This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My husband's computer is infected with malware once again! He

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

We use Microsoft Security Essentials and several days ago, it stopped responding on my husband's computer. Last night I was trying to uninstall his MSE and reinstall it, hoping this would fix the glitch and it was then that I realized his computer seems to definitely be infected. Unable to reinstall MSE. Unable to see if the Windows Firewall is on. Able to get to search engines such as Mozilla Firefox and Google but I did notice this problem. When I googled something and the hits came up, when I clicked on any link, instead of taking me to the correct location, his computer now goes to some advertisement. Please advise! You guys have been my salvation many times in the past. I think my computer has been infected maybe once; my husband has a penchant for getting his infected! I anxiously await your guidance! Thank you!! :o

Here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:46:59 AM, on 9/27/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Nuance\dgnsvc.exe
C:\WINDOWS\system32\IProsetMonitor.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
C:\Program Files\PDF Architect\HelperService.exe
C:\Program Files\PDF Architect\ConversionService.exe
c:\documents and settings\all users\application data\Clickfree\C2NPlus\Reminder\SacNetAgent.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe
C:\Program Files\Common Files\AOL\1270162804\ee\AOLSoftware.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor\visicom_antiphishing.exe
C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Documents and Settings\All Users\Application Data\clickfree\cfagent.exe
C:\documents and settings\all users\application data\Clickfree\C2NPlus\reminder\SacReminder.exe
C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files\WizMouse\WizMouse.exe
C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AnVir Task Manager\anvir.exe
C:\Program Files\Software Informer\softinfo.exe
C:\Program Files\Upromise\dca-ua.exe
C:\Program Files\Upromise\UpromiseTray.exe
C:\Program Files\AOL Desktop 9.6\waol.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\AOL Desktop 9.6\shellmon.exe
C:\Program Files\Common Files\aol\1270162804\ee\aolupdates.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Drew Krajeski\My Documents\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=fmtob…p;cr=1837363338
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6081010
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: FCToolbarURLSearchHook Class - {2d914c15-11e5-93b4-ad21-35ba2aec33c8} - C:\Program Files\Ebates Cash Back Toolbar\Helper.dll
O2 - BHO: CouponFollow.BHO - {2018eb71-06b5-4438-abf4-e40df31e0be5} - mscoree.dll (file missing)
O2 - BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll
O2 - BHO: Qwiklinx - {3E7C8B5A-96AB-438F-BF9B-782400655440} - C:\Documents and Settings\Drew Krajeski\Application Data\Qwiklinx\Qwiklinx.dll
O2 - BHO: ShopAtHome - {66516A07-F617-488A-90CF-4E690CFB3C5F} - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll
O2 - BHO: FCTBPos00Pos - {796E3F7C-B3A1-6094-41A6-21866FF2BAD6} - C:\Program Files\Ebates Cash Back Toolbar\Toolbar.dll
O2 - BHO: DCA - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files\Upromise\dca-bho.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (file missing)
O2 - BHO: ToolHelper - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll
O2 - BHO: Freecause Shopping BHO - {F9E44926-2497-46F3-8A25-928136AC079E} - C:\Program Files\Shop to Win 20\Shop to Win 20.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O3 - Toolbar: PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files\PDF Architect\PDFIEPlugin.dll
O3 - Toolbar: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O3 - Toolbar: ShopAtHome.com Toolbar - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll
O3 - Toolbar: Support.com Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Ebates Cash Back Toolbar - {FC5405B9-EE85-8754-9D4F-9CC300948A6F} - C:\Program Files\Ebates Cash Back Toolbar\Toolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1270162804\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking11\Ereg.ini
O4 - HKLM\..\Run: [Nuance.ctfmngr] C:\Program Files\Nuance\NaturallySpeaking11\Program\ctfmngr.exe /restore
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Anti-phishing Domain Advisor] "C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor\visicom_antiphishing.exe"
O4 - HKLM\..\Run: [ShopAtHomeWatcher] C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ClickfreeMonitor] C:\Documents and Settings\All Users\Application Data\clickfree\cfagent.exe
O4 - HKCU\..\Run: [SacReminderHDDV2N] c:\documents and settings\all users\application data\Clickfree\C2NPlus\reminder\SacReminder.exe
O4 - HKCU\..\Run: [ISUSPM] C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe -scheduler
O4 - HKCU\..\Run: [WizMouse] "C:\Program Files\WizMouse\WizMouse.exe"
O4 - HKCU\..\Run: [InstallIQUpdater] "C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe" /silent /autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnVir Task Manager] "C:\Program Files\AnVir Task Manager\anvir.exe" Minimized
O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun
O4 - HKCU\..\Run: [PC Speed Maximizer] "C:\Program Files\PC Speed Maximizer\SPMStarter.exe"
O4 - HKCU\..\Run: [SPMTray] "C:\Program Files\PC Speed Maximizer\SPMTray.exe"
O4 - HKCU\..\Run: [Upromise Update] C:\Program Files\Upromise\dca-ua.exe
O4 - HKCU\..\Run: [Upromise Tray] C:\Program Files\Upromise\UpromiseTray.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL Desktop 9.6\AOL.EXE" -b
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Desktop\Install\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\???\???\???\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\GoogleUpdate.exe" >
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O9 - Extra 'Tools' menuitem: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O9 - Extra button: Coupons at Checkout Settings - {2018eb71-06b5-4438-abf4-e40df31e0be5} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Coupons at Checkout Settings - {2018eb71-06b5-4438-abf4-e40df31e0be5} - mscoree.dll (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfios.verizon.net/sdcCommo…20Installer.cab
O16 - DPF: {36299202-09EF-4ABF-ADB9-47C599DBE778} (HP Product Detection Control) - https://www.hpwindows7upgrade.arvato.com/no…PProdDetect.cab
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://juniper.net/dana-cached/sc/JuniperSetupClient.cab
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Dragon Service (DragonSvc) - Nuance Communications, Inc. - C:\Program Files\Common Files\Nuance\dgnsvc.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® PROSet Monitoring Service - Intel Corporation - C:\WINDOWS\system32\IProsetMonitor.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Microsoft Antimalware Service (MsMpSvc) - Unknown owner - c:\Program Files\Microsoft Security Client\MsMpEng.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
O23 - Service: PDF Architect Helper Service - pdfforge GbR - C:\Program Files\PDF Architect\HelperService.exe
O23 - Service: PDF Architect Service - pdfforge GbR - C:\Program Files\PDF Architect\ConversionService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SacNetAgentService_C57C4F854F53 - Storage Appliance Corporation - c:\documents and settings\all users\application data\Clickfree\C2NPlus\Reminder\SacNetAgent.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 14814 bytes
Thanks in advance for your help!!
Hi cranmergirl,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.

=========================

[external image: Posted Image] Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
=========================

[external image: Posted Image] aswMBR

Download aswMBR.exe and save it to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
=========================
[external image: Posted Image] OTL

Download OTL to your desktop.
  • Make sure all other windows are closed and to let it run uninterrupted.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    services.*
    /md5stop
    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    dir "%systemdrive%\*" /S /A:L /C
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    BASESERVICES
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
    • You may need two posts to fit them both in.
=========================

In your next post please provide the following:
  • checkup.txt
  • aswMBR.txt
  • attach MBR.zip
  • OTL.txt
  • Extras.txt
Hi OCD! Thank you so much for replying. Full disclosure…since I first posted on WTT, I did several things. I was able to download Malwarebytes Anti-Malware in safe mode and run it. I deleted all malware shown. I tried to do a System Restore and each time I would choose a date and go through the process, my computer would say that System Restore was "incomplete." However, at some point, I realized that Microsoft Security Essentials was back on my husband's computer! Strange since I had uninstalled it and had been unable to reinstall it. Apparently, I had been successful in reinstalling it but the virus was hiding its existence from me?? Anyway; I updated MSE and ran it. It found a Trojan:Win 32/Sirefef.AB. I quarantined it and then deleted it. So now I will follow your instructions carefully. Here is the checkup.txt log:

Results of screen317's Security Check version 0.99.73
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Spykee
Malwarebytes Anti-Malware version 1.75.0.1300
Wise Disk Cleaner Professional v5.2
JavaFX 2.0.2
Java™ 7 Update 2
Java™ 6 Update 7
Java version out of Date!
Adobe Flash Player 11.8.800.168
Adobe Reader 10.1.8 Adobe Reader out of Date!
Mozilla Firefox (23.0.1)
Google Chrome 29.0.1547.66
Google Chrome 29.0.1547.76
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
Microsoft Security Essentials MSMpEng.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 21% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````


Here is aswMBR.txt:

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-09-27 23:41:19
—————————–
23:41:19.328 OS Version: Windows 5.1.2600 Service Pack 3
23:41:19.328 Number of processors: 2 586 0x1706
23:41:19.328 ComputerName: D3H5MKH1 UserName:
23:41:20.281 Initialize success
23:43:48.812 AVAST engine defs: 13092702
23:44:02.875 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
23:44:02.875 Disk 0 Vendor: Hitachi_HDP725050GLA360 GM4OA5BA Size: 476940MB BusType: 3
23:44:03.078 Disk 0 MBR read successfully
23:44:03.078 Disk 0 MBR scan
23:44:03.125 Disk 0 Windows XP default MBR code
23:44:03.140 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 54 MB offset 63
23:44:03.171 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 476874 MB offset 112455
23:44:03.203 Disk 0 scanning sectors +976752000
23:44:03.296 Disk 0 scanning C:\WINDOWS\system32\drivers
23:44:22.265 Service scanning
23:44:36.375 Service MpKsl5d4d37ee c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{82E4A7D1-4639-4B8E-88A5-9377E32D0804}\MpKsl5d4d37ee.sys **LOCKED** 32
23:44:52.437 Service ?etadpug C:\Program Files\Google\Desktop\Install\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\ \ **HIDDEN**
23:44:52.968 Modules scanning
23:44:59.015 Disk 0 trace - called modules:
23:44:59.046 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
23:44:59.062 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8abf2ab8]
23:44:59.078 3 CLASSPNP.SYS[ba0f8fd7] -> nt!IofCallDriver -> \Device\0000006d[0x8ac72248]
23:44:59.078 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8abf6940]
23:44:59.984 AVAST engine scan C:\WINDOWS
23:45:17.859 AVAST engine scan C:\WINDOWS\system32
23:49:23.703 AVAST engine scan C:\WINDOWS\system32\drivers
23:49:56.421 AVAST engine scan C:\Documents and Settings\Drew Krajeski
23:53:44.812 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Drew Krajeski\My Documents\VIRUS FIXES\MBR.dat"
23:53:44.859 The log file has been saved successfully to "C:\Documents and Settings\Drew Krajeski\My Documents\VIRUS FIXES\aswMBR.txt"

Here is the OTL.txt:

OTL logfile created on: 9/28/2013 12:00:59 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Drew Krajeski\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.99 Gb Total Physical Memory | 1.94 Gb Available Physical Memory | 64.88% Memory free
4.83 Gb Paging File | 3.77 Gb Available in Paging File | 77.98% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.70 Gb Total Space | 399.11 Gb Free Space | 85.70% Space Free | Partition Type: NTFS
Drive E: | 133.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive J: | 931.30 Gb Total Space | 927.86 Gb Free Space | 99.63% Space Free | Partition Type: NTFS

Computer Name: D3H5MKH1 | User Name: Drew Krajeski | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Drew Krajeski\My Documents\Downloads\OTL(2).exe (OldTimer Tools)
PRC - C:\Documents and Settings\Drew Krajeski\My Documents\Downloads\aswMBR(1).exe (AVAST Software)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AOL Desktop 9.7\waol.exe (AOL Inc.)
PRC - C:\Program Files\AOL Desktop 9.7\shellmon.exe (AOL Inc.)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe ()
PRC - C:\Program Files\PDF Architect\HelperService.exe (pdfforge GbR)
PRC - C:\Program Files\PDF Architect\ConversionService.exe (pdfforge GbR)
PRC - C:\Documents and Settings\Drew Krajeski\Local Settings\Temp\Foxit Updater.exe (Foxit Corporation)
PRC - C:\Program Files\AnVir Task Manager\AnVir.exe (AnVir Software)
PRC - C:\WINDOWS\system32\IPROSetMonitor.exe (Intel Corporation)
PRC - C:\Program Files\Software Informer\softinfo.exe (Informer Technologies, Inc.)
PRC - C:\Program Files\Upromise\UpromiseTray.exe (Upromise, Inc.)
PRC - C:\Program Files\Upromise\dca-ua.exe (Compete, Inc.)
PRC - C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor\visicom_antiphishing.exe (Visicom Media Inc. (Powered by Panda Security))
PRC - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\WizMouse\WizMouse.exe ()
PRC - C:\Documents and Settings\All Users\Application Data\Clickfree\C2NPlus\Reminder\SacReminder.exe (Storage Appliance Corp.)
PRC - c:\Documents and Settings\All Users\Application Data\Clickfree\C2NPlus\Reminder\SacNetAgent.exe (Storage Appliance Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\Clickfree\cfagent.exe (Clickfree)
PRC - C:\Program Files\Common Files\Nuance\dgnsvc.exe (Nuance Communications, Inc.)
PRC - C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
PRC - C:\Program Files\Common Files\aol\1270162804\ee\aolsoftware.exe (AOL Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
PRC - C:\Program Files\Common Files\aol\acs\AOLacsd.exe (AOL LLC)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\AOL Desktop 9.7\zlib.dll ()
MOD - C:\Program Files\AOL Desktop 9.7\libcef.dll ()
MOD - C:\Program Files\AOL Desktop 9.7\libGLESv2.dll ()
MOD - C:\Program Files\AOL Desktop 9.7\libEGL.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\f93600ac836b9140e1df13bb0f6bfccf\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\10df39542df7d48462451fc39bce8418\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\b14359470744c840c59fbe4e58034fd6\mscorlib.ni.dll ()
MOD - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe ()
MOD - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelperPS.dll ()
MOD - C:\Program Files\WizMouse\WizMouse.exe ()
MOD - C:\WINDOWS\system32\IS_ContextMenu.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Clickfree\C2NPlus\Reminder\1530Class.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Clickfree\C2NPlus\Reminder\SPTIASPI.DLL ()
MOD - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()


========== Services (SafeList) ==========

SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe File not found
SRV - (etadpug) – C:\Program Files\Google\Desktop\Install\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\ \ \ﯹ๛\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\GoogleUpdate.exe < [WARNING: C:\Program Files\Google\Desktop\Install\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\ \ \???\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\GoogleUpdate.exe <] File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (PDF Architect Helper Service) – C:\Program Files\PDF Architect\HelperService.exe (pdfforge GbR)
SRV - (PDF Architect Service) – C:\Program Files\PDF Architect\ConversionService.exe (pdfforge GbR)
SRV - (Intel® – C:\WINDOWS\system32\IPROSetMonitor.exe (Intel Corporation)
SRV - (PCCUJobMgr) – C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
SRV - (SacNetAgentService_C57C4F854F53) – c:\Documents and Settings\All Users\Application Data\Clickfree\C2NPlus\Reminder\SacNetAgent.exe (Storage Appliance Corporation)
SRV - (DragonSvc) – C:\Program Files\Common Files\Nuance\dgnsvc.exe (Nuance Communications, Inc.)
SRV - (rpcapd) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (sprtsvc_dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\aol\acs\AOLacsd.exe (AOL LLC)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (SSPORT) – C:\WINDOWS\system32\Drivers\SSPORT.sys File not found
DRV - (rt2870) – system32\DRIVERS\rt2870.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (PCASp50) – System32\Drivers\PCASp50.sys File not found
DRV - (MRESP50a64) – C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS File not found
DRV - (MRESP50) – C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (MREMP50a64) – C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS File not found
DRV - (MREMP50) – C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (chakfphd) – C:\WINDOWS\system32\drivers\chakfphd.sys File not found
DRV - (catchme) – C:\DOCUME~1\DREWKR~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (aswMBR) – C:\DOCUME~1\DREWKR~1\LOCALS~1\Temp\aswMBR.sys File not found
DRV - (MpKsl5d4d37ee) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{82E4A7D1-4639-4B8E-88A5-9377E32D0804}\MpKsl5d4d37ee.sys (Microsoft Corporation)
DRV - (DigiartyVirtualCDBus) – C:\WINDOWS\system32\drivers\DigiartyVirtualCDBus.sys (LotSoft, Inc.)
DRV - (SWDUMon) – C:\WINDOWS\system32\drivers\SWDUMon.sys ()
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (Linksys_adapter_H) – C:\WINDOWS\system32\drivers\AE1200xp.sys (Broadcom Corporation)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (DgiVecp) – C:\WINDOWS\system32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)
DRV - (wanatw) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=fmtob…p;cr=1837363338
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6081010
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6081010
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {443789B7-F39C-4b5c-9287-DA72D38F4FE6}
IE - HKLM\..\SearchScopes,DefaultScope = {443789B7-F39C-4b5c-9287-DA72D38F4FE6}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1837363338
IE - HKLM\..\SearchScopes\{79809194-BE76-9834-A9A7-3EAFA9125A67}: "URL" = http://slirsredirect.search.aol.com/redire…mrud=17-07-2011

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://www.foxnews.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {2d914c15-11e5-93b4-ad21-35ba2aec33c8} - C:\Program Files\Ebates Cash Back Toolbar\Helper.dll ()
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
IE - HKCU\..\SearchScopes,DefaultScope = {DD234610-0BA5-43EE-B017-E6C01556EB35}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…56-EBC4D0131CA7
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1837363338
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{79809194-BE76-9834-A9A7-3EAFA9125A67}: "URL" = http://blekkosearch.mystart.com/blekkotb_s…q={searchTerms}
IE - HKCU\..\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}: "URL" = http://search.alot.com/web?q={searchTerms}
IE - HKCU\..\SearchScopes\{D5F539B8-1FC6-48C7-85E9-4D74D6906162}: "URL" = http://slirsredirect.search.aol.com/redire…mrud=17-07-2011
IE - HKCU\..\SearchScopes\{DD234610-0BA5-43EE-B017-E6C01556EB35}: "URL" = http://srp.freecause.com/?ourmark=4&si…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Search the Web"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.foxnews.com|www.google.com"
FF - prefs.js..extensions.enabledAddons: FFToolbar%40upromise:7.1.0.5277
FF - prefs.js..extensions.enabledAddons: %7Bb9871413-95b7-01c4-69cf-961a01420158%7D:1.301.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.2.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.2.1: C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@logitech.com/HarmonyRemote,version=1.0.0: C:\Program Files\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files\Verizon\VSP\nprpspa.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\PDF Architect\FFPDFArchitectExt [2013/01/11 15:58:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/09/07 15:21:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/09/27 14:57:28 | 000,000,000 | —D | M]

[2009/08/09 15:05:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Extensions
[2013/09/27 11:52:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\extensions
[2013/05/09 17:45:09 | 000,000,000 | —D | M] (Support.com Toolbar) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\extensions\[removed]
[2013/01/12 15:56:20 | 000,455,818 | —- | M] () (No name found) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\extensions\[removed]
[2013/09/07 14:33:29 | 000,431,310 | —- | M] () (No name found) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\extensions\{b9871413-95b7-01c4-69cf-961a01420158}.xpi
[2013/05/09 17:45:09 | 000,002,336 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\searchplugins\askcom.xml
[2013/09/07 15:21:34 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/09/07 15:22:05 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/12/09 19:16:12 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2009/11/19 18:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2009/11/19 18:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2008/06/03 01:35:57 | 000,002,275 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\aolsearch.xml
[2012/01/06 07:31:07 | 000,002,049 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml
[2012/06/07 20:39:30 | 000,002,158 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\search.xml

========== Chrome ==========

CHR - default_search_provider: Web Search (Enabled)
CHR - default_search_provider: search_url = http://start.funmoods.com/results.php?f=4&…p;cr=1837363338
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://start.funmoods.com/?f=1&a=fmtob…p;cr=1837363338
CHR - plugin: First user (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Error reading preferences file
CHR - Extension: SaveByclick = C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bgfaeeogolelccmmfcfoikennpedhhno\1_0\
CHR - Extension: FunDial = C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\1.0.1_0\
CHR - Extension: Make this page red = C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dnfaglepmjgohnkcoieaijlheabmcdeo\1.2_0\
CHR - Extension: Funmoods = C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\1.5.1_0\

O1 HOSTS File: ([2012/02/01 16:50:17 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (PDF Architect Helper) - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
O2 - BHO: (Qwiklinx) - {3E7C8B5A-96AB-438F-BF9B-782400655440} - C:\Documents and Settings\Drew Krajeski\Application Data\Qwiklinx\Qwiklinx.dll (Qwiklinx, Inc.)
O2 - BHO: (ShopAtHome.com Cash Back Helper) - {66516A07-F617-488A-90CF-4E690CFB3C5F} - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
O2 - BHO: (Ebates Cash Back Toolbar BHO) - {796E3F7C-B3A1-6094-41A6-21866FF2BAD6} - C:\Program Files\Ebates Cash Back Toolbar\Toolbar.dll ()
O2 - BHO: (DCA BHO) - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files\Upromise\dca-bho.dll (Compete, Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll File not found
O2 - BHO: (Upromise TurboSaver) - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O2 - BHO: (Shop to Win) - {F9E44926-2497-46F3-8A25-928136AC079E} - C:\Program Files\Shop to Win 20\Shop to Win 20.dll (Shop To Win, LLC)
O3 - HKLM\..\Toolbar: (Upromise TurboSaver) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O3 - HKLM\..\Toolbar: (PDF Architect Toolbar) - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files\PDF Architect\PDFIEPlugin.dll (pdfforge GbR)
O3 - HKLM\..\Toolbar: (ShopAtHome.com Toolbar) - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Ebates Cash Back Toolbar) - {FC5405B9-EE85-8754-9D4F-9CC300948A6F} - C:\Program Files\Ebates Cash Back Toolbar\Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Upromise TurboSaver) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (ShopAtHome.com Toolbar) - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Ebates Cash Back Toolbar) - {FC5405B9-EE85-8754-9D4F-9CC300948A6F} - C:\Program Files\Ebates Cash Back Toolbar\Toolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Anti-phishing Domain Advisor] C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor\visicom_antiphishing.exe (Visicom Media Inc. (Powered by Panda Security))
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DNS7reminder] C:\Program Files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\aol\1270162804\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [MSC] "c:\Program Files\Microsoft Security Client\mssecex.exe" -hide -runkey File not found
O4 - HKLM..\Run: [Nuance.ctfmngr] C:\Program Files\Nuance\NaturallySpeaking11\Program\ctfmngr.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe ()
O4 - HKLM..\Run: [ShopAtHomeWatcher] C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe ()
O4 - HKCU..\Run: [AnVir Task Manager] C:\Program Files\AnVir Task Manager\anvir.exe (AnVir Software)
O4 - HKCU..\Run: [AOL Fast Start] C:\Program Files\AOL Desktop 9.7\AOL.EXE (AOL Inc.)
O4 - HKCU..\Run: [ClickfreeMonitor] C:\Documents and Settings\All Users\Application Data\Clickfree\cfagent.exe (Clickfree)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [fsm] File not found
O4 - HKCU..\Run: [Google Update] Reg Error: Value error. File not found
O4 - HKCU..\Run: [ISUSPM] C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKCU..\Run: [PC Speed Maximizer] "C:\Program Files\PC Speed Maximizer\SPMStarter.exe" File not found
O4 - HKCU..\Run: [SacReminderHDDV2N] c:\Documents and Settings\All Users\Application Data\Clickfree\C2NPlus\Reminder\SacReminder.exe (Storage Appliance Corp.)
O4 - HKCU..\Run: [Software Informer] C:\Program Files\Software Informer\softinfo.exe (Informer Technologies, Inc.)
O4 - HKCU..\Run: [SPMTray] "C:\Program Files\PC Speed Maximizer\SPMTray.exe" File not found
O4 - HKCU..\Run: [Upromise Tray] C:\Program Files\Upromise\UpromiseTray.exe (Upromise, Inc.)
O4 - HKCU..\Run: [Upromise Update] C:\Program Files\Upromise\dca-ua.exe (Compete, Inc.)
O4 - HKCU..\Run: [WizMouse] C:\Program Files\WizMouse\WizMouse.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9 - Extra Button: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O9 - Extra 'Tools' menuitem : Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - mswsock.dll File not found
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyfios.verizon.net/sdcCommo…20Installer.cab (Support.com Configuration Class)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {36299202-09EF-4ABF-ADB9-47C599DBE778} https://www.hpwindows7upgrade.arvato.com/no…PProdDetect.cab (HP Product Detection Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.microsoft.com/download/7/E…04/clearadj.cab (CTAdjust Class)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{876863F4-F078-43F9-8055-5AB0D8D5915E}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E4D8A072-3585-4EEB-ACE6-BE1418B200FE}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 17:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/07/06 13:55:49 | 000,000,097 | R— | M] () - E:\Autorun.inf – [ CDFS ]
O32 - AutoRun File - [2012/01/21 13:16:52 | 000,000,044 | —- | M] () - J:\Autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: edlipers - (C:\WINDOWS\system32\MRTsi64.dll) - File not found
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Remoteaccess - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.pspgru - C:\WINDOWS\System32\PSPGRU.acm (Philips Austria GmbH - Speech Processing)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/09/27 15:42:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew Krajeski\Desktop\AOL Saved PFC
[2013/09/27 15:26:15 | 000,000,000 | —D | C] – C:\Program Files\AOL Desktop 9.7
[2013/09/27 15:03:40 | 000,000,000 | —D | C] – C:\43145a898785a1f02137b8f8
[2013/09/27 10:50:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew Krajeski\My Documents\VIRUS FIXES
[2013/09/26 16:33:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew Krajeski\Application Data\Systweak
[2013/09/26 15:27:25 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Apple Computer
[2013/09/19 17:12:38 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2013/09/19 17:12:34 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2013/09/12 20:42:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew Krajeski\My Documents\eagle-logo-header
[2013/09/07 15:21:33 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/09/07 13:20:51 | 000,027,648 | —- | C] (Johnson-Grace Company) – C:\WINDOWS\System32\jgpl400.dll
[2013/09/07 13:20:50 | 000,163,840 | —- | C] (America Online) – C:\WINDOWS\System32\jgdw400.dll
[2013/01/12 15:47:27 | 000,940,544 | —- | C] (Apache Software Foundation) – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\log4cxx.dll

========== Files - Modified Within 30 Days ==========

[2013/09/28 00:05:00 | 000,000,250 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2013/09/27 23:57:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/09/27 23:26:00 | 000,000,900 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/27 20:30:10 | 000,483,994 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/09/27 20:30:10 | 000,080,954 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/09/27 20:26:05 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/09/27 20:25:56 | 000,000,896 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/27 20:25:48 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/09/27 20:25:47 | 3209,871,360 | -HS- | M] () – C:\hiberfil.sys
[2013/09/27 15:42:45 | 000,000,654 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL Desktop 9.7.lnk
[2013/09/27 15:42:45 | 000,000,636 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AOL Desktop 9.7.lnk
[2013/09/27 15:42:35 | 000,000,006 | —- | M] () – C:\WINDOWS\msoffice.ini
[2013/09/27 15:17:57 | 000,001,698 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Desktop\Microsoft Security Essentials.lnk
[2013/09/27 14:56:20 | 000,001,919 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2013/09/27 12:10:07 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/27 11:57:10 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2013/09/19 14:29:04 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2013/09/19 13:57:42 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/09/19 13:57:41 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/09/14 07:25:42 | 000,196,926 | —- | M] () – C:\Documents and Settings\Drew Krajeski\My Documents\Esserman.zip
[2013/09/12 20:42:36 | 000,089,758 | —- | M] () – C:\Documents and Settings\Drew Krajeski\My Documents\eagle-logo-header.zip
[2013/09/12 16:35:01 | 000,171,488 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/09/12 06:44:30 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/09/07 13:40:30 | 000,058,696 | —- | M] (AOL Inc.) – C:\WINDOWS\System32\AOLParconLink.exe
[2013/09/07 13:20:51 | 000,027,648 | —- | M] (Johnson-Grace Company) – C:\WINDOWS\System32\jgpl400.dll
[2013/09/07 13:20:50 | 000,163,840 | —- | M] (America Online) – C:\WINDOWS\System32\jgdw400.dll

========== Files Created - No Company Name ==========

[2013/09/27 15:30:31 | 000,000,654 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL Desktop 9.7.lnk
[2013/09/27 15:30:31 | 000,000,636 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL Desktop 9.7.lnk
[2013/09/27 15:17:57 | 000,001,698 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Desktop\Microsoft Security Essentials.lnk
[2013/09/27 14:58:26 | 3209,871,360 | -HS- | C] () – C:\hiberfil.sys
[2013/09/27 11:26:34 | 000,000,664 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\d3d9caps.dat
[2013/09/19 17:12:55 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2013/09/14 07:25:41 | 000,196,926 | —- | C] () – C:\Documents and Settings\Drew Krajeski\My Documents\Esserman.zip
[2013/09/12 20:42:36 | 000,089,758 | —- | C] () – C:\Documents and Settings\Drew Krajeski\My Documents\eagle-logo-header.zip
[2013/01/12 15:47:27 | 000,094,208 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\common_functions.dll
[2012/09/03 19:44:27 | 000,000,844 | —- | C] () – C:\Documents and Settings\Drew Krajeski\.recently-used.xbel
[2012/07/10 07:13:35 | 000,000,000 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Application Data\SharedSettings.ccs
[2012/07/10 07:12:18 | 000,058,368 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\gdsukavj
[2012/06/07 20:58:12 | 000,302,425 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\funmoods-speeddial.crx
[2012/02/15 08:02:42 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/25 13:10:40 | 000,015,312 | —- | C] () – C:\WINDOWS\System32\RaCoInst.dat
[2011/09/02 07:08:50 | 000,102,400 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\ie_runner_app.exe
[2011/08/25 17:19:48 | 000,001,715 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Application Data\SAS7_000.DAT
[2010/04/28 18:30:41 | 000,001,020 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Application Data\wklnhst.dat
[2009/04/11 16:23:46 | 000,038,912 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2004/08/11 17:21:56 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2009/04/29 00:46:52 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/09/27 20:26:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor
[2013/05/09 17:44:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ask
[2012/06/23 08:44:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\blekko toolbars
[2011/04/07 17:31:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CFTEMP
[2011/03/19 14:05:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Clickfree
[2012/07/10 08:14:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F4D55F1722F092F00009A52DD151FC4E
[2012/07/10 10:46:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HitmanPro
[2013/07/04 15:19:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2011/07/23 08:52:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2011/08/08 11:00:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011/07/24 08:35:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pc health check
[2011/12/31 16:32:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2011/07/24 08:08:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spotmau
[2008/10/10 09:34:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2013/09/23 03:00:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/07/24 08:35:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp360
[2011/08/08 11:00:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UAB
[2008/10/10 09:35:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2009/04/11 16:26:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/02/02 07:44:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\W3i
[2011/12/18 08:09:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2009/04/11 16:28:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\acccore
[2011/12/26 17:31:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\alotappbar
[2013/01/11 15:59:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\APP_NAME_NON_STRING
[2012/02/13 21:12:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\BDlot
[2012/06/22 05:47:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\blekkotb_019
[2011/12/09 19:16:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Catalina Marketing Corp
[2009/10/10 19:10:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/04/25 21:11:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Digiarty
[2012/06/07 20:58:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\FCSB000063941
[2013/07/08 20:45:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\FCTB000100433
[2013/01/11 16:20:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Foxit Software
[2013/07/04 15:19:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Juniper Networks
[2011/07/23 09:06:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Nuance
[2012/02/02 12:44:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Oracle
[2012/06/07 20:53:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\PC Speed Maximizer
[2012/09/20 23:13:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\PCCUStubInstaller
[2013/01/11 16:10:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\PDF Architect
[2013/01/11 15:58:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\pdfforge
[2013/08/12 06:34:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Qwiklinx
[2013/03/29 12:20:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome
[2013/09/27 15:29:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Software Informer
[2011/07/24 08:08:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\spotmau
[2012/01/25 17:11:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\SystemRequirementsLab
[2013/09/26 17:03:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Systweak
[2011/08/04 15:00:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Template
[2011/08/09 07:15:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Tific
[2013/01/12 15:47:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\upromise
[2011/11/21 06:29:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\URSoft
[2009/09/13 06:51:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Viewpoint

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EX_ >
[2004/08/04 05:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\i386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\i386\explorer.exe

< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2013/09/28 00:02:44 | 000,075,336 | —- | M] () MD5=4E43FD1EDEEEF65AD59A416CD63B60EF – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf

< MD5 for: EXPLORER.HTM >
[2004/11/09 17:36:40 | 000,002,225 | —- | M] () MD5=27E8E84DB81847B335D3C78356EAEB78 – C:\Program Files\ZyXEL Communications Corporation\ZyXEL PLA-4xx Series Configuration Utility\Online_Help\wwhelp\wwhimpl\java\html\explorer.htm

< MD5 for: EXPLORER.SC_ >
[2004/08/04 05:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\i386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2004/08/04 05:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/08/04 05:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\i386\iexplore.chm
[2004/08/04 05:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EX_ >
[2004/08/04 05:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\i386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2008/04/13 20:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie8\iexplore.exe
[2008/04/13 20:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\ERDNT\cache\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2012/07/10 09:16:19 | 001,012,656 | —- | M] () MD5=C7D040F4C3C0214B460AABDE52BE9189 – C:\Documents and Settings\Drew Krajeski\My Documents\Downloads\iExplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui

< MD5 for: IEXPLORE.HLP >
[2004/08/04 05:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\i386\iexplore.hlp
[2004/08/04 05:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2004/08/04 05:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\i386\services
[2004/08/04 05:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES.CFG >
[2013/09/03 09:53:56 | 000,558,864 | —- | M] () MD5=4097D9DB7F5DB4533DDA8271136C9B7B – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\ERDNT\cache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/04 05:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\i386\services.exe

< MD5 for: SERVICES.LNK >
[2004/08/11 17:15:06 | 000,001,506 | —- | M] () MD5=C04255E822F6017251E30CE1481EB38E – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2004/08/04 05:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\i386\services.msc
[2004/08/04 05:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: WINLOGON.EXE >
[2004/08/04 05:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\i386\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2004/08/11 17:15:00 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/04/11 06:50:03 | 000,000,211 | —- | M] () – C:\Boot.bak
[2012/01/29 11:43:14 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/04 00:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2012/02/01 16:51:20 | 000,016,085 | —- | M] () – C:\ComboFix.txt
[2004/08/11 17:15:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/10/10 09:07:32 | 000,007,477 | R— | M] () – C:\dell.sdr
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2013/09/27 20:25:47 | 3209,871,360 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2013/09/27 15:30:37 | 000,061,624 | —- | M] () – C:\install.log
[2012/01/29 01:21:04 | 000,000,000 | —- | M] () – C:\install.rdf
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2004/08/11 17:15:00 | 000,000,000 | —- | M] () – C:\IO.SYS
[2012/02/02 12:34:23 | 000,026,311 | —- | M] () – C:\JavaRa.log
[2004/08/11 17:15:00 | 000,000,000 | —- | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/18 06:24:39 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/09/27 20:25:45 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2012/07/10 09:41:50 | 000,000,436 | —- | M] () – C:\rkill.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/11 17:14:22 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is CCE1-E82B
Directory of C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices
08/14/2013 06:02 AM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote
08/14/2013 06:01 AM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices
08/14/2013 06:06 AM v4.0_4.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
3 Dir(s) 428,492,554,240 bytes free

< %systemroot%\System32\config\*.sav >
[2004/08/11 17:06:14 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/11 17:06:14 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/11 17:06:14 | 000,876,544 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Desktop\*.exe >
[2012/03/28 17:46:56 | 000,309,560 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Desktop\EbatesCashBackToolbar.exe
[2011/09/04 09:07:52 | 000,600,648 | —- | M] (Antibody Software ) – C:\Documents and Settings\Drew Krajeski\Desktop\wizmouse_1_6_0_1_setup.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-09-13 11:48:24

========== Base Services ==========
SRV - [2008/04/13 20:12:12 | 000,044,544 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\alg.exe – (ALG)
SRV - [2008/04/13 20:12:11 | 000,006,656 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wuauserv.dll – (wuauserv)
SRV - [2008/04/13 20:12:03 | 000,409,088 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\qmgr.dll – (BITS)
SRV - [2012/07/06 09:58:51 | 000,078,336 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\browser.dll – (Browser)
SRV - [2008/04/13 20:11:51 | 000,062,464 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\cryptsvc.dll – (CryptSvc)
SRV - [2008/04/13 20:11:51 | 000,126,976 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\dhcpcsvc.dll – (Dhcp)
SRV - [2009/04/20 13:17:26 | 000,045,568 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\dnsrslvr.dll – (Dnscache)
SRV - [2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\services.exe – (Eventlog)
SRV - [2008/04/13 20:11:52 | 000,033,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\eapsvc.dll – (EapHost)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\shsvcs.dll – (FastUserSwitchingCompatibility)
SRV - [2008/04/13 20:12:08 | 000,015,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\w3ssl.dll – (HTTPFilter)
SRV - [2008/04/13 20:11:54 | 000,021,504 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\hidserv.dll – (HidServ)
SRV - [2008/04/13 20:12:22 | 000,150,528 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\imapi.exe – (ImapiService)
No service found with a name of PolicyAgent
SRV - [2008/04/13 20:11:52 | 000,023,552 | —- | M] (Microsoft Corp.) [Auto | Running] – C:\WINDOWS\system32\dmserver.dll – (dmserver)
SRV - [2008/04/13 20:12:17 | 000,224,768 | —- | M] (Microsoft Corp., Veritas Software) [On_Demand | Stopped] – C:\WINDOWS\System32\dmadmin.exe – (dmadmin)
SRV - [2008/04/13 20:12:17 | 000,005,120 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\System32\dllhost.exe – (SwPrv)
SRV - [2008/04/13 20:12:24 | 000,013,312 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\lsass.exe – (Netlogon)
SRV - [2008/04/13 20:12:01 | 000,198,144 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\netman.dll – (Netman)
SRV - [2008/06/20 12:02:47 | 000,245,248 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\mswsock.dll – (Nla)
SRV - [2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\services.exe – (PlugPlay)
SRV - [2010/08/17 09:17:06 | 000,058,880 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\spoolsv.exe – (Spooler)
SRV - [2008/04/13 20:12:24 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (ProtectedStorage)
SRV - [2008/04/13 20:12:03 | 000,088,576 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\rasauto.dll – (RasAuto)
SRV - [2008/04/13 20:12:03 | 000,186,368 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\rasmans.dll – (RasMan)
SRV - [2009/02/09 08:10:48 | 000,401,408 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\rpcss.dll – (RpcSs)
SRV - [2008/04/13 20:12:02 | 000,435,200 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\ntmssvc.dll – (NtmsSvc)
SRV - [2008/04/13 20:12:05 | 000,018,944 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\seclogon.dll – (seclogon)
SRV - [2008/04/13 20:12:24 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (SamSs)
SRV - [2008/04/13 20:12:10 | 000,080,896 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wscsvc.dll – (wscsvc)
SRV - [2010/08/27 01:57:43 | 000,099,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\srvsvc.dll – (lanmanserver)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\shsvcs.dll – (ShellHWDetection)
SRV - [2008/04/13 20:12:07 | 000,171,008 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\srsvc.dll – (srservice)
SRV - [2008/04/13 20:12:05 | 000,192,512 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\schedsvc.dll – (Schedule)
SRV - [2008/04/13 20:11:56 | 000,013,824 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lmhsvc.dll – (LmHosts)
SRV - [2008/04/13 20:12:07 | 000,249,856 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\tapisrv.dll – (TapiSrv)
SRV - [2008/04/13 20:12:07 | 000,295,424 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\termsrv.dll – (TermService)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\shsvcs.dll – (Themes)
SRV - [2008/04/13 20:12:38 | 000,289,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\vssvc.exe – (VSS)
SRV - [2008/04/13 20:11:50 | 000,042,496 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\audiosrv.dll – (AudioSrv)
SRV - [2008/04/13 20:11:55 | 000,331,264 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\ipnathlp.dll – (SharedAccess)
SRV - [2008/04/13 20:12:08 | 000,333,824 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wiaservc.dll – (stisvc)
SRV - [2008/04/13 20:12:28 | 000,078,848 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\System32\msiexec.exe – (MSIServer)
SRV - [2008/04/13 20:12:09 | 000,144,896 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wbem\wmisvc.dll – (winmgmt)
SRV - [2009/02/09 08:10:48 | 000,617,472 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\advapi32.dll – (Wmi)
SRV - [2008/04/13 20:11:52 | 000,132,096 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\dot3svc.dll – (Dot3svc)
SRV - [2008/04/13 20:12:11 | 000,483,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wzcsvc.dll – (WZCSVC)
SRV - [2009/06/10 02:14:49 | 000,132,096 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wkssvc.dll – (lanmanworkstation)

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: Hitachi HDP725050GLA360
Partitions: 2
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 - Removable media other than\tfloppy
Interface type: USB
Media Type: Removable media other than\tfloppy
Model: Clikfree Backup Drive USB Device
Partitions: 1
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: TEAC USB HS-CF Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model: TEAC USB HS-xD/SM USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE4 -
Interface type: USB
Media Type:
Model: TEAC USB HS-MS Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE5 -
Interface type: USB
Media Type:
Model: TEAC USB HS-SD Card USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 55.00MB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 466.00GB
Starting Offset: 57576960
Hidden sectors: 0


DeviceID: Disk #1, Partition #0
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 931.00GB
Starting Offset: 32256
Hidden sectors: 0


========== Alternate Data Streams ==========

@Alternate Data Stream - 236 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0FF263E8

< End of report >

The Extras.txt did not appear at the end of this scan but one did earlier when I ran OTL based on the instructions to run three scans posted in the Virus, Spyware & Malware Removal forum. Here is that txt:

OTL Extras logfile created on: 9/27/2013 8:33:27 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Drew Krajeski\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.99 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 75.24% Memory free
4.83 Gb Paging File | 4.12 Gb Available in Paging File | 85.30% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.70 Gb Total Space | 399.26 Gb Free Space | 85.73% Space Free | Partition Type: NTFS
Drive E: | 133.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive J: | 931.30 Gb Total Space | 927.86 Gb Free Space | 99.63% Space Free | Partition Type: NTFS

Computer Name: D3H5MKH1 | User Name: Drew Krajeski | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"53271:UDP" = 53271:UDP:*:Enabled:SacNetAgentCommunicationPort1
"53272:TCP" = 53272:TCP:*:Enabled:SacNetAgentCommunicationPort2

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\aol\acs\AOLDial.exe" = C:\Program Files\Common Files\aol\acs\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialer – (America Online)
"C:\Program Files\Common Files\aol\acs\AOLacsd.exe" = C:\Program Files\Common Files\aol\acs\AOLacsd.exe:*:Enabled:AOL Connectivity Service – (AOL LLC)
"C:\Program Files\Common Files\aol\1270162804\ee\aolsoftware.exe" = C:\Program Files\Common Files\aol\1270162804\ee\aolsoftware.exe:*:Enabled:AOL Shared Components – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.7\waol.exe" = C:\Program Files\AOL Desktop 9.7\waol.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed – (AOL Inc.)
"C:\Program Files\Common Files\aol\Loader\aolload.exe" = C:\Program Files\Common Files\aol\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL Inc.)
"C:\Program Files\Common Files\aol\System Information\sinf.exe" = C:\Program Files\Common Files\aol\System Information\sinf.exe:*:Enabled:AOL System Information – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe" = C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe:*:Enabled:AOL Browser – (AOL Inc.)
"c:\documents and settings\all users\application data\Clickfree\C2NPlus\Reminder\SacNetAgent.exe" = c:\documents and settings\all users\application data\Clickfree\C2NPlus\Reminder\SacNetAgent.exe:*:Enabled:SacNetAgentService – (Storage Appliance Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09531CAE-B186-49A9-B44F-C607CC54FA2A}" = PDF Architect
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{1111706F-666A-4037-7777-202328764D10}" = JavaFX 2.0.2
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{26A24AE4-039D-4CA4-87B4-2F83217002FF}" = Java™ 7 Update 2
"{27F00C63-449B-2FAB-CBE8-24AB80E17449}" = Acrobat.com
"{2E497885-E60B-420A-832D-0148B392E058}_is1" = Qwiklinx
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36D00BF1-C0BE-4237-ADD4-B166CAF3E284}" = ZyXEL PLA-4xx Series Configuration Utility
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DADB23F-94E6-4E4D-AFE8-15DE4395E8F3}" = Microsoft Security Client
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4640FDE1-B83A-4376-84ED-86F86BEE2D41}" = Driver Detective
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A5A427F-BA39-4BF0-9999-9A47FBE60C9F}" = Visual C++ 9.0 Runtime for Dragon NaturallySpeaking
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{634F79E1-2A41-4C40-9E8D-89EC740AC9D6}" = Logitech Harmony Remote Software
"{6438A99C-A37E-4758-A0AE-95F8A63AAFF5}" = Intel® Network Connections [removed]
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}" = InstallIQ Updater
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A2713384-7398-43E9-9D43-565B3A7FEFEE}" = Security Advisor
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.8)
"{AE502938-5BF1-4CEA-961D-0081B992C878}_is1" = Shop To Win
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0DA129B-1E45-494D-A362-5CD0109C306B}" = WOT for Internet Explorer
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E5D4B0C7-985F-4EF0-9932-8F1E4B60B89E}" = Coupons at Checkout
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EFE3D683-903C-4B58-AB8F-C68C69F33758}" = System Requirements Lab for Intel
"{EFFA53BC-8C04-2E21-3D90-A13B1697B0CA}" = Dragon NaturallySpeaking 11
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F169F5B9-776C-401B-AF01-155433C6BE9B}" = Vz In Home Agent
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Anti-phishing Domain Advisor" = Anti-phishing Domain Advisor
"AnVir Task Manager" = AnVir Task Manager
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Ebates Cash Back Toolbar" = Ebates Cash Back Toolbar
"ESET Online Scanner" = ESET Online Scanner v3
"Foxit Reader_is1" = Foxit Reader
"Google Chrome" = Google Chrome
"GoToAssist" = GoToAssist 8.0.0.514
"GRTSoft Data Recovery_is1" = GRTSoft Data Recovery 2.5
"HDMI" = Intel® Graphics Media Accelerator Driver
"HitmanPro36" = HitmanPro 3.6
"ie8" = Windows Internet Explorer 8
"Juniper_Setup_Client Activex Control" = Juniper Networks, Inc. Setup Client Activex Control
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 23.0.1 (x86 en-US)" = Mozilla Firefox 23.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NortonPCCheckup" = Norton PC Checkup
"PC Speed Maximizer_is1" = PC Speed Maximizer v3.0
"Photo Stamp Remover_is1" = Photo Stamp Remover 3.1
"Realtek Drivers Update Utility 3.0_is1" = Realtek Drivers Update Utility 3.0
"Samsung CLP-300 Series" = Samsung CLP-300 Series
"SearchAssist" = SearchAssist
"ShopAtHome.com Helper" = ShopAtHome.com Helper
"ShopAtHome.com Toolbar" = ShopAtHome.com Toolbar
"Software Informer_is1" = Software Informer 1.1
"Spykee" = Spykee
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPcapInst" = WinPcap 4.1.1
"Wise Disk Cleaner_is1" = Wise Disk Cleaner Professional v5.2
"WizMouse_is1" = WizMouse v1.6.0.1
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YU2010_is1" = Your Uninstaller! 7

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Support.com Toolbar Updater
"Juniper_Setup_Client" = Juniper Networks, Inc. Setup Client
"Neoteris_Host_Checker" = Juniper Networks Host Checker
"Upromise TurboSaver" = Upromise TurboSaver (remove only)

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/26/2013 5:54:04 PM | Computer Name = D3H5MKH1 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80070643 Description:. 0x80070643. Fatal error during installation.

Error - 9/27/2013 10:27:22 AM | Computer Name = D3H5MKH1 | Source = MsiInstaller | ID = 10005
Description = Product: Microsoft Security Client – The installer has encountered
an unexpected error installing this package. This may indicate a problem with this
package. The error code is 2324. The arguments are: 1920, c:\Program Files\Microsoft
Security Client\SymSrv.yes,

Error - 9/27/2013 10:27:41 AM | Computer Name = D3H5MKH1 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80070643 Description:. 0x80070643. Fatal error during installation.

Error - 9/27/2013 12:59:21 PM | Computer Name = D3H5MKH1 | Source = MsiInstaller | ID = 10005
Description = Product: Microsoft Security Client – The installer has encountered
an unexpected error installing this package. This may indicate a problem with this
package. The error code is 2324. The arguments are: 1920, c:\Program Files\Microsoft
Security Client\SymSrv.yes,

Error - 9/27/2013 12:59:25 PM | Computer Name = D3H5MKH1 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80070643 Description:. 0x80070643. Fatal error during installation.

Error - 9/27/2013 2:54:31 PM | Computer Name = D3H5MKH1 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x8004FF11 Description:. 0x8004FF11.

Error - 9/27/2013 2:56:20 PM | Computer Name = D3H5MKH1 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x8004FF11 Description:. 0x8004FF11.

Error - 9/27/2013 3:13:13 PM | Computer Name = D3H5MKH1 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070490, P2 remediation, P3 remediationfailuretelemetry,
P4 1.1.9901.0, P5 mpengine, P6 0, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 9/27/2013 3:45:14 PM | Computer Name = D3H5MKH1 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070490, P2 remediation, P3 remediationfailuretelemetry,
P4 1.1.9901.0, P5 mpengine, P6 0, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 9/27/2013 8:25:59 PM | Computer Name = D3H5MKH1 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070490, P2 remediation, P3 remediationfailuretelemetry,
P4 1.1.9901.0, P5 mpengine, P6 0, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

[ System Events ]
Error - 9/27/2013 3:13:00 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2

Error - 9/27/2013 3:45:08 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 9/27/2013 3:45:08 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%20

Error - 9/27/2013 3:45:08 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The Java Quick Starter service failed to start due to the following
error: %%2

Error - 9/27/2013 3:45:08 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2

Error - 9/27/2013 8:26:01 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 9/27/2013 8:26:01 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%20

Error - 9/27/2013 8:26:01 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The Java Quick Starter service failed to start due to the following
error: %%2

Error - 9/27/2013 8:26:01 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2

Error - 9/27/2013 8:26:03 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
iaStor


< End of report >
Thank you!!

Attachments:

Hi cranmergirl,

[external image: Posted Image] Uninstall via Add/Remove Programs
  • Please go to Start > Control Panel > Add Remove Programs.
    Locate the following programs: (if present)
    • Ask
    • Ask Toolbar
    • Ebates Cash Back Toolbar
    • SearchAssist
    • ShopAtHome.com Helper
    • ShopAtHome.com Toolbar
  • Click Remove and allow Windows to completely remove each one in turn.
  • Then reboot your computer to complete this part of the process.
=========================

[external image: Posted Image] Run OTL.exe

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
    PRC - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe ()
    PRC - C:\Program Files\Upromise\UpromiseTray.exe (Upromise, Inc.)
    PRC - C:\Program Files\Upromise\dca-ua.exe (Compete, Inc.)
    MOD - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe ()
    MOD - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelperPS.dll ()
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=fmtob…p;cr=1837363338
    IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {443789B7-F39C-4b5c-9287-DA72D38F4FE6}
    IE - HKLM\..\SearchScopes,DefaultScope = {443789B7-F39C-4b5c-9287-DA72D38F4FE6}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
    IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1837363338
    IE - HKLM\..\SearchScopes\{79809194-BE76-9834-A9A7-3EAFA9125A67}: "URL" = http://slirsredirect.search.aol.com/redire…mrud=17-07-2011
    IE - HKCU\..\URLSearchHook: - No CLSID value found
    IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    IE - HKCU\..\URLSearchHook: {2d914c15-11e5-93b4-ad21-35ba2aec33c8} - C:\Program Files\Ebates Cash Back Toolbar\Helper.dll ()
    IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
    IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
    IE - HKCU\..\SearchScopes,DefaultScope = {DD234610-0BA5-43EE-B017-E6C01556EB35}
    IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…56-EBC4D0131CA7
    IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1837363338
    IE - HKCU\..\SearchScopes\{79809194-BE76-9834-A9A7-3EAFA9125A67}: "URL" = http://blekkosearch.mystart.com/blekkotb_s…q={searchTerms}
    IE - HKCU\..\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}: "URL" = http://search.alot.com/web?q={searchTerms}
    IE - HKCU\..\SearchScopes\{D5F539B8-1FC6-48C7-85E9-4D74D6906162}: "URL" = http://slirsredirect.search.aol.com/redire…mrud=17-07-2011
    IE - HKCU\..\SearchScopes\{DD234610-0BA5-43EE-B017-E6C01556EB35}: "URL" = http://srp.freecause.com/?ourmark=4&si…q={searchTerms}
    FF - prefs.js..browser.search.defaultengine: "Ask.com"
    FF - prefs.js..browser.search.defaultenginename: "Ask.com"
    FF - prefs.js..browser.search.order.1: "Ask.com"
    FF - prefs.js..browser.search.selectedEngine: "Search the Web"
    [2013/05/09 17:45:09 | 000,000,000 | —D | M] (Support.com Toolbar) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\extensions\[removed]
    [2013/01/12 15:56:20 | 000,455,818 | —- | M] () (No name found) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\extensions\[removed]
    [2013/05/09 17:45:09 | 000,002,336 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\searchplugins\askcom.xml
    CHR - default_search_provider: Web Search (Enabled)
    CHR - default_search_provider: search_url = http://start.funmoods.com/results.php?f=4&…p;cr=1837363338
    CHR - homepage: http://start.funmoods.com/?f=1&a=fmtob…p;cr=1837363338
    CHR - Extension: SaveByclick = C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bgfaeeogolelccmmfcfoikennpedhhno\1_0\
    CHR - Extension: FunDial = C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\1.0.1_0\
    CHR - Extension: Make this page red = C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dnfaglepmjgohnkcoieaijlheabmcdeo\1.2_0\
    CHR - Extension: Funmoods = C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\1.5.1_0\
    O2 - BHO: (Qwiklinx) - {3E7C8B5A-96AB-438F-BF9B-782400655440} - C:\Documents and Settings\Drew Krajeski\Application Data\Qwiklinx\Qwiklinx.dll (Qwiklinx, Inc.)
    O2 - BHO: (ShopAtHome.com Cash Back Helper) - {66516A07-F617-488A-90CF-4E690CFB3C5F} - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
    O2 - BHO: (Ebates Cash Back Toolbar BHO) - {796E3F7C-B3A1-6094-41A6-21866FF2BAD6} - C:\Program Files\Ebates Cash Back Toolbar\Toolbar.dll ()
    O2 - BHO: (DCA BHO) - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files\Upromise\dca-bho.dll (Compete, Inc.)
    O2 - BHO: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    O2 - BHO: (Upromise TurboSaver) - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
    O2 - BHO: (Shop to Win) - {F9E44926-2497-46F3-8A25-928136AC079E} - C:\Program Files\Shop to Win 20\Shop to Win 20.dll (Shop To Win, LLC)
    O3 - HKLM\..\Toolbar: (Upromise TurboSaver) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
    O3 - HKLM\..\Toolbar: (ShopAtHome.com Toolbar) - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
    O3 - HKLM\..\Toolbar: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    O3 - HKLM\..\Toolbar: (Ebates Cash Back Toolbar) - {FC5405B9-EE85-8754-9D4F-9CC300948A6F} - C:\Program Files\Ebates Cash Back Toolbar\Toolbar.dll ()
    O3 - HKCU\..\Toolbar\WebBrowser: (Upromise TurboSaver) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (ShopAtHome.com Toolbar) - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
    O3 - HKCU\..\Toolbar\WebBrowser: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    O3 - HKCU\..\Toolbar\WebBrowser: (Ebates Cash Back Toolbar) - {FC5405B9-EE85-8754-9D4F-9CC300948A6F} - C:\Program Files\Ebates Cash Back Toolbar\Toolbar.dll ()
    O3 - HKCU\..\Toolbar\WebBrowser: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    O3 - HKCU\..\Toolbar\WebBrowser: (Ebates Cash Back Toolbar) - {FC5405B9-EE85-8754-9D4F-9CC300948A6F} - C:\Program Files\Ebates Cash Back Toolbar\Toolbar.dll ()
    O4 - HKLM..\Run: [ShopAtHomeWatcher] C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe ()
    O4 - HKCU..\Run: [ClickfreeMonitor] C:\Documents and Settings\All Users\Application Data\Clickfree\cfagent.exe (Clickfree)
    O4 - HKCU..\Run: [Upromise Tray] C:\Program Files\Upromise\UpromiseTray.exe (Upromise, Inc.)
    O4 - HKCU..\Run: [Upromise Update] C:\Program Files\Upromise\dca-ua.exe (Compete, Inc.)
    O9 - Extra Button: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
    O9 - Extra 'Tools' menuitem : Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
    [2012/07/10 07:12:18 | 000,058,368 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\gdsukavj
    [2012/06/07 20:58:12 | 000,302,425 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\funmoods-speeddial.crx
    [2013/05/09 17:44:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ask
    [2012/06/23 08:44:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\blekko toolbars
    [2011/03/19 14:05:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Clickfree
    [2013/08/12 06:34:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Qwiklinx
    [2013/03/29 12:20:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome
    [2013/01/12 15:47:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\upromise
    [2012/03/28 17:46:56 | 000,309,560 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Desktop\EbatesCashBackToolbar.exe
    
    :Commands
    [purity]
    [createrestorepoint]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

[external image: Posted Image] AdwCleaner

Download AdwCleaner to your desktop.

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
=========================

[external image: Posted Image] Junkware Removal Tool

Download Junkware Removal Tool to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Shut down your protection software now to avoid potential conflicts.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
=========================

[external image: Posted Image] Reboot

=========================

[external image: Posted Image] Re-run OTL (it should be located on your desktop).
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt. (No Extras.txt will be produced)
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
=========================

In your next post please provide the following:
  • AdwCleaner[S0].txt
  • JRT.txt
  • Fresh OTL.txt
  • How is the computer running, what issues/symptoms are you experiencing?
Hi OCD, Sorry about the delay in replying to your quick response! Busy weekend…. Here are the logs you requested, starting with the AdwCleaner log: # AdwCleaner v3.005 - Report created 28/09/2013 at 23:46:17 # Updated 22/09/2013 by Xplode # Operating System : Microsoft Windows XP Service Pack 3 (32 bits) # Username : Drew Krajeski - D3H5MKH1 # Running from : C:\Documents and Settings\Drew Krajeski\My Documents\Downloads\AdwCleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor Folder Deleted : C:\Documents and Settings\All Users\Application Data\Viewpoint Folder Deleted : C:\Documents and Settings\All Users\Start Menu\Programs\SaveByClick Folder Deleted : C:\Program Files\alotappbar Folder Deleted : C:\Program Files\OApps Folder Deleted : C:\Program Files\PC Speed Maximizer Folder Deleted : C:\Program Files\Qwiklinx Folder Deleted : C:\Program Files\Shop to Win 20 Folder Deleted : C:\Program Files\Shop To Win Folder Deleted : C:\Program Files\Upromise Folder Deleted : C:\Program Files\Viewpoint Folder Deleted : C:\DOCUME~1\DREWKR~1\LOCALS~1\Temp\AirInstaller Folder Deleted : C:\DOCUME~1\DREWKR~1\LOCALS~1\Temp\Upromise Folder Deleted : C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\apn Folder Deleted : C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\PackageAware Folder Deleted : C:\Documents and Settings\Drew Krajeski\Application Data\alotappbar Folder Deleted : C:\Documents and Settings\Drew Krajeski\Application Data\FCSB000063941 Folder Deleted : C:\Documents and Settings\Drew Krajeski\Application Data\pdfforge Folder Deleted : C:\Documents and Settings\Drew Krajeski\Application Data\Systweak Folder Deleted : C:\Documents and Settings\Drew Krajeski\Application Data\Viewpoint Folder Deleted : C:\Documents and Settings\Drew Krajeski\Start Menu\Programs\Shop to Win 20 Folder Deleted : C:\Documents and Settings\Drew Krajeski\My Documents\ShopToWin Folder Deleted : C:\Documents and Settings\Kelly Krajeski\Local Settings\Application Data\AskToolbar Folder Deleted : C:\Documents and Settings\Kelly Krajeski\Application Data\Viewpoint Folder Deleted : C:\Documents and Settings\Robin Krajeski\Local Settings\Application Data\AskToolbar Folder Deleted : C:\Documents and Settings\Robin Krajeski\Application Data\Viewpoint Folder Deleted : C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\FCTB Folder Deleted : C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj Folder Deleted : C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dnfaglepmjgohnkcoieaijlheabmcdeo Folder Deleted : C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrch.xml File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\search.xml ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dnfaglepmjgohnkcoieaijlheabmcdeo Key Deleted : HKCU\Software\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [Backup.old.Start Page] Key Deleted : HKLM\SOFTWARE\Classes\AppID\CptUrlPassthru.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\dca-api.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\dca-bho.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\ShoppingBHO.DLL Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1 Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1 Key Deleted : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor Key Deleted : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor.1 Key Deleted : HKLM\SOFTWARE\Classes\dcabho.Dca Key Deleted : HKLM\SOFTWARE\Classes\dcabho.Dca.1 Key Deleted : HKLM\SOFTWARE\Classes\QwiklinxBHO Key Deleted : HKLM\SOFTWARE\Classes\QwiklinxBHO.1 Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E} Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD} Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Anti-phishing Domain Advisor] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP Key Deleted : HKLM\SOFTWARE\Classes\FCSB000063941.JSOptionsImpl Key Deleted : HKLM\SOFTWARE\Classes\FCSB000063941.JSOptionsImpl.1 Key Deleted : HKLM\SOFTWARE\Classes\FCSB000063941.Shopping Key Deleted : HKLM\SOFTWARE\Classes\FCSB000063941.Shopping.1 Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A57F7191-1E7F-4852-BAAF-F80A43E2687A} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{DBBBC528-9C8C-4051-9187-ED6F01A457C9} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EB583FE1-9458-4EDA-AC68-24D24F17C70F} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B1BCB34F-5DC6-43B4-94B5-DFF4F02E2AF7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{41D42E90-86D2-4521-9847-625D114F7D30} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{622382CB-942C-4580-A2B3-7B06A58D8538} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E2C1A522-B8E1-45D1-B316-F5625004A28C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{204C0025-C26A-43E2-853C-D8A8EB1BCE51} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C4E09482-2C6A-44B2-8D40-ABC01B36BB9D} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C8758BC4-4581-48C7-BA38-C1A650477AE9} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{06E58E5E-F8CB-4049-991E-A41C03BD419E} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E44926-2497-46F3-8A25-928136AC079E} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{06E58E5E-F8CB-4049-991E-A41C03BD419E} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E44926-2497-46F3-8A25-928136AC079E} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F9E44926-2497-46F3-8A25-928136AC079E} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}] Key Deleted : HKCU\Software\alotAppbar Key Deleted : HKCU\Software\APN PIP Key Deleted : HKCU\Software\Compete Key Deleted : HKCU\Software\CompeteInc Key Deleted : HKCU\Software\distromatic Key Deleted : HKCU\Software\Qwiklinx Key Deleted : HKCU\Software\ShopToWin Key Deleted : HKCU\Software\YahooPartnerToolbar Key Deleted : HKCU\Software\AppDataLow\Software\Freecause Key Deleted : HKLM\Software\CompeteInc Key Deleted : HKLM\Software\Freeze.com Key Deleted : HKLM\Software\MetaStream Key Deleted : HKLM\Software\PIP Key Deleted : HKLM\Software\systweak Key Deleted : HKLM\Software\Viewpoint Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2E497885-E60B-420A-832D-0148B392E058}_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AE502938-5BF1-4CEA-961D-0081B992C878}_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-phishing Domain Advisor Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{26B5A6D1-1F75-3B59-5825-E4D4CAE3445D} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{2E497885-E60B-420A-832D-0148B392E058}_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AE502938-5BF1-4CEA-961D-0081B992C878}_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Anti-phishing Domain Advisor Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer ***** [ Browsers ] ***** -\\ Internet Explorer v8.0.6001.18702 -\\ Mozilla Firefox v23.0.1 (en-US) [ File : C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\prefs.js ] Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.AutoSearchEventData", "auto%20search"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.ClearCacheDate", 28); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.DNSCatch", true); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.DisplayEULA", true); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.DnsCatchEventData", "dns%20catch"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.EBOMode", false); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.EnableDCAData_xx", true); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.EnableDCA_xx", false); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.FirstLaunchShown", true); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.InstallDomain", "upromise.com"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.InstallType", "one_click"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.NewTabSearchEventData", "tab%20search"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.ShowRecommendedOptions", true); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.StateReportDate", "1380425764039"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.TopRightSearchEventData", "top%20right%20search"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.beforeInstallSaved", true); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.beforeinstall.homepage", "hxxp%3A//www.foxnews.com%7Cwww.google.com"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.beforeinstall.search", "Ask.com"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.comp.affiliate.116.disabled", false); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.comp.search.58.engine_img", "aHR0cHM6Ly9zdGF0aWMucmV3YXJ6LmNvbS9jbGllbnRzL1Vwcm9taXNlL3Rvb2xiYXJzL3Byb2R 1Y3Rpb24vMTAwOTg3L2ltYWdlcy95YWhvb19mYXZpY2[…] Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.comp.search.58.engine_url", "aHR0cDovL29sbWNkbi51cHJvbWlzZS5jb20vc2VhcmNoLmh0bWw/cXM9"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.comp.search.58.text", "Search%20the%20Web"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.customNewTab", true); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.dcaDefaultMode", false); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.dcaShowInstallerPage", false); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.dcaShowSurvey", true); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.helpUsImprove", true); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.hideOthers", true); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.partnerauth", false); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.processAddrBar", false); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.remove_homepage", true); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.remove_search", true); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.restoreSearch", false); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.searchHistory", false); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.session", "F5207E3FB9013E5D5AA0748B883D2AB2E5A93466EF6575CDA17E7BC052500944C0AB765B509 9A993ACE3482064D0E14BF215564D7310CB129588652FD5A89EC9BF51BB29[…] Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.showFirstLaunchOptions", false); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.tb_lang", "en"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.tool_id", "100987"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.user_id", "104109"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.user_key", "70566637d4f5bdcb949a95987232ecff842f9965"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.user_layouts", "100987"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.xml_service_url", "cf2788bd15fe5bcbc566786e33a951d1"); Line Deleted : user_pref("freecauseb987141395b701c469cf961a01420158.yahooSearch", false); [ File : C:\Documents and Settings\Kelly Krajeski\Application Data\Mozilla\Firefox\Profiles\vy29kcyb.default\prefs.js ] Line Deleted : user_pref("browser.search.defaultengine", "Ask.com"); Line Deleted : user_pref("browser.search.defaultenginename", "Ask.com"); Line Deleted : user_pref("browser.search.order.1", "Ask.com"); Line Deleted : user_pref("browser.search.selectedEngine", "Ask.com"); Line Deleted : user_pref("extensions.asktb.ff-original-keyword-url", ""); -\\ Google Chrome v29.0.1547.76 [ File : C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ] Deleted : urls_to_restore_on_startup Deleted : homepage Deleted : icon_url Deleted : search_url Deleted : keyword ************************* AdwCleaner[R0].txt - [18007 octets] - [28/09/2013 23:44:35] AdwCleaner[S0].txt - [17651 octets] - [28/09/2013 23:46:17] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [17712 octets] ########## More to follow…..
Next log (JRT.txt)… ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.3 (09.27.2013:1) OS: Microsoft Windows XP x86 Ran by [removed] on Sun 09/29/2013 at 0:02:49.14 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\software informer ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1663C10B-0D55-438D-8496-19A3DBAEC0E4} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2018eb71-06b5-4438-abf4-e40df31e0be5} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{2018eb71-06b5-4438-abf4-e40df31e0be5} ~~~ Files Successfully deleted: [File] "C:\Program Files\mozilla firefox\plugins\npcouponprinter.dll" Successfully deleted: [File] "C:\Program Files\mozilla firefox\plugins\npmozcouponprinter.dll" ~~~ Folders Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\w3i" Successfully deleted: [Folder] "C:\Documents and Settings\Drew Krajeski\Application Data\pccustubinstaller" Successfully deleted: [Folder] "C:\Documents and Settings\Drew Krajeski\Application Data\software informer" Successfully deleted: [Folder] "C:\Program Files\coupons" Successfully deleted: [Folder] "C:\Program Files\software informer" Successfully deleted: [Folder] "C:\Program Files\w3i" Successfully deleted: [Folder] "C:\WINDOWS\system32\ai_recyclebin" ~~~ FireFox Successfully deleted: [Folder] C:\Documents and Settings\Drew Krajeski\Application Data\mozilla\firefox\profiles\detycbl9.default-1358020424890\fctb Successfully deleted the following from C:\Documents and Settings\Drew Krajeski\Application Data\mozilla\firefox\profiles\detycbl9.default-1358020424890\prefs.js user_pref("freecauseb987141395b701c469cf961a01420158.AutoSearchEventData", "auto%20search"); user_pref("freecauseb987141395b701c469cf961a01420158.ClearCacheDate", 29); user_pref("freecauseb987141395b701c469cf961a01420158.DNSCatch", true); user_pref("freecauseb987141395b701c469cf961a01420158.DisplayEULA", true); user_pref("freecauseb987141395b701c469cf961a01420158.DnsCatchEventData", "dns%20catch"); user_pref("freecauseb987141395b701c469cf961a01420158.EBOMode", false); user_pref("freecauseb987141395b701c469cf961a01420158.EnableDCAData_xx", true); user_pref("freecauseb987141395b701c469cf961a01420158.EnableDCA_xx", false); user_pref("freecauseb987141395b701c469cf961a01420158.FirstLaunchShown", true); user_pref("freecauseb987141395b701c469cf961a01420158.InstallDomain", "upromise.com"); user_pref("freecauseb987141395b701c469cf961a01420158.InstallType", "one_click"); user_pref("freecauseb987141395b701c469cf961a01420158.NewTabSearchEventData", "tab%20search"); user_pref("freecauseb987141395b701c469cf961a01420158.ShowRecommendedOptions", true); user_pref("freecauseb987141395b701c469cf961a01420158.StateReportDate", "1380427247058"); user_pref("freecauseb987141395b701c469cf961a01420158.TopRightSearchEventData", "top%20right%20search"); user_pref("freecauseb987141395b701c469cf961a01420158.beforeInstallSaved", true); user_pref("freecauseb987141395b701c469cf961a01420158.beforeinstall.homepage", "hxxp%3A//www.foxnews.com%7Cwww.google.com"); user_pref("freecauseb987141395b701c469cf961a01420158.beforeinstall.search", "Google"); user_pref("freecauseb987141395b701c469cf961a01420158.comp.affiliate.116.disabled", false); user_pref("freecauseb987141395b701c469cf961a01420158.comp.search.58.engine_img", "aHR0cHM6Ly9zdGF0aWMucmV3YXJ6LmNvbS9jbGllbnRzL1Vwcm9taXNlL3Rvb2xiYXJzL3Byb2R 1Y3Rpb24vMTAwOTg3L user_pref("freecauseb987141395b701c469cf961a01420158.comp.search.58.engine_url", "aHR0cDovL29sbWNkbi51cHJvbWlzZS5jb20vc2VhcmNoLmh0bWw/cXM9"); user_pref("freecauseb987141395b701c469cf961a01420158.comp.search.58.text", "Search%20the%20Web"); user_pref("freecauseb987141395b701c469cf961a01420158.customNewTab", true); user_pref("freecauseb987141395b701c469cf961a01420158.dcaDefaultMode", false); user_pref("freecauseb987141395b701c469cf961a01420158.dcaShowInstallerPage", false); user_pref("freecauseb987141395b701c469cf961a01420158.dcaShowSurvey", true); user_pref("freecauseb987141395b701c469cf961a01420158.helpUsImprove", true); user_pref("freecauseb987141395b701c469cf961a01420158.hideOthers", true); user_pref("freecauseb987141395b701c469cf961a01420158.partnerauth", false); user_pref("freecauseb987141395b701c469cf961a01420158.processAddrBar", false); user_pref("freecauseb987141395b701c469cf961a01420158.remove_homepage", true); user_pref("freecauseb987141395b701c469cf961a01420158.remove_search", true); user_pref("freecauseb987141395b701c469cf961a01420158.restoreSearch", false); user_pref("freecauseb987141395b701c469cf961a01420158.searchHistory", false); user_pref("freecauseb987141395b701c469cf961a01420158.showFirstLaunchOptions", false); user_pref("freecauseb987141395b701c469cf961a01420158.tb_lang", "en"); user_pref("freecauseb987141395b701c469cf961a01420158.tool_id", "100987"); user_pref("freecauseb987141395b701c469cf961a01420158.user_id", "104109"); user_pref("freecauseb987141395b701c469cf961a01420158.user_key", "3ca5ae45c3920768df0f047bd480e6f909e7da02"); user_pref("freecauseb987141395b701c469cf961a01420158.user_layouts", "100987"); user_pref("freecauseb987141395b701c469cf961a01420158.vars.display_state", "show"); user_pref("freecauseb987141395b701c469cf961a01420158.xml_service_url", "cf2788bd15fe5bcbc566786e33a951d1"); user_pref("freecauseb987141395b701c469cf961a01420158.yahooSearch", false); ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Sun 09/29/2013 at 0:05:54.56 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Here is the OTL log:

OTL logfile created on: 9/29/2013 12:13:52 AM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Drew Krajeski\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.99 Gb Total Physical Memory | 2.29 Gb Available Physical Memory | 76.70% Memory free
4.83 Gb Paging File | 4.22 Gb Available in Paging File | 87.35% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.70 Gb Total Space | 399.02 Gb Free Space | 85.68% Space Free | Partition Type: NTFS
Drive E: | 133.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive J: | 931.30 Gb Total Space | 927.86 Gb Free Space | 99.63% Space Free | Partition Type: NTFS

Computer Name: D3H5MKH1 | User Name: Drew Krajeski | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Drew Krajeski\My Documents\Downloads\OTL(3).exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AOL Desktop 9.7\waol.exe (AOL Inc.)
PRC - C:\Program Files\AOL Desktop 9.7\shellmon.exe (AOL Inc.)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\PDF Architect\HelperService.exe (pdfforge GbR)
PRC - C:\Program Files\PDF Architect\ConversionService.exe (pdfforge GbR)
PRC - C:\WINDOWS\system32\IPROSetMonitor.exe (Intel Corporation)
PRC - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\WizMouse\WizMouse.exe ()
PRC - C:\Program Files\Common Files\Nuance\dgnsvc.exe (Nuance Communications, Inc.)
PRC - C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
PRC - C:\Program Files\Common Files\aol\1270162804\ee\aolsoftware.exe (AOL Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
PRC - C:\Program Files\Common Files\aol\acs\AOLacsd.exe (AOL LLC)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\AOL Desktop 9.7\zlib.dll ()
MOD - C:\Program Files\AOL Desktop 9.7\libcef.dll ()
MOD - C:\Program Files\AOL Desktop 9.7\libGLESv2.dll ()
MOD - C:\Program Files\AOL Desktop 9.7\libEGL.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\f93600ac836b9140e1df13bb0f6bfccf\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\10df39542df7d48462451fc39bce8418\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\b14359470744c840c59fbe4e58034fd6\mscorlib.ni.dll ()
MOD - C:\Program Files\WizMouse\WizMouse.exe ()
MOD - C:\WINDOWS\system32\IS_ContextMenu.dll ()
MOD - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()


========== Services (SafeList) ==========

SRV - (SacNetAgentService_C57C4F854F53) – c:\documents and settings\all users\application data\Clickfree\C2NPlus\Reminder\SacNetAgent.exe File not found
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe File not found
SRV - (etadpug) – C:\Program Files\Google\Desktop\Install\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\ \ \ﯹ๛\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\GoogleUpdate.exe < [WARNING: C:\Program Files\Google\Desktop\Install\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\ \ \???\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\GoogleUpdate.exe <] File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (PDF Architect Helper Service) – C:\Program Files\PDF Architect\HelperService.exe (pdfforge GbR)
SRV - (PDF Architect Service) – C:\Program Files\PDF Architect\ConversionService.exe (pdfforge GbR)
SRV - (Intel® – C:\WINDOWS\system32\IPROSetMonitor.exe (Intel Corporation)
SRV - (PCCUJobMgr) – C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
SRV - (DragonSvc) – C:\Program Files\Common Files\Nuance\dgnsvc.exe (Nuance Communications, Inc.)
SRV - (rpcapd) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (sprtsvc_dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\aol\acs\AOLacsd.exe (AOL LLC)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (SSPORT) – C:\WINDOWS\system32\Drivers\SSPORT.sys File not found
DRV - (rt2870) – system32\DRIVERS\rt2870.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (PCASp50) – System32\Drivers\PCASp50.sys File not found
DRV - (MRESP50a64) – C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS File not found
DRV - (MRESP50) – C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (MREMP50a64) – C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS File not found
DRV - (MREMP50) – C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (chakfphd) – C:\WINDOWS\system32\drivers\chakfphd.sys File not found
DRV - (catchme) – C:\DOCUME~1\DREWKR~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (DigiartyVirtualCDBus) – C:\WINDOWS\system32\drivers\DigiartyVirtualCDBus.sys (LotSoft, Inc.)
DRV - (SWDUMon) – C:\WINDOWS\system32\drivers\SWDUMon.sys ()
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (Linksys_adapter_H) – C:\WINDOWS\system32\drivers\AE1200xp.sys (Broadcom Corporation)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (DgiVecp) – C:\WINDOWS\system32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)
DRV - (wanatw) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6081010
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6081010
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {443789B7-F39C-4b5c-9287-DA72D38F4FE6}
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the Web"
FF - prefs.js..browser.search.selectedEngine: "Search the Web"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.foxnews.com|www.google.com"
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.2.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.2.1: C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@logitech.com/HarmonyRemote,version=1.0.0: C:\Program Files\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files\Verizon\VSP\nprpspa.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\PDF Architect\FFPDFArchitectExt [2013/01/11 15:58:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/09/07 15:21:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/09/29 00:03:11 | 000,000,000 | —D | M]

[2009/08/09 15:05:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Extensions
[2013/09/28 23:38:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\extensions
[2013/09/07 14:33:29 | 000,431,310 | —- | M] () (No name found) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\extensions\{b9871413-95b7-01c4-69cf-961a01420158}.xpi
[2013/09/07 15:21:34 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/09/07 15:22:05 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/12/09 19:16:12 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2008/06/03 01:35:57 | 000,002,275 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\aolsearch.xml

========== Chrome ==========

CHR - default_search_provider: Web Search (Enabled)
CHR - default_search_provider: search_url = http://www.google.com
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: First user (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Error reading preferences file

O1 HOSTS File: ([2013/09/28 23:54:57 | 000,036,300 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 08sr.combineads.info # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 08srvr.combineads.info # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 12srvr.combineads.info # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 2010-fr.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 2012-new.biz # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 2319825.ourtoolbar.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 24h00business.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 a.daasafterdusk.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 ad.adn360.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 adeartss.eu # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 adesoeasy.eu # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 adf.girldatesforfree.net # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 adm.soft365.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 adomicileavail.googlepages.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 ads7.complexadveising.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 ads.aff.co # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 ads.alpha00001.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 ads.cloud4ads.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 ads.eorezo.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 ads.hooqy.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 ads.icksor.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 ads.regiedepub.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 ads.sucomspot.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 ads.tersecta.com # hosts anti-adware / pups
O1 - Hosts: 127.0.0.1 a.dungtank.com # hosts anti-adware / pups
O1 - Hosts: 595 more lines…
O2 - BHO: (PDF Architect Helper) - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll File not found
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DNS7reminder] C:\Program Files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\aol\1270162804\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [MSC] "c:\Program Files\Microsoft Security Client\mssecex.exe" -hide -runkey File not found
O4 - HKLM..\Run: [Nuance.ctfmngr] C:\Program Files\Nuance\NaturallySpeaking11\Program\ctfmngr.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe ()
O4 - HKCU..\Run: [AOL Fast Start] C:\Program Files\AOL Desktop 9.7\AOL.EXE (AOL Inc.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [fsm] File not found
O4 - HKCU..\Run: [Google Update] Reg Error: Value error. File not found
O4 - HKCU..\Run: [ISUSPM] C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKCU..\Run: [SacReminderHDDV2N] c:\documents and settings\all users\application data\Clickfree\C2NPlus\reminder\SacReminder.exe File not found
O4 - HKCU..\Run: [SPMTray] "C:\Program Files\PC Speed Maximizer\SPMTray.exe" File not found
O4 - HKCU..\Run: [WizMouse] C:\Program Files\WizMouse\WizMouse.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9 - Extra Button: Coupons at Checkout Settings - {2018eb71-06b5-4438-abf4-e40df31e0be5} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Coupons at Checkout Settings - {2018eb71-06b5-4438-abf4-e40df31e0be5} - Reg Error: Key error. File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - mswsock.dll File not found
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyfios.verizon.net/sdcCommo…20Installer.cab (Support.com Configuration Class)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {36299202-09EF-4ABF-ADB9-47C599DBE778} https://www.hpwindows7upgrade.arvato.com/no…PProdDetect.cab (HP Product Detection Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.microsoft.com/download/7/E…04/clearadj.cab (CTAdjust Class)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{876863F4-F078-43F9-8055-5AB0D8D5915E}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E4D8A072-3585-4EEB-ACE6-BE1418B200FE}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 17:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/07/06 13:55:49 | 000,000,097 | R— | M] () - E:\Autorun.inf – [ CDFS ]
O32 - AutoRun File - [2012/01/21 13:16:52 | 000,000,044 | —- | M] () - J:\Autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: edlipers - (C:\WINDOWS\system32\MRTsi64.dll) - File not found
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/09/29 00:02:47 | 000,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2013/09/28 23:54:09 | 000,000,000 | —D | C] – C:\Program Files\Hosts_Anti_Adwares_PUPs
[2013/09/28 23:44:19 | 000,000,000 | —D | C] – C:\AdwCleaner
[2013/09/28 23:38:10 | 000,000,000 | —D | C] – C:\_OTL
[2013/09/27 15:42:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew Krajeski\My Documents\AOL Saved PFC
[2013/09/27 15:26:15 | 000,000,000 | —D | C] – C:\Program Files\AOL Desktop 9.7
[2013/09/27 15:03:40 | 000,000,000 | —D | C] – C:\43145a898785a1f02137b8f8
[2013/09/27 10:50:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew Krajeski\My Documents\VIRUS FIXES
[2013/09/26 15:27:25 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Apple Computer
[2013/09/19 17:12:38 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2013/09/19 17:12:34 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2013/09/12 20:42:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew Krajeski\My Documents\eagle-logo-header
[2013/09/07 15:21:33 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/09/07 13:20:51 | 000,027,648 | —- | C] (Johnson-Grace Company) – C:\WINDOWS\System32\jgpl400.dll
[2013/09/07 13:20:50 | 000,163,840 | —- | C] (America Online) – C:\WINDOWS\System32\jgdw400.dll
[2013/01/12 15:47:27 | 000,940,544 | —- | C] (Apache Software Foundation) – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\log4cxx.dll

========== Files - Modified Within 30 Days ==========

[2013/09/29 00:14:20 | 000,483,994 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/09/29 00:14:20 | 000,080,954 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/09/29 00:10:12 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/09/29 00:10:12 | 000,000,896 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/29 00:10:04 | 3209,871,360 | -HS- | M] () – C:\hiberfil.sys
[2013/09/29 00:10:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/09/28 23:54:57 | 000,036,300 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2013/09/28 23:26:00 | 000,000,900 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/28 22:57:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/09/28 10:10:09 | 000,000,604 | —- | M] () – C:\Documents and Settings\Drew Krajeski\My Documents\play_icon.bmp
[2013/09/28 03:34:05 | 000,001,610 | —- | M] () – C:\Documents and Settings\All Users\Desktop\HitmanPro.lnk
[2013/09/28 03:29:11 | 000,000,938 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Desktop\Shortcut to JRT.lnk
[2013/09/28 03:28:02 | 000,000,979 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Desktop\Shortcut to AdwCleaner.lnk
[2013/09/28 03:23:13 | 000,000,957 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Desktop\Shortcut to OTL(3).lnk
[2013/09/27 15:42:45 | 000,000,654 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL Desktop 9.7.lnk
[2013/09/27 15:42:45 | 000,000,636 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AOL Desktop 9.7.lnk
[2013/09/27 15:42:35 | 000,000,006 | —- | M] () – C:\WINDOWS\msoffice.ini
[2013/09/27 15:17:57 | 000,001,698 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Desktop\Microsoft Security Essentials.lnk
[2013/09/27 14:56:20 | 000,001,919 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2013/09/27 12:10:07 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/27 11:57:10 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2013/09/19 14:29:04 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2013/09/19 13:57:42 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/09/19 13:57:41 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/09/14 07:25:42 | 000,196,926 | —- | M] () – C:\Documents and Settings\Drew Krajeski\My Documents\Esserman.zip
[2013/09/12 20:42:36 | 000,089,758 | —- | M] () – C:\Documents and Settings\Drew Krajeski\My Documents\eagle-logo-header.zip
[2013/09/12 16:35:01 | 000,171,488 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/09/12 06:44:30 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/09/07 13:40:30 | 000,058,696 | —- | M] (AOL Inc.) – C:\WINDOWS\System32\AOLParconLink.exe
[2013/09/07 13:20:51 | 000,027,648 | —- | M] (Johnson-Grace Company) – C:\WINDOWS\System32\jgpl400.dll
[2013/09/07 13:20:50 | 000,163,840 | —- | M] (America Online) – C:\WINDOWS\System32\jgdw400.dll

========== Files Created - No Company Name ==========

[2013/09/28 10:10:09 | 000,000,604 | —- | C] () – C:\Documents and Settings\Drew Krajeski\My Documents\play_icon.bmp
[2013/09/28 03:29:11 | 000,000,938 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Desktop\Shortcut to JRT.lnk
[2013/09/28 03:28:02 | 000,000,979 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Desktop\Shortcut to AdwCleaner.lnk
[2013/09/28 03:23:13 | 000,000,957 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Desktop\Shortcut to OTL(3).lnk
[2013/09/27 15:30:31 | 000,000,654 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL Desktop 9.7.lnk
[2013/09/27 15:30:31 | 000,000,636 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL Desktop 9.7.lnk
[2013/09/27 15:17:57 | 000,001,698 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Desktop\Microsoft Security Essentials.lnk
[2013/09/27 14:58:26 | 3209,871,360 | -HS- | C] () – C:\hiberfil.sys
[2013/09/27 11:26:34 | 000,000,664 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\d3d9caps.dat
[2013/09/19 17:12:55 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2013/09/14 07:25:41 | 000,196,926 | —- | C] () – C:\Documents and Settings\Drew Krajeski\My Documents\Esserman.zip
[2013/09/12 20:42:36 | 000,089,758 | —- | C] () – C:\Documents and Settings\Drew Krajeski\My Documents\eagle-logo-header.zip
[2013/01/12 15:47:27 | 000,094,208 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\common_functions.dll
[2012/09/03 19:44:27 | 000,000,844 | —- | C] () – C:\Documents and Settings\Drew Krajeski\.recently-used.xbel
[2012/07/10 07:13:35 | 000,000,000 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Application Data\SharedSettings.ccs
[2012/02/15 08:02:42 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/25 13:10:40 | 000,015,312 | —- | C] () – C:\WINDOWS\System32\RaCoInst.dat
[2011/09/02 07:08:50 | 000,102,400 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\ie_runner_app.exe
[2011/08/25 17:19:48 | 000,001,715 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Application Data\SAS7_000.DAT
[2010/04/28 18:30:41 | 000,001,020 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Application Data\wklnhst.dat
[2009/04/11 16:23:46 | 000,038,912 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2004/08/11 17:21:56 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2009/04/29 00:46:52 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Alternate Data Streams ==========

@Alternate Data Stream - 236 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0FF263E8

< End of report >


Computer seems to be running well….no complaints from my husband! Thanks so much!!
Hi cranmergirl,

It's important that you follow through with the remainder of the steps I will outline. Absence of symptoms doesn't necessarily translate into malware free. We are making progress so please stay with me until I give you the "all clean" sign. :thumbup:

[external image: Posted Image] Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware to your desktop.

Right click mbam-setup.exe and select "Run as Administrator" and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
=========================

[external image: Posted Image] ESET Online Scanner

*Note:
  • It is recommended to disable on-board antivirus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
  • Please don't go surfing while your resident protection is disabled!
  • Once the scan is finished remember to re-enable your antivirus along with your anti-spyware programs.
** You need to run your browser with Administrator Rights, to do so right click your browsers short cut and select "Run as Administrator".

= = = = = = = = = = = = = = = = = = = =

Go here to run ESET Online Scanner

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notification Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.
=========================

In your next post please provide the following:

  • MBAM log
  • ESET's log.txt
  • How's the computer running, any symptoms?
Hi OCD, Okay, I'm with you till you give me the All Clear! Here is the first log you requested (mbam): Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.09.29.01 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Drew Krajeski :: D3H5MKH1 [administrator] 9/29/2013 12:58:36 AM mbam-log-2013-09-29 (00-58-36).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 267812 Time elapsed: 13 minute(s), 35 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_*202EETADPUG (Rootkit.0Access) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) More to follow…… :wavey:
ESET scan running….taking a very long time…after 50 minutes, it is only 36% of the way completed (it has found 2 threats so far)….I will let it run all night and post the ESET log in the morning….thanks again for all your help in cleaning up my husband's computer! :adios:
Surprise! It suddenly sped up and completed faster than expected. Here are the results: C:\Documents and Settings\Drew Krajeski\My Documents\Downloads\realtek-drivers-update-utility.exe Win32/DriverBoss.B application C:\Documents and Settings\Drew Krajeski\My Documents\Old Firefox Data\extensions\[removed]\content\bg.js Win32/Adware.MultiPlug.H application C:\Program Files\Realtek Drivers Update Utility 3.0\driverlib.dll Win32/DriverBoss.B application C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP133\A0021465.exe a variant of Win32/Adware.SpeedingUpMyPC.C application C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP133\A0021470.exe a variant of Win32/SpeedingUpMyPC application C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP49\A0006191.dll Win32/Toolbar.BHO.B application C:\WINDOWS\system32\TuneUp360.ocx Win32/TuneUp360 application C:\_OTL\MovedFiles\09282013_233810\C_Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bgfaeeogolelccmmfcfoikennpedhhno\1_0\50f073e865eec9.77656265.js Win32/Adware.MultiPlug.H application Computer seems to be running pretty well….Will check back with you tomorrow! I need some sleep….. :wacko: Thanks again!
Hi cranmergirl,

[external image: Posted Image] ComboFix

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.
    ———————————————————————————————
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

=========================

In your next post please provide the following:
  • Combofix.txt
Hi OCD,
Here is the ComboFix log:

ComboFix 13-09-28.02 - Drew Krajeski 09/29/2013 21:59:17.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3061.2100 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\DREWKR~1\LOCALS~1\APPLIC~1\Google\Desktop\Install
c:\docume~1\DREWKR~1\LOCALS~1\APPLIC~1\Google\Desktop\Install\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\C3C1~1\01C8~1\CFFE~1\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\L\00000004.@
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Drew Krajeski\Local Settings\Application Data\.#
c:\documents and settings\Drew Krajeski\Local Settings\Application Data\.#\MBX@D2C@393470.###
c:\documents and settings\Drew Krajeski\Local Settings\Application Data\.#\MBX@D2C@393480.###
c:\documents and settings\Drew Krajeski\Local Settings\Application Data\.#\MBX@D2C@393490.###
c:\documents and settings\Drew Krajeski\Local Settings\Application Data\.#\MBX@D2C@3934A0.###
c:\documents and settings\Drew Krajeski\Local Settings\Application Data\.#\MBX@E94@393470.###
c:\documents and settings\Drew Krajeski\Local Settings\Application Data\.#\MBX@E94@393480.###
c:\documents and settings\Drew Krajeski\Local Settings\Application Data\.#\MBX@E94@393490.###
c:\documents and settings\Drew Krajeski\Local Settings\Application Data\.#\MBX@E94@3934A0.###
c:\documents and settings\Drew Krajeski\Local Settings\Application Data\common_functions.dll
c:\documents and settings\Drew Krajeski\Local Settings\Application Data\ie_runner_app.exe
c:\program files\Google\Desktop\Install
c:\program files\Google\Desktop\Install\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\0103~1\0103~1\CFFE~1\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\L\00000004.@
c:\program files\Google\Desktop\Install\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\0103~1\0103~1\CFFE~1\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\L\201d3dde
c:\program files\Google\Desktop\Install\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\0103~1\0103~1\CFFE~1\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\L\76603ac3
.
.
((((((((((((((((((((((((( Files Created from 2013-08-28 to 2013-09-30 )))))))))))))))))))))))))))))))
.
.
2013-09-29 22:34 . 2013-09-05 05:02 7328304 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{11F23652-23E7-4F67-B994-4CBC419272A3}\mpengine.dll
2013-09-29 07:28 . 2013-09-05 05:02 7328304 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-09-29 04:02 . 2013-09-29 04:02 ——– d—–w- c:\windows\ERUNT
2013-09-29 03:54 . 2013-09-29 03:54 ——– d—–w- c:\program files\Hosts_Anti_Adwares_PUPs
2013-09-29 03:44 . 2013-09-29 03:55 ——– d—–w- C:\AdwCleaner
2013-09-29 03:38 . 2013-09-29 03:38 ——– d—–w- C:\_OTL
2013-09-27 19:26 . 2013-09-27 19:55 ——– d—–w- c:\program files\AOL Desktop 9.7
2013-09-27 19:03 . 2013-09-27 19:11 ——– d—–w- C:\43145a898785a1f02137b8f8
2013-09-26 19:27 . 2013-09-26 19:27 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2013-09-07 17:20 . 2013-09-07 17:20 348160 —-a-w- c:\windows\system32\msvcr71.dll
2013-09-07 17:20 . 2013-09-07 17:20 499712 —-a-w- c:\windows\system32\msvcp71.dll
2013-09-03 13:53 . 2013-09-03 13:53 187248 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-19 17:57 . 2012-04-04 10:03 692616 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-19 17:57 . 2011-11-24 12:10 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-07 17:40 . 2011-04-08 11:21 58696 —-a-w- c:\windows\system32\AOLParconLink.exe
2013-08-09 01:56 . 2004-08-11 21:00 386560 —-a-w- c:\windows\system32\themeui.dll
2013-08-08 06:05 . 2004-08-11 21:00 920064 —-a-w- c:\windows\system32\wininet.dll
2013-08-08 06:05 . 2004-08-11 21:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-08-08 06:05 . 2004-08-11 21:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2013-08-08 06:05 . 2004-08-11 21:00 18944 —-a-w- c:\windows\system32\corpol.dll
2013-08-08 01:27 . 2004-08-11 21:00 1877760 —-a-w- c:\windows\system32\win32k.sys
2013-08-08 00:02 . 2004-08-11 21:00 385024 —-a-w- c:\windows\system32\html.iec
2013-08-05 13:30 . 2004-08-11 21:00 1289728 —-a-w- c:\windows\system32\ole32.dll
2013-08-03 18:18 . 2006-10-19 01:47 1543680 —-a-w- c:\windows\system32\wmvdecod.dll
2013-07-10 10:37 . 2004-08-11 21:00 406016 —-a-w- c:\windows\system32\usp10.dll
2013-07-04 03:03 . 2004-08-11 21:00 2149888 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-07-04 02:08 . 2004-08-04 02:59 2028544 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-16 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-16 138008]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-16 16132608]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\ssmmgr.exe" [2007-05-29 520192]
"HostManager"="c:\program files\Common Files\AOL\1270162804\ee\AOLSoftware.exe" [2010-03-08 41800]
"DNS7reminder"="c:\program files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" [2007-04-16 259624]
"Nuance.ctfmngr"="c:\program files\Nuance\NaturallySpeaking11\Program\ctfmngr.exe" [2011-07-22 39856]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-10-10 13:35 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\aol\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\aol\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\aol\\1270162804\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL Desktop 9.7\\waol.exe"=
"c:\\Program Files\\Common Files\\aol\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\aol\\System Information\\sinf.exe"=
"c:\\Program Files\\AOL Desktop 9.7\\AOLBrowser\\aolbrowser.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:@xpsp2res.dll,-22004
"445:TCP"= 445:TCP:@xpsp2res.dll,-22005
"137:UDP"= 137:UDP:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:@xpsp2res.dll,-22002
"53271:UDP"= 53271:UDP:SacNetAgentCommunicationPort1
"53272:TCP"= 53272:TCP:SacNetAgentCommunicationPort2
.
R1 MpKsle233b596;MpKsle233b596;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C863EA7F-8BA9-45A2-AB9D-7D627B8A164A}\MpKsle233b596.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C863EA7F-8BA9-45A2-AB9D-7D627B8A164A}\MpKsle233b596.sys [?]
R2 DragonSvc;Dragon Service;c:\program files\Common Files\Nuance\dgnsvc.exe [7/23/2010 1:19 PM 296808]
R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IPROSetMonitor.exe [1/25/2012 5:16 PM 132768]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [10/20/2009 2:19 PM 50704]
R2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe [8/9/2011 7:15 AM 126392]
R2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files\PDF Architect\HelperService.exe [12/14/2012 5:29 PM 1522912]
R2 PDF Architect Service;PDF Architect Service;c:\program files\PDF Architect\ConversionService.exe [12/14/2012 5:28 PM 906464]
R3 Linksys_adapter_H;Linksys Adapter Network Driver;c:\windows\system32\drivers\AE1200xp.sys [1/28/2012 12:03 PM 1034240]
S1 chakfphd;chakfphd;\??\c:\windows\system32\drivers\chakfphd.sys –> c:\windows\system32\drivers\chakfphd.sys [?]
S2 SacNetAgentService_C57C4F854F53;SacNetAgentService_C57C4F854F53;c:\documents and settings\all users\application data\Clickfree\C2NPlus\Reminder\SacNetAgent.exe –> c:\documents and settings\all users\application data\Clickfree\C2NPlus\Reminder\SacNetAgent.exe [?]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys –> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [6/2/2011 11:08 AM 11336]
S3 DigiartyVirtualCDBus;Digiarty Virtual Driver;c:\windows\system32\drivers\DigiartyVirtualCDBus.sys [2/13/2012 9:12 PM 163008]
S3 SWDUMon;SWDUMon;c:\windows\system32\drivers\SWDUMon.sys [7/24/2011 4:14 PM 12984]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-19 18:26 1177552 —-a-w- c:\program files\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 17:57]
.
2013-09-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-03-13 20:41]
.
2013-09-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-03-13 20:41]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.foxnews.com/
mStart Page =
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {{2018eb71-06b5-4438-abf4-e40df31e0be5} - {2018eb71-06b5-4438-abf4-e40df31e0be5} -
TCP: DhcpNameServer = 192.168.1.1
DPF: {36299202-09EF-4ABF-ADB9-47C599DBE778} - hxxps://www.hpwindows7upgrade.arvato.com/north_america/EndCustomer/HPProdDetect.cab
FF - ProfilePath - c:\documents and settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\
FF - prefs.js: browser.search.selectedEngine - Search the Web
FF - prefs.js: browser.startup.homepage - hxxp://www.foxnews.com|www.google.com
FF - ExtSQL: 2013-09-07 14:33; {b9871413-95b7-01c4-69cf-961a01420158}; c:\documents and settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\extensions\{b9871413-95b7-01c4-69cf-961a01420158}.xpi
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-MSC - c:\program files\Microsoft Security Client\mssecex.exe
AddRemove-Coupon Printer for Windows5.0.0.0 - c:\program files\Coupons\uninstall.exe
AddRemove-ShopAtHome.com Helper - c:\documents and settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeToolbar\..\ShopAtHomeHelper\uninst.exe
AddRemove-Software Informer_is1 - c:\program files\Software Informer\unins000.exe
AddRemove-Upromise TurboSaver - c:\program files\Upromise\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-09-29 22:03
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCCUJobMgr]
"ImagePath"="\"c:\program files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files\Norton PC Checkup\Engine\2.0.12.27\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(884)
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
c:\windows\system32\igfxdev.dll
.
Completion time: 2013-09-29 22:04:38
ComboFix-quarantined-files.txt 2013-09-30 02:04
ComboFix2.txt 2012-02-01 20:51
.
Pre-Run: 428,212,400,128 bytes free
Post-Run: 428,390,768,640 bytes free
.
- - End Of File - - 9E53C34D723138ED0D419A93C09A0856
8F558EB6672622401DA993E1E865C861

Awaiting your instructions….. :notworthy:
Hi cranmergirl,

[external image: Posted Image] Enable Hidden Files & Folders :

To enable the viewing of hidden and protected system files in Windows please follow these steps:
  • Close all programs so that you are at your desktop.
  • Click on the Start button. (This is the small round button with the Windows flag in the lower left corner.)
  • Click on the Control Panel menu option.
  • When the control panel opens you can either be in Classic View or Control Panel Home view:

    If you are in the Classic View do the following:
    • Double-click on the Folder Options icon.
    • Click on the View tab.
    • Go to step 5
    If you are in the Control Panel Home view do the following:
    • Click on the Appearance and Personalization link.
    • Click on Show Hidden Files or Folders.
    • Go to step 5.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the check mark from the check box labeled Hide extensions for known file types.
  • Remove the check mark from the check box labeled Hide protected operating system files.
  • Press the Apply button and then the OK button.
=========================

[external image: Posted Image] VirusTotal

Please go to: VirusTotal

[external image: Posted Image]

  • Click the Browse button and search for the following file: c:\windows\system32\drivers\chakfphd.sys
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

=========================

In your next post please provide the following:
  • VirusTotal results
  • Any remaining symptoms?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI