.543 AVAST engine scan C:\WINDOWS\system32 09:45:02.497 AVAST engine scan C:\WINDOWS\system32\drivers 09:45:40.856 AVAST engine scan C:\Documents and Settings\Tracy 09:46:31.934 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Tracy\Desktop\MBR.dat" 09:46:31.965 The log file has been saved successfully to "C:\Documents and Settings\Tracy\Desktop\aswMBR.txt" Thank you tletch
Not a problem. :)

Please read through these instructions to familiarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================

Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications

====================================================


Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
Hi Conspire, I have been having a horrible time. I tried to disable my Norton Security Suite, just after downloading Combo Fix so I could run it. It did not work, and I got a message from Combo fix that my antivirus was preventing it from working and to disable it. I did a remote session with a technician (from Norton/Comcast) and she removed my old version and reinstalled a new version. I lost communication with her so once it was installed again I did another remote session with a differnt technician. At that point we did disable it, but then when I tried to open Word to copy and paste how to get it working again based on what I did to disable it well I got a message that Word needed to be installed. I don't understand what is happening, and now I can't even get to the internet on that computer at all. So, it looks like I will have to reinstall my Microsoft. I even tried a system restore before I discovered that I can't get to the internet and now I am working on my laptop that also needed to go through a system restore. Looks like I need to update my AVG on this thing and I dont' want to update Java because last time I did when I typed in the letter u it typed in a four. Oh, my gosh I am beat. Any suggestions. I don't even see system restore any more under accessories/MSFT Thank you. tletch
Try booting your computer in safe mode and run ComboFix from there.

Reboot your computer in Safe Mode
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
Tutorial if you need it How to boot into Safemode
Hi I am back. I tried a different restore point; the one created by Old timer I used to first submit here. (OTS) thankfully it created a restore point. So, I guess I got the Internet back and MSFT too. I will use Combo fix tomorrow I am beat. Thanks for the suggestion to reboot using F8. I have done that before, but didn't think to use it and run Combo fix. Obviously I am infected and will need to run the programs you suggested after I disable Norton though. I won't be updating that program until I fix what's wrong though. Thanks for hanging with me. I really appreciate your help I will submit my results tomorrow. G nite tletch
Hi I copied and read the instructions for Combo fix and emailed them to myself just in case. I used Revo uninstaller to uninstall Norton. I tried using combo fix, but a message came up that Norton is still a problem. I don't know what to do it's not listed in all programs nor does it show in Revo. I would like to use Combo fix but it said it's not advisable to use it in safe mode. Please when time permits let me know what I should do. Thank you. tletch
Hi Conspire,
here is the results of my Combo fix scan.
I can not open up word now though just like before so I think I need to use the Microsoft Reco very Console.
I had one already installed, but it had to update.

Since I can't open word and probably the Internet either I am on laptop and used flash drive to copy paste log results.

thanks so much for your help I don't know what to do next

ComboFix 13-08-22.01 - Tracy 08/23/2013 11:32:53.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1538 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\GoToAssistDownloadHelper.exe
c:\documents and settings\All Users\Application Data\AMMYY
c:\documents and settings\All Users\Application Data\AMMYY\hr
c:\documents and settings\All Users\Application Data\AMMYY\hr3
c:\documents and settings\All Users\Application Data\AMMYY\settings3.bin
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\dell\Application Data\Toolbar4
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\ar.exe
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\basis.xml
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\cache\b1029ae9a6f423d36ca3b209caa52348
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\CCleaner.exe
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\FreeFTP.exe
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\icons.bmp
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\info.txt
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\Resize.exe
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\tbcore3
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\TbHelper2.exe
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\uninstall.exe
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\uninstaller.exe
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\update.exe
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\version.txt
c:\documents and settings\dell\Application Data\Toolbar4\{3E9211B0-D7C7-4B3F-AD07-D8ABA53426E4}\your_logo.png
c:\documents and settings\Tracy\Application Data\PriceGong
c:\documents and settings\Tracy\Application Data\PriceGong\Data\1.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\2229.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\4489.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\450.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\a.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\b.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\c.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\d.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\e.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\f.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\g.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\gc.log
c:\documents and settings\Tracy\Application Data\PriceGong\Data\h.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\i.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\j.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\k.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\l.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\m.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\n.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\o.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\p.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\q.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\r.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\s.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\t.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\u.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\v.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\w.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\wlu.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\x.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\y.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Tracy\Application Data\PriceGong\Data\z.txt
c:\documents and settings\Tracy\Application Data\PriceGong\Data\z.xml
c:\documents and settings\Tracy\g2mdlhlpx.exe
c:\documents and settings\Tracy\GoToAssistDownloadHelper.exe
c:\documents and settings\Tracy\Local Settings\Application Data\assembly\tmp
c:\documents and settings\Tracy\System
c:\documents and settings\Tracy\System\win_qs8.jqx
c:\documents and settings\Tracy\WINDOWS
c:\program files\Fast Browser Search
c:\program files\Fast Browser Search\basis_es.xml
c:\program files\Fast Browser Search\basis_fr.xml
c:\program files\Fast Browser Search\basis_it.xml
c:\program files\Fast Browser Search\basis_nr.xml
c:\program files\Fast Browser Search\basis_pt.xml
c:\program files\Fast Browser Search\basis_ru.xml
c:\program files\Fast Browser Search\basis_tr.xml
c:\program files\Fast Browser Search\BHO.dll
c:\program files\Fast Browser Search\ClearRecycleBin.exe
c:\program files\Fast Browser Search\error.html
c:\program files\Fast Browser Search\FBSPlugin.dll
c:\program files\Fast Browser Search\fbsProtection.xml
c:\program files\Fast Browser Search\FbsSearchProvider.xml
c:\program files\Fast Browser Search\FbsSearchProviderIE8.exe
c:\program files\Fast Browser Search\FBStoolbar.dll
c:\program files\Fast Browser Search\fbstoolbar.jar
c:\program files\Fast Browser Search\fbstoolbar.manifest
c:\program files\Fast Browser Search\icons.bmp
c:\program files\Fast Browser Search\IE\basis.xml
c:\program files\Fast Browser Search\IE\fbsSearchProvider.xml
c:\program files\Fast Browser Search\IE\search_es.bmp
c:\program files\Fast Browser Search\IE\search_fr.bmp
c:\program files\Fast Browser Search\IE\search_it.bmp
c:\program files\Fast Browser Search\IE\search_pt.bmp
c:\program files\Fast Browser Search\IE\search_ru.bmp
c:\program files\Fast Browser Search\IE\SearchAssistant.dll
c:\program files\Fast Browser Search\IE\SearchGuardPlus.ico
c:\program files\Fast Browser Search\IE\SGPU.ico
c:\program files\Fast Browser Search\IE\sgpUpdater.exe
c:\program files\Fast Browser Search\IE\sgpUpdater.xml
c:\program files\Fast Browser Search\IE\SGPUpdaterS.exe
c:\program files\Fast Browser Search\IE\tbhelper.dll
c:\program files\Fast Browser Search\IE\tbs_include_script_003175.js
c:\program files\Fast Browser Search\IE\tbs_include_script_005064.js
c:\program files\Fast Browser Search\IE\tbs_include_script_012817.js
c:\program files\Fast Browser Search\IE\Toolbar Help.htm
c:\program files\Fast Browser Search\IE\ToolBarBHO.dll
c:\program files\Fast Browser Search\IE\uninstall.exe
c:\program files\Fast Browser Search\IE\uninstalSGP.exe
c:\program files\Fast Browser Search\IE\uninstalSGPU.exe
c:\program files\Fast Browser Search\info.txt
c:\program files\Fast Browser Search\local.xml
c:\program files\Fast Browser Search\logobg.bmp
c:\program files\Fast Browser Search\MTWBtoolbar.html
c:\program files\Fast Browser Search\search.bmp
c:\program files\Fast Browser Search\search_br.bmp
c:\program files\Fast Browser Search\search_de.bmp
C:\reg.reg
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\_000012_.tmp.dll
c:\windows\system32\_005115_.tmp.dll
c:\windows\system32\_005116_.tmp.dll
c:\windows\system32\_005117_.tmp.dll
c:\windows\system32\_005118_.tmp.dll
c:\windows\system32\_005125_.tmp.dll
c:\windows\system32\_005126_.tmp.dll
c:\windows\system32\_005127_.tmp.dll
c:\windows\system32\_005129_.tmp.dll
c:\windows\system32\_005130_.tmp.dll
c:\windows\system32\_005133_.tmp.dll
c:\windows\system32\_005134_.tmp.dll
c:\windows\system32\_005136_.tmp.dll
c:\windows\system32\_005137_.tmp.dll
c:\windows\system32\_005138_.tmp.dll
c:\windows\system32\_005140_.tmp.dll
c:\windows\system32\_005141_.tmp.dll
c:\windows\system32\_005142_.tmp.dll
c:\windows\system32\_005143_.tmp.dll
c:\windows\system32\_005144_.tmp.dll
c:\windows\system32\_005148_.tmp.dll
c:\windows\system32\_005149_.tmp.dll
c:\windows\system32\_005151_.tmp.dll
c:\windows\system32\_005154_.tmp.dll
c:\windows\system32\_005156_.tmp.dll
c:\windows\system32\_005157_.tmp.dll
c:\windows\system32\_005158_.tmp.dll
c:\windows\system32\_005159_.tmp.dll
c:\windows\system32\_005163_.tmp.dll
c:\windows\system32\_005164_.tmp.dll
c:\windows\system32\_005165_.tmp.dll
c:\windows\system32\_005166_.tmp.dll
c:\windows\system32\_005171_.tmp.dll
c:\windows\system32\_005173_.tmp.dll
c:\windows\system32\_005174_.tmp.dll
c:\windows\system32\CNCUPM2K.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_FAD
.
.
((((((((((((((((((((((((( Files Created from 2013-07-23 to 2013-08-23 )))))))))))))))))))))))))))))))
.
.
2013-08-23 18:09 . 2013-08-23 18:09 142484430 -c–a-w- C:\backup.reg
2013-08-23 08:20 . 2013-08-23 08:20 ——– d—–w- c:\windows\system32\wbem\Repository
2013-08-23 08:06 . 2013-08-23 08:18 ——– d—–w- c:\program files\Mozilla Maintenance Service
2013-08-23 05:11 . 2013-08-23 08:18 ——– d—–w- c:\windows\system32\drivers\N360\1401000.018
2013-08-23 05:10 . 2013-08-23 08:18 ——– d—–w- c:\program files\NortonInstaller(2)
2013-08-06 01:10 . 2013-08-06 01:10 ——– d—–w- c:\documents and settings\Tracy\Local Settings\Application Data\IAC
2013-08-06 00:51 . 2013-08-06 00:51 ——– d—–w- c:\documents and settings\All Users\Application Data\VS Revo Group
2013-08-03 15:09 . 2013-08-03 15:09 40776 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2013-07-25 05:34 . 2013-07-25 05:34 ——– d—–w- c:\documents and settings\Tracy\.swt
2013-07-25 05:32 . 2013-07-26 06:42 ——– d—–w- c:\documents and settings\Tracy\Application Data\Azureus
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2006-11-05 07:13 . 2006-11-05 07:11 21290704 —-a-w- c:\program files\AdbeRdr708_en_US.exe
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-14 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netman.dll
[-] 2005-08-22 . 36739B39267914BA69AD0610A0299732 . 197632 . . [5.1.2600.2743] . . c:\windows\$NtServicePackUninstall$\netman.dll
[-] 2005-08-22 . 36739B39267914BA69AD0610A0299732 . 197632 . . [5.1.2600.2743] . . c:\windows\SYSTEM32\netman.dll
[-] 2005-08-22 . 3516D8A18B36784B1005B950B84232E1 . 197632 . . [5.1.2600.2743] . . c:\windows\$hf_mig$\KB905414\SP2QFE\netman.dll
[-] 2004-03-19 . E7FF9267BBEB1386975278A27378526F . 154112 . . [5.1.2600.1106] . . c:\windows\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\netman.dll
.
[7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe
[-] 2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2GDR\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\SYSTEM32\spoolsv.exe
[-] 2004-03-19 . 9B4155BA58192D4073082B8FC5D42612 . 51200 . . [5.1.2600.0] . . c:\windows\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\spoolsv.exe
.
[7] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\linkinfo.dll
[-] 2005-09-01 . 648BF0B4DDE4F7A1156DAE7174D36EFA . 19968 . . [5.1.2600.2751] . . c:\windows\$hf_mig$\KB900725\SP2QFE\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\$NtServicePackUninstall$\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\SYSTEM32\linkinfo.dll
[-] 2004-08-20 . 9989FF9505C69E6F2D7C6EFC7A1C01A2 . 15872 . . [5.1.2600.1579] . . c:\windows\SoftwareDistribution\Download\95cf6eb04c28d6c2d66103e61d5c5b6d\sp1qfe\linkinfo.dll
[-] 2004-03-19 . 7D8C58C0CBB7331E9296A7357827CA8E . 15360 . . [5.1.2600.0] . . c:\windows\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\linkinfo.dll
.
[7] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tapisrv.dll
[-] 2005-07-08 . 1418A3A6E76E5A2E3F5E43866E793A8B . 249344 . . [5.1.2600.2716] . . c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\$hf_mig$\KB893756\SP2GDR\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\$NtServicePackUninstall$\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\SYSTEM32\tapisrv.dll
[-] 2004-03-19 . 9B3A213B6591A79EBABBFB4E4EA0A23E . 233984 . . [5.1.2600.1106] . . c:\windows\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\tapisrv.dll
.
[7] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
[-] 2007-03-08 . 7AA4F6C00405DFC4B70ED4214E7D687B . 578048 . . [5.1.2600.3099] . . c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
[-] 2007-03-08 . B409909F6E2E8A7067076ED748ABF1E7 . 577536 . . [5.1.2600.3099] . . c:\windows\$NtServicePackUninstall$\user32.dll
[-] 2007-03-08 . B409909F6E2E8A7067076ED748ABF1E7 . 577536 . . [5.1.2600.3099] . . c:\windows\SYSTEM32\user32.dll
[-] 2005-03-02 . 74202EB1BD67E8BE9509E38C8D2234B0 . 561152 . . [5.1.2600.1634] . . c:\windows\SoftwareDistribution\Download\93c9bb5898f80e6361e0dc6ea165864f\sp1qfe\user32.dll
[-] 2005-03-02 . 1800F293BCCC8EDE8A70E12B88D80036 . 577024 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
[-] 2005-03-02 . 1800F293BCCC8EDE8A70E12B88D80036 . 577024 . . [5.1.2600.2622] . . c:\windows\SoftwareDistribution\Download\93c9bb5898f80e6361e0dc6ea165864f\sp2qfe\user32.dll
[-] 2005-03-02 . DE2DB164BBB35DB061AF0997E4499054 . 577024 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2GDR\user32.dll
[-] 2005-03-02 . DE2DB164BBB35DB061AF0997E4499054 . 577024 . . [5.1.2600.2622] . . c:\windows\SoftwareDistribution\Download\93c9bb5898f80e6361e0dc6ea165864f\sp2gdr\user32.dll
[-] 2004-12-29 . 0706E1CD6B89800781DB038F4B3F5654 . 574464 . . [5.1.2600.1617] . . c:\windows\SoftwareDistribution\Download\8a4341850daecfe5fcade73622025bbf\sp1qfe\user32.dll
[-] 2004-06-17 . 31FB2D788A9AA618452C02E8375B6DCD . 560128 . . [5.1.2600.1561] . . c:\windows\SoftwareDistribution\Download\cf113cf67754a276d1983478748b20da\sp1qfe\user32.dll
[-] 2004-06-17 . 31FB2D788A9AA618452C02E8375B6DCD . 560128 . . [5.1.2600.1561] . . c:\windows\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\user32.dll
.
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2007-06-13 . 7712DF0CDDE3A5AC89843E61CD5B3658 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[-] 2004-03-19 . A82B28BFC2E4455FE43022A498C0EF0A . 1004032 . . [6.00.2800.1106] . . c:\windows\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\explorer.exe
.
[7] 2008-04-14 . ECCE74BC6168375016450A86A164D976 . 1287168 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ole32.dll
[-] 2005-07-26 . AB8231D13692AC5088EB9C226B0C0576 . 1285120 . . [5.1.2600.2726] . . c:\windows\$NtServicePackUninstall$\ole32.dll
[-] 2005-07-26 . AB8231D13692AC5088EB9C226B0C0576 . 1285120 . . [5.1.2600.2726] . . c:\windows\SYSTEM32\ole32.dll
[-] 2005-07-26 . A2F755E237FA2CDD748A80BFBE6657F3 . 1285632 . . [5.1.2600.2726] . . c:\windows\$hf_mig$\KB902400\SP2QFE\ole32.dll
[-] 2005-04-28 . 7440D29F257B7E44329343F944F2142C . 1286144 . . [5.1.2600.2665] . . c:\windows\$hf_mig$\KB894391\SP2QFE\ole32.dll
[-] 2005-01-14 . ABDEF60CED7C04AB35A415EFB6B96D81 . 1285120 . . [5.1.2600.2595] . . c:\windows\$hf_mig$\KB873333\SP2GDR\ole32.dll
[-] 2005-01-14 . 2E752611C9A9AE1B6BFD0DA03CF7F17E . 1284608 . . [5.1.2600.2595] . . c:\windows\$hf_mig$\KB873333\SP2QFE\ole32.dll
[-] 2004-03-06 . D651E85D49FE38C8B98A62ED1392FF40 . 1183744 . . [5.1.2600.1362] . . c:\windows\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\ole32.dll
.
[7] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\shsvcs.dll
[-] 2006-12-19 . 6815DEF9B810AEFAC107EEAF72DA6F82 . 134656 . . [6.00.2900.3051] . . c:\windows\$NtServicePackUninstall$\shsvcs.dll
[-] 2006-12-19 . 6815DEF9B810AEFAC107EEAF72DA6F82 . 134656 . . [6.00.2900.3051] . . c:\windows\SYSTEM32\shsvcs.dll
[-] 2006-12-19 . 53D9184A21C5CBF600D918E51EF3A7E5 . 135168 . . [6.00.2900.3051] . . c:\windows\$hf_mig$\KB928255\SP2QFE\shsvcs.dll
[-] 2004-10-28 . AD324E21EF7E668C9910EB5ADF6495C0 . 116736 . . [6.00.2800.1605] . . c:\windows\SoftwareDistribution\Download\c9057d3faf4a326a2fefff7bde9fec31\sp1qfe\shsvcs.dll
[-] 2004-03-19 . 61684089A54936E40F65DA02D47A28AE . 116224 . . [6.00.2800.1106] . . c:\windows\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\shsvcs.dll
.
[7] 2008-04-14 . 8BAD69CBAC032D4BBACFCE0306174C30 . 333824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wiaservc.dll
[-] 2006-12-19 . D9F097AA3B97034D3358A01B43E635B2 . 333824 . . [5.1.2600.3051] . . c:\windows\$hf_mig$\KB927802\SP2QFE\wiaservc.dll
[-] 2006-12-19 . B6763F8534AC547CF1AF98AFDFF2EDC8 . 333824 . . [5.1.2600.3051] . . c:\windows\$NtServicePackUninstall$\wiaservc.dll
[-] 2006-12-19 . B6763F8534AC547CF1AF98AFDFF2EDC8 . 333824 . . [5.1.2600.3051] . . c:\windows\SYSTEM32\wiaservc.dll
[-] 2004-03-19 . 0AC40B75640B550C26347B5F65F6E0EE . 316416 . . [5.1.2600.1106] . . c:\windows\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\wiaservc.dll
.
[7] 2008-04-14 . 6F9BEF24C578D5D6740E080BEDD6A448 . 7680 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rasadhlp.dll
[-] 2006-06-26 . B5D08C96B2DADAF5171FB69E341B272B . 7680 . . [5.1.2600.2938] . . c:\windows\$hf_mig$\KB920683\SP2QFE\rasadhlp.dll
[-] 2006-06-26 . 5F098BD2AE6B03044B085DECFFDF91EC . 8192 . . [5.1.2600.2938] . . c:\windows\$NtServicePackUninstall$\rasadhlp.dll
[-] 2006-06-26 . 5F098BD2AE6B03044B085DECFFDF91EC . 8192 . . [5.1.2600.2938] . . c:\windows\SYSTEM32\rasadhlp.dll
[-] 2004-03-19 . C5ABBBD9C7307679B4FBA203213A6FD4 . 6144 . . [5.1.2600.0] . . c:\windows\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\backup\rasadhlp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{3DFCDCA1-AEAC-4302-A690-BFB683568BAA}]
2013-01-15 22:30 328072 —-a-w- c:\program files\DigitalAdvertisingAlliance\Protect My Choices\pmc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2013-02-06 00:18 1020424 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2013-02-06 00:18 1020424 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2013-02-06 00:18 1020424 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-06-27 23:11 579024 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-06-27 23:11 579024 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-06-27 23:11 579024 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-06-27 23:11 579024 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-06-27 23:11 579024 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-06-27 23:11 579024 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\Tracy\Application Data\mjusbsp\cdloader2.exe" [2012-02-01 50592]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DNS7reminder"="c:\program files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" [2007-04-16 259624]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-06 421888]
"iYogi Support Dock"="c:\program files\iYogi Support Dock\iYogiSupportDock.exe" [2012-09-18 2303904]
"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2013-02-06 1065480]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"{91120000-0014-0000-0000-0000000FF1CE}"="del" [X]
"{91120000-002E-0000-0000-0000000FF1CE}"="del" [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0\0\0\0_? \0\0a? \0.\0????????\0sasnative32
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-07 06:46 57344 -c–a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bomgar Support Reconnect [1354495352]]
2012-01-27 16:01 916392 —-a-w- c:\documents and settings\All Users\Application Data\iyogi-scc-50BBF401\iyogi-scc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2012-02-01 17:36 50592 —-a-w- c:\documents and settings\Tracy\Application Data\mjusbsp\cdloader2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 07:56 15360 —-a-w- c:\windows\SYSTEM32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
2007-11-15 17:23 202544 -c–a-w- c:\program files\Dell Support Center\bin\sprtcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iYogi Support Dock]
2012-09-18 07:19 2303904 —-a-w- c:\program files\iYogi Support Dock\iYogiSupportDock.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-06 01:36 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\NewSoft\\Presto! PageManager 6\\NetGroup.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\Tracy\\Application Data\\mjusbsp\\magicJack.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"51001:TCP"= 51001:TCP:Dragon Smart Phone Server
.
R1 archlp;archlp;c:\windows\SYSTEM32\DRIVERS\ArcHlp.sys [9/22/2012 11:06 PM 127744]
R2 IYSODiskOptimizer;IYSODiskOptimizer;c:\program files\iYogi Support Dock\pccare\iysoDefragSrv.exe [11/30/2011 11:33 AM 263168]
R2 npf;NetGroup Packet Filter Driver;c:\windows\SYSTEM32\DRIVERS\npf.sys [2/11/2011 2:23 PM 35088]
R2 SupportDockService.exe;Support Dock Service;c:\program files\iYogi Support Dock\Services\CommAgent\SupportDockService.exe [9/4/2012 4:51 AM 78336]
R3 ArcCD;ArcCD Filter Driver Service;c:\windows\SYSTEM32\DRIVERS\ArcCD.sys [9/22/2012 11:06 PM 36224]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS –> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys –> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S2 iyogi-scc-1358313302;iYogi Support Client [1358313302];"c:\documents and settings\All Users\Application Data\iyogi-scc-50F63756\iyogi-scc.exe" -service:run –> c:\documents and settings\All Users\Application Data\iyogi-scc-50F63756\iyogi-scc.exe [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys [8/3/2013 8:09 AM 40776]
S3 pbfilter;pbfilter;\??\c:\program files\PeerBlock\pbfilter.sys –> c:\program files\PeerBlock\pbfilter.sys [?]
S3 PulseUsb;Livescribe Smartpen USB Driver;c:\windows\SYSTEM32\DRIVERS\PulseUsb.sys [10/27/2010 11:59 AM 20480]
S3 Revoflt;Revoflt;c:\windows\SYSTEM32\DRIVERS\revoflt.sys [6/27/2011 2:06 PM 27064]
S3 ssmirrdr;ssmirrdr;c:\windows\SYSTEM32\DRIVERS\ssmirrdr.sys [9/22/2010 5:52 AM 10112]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\SYSTEM32\DRIVERS\wdcsam.sys [5/6/2008 5:06 PM 11520]
S4 ADExchange;ArcSoft Exchange Service;c:\program files\Common Files\ArcSoft\esinter\Bin\eservutil.exe –> c:\program files\Common Files\ArcSoft\esinter\Bin\eservutil.exe [?]
S4 ArcUdfs;ArcUdfs FileSystem Driver Service;c:\windows\SYSTEM32\DRIVERS\ArcUdfs.sys [9/22/2012 11:06 PM 134912]
S4 DragonSvc;Dragon Service;c:\program files\Common Files\Nuance\dgnsvc.exe [7/23/2010 1:24 PM 296808]
S4 PenCommService;Livescribe Pulse Smartpen Service;c:\program files\Common Files\Livescribe\PenComm\PenCommService.exe [8/11/2011 4:03 PM 470528]
S4 SDiManage;SDiManage;c:\program files\SDC\SDiManage\IYogiMonitoringSvc.exe [9/5/2012 12:23 PM 25048]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - ArcRec
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-03-17 20:14 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-08-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 20:01]
.
2013-08-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-02 00:57]
.
2013-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-11-12 20:02]
.
2013-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-11-12 20:02]
.
2013-08-18 c:\windows\Tasks\IYSO-IYSODiskOptimizer.job
- c:\program files\iYogi Support Dock\pccare\iysoDiskOptimizer.exe [2011-11-30 00:35]
.
2013-08-18 c:\windows\Tasks\IYSO-IYSOOneClickCare.job
- c:\program files\iYogi Support Dock\pccare\iyso.exe [2011-11-30 00:35]
.
2013-08-18 c:\windows\Tasks\IYSO-IYSOPrivacyProtector.job
- c:\program files\iYogi Support Dock\pccare\iysoPrivacyProtector.exe [2011-11-30 00:35]
.
2013-08-17 c:\windows\Tasks\IYSO-IYSORegistryCleaner.job
- c:\program files\iYogi Support Dock\pccare\iysoRegClean.exe [2011-11-30 00:34]
.
2013-08-17 c:\windows\Tasks\IYSO-IYSORegistryOptimizer.job
- c:\program files\iYogi Support Dock\pccare\iysoRegistryOptimizer.exe [2011-11-30 00:34]
.
2013-08-18 c:\windows\Tasks\IYSO-IYSOSystemCleaner.job
- c:\program files\iYogi Support Dock\pccare\iysoSystemCleaner.exe [2011-11-30 00:34]
.
2013-08-23 c:\windows\Tasks\User_Feed_Synchronization-{163BEBF5-21BC-458F-A016-A747DECFA5D3}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 12:31]
.
2013-08-22 c:\windows\Tasks\User_Feed_Synchronization-{D4373AF6-61AF-41F4-B911-DBFA37C2838B}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 12:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = https://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: clonewarsadventures.com
Trusted Zone: download.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Tracy\Application Data\Mozilla\Firefox\Profiles\m3exjy1b.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3287822&CUI;=UN20841189803632180&UM;=2&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://search.yahoo.com?type=994519&fr;=spigot-yhp-ff
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&ilc;=12&type;=994519&p;=
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - 7c07ccf1000000000000000f1f59742b
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15831
FF - user.js: extensions.delta.vrsn - [removed]
FF - user.js: extensions.delta.vrsni - [removed]
FF - user.js: extensions.delta.vrsnTs - [removed]:39
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKCU-Run-CB453CAA6E1138CBF54EDB4C92B9390591ABCBF6._service_run - c:\program files\Google\Chrome\Application\chrome.exe
AddRemove-PC TuneUp Maestro - c:\program files\CompuClever\PC TuneUp Maestro\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-08-23 11:59
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet006\Services\iyogi-scc-1358313302]
"ImagePath"="\"c:\documents and settings\All Users\Application Data\iyogi-scc-50F63756\iyogi-scc.exe\" -service:run"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,be,61,18,ac,9e,da,03,41,82,6c,ac,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,be,61,18,ac,9e,da,03,41,82,6c,ac,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Toolbar\QuickComplete]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
@DACL=(02 0000)
"Asynchronous"=dword:00000001
"DllName"=expand:"%SystemRoot%\\System32\\dimsntfy.dll"
"Startup"="WlDimsStartup"
"Shutdown"="WlDimsShutdown"
"Logon"="WlDimsLogon"
"Logoff"="WlDimsLogoff"
"StartShell"="WlDimsStartShell"
"Lock"="WlDimsLock"
"Unlock"="WlDimsUnlock"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
@DACL=(02 0000)
"Logon"="WLEventLogon"
"Logoff"="WLEventLogoff"
"Startup"="WLEventStartup"
"Shutdown"="WLEventShutdown"
"StartScreenSaver"="WLEventStartScreenSaver"
"StopScreenSaver"="WLEventStopScreenSaver"
"Lock"="WLEventLock"
"Unlock"="WLEventUnlock"
"StartShell"="WLEventStartShell"
"PostShell"="WLEventPostShell"
"Disconnect"="WLEventDisconnect"
"Reconnect"="WLEventReconnect"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000000
"SafeMode"=dword:00000001
"MaxWait"=dword:ffffffff
"DllName"=expand:"WgaLogon.dll"
"Event"=dword:00000002
"InstallEvent"="1.9.0040.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(2108)
c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
c:\program files\Google\Drive\googledrivesync32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\EPSON\EBAPI\eEBSVC.exe
c:\program files\Carbonite\Carbonite Backup\carboniteservice.exe
c:\windows\system32\fxssvc.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\Google\Update\1.3.21.153\GoogleCrashHandler.exe
c:\windows\System32\vssvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2013-08-23 12:06:45 - machine was rebooted
ComboFix-quarantined-files.txt 2013-08-23 19:06
.
Pre-Run: 38,658,744,320 bytes free
Post-Run: 38,844,092,416 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 016435D244342CCAC372E15C7410099F
8F558EB6672622401DA993E1E865C861
Hi Conspire, As you know I completed combo fix, but now I can't access Windows word, and other programs. I guess I need to know what to do next like how to use the recovery tools (forgot what they are called). Thank you, Tracy
Hi Tracy,

Your computer appears to be heavily infected. Therefore, I would consider to not touch other programs as of now while we try to get rid of the infections.

Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin…be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button…a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

===================================================

Please download Junkware Removal Tool to your desktop.
  • Shutdown your antivirus to avoid any conflicts.
  • Right-mouse click JRT.exe and select Run as administrator
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message
===================================================

On your next reply please post :
AdwCleaner log
JRT log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.
Hi Conspire, Yes, I guess I am heavily infected. I will follow the instructions for the two programs and again copy the results to my flash drive and copy/paste them into my next post. I can only do one tonight and tomorrow the other, but right now my Norton was ininstalled so processes will be easier. Thank goodness I got laptop up (system restore) and my antivirus on that is okay. Thanks for all your help and support. tletch

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI