This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Painfully slow computer, can't get any work done - spyware? [Close

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My system is chugging really bad, I'm about to delete my kids' user accounts because it seems to have gotten worse as they use my computer more. They are playing Minecraft, Wizard101 and Pirate101 games - sometimes games they find from clicking on advertisements. Not good!

I'll be in the middle of an email in Outlook and it will take minutes between words just to type an email and the program either goes "no response" or crashes on me. I use Firefox primarily, but when I open IE, it crashes a lot.

I ran a program called SuperAntiSpyware Free Edition - it found hundreds of threats and quarantined them. Not sure if I should release those and uninstall the product - it got good reviews from some friends so I tried it.

Twice, I have found a black screen when I start up my computer. I am attaching 2 pictures of what that looks like.

My hijackthis log….

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:02:46 PM, on 9/5/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe
C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files (x86)\Intuit\QuickBooks 2013\QBW32.EXE
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Sonja\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.expectnothing.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pctools.com/mrc/fix_homepage/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: PC Tools Browser Defender - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ÿþ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: RoboForm BHO - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Fast Free Converter 3.0 - {B75A1838-7232-4D19-9E57-C85F4A6D4193} - C:\PROGRA~2\FASTFR~1\FASTFR~1\FASTFR~1.DLL
O2 - BHO: Define - {B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE} - C:\Users\Jared\AppData\Local\DefineExt\temp.dat
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: PC Tools Browser Defender - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [PCTools FGuard] C:\Program Files (x86)\Spyware Doctor\BDT\FGuard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Garmin Lifetime Updater] C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Intuit Data Protect.lnk = C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: QuickBooks_Standard_21.lnk = C:\Program Files (x86)\Intuit\QuickBooks 2013\QBW32.EXE
O8 - Extra context menu item: Customize Menu - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {62AEFF80-16AD-4AC4-B812-E70EB5F37301} (Zenfolio Uploader) - http://www.zenfolio.com/zf/code/upload-ie-win-x86.cab
O18 - Protocol: intu-help-qb6 - {6898B29B-BF49-43CB-A0B1-D0B9496AF491} - C:\Program Files (x86)\Intuit\QuickBooks 2013\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: McAfee Application Installer Cleanup (0306111279741561) (0306111279741561mcinstcleanup) - Unknown owner - C:\Users\Sonja\AppData\Local\Temp\030611~1.EXE (file missing)
O23 - Service: Adobe Active File Monitor V11 (AdobeActiveFileMonitor11.0) - Adobe Systems Incorporated - C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: FastFreeConverterUpdt - Unknown owner - C:\Program Files (x86)\Fast Free Converter\FastFreeConverterUpdt.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GManager - Unknown owner - C:\Windows\system32\GManager.exe (file missing)
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: MCTDesktopSvr - Unknown owner - C:\Program Files (x86)\Common Files\DesktopUtil\MCTDesktopSvr.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\SysWOW64\nlssrv32.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QBIDPService (QBVSS) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files (x86)\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files (x86)\Spyware Doctor\TFEngine\TFService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 18769 bytes
Hi and Welcome!! Sonja27 :)

My name is Robybel.

I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! ;)

==================================

Scan with OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true /fp
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.

=============================== Next =======================================


Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

On your next reply please post :
  • OTL.txt
  • Extras.txt
  • aswMBR log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
OTL report….

OTL logfile created on: 9/7/2013 10:34:37 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Sonja\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.96 Gb Total Physical Memory | 4.07 Gb Available Physical Memory | 68.25% Memory free
11.92 Gb Paging File | 9.51 Gb Available in Paging File | 79.83% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 921.59 Gb Total Space | 91.66 Gb Free Space | 9.95% Space Free | Partition Type: NTFS

Computer Name: SONJA-PC | User Name: Sonja | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Sonja\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
PRC - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
PRC - C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\DesktopUtil\MCTDUtil.exe (Magic Control Technology Corporation)
PRC - C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Windows\SysWOW64\nlssrv32.exe (Nalpeiron Ltd.)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\DesktopUtil\MCTDesktopSvr.exe ()
PRC - C:\Program Files (x86)\Common Files\DesktopUtil\FDispPos.exe (Magic Control Technology Corporation)
PRC - C:\Program Files (x86)\Photodex\ProShowGold\scsiaccess.exe ()
PRC - C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\a379b2e18ccf462ff63e86ee309c600b\System.WorkflowServices.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\b26c0ed378c4b15c60cef0baada4e0dc\System.ServiceModel.Routing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\ebf949aee7febad1902974b1a2bd77a2\System.ServiceModel.Discovery.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\800370766976fd4ec232b4e29781717d\System.ServiceModel.Channels.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\b15622741724e17f1335c4771c3700a0\System.ServiceModel.Activities.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\c1b67737c13c99776cde5989ec2885c8\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\a0445401f2473a1aa4b66c9c0791c7f6\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\9714573400d1d3724808c63f1fd6de83\System.ServiceModel.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\dcb0e7d56ffca14d7c483103235b11ad\System.Transactions.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\e7b4706dfe18f29486dbaf5d35e01765\System.Runtime.DurableInstancing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\ef7642a4f2724135d445e2ea36582e78\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\910fe53ec2122cf3a2ad11c2b2f5cbfd\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\d01a925ecd339eae8ea1da8488eb2283\System.Xml.Linq.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\866894ebe5258bf9f45d6b063229e990\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\dea60259d636ef6ee0378b35b8472065\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\5b203b29d086eaf4a29411d6471d3d04\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\c23dd99bf24a80b1bf6e7113f244b13f\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\7d89c5b8ffbe18bda81b6e57ff897036\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f018ebe38e7f07aa8a57214c47b2d037\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\537fb59e8379373167d2df0c4ef20126\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\f01c5c76d0a19516a37b7bd191a02cda\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\14f511c47523f19ca591eb207e9e2084\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\e10fd15441d278c04a03302880a3e231\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\e43f80b6a3a40323520dd89cb77500a8\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\27dcf04ed7a3506045597c02a5a1fc31\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\dfeff31ab1e7cd3480c8942290c92f5d\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\43cd41484df96d15df949eb17dd88152\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\7a9ff5ce3a909d075179a2ac70d8f388\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b573c6a62bb88df0ee2af59b6a8ca910\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\5de5d8c1c02e33789e3cf7e3f54c0ec9\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\15872842e3e63ddf0f720f406706198e\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3f95a6d480ed1ebe45cf27b770ba94ed\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\wincfi39.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SRV:64bit: - (GManager) – C:\Windows\SysNative\GManager.exe ()
SRV:64bit: - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS64.exe (Microsoft Corporation)
SRV:64bit: - (LBTServ) – C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (QBCFMonitorService) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (N360) – C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeActiveFileMonitor11.0) – C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (QBVSS) – C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
SRV - (QBFCService) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (sdCoreService) – C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (ThreatFire) – C:\Program Files (x86)\Spyware Doctor\TFEngine\TFService.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (nlsX86cc) – C:\Windows\SysWOW64\nlssrv32.exe (Nalpeiron Ltd.)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
SRV - (MCTDesktopSvr) – C:\Program Files (x86)\Common Files\DesktopUtil\MCTDesktopSvr.exe ()
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (ScsiAccess) – C:\Program Files (x86)\Photodex\ProShowGold\scsiaccess.exe ()
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\N360x64\1404000.028\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\N360x64\1404000.028\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (PCDSRVC{D3412D80-CF3B4A27-06020200}_0) – c:\Program Files\My Dell\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\N360x64\1404000.028\symnets.sys (Symantec Corporation)
DRV:64bit: - (ccSet_N360) – C:\Windows\SysNative\drivers\N360x64\1404000.028\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\N360x64\1404000.028\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\N360x64\1404000.028\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Corel Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (mctkmd) – C:\Windows\SysNative\drivers\mctkmd64.sys (Magic Control Technology Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (pctDS) – C:\Windows\SysNative\drivers\pctDS64.sys (PC Tools)
DRV:64bit: - (pctplsg) – C:\Windows\SysNative\drivers\pctplsg64.sys (PC Tools)
DRV:64bit: - (PCTSD) – C:\Windows\SysNative\drivers\PCTSD64.sys (PC Tools)
DRV:64bit: - (pctgntdi) – C:\Windows\SysNative\drivers\pctgntdi64.sys (PC Tools)
DRV:64bit: - (TFSysMon) – C:\Windows\SysNative\drivers\TfSysMon.sys (PC Tools)
DRV:64bit: - (TfFsMon) – C:\Windows\SysNative\drivers\TfFsMon.sys (PC Tools)
DRV:64bit: - (TfNetMon) – C:\Windows\SysNative\drivers\TfNetMon.sys (PC Tools)
DRV:64bit: - (PCTCore) – C:\Windows\SysNative\drivers\PCTCore64.sys (PC Tools)
DRV:64bit: - (pctEFA) – C:\Windows\SysNative\drivers\pctEFA64.sys (PC Tools)
DRV:64bit: - (PCTBD) – C:\Windows\SysNative\drivers\PCTBD64.sys (PC Tools)
DRV:64bit: - (t1pusb64) – C:\Windows\SysNative\drivers\t1pusb64.sys (Magic Control Technology Corp.)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (mctkmdldr) – C:\Windows\SysNative\drivers\mctKmdldr64.sys (Magic Control Technology Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidEqd) – C:\Windows\SysNative\drivers\LHidEqd.sys (Logitech, Inc.)
DRV:64bit: - (LEqdUsb) – C:\Windows\SysNative\drivers\LEqdUsb.sys (Logitech, Inc.)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (k57nd60a) – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (HECIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (BVRPMPR5a64) – C:\Windows\SysNative\drivers\BVRPMPR5a64.SYS (Avanquest Software)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20130906.017\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20130906.017\eng64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\IPSDefs\20130905.001\IDSviA64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx64.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (DTC328X) – C:\Windows\SysWOW64\drivers\Dtc328x.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {FA7355B6-46D0-4D58-95A2-991C7132519F}
IE:64bit: - HKLM\..\SearchScopes\{FA7355B6-46D0-4D58-95A2-991C7132519F}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.pctools.com/mrc/fix_homepage/
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{4EECABB8-A41C-4C16-A0B5-1171D8A13AED}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {4EECABB8-A41C-4C16-A0B5-1171D8A13AED}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…eo=US&ver;=4
IE - HKCU\..\SearchScopes\{DBA4D615-4F2C-4819-BEA0-F00B2BDEA406}: "URL" = http://search.yahoo.com/search?fr=chr-gree…p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.expectnothing.com"
FF - prefs.js..extensions.enabledAddons: [removed]:1.1
FF - prefs.js..extensions.enabledAddons: [removed]:[removed]
FF - prefs.js..extensions.enabledAddons: [removed]:1.70
FF - prefs.js..extensions.enabledAddons: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.22
FF - prefs.js..extensions.enabledAddons: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:4.0.4
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.55
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:3.0.1
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.98
FF - prefs.js..extensions.enabledItems: [removed]:4.5
FF - prefs.js..extensions.enabledItems: {cb84136f-9c44-433a-9048-c5cd9df1dc16}:4.0.0.0
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:3.2
FF - prefs.js..extensions.enabledItems: {97A78363-B868-4B48-AC91-A783A31215AF}:1.0.2
FF - prefs.js..extensions.enabledItems: [removed]:1.1
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2011.7.3.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..network.proxy.type: 0


FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\Sonja\AppData\Local\Citrix\Plugins\79\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\IPSFFPlgn\ [2013/07/15 07:27:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\coFFPlgn\ [2013/09/07 09:10:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/12/06 16:01:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files (x86)\Spyware Doctor\BDT\Firefox\ [2011/11/27 20:29:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox [2011/12/07 18:43:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/01/11 22:45:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/01/11 22:45:07 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/12/06 16:01:40 | 000,000,000 | —D | M]

[2010/06/30 18:20:28 | 000,000,000 | —D | M] (No name found) – C:\Users\Sonja\AppData\Roaming\Mozilla\Extensions
[2013/06/29 12:52:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\extensions
[2013/06/29 12:52:24 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2011/09/05 08:54:27 | 000,000,000 | —D | M] (No name found) – C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}-trash
[2013/06/10 20:33:53 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/11/04 12:14:44 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/12/07 18:29:28 | 000,000,000 | —D | M] (Разпознаване на устройство Logitech) – C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\extensions\[removed]
[2011/01/16 23:26:31 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\extensions\[removed]
[2011/10/05 15:18:19 | 000,000,000 | —D | M] (TinEye Reverse Image Search) – C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\extensions\[removed]
[2011/12/07 18:29:32 | 000,221,023 | —- | M] () (No name found) – C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\extensions\[removed]
[2011/12/07 18:27:23 | 000,002,469 | —- | M] () – C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\searchplugins\safesearch.xml
[2013/06/10 20:55:16 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/02/05 09:57:23 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/12/01 16:27:03 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/11/20 21:04:51 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/10/19 16:18:49 | 000,248,192 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2011/12/01 16:26:41 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012/10/19 16:18:57 | 000,248,192 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/11/20 18:04:05 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/20 18:04:05 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2011/12/04 00:03:02 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [FDispPos] C:\Program Files (x86)\Common Files\DesktopUtil\Util-Desktop.exe ()
O4:64bit: - HKLM..\Run: [MCTDUtil] C:\Program Files (x86)\Common Files\DesktopUtil\Util-Desktop.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DATAMNGR] File not found
O4 - HKLM..\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter File not found
O4 - HKLM..\Run: [Garmin Lifetime Updater] C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized File not found
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files (x86)\Spyware Doctor\BDT\FGuard.exe File not found
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [GarminExpressTrayApp] C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKCU..\Run: [RoboForm] C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware)
O4 - HKLM..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe (Dell)
O4 - Startup: C:\Users\Sonja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Customize Menu - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8:64bit: - Extra context menu item: Fill Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8:64bit: - Extra context menu item: RoboForm Toolbar - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8:64bit: - Extra context menu item: Save Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Customize Menu - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000017 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {62AEFF80-16AD-4AC4-B812-E70EB5F37301} http://www.zenfolio.com/zf/code/upload-ie-win-x86.cab (Zenfolio Uploader)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{84A6BF92-CBBA-48E7-8E9D-BDF12193A072}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\intu-help-qb6 - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\qbwc - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\intu-help-qb6 {6898B29B-BF49-43cb-A0B1-D0B9496AF491} - C:\Program Files (x86)\Intuit\QuickBooks 2013\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{9aba7595-317f-11e1-bc26-b8ac6fa51810}\Shell - "" = AutoRun
O33 - MountPoints2\{9aba7595-317f-11e1-bc26-b8ac6fa51810}\Shell\AutoRun\command - "" = I:\KODAK_Camera_Setup_App.exe
O33 - MountPoints2\{9aba75a5-317f-11e1-bc26-b8ac6fa51810}\Shell - "" = AutoRun
O33 - MountPoints2\{9aba75a5-317f-11e1-bc26-b8ac6fa51810}\Shell\AutoRun\command - "" = I:\KODAK_Camera_Setup_App.exe
O33 - MountPoints2\{ee30505a-18df-11e0-9081-b8ac6fa51810}\Shell - "" = AutoRun
O33 - MountPoints2\{ee30505a-18df-11e0-9081-b8ac6fa51810}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/09/07 10:32:29 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Sonja\Desktop\OTL.exe
[2013/09/07 09:05:03 | 000,000,000 | -HSD | C] – C:\found.003
[2013/09/06 10:17:55 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{EEA98FA2-0997-4E61-8CA8-83AD97504D32}
[2013/09/05 12:08:25 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{2EBC45B6-8355-43C2-9D91-ADFAC033AEA2}
[2013/09/04 22:07:03 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{86B656D8-AEC5-4487-A6D5-6B8089AFE471}
[2013/09/04 21:26:16 | 000,000,000 | -HSD | C] – C:\found.002
[2013/09/04 10:06:38 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{161BD766-0B1B-4AC4-BBC6-C5E6354BD63E}
[2013/09/03 10:05:56 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{E773909D-6AA3-497D-9F4B-8A424B92A81B}
[2013/09/03 09:49:58 | 000,000,000 | -HSD | C] – C:\found.001
[2013/09/02 09:06:29 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{F3BAA2C0-96B0-48A4-A1DA-9ECF81F8DBAF}
[2013/09/01 21:06:05 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{90C37261-DC4B-403A-B06A-2B3ABAE18314}
[2013/09/01 09:05:38 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{F92AEC0C-C24C-4B48-9F41-E4B479DC6108}
[2013/08/31 02:25:06 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{DCD19A7D-AE08-412B-BEA9-2664C755D949}
[2013/08/30 21:30:24 | 000,000,000 | -HSD | C] – C:\found.000
[2013/08/30 18:19:32 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Roaming\SUPERAntiSpyware.com
[2013/08/30 18:18:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2013/08/30 18:18:54 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2013/08/30 18:18:54 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2013/08/30 14:24:39 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{E77128D2-337D-4EED-BBCE-2713212B77A3}
[2013/08/24 10:41:11 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{BF3846E4-FCC2-4695-87B6-9058F3A2807D}
[2013/08/22 10:13:34 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{FC5B1F39-CC2B-473A-BFC9-033BB9D4FACB}
[2013/08/21 09:52:33 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{E1261B22-1F3D-4480-A2BD-E738E4B913BD}
[2013/08/21 09:46:05 | 000,000,000 | R–D | C] – C:\Users\Sonja\Google Drive
[2013/08/20 09:51:34 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{75E5665E-07AE-4819-BA80-045DE7B0C413}
[2013/08/19 09:50:55 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{89FF94D1-91DA-4BD4-B4F7-3439C4D22D7A}
[2013/08/17 07:45:33 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{B8A798E3-33DC-49F1-A748-CCAF27ED3819}
[2013/08/16 11:09:47 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{29962D63-EB27-4C82-851D-152FDBB94A5E}
[2013/08/15 23:09:23 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{60A74495-F860-4D13-8E25-C2D8354474AE}
[2013/08/15 10:14:55 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{A1E044F2-E4B2-480B-BA4C-FBDE609559E2}
[2013/08/14 09:34:11 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{8A1F98F6-B66D-41D0-BA4C-8AACAE3E8406}
[2013/08/13 10:09:56 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bay Photo Emerge
[2013/08/13 09:01:43 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{5081BFEB-7872-44EC-AE14-3671A4B6FD2C}
[2013/08/12 19:57:23 | 000,000,000 | —D | C] – C:\Users\Sonja\Desktop\word
[2013/08/12 19:57:23 | 000,000,000 | —D | C] – C:\Users\Sonja\Desktop\CONTRACT - PDF
[2013/08/12 19:57:20 | 000,000,000 | —D | C] – C:\Users\Sonja\Desktop\club_application
[2013/08/12 18:39:08 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{9F116204-BB2B-4EA9-8DDB-F5482225CF00}
[2013/08/09 08:19:55 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{220383E1-58E0-4648-BD7F-01E922D897CC}
[2013/08/08 10:50:18 | 000,000,000 | —D | C] – C:\Users\Sonja\AppData\Local\{95EE779E-30A9-4133-ABE0-26958C2D87FC}

========== Files - Modified Within 30 Days ==========

[2013/09/07 10:32:32 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Sonja\Desktop\OTL.exe
[2013/09/07 09:48:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/07 09:48:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/07 09:20:19 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/07 09:20:19 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/07 09:07:48 | 000,002,760 | —- | M] () – C:\Windows\SysNative\GManager.ini
[2013/09/07 09:07:39 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/09/07 09:07:33 | 504,717,311 | -HS- | M] () – C:\hiberfil.sys
[2013/09/07 09:07:01 | 000,003,344 | —- | M] () – C:\bootsqm.dat
[2013/09/06 16:51:20 | 000,000,000 | —- | M] () – C:\END
[2013/09/06 16:28:58 | 000,000,632 | RHS- | M] () – C:\Users\Sonja\ntuser.pol
[2013/09/04 19:46:37 | 000,024,153 | —- | M] () – C:\Users\Sonja\AppData\Roaming\ProSelect_Prefs_41.xml
[2013/09/03 21:43:15 | 000,779,306 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/09/03 21:43:15 | 000,660,624 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/09/03 21:43:15 | 000,121,738 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/09/01 10:04:10 | 922,607,003 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/08/30 18:19:03 | 000,001,810 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2013/08/15 12:45:23 | 000,002,328 | —- | M] () – C:\{8D3F6ED9-9E9C-4D5C-9A05-5DDD7E91D271}
[2013/08/15 12:43:14 | 000,002,456 | —- | M] () – C:\{0D7B3D12-1020-447B-98E5-51C1AD97315C}
[2013/08/14 17:09:23 | 000,002,160 | —- | M] () – C:\{00521077-3542-496C-A017-27107AD914D7}
[2013/08/14 16:58:53 | 000,002,264 | —- | M] () – C:\{1E8DB2D3-F79D-471D-A844-60B948296BE2}
[2013/08/14 16:57:03 | 000,002,200 | —- | M] () – C:\{AD89014B-0F9A-49CA-BF6B-8C03BCC238E0}
[2013/08/14 16:48:49 | 000,002,392 | —- | M] () – C:\{2923DACE-D5D4-4C5F-B355-67160A1ACBB2}
[2013/08/14 16:46:14 | 000,002,416 | —- | M] () – C:\{4258C251-E4DB-4B49-BA45-FCED88757613}
[2013/08/13 10:09:56 | 000,002,019 | —- | M] () – C:\Users\Sonja\Desktop\Bay Photo Emerge.lnk
[2013/08/08 19:11:54 | 107,360,256 | —- | M] () – C:\Users\Sonja\Desktop\AndrewAbby.mpg

========== Files Created - No Company Name ==========

[2013/09/07 09:07:01 | 000,003,344 | —- | C] () – C:\bootsqm.dat
[2013/08/30 18:19:01 | 000,001,810 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2013/08/21 09:43:48 | 000,000,896 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/21 09:43:46 | 000,000,892 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/15 12:45:22 | 000,002,328 | —- | C] () – C:\{8D3F6ED9-9E9C-4D5C-9A05-5DDD7E91D271}
[2013/08/15 12:43:13 | 000,002,456 | —- | C] () – C:\{0D7B3D12-1020-447B-98E5-51C1AD97315C}
[2013/08/14 17:09:22 | 000,002,160 | —- | C] () – C:\{00521077-3542-496C-A017-27107AD914D7}
[2013/08/14 16:58:52 | 000,002,264 | —- | C] () – C:\{1E8DB2D3-F79D-471D-A844-60B948296BE2}
[2013/08/14 16:57:02 | 000,002,200 | —- | C] () – C:\{AD89014B-0F9A-49CA-BF6B-8C03BCC238E0}
[2013/08/14 16:48:47 | 000,002,392 | —- | C] () – C:\{2923DACE-D5D4-4C5F-B355-67160A1ACBB2}
[2013/08/14 16:46:12 | 000,002,416 | —- | C] () – C:\{4258C251-E4DB-4B49-BA45-FCED88757613}
[2013/08/08 19:11:28 | 107,360,256 | —- | C] () – C:\Users\Sonja\Desktop\AndrewAbby.mpg
[2013/01/14 12:21:41 | 000,000,632 | RHS- | C] () – C:\Users\Sonja\ntuser.pol
[2013/01/05 20:16:55 | 000,038,443 | —- | C] () – C:\Users\Sonja\AppData\Roaming\Comma Separated Values (Windows).ADR
[2013/01/05 20:15:43 | 000,038,431 | —- | C] () – C:\Users\Sonja\AppData\Roaming\Microsoft Excel 97-2003.ADR
[2012/12/18 20:54:49 | 000,000,090 | —- | C] () – C:\Windows\QBChanUtil_Trigger.ini
[2012/12/18 20:51:42 | 000,773,900 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/12/03 11:05:18 | 000,024,153 | —- | C] () – C:\Users\Sonja\AppData\Roaming\ProSelect_Prefs_41.xml
[2012/12/03 11:04:24 | 000,185,547 | —- | C] () – C:\Windows\ProSelect Uninstaller.exe
[2012/11/13 13:49:53 | 000,430,080 | —- | C] () – C:\Windows\SysWow64\UDLL.dll
[2012/11/13 13:49:53 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\mctudll.dll
[2012/10/23 11:14:05 | 000,003,072 | —- | C] () – C:\Users\Sonja\AppData\Roaming\Millers Designer Plus Prefsv3
[2012/07/23 16:26:42 | 004,887,692 | —- | C] () – C:\Users\Sonja\MJ0C0980.jpg
[2012/04/20 20:30:45 | 000,000,132 | —- | C] () – C:\Users\Sonja\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/02/27 12:44:48 | 000,326,144 | —- | C] () – C:\Windows\SysWow64\SilverEfexPro2FC32.dll
[2012/02/22 20:26:34 | 000,326,144 | —- | C] () – C:\Windows\SysWow64\Viveza2FC32.dll
[2011/11/12 07:39:35 | 000,018,944 | —- | C] () – C:\Users\Sonja\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/11 13:21:23 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/05/18 14:17:24 | 000,001,940 | —- | C] () – C:\Users\Sonja\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/01/24 10:57:00 | 000,060,864 | —- | C] () – C:\Users\Sonja\g2mdlhlpx.exe
[2010/09/07 19:54:10 | 000,001,537 | —- | C] () – C:\Users\Sonja\.recently-used.xbel

========== ZeroAccess Check ==========

[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/01/04 03:44:25 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/01/04 01:59:38 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 18:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 05:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 18:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/08/23 20:31:35 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\.minecraft
[2012/03/09 17:45:48 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\Amazon
[2012/10/18 20:36:56 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\canon
[2011/01/24 15:28:34 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/10/02 14:35:49 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\com.adobe.DC3Module.AdobeADC
[2013/01/22 21:48:17 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/04/10 12:56:56 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\com.pandora.desktop.FB9956FD96E03239939108614098AD95535EE674.1
[2013/08/23 21:20:19 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\Dropbox
[2012/06/04 15:31:21 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\FileZilla
[2010/07/06 17:26:54 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\FreeAudioPack
[2013/06/29 12:55:56 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\GARMIN
[2010/09/07 19:54:10 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\gtk-2.0
[2010/09/04 19:02:56 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\HDRsoft
[2010/07/06 09:16:44 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\Imagenomic
[2010/09/08 15:11:19 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\Leadertech
[2010/09/06 16:46:52 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\Mask Pro 4.0
[2012/10/23 11:13:59 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\Millers Designer Plus
[2012/03/06 11:18:10 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\MillersRemoteSuiteSportsEvents
[2010/07/03 08:12:38 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\Netscape
[2011/12/08 17:14:43 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\onOne Software
[2011/11/13 17:25:30 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\Pamela
[2011/05/24 15:43:43 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\PCDr
[2013/03/19 20:52:06 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\Photodex
[2013/09/04 19:46:34 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\ProSelect
[2012/12/03 11:05:18 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\ProSelect Resources
[2010/06/30 13:19:14 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/11/27 20:23:30 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\TestApp
[2013/07/10 18:50:50 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\Tific
[2011/11/29 17:29:04 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\uTorrent
[2010/07/01 14:55:18 | 000,000,000 | —D | M] – C:\Users\Sonja\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2010/06/23 08:46:13 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_b8b0208ee0ce1889\explorer.exe
[2011/02/25 23:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/25 22:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 18:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/25 22:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2010/06/23 08:46:19 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/25 22:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/24 23:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/24 23:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/25 23:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 05:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2010/06/23 08:46:13 | 002,868,736 | —- | M] (Microsoft Corporation) MD5=6D4F9E4B640B413C6F73414327484C80 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_addea9f19345cd81\explorer.exe
[2010/06/23 08:46:15 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/06/23 08:46:19 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2010/06/23 08:46:15 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 06:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2010/06/23 08:46:19 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2010/06/23 08:46:15 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 18:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2010/06/23 08:46:19 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2010/06/23 08:46:13 | 002,868,736 | —- | M] (Microsoft Corporation) MD5=CA17F8620815267DC838E30B68CB5052 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_ae5b763cac6d568e\explorer.exe
[2011/02/25 23:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2010/06/23 08:46:15 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2010/06/23 08:46:13 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_b8335443c7a68f7c\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 18:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 18:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2012/12/14 17:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 18:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 18:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 18:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
[2009/07/13 18:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 05:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 05:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 18:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 18:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 06:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 06:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 06:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 06:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 18:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/12/14 17:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010/06/23 08:46:19 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2010/06/23 08:46:19 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: ST31000528AS ATA Device
Partitions: 3
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Generic- SD/MMC USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: Generic- Compact Flash USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model: Generic- SM/xD Picture USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE4 -
Interface type: USB
Media Type:
Model: Generic- MS/MS-Pro USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 39.00MB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 10.00GB
Starting Offset: 41943040
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 922.00GB
Starting Offset: 10651435008
Hidden sectors: 0


========== Alternate Data Streams ==========

@Alternate Data Stream - 929 bytes -> C:\Users\Sonja\Documents\Larry_AnniversaryEmail.eml:OECustomProperty
@Alternate Data Stream - 913 bytes -> C:\Users\Sonja\Documents\Paint_estimate.eml:OECustomProperty
@Alternate Data Stream - 845 bytes -> C:\Users\Sonja\Documents\Concerns about Iron.eml:OECustomProperty
@Alternate Data Stream - 833 bytes -> C:\Users\Sonja\Documents\Shaklee_New Autoship Rewards.eml:OECustomProperty
@Alternate Data Stream - 792 bytes -> C:\Users\Sonja\Documents\Baby Squirrel- story.eml:OECustomProperty
@Alternate Data Stream - 745 bytes -> C:\Users\Sonja\Documents\Re_ Basic H&G.eml;:OECustomProperty
@Alternate Data Stream - 733 bytes -> C:\Users\Sonja\Documents\B Vitamins.eml:OECustomProperty
@Alternate Data Stream - 186 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 1133 bytes -> C:\Users\Sonja\Documents\Shaklee Family_ Exploding Myth of High Carb Diet Link to Breast Cancer.eml:OECustomProperty
@Alternate Data Stream - 1085 bytes -> C:\Users\Sonja\Documents\Shaklee_Auto Ship Clarification.eml:OECustomProperty
@Alternate Data Stream - 1061 bytes -> C:\Users\Sonja\Documents\Fw_ ALERT! News about lead in children's vitamins 5_22_04.eml:OECustomProperty

< End of report >
2nd report from OTL

OTL Extras logfile created on: 9/7/2013 10:34:37 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Sonja\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.96 Gb Total Physical Memory | 4.07 Gb Available Physical Memory | 68.25% Memory free
11.92 Gb Paging File | 9.51 Gb Available in Paging File | 79.83% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 921.59 Gb Total Space | 91.66 Gb Free Space | 9.95% Space Free | Partition Type: NTFS

Computer Name: SONJA-PC | User Name: Sonja | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\SysWow64\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Digital Photo Professional] – C:\Program Files (x86)\Canon\Digital Photo Professional\DPPViewer.exe /path "%1"
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\SysWow64\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Digital Photo Professional] – C:\Program Files (x86)\Canon\Digital Photo Professional\DPPViewer.exe /path "%1"
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00B5CB46-2356-4EDB-BC56-4BA210AF357D}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{07EC0EDF-DD75-4C14-97C2-D9A6FA363EAC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0CCCE290-1E79-48BE-8D01-53FC8430B1F7}" = rport=10243 | protocol=6 | dir=out | app=system |
"{125D15A0-88BF-48C9-8710-2820813EDEC6}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{2DDB7B9E-11BF-4560-AC28-70F4EA949CC8}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2FBE806C-C578-4D4B-AA89-3EC8C47BCDCE}" = lport=2869 | protocol=6 | dir=in | app=system |
"{3BD569EC-9440-4989-9600-B7001974F866}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{3F3BC6AE-3B44-41CD-A0A5-18AC33C63F0A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{43E91C33-6B4F-4292-9B76-B64DA04221F3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{44476B4A-BA7C-4D79-84E9-F09816EA6352}" = lport=137 | protocol=17 | dir=in | app=system |
"{4905063D-F3AB-4828-85BD-69733EE6D14E}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{5E7EF9DF-8ED0-49F3-8DA5-D01E250D02E5}" = lport=445 | protocol=6 | dir=in | app=system |
"{5E95C292-C766-49E5-B74E-B1CBE51A7892}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{6685948B-BE98-40C3-9722-712D44D87B57}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{66EFDDB0-D256-47F9-B3CF-C91F5009DB2E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8D893570-F880-4AA3-8827-544648D15767}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{96EB26DE-75FF-499A-9879-2CD73DC4123F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{99B0A91F-23CC-49CB-B4F8-D7FFC95517FF}" = lport=139 | protocol=6 | dir=in | app=system |
"{9A92C88E-ADFB-4DF6-B5C0-F8D38E51D3EC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9C0B5421-E6BE-4A21-87AB-EC03836C7429}" = lport=138 | protocol=17 | dir=in | app=system |
"{C4EA490C-CDA5-4194-B977-A063AF485A49}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D8231212-5186-449E-8D0A-B747EC078808}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DD734F22-FCC0-479E-A701-5A9833101A30}" = rport=137 | protocol=17 | dir=out | app=system |
"{E70FF87E-B7C3-404F-ABA0-9AC1B7655AD9}" = rport=139 | protocol=6 | dir=out | app=system |
"{ED5A679E-EF5D-4B35-89CA-0667F8C08EF4}" = rport=445 | protocol=6 | dir=out | app=system |
"{EE6C65FF-B80B-4767-8C75-497F3A260842}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FD9DCA01-395C-4748-9BB6-B44533FAABB1}" = lport=10243 | protocol=6 | dir=in | app=system |
"{FE8C19BF-EAC1-419F-AE7F-873381924D53}" = rport=138 | protocol=17 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{055AFFE7-B623-4BAA-B8FD-BFEB0C566291}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{08BF9723-94B8-4519-ADD1-6C8DECABB462}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{0AFF953A-9591-4B3B-A68E-BEC37B7E6359}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0ECAAC65-EBA8-4094-A785-6291232A8DA1}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{156F7D9B-EC5F-4D07-B778-E47981F07072}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{1AD3435B-B891-47E6-9C1D-C77E5CD70E48}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifecam.exe |
"{22B5162F-6EEB-4BF1-8B1B-CDCB2A42CDDC}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{23EF6178-5F0D-40F8-BDC8-41B0BC05EC41}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |
"{33D48A90-B0C7-44AE-A247-4EA86C23D843}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{37669577-F24F-4FB7-8FFF-8C3F562E19FB}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{3B44CF00-61D2-4518-B224-33F712D37038}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3FDBAE96-66B1-40A0-B3B1-3ED64BAB7E8A}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{4AE19B85-3317-4641-A408-4611AD14FA1B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqfxt08.exe |
"{50864D82-52E3-485B-B360-56C2389783BB}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{536C56E8-3AF0-4662-801B-1FB9EDBF4BC8}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{54AF34AE-2FA4-4522-A11C-4B11E80F59F7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{58039A07-17D2-4008-AA74-A368E2806C4C}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{58D641F5-4540-4B2A-A533-5F2145EA2621}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5BB26281-934E-46F9-B78C-0E39BEA865A8}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{5E2F112E-63F7-4D2E-85FE-4B1CF5DD071A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |
"{60BB6D74-F81C-42E7-90C6-A756B66884FD}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{636AEED9-C895-4E6D-A371-325FAC2AEA6A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposfx08.exe |
"{645B6B57-CC1B-4E67-8769-A4EBA4FDE236}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6689D23F-DA80-4747-8438-5432E99B89BE}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxs08.exe |
"{66ACB550-4A56-4B5C-B3FD-F75F71ACD529}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe |
"{673755E3-199D-4B32-B871-35267D0F5FE4}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifeexp.exe |
"{6AF557B1-99A1-40C7-9E6C-B89C61529BF6}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxm08.exe |
"{6FD9DB78-939A-493D-AC87-C8294E5DCD1E}" = protocol=6 | dir=out | app=system |
"{73AD5981-4763-4940-8BF4-384C48209576}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifeenc2.exe |
"{7CFFF969-4387-4025-BC2F-52ABA84EE78A}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifetray.exe |
"{8079A05E-3946-4058-A76D-9AAAC80C1033}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |
"{80F0117B-748B-4553-A3C5-44ABBAF46142}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{82809638-818B-47AD-891D-69C350F3B748}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{876625D8-BC9D-40D0-BD87-45D33852ABBA}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{9618DB07-E243-4180-B82E-8360473CD1AA}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{961E4DCB-C14D-4ABC-BC4B-87ECAAEDC12D}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe |
"{97639019-B024-41C8-8776-97B00A8D9FD3}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe |
"{99478621-80E7-4FAA-9116-23EB01A0AAE9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9F43F43C-3989-46CF-BD71-3A5EA36CD74E}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifecam.exe |
"{A26328B5-5409-4849-A94E-6F35BD2A1D21}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe |
"{A4E1C1F8-960B-49AF-9AFE-EB42DB0A9BAE}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{A990DF34-1C49-49BF-86F8-5000C251335B}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifeexp.exe |
"{ADE675C5-0F5B-41DF-B116-1D11A7688102}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{B37DE822-853D-4EDC-93D5-CA561ED614E5}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B54ED629-A1A3-4325-B2AD-004CAD227228}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifeenc2.exe |
"{B74B5882-9EB9-4258-9373-7A7BAE1B7961}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{BAC5D8D8-EF29-40EF-8F8D-44EE4AFEC519}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{BF3F777F-3574-4318-B735-3A4D5149624C}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd dx\powerdvd.exe |
"{BF4127AD-5F8C-4250-AE94-BDDCC6275126}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpzwiz01.exe |
"{C8855733-9FE0-4D9F-80FB-04B50B8B7616}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CC97C25F-55A8-443F-BFEF-1F21463EB42F}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{CDE0CB36-050F-4B9B-9E93-C340C0705FF4}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D03FE3C0-EAA8-4C66-A019-FE013C2B936D}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |
"{D0FFC64E-D495-4AC2-8BE9-813A3EF11F6A}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifetray.exe |
"{E5D637F0-C034-44B8-A516-06377797C5DF}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{E84BA2CF-951A-46F3-B203-8C9A27C3C352}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{EAC410F4-2BEC-41AF-9D68-5A60908C5845}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F8204DDD-C453-495A-8E21-1972F004D778}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{FC8E5100-477A-4B5B-8711-EE4674241939}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety
"{06B60360-9DBD-4593-90A0-FD237F0845A2}" = Topaz DeNoise 5 (64-bit)
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{1387BA33-3FAC-49E9-B545-0E8D3BBC550B}" = Adobe Photoshop Lightroom 3 64-bit
"{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}" = iTunes
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{23170F69-40C1-2702-0915-000001000000}" = 7-Zip 9.15 (x64 edition)
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4FFA2088-8317-3B14-93CD-4C699DB37843}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
"{5CE7E3F5-9803-4F32-AA89-2D8848A80109}" = Microsoft LifeCam
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{62F63009-A408-4E0A-BB7F-EFB6F82ED26B}" = Topaz DeNoise 4 (64-bit)
"{66CF1DF9-1715-4325-89BC-76B1CA2EE3BE}" = Adobe Premiere Elements 11
"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
"{6C1A010F-9108-4162-A26F-9FEC4AC0F0F0}" = Adobe Photoshop Lightroom 5 64-bit
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}" = Apple Mobile Device Support
"{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}" = HP Officejet 4500 G510n-z
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8D93BD99-EECF-4812-B3BA-B8A2E7FEEA11}" = Topaz Simplify 3 (64-bit)
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B9DBB81-1F48-48B0-8CB3-051311DC73F7}" = Adobe Photoshop Lightroom 2.7 64-bit
"{9C5A08BF-BB99-4998-81BD-F6CC32483B34}" = Microsoft Corporation
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{A4DDB2AB-ECCD-4C3A-8633-77D5A1A0E542}" = Network64
"{A981E64B-0F10-45D9-BD5C-A4DF7B87E218}" = Topaz Detail 2 (64-bit)
"{B143BE44-8723-315E-9413-011C55873C0E}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{BA3D5FF2-A405-4654-826E-A09FABB01853}" = Topaz Fusion Express 2 (64-bit)
"{BFE972A5-DC62-03F9-F03E-8AC751DFE770}" = ccc-utility64
"{C73A3942-84C8-4597-9F9B-EE227DCBA758}" = Dell Dock
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D9EA591C-2ED0-4E91-BF5F-A6B4B1CCEFC7}" = Topaz ReMask 2 (64-bit)
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DC8F0C18-E6B0-4722-A4AB-D134473091C2}" = Topaz DeJpeg 4 (64-bit)
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F7ADB493-B913-4D61-9A63-DA736C20C3F2}" = Adobe Photoshop Lightroom 4.1 64-bit
"{FA85C599-2569-4C48-9AA6-2B8D8F029FA7}" = Topaz Clean 3 (64-bit)
"{FB237A35-F491-4AC1-95E0-85118D6751D9}" = Topaz Adjust 4 (64-bit)
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"45A7283175C62FAC673F913C1F532C5361F97841" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
"HP Document Manager" = HP Document Manager 2.0
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"ImagenomicNoisewareProPlugin" = Imagenomic Noiseware 4.2 Professional Plug-in (build 4205)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"PC-Doctor for Windows" = My Dell
"PremElem110" = Adobe Premiere Elements 11
"Shop for HP Supplies" = Shop for HP Supplies
"SP6" = Logitech SetPoint 6.15

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{03CEC5A3-648C-3E00-7CDB-C049B47A5EDC}" = CCC Help Spanish
"{051EF664-EB85-8320-1184-35136C6B0BEF}" = CCC Help Portuguese
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0566E404-1FCB-16C4-C265-9415012650D5}" = CCC Help Korean
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{07A8ED9E-B98E-437F-B750-241B412BE924}" = Garmin USB Drivers
"{07BB25C3-55B6-303C-1E7C-2C528555014D}" = CCC Help Dutch
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{09907A60-5843-4E83-A471-3102A42231B8}_is1" = SD Card Recovery
"{0A6C24B8-F519-4A1B-B3A1-0D4FA1078824}" = Topaz DeNoise 4
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{1583FB9E-D1D7-A29B-F3D3-7D6B74D75128}" = Catalyst Control Center Graphics Previews Vista
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.5.7
"{1EE6959C-49F2-5D45-A007-776A7A053043}" = CCC Help English
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{222E1C7F-5892-0015-BF94-914B7EBEB564}" = CCC Help Finnish
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java™ 6 Update 29
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{301CC8D1-FE75-41ED-9B11-41F006110950}" = Garmin City Navigator North America NT 2010.10 Update
"{3167CC62-C775-4E47-92C1-73EBB845751A}" = QuickBooks
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{38001EBD-D270-2BBC-CEAE-B88BDE197E16}" = CCC Help Russian
"{3A4D5E2D-988D-4ee9-8E7F-3AC200A2B8F5}" = 4500G510nz_Software_Min
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3C631966-387E-4054-85D9-BBFFABE32BD8}" = QuickBooks Pro 2013
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{42E0794B-B4A6-CDB6-308F-04A5CA54B81E}" = CCC Help French
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4B2A76D6-9FBD-3585-99EB-799FEF47C16B}" = Millers Sports and Events
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{59679381-3F22-4A40-A7AD-890242D74DF4}" = Perfect Photo Suite 6
"{599EAA99-BBA8-C8FF-C2EA-04D0C8FA6D89}" = Catalyst Control Center InstallProxy
"{5AF4B3C4-C393-48D7-AC7E-8E7615579548}" = Adobe AIR
"{5B05FF91-F20C-4832-A8DE-E1912639C17C}" = 4500G510nz
"{5DFB9027-0099-5816-8428-CF25B64B46C9}" = CCC Help Czech
"{634CE363-2BB8-FF85-83C3-734699DFC570}" = CCC Help German
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6545416A-A60A-8DE4-3590-15F0662461DF}" = CCC Help Polish
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{690879A5-18EF-447B-98D6-B699D51008AB}" = 4500_G510nz_Help
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{770D3BDC-19D7-49D0-B60B-C5BB77553FBB}" = Topaz Fusion Express 2
"{774A70C8-29CA-565A-FB84-01B408F119B2}" = CCC Help Chinese Standard
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{81C5AD1D-C7C6-48AC-AC85-8F04293B1780}" = SEE2 Xtreme UV150 / UV250 12.01.0411.1177
"{81F1814D-8658-72CC-D370-A08E1014EF03}" = Pandora
"{820B6609-4C97-3A2B-B644-573B06A0F0CC}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{85E00941-FDFF-4796-A3B8-3ACC766FFCA5}" = Topaz Clean 3
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A1EBF29-7CF8-471E-B90B-95FF36AC8248}" = Topaz Simplify 3
"{8A9DE8C3-5B21-34EC-DE5D-BAFAB8D8C9D9}" = CCC Help Greek
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91D1580F-35C5-8D29-144C-605E3568B3A5}" = Catalyst Control Center Graphics Full Existing
"{92A51949-EE4C-466D-AAF0-99E74A49A63F}" = DocMgr
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-007D-0409-0000-0000000FF1CE}" = Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit
"{95140000-0081-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{958FD5FD-1F71-493B-CC6C-4922F3EA2356}" = CCC Help Danish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9AAD03E8-4F65-4DE2-8F6C-1B079C0C8521}" = Garmin Lifetime Updater
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E146BA1-26DD-4C3B-9F0F-90F2E3CEC9D2}" = Topaz DeJpeg 4
"{9E82D1DB-3AFB-4D18-A221-081F1B4B4789}" = Topaz DeNoise 5
"{9FDC7042-CB9F-4336-A14C-DF10F53762E2}" = Topaz Adjust 4
"{9FDFB9AE-B7A9-3481-E85C-08E7FA6D620B}" = Catalyst Control Center Graphics Full New
"{A0AD3E2F-427D-09F9-85FB-450E35A03046}" = CCC Help Hungarian
"{A1D31E2C-C7E1-2E6E-EAE9-0C3BAFB5B1F9}" = CCC Help Thai
"{A69D7B32-2BE9-42BF-B576-69B5E0FF7394}" = Catalyst Control Center - Branding
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2C07E85-76D6-DC01-48A9-7577AD95CD70}" = CCC Help Swedish
"{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{B614E5FA-6DA4-45A1-845C-52F870240A89}" = PRE11 STI 64Installer
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B91C2CFE-15D0-C863-963A-DFF09D2AE726}" = Catalyst Control Center Core Implementation
"{BACF2A73-2F91-9657-F9B5-10723A9B1E5B}" = CCC Help Italian
"{BCFFAF65-50B7-4419-AFCA-A7BA797E2C3D}" = Topaz ReMask 2
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C8694EE7-24F3-6593-FE50-00E575C79272}" = Skins
"{C8773FDB-D0DB-BE52-D536-F48F9886B57B}" = Adobe Download Assistant
"{C921D7C4-24D7-4210-AEE9-DFC5DDC78428}" = Topaz Detail 2
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CDF7810C-10AB-7E95-ABC5-0D60C5761876}" = Catalyst Control Center Graphics Light
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4D065E1-3ABF-41D0-B385-FC6F027F4D00}" = Elements 11 Organizer
"{D5D35107-8CFE-5FFB-2D64-1CE29202493B}" = Catalyst Control Center Graphics Previews Common
"{D8D98FAB-17E7-A123-D654-6574E6187EE2}" = CCC Help Chinese Traditional
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DAC44207-C17F-DAFA-CE5D-010AB94A38AB}" = CCC Help Norwegian
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E31C77D0-B0F0-318B-0A39-F57BF54D22AD}" = ccc-core-static
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EA3CD5E7-0C84-2479-6490-B6228F87B174}" = CCC Help Japanese
"{ECEB9207-85FE-3004-CD20-5DAEE0F1D1E0}" = CCC Help Turkish
"{EFD5DA1B-2CB7-1249-A15E-8EC3E97E2F37}" = Miller's Albums and Books
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F68AFC71-77CD-0B22-4C4F-C09097E058E9}" = Catalyst Control Center Localization All
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"1675-4393-0139-4708" = Miller's Remote Suite (PLUS) 1.0.0.13 Production
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AI RoboForm" = RoboForm 7-6-5 (All Users)
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.15
"Browser Defender_is1" = Browser Defender 4.0
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"com.pandora.desktop.FB9956FD96E03239939108614098AD95535EE674.1" = Pandora
"Coupon Printer for Windows5.0.0.2" = Coupon Printer for Windows
"Dell Dock" = Dell Dock
"ESET Online Scanner" = ESET Online Scanner v3
"Free PDF to Word Doc Converter_is1" = Free PDF to Word Doc Converter v1.1
"GoToAssist" = GoToAssist 8.0.0.514
"HijackThis" = HijackThis 2.0.2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"MillersRemoteSuiteAlbums" = Miller's Albums and Books
"MillersRemoteSuiteSportsEvents" = Millers Sports and Events
"Mozilla Firefox 8.0.1 (x86 en-US)" = Mozilla Firefox 8.0.1 (x86 en-US)
"N360" = Norton 360
"Office14.SingleImage" = Microsoft Office Home and Business 2010
"Photodex Presenter" = Photodex Presenter
"ProSelect 2012r2" = ProSelect
"ProSelect 2012r2.3" = ProSelect
"ProShow Gold" = ProShow Gold
"Silver Efex Pro 2" = Silver Efex Pro 2
"simple2_is1" = Tone Mapping Plug-In 1.2
"Spyware Doctor" = PC Tools Spyware Doctor 9.0
"Topaz Adjust 4" = Topaz Adjust 4
"Topaz Adjust 4 (64-bit)" = Topaz Adjust 4 (64-bit)
"Topaz Clean 3" = Topaz Clean 3
"Topaz Clean 3 (64-bit)" = Topaz Clean 3 (64-bit)
"Topaz DeJpeg 4" = Topaz DeJpeg 4
"Topaz DeJpeg 4 (64-bit)" = Topaz DeJpeg 4 (64-bit)
"Topaz DeNoise 5" = Topaz DeNoise 5
"Topaz DeNoise 5 (64-bit)" = Topaz DeNoise 5 (64-bit)
"Topaz Detail 2" = Topaz Detail 2
"Topaz Detail 2 (64-bit)" = Topaz Detail 2 (64-bit)
"Topaz Fusion Express 2" = Topaz Fusion Express 2
"Topaz Fusion Express 2 (64-bit)" = Topaz Fusion Express 2 (64-bit)
"Topaz ReMask 2" = Topaz ReMask 2
"Topaz Simplify 3" = Topaz Simplify 3
"Topaz Simplify 3 (64-bit)" = Topaz Simplify 3 (64-bit)
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"Viveza 2" = Viveza 2
"WinLiveSuite" = Windows Live Essentials
"zfupload" = Zenfolio Uploader

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Bay Photo" = Bay Photo
"Bay Photo Economy" = Bay Photo Economy
"Bay Photo Emerge" = Bay Photo Emerge
"GoToMeeting" = GoToMeeting 5.4.0.1083
"Millers Designer Plus" = Millers Designer Plus
"Miller's ROES" = Miller's ROES
"MiraScan" = MiraScan V3.04
"ROES.whcc" = ROES.whcc

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/6/2013 7:46:58 PM | Computer Name = Sonja-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 9/6/2013 7:48:57 PM | Computer Name = Sonja-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 9/6/2013 7:57:51 PM | Computer Name = Sonja-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 9/6/2013 9:24:03 PM | Computer Name = Sonja-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 8.0.1.4341 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 324 Start
Time: 01ceab68d2dea3d0 Termination Time: 0 Application Path: C:\Program Files (x86)\Mozilla
Firefox\firefox.exe Report Id: 2561e899-175c-11e3-a4f4-b8ac6fa51810

Error - 9/6/2013 9:24:34 PM | Computer Name = Sonja-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 8.0.1.4341 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: c5c Start
Time: 01ceab68f1e670c5 Termination Time: 31 Application Path: C:\Program Files (x86)\Mozilla
Firefox\firefox.exe Report Id: 3c97a937-175c-11e3-a4f4-b8ac6fa51810

Error - 9/7/2013 12:16:06 AM | Computer Name = Sonja-PC | Source = Microsoft-Windows-Defrag | ID = 257
Description =

Error - 9/7/2013 12:54:15 AM | Computer Name = Sonja-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 8.0.1.4341 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1978 Start
Time: 01ceab8600233756 Termination Time: 0 Application Path: C:\Program Files (x86)\Mozilla
Firefox\firefox.exe Report Id: 612edbda-1779-11e3-a4f4-b8ac6fa51810

Error - 9/7/2013 12:56:36 AM | Computer Name = Sonja-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 9/7/2013 12:08:09 PM | Computer Name = Sonja-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 9/7/2013 1:08:13 PM | Computer Name = Sonja-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

[ Dell Events ]
Error - 9/11/2011 10:18:50 PM | Computer Name = Sonja-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 9/11/2011 10:21:47 PM | Computer Name = Sonja-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 9/11/2011 10:21:47 PM | Computer Name = Sonja-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 9/12/2011 6:40:44 PM | Computer Name = Sonja-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 9/12/2011 6:40:44 PM | Computer Name = Sonja-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 9/14/2011 11:14:07 AM | Computer Name = Sonja-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 9/14/2011 11:14:07 AM | Computer Name = Sonja-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 9/15/2011 11:00:31 AM | Computer Name = Sonja-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 9/15/2011 11:00:31 AM | Computer Name = Sonja-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 9/19/2011 10:03:21 PM | Computer Name = Sonja-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

[ System Events ]
Error - 9/6/2013 7:29:27 PM | Computer Name = Sonja-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the SftService service.

Error - 9/6/2013 7:33:37 PM | Computer Name = Sonja-PC | Source = Service Control Manager | ID = 7022
Description = The Windows Update service hung on starting.

Error - 9/6/2013 7:51:15 PM | Computer Name = Sonja-PC | Source = Service Control Manager | ID = 7034
Description = The FastFreeConverterUpdt service terminated unexpectedly. It has
done this 1 time(s).

Error - 9/6/2013 7:57:10 PM | Computer Name = Sonja-PC | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\drivers\DTC328X.SYS has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 9/6/2013 7:57:41 PM | Computer Name = Sonja-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
DTC328X

Error - 9/6/2013 8:03:23 PM | Computer Name = Sonja-PC | Source = Service Control Manager | ID = 7022
Description = The Windows Update service hung on starting.

Error - 9/7/2013 12:13:31 AM | Computer Name = Sonja-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume OS.

Error - 9/7/2013 12:07:27 PM | Computer Name = Sonja-PC | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\drivers\DTC328X.SYS has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 9/7/2013 12:07:58 PM | Computer Name = Sonja-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
DTC328X

Error - 9/7/2013 12:13:01 PM | Computer Name = Sonja-PC | Source = Service Control Manager | ID = 7022
Description = The Windows Update service hung on starting.


< End of report >
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-09-07 14:08:58 —————————– 14:08:58.209 OS Version: Windows x64 6.1.7601 Service Pack 1 14:08:58.209 Number of processors: 4 586 0x1E05 14:08:58.209 ComputerName: SONJA-PC UserName: Sonja 14:09:02.016 Initialize success 14:10:05.020 AVAST engine defs: 13090701 14:10:11.650 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 14:10:11.666 Disk 0 Vendor: ST31000528AS CC45 Size: 953869MB BusType: 3 14:10:11.728 Disk 0 MBR read successfully 14:10:11.744 Disk 0 MBR scan 14:10:11.744 Disk 0 Windows VISTA default MBR code 14:10:11.744 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63 14:10:11.775 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 10118 MB offset 81920 14:10:11.775 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 943710 MB offset 20803584 14:10:11.822 Disk 0 scanning C:\Windows\system32\drivers 14:10:24.708 Service scanning 14:10:48.544 Modules scanning 14:10:48.544 Disk 0 trace - called modules: 14:10:48.560 ntoskrnl.exe CLASSPNP.SYS disk.sys PCTCore64.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 14:10:48.576 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800655d790] 14:10:48.576 3 CLASSPNP.SYS[fffff88001f8343f] -> nt!IofCallDriver -> [0xfffffa80063c2cf0] 14:10:48.576 5 PCTCore64.sys[fffff88001129f38] -> nt!IofCallDriver -> [0xfffffa800548dd10] 14:10:48.591 7 ACPI.sys[fffff88000f967a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800628d060] 14:10:51.399 AVAST engine scan C:\Windows 14:10:55.970 AVAST engine scan C:\Windows\system32 14:14:51.250 AVAST engine scan C:\Windows\system32\drivers 14:15:39.162 AVAST engine scan C:\Users\Sonja 14:20:26.525 Disk 0 MBR has been saved successfully to "C:\Users\Sonja\Desktop\MBR.dat" 14:20:26.525 The log file has been saved successfully to "C:\Users\Sonja\Desktop\aswMBR.txt"
Hi Sonja27 ;)

Good job :)

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Next

[external image: Posted Image] AdwCleaner

Double click on AdwCleaner.exe to run the tool again.
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished…
  • This time, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

Next

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


Next


  • Download RogueKiller and save it to your desktop.
  • Quit all other programs
  • Start RogueKiller.exe
  • Wait until the Prescan has finished …
  • Click on Scan
    [external image: Posted Image]
  • Wait for the end of the scan
  • A report will be created on your desktop.
  • Click on the Delete button
    [external image: Posted Image]
  • Next click on the ShortcutsFix
    [external image: Posted Image]
  • another report will be created on your desktop.

Please post: All RKreport.txt text files located on your desktop.

On your next reply please post :
  • checkup.txt
  • AdwCleaner[S1].txt
  • JRT.txt
  • All RKreport.txt

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Results of screen317's Security Check version 0.99.73
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Norton 360
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Out of date HijackThis installed!
PC Tools Spyware Doctor 9.0
Malwarebytes Anti-Malware version 1.70.0.1100
Out of date Malwarebytes Anti-Malware installed!
HijackThis 2.0.2
Java™ 6 Update 29
Java version out of Date!
Adobe Flash Player 10 Flash Player out of Date!
Adobe Reader 10.1.4 Adobe Reader out of Date!
Mozilla Firefox (8.0.1)
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 5%
````````````````````End of Log``````````````````````



Am working on step 2.
Just in case…. I found AdwCleaner and ran it - here's the report. # AdwCleaner v3.003 - Report created 08/09/2013 at 19:02:21 # Updated 07/09/2013 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : Sonja - SONJA-PC # Running from : C:\Users\Sonja\Desktop\AdwCleaner.exe # Option : Scan ***** [ Services ] ***** ***** [ Files / Folders ] ***** File Found : C:\END File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\safesearch.xml File Found : C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\searchplugins\safesearch.xml File Found : C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\user.js File Found : C:\Windows\System32\Tasks\DSite File Found : C:\Windows\Tasks\DSite.job Folder Found : C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} Folder Found : C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\Extensions\[removed] Folder Found C:\Program Files (x86)\Common Files\AVG Secure Search Folder Found C:\ProgramData\boost_interprocess Folder Found C:\Users\Sonja\AppData\Local\PackageAware Folder Found C:\Users\Sonja\AppData\LocalLow\Conduit Folder Found C:\Users\Sonja\AppData\LocalLow\Minibar Folder Found C:\Users\Sonja\AppData\LocalLow\PriceGong Folder Found C:\Users\Sonja\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z Folder Found C:\Users\Sonja\AppData\Roaming\DSite Folder Found C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\Conduit Folder Found C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\ConduitEngine ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKCU\Software\AppDataLow\Software\PriceGong Key Found : HKCU\Software\Ask&Record Key Found : HKCU\Software\dsiteproducts Key Found : HKCU\Software\ilivid Key Found : HKCU\Software\InstallCore Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages Key Found : HKCU\Software\YahooPartnerToolbar Key Found : HKCU\Software\Zugo Key Found : [x64] HKCU\Software\Ask&Record Key Found : [x64] HKCU\Software\dsiteproducts Key Found : [x64] HKCU\Software\ilivid Key Found : [x64] HKCU\Software\InstallCore Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} Key Found : [x64] HKCU\Software\YahooPartnerToolbar Key Found : [x64] HKCU\Software\Zugo Key Found : HKLM\Software\AVG Security Toolbar Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Found : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD} Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Found : HKLM\SOFTWARE\Classes\CLSID\{D6598005-A921-4F83-B6E6-F4F030D1BF37} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : HKLM\SOFTWARE\Classes\Interface\{0F6ECBD3-98B1-4044-8520-69407A70C83C} Key Found : HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA} Key Found : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : HKLM\SOFTWARE\Classes\Interface\{8A41F062-A222-4322-A8C4-26218BE869B9} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : HKLM\SOFTWARE\Classes\Interface\{C0207057-3461-4F7F-B689-D016B7A03964} Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Found : HKLM\SOFTWARE\Classes\Interface\{C6A61AAE-D30B-4E7A-A3D8-8A34E5BA3414} Key Found : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Key Found : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol Key Found : HKLM\SOFTWARE\Classes\S Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2786678 Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4F9AD2F2-3A64-470E-93F7-A03423E52ACA} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A7C2FCDD-0359-49DD-8339-BE2A5BD60918} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{F13D3582-1359-4F8F-9A48-EF3AE9F5701C} Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Found : HKLM\Software\Conduit Key Found : HKLM\Software\DataMngr Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_hamachi_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_hamachi_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [DataMngr] Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt] Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] ***** [ Browsers ] ***** -\\ Internet Explorer v9.0.8112.16421 -\\ Mozilla Firefox v8.0.1 (en-US) [ File : C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\prefs.js ] Line Found : user_pref("CT2786678..clientLogIsEnabled", false); Line Found : user_pref("CT2786678..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent"); Line Found : user_pref("CT2786678..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation"); Line Found : user_pref("CT2786678.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Line Found : user_pref("CT2786678.CTID", "CT2786678"); Line Found : user_pref("CT2786678.CurrentServerDate", "17-1-2011"); Line Found : user_pref("CT2786678.DialogsAlignMode", "LTR"); Line Found : user_pref("CT2786678.DownloadReferralCookieData", ""); Line Found : user_pref("CT2786678.EMailNotifierPollDate", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.FeedLastCount5690698542593514850", 183); Line Found : user_pref("CT2786678.FeedPollDate129301619375443753", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.FeedPollDate129301619375443759", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.FeedPollDate129301619375444699", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.FeedPollDate129301619375444705", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.FeedPollDate129301619375444711", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.FeedPollDate129301619375444717", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.FeedPollDate129301619375444723", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.FeedPollDate129301619375444729", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.FeedPollDate129301619375444735", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.FeedPollDate129301619375444741", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.FeedPollDate129301619375444747", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.FeedTTL129301619375444699", 10); Line Found : user_pref("CT2786678.FeedTTL129301619375444723", 15); Line Found : user_pref("CT2786678.FeedTTL129301619375444735", 5); Line Found : user_pref("CT2786678.FeedTTL129301619375444747", 5); Line Found : user_pref("CT2786678.FirstServerDate", "17-1-2011"); Line Found : user_pref("CT2786678.FirstTime", true); Line Found : user_pref("CT2786678.FirstTimeFF3", true); Line Found : user_pref("CT2786678.FixPageNotFoundErrors", false); Line Found : user_pref("CT2786678.GroupingServerCheckInterval", 1440); Line Found : user_pref("CT2786678.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Line Found : user_pref("CT2786678.HasUserGlobalKeys", true); Line Found : user_pref("CT2786678.Initialize", true); Line Found : user_pref("CT2786678.InitializeCommonPrefs", true); Line Found : user_pref("CT2786678.InstallationAndCookieDataSentCount", 1); Line Found : user_pref("CT2786678.InstallationType", "UnknownIntegration"); Line Found : user_pref("CT2786678.InstalledDate", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.IsGrouping", false); Line Found : user_pref("CT2786678.IsMulticommunity", false); Line Found : user_pref("CT2786678.IsOpenThankYouPage", true); Line Found : user_pref("CT2786678.IsOpenUninstallPage", false); Line Found : user_pref("CT2786678.LanguagePackLastCheckTime", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.LanguagePackReloadIntervalMM", 1440); Line Found : user_pref("CT2786678.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx"); Line Found : user_pref("CT2786678.LastLogin_3.2.5.2", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.LatestVersion", "3.2.5.2"); Line Found : user_pref("CT2786678.Locale", "en"); Line Found : user_pref("CT2786678.MCDetectTooltipHeight", "83"); Line Found : user_pref("CT2786678.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Line Found : user_pref("CT2786678.MCDetectTooltipWidth", "295"); Line Found : user_pref("CT2786678.SearchFromAddressBarIsInit", true); Line Found : user_pref("CT2786678.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q="); Line Found : user_pref("CT2786678.SearchInNewTabEnabled", true); Line Found : user_pref("CT2786678.SearchInNewTabIntervalMM", 1440); Line Found : user_pref("CT2786678.SearchInNewTabLastCheckTime", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID"); Line Found : user_pref("CT2786678.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID"); Line Found : user_pref("CT2786678.ServiceMapLastCheckTime", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.SettingsLastCheckTime", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.SettingsLastUpdate", "1295273672"); Line Found : user_pref("CT2786678.ThirdPartyComponentsInterval", 504); Line Found : user_pref("CT2786678.ThirdPartyComponentsLastCheck", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.ThirdPartyComponentsLastUpdate", "1246790578"); Line Found : user_pref("CT2786678.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=101&sealid=112"); Line Found : user_pref("CT2786678.UserID", "UN66697515828275327"); Line Found : user_pref("CT2786678.WeatherNetwork", ""); Line Found : user_pref("CT2786678.WeatherPollDate", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.WeatherUnit", "C"); Line Found : user_pref("CT2786678.alertChannelId", "1178763"); Line Found : user_pref("CT2786678.myStuffEnabled", true); Line Found : user_pref("CT2786678.myStuffPublihserMinWidth", 400); Line Found : user_pref("CT2786678.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID"); Line Found : user_pref("CT2786678.myStuffServiceIntervalMM", 1440); Line Found : user_pref("CT2786678.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT"); Line Found : user_pref("CT2786678.testingCtid", ""); Line Found : user_pref("CT2786678.toolbarAppMetaDataLastCheckTime", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CT2786678.toolbarContextMenuLastCheckTime", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1178763/1174448/US", "\"0\""); Line Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/US", "\"0\""); Line Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2786678", "\"1285982114\""); Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en", "L+tncv4eqt6Qm5T3dzChdA=="); Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en", "poKjTfHs0NrVUIalKI8jyg=="); Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en", "QmycQXJXVyFVAzIiNllWhQ=="); Line Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en", "SuMy8xgBA7+FodOxmk9aiQ=="); Line Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"634289840782570000\""); Line Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634303635100000000"); Line Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2786678/CT2786678", "\"1295273672\""); Line Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"634307860320500000\""); Line Found : user_pref("CommunityToolbar.EngineOwner", "CT2786678"); Line Found : user_pref("CommunityToolbar.EngineOwnerGuid", "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"); Line Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "utorrentbar"); Line Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); Line Found : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2786678"); Line Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"); Line Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "utorrentbar"); Line Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.properties"); Line Found : user_pref("CommunityToolbar.ToolbarsList", "ConduitEngine,CT2786678"); Line Found : user_pref("CommunityToolbar.ToolbarsList2", "ConduitEngine,CT2786678"); Line Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440); Line Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed Dec 07 2011 17:24:48 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); Line Found : user_pref("CommunityToolbar.alert.locale", "en"); Line Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); Line Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Dec 07 2011 17:24:48 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611"); Line Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); Line Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); Line Found : user_pref("CommunityToolbar.alert.showTrayIcon", false); Line Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); Line Found : user_pref("CommunityToolbar.alert.userId", "bf85937d-e423-497b-8e9d-ac25fc054afd"); Line Found : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("ConduitEngine.CTID", "ConduitEngine"); Line Found : user_pref("ConduitEngine.FirstServerDate", "01/17/2011 20"); Line Found : user_pref("ConduitEngine.FirstTime", true); Line Found : user_pref("ConduitEngine.FirstTimeFF3", true); Line Found : user_pref("ConduitEngine.FixPageNotFoundErrors", false); Line Found : user_pref("ConduitEngine.HasUserGlobalKeys", true); Line Found : user_pref("ConduitEngine.Initialize", true); Line Found : user_pref("ConduitEngine.InitializeCommonPrefs", true); Line Found : user_pref("ConduitEngine.InstallationType", "UnknownIntegration"); Line Found : user_pref("ConduitEngine.InstalledDate", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("ConduitEngine.IsMulticommunity", false); Line Found : user_pref("ConduitEngine.IsOpenThankYouPage", false); Line Found : user_pref("ConduitEngine.IsOpenUninstallPage", false); Line Found : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("ConduitEngine.LastLogin_3.2.5.2", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("ConduitEngine.PublisherContainerWidth", 0); Line Found : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true); Line Found : user_pref("ConduitEngine.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CTXXXX&q="); Line Found : user_pref("ConduitEngine.SettingsLastCheckTime", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("ConduitEngine.UserID", "UN35375416743791666"); Line Found : user_pref("ConduitEngine.engineLocale", "en-US"); Line Found : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Found : user_pref("ConduitEngine.initDone", true); Line Found : user_pref("avg.userPreferences.URLBarFocus.whiteList", "bing\\.com|google\\.\\w+|yahoo\\.\\w+|gmail\\.\\w+|hotmail\\.\\w+|live\\.\\w+|isearch\\.avg\\.com|mysearch\\.avg\\.com"); Line Found : user_pref("browser.search.defaultenginename", "AVG Secure Search"); Line Found : user_pref("browser.search.selectedEngine", "AVG Secure Search"); Line Found : user_pref("extensions.enabledItems", "[removed]:1.0.176.0,[removed]:1.55 ,{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:3.0.1,{22119944-ED35-4ab1-910B-E619EA06A115}:6.[…] Line Found : user_pref("extensions.kango.storage.minibar.config", "{\"name\":\"FacebookJS\",\"description\":\"Bend facebook to your will\",\"button\":{\"tooltip\":\"Facebook\",\"icon\":\"hxxp://www.bigspeedpro.com[…] Line Found : user_pref("extensions.kango.storage.ui.button.iconCache", "\"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABMAAAATCAYAAAByUDbMAAACF0lEQVQ4jdWUvUtbURiHn 5ASkEIjgTjokkFwcqvFr+RGxUGHbAYcHEUTRG2sNtprg8QYR[…] ************************* AdwCleaner[R0].txt - [22419 octets] - [08/09/2013 19:02:21] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [22480 octets] ##########
Hi Sonja27

You miss JRT and RogueKiller logs Please post them on your next reply ;)

Next

[external image: Posted Image] AdwCleaner

Double click on AdwCleaner.exe to run the tool again.
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished…
  • This time, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

NEXT

Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.

On your next reply please post :
  • JRT log
  • AdwCleaner report
  • All roguekiller logs
  • Combofix log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.5.9 (09.07.2013:1) OS: Windows 7 Home Premium x64 Ran by [removed] on Sun 09/08/2013 at 21:12:57.71 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\datamngr ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\scripthelper.exe Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\viprotocol.dll Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dsiteproducts Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilivid Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installcore Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\yahoopartnertoolbar Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\zugo Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\pricegong Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\utorrentbar Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\conduit.engine Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\protocols\handler\viprotocol Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\s Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi.1 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole.1 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2786678 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\UpdateTask_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\UpdateTask_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetup-r362-n-bf_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetup-r362-n-bf_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_hamachi_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_hamachi_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicUpdate_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicUpdate_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Softonic_EN_1-4-9_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Softonic_EN_1-4-9_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Softonic_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Softonic_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\UpdateTask_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\UpdateTask_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetup-r362-n-bf_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetup-r362-n-bf_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_hamachi_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_hamachi_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicUpdate_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicUpdate_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\Softonic_EN_1-4-9_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\Softonic_EN_1-4-9_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\Softonic_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\Softonic_RASMANCS Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} ~~~ Files Successfully deleted: [File] C:\Windows\Tasks\dsite.job Successfully deleted: [File] "C:\Program Files (x86)\mozilla firefox\plugins\npcouponprinter.dll" Successfully deleted: [File] "C:\Program Files (x86)\mozilla firefox\plugins\npmozcouponprinter.dll" Successfully deleted: [File] "C:\end" ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess" Successfully deleted: [Folder] "C:\Users\Sonja\AppData\Roaming\dsite" Successfully deleted: [Folder] "C:\Users\Sonja\appdata\locallow\conduit" Successfully deleted: [Folder] "C:\Users\Sonja\appdata\locallow\minibar" Successfully deleted: [Folder] "C:\Users\Sonja\appdata\locallow\pricegong" Successfully deleted: [Folder] "C:\Users\Sonja\appdata\locallow\utorrentbar" Successfully deleted: [Folder] "C:\Program Files (x86)\coupons" Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{012428DA-D7BF-43CB-9DD3-23FBF5CE026E} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{01502ED3-C5F4-4F4E-8F03-89C31E0A743F} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{015E5E47-0098-401B-A2D8-5B07D725C732} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{01A27B80-C012-4F49-9F83-3EFBE0947DF9} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{030D1621-9BAB-41B1-A418-7C0CFC5BD1B8} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{036CB772-DA28-4E77-901C-CB9D9AFE7876} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{050B11C4-784F-41F6-AA2E-E1F797594BFB} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{065F943C-E83D-463E-AB85-2FDF2F844FF8} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{06DF232E-A6AB-4F81-942E-3ECDC31DE180} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{079DAA91-17B9-4524-986F-67A77A30FE28} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{07BA263C-643C-4762-987E-0CB655412F20} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{07BA95CC-6E52-44BC-B4DF-A6B04154DF9B} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{095AB81D-0420-4203-9339-8EA42C0B0B75} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{096308B9-3FAA-49D4-9092-D88B767D1449} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{0968E6C7-1A9E-49C0-8916-E864B36C499F} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{0AECFB06-6F82-46DF-8939-4F5F07D07A0C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{0B03A816-FC7B-4E4D-8F59-CB62D895503F} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{0C296B79-2E0F-4B89-B03F-18F2610FE1DC} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{0C480B86-44CE-4728-A076-BDA5573C8277} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{0C719B0E-3CA1-4607-87CA-E6FE4A61D741} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{0C788EED-261B-4975-8600-EB84027DC115} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{0C92D237-1DDE-472D-AA9C-ABE3E50B4C86} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{0CE65868-7B89-494D-88E1-DA00E004F6DC} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{0D5F8340-C40D-46F0-AE52-6451FDB295CA} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{0D7298AF-6D03-4B83-BC8B-409D1993B1DC} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{10258B2C-9E3D-4942-8EAC-434D08A81203} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{10E994B7-51AC-4DF4-B412-A712C27B74AE} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1153E907-B4FE-43F0-A55A-3DDDE36BB409} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{11BAFA25-05F1-47E4-B669-1F2A37A877D4} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1211E76A-3898-4BCC-A01C-2E27619855A5} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1339AEB1-0998-4B60-A318-7160B3F7E49C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{139AB696-B4A4-407E-A393-78508034A598} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1481163E-9412-4B3C-BE0A-4073F2463ACA} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{14CCD073-3440-41EA-BCA0-2F0BEA35677E} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{14DA2B53-A3BD-4AB2-A366-EA55EF3F4655} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1575BE41-6A62-43C2-BF65-66DE8B4267B1} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{15FBF416-ABF4-4139-B0FB-D9BB60258ADC} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{161BD766-0B1B-4AC4-BBC6-C5E6354BD63E} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1668B209-D4E8-48B6-9C5F-C2124DF4C4E7} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{16BC1C21-78D3-473C-8097-825269E6A0E9} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{16E7752E-9859-4A89-B8B6-2D5970A8351B} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1713D4EF-06B4-4280-A492-631191E93E15} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1754F224-215F-46C4-8518-C21B4BD1AA0A} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{18889E98-C6EF-490C-8E9A-E3D28A349376} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{18A878BF-8433-424C-B6E0-865BDB6C493A} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{198A7C2B-ED54-40B2-840F-899251D99C9E} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{19A0006B-63D0-4170-BC22-F524FA11F070} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{19A5754B-AF0D-4B14-82F8-922E6608AD5E} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1A5A7BFD-5385-44BB-8CD2-E98ADB459112} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1AC5E2A4-CDD3-4F9E-80CD-052B56D8F9D9} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1AC769DD-361A-4E03-A213-B45E198507BC} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1CEA4010-26BB-4812-AFA7-FFB81D8A88C1} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1D463026-C095-4CFF-B08B-D42A8EAB7545} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1DBA0187-71AF-4E84-AB3B-351A741CC8F9} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1E5FB24D-F47B-4F39-A3B1-F3D67CC0F59C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{1FEFBA6A-EA7F-4C0C-ADA8-6D7E1F7F0A0D} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{22014C7B-FA84-44B7-B396-FFFCE57FA991} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{220383E1-58E0-4648-BD7F-01E922D897CC} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{24C5C509-99CF-41DE-90A6-F6AB936C82F3} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{251BFBD4-7C74-4D0D-8800-E586E15A287E} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{26387272-4310-44B4-B228-C791FE7D53EB} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{26E72886-C0A9-45EC-A5B4-03E4F9C6F058} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{27E0B877-5A47-4B4B-A08E-F926C6F93971} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{297B3FF2-D80F-4A86-94D9-1B76C88DB954} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{29962D63-EB27-4C82-851D-152FDBB94A5E} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{299B5B05-5FA9-453B-A895-A1EA637F2F49} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{29E8C254-A943-4AE8-AB09-DC2F042E12D8} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{2C020825-A514-4EFA-AA4C-500B656F6526} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{2D838A5F-A4E0-43DF-92F1-84740E27DC44} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{2E96140E-CB86-4838-BDC9-03E2C49F8BC9} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{2EBC45B6-8355-43C2-9D91-ADFAC033AEA2} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{3173636D-9515-4CD8-BC5F-30B0117899D7} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{343B759C-FE4E-41A1-BD8A-97934F688195} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{34536FC3-87EA-4242-A1C7-F7D5DABDE88E} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{3530F0FE-7E4F-41DE-8AE6-8460C4614AEA} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{35379E85-505F-4D1D-A28B-6731327C8863} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{35D04B47-9A80-47DD-AC8F-1889BC0BE51B} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{361BFF91-B001-4B74-91E1-60B7BA10CC31} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{3723B871-58B2-4EFD-B740-E36877934934} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{3790F02B-F271-4874-968D-E4FDD9158E64} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{39B99EDF-523A-4BCA-98FD-C77A97C07DD0} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{3B3BF0F3-F9CD-4DD1-B9B4-70C0C83E18BF} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{3B7CCFE8-8DC4-445F-B29D-FB6DA1EE9408} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{3D4DBCB6-BDB8-4A7E-A696-BD6C4C168BF1} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{3EF22C6C-2DF0-4A3F-8D3A-DA8413D69299} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{3F9E222B-FA79-471C-804F-F3F001CDD4D6} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{3FCC1083-7DCB-4623-BED1-F0CA9CA06E34} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{403D147B-7703-48FF-97B0-0353D23F28AD} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{4276366E-B9A8-4940-8A6A-C66DED6C2F60} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{431EF2D1-317F-4938-A72D-88A8D4A2ACB8} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{43EF31C2-A936-4552-B293-ADBD7A1C7AB8} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{45DD724E-C356-410D-8FCC-2AA964DC73AF} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{460C2011-7E41-49B6-8072-5F6EE3C7DF93} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{46F685C0-1498-481A-BBAD-B28500A0DE7C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{4739EB08-2217-4E4F-93DE-4B452026EB5D} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{484F7977-512D-4C9C-9480-AFFC996192D9} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{4851F5BA-FAE7-472C-92F1-BA030FA0A470} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{4883FC12-91E1-488F-B6C8-120D0936BD85} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{48BADEE5-9CD8-4CB3-B54F-8DAC9C42332B} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{4969E6E9-29D5-4B89-A00D-BC7103A48EFA} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{49EBF680-24F6-4F3B-8418-E07526BC0B81} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{4C3EB4BE-EE39-4A59-B40E-D414FCCBF43E} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{4E04B415-D4C3-4DFD-8B25-431E5CF233A7} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{4F019722-ECE0-4009-B28F-86F84E36FD70} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{505BB993-176B-4EA9-9F81-014A8041EAC7} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{505D1D0A-3208-4347-98B3-213BCBC5BB0A} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{5081BFEB-7872-44EC-AE14-3671A4B6FD2C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{51032B71-92BF-4B4D-B3A0-02F6CB1C43D9} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{52DF5175-BD73-4B26-AD98-14E40C0A55A1} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{53773014-B28B-4146-9550-167B35CF6E79} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{53EB1749-11B5-4537-A992-2D8F4A4F9915} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{55FA3CD1-39C7-447A-BF66-25825967081D} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{56960426-DAD7-45E3-9EAC-4F8EB5A7D65A} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{57E810D3-8F07-4BC0-AE54-473F8DBAD386} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{5AE044D2-A0E6-4541-89E7-2F3A12AD08D5} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{5BEE3C1B-49CB-4E89-8EAE-D09248D31EC3} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{5C9F28BD-7D0A-491A-A247-64EFECF06752} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{5D303051-5BCD-4BF4-A19F-E134919532E1} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{5E8AFB93-19DA-49AC-BDE4-D63B2CFACD22} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{5FA53FC3-AD32-4C22-BC6C-184F14138AC9} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{5FCD2201-C0E9-4D6B-B611-92B99AE087A0} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{60810B9A-DE46-48C4-80C2-64657FA74547} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{60A74495-F860-4D13-8E25-C2D8354474AE} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{6146EE99-9D1B-4C3C-A1D2-D6F4B3BAFCBA} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{6244580A-3D60-4630-9FFB-898C2F791C50} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{6336BE60-F7DF-494B-A641-30C78F8F33F4} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{638A5FF3-B0DA-4F1B-8BFD-C1198489A62D} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{63E259B1-087B-4182-BE03-BEA97439A484} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{64097C44-1DC6-45AC-AFCB-325B61E9D9F6} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{66C40614-ED4C-461C-B9B3-DD066C97A5BE} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{67361F54-B1D4-4C4A-8BB3-7117898BA9A0} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{688CF956-7027-4813-8134-7E4872C8D9A6} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{6A6E626D-FDE4-484C-B391-EFAE4D5C463F} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{6AF9DBB4-B958-402A-B622-D2BCEBD025C5} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{6B62B935-7079-4CDA-A78E-26EFD1CF167A} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{6B9D86E8-A690-47D2-9B5F-4BABE528A8D4} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{6CAFC3ED-74F5-4516-A6CD-B3AC085F997C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{6D1B3CCC-F548-4762-95F2-03E06846D688} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{6E2D3F81-40ED-4EDA-AA3D-4A3327FAEBC7} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{6F6476B7-BCFB-48F2-AB9E-F80961A929B1} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{6F713CAA-DAC1-40EB-A127-2FD5FF0E5007} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{73F05D49-394D-491C-B9FE-BAFC600CC06A} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{745FBEF2-9569-4897-9970-8951DB7D17C3} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{74D97268-0053-45C8-9A30-C1AE2947FC18} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{75E5665E-07AE-4819-BA80-045DE7B0C413} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{75F429E3-BBF4-4089-9F90-1C22AD0E9ED8} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{76B3BD15-2748-4E15-A48E-C5DCCE75F8A9} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{7780D422-4E67-482B-AE86-1F9B82DAD699} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{77BECD81-65EE-4688-A894-FAA5C6C97896} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{7813CEC8-EF08-4498-8125-27AF53700253} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{78EC3E71-B0A9-4924-BC0F-E41E356F4BCD} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{794E34DB-7B29-4EC8-8669-060EF07A441F} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{79C3A066-AE3A-43B9-8136-784609E823E5} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{7A8821B6-E441-4436-BA1A-03A9A1D167EE} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{7BD4D9A0-8D0A-4CB5-9A87-690E1D91C7F3} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{7D0A1F17-061B-46F7-9B00-2FB3F82A8C52} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{7D0F6436-5FFE-4DD2-84A0-8FB593A7FD1F} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{7DE1ACAB-64A8-4A18-BBDD-7177DBD478BD} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{7EF974C2-84E2-4B87-A775-FA7A86B6DE83} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{7F1C8CC9-39D3-4BE0-9899-434BBA994AAF} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{816B2A0B-B3E9-41AA-A2FC-06AFA509E491} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{826A329A-C00C-47C0-BA09-B10CB45E7360} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{8361237D-CD7E-46EE-A470-A4BB476EA06B} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{83A7D876-CA51-4C7C-88D9-B8B0602AD881} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{840A1639-32A9-460D-8095-ABE41EA780BA} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{86B656D8-AEC5-4487-A6D5-6B8089AFE471} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{87005C80-4CEB-406C-95E4-440F40F0C7D7} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{8736F733-AB96-4A9A-B8EA-4C98BBF6BAB8} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{8746FCE1-3DCA-4F2B-BC21-3EA762A27658} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{87476714-0B99-4ADB-ABAB-E742EB80D2F2} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{8971B51B-50DE-4ADE-8FFF-D07F9BD024A7} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{89A29A54-05C7-4E8D-A133-385FD4858080} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{89FF94D1-91DA-4BD4-B4F7-3439C4D22D7A} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{8A1F98F6-B66D-41D0-BA4C-8AACAE3E8406} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{8C636FB0-1E6F-4E6E-AA6C-3B7FF542FD5F} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{8DC56E7F-A347-48BD-80A0-A6431194BCA7} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{8DCEA4DF-335D-48CB-B657-7D3C08FBB48A} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{8EA19BDC-7D8F-4609-B8C4-4E92C703CE00} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{8ED85534-7209-4804-961A-19B5AF29A302} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{90C37261-DC4B-403A-B06A-2B3ABAE18314} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{91D12FDB-D2E3-4559-AE7C-4F51A37252DC} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{91E45DC8-0FA9-4906-88EC-0AE11BAE66A3} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{93D8EE76-7444-44F6-A1B9-046B745E2A3E} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{9553D29A-14E5-48C8-AC43-799830EE12E9} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{95A2CCA2-810D-4B11-9BD9-C2DC821E2372} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{95EE779E-30A9-4133-ABE0-26958C2D87FC} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{96C905C7-628F-45AC-A2EC-453963AF6370} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{987D453B-480C-4414-80C9-9693F71D859C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{98E05627-A760-4058-965A-7DF9C997D5FF} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{99CEC50F-4A33-4D61-B548-8BD58E2BC55B} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{9A3D939C-75C2-46FA-8A6B-52401B3B804C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{9B0D19BD-4740-4F37-A3F7-2E0F1888900F} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{9B5802D5-BB19-46E4-810E-338B79D20AEA} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{9C6DC47E-201D-41CC-A68C-A6349125721C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{9CAE5121-935F-4D77-B98B-4C809F25E285} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{9F116204-BB2B-4EA9-8DDB-F5482225CF00} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{A023D625-0F68-4FA3-9C09-FEE27B1D8DBA} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{A0711DC2-24D9-4FA0-8782-46100B83437C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{A1E044F2-E4B2-480B-BA4C-FBDE609559E2} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{A32832E3-8709-4E23-85E4-D9D905DFF494} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{A553E21A-8D0F-4690-A79A-B463E4CC42E6} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{A6A6FF5A-8EF3-4733-B7D0-10BFB6F3DC35} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{A74AB193-227D-4C34-8CDB-DCDADD7838D4} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{A7CB7FB3-241E-4B45-B013-40D2AED3DBED} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{A9125731-82D4-4AEE-AC50-FA61782605E4} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{AB0151F3-7FE9-4812-8A82-45CD07C2FA98} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{ABD2137F-5D73-468A-B770-7B51C674F2C4} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{AC008857-3095-40D9-82B7-C475F4F754EE} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{AC461746-132E-4017-BA2F-72D89FA949C8} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{AE031A37-F574-420C-B534-00749DEC6A29} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{AE282491-4CCF-4814-AC76-5278D441751B} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{B03155DF-1B3A-4B49-9E12-180922F6D158} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{B04060A0-B549-43D7-A577-0C56336CE8E7} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{B1DEB797-425F-48E1-83B6-79132DF72C9C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{B2CD16F2-9C68-447D-B437-CAF4C451B90D} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{B392FA32-3B72-4731-AFF0-A91CB52349C9} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{B3DF86F6-80D5-4822-B05C-1E255DA7D71A} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{B6EDC7C5-1F07-48DB-9E45-9C2867C3A99B} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{B8934173-CE48-44D2-8A9C-9F32C372E47D} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{B8A798E3-33DC-49F1-A748-CCAF27ED3819} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{B8ACDE26-4124-403C-8E42-57B0653B6194} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{B90C2E5B-9A49-48AB-9E72-10B90FB2F389} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{BC481D16-E270-4CA2-BA38-0CB2700F3460} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{BC62A8DA-B37B-471C-BD89-A733EFA48143} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{BCACB39C-B21D-4405-A091-4E8068D6B05C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{BD8753A1-08BA-48D1-932B-3D58E3F9CC24} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{BDC6A688-CA71-4D07-AA57-D53C2047FCC9} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{BF3846E4-FCC2-4695-87B6-9058F3A2807D} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{C1F2F057-F93A-43EA-98C4-E0D9AF96F066} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{C3F6CBCE-8903-40B9-8DBE-9CF747447761} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{C404C289-9374-42F8-B8EB-C4A8D4FC34C5} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{C472186D-3927-45A0-9950-33F48705277C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{C49EFC82-1A63-44E6-A6A6-467EB82A5CE7} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{C5A87D5A-48FF-4AC1-BE76-09A35A807AE1} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{C5C91107-FF9E-4F50-AD08-156D678DA166} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{C656DD42-A062-47F2-A05F-5AF6BCB858A9} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{C6CF3F11-5158-4AD0-BCCE-D390AA1B6EF4} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{C7226BEE-0C1C-41FC-87E8-4813ED6FA613} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{C773D8A1-8BF0-47A1-A744-68AC614A8F38} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{C7BFAF0A-055D-40F8-A2C1-62FA89A7F201} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{C838E46A-9134-4655-95B5-6B65486FE389} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{CAC8217F-3E8B-42E3-A429-5926530FB2E6} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{CB015572-18B5-4C04-BF5A-8708499D5729} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{CB75388D-3A34-471D-B9D9-89DC5D7C4A64} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{CDA32233-0101-4C4A-A1BD-7D8773895702} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{D15FC480-F221-4FEA-9980-71C281C6D22C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{D227662D-458F-4325-A386-56EACBCA414A} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{D22F0CC2-6B32-422B-AC4E-5E94D2F00766} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{D382D37F-8316-4305-A34E-2A5FF35E4DAA} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{D45A6B9A-9D8A-4263-BA05-D8FCD54606A6} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{D58D7B18-FF61-45C6-BAF0-11AB5AA67003} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{D5D3FC8A-CFEC-48B7-B34E-16600CD70BBF} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{D6A0A44A-71EB-4699-9F2B-ACBC4C5E8A97} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{D8C77BF9-2252-4F2D-BDD1-D155BCD0581F} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{DACEC451-4C10-4571-8723-ABECDB8EA368} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{DC9E4FA3-9F95-4EC0-B8DF-6414DFFE1067} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{DCD19A7D-AE08-412B-BEA9-2664C755D949} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{DCFCA95D-CF6A-4635-9ECD-1B74AD471A4B} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{DF0387F2-7C26-4F77-B8A9-49BD95301F0E} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{DFA718D3-A7A6-446D-8D87-9814DC9E84FF} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{DFF070C2-4303-44A2-B21A-86B9AC73FDF4} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E005AB5E-6B25-4977-8EC0-D40E1D84F25A} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E1261B22-1F3D-4480-A2BD-E738E4B913BD} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E1F04D03-897A-48BE-8CE6-BC25EC74E385} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E2C89996-5166-4637-9AB2-E75FA477535E} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E33666B8-9F30-4685-9860-43A35934580E} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E3C0C5BF-7B0B-49AD-A4CF-4D4B0EC8A11A} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E51113AE-4CCD-4933-B05C-AC63D19D94E3} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E6A2FD0D-E21C-4506-A01F-ECDD559E143B} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E6BF4798-3318-478B-A8DA-BDAD10633CFE} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E77128D2-337D-4EED-BBCE-2713212B77A3} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E773909D-6AA3-497D-9F4B-8A424B92A81B} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E7A10EFF-7602-4DF3-B0C6-D017C34ED734} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E80FE0DD-017A-46F2-9BF7-36869FF692E6} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E85F666B-BDCB-4022-9A9B-440C39A407FD} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{E9F7B8DD-8340-429E-AE6B-EC3068AA390C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{EC28367B-A5E0-4950-81B0-8D45DB420EA8} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{EC3BD4EB-B1CB-479E-9B06-203EBC4B7987} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{ECD198F7-40DE-44B6-AC88-928656390A7C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{ED8C6BB8-A6F8-4410-81E0-CEE62F1B4B75} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{EEA98FA2-0997-4E61-8CA8-83AD97504D32} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{EECDF4EC-796E-4850-8179-545DA666A17F} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{F11BF7E1-719D-4314-BFA1-A4AE930ABE85} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{F3BAA2C0-96B0-48A4-A1DA-9ECF81F8DBAF} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{F3D600C0-1E9B-4886-B3AD-B21BD5E6A2B9} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{F3E85AA9-7B55-4535-9D08-C5530B26F786} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{F4E5F19A-B5E0-4BC2-926C-B4E010862707} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{F527F225-D74D-4095-A117-293F1B01755F} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{F588CED4-D104-49A9-80CC-322E1552CA05} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{F5DDC3FE-BD5D-445E-B011-D4D10942B5C4} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{F612C717-CE1C-41D1-AAAE-26CD3625A2A0} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{F65DE7E1-6A48-4DE4-A5DC-4EBEBAA9FE19} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{F691EAC8-2DCF-4B2C-9F91-728B903E7A79} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{F7B0B00E-8F60-425C-8943-B38D5CAE62F8} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{F9128F34-1286-4F64-8D94-8106AEA33CCB} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{F92AEC0C-C24C-4B48-9F41-E4B479DC6108} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{FAB6DD84-8F5E-454B-89AB-4BFCDC8EE027} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{FBC221F9-7879-4EFB-A57B-1112B157006C} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{FC41400F-A4B7-4B45-B5A4-EF4A2A07D1C1} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{FC5B1F39-CC2B-473A-BFC9-033BB9D4FACB} Successfully deleted: [Empty Folder] C:\Users\Sonja\appdata\local\{FD2AB4C1-13FA-48A6-9CC2-7049A3E5921C} ~~~ FireFox Failed to delete: [File] "C:\Program Files (x86)\Mozilla Firefox\searchplugins\safesearch.xml" Successfully deleted: [File] "C:\Program Files (x86)\Mozilla Firefox\searchplugins\safesearch.xml" Successfully deleted: [File] C:\Users\Sonja\AppData\Roaming\mozilla\firefox\profiles\mjoa72o7.default\user.js Successfully deleted: [File] C:\Users\Sonja\AppData\Roaming\mozilla\firefox\profiles\mjoa72o7.default\searchplugins\safesearch.xml Successfully deleted: [Folder] C:\Users\Sonja\AppData\Roaming\mozilla\firefox\profiles\mjoa72o7.default\extensions\[removed] Successfully deleted the following from C:\Users\Sonja\AppData\Roaming\mozilla\firefox\profiles\mjoa72o7.default\prefs.js user_pref("CT2786678..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent"); user_pref("CT2786678..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation"); user_pref("CT2786678.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); user_pref("CT2786678.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); user_pref("CT2786678.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx"); user_pref("CT2786678.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q="); user_pref("CT2786678.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID"); user_pref("CT2786678.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID"); user_pref("CT2786678.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID"); user_pref("CT2786678.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT"); user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1178763/1174448/US", "\"0\""); user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/US", "\"0\""); user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2786678", "\"1285982114\""); user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en", "L+tncv4eqt6Qm5T3dzChdA=="); user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en", "poKjTfHs0NrVUIalKI8jyg=="); user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en", "QmycQXJXVyFVAzIiNllWhQ=="); user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en", "SuMy8xgBA7+FodOxmk9aiQ=="); user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"634289840782570000\""); user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634303635100000000"); user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2786678/CT2786678", "\"1295273672\""); user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"634307860320500000\""); user_pref("CommunityToolbar.EngineOwner", "CT2786678"); user_pref("CommunityToolbar.EngineOwnerGuid", "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"); user_pref("CommunityToolbar.EngineOwnerToolbarId", "utorrentbar"); user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); user_pref("CommunityToolbar.OriginalEngineOwner", "CT2786678"); user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"); user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "utorrentbar"); user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.properties"); user_pref("CommunityToolbar.ToolbarsList", "ConduitEngine,CT2786678"); user_pref("CommunityToolbar.ToolbarsList2", "ConduitEngine,CT2786678"); user_pref("CommunityToolbar.alert.alertInfoInterval", 1440); user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed Dec 07 2011 17:24:48 GMT-0800 (Pacific Standard Time)"); user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); user_pref("CommunityToolbar.alert.locale", "en"); user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Dec 07 2011 17:24:48 GMT-0800 (Pacific Standard Time)"); user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611"); user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); user_pref("CommunityToolbar.alert.showTrayIcon", false); user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); user_pref("CommunityToolbar.alert.userId", "bf85937d-e423-497b-8e9d-ac25fc054afd"); user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); user_pref("ConduitEngine.CTID", "ConduitEngine"); user_pref("ConduitEngine.FirstServerDate", "01/17/2011 20"); user_pref("ConduitEngine.FirstTime", true); user_pref("ConduitEngine.FirstTimeFF3", true); user_pref("ConduitEngine.FixPageNotFoundErrors", false); user_pref("ConduitEngine.HasUserGlobalKeys", true); user_pref("ConduitEngine.Initialize", true); user_pref("ConduitEngine.InitializeCommonPrefs", true); user_pref("ConduitEngine.InstallationType", "UnknownIntegration"); user_pref("ConduitEngine.InstalledDate", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); user_pref("ConduitEngine.IsMulticommunity", false); user_pref("ConduitEngine.IsOpenThankYouPage", false); user_pref("ConduitEngine.IsOpenUninstallPage", false); user_pref("ConduitEngine.LanguagePackLastCheckTime", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); user_pref("ConduitEngine.LastLogin_3.2.5.2", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); user_pref("ConduitEngine.PublisherContainerWidth", 0); user_pref("ConduitEngine.SearchFromAddressBarIsInit", true); user_pref("ConduitEngine.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CTXXXX&q="); user_pref("ConduitEngine.SettingsLastCheckTime", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); user_pref("ConduitEngine.UserID", "UN35375416743791666"); user_pref("ConduitEngine.engineLocale", "en-US"); user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); user_pref("ConduitEngine.initDone", true); user_pref("browser.bdtoolbar.search_searchbar", false); user_pref("extensions.kango.storage.minibar.config", "{\"name\":\"FacebookJS\",\"description\":\"Bend facebook to your will\",\"button\":{\"tooltip\":\"Facebook\",\"icon\":\"h ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Sun 09/08/2013 at 21:21:21.02 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
I ran this and here's the log. Still working on RogueKiller. I may have to uninstall and reinstall. # AdwCleaner v3.003 - Report created 08/09/2013 at 21:38:18 # Updated 07/09/2013 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : Sonja - SONJA-PC # Running from : C:\Users\Sonja\Desktop\AdwCleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search Folder Deleted : C:\Users\Sonja\AppData\Local\PackageAware Folder Deleted : C:\Users\Sonja\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z Folder Deleted : C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\Conduit Folder Deleted : C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\ConduitEngine Folder Deleted : C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D6598005-A921-4F83-B6E6-F4F030D1BF37} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0F6ECBD3-98B1-4044-8520-69407A70C83C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8A41F062-A222-4322-A8C4-26218BE869B9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C0207057-3461-4F7F-B689-D016B7A03964} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C6A61AAE-D30B-4E7A-A3D8-8A34E5BA3414} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4F9AD2F2-3A64-470E-93F7-A03423E52ACA} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A7C2FCDD-0359-49DD-8339-BE2A5BD60918} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F13D3582-1359-4F8F-9A48-EF3AE9F5701C} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKCU\Software\Ask&Record Key Deleted : HKLM\Software\AVG Security Toolbar Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages ***** [ Browsers ] ***** -\\ Internet Explorer v9.0.8112.16421 -\\ Mozilla Firefox v8.0.1 (en-US) [ File : C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\mjoa72o7.default\prefs.js ] Line Deleted : user_pref("CT2786678..clientLogIsEnabled", false); Line Deleted : user_pref("CT2786678.CTID", "CT2786678"); Line Deleted : user_pref("CT2786678.CurrentServerDate", "17-1-2011"); Line Deleted : user_pref("CT2786678.DialogsAlignMode", "LTR"); Line Deleted : user_pref("CT2786678.DownloadReferralCookieData", ""); Line Deleted : user_pref("CT2786678.EMailNotifierPollDate", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.FeedLastCount5690698542593514850", 183); Line Deleted : user_pref("CT2786678.FeedPollDate129301619375443753", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.FeedPollDate129301619375443759", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.FeedPollDate129301619375444699", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.FeedPollDate129301619375444705", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.FeedPollDate129301619375444711", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.FeedPollDate129301619375444717", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.FeedPollDate129301619375444723", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.FeedPollDate129301619375444729", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.FeedPollDate129301619375444735", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.FeedPollDate129301619375444741", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.FeedPollDate129301619375444747", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.FeedTTL129301619375444699", 10); Line Deleted : user_pref("CT2786678.FeedTTL129301619375444723", 15); Line Deleted : user_pref("CT2786678.FeedTTL129301619375444735", 5); Line Deleted : user_pref("CT2786678.FeedTTL129301619375444747", 5); Line Deleted : user_pref("CT2786678.FirstServerDate", "17-1-2011"); Line Deleted : user_pref("CT2786678.FirstTime", true); Line Deleted : user_pref("CT2786678.FirstTimeFF3", true); Line Deleted : user_pref("CT2786678.FixPageNotFoundErrors", false); Line Deleted : user_pref("CT2786678.GroupingServerCheckInterval", 1440); Line Deleted : user_pref("CT2786678.HasUserGlobalKeys", true); Line Deleted : user_pref("CT2786678.Initialize", true); Line Deleted : user_pref("CT2786678.InitializeCommonPrefs", true); Line Deleted : user_pref("CT2786678.InstallationAndCookieDataSentCount", 1); Line Deleted : user_pref("CT2786678.InstallationType", "UnknownIntegration"); Line Deleted : user_pref("CT2786678.InstalledDate", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.IsGrouping", false); Line Deleted : user_pref("CT2786678.IsMulticommunity", false); Line Deleted : user_pref("CT2786678.IsOpenThankYouPage", true); Line Deleted : user_pref("CT2786678.IsOpenUninstallPage", false); Line Deleted : user_pref("CT2786678.LanguagePackLastCheckTime", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.LanguagePackReloadIntervalMM", 1440); Line Deleted : user_pref("CT2786678.LastLogin_3.2.5.2", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.LatestVersion", "3.2.5.2"); Line Deleted : user_pref("CT2786678.Locale", "en"); Line Deleted : user_pref("CT2786678.MCDetectTooltipHeight", "83"); Line Deleted : user_pref("CT2786678.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Line Deleted : user_pref("CT2786678.MCDetectTooltipWidth", "295"); Line Deleted : user_pref("CT2786678.SearchFromAddressBarIsInit", true); Line Deleted : user_pref("CT2786678.SearchInNewTabEnabled", true); Line Deleted : user_pref("CT2786678.SearchInNewTabIntervalMM", 1440); Line Deleted : user_pref("CT2786678.SearchInNewTabLastCheckTime", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.ServiceMapLastCheckTime", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.SettingsLastCheckTime", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.SettingsLastUpdate", "1295273672"); Line Deleted : user_pref("CT2786678.ThirdPartyComponentsInterval", 504); Line Deleted : user_pref("CT2786678.ThirdPartyComponentsLastCheck", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.ThirdPartyComponentsLastUpdate", "1246790578"); Line Deleted : user_pref("CT2786678.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=101&sealid=112"); Line Deleted : user_pref("CT2786678.UserID", "UN66697515828275327"); Line Deleted : user_pref("CT2786678.WeatherNetwork", ""); Line Deleted : user_pref("CT2786678.WeatherPollDate", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.WeatherUnit", "C"); Line Deleted : user_pref("CT2786678.alertChannelId", "1178763"); Line Deleted : user_pref("CT2786678.myStuffEnabled", true); Line Deleted : user_pref("CT2786678.myStuffPublihserMinWidth", 400); Line Deleted : user_pref("CT2786678.myStuffServiceIntervalMM", 1440); Line Deleted : user_pref("CT2786678.testingCtid", ""); Line Deleted : user_pref("CT2786678.toolbarAppMetaDataLastCheckTime", "Mon Jan 17 2011 09:16:01 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CT2786678.toolbarContextMenuLastCheckTime", "Mon Jan 17 2011 09:16:02 GMT-0800 (Pacific Standard Time)"); Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1178763/1174448/US", "\"0\""); Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/US", "\"0\""); Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2786678", "\"1285982114\""); Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"634289840782570000\""); Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2786678/CT2786678", "\"1295273672\""); Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"634307860320500000\""); Line Deleted : user_pref("avg.userPreferences.URLBarFocus.whiteList", "bing\\.com|google\\.\\w+|yahoo\\.\\w+|gmail\\.\\w+|hotmail\\.\\w+|live\\.\\w+|isearch\\.avg\\.com|mysearch\\.avg\\.com"); Line Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search"); Line Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search"); Line Deleted : user_pref("extensions.enabledItems", "[removed]:1.0.176.0,[removed]:1.55 ,{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:3.0.1,{22119944-ED35-4ab1-910B-E619EA06A115}:6.[…] Line Deleted : user_pref("extensions.kango.storage.minibar.config", "{\"name\":\"FacebookJS\",\"description\":\"Bend facebook to your will\",\"button\":{\"tooltip\":\"Facebook\",\"icon\":\"hxxp://www.bigspeedpro.com[…] Line Deleted : user_pref("extensions.kango.storage.ui.button.iconCache", "\"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABMAAAATCAYAAAByUDbMAAACF0lEQVQ4jdWUvUtbURiHn 5ASkEIjgTjokkFwcqvFr+RGxUGHbAYcHEUTRG2sNtprg8QYR[…] ************************* AdwCleaner[R0].txt - [22597 octets] - [08/09/2013 19:02:21] AdwCleaner[R1].txt - [11923 octets] - [08/09/2013 21:36:51] AdwCleaner[S0].txt - [12039 octets] - [08/09/2013 21:38:18] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12100 octets] ##########

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI