PDA

View Full Version : Malware Infection



DaReelDeel
2010-07-12, 20:04
My Spybot S&D is showing that I have been infected with Win32.agent.ieu

Here is the DDS log.


DDS (Ver_10-03-17.01) - NTFSx86
Run by Darlin at 13:40:46.40 on 12/07/2010
Internet Explorer: 7.0.6002.18005
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2814.1478 [GMT -4:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Eropea.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conime.exe
C:\Windows\Explorer.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Darlin\Downloads\dds.scr
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.ca/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
uSearch Page =
uSearch Bar =
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
uInternet Settings,ProxyOverride = <local>;*.local
uInternet Settings,ProxyServer = http=127.0.0.1:5555
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Google Update] "c:\users\darlin\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [pacqwen] rundll32 "c:\users\darlin\appdata\roaming\nb-NOM.dll",UDPNTWWWQJ
uRun: [JDK5SWFMZY] c:\users\darlin\appdata\local\temp\Ez1.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [PopRock] c:\users\darlin\appdata\local\temp\a.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\2.0"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [FBSSA] c:\program files\sgpsa\ie3sh.exe
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [SweetIM] c:\program files\sweetim\messenger\SweetIM.exe
mRun: [RogersServicepointAgent.exe] "c:\program files\rogers online protection\rogers servicepoint agent\RogersServicepointAgent.exe" /AUTORUN
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
StartupFolder: c:\users\darlin\appdata\roaming\micros~1\windows\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe
StartupFolder: c:\users\darlin\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\users\darlin\appdata\roaming\microsoft\windows\start menu\programs\startup\wwwxbv32.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {612F6E5C-B314-4bab-93D1-D266AAFBE700} - c:\program files\xmlbar\youku downloader\YoukuDownloader(xmlbar).exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: intu-qt2009 - {03947252-2355-4e9b-B446-8CCC75C43370} - c:\program files\quicktax 2009\ic2009pp.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
IFEO: image file execution options - svchost.exe
IFEO: a.exe - svchost.exe
IFEO: aAvgApi.exe - svchost.exe
IFEO: AAWTray.exe - svchost.exe
IFEO: About.exe - svchost.exe

Note: multiple IFEO entries found. Please refer to Attach.txt

================= FIREFOX ===================

FF - ProfilePath - c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{6ac85730-7d0f-4de0-b3fa-21142dd85326}\platform\winnt\components\ColorZilla.dll
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\rogers online protection\rogers servicepoint agent\nprpspa.dll
FF - plugin: c:\users\darlin\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 151216]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\sminst\BLService.exe [2008-8-11 361808]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2008-8-11 193840]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-3-25 42368]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-5-9 43040]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate1ca2cdcaf95cfe9;Google Update Service (gupdate1ca2cdcaf95cfe9);c:\program files\google\update\GoogleUpdate.exe [2009-9-3 133104]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

=============== Created Last 30 ================

2010-07-12 16:25:33 0 d-----w- c:\program files\Safer Networking
2010-07-12 13:25:28 8 ----a-w- c:\users\darlin\appdata\roaming\vdnxlf.dat
2010-07-12 13:25:24 4 ----a-w- c:\users\darlin\appdata\roaming\avdrn.dat
2010-07-12 03:08:05 255227926 ----a-w- c:\windows\MEMORY.DMP
2010-07-12 01:05:43 0 d-----w- c:\program files\CCleaner
2010-07-11 23:58:21 0 d-----w- c:\program files\Microsoft Security Essentials
2010-07-11 23:54:59 0 d-----w- c:\program files\TweetDeck
2010-07-11 21:46:31 88 ----a-w- c:\windows\wininit.ini
2010-07-11 21:16:36 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-07-11 21:16:36 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-07-11 20:03:40 206336 ----a-w- c:\windows\Eropea.exe
2010-07-11 18:14:26 0 d-sh--w- c:\programdata\SMACCEEAV
2010-07-10 03:20:48 88576 --sha-r- c:\users\darlin\appdata\roaming\nb-NOM.dll
2010-07-01 03:07:30 0 d-----w- c:\users\darlin\dwhelper
2010-06-23 16:25:13 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 16:25:13 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 16:25:13 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 16:25:13 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 16:25:13 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-22 23:32:16 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-22 23:32:16 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-20 19:29:53 0 d-----w- c:\program files\iPod
2010-06-20 19:29:48 0 d-----w- c:\program files\iTunes
2010-06-20 19:24:01 0 d-----w- c:\program files\Bonjour
2010-06-14 17:32:43 0 d-----w- c:\programdata\LightScribe

==================== Find3M ====================

2010-07-12 17:29:44 31966 ----a-w- c:\programdata\nvModes.dat
2010-06-25 15:20:20 62236 ----a-w- c:\windows\system32\perfh00C.dat
2010-06-25 15:20:20 19286 ----a-w- c:\windows\system32\perfc00C.dat
2010-06-20 19:25:57 86016 ----a-w- c:\windows\inf\infstor.dat
2010-06-20 19:25:57 51200 ----a-w- c:\windows\inf\infpub.dat
2010-06-20 19:25:56 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-06-01 17:37:48 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-26 17:06:41 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47:41 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-18 20:35:16 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-04 19:15:20 834048 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 18:37:45 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-01 14:13:48 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-04-30 02:15:22 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-04-28 14:25:59 97420 ----a-w- c:\windows\fonts\leelawdb.ttf
2010-04-27 21:28:06 37665 ----a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont
2010-04-23 14:13:55 2048 ----a-w- c:\windows\system32\tzres.dll
2008-08-11 10:55:35 37390 ----a-w- c:\windows\inf\perflib\040c\perfd.dat
2008-08-11 10:55:35 37390 ----a-w- c:\windows\inf\perflib\040c\perfc.dat
2008-08-11 10:55:35 340236 ----a-w- c:\windows\inf\perflib\040c\perfi.dat
2008-08-11 10:55:35 340236 ----a-w- c:\windows\inf\perflib\040c\perfh.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2010-03-10 23:05:08 59232800 --sha-w- c:\windows\system32\drivers\fidbox.dat
2008-08-11 10:58:25 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 13:42:56.27 ===============

ken545
2010-07-17, 22:05
:snwelcome:


Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.

You do have some issue going on , the infections you picked up are most likely from using programs like Limewire Read this please
http://forums.spybot.info/showthread.php?t=282

Its advisable to remove Limewire via Programs and Features in the Control Panel.





Download ComboFix from one of these locations:

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)


* IMPORTANT !!! Save ComboFix.exe to your Desktop


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See this Link (http://www.bleepingcomputer.com/forums/topic114351.html) for programs that need to be disabled and instruction on how to disable them.
Remember to re-enable them when we're done.


Double click on ComboFix.exe & follow the prompts.


As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.


Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



http://img.photobucket.com/albums/v706/ried7/RC1.png


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://img.photobucket.com/albums/v706/ried7/RC2-1.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

DaReelDeel
2010-07-18, 03:19
Thank you for helping me. I uninstalled Limewire. I ran combofix. I have attached the requested ComboFix.txt file. Hope to hear from you soon.

ComboFix 10-07-16.01 - Darlin 17/07/2010 20:53:51.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2814.1866 [GMT -4:00]
Running from: c:\users\Darlin\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Bhing or J.A\.COMMgr
c:\users\Darlin\AppData\Local\{108057BE-9388-4000-ABFC-367BF24447FD}
c:\users\Darlin\AppData\Local\{108057BE-9388-4000-ABFC-367BF24447FD}\chrome.manifest
c:\users\Darlin\AppData\Local\{108057BE-9388-4000-ABFC-367BF24447FD}\chrome\content\_cfg.js
c:\users\Darlin\AppData\Local\{108057BE-9388-4000-ABFC-367BF24447FD}\chrome\content\overlay.xul
c:\users\Darlin\AppData\Local\{108057BE-9388-4000-ABFC-367BF24447FD}\install.rdf
c:\users\Darlin\AppData\Roaming\avdrn.dat
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\CLSV.exe
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\CLSV.sys
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\dudl.drv
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\energy.drv
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\FS.dll
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\FS.drv
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\FW.exe
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\gid.drv
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\hymt.sys
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\kernel32.sys
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\kernel32.tmp
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\pal.tmp
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\PE.sys
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\PE.tmp
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\SM.tmp
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\snl2w.exe
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv
c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wwwxbv32.exe
c:\windows\system32\system

.
((((((((((((((((((((((((( Files Created from 2010-06-18 to 2010-07-18 )))))))))))))))))))))))))))))))
.

2010-07-18 01:04 . 2010-07-18 01:04 -------- d-----w- c:\users\TEMP\AppData\Local\temp
2010-07-18 01:04 . 2010-07-18 01:04 -------- d-----w- c:\users\TEMP.Darlin-PC\AppData\Local\temp
2010-07-18 01:04 . 2010-07-18 01:04 -------- d-----w- c:\users\TEMP.Darlin-PC.000\AppData\Local\temp
2010-07-18 01:04 . 2010-07-18 01:04 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-07-18 01:04 . 2010-07-18 01:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-18 01:04 . 2010-07-18 01:04 -------- d-----w- c:\users\Bhing or J.A\AppData\Local\temp
2010-07-12 16:25 . 2010-07-12 16:25 -------- d-----w- c:\program files\Safer Networking
2010-07-12 13:25 . 2010-07-12 13:25 -------- d-----w- c:\windows\Sun
2010-07-12 01:05 . 2010-07-12 01:05 -------- d-----w- c:\program files\CCleaner
2010-07-11 23:54 . 2010-07-11 23:54 -------- d-----w- c:\program files\TweetDeck
2010-07-11 21:16 . 2010-07-12 01:18 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-07-11 21:16 . 2010-07-11 21:16 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-07-11 18:14 . 2010-07-11 18:14 -------- d-sh--w- c:\programdata\SMACCEEAV
2010-07-10 03:20 . 2010-07-10 03:20 88576 --sha-r- c:\users\Darlin\AppData\Roaming\nb-NOM.dll
2010-07-01 03:07 . 2010-07-01 03:07 -------- d-----w- c:\users\Darlin\dwhelper
2010-06-29 20:36 . 2010-06-14 16:08 103424 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2010-06-29 20:36 . 2010-06-14 16:08 4687872 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
2010-06-29 20:36 . 2010-06-14 16:08 545280 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2010-06-29 20:36 . 2010-06-14 16:08 4687360 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
2010-06-29 20:36 . 2010-06-14 16:08 425984 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2010-06-29 20:36 . 2010-06-14 16:08 152064 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2010-06-29 20:36 . 2010-06-14 16:08 57856 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2010-06-23 16:25 . 2009-11-08 14:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 16:25 . 2009-11-08 14:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 16:25 . 2009-11-08 14:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 16:25 . 2009-11-08 14:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 16:25 . 2009-11-08 14:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-22 23:32 . 2010-04-16 16:43 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-22 23:32 . 2010-04-16 14:39 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-20 19:29 . 2010-06-20 19:29 -------- d-----w- c:\program files\iPod
2010-06-20 19:29 . 2010-06-20 19:31 -------- d-----w- c:\program files\iTunes
2010-06-20 19:24 . 2010-06-20 19:24 -------- d-----w- c:\program files\Bonjour
2010-06-20 19:20 . 2010-06-20 19:20 72504 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-18 00:48 . 2009-08-21 23:44 -------- d-----w- c:\users\Darlin\AppData\Roaming\LimeWire
2010-07-18 00:44 . 2009-08-21 23:40 -------- d-----w- c:\program files\LimeWire
2010-07-18 00:38 . 2009-09-05 23:39 48670 ----a-w- c:\programdata\nvModes.dat
2010-07-18 00:36 . 2008-08-11 12:18 12 ----a-w- c:\windows\bthservsdp.dat
2010-07-15 14:19 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-07-14 02:07 . 2009-08-14 18:56 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-12 13:25 . 2010-07-12 13:25 8 ----a-w- c:\users\Darlin\AppData\Roaming\vdnxlf.dat
2010-07-12 02:07 . 2009-08-24 20:51 1356 ----a-w- c:\users\Darlin\AppData\Local\d3d9caps.dat
2010-07-11 17:54 . 2009-12-30 23:37 -------- d-----w- c:\users\Darlin\AppData\Roaming\vlc
2010-06-25 15:20 . 2008-08-11 10:56 62236 ----a-w- c:\windows\system32\perfh00C.dat
2010-06-25 15:20 . 2008-08-11 10:56 19286 ----a-w- c:\windows\system32\perfc00C.dat
2010-06-25 15:15 . 2009-08-24 21:08 -------- d-----w- c:\program files\Microsoft.NET
2010-06-23 17:56 . 2009-08-22 01:22 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-20 19:29 . 2009-08-21 23:38 -------- d-----w- c:\program files\Common Files\Apple
2010-06-14 17:32 . 2010-06-14 17:32 -------- d-----w- c:\programdata\LightScribe
2010-06-11 17:22 . 2009-08-14 18:59 -------- d-----w- c:\programdata\Microsoft Help
2010-06-08 21:01 . 2009-08-21 22:23 77944 ----a-w- c:\users\Darlin\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-08 17:24 . 2009-08-21 23:45 -------- d-----w- c:\users\Darlin\AppData\Roaming\Apple Computer
2010-06-08 17:24 . 2009-08-21 23:38 -------- d-----w- c:\programdata\Apple
2010-06-08 15:10 . 2009-12-02 20:45 -------- d-----w- c:\programdata\Norton
2010-06-05 17:27 . 2010-02-15 18:56 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-02 22:46 . 2010-06-02 22:28 -------- d-----w- c:\users\Darlin\AppData\Roaming\BitComet
2010-06-01 17:37 . 2009-10-03 03:00 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-26 17:06 . 2010-06-10 18:58 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-10 18:58 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-16 01:16 . 2010-05-16 01:16 101376 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
2010-05-16 01:16 . 2010-05-16 01:16 52224 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
2010-05-04 19:15 . 2010-06-10 18:58 834048 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 18:37 . 2010-06-10 18:58 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-01 14:13 . 2010-06-10 18:57 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-04-30 02:15 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-04-23 14:13 . 2010-05-25 23:39 2048 ----a-w- c:\windows\system32\tzres.dll
2010-03-10 23:05 . 2009-10-03 04:02 59232800 --sha-w- c:\windows\System32\drivers\fidbox.dat
2008-08-11 10:58 . 2008-08-11 10:58 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-02-26 2289664]
"Google Update"="c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-08-21 133104]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"pacqwen"="c:\users\Darlin\AppData\Roaming\nb-NOM.dll" [2010-07-10 88576]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-26 49152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-05 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"RogersServicepointAgent.exe"="c:\program files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" [2009-02-27 3228912]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-06-12 468264]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]

c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-7-31 139776]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):2f,48,75,21,55,e6,ca,01

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1ca2cdcaf95cfe9;Google Update Service (gupdate1ca2cdcaf95cfe9);c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 133104]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-04-26 361808]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-05-09 43040]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-02-26 21:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-07-18 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-09-03 21:21]

2010-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 21:22]

2010-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 21:22]

2010-07-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job
- c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-21 23:27]

2010-07-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job
- c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-21 23:27]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
uInternet Settings,ProxyOverride = <local>;*.local
uInternet Settings,ProxyServer = http=127.0.0.1:5555
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{612F6E5C-B314-4bab-93D1-D266AAFBE700} - c:\program files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe
FF - ProfilePath - c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll
FF - plugin: c:\users\Darlin\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-FBSSA - c:\program files\SGPSA\ie3sh.exe
HKLM-Run-SweetIM - c:\program files\SweetIM\Messenger\SweetIM.exe
AddRemove-NSS - c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.3.34\InstStub.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-17 21:05
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
FBSSA = c:\program files\SGPSA\ie3sh.exe??es ???????owser Search\uninstalSGPU.exe??r????????m??_????????6??

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-07-17 21:09:19
ComboFix-quarantined-files.txt 2010-07-18 01:09

Pre-Run: 140,048,392,192 bytes free
Post-Run: 139,231,453,184 bytes free

- - End Of File - - C82E3F144D9A2D17DDCE6BB5455E7A83

ken545
2010-07-18, 03:53
Hi,

Please just copy and paste the reports into this thread , its easier for me to see and analyze.

CF logs are quite intense, just looking it over quickly it looks fairly good, what I would like you to do is to run both these programs and post the log for Malwarebytes, then reboot and run DDS and post a new DDS log please

Remember with Vista you may have to right click the program and select RUN AS ADMINISTRATOR


Please download ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1) by Atribune to your desktop.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.




Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)


Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
http://i24.photobucket.com/albums/c30/ken545/MBAMCapture.jpg
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please

DaReelDeel
2010-07-18, 19:16
I ran ATF Cleaner and the Malwarebytes' scan. Here is the log.


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

18/07/2010 12:56:17 PM
mbam-log-2010-07-18 (12-56-17).txt

Scan type: Quick scan
Objects scanned: 161010
Time elapsed: 6 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\poprock (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\ProgramData\00412209 (Rogue.Multiple) -> Quarantined and deleted successfully.

Files Infected:
(No malicious items detected)

_________________________________________________________________

Here is the new DDS log.


DDS (Ver_10-03-17.01) - NTFSx86
Run by Darlin at 13:10:18.48 on 18/07/2010
Internet Explorer: 7.0.6002.18005
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2814.1579 [GMT -4:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Darlin\Desktop\dds.scr
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
uInternet Settings,ProxyOverride = <local>;*.local
uInternet Settings,ProxyServer = http=127.0.0.1:5555
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Google Update] "c:\users\darlin\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [pacqwen] rundll32 "c:\users\darlin\appdata\roaming\nb-NOM.dll",UDPNTWWWQJ
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [JDK5SWFMZY] c:\users\darlin\appdata\local\temp\Ez1.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\2.0"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [RogersServicepointAgent.exe] "c:\program files\rogers online protection\rogers servicepoint agent\RogersServicepointAgent.exe" /AUTORUN
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
StartupFolder: c:\users\darlin\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {612F6E5C-B314-4bab-93D1-D266AAFBE700} - c:\program files\xmlbar\youku downloader\YoukuDownloader(xmlbar).exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: intu-qt2009 - {03947252-2355-4e9b-B446-8CCC75C43370} - c:\program files\quicktax 2009\ic2009pp.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"

================= FIREFOX ===================

FF - ProfilePath - c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{6ac85730-7d0f-4de0-b3fa-21142dd85326}\platform\winnt\components\ColorZilla.dll
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\rogers online protection\rogers servicepoint agent\nprpspa.dll
FF - plugin: c:\users\darlin\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\sminst\BLService.exe [2008-8-11 361808]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2008-8-11 193840]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-5-9 43040]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate1ca2cdcaf95cfe9;Google Update Service (gupdate1ca2cdcaf95cfe9);c:\program files\google\update\GoogleUpdate.exe [2009-9-3 133104]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

=============== Created Last 30 ================

2010-07-18 16:48:42 0 d-----w- c:\users\darlin\appdata\roaming\Malwarebytes
2010-07-18 16:48:32 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-18 16:48:31 0 d-----w- c:\programdata\Malwarebytes
2010-07-18 16:48:30 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-18 16:48:30 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-18 01:09:24 0 d-sh--w- C:\$RECYCLE.BIN
2010-07-18 00:50:15 98816 ----a-w- c:\windows\sed.exe
2010-07-18 00:50:15 77312 ----a-w- c:\windows\MBR.exe
2010-07-18 00:50:15 256512 ----a-w- c:\windows\PEV.exe
2010-07-18 00:50:15 161792 ----a-w- c:\windows\SWREG.exe
2010-07-18 00:50:07 0 d-----w- C:\ComboFix
2010-07-12 16:25:33 0 d-----w- c:\program files\Safer Networking
2010-07-12 13:25:28 8 ----a-w- c:\users\darlin\appdata\roaming\vdnxlf.dat
2010-07-12 03:08:05 255227926 ----a-w- c:\windows\MEMORY.DMP
2010-07-12 01:05:43 0 d-----w- c:\program files\CCleaner
2010-07-11 23:54:59 0 d-----w- c:\program files\TweetDeck
2010-07-11 21:46:31 88 ----a-w- c:\windows\wininit.ini
2010-07-11 21:16:36 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-07-11 21:16:36 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-07-11 18:14:26 0 d-sh--w- c:\programdata\SMACCEEAV
2010-07-10 03:20:48 88576 --sha-r- c:\users\darlin\appdata\roaming\nb-NOM.dll
2010-07-01 03:07:30 0 d-----w- c:\users\darlin\dwhelper
2010-06-23 16:25:13 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 16:25:13 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 16:25:13 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 16:25:13 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 16:25:13 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-22 23:32:16 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-22 23:32:16 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-20 19:29:53 0 d-----w- c:\program files\iPod
2010-06-20 19:29:48 0 d-----w- c:\program files\iTunes
2010-06-20 19:24:01 0 d-----w- c:\program files\Bonjour

==================== Find3M ====================

2010-07-18 17:02:42 48670 ----a-w- c:\programdata\nvModes.dat
2010-06-25 15:20:20 62236 ----a-w- c:\windows\system32\perfh00C.dat
2010-06-25 15:20:20 19286 ----a-w- c:\windows\system32\perfc00C.dat
2010-06-20 19:25:57 86016 ----a-w- c:\windows\inf\infstor.dat
2010-06-20 19:25:57 51200 ----a-w- c:\windows\inf\infpub.dat
2010-06-20 19:25:56 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-06-01 17:37:48 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-26 17:06:41 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47:41 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-18 20:35:16 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-04 19:15:20 834048 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 18:37:45 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-01 14:13:48 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-04-30 02:15:22 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-04-28 14:25:59 97420 ----a-w- c:\windows\fonts\leelawdb.ttf
2010-04-27 21:28:06 37665 ----a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont
2010-04-23 14:13:55 2048 ----a-w- c:\windows\system32\tzres.dll
2008-08-11 10:55:35 37390 ----a-w- c:\windows\inf\perflib\040c\perfd.dat
2008-08-11 10:55:35 37390 ----a-w- c:\windows\inf\perflib\040c\perfc.dat
2008-08-11 10:55:35 340236 ----a-w- c:\windows\inf\perflib\040c\perfi.dat
2008-08-11 10:55:35 340236 ----a-w- c:\windows\inf\perflib\040c\perfh.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2010-03-10 23:05:08 59232800 --sha-w- c:\windows\system32\drivers\fidbox.dat
2008-08-11 10:58:25 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 13:12:01.78 ===============

Thanks again for your help. Hope to hear from you soon. :thanks:

ken545
2010-07-18, 21:51
Hello,

You still have some things going on, lets do this, make sure you follow the instructions in the picture to check and uncheck whats shown

Download the GMER Rootkit Scanner (http://www.gmer.net/gmer.zip). Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double click GMER.exe.
http://img.photobucket.com/albums/v666/sUBs/gmer_zip.gif
If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on NO, then use the following settings for a more complete scan..
In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED ...
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
http://www.geekstogo.com/misc/guide_icons/GMER_thumb.jpg (http://www.geekstogo.com/misc/guide_icons/GMER_instructions.jpg)
Click the image to enlarge it

Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries
Please copy and paste the report into your Post.

DaReelDeel
2010-07-19, 16:54
Hi! I had a problem with the GMER Rookit Scanner. I unzipped gmer.exe to my desktop and started the scan. The scan stops and an error message popped up. I tried again, and then my laptop shut down.

ken545
2010-07-19, 18:16
OK, GMER sometimes acts differently on some systems,


Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Check the boxes beside LOP Check and Purity Check.
Under the Custom Scan box paste this in


netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav



Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

DaReelDeel
2010-07-19, 19:28
Hi again! I ran OTL and only one .txt file popped up. Here is the OTL.txt log, but I couldn't find the Extras.txt file.


OTL logfile created on: 19/07/2010 1:07:16 PM - Run 2
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Darlin\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.54 Gb Total Space | 130.92 Gb Free Space | 58.57% Space Free | Partition Type: NTFS
Drive D: | 9.35 Gb Total Space | 1.70 Gb Free Space | 18.16% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DARLIN-PC
Current User Name: Darlin
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Darlin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
PRC - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\WINDOWS\SMINST\BLService.exe ()
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Darlin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (WPFFontCache_v0400) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\WINDOWS\System32\FntCache.dll (Microsoft Corporation)
SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (Recovery Service for Windows) -- C:\WINDOWS\SMINST\BLService.exe ()
SRV - (Automatic LiveUpdate Scheduler) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (RPSKT) Security Services Driver (x86) -- C:\Windows\System32\DRIVERS\rp_skt32.sys File not found
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (catchme) -- C:\Users\Darlin\AppData\Local\Temp\catchme.sys File not found
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (BCM43XX) -- C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (BCM43XV) -- C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (nvlddmkm) -- C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (RTSTOR) -- C:\WINDOWS\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (CnxtHdAudService) -- C:\WINDOWS\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (NVHDA) -- C:\WINDOWS\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (nvsmu) -- C:\WINDOWS\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (SynTP) -- C:\WINDOWS\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (NVENETFD) -- C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\WINDOWS\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HSFHWAZL) -- C:\WINDOWS\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (HSF_DPV) -- C:\WINDOWS\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) -- C:\WINDOWS\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) -- C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqRemHid) -- C:\WINDOWS\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (PID_0928) Labtec WebCam(PID_0928) -- C:\WINDOWS\System32\drivers\LV561AV.SYS (Labtec Inc.)
DRV - (LVUSBSta) -- C:\WINDOWS\System32\drivers\LVUSBSta.sys (Labtec Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009/09/11 16:51:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/09 19:03:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/09 19:03:01 | 000,000,000 | ---D | M]

[2010/03/17 16:27:38 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Extensions
[2009/08/21 19:44:39 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Extensions\mozswing@mozswing.org
[2010/07/09 18:50:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions
[2010/06/16 15:38:47 | 000,000,000 | ---D | M] (TwitterBar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}
[2010/04/27 17:10:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2010/03/18 20:51:56 | 000,000,000 | ---D | M] (AniWeather) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}
[2010/05/25 20:18:05 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/03/28 14:09:55 | 000,000,000 | ---D | M] (ScrapBook) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2010/03/18 21:34:21 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2010/03/18 21:01:38 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2010/06/08 11:09:24 | 000,000,000 | ---D | M] (ReminderFox) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
[2010/04/19 12:34:58 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/06/30 22:17:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/05/10 10:13:14 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/03/18 21:34:21 | 000,000,000 | ---D | M] (Pixlr Grabber) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{d47a9f51-8281-43fa-f450-f28ef8735e9a}
[2010/06/02 19:11:22 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/04/12 10:07:01 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/05/15 21:16:08 | 000,000,000 | ---D | M] (DVDVideoSoft Toolbar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] (FoxTab) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2010/06/29 16:37:12 | 000,000,000 | ---D | M] (SearchPreview) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
[2010/04/15 10:12:43 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\FirefoxAddon@similarWeb.com
[2010/03/18 21:39:06 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\googletube@googletube.com
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\illimitux@illimitux.net
[2010/04/12 10:07:29 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\isreaditlater@ideashower.com
[2010/04/14 10:14:52 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\personas@christopher.beard
[2010/06/29 16:36:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com
[2010/06/29 16:36:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com-trash
[2010/03/18 21:01:33 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\SkipScreen@SkipScreen
[2010/06/16 15:38:34 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\smarterwiki@wikiatic.com
[2010/07/04 17:21:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\unplug@compunach
[2010/06/16 15:38:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\videosurf_enhanced@videosurf.com
[2010/04/21 10:16:53 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\YoutubeDownloader@PeterOlayev.com
[2010/03/05 15:29:29 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] (TwitterBar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2010/03/05 15:04:55 | 000,000,000 | ---D | M] (TV-Fox) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{2f17f610-5e97-4fed-828f-9940b7b577a4}
[2010/03/04 17:52:58 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{99210d54-6321-41e8-bd1b-2b4c55874efb}
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] (QuickWiki) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{EE223D7A-F30F-11DD-8F0A-D2AD55D89593}
[2010/03/04 17:52:58 | 000,000,000 | ---D | M] (FoxTab) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\en-CA@dictionaries.addons.mozilla.org
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\FirefoxAddon@myfacebook.com
[2010/03/04 17:53:01 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\FirefoxAddon@similarWeb.com
[2010/03/04 18:20:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\firefox-extension@shareaholic.com
[2010/03/04 18:20:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\googletube@googletube.com
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\illimitux@illimitux.net
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\isreaditlater@ideashower.com
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\personas@christopher.beard
[2010/03/04 17:53:00 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\piclens@cooliris.com
[2010/03/04 17:53:01 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\quickdrag@mozilla.ktechcomputing.com
[2010/03/04 18:20:45 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\firefox-extension@shareaholic.com\chrome
[2010/03/04 18:32:31 | 000,007,972 | ---- | M] () -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\searchplugins\oneriot-social-web-search.xml
[2010/03/04 17:43:36 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/02/21 06:22:32 | 000,712,704 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll

O1 HOSTS File: ([2010/07/17 21:05:08 | 000,000,027 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [RogersServicepointAgent.exe] C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [JDK5SWFMZY] C:\Users\Darlin\AppData\Local\Temp\Ez1.exe File not found
O4 - HKCU..\Run: [pacqwen] C:\Users\Darlin\AppData\Roaming\nb-NOM.DLL ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Run YoukuDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe File not found
O9 - Extra 'Tools' menuitem : Youku Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 64.71.255.198 192.168.1.1
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Darlin\Pictures\wild_shutterstock_8532871.jpg
O24 - Desktop BackupWallPaper: C:\Users\Darlin\Pictures\wild_shutterstock_8532871.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/11 09:46:21 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/07/19 13:03:23 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\Darlin\Desktop\OTL.exe
[2010/07/18 15:12:02 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Apple
[2010/07/18 14:54:21 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Adobe
[2010/07/18 13:28:51 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Apple Computer
[2010/07/18 12:48:42 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Roaming\Malwarebytes
[2010/07/18 12:48:32 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/07/18 12:48:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/07/18 12:48:30 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/07/18 12:48:30 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/17 21:09:24 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010/07/17 21:09:21 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010/07/17 20:50:15 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/07/17 20:50:15 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/07/17 20:50:15 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/07/17 20:50:08 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/07/17 20:50:07 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010/07/17 20:49:37 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/07/17 20:49:18 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/07/12 12:25:33 | 000,000,000 | ---D | C] -- C:\Program Files\Safer Networking
[2010/07/12 09:25:13 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2010/07/11 21:05:43 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010/07/11 19:54:59 | 000,000,000 | ---D | C] -- C:\Program Files\TweetDeck
[2010/07/11 17:16:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2010/07/11 17:16:36 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010/07/11 14:14:26 | 000,000,000 | -HSD | C] -- C:\ProgramData\SMACCEEAV
[2010/06/30 23:07:30 | 000,000,000 | ---D | C] -- C:\Users\Darlin\dwhelper
[2010/06/23 12:25:13 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2010/06/23 12:25:13 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2010/06/23 12:25:13 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll
[2010/06/22 19:32:16 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/06/22 19:32:16 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
[2010/06/20 15:29:53 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/06/20 15:29:48 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/06/20 15:24:01 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[4 C:\Users\Darlin\Documents\*.tmp files -> C:\Users\Darlin\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/07/19 13:08:35 | 008,126,464 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat
[2010/07/19 13:03:23 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Darlin\Desktop\OTL.exe
[2010/07/19 13:02:54 | 000,018,171 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 5 Activity 2.docx
[2010/07/19 12:56:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/19 12:54:10 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010/07/19 12:49:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job
[2010/07/19 12:42:17 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/19 12:42:17 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/19 10:46:10 | 000,000,246 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2010/07/19 10:44:27 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2010/07/19 10:44:27 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/07/19 10:44:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/07/19 10:42:38 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/19 10:42:21 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/07/19 10:42:05 | 2951,024,640 | -HS- | M] () -- C:\hiberfil.sys
[2010/07/19 10:42:04 | 266,659,862 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/07/18 22:11:35 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/07/18 22:11:32 | 000,524,288 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TMContainer00000000000000000001.regtrans-ms
[2010/07/18 22:11:32 | 000,065,536 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TM.blf
[2010/07/18 22:11:24 | 002,448,920 | -H-- | M] () -- C:\Users\Darlin\AppData\Local\IconCache.db
[2010/07/18 21:20:34 | 000,039,597 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 4 Activity 6.docx
[2010/07/18 17:49:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job
[2010/07/18 13:28:45 | 000,002,255 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/07/18 12:48:34 | 000,000,818 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/17 21:05:16 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/07/17 21:05:08 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010/07/15 21:42:33 | 000,016,231 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 4 Activity 2.docx
[2010/07/14 21:56:30 | 000,019,630 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 4 Activity 1.docx
[2010/07/13 22:15:38 | 000,023,396 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 3 Activity 3.docx
[2010/07/13 16:47:10 | 000,000,104 | ---- | M] () -- C:\Users\Darlin\Desktop\Recycle Bin - Shortcut.lnk
[2010/07/12 21:50:52 | 000,017,444 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 3 Activity 1.docx
[2010/07/12 13:52:59 | 000,006,105 | ---- | M] () -- C:\Users\Darlin\Documents\Attach.zip
[2010/07/12 09:25:29 | 000,000,008 | ---- | M] () -- C:\Users\Darlin\AppData\Roaming\vdnxlf.dat
[2010/07/11 22:07:45 | 000,001,356 | ---- | M] () -- C:\Users\Darlin\AppData\Local\d3d9caps.dat
[2010/07/11 21:56:48 | 000,013,944 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 2 Activity 7.docx
[2010/07/11 19:55:01 | 000,000,762 | ---- | M] () -- C:\Users\Public\Desktop\TweetDeck.lnk
[2010/07/11 19:19:13 | 000,311,040 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/07/11 17:46:31 | 000,000,088 | ---- | M] () -- C:\Windows\wininit.ini
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183614.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183519.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183518.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183517.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183516.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180651.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180650.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180647.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180645.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180643.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180642.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180641.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180616.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180615.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180614.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180613.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180612.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174936.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174923.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174920.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174919.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174917.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174843.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174842.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174840.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174646.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174644.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174627.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173902.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173617.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173616.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173615.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173608.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173607.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173606.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173605.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173604.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173603.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173602.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173601.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173557.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173518.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-172944.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-172848.backup
[2010/07/09 23:20:49 | 000,088,576 | RHS- | M] () -- C:\Users\Darlin\AppData\Roaming\nb-NOM.dll
[2010/07/08 00:38:14 | 000,019,441 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 2 Activity 3.docx
[2010/07/06 23:28:16 | 000,018,895 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 1 Activity 8.docx
[2010/07/06 21:59:03 | 000,012,800 | ---- | M] () -- C:\Users\Darlin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/06 21:37:18 | 000,013,435 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 1 Activity 5.docx
[2010/07/04 20:35:36 | 000,020,474 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 1 Assignment 4.docx
[2010/07/02 23:37:59 | 000,015,047 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 1 Assignment 1.docx
[2010/07/01 21:49:49 | 000,002,047 | ---- | M] () -- C:\Users\Darlin\Desktop\Google Chrome.lnk
[2010/07/01 21:49:49 | 000,002,009 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/06/25 11:20:20 | 002,325,706 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/06/25 11:20:20 | 000,062,236 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2010/06/25 11:20:20 | 000,019,286 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2010/06/25 11:20:19 | 000,685,978 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/06/25 11:20:19 | 000,620,982 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/06/20 15:31:10 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[4 C:\Users\Darlin\Documents\*.tmp files -> C:\Users\Darlin\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/19 13:02:53 | 000,018,171 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 5 Activity 2.docx
[2010/07/18 21:20:20 | 000,039,597 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 4 Activity 6.docx
[2010/07/18 12:48:34 | 000,000,818 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/17 20:50:15 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010/07/17 20:50:15 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/07/17 20:50:15 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/07/17 20:50:15 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/07/17 20:50:15 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/07/15 21:41:27 | 000,016,231 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 4 Activity 2.docx
[2010/07/14 18:31:52 | 000,019,630 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 4 Activity 1.docx
[2010/07/13 22:14:05 | 000,023,396 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 3 Activity 3.docx
[2010/07/13 16:47:10 | 000,000,104 | ---- | C] () -- C:\Users\Darlin\Desktop\Recycle Bin - Shortcut.lnk
[2010/07/12 17:29:08 | 000,017,444 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 3 Activity 1.docx
[2010/07/12 13:52:59 | 000,006,105 | ---- | C] () -- C:\Users\Darlin\Documents\Attach.zip
[2010/07/12 09:25:28 | 000,000,008 | ---- | C] () -- C:\Users\Darlin\AppData\Roaming\vdnxlf.dat
[2010/07/11 23:08:05 | 266,659,862 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010/07/11 22:13:06 | 2951,024,640 | -HS- | C] () -- C:\hiberfil.sys
[2010/07/11 21:12:54 | 000,001,972 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/07/11 21:12:54 | 000,001,111 | ---- | C] () -- C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2010/07/11 21:07:22 | 000,013,944 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 2 Activity 7.docx
[2010/07/11 17:46:31 | 000,000,088 | ---- | C] () -- C:\Windows\wininit.ini
[2010/07/09 23:20:48 | 000,088,576 | RHS- | C] () -- C:\Users\Darlin\AppData\Roaming\nb-NOM.dll
[2010/07/08 00:08:30 | 000,019,441 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 2 Activity 3.docx
[2010/07/06 23:28:16 | 000,018,895 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 1 Activity 8.docx
[2010/07/06 21:37:17 | 000,013,435 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 1 Activity 5.docx
[2010/07/04 20:35:24 | 000,020,474 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 1 Assignment 4.docx
[2010/07/02 23:37:58 | 000,015,047 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 1 Assignment 1.docx
[2010/06/20 18:55:00 | 000,002,255 | ---- | C] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/06/20 15:31:10 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2009/09/17 16:23:53 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2008/01/20 22:24:38 | 000,033,794 | ---- | C] () -- C:\Windows\System32\unelwin.dll
[2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/03/09 05:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2005/01/19 09:30:54 | 000,009,255 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini

========== LOP Check ==========

[2010/06/02 18:46:13 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\BitComet
[2009/10/09 21:17:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\iWin
[2010/07/17 20:48:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\LimeWire
[2010/06/08 13:18:41 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Opera
[2009/10/10 23:06:18 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\PlayFirst
[2010/03/10 18:32:47 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Rogers Online Protection
[2009/10/17 15:25:15 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Template
[2009/08/21 21:22:19 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2009/11/30 17:12:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2009/09/05 19:38:05 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\WildTangent
[2010/07/18 22:11:38 | 000,032,644 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/01/20 22:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\ERDNT\cache\AGP440.sys
[2008/01/20 22:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\System32\drivers\AGP440.sys
[2008/01/20 22:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/20 22:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/20 22:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/20 22:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 05:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\WINDOWS\System32\drivers\atapi.sys
[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/20 22:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/20 22:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 05:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 05:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\WINDOWS\ERDNT\cache\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\WINDOWS\System32\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\WINDOWS\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2007/01/13 01:30:08 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files\CyberLink\PowerDirector\EventLog.dll

< MD5 for: IASTORV.SYS >
[2008/01/20 22:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\WINDOWS\System32\drivers\iaStorV.sys
[2008/01/20 22:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\WINDOWS\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/20 22:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\WINDOWS\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 05:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\WINDOWS\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/04/11 02:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\WINDOWS\System32\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/20 22:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2006/11/02 05:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/20 22:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\WINDOWS\System32\drivers\nvstor.sys
[2008/01/20 22:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/20 22:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\WINDOWS\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/20 22:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\WINDOWS\System32\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/04/11 02:27:47 | 000,241,128 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5 -- C:\WINDOWS\System32\rsaenh.dll
[2009/04/11 02:28:23 | 000,228,352 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\SLC.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2008/01/20 23:14:18 | 016,846,848 | ---- | M] () -- C:\WINDOWS\System32\config\COMPONENTS.SAV
[2008/01/20 23:14:08 | 000,106,496 | ---- | M] () -- C:\WINDOWS\System32\config\DEFAULT.SAV
[2008/01/20 23:14:18 | 000,020,480 | ---- | M] () -- C:\WINDOWS\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | ---- | M] () -- C:\WINDOWS\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | ---- | M] () -- C:\WINDOWS\System32\config\SYSTEM.SAV

========== Files - Unicode (All) ==========
[2009/10/02 23:23:37 | 000,000,036 | ---- | M] ()(C:\Windows\System32\?????????????????????????????????????????????????) -- C:\Windows\System32\㩃停潲牧浡䘠汩獥剜杯牥⁳湏楬敮倠潲整瑣潩屮潒敧獲传汮湩⁥牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩⹷潣普杩
[2009/10/02 23:23:37 | 000,000,036 | ---- | C] ()(C:\Windows\System32\?????????????????????????????????????????????????) -- C:\Windows\System32\㩃停潲牧浡䘠汩獥剜杯牥⁳湏楬敮倠潲整瑣潩屮潒敧獲传汮湩⁥牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩⹷潣普杩
< End of report >

ken545
2010-07-19, 20:01
Run OTL

Under the Custom Scans/Fixes box at the bottom, paste in the following



:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O4 - HKCU..\Run: [JDK5SWFMZY] C:\Users\Darlin\AppData\Local\Temp\Ez1.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present


:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]



Then click the Run Fix button at the top
Let the program run unhindered, reboot when it is done
Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

DaReelDeel
2010-07-19, 20:17
Hi! I ran the custom fix on OTL and rebooted. Here is the new OTL log. Thanks again for helping.


All processes killed
========== OTL ==========
No active process named explorer.exe was found!
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\JDK5SWFMZY deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Bhing or J.A
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 166634 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Darlin
->Temp folder emptied: 2814440 bytes
->Temporary Internet Files folder emptied: 64914120 bytes
->Java cache emptied: 10711059 bytes
->FireFox cache emptied: 11913456 bytes
->Google Chrome cache emptied: 373442400 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 15944 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: TEMP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: TEMP.Darlin-PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: TEMP.Darlin-PC.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 112012 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 443.00 mb


OTL by OldTimer - Version 3.2.9.1 log created on 07192010_140904

Files\Folders moved on Reboot...
C:\Users\Darlin\AppData\Local\Temp\ehmsas.txt moved successfully.
C:\Users\Darlin\AppData\Local\Temp\VGXCCC.tmp moved successfully.

Registry entries deleted on Reboot...

ken545
2010-07-19, 23:29
Go ahead and run OTL without adding all the entries to the custom scan and post the new log please

DaReelDeel
2010-07-20, 19:28
Hello,

I ran an OTL scan without the entries to the custom scan. Here is the new log.


OTL logfile created on: 20/07/2010 1:22:36 PM - Run 3
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Darlin\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.54 Gb Total Space | 129.71 Gb Free Space | 58.02% Space Free | Partition Type: NTFS
Drive D: | 9.35 Gb Total Space | 1.70 Gb Free Space | 18.16% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DARLIN-PC
Current User Name: Darlin
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Darlin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
PRC - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\WINDOWS\SMINST\BLService.exe ()
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Darlin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (WPFFontCache_v0400) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\WINDOWS\System32\FntCache.dll (Microsoft Corporation)
SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (Recovery Service for Windows) -- C:\WINDOWS\SMINST\BLService.exe ()
SRV - (Automatic LiveUpdate Scheduler) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (RPSKT) Security Services Driver (x86) -- C:\Windows\System32\DRIVERS\rp_skt32.sys File not found
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (catchme) -- C:\Users\Darlin\AppData\Local\Temp\catchme.sys File not found
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (BCM43XX) -- C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (BCM43XV) -- C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (nvlddmkm) -- C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (RTSTOR) -- C:\WINDOWS\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (CnxtHdAudService) -- C:\WINDOWS\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (NVHDA) -- C:\WINDOWS\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (nvsmu) -- C:\WINDOWS\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (SynTP) -- C:\WINDOWS\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (NVENETFD) -- C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\WINDOWS\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HSFHWAZL) -- C:\WINDOWS\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (HSF_DPV) -- C:\WINDOWS\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) -- C:\WINDOWS\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) -- C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqRemHid) -- C:\WINDOWS\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (PID_0928) Labtec WebCam(PID_0928) -- C:\WINDOWS\System32\drivers\LV561AV.SYS (Labtec Inc.)
DRV - (LVUSBSta) -- C:\WINDOWS\System32\drivers\LVUSBSta.sys (Labtec Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009/09/11 16:51:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/09 19:03:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/09 19:03:01 | 000,000,000 | ---D | M]

[2010/03/17 16:27:38 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Extensions
[2009/08/21 19:44:39 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Extensions\mozswing@mozswing.org
[2010/07/09 18:50:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions
[2010/06/16 15:38:47 | 000,000,000 | ---D | M] (TwitterBar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}
[2010/04/27 17:10:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2010/03/18 20:51:56 | 000,000,000 | ---D | M] (AniWeather) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}
[2010/05/25 20:18:05 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/03/28 14:09:55 | 000,000,000 | ---D | M] (ScrapBook) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2010/03/18 21:34:21 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2010/03/18 21:01:38 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2010/06/08 11:09:24 | 000,000,000 | ---D | M] (ReminderFox) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
[2010/04/19 12:34:58 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/06/30 22:17:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/05/10 10:13:14 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/03/18 21:34:21 | 000,000,000 | ---D | M] (Pixlr Grabber) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{d47a9f51-8281-43fa-f450-f28ef8735e9a}
[2010/06/02 19:11:22 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/04/12 10:07:01 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/05/15 21:16:08 | 000,000,000 | ---D | M] (DVDVideoSoft Toolbar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] (FoxTab) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2010/06/29 16:37:12 | 000,000,000 | ---D | M] (SearchPreview) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
[2010/04/15 10:12:43 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\FirefoxAddon@similarWeb.com
[2010/03/18 21:39:06 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\googletube@googletube.com
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\illimitux@illimitux.net
[2010/04/12 10:07:29 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\isreaditlater@ideashower.com
[2010/04/14 10:14:52 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\personas@christopher.beard
[2010/06/29 16:36:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com
[2010/06/29 16:36:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com-trash
[2010/03/18 21:01:33 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\SkipScreen@SkipScreen
[2010/06/16 15:38:34 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\smarterwiki@wikiatic.com
[2010/07/04 17:21:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\unplug@compunach
[2010/06/16 15:38:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\videosurf_enhanced@videosurf.com
[2010/04/21 10:16:53 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\YoutubeDownloader@PeterOlayev.com
[2010/03/05 15:29:29 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] (TwitterBar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2010/03/05 15:04:55 | 000,000,000 | ---D | M] (TV-Fox) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{2f17f610-5e97-4fed-828f-9940b7b577a4}
[2010/03/04 17:52:58 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{99210d54-6321-41e8-bd1b-2b4c55874efb}
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] (QuickWiki) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{EE223D7A-F30F-11DD-8F0A-D2AD55D89593}
[2010/03/04 17:52:58 | 000,000,000 | ---D | M] (FoxTab) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\en-CA@dictionaries.addons.mozilla.org
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\FirefoxAddon@myfacebook.com
[2010/03/04 17:53:01 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\FirefoxAddon@similarWeb.com
[2010/03/04 18:20:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\firefox-extension@shareaholic.com
[2010/03/04 18:20:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\googletube@googletube.com
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\illimitux@illimitux.net
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\isreaditlater@ideashower.com
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\personas@christopher.beard
[2010/03/04 17:53:00 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\piclens@cooliris.com
[2010/03/04 17:53:01 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\quickdrag@mozilla.ktechcomputing.com
[2010/03/04 18:20:45 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\firefox-extension@shareaholic.com\chrome
[2010/03/04 18:32:31 | 000,007,972 | ---- | M] () -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\searchplugins\oneriot-social-web-search.xml
[2010/03/04 17:43:36 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/02/21 06:22:32 | 000,712,704 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll

O1 HOSTS File: ([2010/07/17 21:05:08 | 000,000,027 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [RogersServicepointAgent.exe] C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [pacqwen] C:\Users\Darlin\AppData\Roaming\nb-NOM.DLL ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Run YoukuDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe File not found
O9 - Extra 'Tools' menuitem : Youku Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Darlin\Pictures\wild_shutterstock_8532871.jpg
O24 - Desktop BackupWallPaper: C:\Users\Darlin\Pictures\wild_shutterstock_8532871.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/11 09:46:21 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/07/19 14:09:04 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/07/19 13:03:23 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\Darlin\Desktop\OTL.exe
[2010/07/18 15:12:02 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Apple
[2010/07/18 14:54:21 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Adobe
[2010/07/18 13:28:51 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Apple Computer
[2010/07/18 12:48:42 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Roaming\Malwarebytes
[2010/07/18 12:48:32 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/07/18 12:48:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/07/18 12:48:30 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/07/18 12:48:30 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/17 21:09:24 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010/07/17 21:09:21 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010/07/17 20:50:15 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/07/17 20:50:15 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/07/17 20:50:15 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/07/17 20:50:08 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/07/17 20:50:07 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010/07/17 20:49:37 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/07/17 20:49:18 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/07/12 12:25:33 | 000,000,000 | ---D | C] -- C:\Program Files\Safer Networking
[2010/07/12 09:25:13 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2010/07/11 21:05:43 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010/07/11 19:54:59 | 000,000,000 | ---D | C] -- C:\Program Files\TweetDeck
[2010/07/11 17:16:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2010/07/11 17:16:36 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010/07/11 14:14:26 | 000,000,000 | -HSD | C] -- C:\ProgramData\SMACCEEAV
[2010/06/30 23:07:30 | 000,000,000 | ---D | C] -- C:\Users\Darlin\dwhelper
[2010/06/23 12:25:13 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2010/06/23 12:25:13 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2010/06/23 12:25:13 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll
[2010/06/22 19:32:16 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/06/22 19:32:16 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
[2010/06/20 15:29:53 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/06/20 15:29:48 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/06/20 15:24:01 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[4 C:\Users\Darlin\Documents\*.tmp files -> C:\Users\Darlin\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/07/20 13:23:46 | 008,126,464 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat
[2010/07/20 12:59:48 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2010/07/20 12:59:48 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/07/20 12:59:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/07/20 12:59:43 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job
[2010/07/20 12:59:43 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/20 10:36:16 | 000,002,255 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/07/20 10:13:31 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010/07/20 10:11:05 | 000,000,246 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2010/07/20 10:10:03 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/20 10:09:48 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/20 10:09:48 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/20 10:09:47 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/07/20 10:09:36 | 2951,077,888 | -HS- | M] () -- C:\hiberfil.sys
[2010/07/19 17:49:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job
[2010/07/19 17:02:18 | 000,019,592 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 5 Activity 2.docx
[2010/07/19 14:10:34 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/07/19 14:10:32 | 000,524,288 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TMContainer00000000000000000001.regtrans-ms
[2010/07/19 14:10:32 | 000,065,536 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TM.blf
[2010/07/19 13:03:23 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Darlin\Desktop\OTL.exe
[2010/07/19 10:42:04 | 266,659,862 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/07/18 22:11:24 | 002,448,920 | -H-- | M] () -- C:\Users\Darlin\AppData\Local\IconCache.db
[2010/07/18 21:20:34 | 000,039,597 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 4 Activity 6.docx
[2010/07/18 12:48:34 | 000,000,818 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/17 21:05:16 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/07/17 21:05:08 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010/07/15 21:42:33 | 000,016,231 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 4 Activity 2.docx
[2010/07/14 21:56:30 | 000,019,630 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 4 Activity 1.docx
[2010/07/13 22:15:38 | 000,023,396 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 3 Activity 3.docx
[2010/07/13 16:47:10 | 000,000,104 | ---- | M] () -- C:\Users\Darlin\Desktop\Recycle Bin - Shortcut.lnk
[2010/07/12 21:50:52 | 000,017,444 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 3 Activity 1.docx
[2010/07/12 13:52:59 | 000,006,105 | ---- | M] () -- C:\Users\Darlin\Documents\Attach.zip
[2010/07/12 09:25:29 | 000,000,008 | ---- | M] () -- C:\Users\Darlin\AppData\Roaming\vdnxlf.dat
[2010/07/11 22:07:45 | 000,001,356 | ---- | M] () -- C:\Users\Darlin\AppData\Local\d3d9caps.dat
[2010/07/11 21:56:48 | 000,013,944 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 2 Activity 7.docx
[2010/07/11 19:55:01 | 000,000,762 | ---- | M] () -- C:\Users\Public\Desktop\TweetDeck.lnk
[2010/07/11 19:19:13 | 000,311,040 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/07/11 17:46:31 | 000,000,088 | ---- | M] () -- C:\Windows\wininit.ini
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183614.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183519.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183518.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183517.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183516.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180651.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180650.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180647.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180645.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180643.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180642.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180641.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180616.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180615.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180614.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180613.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180612.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174936.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174923.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174920.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174919.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174917.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174843.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174842.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174840.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174646.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174644.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174627.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173902.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173617.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173616.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173615.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173608.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173607.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173606.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173605.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173604.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173603.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173602.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173601.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173557.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173518.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-172944.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-172848.backup
[2010/07/09 23:20:49 | 000,088,576 | RHS- | M] () -- C:\Users\Darlin\AppData\Roaming\nb-NOM.dll
[2010/07/08 00:38:14 | 000,019,441 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 2 Activity 3.docx
[2010/07/06 23:28:16 | 000,018,895 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 1 Activity 8.docx
[2010/07/06 21:59:03 | 000,012,800 | ---- | M] () -- C:\Users\Darlin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/06 21:37:18 | 000,013,435 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 1 Activity 5.docx
[2010/07/04 20:35:36 | 000,020,474 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 1 Assignment 4.docx
[2010/07/02 23:37:59 | 000,015,047 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 1 Assignment 1.docx
[2010/07/01 21:49:49 | 000,002,047 | ---- | M] () -- C:\Users\Darlin\Desktop\Google Chrome.lnk
[2010/07/01 21:49:49 | 000,002,009 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/06/25 11:20:20 | 002,325,706 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/06/25 11:20:20 | 000,062,236 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2010/06/25 11:20:20 | 000,019,286 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2010/06/25 11:20:19 | 000,685,978 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/06/25 11:20:19 | 000,620,982 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/06/20 15:31:10 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[4 C:\Users\Darlin\Documents\*.tmp files -> C:\Users\Darlin\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/19 13:02:53 | 000,019,592 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 5 Activity 2.docx
[2010/07/18 21:20:20 | 000,039,597 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 4 Activity 6.docx
[2010/07/18 12:48:34 | 000,000,818 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/17 20:50:15 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010/07/17 20:50:15 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/07/17 20:50:15 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/07/17 20:50:15 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/07/17 20:50:15 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/07/15 21:41:27 | 000,016,231 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 4 Activity 2.docx
[2010/07/14 18:31:52 | 000,019,630 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 4 Activity 1.docx
[2010/07/13 22:14:05 | 000,023,396 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 3 Activity 3.docx
[2010/07/13 16:47:10 | 000,000,104 | ---- | C] () -- C:\Users\Darlin\Desktop\Recycle Bin - Shortcut.lnk
[2010/07/12 17:29:08 | 000,017,444 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 3 Activity 1.docx
[2010/07/12 13:52:59 | 000,006,105 | ---- | C] () -- C:\Users\Darlin\Documents\Attach.zip
[2010/07/12 09:25:28 | 000,000,008 | ---- | C] () -- C:\Users\Darlin\AppData\Roaming\vdnxlf.dat
[2010/07/11 23:08:05 | 266,659,862 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010/07/11 22:13:06 | 2951,077,888 | -HS- | C] () -- C:\hiberfil.sys
[2010/07/11 21:12:54 | 000,001,972 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/07/11 21:12:54 | 000,001,111 | ---- | C] () -- C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2010/07/11 21:07:22 | 000,013,944 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 2 Activity 7.docx
[2010/07/11 17:46:31 | 000,000,088 | ---- | C] () -- C:\Windows\wininit.ini
[2010/07/09 23:20:48 | 000,088,576 | RHS- | C] () -- C:\Users\Darlin\AppData\Roaming\nb-NOM.dll
[2010/07/08 00:08:30 | 000,019,441 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 2 Activity 3.docx
[2010/07/06 23:28:16 | 000,018,895 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 1 Activity 8.docx
[2010/07/06 21:37:17 | 000,013,435 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 1 Activity 5.docx
[2010/07/04 20:35:24 | 000,020,474 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 1 Assignment 4.docx
[2010/07/02 23:37:58 | 000,015,047 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 1 Assignment 1.docx
[2010/06/20 18:55:00 | 000,002,255 | ---- | C] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/06/20 15:31:10 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2009/09/17 16:23:53 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2008/01/20 22:24:38 | 000,033,794 | ---- | C] () -- C:\Windows\System32\unelwin.dll
[2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/03/09 05:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2005/01/19 09:30:54 | 000,009,255 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini

========== LOP Check ==========

[2010/06/02 18:46:13 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\BitComet
[2009/10/09 21:17:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\iWin
[2010/07/17 20:48:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\LimeWire
[2010/06/08 13:18:41 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Opera
[2009/10/10 23:06:18 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\PlayFirst
[2010/03/10 18:32:47 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Rogers Online Protection
[2009/10/17 15:25:15 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Template
[2009/08/21 21:22:19 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2009/11/30 17:12:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2009/09/05 19:38:05 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\WildTangent
[2010/07/19 14:10:35 | 000,032,644 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2009/10/02 23:23:37 | 000,000,036 | ---- | M] ()(C:\Windows\System32\?????????????????????????????????????????????????) -- C:\Windows\System32\㩃停潲牧浡䘠汩獥剜杯牥⁳湏楬敮倠潲整瑣潩屮潒敧獲传汮湩⁥牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩⹷潣普杩
[2009/10/02 23:23:37 | 000,000,036 | ---- | C] ()(C:\Windows\System32\?????????????????????????????????????????????????) -- C:\Windows\System32\㩃停潲牧浡䘠汩獥剜杯牥⁳湏楬敮倠潲整瑣潩屮潒敧獲传汮湩⁥牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩⹷潣普杩
< End of report >

ken545
2010-07-21, 00:36
Thanks for the report, how are things running now ?

DaReelDeel
2010-07-21, 18:48
Hi,

I've been having problems with my browsers. I mostly use google chrome. When I google something and click the search results, it shows and then it goes blank. It also tends to redirect me to different websites. I googled my problem and it turns out I have a google redirect virus. When I did a scan with Spybot, it doesn't show any malware problems. I was wondering if you knew how to get rid of this virus. Thanks again for all your help so far.

ken545
2010-07-21, 18:58
Sorry your still having problems, lets do this

With Vista you may need to right click Combofix and select RUN AS ADMINISTRATOR

Download ComboFix from one of these locations:

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)


* IMPORTANT !!! Save ComboFix.exe to your Desktop


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See this Link (http://www.bleepingcomputer.com/forums/topic114351.html) for programs that need to be disabled and instruction on how to disable them.
Remember to re-enable them when we're done.


Double click on ComboFix.exe & follow the prompts.


As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.


Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



http://img.photobucket.com/albums/v706/ried7/RC1.png


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://img.photobucket.com/albums/v706/ried7/RC2-1.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.




I still need to see the GMER log, there could be a rootkit infection we cant see on the regular scans, after you run Combofix and post the log, try running GMER in Safemode

To Enter Safemode

Go to Start> Shut off your Computer> Restart
As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
this will bring up a menu.
Use the Up and Down Arrow Keys to scroll up to Safemode
Then press the Enter Key on your Keyboard

Tutorial if you need it How to boot into Safemode (http://www.bleepingcomputer.com/tutorials/tutorial61.html)



http://img.photobucket.com/albums/v666/sUBs/gmer_zip.gif
Download GMER Rootkit Scanner from here (http://www.gmer.net/gmer.zip) or here (http://www.majorgeeks.com/download.php?det=5198).

Extract the contents of the zipped file to desktop.
Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.

http://i266.photobucket.com/albums/ii277/sUBs_/th_Gmer_initScan.gif (http://i266.photobucket.com/albums/ii277/sUBs_/Gmer_initScan.gif)
Click the image to enlarge it

In the right panel, you will see several boxes that have been checked. Uncheck the following ...
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)

Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.

Save it where you can easily find it, such as your desktop, and post it in your next reply.


**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

DaReelDeel
2010-07-21, 20:19
Hi. I ran combofix. I'm not sure what a Hijackthis log is, but here is the combofix log.

ComboFix 10-07-20.03 - Darlin 21/07/2010 13:57:28.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2814.1836 [GMT -4:00]
Running from: c:\users\Darlin\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-06-21 to 2010-07-21 )))))))))))))))))))))))))))))))
.

2010-07-21 18:06 . 2010-07-21 18:06 -------- d-----w- c:\users\TEMP\AppData\Local\temp
2010-07-21 18:06 . 2010-07-21 18:06 -------- d-----w- c:\users\TEMP.Darlin-PC\AppData\Local\temp
2010-07-21 18:06 . 2010-07-21 18:06 -------- d-----w- c:\users\TEMP.Darlin-PC.000\AppData\Local\temp
2010-07-21 18:06 . 2010-07-21 18:06 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-07-21 18:06 . 2010-07-21 18:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-21 18:06 . 2010-07-21 18:06 -------- d-----w- c:\users\Bhing or J.A\AppData\Local\temp
2010-07-19 18:09 . 2010-07-19 18:09 -------- d-----w- C:\_OTL
2010-07-18 19:12 . 2010-07-18 19:12 -------- d-----w- c:\users\Darlin\AppData\Local\Apple
2010-07-18 18:54 . 2010-07-19 18:56 -------- d-----w- c:\users\Darlin\AppData\Local\Adobe
2010-07-18 17:28 . 2010-07-18 17:28 -------- d-----w- c:\users\Darlin\AppData\Local\Apple Computer
2010-07-18 16:48 . 2010-07-18 16:48 -------- d-----w- c:\users\Darlin\AppData\Roaming\Malwarebytes
2010-07-18 16:48 . 2010-07-18 16:48 -------- d-----w- c:\programdata\Malwarebytes
2010-07-18 16:48 . 2010-07-21 17:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-12 16:25 . 2010-07-12 16:25 -------- d-----w- c:\program files\Safer Networking
2010-07-12 13:25 . 2010-07-12 13:25 -------- d-----w- c:\windows\Sun
2010-07-12 01:05 . 2010-07-12 01:05 -------- d-----w- c:\program files\CCleaner
2010-07-11 23:54 . 2010-07-11 23:54 -------- d-----w- c:\program files\TweetDeck
2010-07-11 21:16 . 2010-07-20 18:28 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-07-11 21:16 . 2010-07-12 01:18 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-07-11 18:14 . 2010-07-11 18:14 -------- d-sh--w- c:\programdata\SMACCEEAV
2010-07-10 03:20 . 2010-07-10 03:20 88576 --sha-r- c:\users\Darlin\AppData\Roaming\nb-NOM.dll
2010-07-01 03:07 . 2010-07-01 03:07 -------- d-----w- c:\users\Darlin\dwhelper
2010-06-29 20:36 . 2010-06-14 16:08 103424 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2010-06-29 20:36 . 2010-06-14 16:08 4687872 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
2010-06-29 20:36 . 2010-06-14 16:08 545280 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2010-06-29 20:36 . 2010-06-14 16:08 4687360 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
2010-06-29 20:36 . 2010-06-14 16:08 425984 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2010-06-29 20:36 . 2010-06-14 16:08 152064 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2010-06-29 20:36 . 2010-06-14 16:08 57856 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2010-06-23 16:25 . 2009-11-08 14:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 16:25 . 2009-11-08 14:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 16:25 . 2009-11-08 14:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 16:25 . 2009-11-08 14:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 16:25 . 2009-11-08 14:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-22 23:32 . 2010-04-16 16:43 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-22 23:32 . 2010-04-16 14:39 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-21 16:30 . 2009-09-05 23:39 48670 ----a-w- c:\programdata\nvModes.dat
2010-07-21 03:14 . 2008-08-11 12:18 12 ----a-w- c:\windows\bthservsdp.dat
2010-07-18 00:48 . 2009-08-21 23:44 -------- d-----w- c:\users\Darlin\AppData\Roaming\LimeWire
2010-07-18 00:44 . 2009-08-21 23:40 -------- d-----w- c:\program files\LimeWire
2010-07-15 14:19 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-07-14 02:07 . 2009-08-14 18:56 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-12 13:25 . 2010-07-12 13:25 8 ----a-w- c:\users\Darlin\AppData\Roaming\vdnxlf.dat
2010-07-12 02:07 . 2009-08-24 20:51 1356 ----a-w- c:\users\Darlin\AppData\Local\d3d9caps.dat
2010-07-11 17:54 . 2009-12-30 23:37 -------- d-----w- c:\users\Darlin\AppData\Roaming\vlc
2010-06-25 15:20 . 2008-08-11 10:56 62236 ----a-w- c:\windows\system32\perfh00C.dat
2010-06-25 15:20 . 2008-08-11 10:56 19286 ----a-w- c:\windows\system32\perfc00C.dat
2010-06-25 15:15 . 2009-08-24 21:08 -------- d-----w- c:\program files\Microsoft.NET
2010-06-23 17:56 . 2009-08-22 01:22 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-20 19:31 . 2010-06-20 19:29 -------- d-----w- c:\program files\iTunes
2010-06-20 19:29 . 2010-06-20 19:29 -------- d-----w- c:\program files\iPod
2010-06-20 19:29 . 2009-08-21 23:38 -------- d-----w- c:\program files\Common Files\Apple
2010-06-20 19:24 . 2010-06-20 19:24 -------- d-----w- c:\program files\Bonjour
2010-06-20 19:20 . 2010-06-20 19:20 72504 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-14 17:32 . 2010-06-14 17:32 -------- d-----w- c:\programdata\LightScribe
2010-06-11 17:22 . 2009-08-14 18:59 -------- d-----w- c:\programdata\Microsoft Help
2010-06-08 21:01 . 2009-08-21 22:23 77944 ----a-w- c:\users\Darlin\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-08 17:24 . 2009-08-21 23:45 -------- d-----w- c:\users\Darlin\AppData\Roaming\Apple Computer
2010-06-08 17:24 . 2009-08-21 23:38 -------- d-----w- c:\programdata\Apple
2010-06-08 15:10 . 2009-12-02 20:45 -------- d-----w- c:\programdata\Norton
2010-06-05 17:27 . 2010-02-15 18:56 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-02 22:46 . 2010-06-02 22:28 -------- d-----w- c:\users\Darlin\AppData\Roaming\BitComet
2010-05-26 17:06 . 2010-06-10 18:58 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-10 18:58 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-21 18:14 . 2009-10-03 03:00 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-16 01:16 . 2010-05-16 01:16 101376 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
2010-05-16 01:16 . 2010-05-16 01:16 52224 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
2010-05-04 19:15 . 2010-06-10 18:58 834048 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 18:37 . 2010-06-10 18:58 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-01 14:13 . 2010-06-10 18:57 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-04-30 02:15 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-04-23 14:13 . 2010-05-25 23:39 2048 ----a-w- c:\windows\system32\tzres.dll
2010-03-10 23:05 . 2009-10-03 04:02 59232800 --sha-w- c:\windows\System32\drivers\fidbox.dat
2008-08-11 10:58 . 2008-08-11 10:58 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( SnapShot@2010-07-18_01.05.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2010-07-21 14:39 71672 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-08-21 22:24 . 2010-07-21 14:39 16772 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1042238982-2704989617-889929576-1000_UserData.bin
+ 2007-09-02 11:55 . 2010-07-21 14:36 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2007-09-02 11:55 . 2010-07-18 00:25 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-07-12 02:45 . 2010-07-21 14:36 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-07-12 02:45 . 2010-07-18 00:25 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-09-02 11:55 . 2010-07-18 00:25 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-09-02 11:55 . 2010-07-21 14:36 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-07-18 00:37 . 2010-07-18 00:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-07-21 14:36 . 2010-07-21 14:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-07-18 00:37 . 2010-07-18 00:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-07-21 14:36 . 2010-07-21 14:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-08-22 00:25 . 2010-07-21 16:30 317314 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2006-11-02 13:05 . 2010-07-21 14:39 100128 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-02-26 2289664]
"Google Update"="c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-08-21 133104]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"pacqwen"="c:\users\Darlin\AppData\Roaming\nb-NOM.dll" [2010-07-10 88576]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-26 49152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-05 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"RogersServicepointAgent.exe"="c:\program files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" [2009-02-27 3228912]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-06-12 468264]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]

c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-7-31 139776]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):2f,48,75,21,55,e6,ca,01

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1ca2cdcaf95cfe9;Google Update Service (gupdate1ca2cdcaf95cfe9);c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 133104]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-04-26 361808]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-05-09 43040]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-02-26 21:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-07-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-09-03 21:21]

2010-07-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 21:22]

2010-07-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 21:22]

2010-07-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job
- c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-21 23:27]

2010-07-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job
- c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-21 23:27]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
uInternet Settings,ProxyOverride = <local>;*.local
uInternet Settings,ProxyServer = http=127.0.0.1:5555
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{612F6E5C-B314-4bab-93D1-D266AAFBE700} - c:\program files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe
FF - ProfilePath - c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll
FF - plugin: c:\users\Darlin\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-21 14:06
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-07-21 14:10:27
ComboFix-quarantined-files.txt 2010-07-21 18:10
ComboFix2.txt 2010-07-18 01:09

Pre-Run: 139,206,582,272 bytes free
Post-Run: 139,173,937,152 bytes free

- - End Of File - - 6827D1C3BFF70014B68AFE44D2993E45

DaReelDeel
2010-07-21, 20:57
I tried to run gmer in safe mode, but it still stopped and shut down.

ken545
2010-07-21, 23:11
Hi,

c:\program files\LimeWire <--I still see it installed ,If you continue to use file sharing programs and sites , 100% guaranteed you will get infected over and over and over again, your downloading that file from and unknown source , malware writers know this and have hopped on the band wagon and using programs like this to infect your computer, you need to uninstall it via "Programs and Features" in the Control Panel You should stay away from any file sharing like the torrents and all the rest, there not safe anymore.


Please download SuperAntiSpyware Free (http://www.superantispyware.com/superantispyware.html)
Install the program

Run SuperAntiSpyware and click: Check for updates
Once the update is finished, on the main screen, click: Scan your computer
Check: Perform Complete Scan
Click Next to start the scan.

Superantispyware scans the computer, and when finished, lists all the infections found.
Make sure everything found has a check next to it, and press: Next <-- Important
Then, click Finish

It is possible that the program asks to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click: Preferences
Click the Statistics/Logs tab
Under Scanner Logs, double-click SuperAntiSpyware Scan Log
It opens in your default text editor (such as Notepad)

Please provide the SuperAntiSpyware log in your reply, as well as a new HijackThis log.





Please run this free online virus scanner from ESET (http://www.eset.com/onlinescan/)

Note: You will need to use Internet explorer for this scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Click Start
Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic

DaReelDeel
2010-07-22, 20:38
I went into my programs in control panel and I couldn't find Limewire. I ran SuperAntiSpyware. Here is the log along with the new HijackThis log.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/22/2010 at 02:03 PM

Application Version : 4.41.1000

Core Rules Database Version : 5247
Trace Rules Database Version: 3059

Scan type : Complete Scan
Total Scan Time : 00:57:26

Memory items scanned : 725
Memory threats detected : 0
Registry items scanned : 9697
Registry threats detected : 7
File items scanned : 34162
File threats detected : 371

Adware.Tracking Cookie
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\darlin@bellcan.adbureau[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\darlin@msnportal.112.2o7[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\darlin@atdmt[3].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\bhing_or_j.a@bellcan.adbureau[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\bhing_or_j.a@advertising[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\bhing_or_j.a@atdmt[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@chitika[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@ad1.clickhype[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@tribalfusion[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@www.burstnet[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@serving-sys[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@ads.allaccess.com[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@bluestreak[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@networldmedia[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@sympatico.112.2o7[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@mediaplex[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@adcentriconline[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@ads.addynamix[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@ad.yieldmanager[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@metroleap.rotator.hadj7.adjuggler[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@ads.monster[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@ads.pointroll[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@adx.bidsystem[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@adultswim[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@analytics.rogersmedia[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@advertising[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@2o7[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@fastclick[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@realmedia[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@imrworldwide[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@tacoda[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@content.yieldmanager[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@ads.creafi[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@content.yieldmanager[3].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@at.atwola[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@clicksor[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@www.googleadservices[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@pro-market[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@doubleclick[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@247realmedia[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@nextag[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@revsci[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@kontera[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@workopolis.122.2o7[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@overture[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@lfstmedia[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@yieldmanager[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@vitamine.networldmedia[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@statcounter[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@vitamine.networldmedia[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@tracking1.aleadpay[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@collective-media[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@media6degrees[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@pointroll[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@richmedia.yahoo[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@media.monster[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@burstnet[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@videoegg.adbureau[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@invitemedia[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@bellcan.adbureau[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@atdmt[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@ads.nba[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@googleads.g.doubleclick[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@adbrite[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@ads.bootcampmedia[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@rogersmedia[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@bs.serving-sys[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@apmebf[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@myroitracking[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@adserver.adtechus[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@zedo[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@ads.networldmedia[3].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@ads.networldmedia[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@casalemedia[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@monstercom.112.2o7[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@greatwolfresorts.112.2o7[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@msnportal.112.2o7[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@adtech[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@serving.adsrevenue.clicksor[2].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@specificclick[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@questionmarket[1].txt
C:\Users\Bhing or J.A\AppData\Roaming\Microsoft\Windows\Cookies\Low\bhing_or_j.a@dmtracker[1].txt
.clickaider.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adserver.adtechus.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.astralmedia.112.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.112.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.112.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.enhance.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.timeinc.122.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
p170t1s1258397.kronos.bravenetmedia.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.247realmedia.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
us.sitestat.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
us.sitestat.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.content.yieldmanager.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.canglobaltv.112.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.enhance.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
counter.surfcounters.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pointroll.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pointroll.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.imrworldwide.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.imrworldwide.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.foxfilmedentertainment.122.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.myroitracking.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.usdm.122.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.msnportal.112.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
clicks.smartbizsearch.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.canoe.112.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.telus.122.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tripod.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tripod.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.elitefitness.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.elitefitness.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.elitefitness.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.elitefitness.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.elitefitness.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
flagcounter.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.hotelscom.122.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.greatwolfresorts.112.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.cx.sxtracking.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.lynxtrack.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.hulu.112.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertise.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
809_149160.clicksvalidate.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.findstuff.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.sympatico.112.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.xiti.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.dmtracker.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adcentriconline.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
metroleap.rotator.hadj7.adjuggler.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
metroleap.rotator.hadj7.adjuggler.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
metroleap.rotator.hadj7.adjuggler.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.richmedia.yahoo.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
hollywoodserials.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adserver.adtechus.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www3.smartadserver.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.warnerbros.112.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.bs.serving-sys.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.doubleclick.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
rts.pgmediaserve.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
rts.pgmediaserve.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
rts.pgmediaserve.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.apmebf.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
hollywoodserials.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
hollywoodserials.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.statcounter.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clickbank.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.content.yieldmanager.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.www.burstnet.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstnet.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstnet.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.burstnet.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.burstbeacon.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstbeacon.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
uk.sitestat.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
uk.sitestat.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
dc.tremormedia.com [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\Darlin\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
objects.tremormedia.com [ C:\Users\Darlin\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DV52KK6J ]
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\darlin@atdmt[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\darlin@d.reduxmedia[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\darlin@bs.serving-sys[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\darlin@serving-sys[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\darlin@ad.yieldmanager[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@adtech[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@richmedia.yahoo[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@adecn[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@247realmedia[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@adlegend[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@gotacha.rotator.hadj7.adjuggler[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@clicksor[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@advertise[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@intermundomedia[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@atwola[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@content.yieldmanager[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@content.yieldmanager[3].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@eyewonder[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@myroitracking[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@bs.serving-sys[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@www.icityfind[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@ad.yieldmanager[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@www.burstbeacon[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@adserver.duetads[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@specificclick[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@tribalfusion[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@at.atwola[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@tacoda[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@clicks.search312[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@revsci[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@serving-sys[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@questionmarket[1].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@adply.plymedia[2].txt
C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies\Low\darlin@adserver.adtechus[1].txt
.advertise.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\cookies.sqlite ]
.media6degrees.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.media6degrees.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.media6degrees.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.statcounter.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.doubleclick.net [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.content.yieldmanager.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.chitika.net [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.content.yieldmanager.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.revsci.net [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.revsci.net [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.revsci.net [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.atdmt.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.atdmt.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.atdmt.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.bellcan.adbureau.net [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.atdmt.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.casalemedia.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.casalemedia.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.casalemedia.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.casalemedia.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.casalemedia.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.casalemedia.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.advertising.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.advertising.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.advertising.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.advertising.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.invitemedia.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.kontera.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.kontera.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.kontera.com [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.revsci.net [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
.revsci.net [ C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\cookies.sqlite ]
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\guest@atdmt[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@tribalfusion[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@ad.yieldmanager[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@media6degrees[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@tacoda[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@adbrite[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@doubleclick[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@interclick[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@content.yieldmanager[3].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@content.yieldmanager[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@a1.interclick[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@burstnet[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@apmebf[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@dc.tremormedia[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@atdmt[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@imrworldwide[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@ads.networldmedia[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@trafficmp[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@ads.networldmedia[3].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@at.atwola[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@smartadserver[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@oasn04.247realmedia[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@adserver.adtechus[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@specificclick[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@invitemedia[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@www.burstnet[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@kontera[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@zedo[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@advertising[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@247realmedia[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@realmedia[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@vitamine.networldmedia[3].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@vitamine.networldmedia[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@fastclick[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@networldmedia[1].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@casalemedia[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@2o7[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@ads.admaxasia[2].txt
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies\Low\guest@mediaplex[1].txt

Browser Hijacker.Deskbar
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid32
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib#Version

Adware.Flash Tracking Cookie
C:\Users\Darlin\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\DV52KK6J\OBJECTS.TREMORMEDIA.COM

Rogue.AntivirusSoft
HKU\Darlin-PC_Bhing or J.A\Software\avsoft

Malware.Trace
HKU\Darlin-PC_Bhing or J.A\SOFTWARE\AVSUITE

Adware.Generic
C:\PROGRAMDATA\{C1DF1BDA-E7BE-4DC5-A5D9-C3D93F09FA65}\OFFLINE\15D3A7BB\3E688669\STBAPPHELPER.EXE
C:\PROGRAMDATA\{C1DF1BDA-E7BE-4DC5-A5D9-C3D93F09FA65}\OFFLINE\CE8732D\3E688669\PRODUCTINFO.DLL
C:\PROGRAMDATA\{C1DF1BDA-E7BE-4DC5-A5D9-C3D93F09FA65}\OFFLINE\MFILEBAGIDE.DLL\BAG\PRODUCTINFO.DLL

Adware.DoubleD
C:\PROGRAMDATA\{C1DF1BDA-E7BE-4DC5-A5D9-C3D93F09FA65}\OFFLINE\B75FA91E\3E688669\STBSVC.EXE

Application.Agent/Gen-TempZ
C:\PROGRAMDATA\{C1DF1BDA-E7BE-4DC5-A5D9-C3D93F09FA65}\OFFLINE\MFILEBAGIDE.DLL\BAG\STBREWLM.EXE
C:\PROGRAMDATA\{C1DF1BDA-E7BE-4DC5-A5D9-C3D93F09FA65}\OFFLINE\MFILEBAGIDE.DLL\BAG\STBTERM.EXE

_________________________________________________________________

Here is the HijackThis log.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:18:18 PM, on 22/07/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RogersServicepointAgent.exe] "C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" /AUTORUN
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Google Update] "C:\Users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [pacqwen] rundll32 "C:\Users\Darlin\AppData\Roaming\nb-NOM.dll",UDPNTWWWQJ
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Run YoukuDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe (file missing)
O9 - Extra 'Tools' menuitem: Youku Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: intu-qt2009 - {03947252-2355-4E9B-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1ca2cdcaf95cfe9) (gupdate1ca2cdcaf95cfe9) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 11316 bytes

DaReelDeel
2010-07-22, 23:08
Hello,

Here is the ESET log.


ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=f22d2c29dcd6f949b4fa432af22038be
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-07-22 09:00:47
# local_time=2010-07-22 05:00:47 (-0500, Eastern Daylight Time)
# country="Canada"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=5892 16776573 100 100 0 116432032 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=217284
# found=7
# cleaned=7
# scan_time=7943
C:\ProgramData\Spybot - Search & Destroy\Recovery\SweetIM23.zip Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\ProgramData\{C1DF1BDA-E7BE-4DC5-A5D9-C3D93F09FA65}\OFFLINE\29A73ACD\3E688669\stb0.dll Win32/Adware.DoubleD.AB application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\ProgramData\{C1DF1BDA-E7BE-4DC5-A5D9-C3D93F09FA65}\OFFLINE\BED3DEFB\3E688669\stbasst.exe a variant of Win32/Adware.DoubleD.AF application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\ProgramData\{C1DF1BDA-E7BE-4DC5-A5D9-C3D93F09FA65}\OFFLINE\EB91CE86\3E688669\stbdl.exe Win32/Adware.DoubleD.AB application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\ProgramData\{C1DF1BDA-E7BE-4DC5-A5D9-C3D93F09FA65}\OFFLINE\mFileBagIDE.dll\bag\FFToolbar.xpi probably a variant of Win32/Adware.DoubleD.AF application (deleted - quarantined) 00000000000000000000000000000000 C
C:\ProgramData\{C1DF1BDA-E7BE-4DC5-A5D9-C3D93F09FA65}\OFFLINE\mFileBagIDE.dll\bag\stbpx.exe a variant of Win32/Adware.DoubleD.AF application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wwwxbv32.exe.vir a variant of Win32/Kryptik.FLY trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

ken545
2010-07-22, 23:20
Looking good, there is one entry with a related file that I cant find out anything about, lets have it checked

You need to enable windows to show all files and folders, instructions Here (http://www.bleepingcomputer.com/tutorials/tutorial62.html)

Go to VirusTotal (http://www.virustotal.com/) and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see. If the site says this file has been checked before, have them check it again

C:\Users\Darlin\AppData\Roaming\nb-NOM.dll <--This file

If the site is busy you can try this one

http://virusscan.jotti.org/en

DaReelDeel
2010-07-23, 01:56
Hello,

When I tried to choose the .dll file, it says I don't have permission to open the file.

ken545
2010-07-23, 02:31
Try this


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1 (http://jpshortstuff.247fixes.com/SystemLook.exe)
Download Mirror #2 (http://images.malwareremoval.com/jpshortstuff/SystemLook.exe)

Double-click SystemLook.exe to run it.
Copy the content of the following codebox into the main textfield:


:file
C:\Users\Darlin\AppData\Roaming\nb-NOM.dll


Click the Look button to start the scan.
When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

DaReelDeel
2010-07-23, 18:54
I scanned the file, here is the log.

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 12:52 on 23/07/2010 by Darlin (Administrator - Elevation successful)

========== file ==========

C:\Users\Darlin\AppData\Roaming\nb-NOM.dll - Unable to find/read file.

-=End Of File=-

ken545
2010-07-23, 19:46
I am inclined to believe its ok. How are things running now ?

DaReelDeel
2010-07-24, 18:38
I still get the error message when I click a link in google. I have to click the link several times to open it. I'm also having a problem with viewing pictures. I can't see images on Facebook, just a white square with shapes on it.

ken545
2010-07-24, 19:21
What error message are you getting ?

DaReelDeel
2010-07-27, 04:08
Sorry I haven't replied for a while, I had family over and we went out of town. I have similar messages to this. Oops! Google Chrome could not find www.facebook.com.

ken545
2010-07-27, 10:14
Does Internet Explorer and Firefox work , is it just Chrome your having issues with ?

DaReelDeel
2010-07-27, 19:27
I have problems with IE and Firefox too. In IE, there are popups and google redirects me to a we ad when I click on a link. In Firefox, when I click on a link, it starts loading the page, but it stays blank. And I also get redirected to searchpro.com.

ken545
2010-07-27, 19:54
If your getting Pop ups and redirects there may be a rootkit responsible for that and we won't know for sure unless we see a GMER report

Make sure you disable all your antivirus and anti spyware programs, you can usually do that by right clicking on it in the system tray and disable them. There most likely responsible for GMER not running

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double click GMER.exe.
http://img.photobucket.com/albums/v666/sUBs/gmer_zip.gif
If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on NO, then use the following settings for a more complete scan..
In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED ...
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
http://www.geekstogo.com/misc/guide_icons/GMER_thumb.jpg (http://www.geekstogo.com/misc/guide_icons/GMER_instructions.jpg)
Click the image to enlarge it

Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries
Please copy and paste the report into your Post.



Lets check this file also please

You need to enable windows to show all files and folders, instructions Here (http://www.bleepingcomputer.com/tutorials/tutorial62.html)

Go to VirusTotal (http://www.virustotal.com/) and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see. If it says this file has been scanned before, have them scan it again.

C:\Windows\Eropea.exe<--This file

If the site is busy you can try this one

http://virusscan.jotti.org/en

DaReelDeel
2010-07-29, 03:18
Hi. I finally was able to run GMER.exe by downloading it from a different website. Here is the log.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-28 17:49:53
Windows 6.0.6002 Service Pack 2
Running: 1etxuh1g.exe; Driver: C:\Users\Darlin\AppData\Local\Temp\pxryrpod.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b91a0f
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001e37b91a0f (not active ControlSet)
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0x2E 0xE8 0xE1 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x25 0xDA 0xEC 0x7E ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xE9 0x02 0x6C 0xFA ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0x50 0x93 0xE5 0xAB ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x01 0x3A 0x48 0xFC ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xB2 0x46 0x9A 0xE2 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xF8 0x31 0x0F 0xA9 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...

---- Files - GMER 1.0.15 ----

File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.ci 4096 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.dir 4096 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.wid 65536 bytes

---- EOF - GMER 1.0.15 ----

I was not able to find the C:\Windows\Eropea.exe file even after enabling windows to show all files and folders.

ken545
2010-07-29, 13:10
GMER is not showing me much, it looks like you didn't run it according to the instructions I posted


http://img.photobucket.com/albums/v666/sUBs/gmer_zip.gif
Download GMER Rootkit Scanner from here (http://www.gmer.net/gmer.zip) or here (http://www.majorgeeks.com/download.php?det=5198).

Extract the contents of the zipped file to desktop.
Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.

http://i266.photobucket.com/albums/ii277/sUBs_/th_Gmer_initScan.gif (http://i266.photobucket.com/albums/ii277/sUBs_/Gmer_initScan.gif)
Click the image to enlarge it

In the right panel, you will see several boxes that have been checked. Uncheck the following ...
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Leave the Sections tab checked
Show All (don't miss this one)

Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.

Save it where you can easily find it, such as your desktop, and post it in your next reply.


**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries





Lets run a new OTL scan and see if your system has changed


Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.
Double click on the icon to run it. Make sure all other windows are closed to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Under the Standard Registry box change it to All.
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.

DaReelDeel
2010-07-31, 00:56
Hi, I ran GMER again and an OTL scan after as you requested. OTL didn't produce an extra.txt log for me, but I have the OTL.txt log. First, here is the gmer.txt log.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-30 18:39:08
Windows 6.0.6002 Service Pack 2
Running: 1etxuh1g.exe; Driver: C:\Users\Darlin\AppData\Local\Temp\pxryrpod.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b91a0f
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001e37b91a0f (not active ControlSet)
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0x2E 0xE8 0xE1 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x25 0xDA 0xEC 0x7E ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xE9 0x02 0x6C 0xFA ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0x50 0x93 0xE5 0xAB ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x01 0x3A 0x48 0xFC ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xB2 0x46 0x9A 0xE2 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xF8 0x31 0x0F 0xA9 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...

---- EOF - GMER 1.0.15 ----

DaReelDeel
2010-07-31, 00:57
Hi, here is the OTL.txt log.



OTL logfile created on: 30/07/2010 6:47:09 PM - Run 4
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Darlin\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 66.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.54 Gb Total Space | 129.72 Gb Free Space | 58.03% Space Free | Partition Type: NTFS
Drive D: | 9.35 Gb Total Space | 1.70 Gb Free Space | 18.16% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DARLIN-PC
Current User Name: Darlin
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Darlin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
PRC - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\SMINST\BLService.exe ()
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Darlin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (WPFFontCache_v0400) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\WINDOWS\System32\FntCache.dll (Microsoft Corporation)
SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (Recovery Service for Windows) -- C:\WINDOWS\SMINST\BLService.exe ()
SRV - (Automatic LiveUpdate Scheduler) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (RPSKT) Security Services Driver (x86) -- C:\Windows\System32\DRIVERS\rp_skt32.sys File not found
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (catchme) -- C:\Users\Darlin\AppData\Local\Temp\catchme.sys File not found
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (BCM43XX) -- C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (BCM43XV) -- C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (nvlddmkm) -- C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (RTSTOR) -- C:\WINDOWS\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (CnxtHdAudService) -- C:\WINDOWS\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (NVHDA) -- C:\WINDOWS\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (nvsmu) -- C:\WINDOWS\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (SynTP) -- C:\WINDOWS\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (NVENETFD) -- C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\WINDOWS\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HSFHWAZL) -- C:\WINDOWS\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (HSF_DPV) -- C:\WINDOWS\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) -- C:\WINDOWS\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) -- C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqRemHid) -- C:\WINDOWS\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (PID_0928) Labtec WebCam(PID_0928) -- C:\WINDOWS\System32\drivers\LV561AV.SYS (Labtec Inc.)
DRV - (LVUSBSta) -- C:\WINDOWS\System32\drivers\LVUSBSta.sys (Labtec Inc.)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\System32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 14:06:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009/09/11 16:51:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/09 19:03:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/09 19:03:01 | 000,000,000 | ---D | M]

[2010/03/17 16:27:38 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Extensions
[2010/03/17 16:27:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/21 19:44:39 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Extensions\mozswing@mozswing.org
[2010/07/28 12:11:51 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions
[2010/07/28 12:11:31 | 000,000,000 | ---D | M] (TwitterBar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}
[2010/04/27 17:10:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2010/03/18 20:51:56 | 000,000,000 | ---D | M] (AniWeather) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}
[2010/05/25 20:18:05 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/03/28 14:09:55 | 000,000,000 | ---D | M] (ScrapBook) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2010/03/18 21:34:21 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2010/03/18 21:01:38 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2010/06/08 11:09:24 | 000,000,000 | ---D | M] (ReminderFox) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
[2010/07/28 12:11:30 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/06/30 22:17:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/07/28 12:11:31 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/03/18 21:34:21 | 000,000,000 | ---D | M] (Pixlr Grabber) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{d47a9f51-8281-43fa-f450-f28ef8735e9a}
[2010/06/02 19:11:22 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/04/12 10:07:01 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/05/15 21:16:08 | 000,000,000 | ---D | M] (DVDVideoSoft Toolbar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] (FoxTab) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2010/07/28 12:11:45 | 000,000,000 | ---D | M] (SearchPreview) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
[2010/07/28 12:11:31 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\FirefoxAddon@similarWeb.com
[2010/03/18 21:39:06 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\googletube@googletube.com
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\illimitux@illimitux.net
[2010/04/12 10:07:29 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\isreaditlater@ideashower.com
[2010/04/14 10:14:52 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\personas@christopher.beard
[2010/06/29 16:36:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com
[2010/06/29 16:36:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com-trash
[2010/03/18 21:01:33 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\SkipScreen@SkipScreen
[2010/06/16 15:38:34 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\smarterwiki@wikiatic.com
[2010/07/28 12:11:30 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\unplug@compunach
[2010/06/16 15:38:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\videosurf_enhanced@videosurf.com
[2010/04/21 10:16:53 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\YoutubeDownloader@PeterOlayev.com
[2010/03/05 15:29:29 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] (TwitterBar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2010/03/05 15:04:55 | 000,000,000 | ---D | M] (TV-Fox) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{2f17f610-5e97-4fed-828f-9940b7b577a4}
[2010/03/04 17:52:58 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{99210d54-6321-41e8-bd1b-2b4c55874efb}
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] (QuickWiki) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{EE223D7A-F30F-11DD-8F0A-D2AD55D89593}
[2010/03/04 17:52:58 | 000,000,000 | ---D | M] (FoxTab) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\en-CA@dictionaries.addons.mozilla.org
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\FirefoxAddon@myfacebook.com
[2010/03/04 17:53:01 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\FirefoxAddon@similarWeb.com
[2010/03/04 18:20:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\firefox-extension@shareaholic.com
[2010/03/04 18:20:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\googletube@googletube.com
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\illimitux@illimitux.net
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\isreaditlater@ideashower.com
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\personas@christopher.beard
[2010/03/04 17:53:00 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\piclens@cooliris.com
[2010/03/04 17:53:01 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\quickdrag@mozilla.ktechcomputing.com
[2010/03/04 18:20:45 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\firefox-extension@shareaholic.com\chrome
[2010/03/04 18:32:31 | 000,007,972 | ---- | M] () -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\searchplugins\oneriot-social-web-search.xml
[2010/03/04 17:43:36 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/07/09 19:03:01 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/07/09 19:02:40 | 000,023,512 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010/07/09 19:02:40 | 000,138,712 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2010/02/21 06:22:32 | 000,712,704 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2010/07/09 19:02:52 | 000,064,984 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2010/04/19 10:49:30 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2010/04/19 10:49:30 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2010/04/19 10:49:31 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2010/04/19 10:49:31 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2010/04/19 10:49:31 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2010/04/19 10:49:32 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2010/04/19 10:49:32 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2010/07/09 19:02:54 | 000,001,394 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
[2010/07/09 19:02:54 | 000,002,193 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2010/07/09 19:02:54 | 000,001,534 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2010/07/09 19:02:54 | 000,002,344 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
[2010/07/09 19:02:54 | 000,002,371 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2010/07/09 19:02:54 | 000,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
[2010/07/09 19:02:54 | 000,001,096 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml

O1 HOSTS File: ([2010/07/17 21:05:08 | 000,000,027 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QPService] C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RogersServicepointAgent.exe] C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ehTray.exe] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Google Update] C:\Users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [pacqwen] C:\Users\Darlin\AppData\Roaming\nb-NOM.DLL ()
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Run YoukuDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe File not found
O9 - Extra 'Tools' menuitem : Youku Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\System32\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\System32\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\System32\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\WINDOWS\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\Windows\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\Windows\System32\sysdm.cpl (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\System32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Darlin\Pictures\wild_shutterstock_8532871.jpg
O24 - Desktop BackupWallPaper: C:\Users\Darlin\Pictures\wild_shutterstock_8532871.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\System32\credssp.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\System32\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\System32\tspkg.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/11 09:46:21 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/07/30 18:46:03 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\Darlin\Desktop\OTL.exe
[2010/07/22 14:17:32 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/07/22 13:01:49 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2010/07/21 14:10:29 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010/07/21 14:09:14 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010/07/21 13:46:04 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010/07/21 13:45:36 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/07/19 14:09:04 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/07/18 15:12:02 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Apple
[2010/07/18 14:54:21 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Adobe
[2010/07/18 13:28:51 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Apple Computer
[2010/07/18 12:48:42 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Roaming\Malwarebytes
[2010/07/18 12:48:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/07/18 12:48:30 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/17 20:50:15 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/07/17 20:50:15 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/07/17 20:50:15 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/07/17 20:50:08 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/07/17 20:49:37 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/07/12 12:25:33 | 000,000,000 | ---D | C] -- C:\Program Files\Safer Networking
[2010/07/12 09:25:13 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2010/07/11 19:54:59 | 000,000,000 | ---D | C] -- C:\Program Files\TweetDeck
[2010/07/11 17:16:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2010/07/11 17:16:36 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010/07/11 14:14:26 | 000,000,000 | -HSD | C] -- C:\ProgramData\SMACCEEAV
[2010/06/30 23:07:30 | 000,000,000 | ---D | C] -- C:\Users\Darlin\dwhelper
[4 C:\Users\Darlin\Documents\*.tmp files -> C:\Users\Darlin\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/07/30 18:49:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job
[2010/07/30 18:48:03 | 008,126,464 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat
[2010/07/30 18:46:03 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Darlin\Desktop\OTL.exe
[2010/07/30 18:44:21 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010/07/30 18:41:04 | 000,000,246 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2010/07/30 18:40:58 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2010/07/30 18:40:58 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/07/30 18:40:54 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/30 18:40:32 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/30 18:40:32 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/30 18:40:30 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/07/30 18:40:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/07/30 18:40:23 | 2951,102,464 | -HS- | M] () -- C:\hiberfil.sys
[2010/07/30 18:39:27 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/07/30 18:39:24 | 000,524,288 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TMContainer00000000000000000001.regtrans-ms
[2010/07/30 18:39:24 | 000,065,536 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TM.blf
[2010/07/30 18:39:16 | 002,508,579 | -H-- | M] () -- C:\Users\Darlin\AppData\Local\IconCache.db
[2010/07/30 17:56:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/30 17:49:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job
[2010/07/29 19:01:29 | 002,380,564 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/07/29 19:01:29 | 000,714,466 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/07/29 19:01:29 | 000,062,236 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2010/07/29 19:01:29 | 000,059,822 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/07/29 19:01:29 | 000,019,286 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2010/07/29 18:44:36 | 000,013,312 | ---- | M] () -- C:\Users\Darlin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/29 12:50:32 | 000,001,356 | ---- | M] () -- C:\Users\Darlin\AppData\Local\d3d9caps.dat
[2010/07/29 12:28:07 | 257,366,390 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/07/28 18:38:07 | 002,512,767 | ---- | M] () -- C:\Users\Darlin\Documents\Canadian Achievements.pptx
[2010/07/28 11:44:42 | 000,002,255 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/07/26 21:59:30 | 000,002,047 | ---- | M] () -- C:\Users\Darlin\Desktop\Google Chrome.lnk
[2010/07/26 21:59:30 | 000,002,009 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/07/22 19:06:22 | 000,030,720 | ---- | M] () -- C:\Users\Darlin\Documents\Water Consumption.doc
[2010/07/22 19:06:13 | 000,014,769 | ---- | M] () -- C:\Users\Darlin\Documents\Final Unit Essay.docx
[2010/07/22 14:17:32 | 000,001,874 | ---- | M] () -- C:\Users\Darlin\Desktop\HijackThis.lnk
[2010/07/21 17:04:41 | 000,020,148 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 6 Activity 3.docx
[2010/07/21 14:06:38 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/07/20 22:25:46 | 000,019,373 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 5 Activity 5.docx
[2010/07/20 19:57:21 | 000,023,377 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 5 Activity 3.docx
[2010/07/20 14:39:39 | 000,038,252 | ---- | M] () -- C:\Users\Darlin\Documents\Charter.rtf
[2010/07/17 21:05:08 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010/07/13 16:47:10 | 000,000,104 | ---- | M] () -- C:\Users\Darlin\Desktop\Recycle Bin - Shortcut.lnk
[2010/07/12 09:25:29 | 000,000,008 | ---- | M] () -- C:\Users\Darlin\AppData\Roaming\vdnxlf.dat
[2010/07/11 19:55:01 | 000,000,762 | ---- | M] () -- C:\Users\Public\Desktop\TweetDeck.lnk
[2010/07/11 19:19:13 | 000,311,040 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/07/11 17:46:31 | 000,000,088 | ---- | M] () -- C:\Windows\wininit.ini
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183614.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183519.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183518.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183517.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183516.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180651.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180650.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180647.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180645.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180643.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180642.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180641.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180616.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180615.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180614.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180613.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180612.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174936.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174923.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174920.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174919.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174917.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174843.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174842.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174840.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174646.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174644.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174627.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173902.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173617.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173616.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173615.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173608.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173607.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173606.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173605.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173604.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173603.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173602.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173601.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173557.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173518.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-172944.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-172848.backup
[2010/07/09 23:20:49 | 000,088,576 | RHS- | M] () -- C:\Users\Darlin\AppData\Roaming\nb-NOM.dll
[4 C:\Users\Darlin\Documents\*.tmp files -> C:\Users\Darlin\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/27 23:08:14 | 002,512,767 | ---- | C] () -- C:\Users\Darlin\Documents\Canadian Achievements.pptx
[2010/07/22 19:06:13 | 000,014,769 | ---- | C] () -- C:\Users\Darlin\Documents\Final Unit Essay.docx
[2010/07/22 16:16:18 | 000,030,720 | ---- | C] () -- C:\Users\Darlin\Documents\Water Consumption.doc
[2010/07/22 14:17:32 | 000,001,874 | ---- | C] () -- C:\Users\Darlin\Desktop\HijackThis.lnk
[2010/07/21 17:04:41 | 000,020,148 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 6 Activity 3.docx
[2010/07/21 14:45:52 | 2951,102,464 | -HS- | C] () -- C:\hiberfil.sys
[2010/07/20 22:25:44 | 000,019,373 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 5 Activity 5.docx
[2010/07/20 19:56:30 | 000,023,377 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 5 Activity 3.docx
[2010/07/20 14:39:39 | 000,038,252 | ---- | C] () -- C:\Users\Darlin\Documents\Charter.rtf
[2010/07/17 20:50:15 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010/07/17 20:50:15 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/07/17 20:50:15 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/07/17 20:50:15 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/07/17 20:50:15 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/07/13 16:47:10 | 000,000,104 | ---- | C] () -- C:\Users\Darlin\Desktop\Recycle Bin - Shortcut.lnk
[2010/07/12 09:25:28 | 000,000,008 | ---- | C] () -- C:\Users\Darlin\AppData\Roaming\vdnxlf.dat
[2010/07/11 23:08:05 | 257,366,390 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010/07/11 21:12:54 | 000,001,972 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/07/11 21:12:54 | 000,001,111 | ---- | C] () -- C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2010/07/11 17:46:31 | 000,000,088 | ---- | C] () -- C:\Windows\wininit.ini
[2010/07/09 23:20:48 | 000,088,576 | RHS- | C] () -- C:\Users\Darlin\AppData\Roaming\nb-NOM.dll
[2009/09/17 16:23:53 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2008/01/20 22:24:38 | 000,033,794 | ---- | C] () -- C:\Windows\System32\unelwin.dll
[2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/03/09 05:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2005/01/19 09:30:54 | 000,009,255 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini

========== LOP Check ==========

[2010/06/02 18:46:13 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\BitComet
[2009/10/09 21:17:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\iWin
[2010/07/17 20:48:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\LimeWire
[2010/06/08 13:18:41 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Opera
[2009/10/10 23:06:18 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\PlayFirst
[2010/03/10 18:32:47 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Rogers Online Protection
[2009/10/17 15:25:15 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Template
[2009/08/21 21:22:19 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2009/11/30 17:12:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2009/09/05 19:38:05 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\WildTangent
[2010/07/30 18:39:30 | 000,032,562 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2009/10/02 23:23:37 | 000,000,036 | ---- | M] ()(C:\Windows\System32\?????????????????????????????????????????????????) -- C:\Windows\System32\㩃停潲牧浡䘠汩獥剜杯牥⁳湏楬敮倠潲整瑣潩屮潒敧獲传汮湩⁥牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩⹷潣普杩
[2009/10/02 23:23:37 | 000,000,036 | ---- | C] ()(C:\Windows\System32\?????????????????????????????????????????????????) -- C:\Windows\System32\㩃停潲牧浡䘠汩獥剜杯牥⁳湏楬敮倠潲整瑣潩屮潒敧獲传汮湩⁥牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩⹷潣普杩
< End of report >

ken545
2010-07-31, 13:52
Hi,

Do this first...Important

Disable the TeaTimer, leave it disabled, do not turn it back on until we're done or it will prevent fixes from taking

Run Spybot-S&D in Advanced Mode.
If it is not already set to do this Go to the Mode menu select "Advanced Mode"
On the left hand side, Click on Tools
Then click on the Resident Icon in the List
Uncheck "Resident TeaTimer" and OK any prompts.
Restart your computer.<--You need to do this for it to take effect

Please do not proceed until the TeaTimer is disabled





Please download OTM by OldTimer (http://oldtimer.geekstogo.com/OTM.exe) and save it to your desktop.
Double click the http://billy-oneal.com/Canned%20Speeches/speechimages/OTM/OTMdesktopicon.png icon on your desktop.
Paste the following code under the http://billy-oneal.com/Canned%20Speeches/speechimages/OTM/pasteline.png area.
Do not include the word "Code".



:Processes
explorer.exe

:Services

:Reg

:Files
C:\Windows\Eropea.exe



:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Push the large http://billy-oneal.com/Canned%20Speeches/speechimages/OTM/btnmoveit.png button.
OTM may ask to reboot the machine. Please do so if asked.
Copy/Paste the contents under the http://billy-oneal.com/Canned%20Speeches/speechimages/OTM/results.png line here in your next reply.
If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.







We can restore this one if it causes problems, I can find absolutely no info on it

Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O4 - HKCU\..\Run: [pacqwen] rundll32 "C:\Users\Darlin\AppData\Roaming\nb-NOM.dll",UDPNTWWWQJ




Post the log from OTM, a new HJT log a new DDS log please

DaReelDeel
2010-07-31, 21:53
Hi, I ran OTM as requested. Here is the log.

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
File/Folder C:\Windows\Eropea.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Bhing or J.A
->Temp folder emptied: 31832 bytes
->Temporary Internet Files folder emptied: 212114 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Darlin
->Temp folder emptied: 2228068 bytes
->Temporary Internet Files folder emptied: 163846847 bytes
->Java cache emptied: 10680337 bytes
->FireFox cache emptied: 38259555 bytes
->Google Chrome cache emptied: 394090265 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 34822 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: TEMP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: TEMP.Darlin-PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: TEMP.Darlin-PC.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 693412 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 582.00 mb


OTM by OldTimer - Version 3.1.15.0 log created on 07312010_152455

Files moved on Reboot...
C:\Users\Darlin\AppData\Local\Temp\ehmsas.txt moved successfully.
C:\Users\Darlin\AppData\Local\Temp\VGXEFE9.tmp moved successfully.

Registry entries deleted on Reboot...


_________________________________________________________________

I ran a system scan on HijackThis and fixed the file. Here is a new HijackThis log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:40:29 PM, on 31/07/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgentComHandler.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RogersServicepointAgent.exe] "C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" /AUTORUN
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Google Update] "C:\Users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Run YoukuDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe (file missing)
O9 - Extra 'Tools' menuitem: Youku Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: intu-qt2009 - {03947252-2355-4E9B-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1ca2cdcaf95cfe9) (gupdate1ca2cdcaf95cfe9) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9676 bytes

DaReelDeel
2010-07-31, 21:54
Here is the new DDS log.


DDS (Ver_10-03-17.01) - NTFSx86
Run by Darlin at 15:42:14.18 on 31/07/2010
Internet Explorer: 7.0.6002.18005
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2814.1891 [GMT -4:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Darlin\Desktop\dds.scr
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
uInternet Settings,ProxyOverride = <local>;*.local
uInternet Settings,ProxyServer = http=127.0.0.1:5555
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Google Update] "c:\users\darlin\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\2.0"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [RogersServicepointAgent.exe] "c:\program files\rogers online protection\rogers servicepoint agent\RogersServicepointAgent.exe" /AUTORUN
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
StartupFolder: c:\users\darlin\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {612F6E5C-B314-4bab-93D1-D266AAFBE700} - c:\program files\xmlbar\youku downloader\YoukuDownloader(xmlbar).exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: intu-qt2009 - {03947252-2355-4e9b-B446-8CCC75C43370} - c:\program files\quicktax 2009\ic2009pp.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"

================= FIREFOX ===================

FF - ProfilePath - c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{6ac85730-7d0f-4de0-b3fa-21142dd85326}\platform\winnt\components\ColorZilla.dll
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\rogers online protection\rogers servicepoint agent\nprpspa.dll
FF - plugin: c:\users\darlin\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\sminst\BLService.exe [2008-8-11 361808]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2008-8-11 193840]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-5-9 43040]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate1ca2cdcaf95cfe9;Google Update Service (gupdate1ca2cdcaf95cfe9);c:\program files\google\update\GoogleUpdate.exe [2009-9-3 133104]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

=============== Created Last 30 ================

2010-07-31 19:24:56 0 d-----w- C:\_OTM
2010-07-22 18:17:32 0 d-----w- c:\program files\Trend Micro
2010-07-22 17:01:49 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-07-21 18:09:14 0 d-sh--w- C:\$RECYCLE.BIN
2010-07-21 17:46:04 0 d-----w- C:\ComboFix
2010-07-19 18:09:04 0 d-----w- C:\_OTL
2010-07-18 16:48:42 0 d-----w- c:\users\darlin\appdata\roaming\Malwarebytes
2010-07-18 16:48:31 0 d-----w- c:\programdata\Malwarebytes
2010-07-18 16:48:30 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-18 00:50:15 98816 ----a-w- c:\windows\sed.exe
2010-07-18 00:50:15 77312 ----a-w- c:\windows\MBR.exe
2010-07-18 00:50:15 256512 ----a-w- c:\windows\PEV.exe
2010-07-18 00:50:15 161792 ----a-w- c:\windows\SWREG.exe
2010-07-12 16:25:33 0 d-----w- c:\program files\Safer Networking
2010-07-12 13:25:28 8 ----a-w- c:\users\darlin\appdata\roaming\vdnxlf.dat
2010-07-12 03:08:05 257366390 ----a-w- c:\windows\MEMORY.DMP
2010-07-11 23:54:59 0 d-----w- c:\program files\TweetDeck
2010-07-11 21:46:31 88 ----a-w- c:\windows\wininit.ini
2010-07-11 21:16:36 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-07-11 21:16:36 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-07-11 18:14:26 0 d-sh--w- c:\programdata\SMACCEEAV
2010-07-10 03:20:48 88576 --sha-r- c:\users\darlin\appdata\roaming\nb-NOM.dll

==================== Find3M ====================

2010-07-31 19:29:27 48670 ----a-w- c:\programdata\nvModes.dat
2010-07-29 23:01:29 62236 ----a-w- c:\windows\system32\perfh00C.dat
2010-07-29 23:01:29 19286 ----a-w- c:\windows\system32\perfc00C.dat
2010-06-20 19:25:57 86016 ----a-w- c:\windows\inf\infstor.dat
2010-06-20 19:25:57 51200 ----a-w- c:\windows\inf\infpub.dat
2010-06-20 19:25:56 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-05-26 17:06:41 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47:41 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-21 18:14:28 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 20:35:16 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-04 19:15:20 834048 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 18:37:45 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-04-30 02:15:22 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-08-11 10:55:35 37390 ----a-w- c:\windows\inf\perflib\040c\perfd.dat
2008-08-11 10:55:35 37390 ----a-w- c:\windows\inf\perflib\040c\perfc.dat
2008-08-11 10:55:35 340236 ----a-w- c:\windows\inf\perflib\040c\perfi.dat
2008-08-11 10:55:35 340236 ----a-w- c:\windows\inf\perflib\040c\perfh.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2010-03-10 23:05:08 59232800 --sha-w- c:\windows\system32\drivers\fidbox.dat
2008-08-11 10:58:25 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 15:44:02.49 ===============

Here is the attach.txt log.

DDS (Ver_10-03-17.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 14/08/2009 2:06:55 PM
System Uptime: 31/07/2010 3:26:46 PM (0 hours ago)

Motherboard: Wistron | | 360A
Processor: AMD Athlon Dual-Core QL-60 | Socket A | 1900/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 224 GiB total, 130.373 GiB free.
D: is FIXED (NTFS) - 9 GiB total, 1.698 GiB free.
E: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================


==== Installed Programs ======================

32 Bit HP CIO Components Installer
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.2
Adobe Shockwave Player
Adobe Shockwave Player 11.5
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Bonjour
Broadcom 802.11 Wireless LAN Adapter
BufferChm
Cards_Calendar_OrderGift_DoMorePlugout
Compatibility Pack for the 2007 Office system
Conexant HD Audio
CustomerResearchQFolder
CyberLink DVD Suite
CyberLink YouCam
D2500
D2500_Help
DeviceDiscovery
DeviceManagementQFolder
DJ_SF_03_D2500_ProductContext
DJ_SF_03_D2500_Software
DJ_SF_03_D2500_Software_Min
ESU for Microsoft Vista
eSupportQFolder
Free Video to iPod Converter version 3.4
Free YouTube to iPod Converter version 3.2
Google Chrome
Google Earth
Google Update Helper
Google Updater
GPBaseService
Halo Combat Evolved
HDAUDIO Soft Data Fax Modem with SmartCP
Hewlett-Packard Active Check for Health Check
Hewlett-Packard Asset Agent for Health Check
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Customer Participation Program 11.0
HP Deskjet D2500 Printer Driver Software 11.0 Rel .3
HP Doc Viewer
HP DVD Play 3.7
HP Easy Setup - Frontend
HP Help and Support
HP Imaging Device Functions 11.0
HP Photosmart Essential 2.5
HP Photosmart Essential 3.0
HP Quick Launch Buttons 6.40 D3
HP Smart Web Printing
HP Solution Center 11.0
HP Total Care Advisor
HP Update
HP User Guides 0118
HP Wireless Assistant
HPNetworkAssistant
HPPhotoSmartDiscLabel_PaperLabel
HPPhotoSmartDiscLabel_PrintOnDisc
HPPhotoSmartDiscLabel_Tattoo
HPPhotoSmartDiscLabelContent1
hpphotosmartdisclabelplugin
HPPhotoSmartPhotobookHolidayPack1
HPPhotoSmartPhotobookModernPack1
HPPhotoSmartPhotobookPlayfulPack1
HPPhotoSmartPhotobookScrapbookPack1
HPPhotoSmartPhotobookWebPack1
HPProductAssistant
iTunes
Java(TM) 6 Update 16
Java(TM) 6 Update 5
LabelPrint
LightScribe System Software 1.12.33.2
LiveUpdate (Symantec Corporation)
MarketResearch
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Live Add-in 1.3
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox (3.6.6)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 6.1
My HP Games
NetWaiting
NVIDIA Drivers
Power2Go
PowerDirector
PSSWCORE
PVSonyDll
QuickPlay SlingPlayer 0.4.6
QuickTax 2009
QuickTime
Realtek USB 2.0 Card Reader
Rogers Servicepoint Agent 2.0.21
RPS CRT
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for 2007 Microsoft Office System (KB982312)
Security Update for 2007 Microsoft Office System (KB982331)
Security Update for Microsoft Office Excel 2007 (KB982308)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB982135)
SmartWebPrinting
SolutionCenter
Spybot - Search & Destroy
Status
Synaptics Pointing Device Driver
The Sims™ 2 Double Deluxe
Toolbox
TrayApp
TweetDeck
Uninstall 1.0.0.1
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VideoToolkit01
Virtual DJ - Atomix Productions
VLC media player 1.0.1
WebReg
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Player Firefox Plugin
WinRAR archiver

==== End Of File ===========================

ken545
2010-08-01, 02:56
Hi,

Remove this entry with Hijackthis

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555

Post a new HJT log and let me know if things have improved

DaReelDeel
2010-08-01, 23:07
Hello, I think it may have done the trick. It seems to have stopped, but I'm not sure. Thanks a bunch for all your help. Here is the new HijackThis log you requested.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:42:02 PM, on 01/08/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RogersServicepointAgent.exe] "C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" /AUTORUN
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Google Update] "C:\Users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Run YoukuDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe (file missing)
O9 - Extra 'Tools' menuitem: Youku Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: intu-qt2009 - {03947252-2355-4E9B-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1ca2cdcaf95cfe9) (gupdate1ca2cdcaf95cfe9) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 10022 bytes

ken545
2010-08-02, 00:20
Great, keep and eye on things and post back in a few days and let me know how its going

DaReelDeel
2010-08-03, 02:06
When I rebooted my laptop, I noticed the redirecting is back again. Although there are no popups, the links redirect me to other websites.

ken545
2010-08-03, 02:52
Lets do this,

Download the HostsXpert 4.3 - Hosts File Manager (http://www.funkytoad.com/download/HostsXpert.zip).

Unzip HostsXpert 4.2.0.0 - Hosts File Manager to a convenient folder such as C:\HostsXpert
Click HostsXpert.exe to Run HostsXpert - Hosts File Manager from its new home
Click "Make Hosts Writable?" in the upper left corner.
Click Restore Microsoft's Hosts file and then click OK.
Click the X to exit the program.
Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.







Backup Your Registry with ERUNT:
Download erunt.zip to your Desktop from here:
http://aumha.org/downloads/erunt.zip
Right-click erunt.zip, select Extract All... and follow the prompts to extract ERUNT to a new folder on your Desktop
Inside the new folder, double-click ERUNT.exe to start the program
OK all the prompts to back up your registry to the default location.Note: to restore your registry, go to the backup folder and start ERDNT.exe



Run OTL

Under the Custom Scans/Fixes box at the bottom, paste in the following



:OTL
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183614.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183519.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183518.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183517.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-183516.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180651.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180650.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180647.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180645.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180643.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180642.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180641.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180616.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180615.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180614.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180613.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-180612.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174936.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174923.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174920.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174919.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174917.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174843.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174842.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174840.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174646.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174644.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-174627.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173902.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173617.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173616.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173615.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173608.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173607.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173606.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173605.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173604.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173603.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173602.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173601.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173557.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-173518.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-172944.backup
[2010/07/11 16:12:13 | 000,002,731 | RHS- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100711-172848.backup

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
Let the program run unhindered, reboot when it is done
Post the log its created please

DaReelDeel
2010-08-03, 18:03
Hi,

When I ran HostsXpert.exe, the top left read Make Hosts ReadOnly? I just continued to Restore Microsoft's Hosts file. Then I ran ERUNT and the the custom fix on OTL. Here is the log.


All processes killed
========== OTL ==========
No active process named Explorer.EXE was found!
C:\WINDOWS\System32\drivers\etc\hosts.20100711-183614.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-183519.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-183518.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-183517.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-183516.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-180651.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-180650.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-180647.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-180645.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-180643.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-180642.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-180641.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-180616.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-180615.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-180614.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-180613.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-180612.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-174936.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-174923.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-174920.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-174919.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-174917.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-174843.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-174842.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-174840.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-174646.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-174644.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-174627.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-173902.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-173617.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-173616.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-173615.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-173608.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-173607.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-173606.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-173605.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-173604.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-173603.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-173602.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-173601.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-173557.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-173518.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-172944.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20100711-172848.backup moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Bhing or J.A
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Darlin
->Temp folder emptied: 2591578 bytes
->Temporary Internet Files folder emptied: 61164015 bytes
->Java cache emptied: 7140 bytes
->FireFox cache emptied: 13512633 bytes
->Google Chrome cache emptied: 347634021 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 8276 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: TEMP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: TEMP.Darlin-PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: TEMP.Darlin-PC.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 189131 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 405.00 mb


OTL by OldTimer - Version 3.2.9.1 log created on 08032010_111207

Files\Folders moved on Reboot...
C:\Users\Darlin\AppData\Local\Temp\ehmsas.txt moved successfully.
C:\Users\Darlin\AppData\Local\Temp\VGXFA64.tmp moved successfully.

Registry entries deleted on Reboot...

ken545
2010-08-03, 18:51
Go ahead and run OTL again and post a new log please. Have things gotten better ?

DaReelDeel
2010-08-04, 20:21
Hi. Below is the new OTL log. There is still a problem. When I go to any website, there is always an error saying they can't find the webpage. I have to refresh it several times before I it appears. This problem is on and off. Also, this address is popping up in a new tab. http://results.google-analytics.com/.


OTL logfile created on: 04/08/2010 2:12:52 PM - Run 5
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Darlin\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.54 Gb Total Space | 129.69 Gb Free Space | 58.02% Space Free | Partition Type: NTFS
Drive D: | 9.35 Gb Total Space | 1.70 Gb Free Space | 18.16% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DARLIN-PC
Current User Name: Darlin
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Darlin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
PRC - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\SMINST\BLService.exe ()
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Darlin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\WINDOWS\System32\FntCache.dll (Microsoft Corporation)
SRV - (YahooAUService) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (Recovery Service for Windows) -- C:\WINDOWS\SMINST\BLService.exe ()
SRV - (Automatic LiveUpdate Scheduler) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (RPSKT) Security Services Driver (x86) -- C:\Windows\System32\DRIVERS\rp_skt32.sys File not found
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (catchme) -- C:\Users\Darlin\AppData\Local\Temp\catchme.sys File not found
DRV - (MpFilter) -- C:\WINDOWS\System32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (MpNWMon) -- C:\WINDOWS\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (BCM43XX) -- C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (BCM43XV) -- C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (nvlddmkm) -- C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (RTSTOR) -- C:\WINDOWS\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (CnxtHdAudService) -- C:\WINDOWS\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (NVHDA) -- C:\WINDOWS\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (nvsmu) -- C:\WINDOWS\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (SynTP) -- C:\WINDOWS\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (NVENETFD) -- C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\WINDOWS\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HSFHWAZL) -- C:\WINDOWS\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (HSF_DPV) -- C:\WINDOWS\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) -- C:\WINDOWS\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) -- C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqRemHid) -- C:\WINDOWS\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (PID_0928) Labtec WebCam(PID_0928) -- C:\WINDOWS\System32\drivers\LV561AV.SYS (Labtec Inc.)
DRV - (LVUSBSta) -- C:\WINDOWS\System32\drivers\LVUSBSta.sys (Labtec Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local

FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009/09/11 16:51:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/09 19:03:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/09 19:03:01 | 000,000,000 | ---D | M]

[2010/03/17 16:27:38 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Extensions
[2009/08/21 19:44:39 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Extensions\mozswing@mozswing.org
[2010/08/01 11:55:27 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions
[2010/07/28 12:11:31 | 000,000,000 | ---D | M] (TwitterBar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}
[2010/04/27 17:10:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2010/03/18 20:51:56 | 000,000,000 | ---D | M] (AniWeather) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}
[2010/05/25 20:18:05 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/03/28 14:09:55 | 000,000,000 | ---D | M] (ScrapBook) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2010/07/31 23:04:28 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/03/18 21:34:21 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2010/03/18 21:01:38 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2010/06/08 11:09:24 | 000,000,000 | ---D | M] (ReminderFox) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
[2010/07/28 12:11:30 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/06/30 22:17:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/07/28 12:11:31 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/03/18 21:34:21 | 000,000,000 | ---D | M] (Pixlr Grabber) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{d47a9f51-8281-43fa-f450-f28ef8735e9a}
[2010/06/02 19:11:22 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/04/12 10:07:01 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/05/15 21:16:08 | 000,000,000 | ---D | M] (DVDVideoSoft Toolbar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] (FoxTab) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2010/07/28 12:11:45 | 000,000,000 | ---D | M] (SearchPreview) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
[2010/07/28 12:11:31 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\FirefoxAddon@similarWeb.com
[2010/03/18 21:39:06 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\googletube@googletube.com
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\illimitux@illimitux.net
[2010/04/12 10:07:29 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\isreaditlater@ideashower.com
[2010/04/14 10:14:52 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\personas@christopher.beard
[2010/06/29 16:36:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com
[2010/06/29 16:36:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com-trash
[2010/03/18 21:01:33 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\SkipScreen@SkipScreen
[2010/06/16 15:38:34 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\smarterwiki@wikiatic.com
[2010/07/28 12:11:30 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\unplug@compunach
[2010/06/16 15:38:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\videosurf_enhanced@videosurf.com
[2010/04/21 10:16:53 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\YoutubeDownloader@PeterOlayev.com
[2010/03/05 15:29:29 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] (TwitterBar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2010/03/05 15:04:55 | 000,000,000 | ---D | M] (TV-Fox) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{2f17f610-5e97-4fed-828f-9940b7b577a4}
[2010/03/04 17:52:58 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{99210d54-6321-41e8-bd1b-2b4c55874efb}
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] (QuickWiki) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{EE223D7A-F30F-11DD-8F0A-D2AD55D89593}
[2010/03/04 17:52:58 | 000,000,000 | ---D | M] (FoxTab) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\en-CA@dictionaries.addons.mozilla.org
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\FirefoxAddon@myfacebook.com
[2010/03/04 17:53:01 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\FirefoxAddon@similarWeb.com
[2010/03/04 18:20:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\firefox-extension@shareaholic.com
[2010/03/04 18:20:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\googletube@googletube.com
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\illimitux@illimitux.net
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\isreaditlater@ideashower.com
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\personas@christopher.beard
[2010/03/04 17:53:00 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\piclens@cooliris.com
[2010/03/04 17:53:01 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\quickdrag@mozilla.ktechcomputing.com
[2010/03/04 18:20:45 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\firefox-extension@shareaholic.com\chrome
[2010/03/04 18:32:31 | 000,007,972 | ---- | M] () -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\searchplugins\oneriot-social-web-search.xml
[2010/03/04 17:43:36 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/02/21 06:22:32 | 000,712,704 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll

O1 HOSTS File: ([2010/08/03 11:04:40 | 000,000,698 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RogersServicepointAgent.exe] C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - Startup: C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Run YoukuDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe File not found
O9 - Extra 'Tools' menuitem : Youku Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Darlin\Pictures\wild_shutterstock_8532871.jpg
O24 - Desktop BackupWallPaper: C:\Users\Darlin\Pictures\wild_shutterstock_8532871.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/11 09:46:21 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/08/03 11:53:55 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010/08/03 11:10:08 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\Darlin\Desktop\OTL.exe
[2010/08/01 16:15:08 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/07/31 23:09:04 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Yahoo
[2010/07/31 23:04:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo! Companion
[2010/07/31 23:03:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo!
[2010/07/31 15:24:56 | 000,000,000 | ---D | C] -- C:\_OTM
[2010/07/22 14:17:32 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/07/22 13:01:49 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2010/07/21 14:10:29 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010/07/21 14:09:14 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010/07/21 13:46:04 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010/07/21 13:45:36 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/07/19 14:09:04 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/07/18 15:12:02 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Apple
[2010/07/18 14:54:21 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Adobe
[2010/07/18 13:28:51 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Apple Computer
[2010/07/18 12:48:42 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Roaming\Malwarebytes
[2010/07/18 12:48:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/07/18 12:48:30 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/17 20:50:15 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/07/17 20:50:15 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/07/17 20:50:15 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/07/17 20:50:08 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/07/17 20:49:37 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/07/12 12:25:33 | 000,000,000 | ---D | C] -- C:\Program Files\Safer Networking
[2010/07/12 09:25:13 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2010/07/11 19:54:59 | 000,000,000 | ---D | C] -- C:\Program Files\TweetDeck
[2010/07/11 17:16:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2010/07/11 17:16:36 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010/07/11 14:14:26 | 000,000,000 | -HSD | C] -- C:\ProgramData\SMACCEEAV
[4 C:\Users\Darlin\Documents\*.tmp files -> C:\Users\Darlin\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/04 14:11:33 | 008,388,608 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat
[2010/08/04 13:56:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/04 13:50:53 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/04 13:50:53 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/04 13:49:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job
[2010/08/04 11:51:00 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2010/08/04 11:51:00 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/08/04 11:50:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/08/04 09:50:25 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010/08/04 09:48:19 | 000,000,246 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2010/08/04 09:46:56 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/04 09:46:43 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/08/04 09:46:33 | 2951,114,752 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/03 22:26:40 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/08/03 22:26:35 | 000,524,288 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TMContainer00000000000000000001.regtrans-ms
[2010/08/03 22:26:35 | 000,065,536 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TM.blf
[2010/08/03 22:26:32 | 002,495,150 | -H-- | M] () -- C:\Users\Darlin\AppData\Local\IconCache.db
[2010/08/03 17:49:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job
[2010/08/03 11:10:09 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Darlin\Desktop\OTL.exe
[2010/08/03 11:04:40 | 000,000,698 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010/08/02 20:08:00 | 000,001,804 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/08/01 16:16:01 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/07/31 23:03:45 | 000,000,966 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/07/29 19:01:29 | 002,380,564 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/07/29 19:01:29 | 000,714,466 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/07/29 19:01:29 | 000,062,236 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2010/07/29 19:01:29 | 000,059,822 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/07/29 19:01:29 | 000,019,286 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2010/07/29 18:44:36 | 000,013,312 | ---- | M] () -- C:\Users\Darlin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/29 12:50:32 | 000,001,356 | ---- | M] () -- C:\Users\Darlin\AppData\Local\d3d9caps.dat
[2010/07/29 12:28:07 | 257,366,390 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/07/28 18:38:07 | 002,512,767 | ---- | M] () -- C:\Users\Darlin\Documents\Canadian Achievements.pptx
[2010/07/26 21:59:30 | 000,002,047 | ---- | M] () -- C:\Users\Darlin\Desktop\Google Chrome.lnk
[2010/07/26 21:59:30 | 000,002,009 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/07/22 19:06:22 | 000,030,720 | ---- | M] () -- C:\Users\Darlin\Documents\Water Consumption.doc
[2010/07/22 19:06:13 | 000,014,769 | ---- | M] () -- C:\Users\Darlin\Documents\Final Unit Essay.docx
[2010/07/22 14:17:32 | 000,001,874 | ---- | M] () -- C:\Users\Darlin\Desktop\HijackThis.lnk
[2010/07/21 17:04:41 | 000,020,148 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 6 Activity 3.docx
[2010/07/21 14:06:38 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/07/20 22:25:46 | 000,019,373 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 5 Activity 5.docx
[2010/07/20 19:57:21 | 000,023,377 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 5 Activity 3.docx
[2010/07/20 14:39:39 | 000,038,252 | ---- | M] () -- C:\Users\Darlin\Documents\Charter.rtf
[2010/07/13 16:47:10 | 000,000,104 | ---- | M] () -- C:\Users\Darlin\Desktop\Recycle Bin - Shortcut.lnk
[2010/07/12 09:25:29 | 000,000,008 | ---- | M] () -- C:\Users\Darlin\AppData\Roaming\vdnxlf.dat
[2010/07/11 19:55:01 | 000,000,762 | ---- | M] () -- C:\Users\Public\Desktop\TweetDeck.lnk
[2010/07/11 19:19:13 | 000,311,040 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/07/11 17:46:31 | 000,000,088 | ---- | M] () -- C:\Windows\wininit.ini
[2010/07/09 23:20:49 | 000,088,576 | RHS- | M] () -- C:\Users\Darlin\AppData\Roaming\nb-NOM.dll
[4 C:\Users\Darlin\Documents\*.tmp files -> C:\Users\Darlin\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/02 20:08:00 | 000,001,804 | ---- | C] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/08/01 16:16:01 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/07/31 23:03:45 | 000,000,966 | ---- | C] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/07/27 23:08:14 | 002,512,767 | ---- | C] () -- C:\Users\Darlin\Documents\Canadian Achievements.pptx
[2010/07/22 19:06:13 | 000,014,769 | ---- | C] () -- C:\Users\Darlin\Documents\Final Unit Essay.docx
[2010/07/22 16:16:18 | 000,030,720 | ---- | C] () -- C:\Users\Darlin\Documents\Water Consumption.doc
[2010/07/22 14:17:32 | 000,001,874 | ---- | C] () -- C:\Users\Darlin\Desktop\HijackThis.lnk
[2010/07/21 17:04:41 | 000,020,148 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 6 Activity 3.docx
[2010/07/21 14:45:52 | 2951,114,752 | -HS- | C] () -- C:\hiberfil.sys
[2010/07/20 22:25:44 | 000,019,373 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 5 Activity 5.docx
[2010/07/20 19:56:30 | 000,023,377 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 5 Activity 3.docx
[2010/07/20 14:39:39 | 000,038,252 | ---- | C] () -- C:\Users\Darlin\Documents\Charter.rtf
[2010/07/17 20:50:15 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010/07/17 20:50:15 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/07/17 20:50:15 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/07/17 20:50:15 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/07/17 20:50:15 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/07/13 16:47:10 | 000,000,104 | ---- | C] () -- C:\Users\Darlin\Desktop\Recycle Bin - Shortcut.lnk
[2010/07/12 09:25:28 | 000,000,008 | ---- | C] () -- C:\Users\Darlin\AppData\Roaming\vdnxlf.dat
[2010/07/11 23:08:05 | 257,366,390 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010/07/11 21:12:54 | 000,001,972 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/07/11 21:12:54 | 000,001,111 | ---- | C] () -- C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2010/07/11 17:46:31 | 000,000,088 | ---- | C] () -- C:\Windows\wininit.ini
[2010/07/09 23:20:48 | 000,088,576 | RHS- | C] () -- C:\Users\Darlin\AppData\Roaming\nb-NOM.dll
[2009/09/17 16:23:53 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2008/01/20 22:24:38 | 000,033,794 | ---- | C] () -- C:\Windows\System32\unelwin.dll
[2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/03/09 05:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2005/01/19 09:30:54 | 000,009,255 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini

========== LOP Check ==========

[2010/06/02 18:46:13 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\BitComet
[2009/10/09 21:17:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\iWin
[2010/07/17 20:48:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\LimeWire
[2010/06/08 13:18:41 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Opera
[2009/10/10 23:06:18 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\PlayFirst
[2010/03/10 18:32:47 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Rogers Online Protection
[2009/10/17 15:25:15 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Template
[2009/08/21 21:22:19 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2009/11/30 17:12:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2009/09/05 19:38:05 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\WildTangent
[2010/08/03 22:26:50 | 000,032,562 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2009/10/02 23:23:37 | 000,000,036 | ---- | M] ()(C:\Windows\System32\?????????????????????????????????????????????????) -- C:\Windows\System32\㩃停潲牧浡䘠汩獥剜杯牥⁳湏楬敮倠潲整瑣潩屮潒敧獲传汮湩⁥牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩⹷潣普杩
[2009/10/02 23:23:37 | 000,000,036 | ---- | C] ()(C:\Windows\System32\?????????????????????????????????????????????????) -- C:\Windows\System32\㩃停潲牧浡䘠汩獥剜杯牥⁳湏楬敮倠潲整瑣潩屮潒敧獲传汮湩⁥牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩⹷潣普杩
< End of report >
[2010/08/04 14:15:07 | 000,000,000 | R--D | M] -- C:\Users\Darlin\Desktop
[2010/08/04 14:11:36 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Local\Temp
[2010/08/04 14:11:33 | 008,388,608 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat
[2010/08/04 14:11:32 | 000,262,144 | -H-- | M] () -- C:\Users\Darlin\ntuser.dat.LOG1
[2010/08/04 13:56:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/04 13:50:53 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/04 13:50:53 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/04 13:49:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job
[2010/08/04 13:10:55 | 000,000,000 | R--D | M] -- C:\Users\Darlin\Downloads
[2010/08/04 11:51:00 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2010/08/04 11:51:00 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/08/04 11:50:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/08/04 09:50:25 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010/08/04 09:48:38 | 000,000,000 | ---D | M] -- C:\Users\Darlin\Tracing
[2010/08/04 09:48:19 | 000,000,246 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2010/08/04 09:46:56 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/04 09:46:43 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/08/03 22:26:40 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/08/03 22:26:35 | 000,524,288 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TMContainer00000000000000000001.regtrans-ms
[2010/08/03 22:26:35 | 000,065,536 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TM.blf
[2010/08/03 22:26:32 | 002,495,150 | -H-- | M] () -- C:\Users\Darlin\AppData\Local\IconCache.db
[2010/08/03 17:49:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job
[2010/08/03 11:55:29 | 000,000,000 | ---D | M] -- C:\ProgramData\Yahoo! Companion
[2010/08/03 11:54:11 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Security Essentials
[2010/08/03 11:10:09 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Darlin\Desktop\OTL.exe
[2010/08/02 20:08:00 | 000,001,804 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/08/02 17:38:38 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Local\Cooliris
[2010/08/01 16:16:01 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/08/01 16:15:59 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2010/08/01 16:15:08 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2010/08/01 16:15:06 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files\Apple
[2010/07/31 23:09:04 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Local\Yahoo
[2010/07/31 23:05:13 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Yahoo!
[2010/07/31 23:04:18 | 000,000,000 | ---D | M] -- C:\ProgramData\Yahoo!
[2010/07/31 23:04:18 | 000,000,000 | ---D | M] -- C:\Program Files\Yahoo!
[2010/07/31 23:03:45 | 000,000,966 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/07/31 23:03:07 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files\microsoft shared
[2010/07/30 18:52:36 | 000,000,000 | R--D | M] -- C:\Users\Darlin\Documents
[2010/07/30 11:45:24 | 000,000,000 | R--D | M] -- C:\Users\Darlin\Pictures
[2010/07/29 19:01:29 | 002,380,564 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/07/29 19:01:29 | 000,714,466 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/07/29 19:01:29 | 000,062,236 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2010/07/29 19:01:29 | 000,059,822 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/07/29 19:01:29 | 000,019,286 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2010/07/29 18:44:36 | 000,013,312 | ---- | M] () -- C:\Users\Darlin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/29 12:50:32 | 000,001,356 | ---- | M] () -- C:\Users\Darlin\AppData\Local\d3d9caps.dat
[2010/07/29 12:28:07 | 257,366,390 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/07/28 18:38:07 | 002,512,767 | ---- | M] () -- C:\Users\Darlin\Documents\Canadian Achievements.pptx
[2010/07/26 21:59:30 | 000,002,047 | ---- | M] () -- C:\Users\Darlin\Desktop\Google Chrome.lnk
[2010/07/26 21:59:30 | 000,002,009 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/07/22 19:06:22 | 000,030,720 | ---- | M] () -- C:\Users\Darlin\Documents\Water Consumption.doc
[2010/07/22 19:06:13 | 000,014,769 | ---- | M] () -- C:\Users\Darlin\Documents\Final Unit Essay.docx
[2010/07/22 14:17:32 | 000,001,874 | ---- | M] () -- C:\Users\Darlin\Desktop\HijackThis.lnk
[2010/07/22 14:17:32 | 000,000,000 | ---D | M] -- C:\Program Files\Trend Micro
[2010/07/22 13:01:49 | 000,000,000 | ---D | M] -- C:\ProgramData\SUPERAntiSpyware.com
[2010/07/21 17:04:41 | 000,020,148 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 6 Activity 3.docx
[2010/07/21 14:13:29 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/21 14:06:38 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/07/21 14:02:15 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2010/07/20 22:25:46 | 000,019,373 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 5 Activity 5.docx
[2010/07/20 19:57:21 | 000,023,377 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 5 Activity 3.docx
[2010/07/20 14:39:39 | 000,038,252 | ---- | M] () -- C:\Users\Darlin\Documents\Charter.rtf
[2010/07/20 14:28:54 | 000,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy
[2010/07/19 14:56:00 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Local\Adobe
[2010/07/18 15:12:02 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Local\Apple
[2010/07/18 13:28:51 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Local\Apple Computer
[2010/07/18 12:48:42 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Malwarebytes
[2010/07/18 12:48:31 | 000,000,000 | ---D | M] -- C:\ProgramData\Malwarebytes
[2010/07/17 20:48:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\LimeWire
[2010/07/17 20:44:29 | 000,000,000 | ---D | M] -- C:\Program Files\LimeWire
[2010/07/15 10:19:17 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Mail
[2010/07/13 22:07:12 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files\Adobe
[2010/07/13 16:47:10 | 000,000,104 | ---- | M] () -- C:\Users\Darlin\Desktop\Recycle Bin - Shortcut.lnk
[2010/07/12 12:25:33 | 000,000,000 | ---D | M] -- C:\Program Files\Safer Networking
[2010/07/12 09:25:29 | 000,000,008 | ---- | M] () -- C:\Users\Darlin\AppData\Roaming\vdnxlf.dat
[2010/07/11 21:18:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Local\QuickPlay
[2010/07/11 21:18:23 | 000,000,000 | ---D | M] -- C:\ProgramData\Spybot - Search & Destroy
[2010/07/11 19:55:01 | 000,000,762 | ---- | M] () -- C:\Users\Public\Desktop\TweetDeck.lnk
[2010/07/11 19:54:59 | 000,000,000 | ---D | M] -- C:\Program Files\TweetDeck
[2010/07/11 19:19:13 | 000,311,040 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/07/11 17:46:31 | 000,000,088 | ---- | M] () -- C:\Windows\wininit.ini
[2010/07/11 14:14:26 | 000,000,000 | -HSD | M] -- C:\ProgramData\SMACCEEAV
[2010/07/11 13:54:58 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\vlc
[2010/07/09 23:20:49 | 000,088,576 | RHS- | M] () -- C:\Users\Darlin\AppData\Roaming\nb-NOM.dll
[2010/07/09 19:03:01 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2010/07/05 21:26:21 | 000,000,000 | --SD | M] -- C:\ProgramData\Microsoft
[2010/07/05 21:26:21 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Local\Microsoft
[4 C:\Users\Darlin\Documents\*.tmp files -> C:\Users\Darlin\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/04 14:16:03 | 008,388,608 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat
[2010/08/04 13:56:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/04 13:50:53 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/04 13:50:53 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/04 13:49:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job
[2010/08/04 11:51:00 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2010/08/04 11:51:00 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/08/04 11:50:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/08/04 09:50:25 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010/08/04 09:48:19 | 000,000,246 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2010/08/04 09:46:56 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/04 09:46:43 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/08/04 09:46:33 | 2951,114,752 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/03 22:26:40 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/08/03 22:26:35 | 000,524,288 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TMContainer00000000000000000001.regtrans-ms
[2010/08/03 22:26:35 | 000,065,536 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TM.blf
[2010/08/03 22:26:32 | 002,495,150 | -H-- | M] () -- C:\Users\Darlin\AppData\Local\IconCache.db
[2010/08/03 17:49:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job
[2010/08/03 11:10:09 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Darlin\Desktop\OTL.exe
[2010/08/03 11:04:40 | 000,000,698 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010/08/02 20:08:00 | 000,001,804 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/08/01 16:16:01 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/07/31 23:03:45 | 000,000,966 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/07/29 19:01:29 | 002,380,564 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/07/29 19:01:29 | 000,714,466 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/07/29 19:01:29 | 000,062,236 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2010/07/29 19:01:29 | 000,059,822 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/07/29 19:01:29 | 000,019,286 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2010/07/29 18:44:36 | 000,013,312 | ---- | M] () -- C:\Users\Darlin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/29 12:50:32 | 000,001,356 | ---- | M] () -- C:\Users\Darlin\AppData\Local\d3d9caps.dat
[2010/07/29 12:28:07 | 257,366,390 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/07/28 18:38:07 | 002,512,767 | ---- | M] () -- C:\Users\Darlin\Documents\Canadian Achievements.pptx
[2010/07/26 21:59:30 | 000,002,047 | ---- | M] () -- C:\Users\Darlin\Desktop\Google Chrome.lnk
[2010/07/26 21:59:30 | 000,002,009 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/07/22 19:06:22 | 000,030,720 | ---- | M] () -- C:\Users\Darlin\Documents\Water Consumption.doc
[2010/07/22 19:06:13 | 000,014,769 | ---- | M] () -- C:\Users\Darlin\Documents\Final Unit Essay.docx
[2010/07/22 14:17:32 | 000,001,874 | ---- | M] () -- C:\Users\Darlin\Desktop\HijackThis.lnk
[2010/07/21 17:04:41 | 000,020,148 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 6 Activity 3.docx
[2010/07/21 14:06:38 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/07/20 22:25:46 | 000,019,373 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 5 Activity 5.docx
[2010/07/20 19:57:21 | 000,023,377 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 5 Activity 3.docx
[2010/07/20 14:39:39 | 000,038,252 | ---- | M] () -- C:\Users\Darlin\Documents\Charter.rtf
[2010/07/13 16:47:10 | 000,000,104 | ---- | M] () -- C:\Users\Darlin\Desktop\Recycle Bin - Shortcut.lnk
[2010/07/12 09:25:29 | 000,000,008 | ---- | M] () -- C:\Users\Darlin\AppData\Roaming\vdnxlf.dat
[2010/07/11 19:55:01 | 000,000,762 | ---- | M] () -- C:\Users\Public\Desktop\TweetDeck.lnk
[2010/07/11 19:19:13 | 000,311,040 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/07/11 17:46:31 | 000,000,088 | ---- | M] () -- C:\Windows\wininit.ini
[2010/07/09 23:20:49 | 000,088,576 | RHS- | M] () -- C:\Users\Darlin\AppData\Roaming\nb-NOM.dll
[4 C:\Users\Darlin\Documents\*.tmp files -> C:\Users\Darlin\Documents\*.tmp -> ]

========== LOP Check ==========

[2010/06/02 18:46:13 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\BitComet
[2009/10/09 21:17:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\iWin
[2010/07/17 20:48:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\LimeWire
[2010/06/08 13:18:41 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Opera
[2009/10/10 23:06:18 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\PlayFirst
[2010/03/10 18:32:47 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Rogers Online Protection
[2009/10/17 15:25:15 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Template
[2009/08/21 21:22:19 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2009/11/30 17:12:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2009/09/05 19:38:05 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\WildTangent
[2010/08/03 22:26:50 | 000,032,562 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2009/10/02 23:23:37 | 000,000,036 | ---- | M] ()(C:\Windows\System32\?????????????????????????????????????????????????) -- C:\Windows\System32\㩃停潲牧浡䘠汩獥剜杯牥⁳湏楬敮倠潲整瑣潩屮潒敧獲传汮湩⁥牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩⹷潣普杩

< End of report >

ken545
2010-08-04, 22:54
Lets flush out your DNS cache

Open Notepad and Copy and paste these lines into Notepad

@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0

Save it as Flush.bat
In the dropdown menu save it as All Files
Save it to your desktop
Double click it to run
It will reboot your computer when done
*** note: Win Vista and Win 7 need to right click and choose to "run as Administrator" .. the computer will reboot itself.



Let me know if this helped

DaReelDeel
2010-08-05, 20:28
Hi! I ran the flush, but there is still an error page saying the webpage is not available.

ken545
2010-08-05, 23:37
This may just be a browser issue and not related to malware. Lets update your browser from Version 7 to 8 and see if this does the trick

Open IE and go to Tools > Windows Updates and download and install all critical updates including IE8

You can also download it from here
http://www.microsoft.com/windows/internet-explorer/default.aspx

DaReelDeel
2010-08-07, 19:49
I updated the browser, but I'm still getting error messages.

ken545
2010-08-07, 19:57
What error messages are you getting ? Is it just the pages wont load or are you being redirected or getting popup windows ?

Open IE and go to Tools > Internet Options > Advanced Tab > Reset Internet Explorer Setting > Reset..... may take a few seconds....then ok your way out.

Close IE and then reopen it and see if things are working now.

Post a new DDS log and let me have another look

DaReelDeel
2010-08-08, 20:51
Hi.I'm still getting the error message that the webpage is not available. I have to refresh it many times for the page to show, but sometimes even refreshing it won't work. Also it redirects me to another website, mostly to this website called searchpro.com. I googled it and it said searchprotocolhost.exe is a virus.
Resetting the internet explorer settings didn't work.

Other than that here is the DDS log and the attach.txt log.


DDS (Ver_10-03-17.01) - NTFSx86
Run by Darlin at 14:40:39.48 on 08/08/2010
Internet Explorer: 7.0.6002.18005
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2814.1824 [GMT -4:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgentComHandler.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Darlin\Desktop\dds.scr
C:\Windows\system32\conime.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
uInternet Settings,ProxyOverride = <local>;*.local
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Google Update] "c:\users\darlin\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\2.0"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [RogersServicepointAgent.exe] "c:\program files\rogers online protection\rogers servicepoint agent\RogersServicepointAgent.exe" /AUTORUN
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
StartupFolder: c:\users\darlin\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {612F6E5C-B314-4bab-93D1-D266AAFBE700} - c:\program files\xmlbar\youku downloader\YoukuDownloader(xmlbar).exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: intu-qt2009 - {03947252-2355-4e9b-B446-8CCC75C43370} - c:\program files\quicktax 2009\ic2009pp.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"

================= FIREFOX ===================

FF - ProfilePath - c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{6ac85730-7d0f-4de0-b3fa-21142dd85326}\platform\winnt\components\ColorZilla.dll
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
FF - component: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\rogers online protection\rogers servicepoint agent\nprpspa.dll
FF - plugin: c:\users\darlin\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\darlin\appdata\roaming\mozilla\firefox\profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 151216]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\sminst\BLService.exe [2008-8-11 361808]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2008-8-11 193840]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-3-25 42368]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-5-9 43040]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate1ca2cdcaf95cfe9;Google Update Service (gupdate1ca2cdcaf95cfe9);c:\program files\google\update\GoogleUpdate.exe [2009-9-3 133104]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

=============== Created Last 30 ================

2010-08-03 15:53:55 0 d-----w- c:\program files\Microsoft Security Essentials
2010-08-01 20:15:08 0 d-----w- c:\program files\iPod
2010-08-01 03:04:16 0 d-----w- c:\programdata\Yahoo! Companion
2010-08-01 03:03:43 0 d-----w- c:\programdata\Yahoo!
2010-07-31 19:24:56 0 d-----w- C:\_OTM
2010-07-22 18:17:32 0 d-----w- c:\program files\Trend Micro
2010-07-22 17:01:49 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-07-21 18:09:14 0 d-sh--w- C:\$RECYCLE.BIN
2010-07-21 17:46:04 0 d-----w- C:\ComboFix
2010-07-19 18:09:04 0 d-----w- C:\_OTL
2010-07-18 16:48:42 0 d-----w- c:\users\darlin\appdata\roaming\Malwarebytes
2010-07-18 16:48:31 0 d-----w- c:\programdata\Malwarebytes
2010-07-18 16:48:30 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-18 00:50:15 98816 ----a-w- c:\windows\sed.exe
2010-07-18 00:50:15 77312 ----a-w- c:\windows\MBR.exe
2010-07-18 00:50:15 256512 ----a-w- c:\windows\PEV.exe
2010-07-18 00:50:15 161792 ----a-w- c:\windows\SWREG.exe
2010-07-12 16:25:33 0 d-----w- c:\program files\Safer Networking
2010-07-12 13:25:28 8 ----a-w- c:\users\darlin\appdata\roaming\vdnxlf.dat
2010-07-12 03:08:05 257366390 ----a-w- c:\windows\MEMORY.DMP
2010-07-11 23:54:59 0 d-----w- c:\program files\TweetDeck
2010-07-11 21:46:31 88 ----a-w- c:\windows\wininit.ini
2010-07-11 21:16:36 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-07-11 21:16:36 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-07-11 18:14:26 0 d-sh--w- c:\programdata\SMACCEEAV
2010-07-10 03:20:48 88576 --sha-r- c:\users\darlin\appdata\roaming\nb-NOM.dll

==================== Find3M ====================

2010-08-08 17:55:48 48670 ----a-w- c:\programdata\nvModes.dat
2010-07-29 23:01:29 62236 ----a-w- c:\windows\system32\perfh00C.dat
2010-07-29 23:01:29 19286 ----a-w- c:\windows\system32\perfc00C.dat
2010-06-20 19:25:57 86016 ----a-w- c:\windows\inf\infstor.dat
2010-06-20 19:25:57 51200 ----a-w- c:\windows\inf\infpub.dat
2010-06-20 19:25:56 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-05-26 17:06:41 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47:41 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-21 18:14:28 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 20:35:16 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-30 02:15:22 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-08-11 10:55:35 37390 ----a-w- c:\windows\inf\perflib\040c\perfd.dat
2008-08-11 10:55:35 37390 ----a-w- c:\windows\inf\perflib\040c\perfc.dat
2008-08-11 10:55:35 340236 ----a-w- c:\windows\inf\perflib\040c\perfi.dat
2008-08-11 10:55:35 340236 ----a-w- c:\windows\inf\perflib\040c\perfh.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2010-03-10 23:05:08 59232800 --sha-w- c:\windows\system32\drivers\fidbox.dat
2008-08-11 10:58:25 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 14:42:32.60 ===============

DDS (Ver_10-03-17.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 14/08/2009 2:06:55 PM
System Uptime: 08/08/2010 1:54:50 PM (1 hours ago)

Motherboard: Wistron | | 360A
Processor: AMD Athlon Dual-Core QL-60 | Socket A | 1900/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 224 GiB total, 129.031 GiB free.
D: is FIXED (NTFS) - 9 GiB total, 1.698 GiB free.
E: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================


==== Installed Programs ======================

32 Bit HP CIO Components Installer
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.2
Adobe Shockwave Player
Adobe Shockwave Player 11.5
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Bonjour
Broadcom 802.11 Wireless LAN Adapter
BufferChm
Cards_Calendar_OrderGift_DoMorePlugout
Compatibility Pack for the 2007 Office system
Conexant HD Audio
CustomerResearchQFolder
CyberLink DVD Suite
CyberLink YouCam
D2500
D2500_Help
DeviceDiscovery
DeviceManagementQFolder
DJ_SF_03_D2500_ProductContext
DJ_SF_03_D2500_Software
DJ_SF_03_D2500_Software_Min
ESU for Microsoft Vista
eSupportQFolder
Free Video to iPod Converter version 3.4
Free YouTube to iPod Converter version 3.2
Google Chrome
Google Earth
Google Update Helper
Google Updater
GPBaseService
Halo Combat Evolved
HDAUDIO Soft Data Fax Modem with SmartCP
Hewlett-Packard Active Check for Health Check
Hewlett-Packard Asset Agent for Health Check
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Customer Participation Program 11.0
HP Deskjet D2500 Printer Driver Software 11.0 Rel .3
HP Doc Viewer
HP DVD Play 3.7
HP Easy Setup - Frontend
HP Help and Support
HP Imaging Device Functions 11.0
HP Photosmart Essential 2.5
HP Photosmart Essential 3.0
HP Quick Launch Buttons 6.40 D3
HP Smart Web Printing
HP Solution Center 11.0
HP Total Care Advisor
HP Update
HP User Guides 0118
HP Wireless Assistant
HPNetworkAssistant
HPPhotoSmartDiscLabel_PaperLabel
HPPhotoSmartDiscLabel_PrintOnDisc
HPPhotoSmartDiscLabel_Tattoo
HPPhotoSmartDiscLabelContent1
hpphotosmartdisclabelplugin
HPPhotoSmartPhotobookHolidayPack1
HPPhotoSmartPhotobookModernPack1
HPPhotoSmartPhotobookPlayfulPack1
HPPhotoSmartPhotobookScrapbookPack1
HPPhotoSmartPhotobookWebPack1
HPProductAssistant
iTunes
Java(TM) 6 Update 16
Java(TM) 6 Update 5
LabelPrint
LightScribe System Software 1.12.33.2
LiveUpdate (Symantec Corporation)
MarketResearch
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Live Add-in 1.3
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox (3.6.6)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 6.1
My HP Games
NetWaiting
NVIDIA Drivers
Power2Go
PowerDirector
PSSWCORE
PVSonyDll
QuickPlay SlingPlayer 0.4.6
QuickTax 2009
QuickTime
Realtek USB 2.0 Card Reader
Rogers Servicepoint Agent 2.0.21
RPS CRT
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for 2007 Microsoft Office System (KB982312)
Security Update for 2007 Microsoft Office System (KB982331)
Security Update for Microsoft Office Excel 2007 (KB982308)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB982135)
SmartWebPrinting
SolutionCenter
Spybot - Search & Destroy
Status
Synaptics Pointing Device Driver
The Sims™ 2 Double Deluxe
Toolbox
TrayApp
TweetDeck
Uninstall 1.0.0.1
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VideoToolkit01
Virtual DJ - Atomix Productions
VLC media player 1.0.1
WebReg
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Player Firefox Plugin
WinRAR archiver
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar

==== End Of File ===========================

ken545
2010-08-08, 22:23
Hi,

We have run so many scans and nothing related to searchpro is showing up

searchprotocolhost.exe <-- This legit , its part of windows



Lets replace your hosts file, lets do it this way.


You already have HostsXpert downloaded to your desktop, if you still have it fine, if not redownload it ...BUT DONT RUN IT YET


Download the HostsXpert 4.3 - Hosts File Manager (http://www.funkytoad.com/download/HostsXpert.zip).

Unzip HostsXpert 4.2.0.0 - Hosts File Manager to a convenient folder such as C:\HostsXpert
Click HostsXpert.exe to Run HostsXpert - Hosts File Manager from its new home
Click "Make Hosts Writable?" in the upper left corner.
Click Restore Microsoft's Hosts file and then click OK.
Click the X to exit the program.
Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.








Please download OTM by OldTimer (http://oldtimer.geekstogo.com/OTM.exe) and save it to your desktop.
Double click the http://billy-oneal.com/Canned%20Speeches/speechimages/OTM/OTMdesktopicon.png icon on your desktop.
Paste the following code under the http://billy-oneal.com/Canned%20Speeches/speechimages/OTM/pasteline.png area.
Do not include the word "Code".



:Processes
explorer.exe

:Services

:Reg

:Files
c:\windows\system32\drivers\etc\hosts


:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Push the large http://billy-oneal.com/Canned%20Speeches/speechimages/OTM/btnmoveit.png button.
OTM may ask to reboot the machine. Please do so if asked.
Copy/Paste the contents under the http://billy-oneal.com/Canned%20Speeches/speechimages/OTM/results.png line here in your next reply.
If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Now run HostsXpert


Restore Microsoft's Hosts file <-- You will get a message stating that there is no hosts file available do you want to create one SAY YES

DaReelDeel
2010-08-09, 19:02
Hi. I ran OTM and restored the Microsoft Hosts file. Here is the log for OTM.

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
c:\windows\system32\drivers\etc\hosts moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Bhing or J.A
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Darlin
->Temp folder emptied: 5526065 bytes
->Temporary Internet Files folder emptied: 70163742 bytes
->Java cache emptied: 370065 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 371204103 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 101923 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: TEMP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: TEMP.Darlin-PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: TEMP.Darlin-PC.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 547844 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 427.00 mb


OTM by OldTimer - Version 3.1.15.0 log created on 08092010_125437

Files moved on Reboot...
C:\Users\Darlin\AppData\Local\Temp\ehmsas.txt moved successfully.
C:\Users\Darlin\AppData\Local\Temp\VGXFB3F.tmp moved successfully.

Registry entries deleted on Reboot...

ken545
2010-08-09, 19:12
Did it fix it ?

DaReelDeel
2010-08-10, 18:51
No. It didn't seem to work.

ken545
2010-08-10, 19:11
ok, we have run about every scan in the book and nothing appears to find and fix this issue, not sure but most likely there is a rootkit type of infection causing this and we wont know until I see a GMER log.

I need you to run GMER, please dont download it from the site you said you downloaded it from to work, download it from the link I am posting, if you still have it on your desktop, drag it to the trash.

We're going to disable your CD drivers, not to worry we will reenable them when were done

Please download DeFogger (http://www.jpshortstuff.247fixes.com/Defogger.exe) to your desktop.

Double click DeFogger to run the tool.

The application window will appear
Click the Disable button to disable your CD Emulation drivers
Click Yes to continue
A 'Finished!' message will appear
Click OK
DeFogger will now ask to reboot the machine - click OK

IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.





Next:

Please download GMER from one of the following locations and save it to your desktop:
Main Mirror (http://gmer.net/download.php)
This version will download a randomly named file (Recommended)
Zipped Mirror (http://gmer.net/gmer.zip)
This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.

Disconnect from the Internet and close all running programs.
Temporarily disable any real-time active protection (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html) so your security programs will not conflict with gmer's driver.
Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

http://img.photobucket.com/albums/v666/sUBs/gmer_zip.gif

GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
Now click the Scan button. If you see a rootkit warning window, click OK.
When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
Click the Copy button and paste the results into your next reply.
Exit GMER and re-enable all active protection when done.




To re-enable your Emulation drivers, double click DeFogger to run the tool.

The application window will appear
Click the Re-enable button to re-enable your CD Emulation drivers
Click Yes to continue
A 'Finished!' message will appear
Click OK
DeFogger will now ask to reboot the machine - click OK

IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.

DaReelDeel
2010-08-12, 19:26
Hello, sorry for the late response. I have followed your instructions and here are the logs.

defogger_disable by jpshortstuff (23.02.10.1)
Log created at 12:24 on 12/08/2010 (Darlin)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-

defogger_enable by jpshortstuff (23.02.10.1)
Log created at 13:18 on 12/08/2010 (Darlin)

Parsing file...


-=E.O.F=-


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-12 13:10:51
Windows 6.0.6002 Service Pack 2
Running: 9524bskr.exe; Driver: C:\Users\Darlin\AppData\Local\Temp\pxryrpod.sys


---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [742C7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [7431A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [742CBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [742BF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [742C75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [742BE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [742F8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [742CDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [742BFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [742BFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [742B71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7434CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [742EC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [742BD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [742B6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [742B687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3272] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [742C2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b91a0f
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001e37b91a0f (not active ControlSet)
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0x2E 0xE8 0xE1 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x25 0xDA 0xEC 0x7E ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xE9 0x02 0x6C 0xFA ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0x50 0x93 0xE5 0xAB ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x01 0x3A 0x48 0xFC ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xB2 0x46 0x9A 0xE2 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xF8 0x31 0x0F 0xA9 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...

---- EOF - GMER 1.0.15 ----

ken545
2010-08-12, 19:45
Leave Defogger disabled and run GMER again this time just check your C: Drive and uncheck all except the Sections Tab


Then run this program
Download http://www.f-secure.com/en_EMEA/security/tools/blacklight/index.html Save it to your desktop

Double-click blbeta.exe
Then accept the agreement
Click > scan then > next
You'll see a list of all items found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).
Copy and paste this log in your next reply.
Don't choose the rename option yet! I want to see the log first, because legitimate items can also be present there, such as "wbemtest.exe"

DaReelDeel
2010-08-13, 23:11
Hi, I ran GMER and checked the C: Drive and unchecked all except the Sections Tab, but when it finished, the log was empty.

I ran the scan, it didn't detect anything, but here is the fsbl log.

08/13/10 16:45:42 [Info]: BlackLight Engine 2.2.1092 initialized
08/13/10 16:45:42 [Info]: OS: 6.0 build 6002 (Service Pack 2)
08/13/10 16:45:43 [Note]: 7019 4
08/13/10 16:45:43 [Note]: 7005 0
08/13/10 16:50:12 [Note]: 7006 0
08/13/10 16:50:12 [Note]: 7027 0
08/13/10 16:50:12 [Note]: 7035 0
08/13/10 16:50:13 [Note]: 7026 0
08/13/10 16:50:13 [Note]: 7026 0
08/13/10 16:50:15 [Note]: FSRAW library version 1.7.1024
08/13/10 16:51:58 [Note]: 4015 80354
08/13/10 16:51:58 [Note]: 4027 80354 196608
08/13/10 16:51:58 [Note]: 4020 78928 262144
08/13/10 16:51:58 [Note]: 4018 78928 262144
08/13/10 16:53:25 [Note]: 4015 9344
08/13/10 16:53:25 [Note]: 4027 9344 65536
08/13/10 16:53:25 [Note]: 4020 36 65536
08/13/10 16:53:25 [Note]: 4018 36 65536
08/13/10 17:06:26 [Note]: 2000 1012
08/13/10 17:06:52 [Note]: 7007 0

ken545
2010-08-14, 02:07
Wow, this bugger is hard to track down


First drag Combofix to the trash and download a fresh copy

Download ComboFix from one of these locations:

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)

* IMPORTANT !!! Save ComboFix.exe to your Desktop


Backup Your Registry with ERUNT:
Download erunt.zip to your Desktop from here:
http://aumha.org/downloads/erunt.zip
Right-click erunt.zip, select Extract All... and follow the prompts to extract ERUNT to a new folder on your Desktop
Inside the new folder, double-click ERUNT.exe to start the program
OK all the prompts to back up your registry to the default location.Note: to restore your registry, go to the backup folder and start ERDNT.exe




Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above Folder::




Folder::
c:\program files\SGPSA

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FBSSA"=-


Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

http://i24.photobucket.com/albums/c30/ken545/CFScriptB-4.gif


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

DaReelDeel
2010-08-14, 20:55
Hi. Here is the combofix log.

ComboFix 10-08-14.01 - Darlin 14/08/2010 14:32:08.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2814.2009 [GMT -4:00]
Running from: c:\users\Darlin\Desktop\ComboFix.exe
Command switches used :: c:\users\Darlin\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-07-14 to 2010-08-14 )))))))))))))))))))))))))))))))
.

2010-08-14 18:40 . 2010-08-14 18:40 -------- d-----w- c:\users\TEMP\AppData\Local\temp
2010-08-14 18:40 . 2010-08-14 18:40 -------- d-----w- c:\users\TEMP.Darlin-PC\AppData\Local\temp
2010-08-14 18:40 . 2010-08-14 18:40 -------- d-----w- c:\users\TEMP.Darlin-PC.000\AppData\Local\temp
2010-08-14 18:40 . 2010-08-14 18:40 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-08-14 18:40 . 2010-08-14 18:40 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-08-14 18:40 . 2010-08-14 18:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-14 18:40 . 2010-08-14 18:40 -------- d-----w- c:\users\Bhing or J.A\AppData\Local\temp
2010-08-12 01:05 . 2010-05-27 20:08 81920 ----a-w- c:\windows\system32\iccvid.dll
2010-08-12 01:05 . 2010-06-29 15:47 834048 ----a-w- c:\windows\system32\wininet.dll
2010-08-12 01:05 . 2010-06-28 16:13 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-08-12 01:05 . 2010-06-11 16:16 274944 ----a-w- c:\windows\system32\schannel.dll
2010-08-12 01:04 . 2010-06-21 13:37 2037760 ----a-w- c:\windows\system32\win32k.sys
2010-08-12 01:04 . 2010-06-18 17:31 36864 ----a-w- c:\windows\system32\rtutils.dll
2010-08-12 01:04 . 2010-06-08 17:35 3600768 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-08-12 01:04 . 2010-06-08 17:35 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-08-12 01:04 . 2010-06-11 16:15 1248768 ----a-w- c:\windows\system32\msxml3.dll
2010-08-12 01:04 . 2010-06-18 15:04 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-12 01:04 . 2010-06-18 15:04 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-08-12 01:04 . 2010-06-16 16:04 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-03 15:53 . 2010-08-03 15:54 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-08-01 20:15 . 2010-08-01 20:15 -------- d-----w- c:\program files\iPod
2010-08-01 20:08 . 2010-08-01 20:08 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-08-01 03:09 . 2010-08-01 03:09 -------- d-----w- c:\users\Darlin\AppData\Local\Yahoo
2010-08-01 03:04 . 2010-08-03 15:55 -------- d-----w- c:\programdata\Yahoo! Companion
2010-08-01 03:03 . 2010-08-01 03:04 -------- d-----w- c:\programdata\Yahoo!
2010-08-01 03:03 . 2010-04-20 20:45 607472 ----a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2010-07-31 19:24 . 2010-07-31 19:24 -------- d-----w- C:\_OTM
2010-07-22 18:17 . 2010-07-22 18:17 -------- d-----w- c:\program files\Trend Micro
2010-07-22 17:01 . 2010-07-22 17:01 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-07-19 18:09 . 2010-07-19 18:09 -------- d-----w- C:\_OTL
2010-07-18 19:12 . 2010-07-18 19:12 -------- d-----w- c:\users\Darlin\AppData\Local\Apple
2010-07-18 18:54 . 2010-07-19 18:56 -------- d-----w- c:\users\Darlin\AppData\Local\Adobe
2010-07-18 17:28 . 2010-07-18 17:28 -------- d-----w- c:\users\Darlin\AppData\Local\Apple Computer
2010-07-18 16:48 . 2010-07-18 16:48 -------- d-----w- c:\users\Darlin\AppData\Roaming\Malwarebytes
2010-07-18 16:48 . 2010-07-18 16:48 -------- d-----w- c:\programdata\Malwarebytes
2010-07-18 16:48 . 2010-07-21 18:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-14 17:04 . 2009-08-14 18:57 -------- d-----w- c:\program files\Microsoft Works
2010-08-14 17:01 . 2009-08-14 18:59 -------- d-----w- c:\programdata\Microsoft Help
2010-08-14 16:54 . 2009-09-05 23:39 48670 ----a-w- c:\programdata\nvModes.dat
2010-08-14 05:09 . 2008-08-11 12:18 12 ----a-w- c:\windows\bthservsdp.dat
2010-08-13 17:40 . 2008-08-11 10:56 62236 ----a-w- c:\windows\system32\perfh00C.dat
2010-08-13 17:40 . 2008-08-11 10:56 19286 ----a-w- c:\windows\system32\perfc00C.dat
2010-08-13 17:37 . 2009-08-24 20:51 1356 ----a-w- c:\users\Darlin\AppData\Local\d3d9caps.dat
2010-08-12 13:44 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-07 18:16 . 2009-09-11 20:45 -------- d-----w- c:\programdata\HP Product Assistant
2010-08-07 18:16 . 2009-08-22 00:41 -------- d-----w- c:\program files\Microsoft
2010-08-01 20:15 . 2010-06-20 19:29 -------- d-----w- c:\program files\iTunes
2010-08-01 20:15 . 2009-08-21 23:38 -------- d-----w- c:\program files\Common Files\Apple
2010-08-01 03:05 . 2009-09-07 21:28 -------- d-----w- c:\users\Darlin\AppData\Roaming\Yahoo!
2010-08-01 03:04 . 2008-08-11 14:32 -------- d-----w- c:\program files\Yahoo!
2010-07-20 18:28 . 2010-07-11 21:16 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-07-18 00:48 . 2009-08-21 23:44 -------- d-----w- c:\users\Darlin\AppData\Roaming\LimeWire
2010-07-18 00:44 . 2009-08-21 23:40 -------- d-----w- c:\program files\LimeWire
2010-07-14 02:07 . 2009-08-14 18:56 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-12 16:25 . 2010-07-12 16:25 -------- d-----w- c:\program files\Safer Networking
2010-07-12 13:25 . 2010-07-12 13:25 8 ----a-w- c:\users\Darlin\AppData\Roaming\vdnxlf.dat
2010-07-12 01:18 . 2010-07-11 21:16 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-07-11 23:54 . 2010-07-11 23:54 -------- d-----w- c:\program files\TweetDeck
2010-07-11 18:14 . 2010-07-11 18:14 -------- d-sh--w- c:\programdata\SMACCEEAV
2010-07-11 17:54 . 2009-12-30 23:37 -------- d-----w- c:\users\Darlin\AppData\Roaming\vlc
2010-07-10 03:20 . 2010-07-10 03:20 88576 --sha-r- c:\users\Darlin\AppData\Roaming\nb-NOM.dll
2010-07-10 03:20 . 2010-07-10 03:20 88576 --sha-r- c:\users\Darlin\AppData\Roaming\nb-NOM.dll
2010-06-25 15:15 . 2009-08-24 21:08 -------- d-----w- c:\program files\Microsoft.NET
2010-06-23 17:56 . 2009-08-22 01:22 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-20 19:24 . 2010-06-20 19:24 -------- d-----w- c:\program files\Bonjour
2010-06-14 16:08 . 2010-06-29 20:36 103424 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2010-06-14 16:08 . 2010-06-29 20:36 545280 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2010-06-14 16:08 . 2010-06-29 20:36 4687360 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
2010-06-14 16:08 . 2010-06-29 20:36 425984 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2010-06-14 16:08 . 2010-06-29 20:36 152064 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2010-06-14 16:08 . 2010-06-29 20:36 4687872 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
2010-06-14 16:08 . 2010-06-29 20:36 57856 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2010-06-08 21:01 . 2009-08-21 22:23 77944 ----a-w- c:\users\Darlin\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-26 17:06 . 2010-06-10 18:58 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-10 18:58 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-21 18:14 . 2009-10-03 03:00 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-03-10 23:05 . 2009-10-03 04:02 59232800 --sha-w- c:\windows\System32\drivers\fidbox.dat
2008-08-11 10:58 . 2008-08-11 10:58 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( SnapShot@2010-07-18_01.05.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-01 03:03 . 2010-08-01 03:03 65536 c:\windows\winsxs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.4053_none_3b0e32bdc9afe437\vcomp.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 49152 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80KOR.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 49152 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80JPN.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 61440 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80ITA.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 61440 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80FRA.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 61440 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80ESP.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 57344 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80ENU.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 65536 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80DEU.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 45056 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80CHT.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 40960 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80CHS.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 57856 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfcm80u.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 69632 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfcm80.dll
+ 2010-08-12 01:05 . 2010-05-28 16:14 81920 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6002.22414_none_6f0c0c64eeb82f1d\iccvid.dll
+ 2010-08-12 01:05 . 2010-05-27 20:08 81920 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6002.18263_none_6e4b5dcdd5c4048a\iccvid.dll
+ 2010-08-12 01:05 . 2010-05-27 19:11 81920 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6001.22702_none_6d2e69d4f18b8b5a\iccvid.dll
+ 2010-08-12 01:05 . 2010-05-27 19:16 81920 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6001.18483_none_6c4f4a27d8adea21\iccvid.dll
+ 2010-08-12 01:04 . 2010-06-18 14:50 99328 c:\windows\winsxs\x86_microsoft-windows-smbserver-common_31bf3856ad364e35_6.0.6001.22715_none_045a07e92948400f\srvnet.sys
+ 2010-08-12 01:04 . 2010-06-18 18:00 36864 c:\windows\winsxs\x86_microsoft-windows-rasrtutils_31bf3856ad364e35_6.0.6002.22427_none_0f77105600c85cb8\rtutils.dll
+ 2010-08-12 01:04 . 2010-06-18 17:31 36864 c:\windows\winsxs\x86_microsoft-windows-rasrtutils_31bf3856ad364e35_6.0.6002.18274_none_0eb4612ae7d5ff77\rtutils.dll
+ 2010-08-12 01:04 . 2010-06-18 16:38 36352 c:\windows\winsxs\x86_microsoft-windows-rasrtutils_31bf3856ad364e35_6.0.6001.22715_none_0d996dc6039bb8f5\rtutils.dll
+ 2010-08-12 01:04 . 2010-06-18 16:43 36352 c:\windows\winsxs\x86_microsoft-windows-rasrtutils_31bf3856ad364e35_6.0.6001.18495_none_0cb94dceeabefe65\rtutils.dll
+ 2010-08-12 01:04 . 2010-06-16 15:56 98192 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22713_none_cda6490a43adceb3\FWPKCLNT.SYS
+ 2010-08-12 01:04 . 2010-06-17 18:30 23552 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.22426_none_f4c2683b236c5a9c\WMM2EXT.dll
+ 2009-09-17 20:22 . 2009-04-11 06:28 23040 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.18273_none_f3ffb9100a79fd5b\WMM2EXT.dll
+ 2010-08-12 01:04 . 2010-06-17 17:24 23552 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.22714_none_f2e4c5ab263fb6d9\WMM2EXT.dll
+ 2006-11-02 12:36 . 2006-11-02 12:36 23040 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.18494_none_f204a5b40d62fc49\WMM2EXT.dll
+ 2010-08-12 01:04 . 2010-06-16 14:01 31232 c:\windows\winsxs\x86_microsoft-windows-l..istry-support-tcpip_31bf3856ad364e35_6.0.6002.22425_none_887cb1b81bbc94f9\tcpipreg.sys
+ 2010-08-12 01:05 . 2010-06-28 14:52 26624 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22720_none_2fd60860332c475f\ieUnatt.exe
+ 2010-06-10 18:58 . 2010-05-04 16:53 26624 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18498_none_2f08baa51a403b96\ieUnatt.exe
+ 2010-08-12 01:05 . 2010-06-28 14:52 48128 c:\windows\winsxs\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.22720_none_f3e18ed7d35462d7\mshtmler.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 78336 c:\windows\winsxs\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.22720_none_f3e18ed7d35462d7\ieencode.dll
+ 2006-11-02 07:33 . 2006-11-02 07:33 48128 c:\windows\winsxs\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.18498_none_f314411cba68570e\mshtmler.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 78336 c:\windows\winsxs\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.18498_none_f314411cba68570e\ieencode.dll
+ 2010-08-12 01:05 . 2010-06-28 16:24 72704 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.22720_none_aea62a241ff3b022\admparse.dll
+ 2008-01-21 02:23 . 2008-01-21 02:23 72704 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.18498_none_add8dc690707a459\admparse.dll
+ 2010-08-12 01:05 . 2010-06-29 16:05 64512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22434_none_043c9ef8b82baeed\WininetPlugin.dll
+ 2010-08-12 01:05 . 2010-06-29 16:00 27648 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22434_none_043c9ef8b82baeed\jsproxy.dll
+ 2009-08-22 16:08 . 2009-04-11 06:28 64512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18278_none_038bc1bf9f2ae71c\WininetPlugin.dll
+ 2009-08-22 16:08 . 2009-04-11 06:28 27648 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18278_none_038bc1bf9f2ae71c\jsproxy.dll
+ 2010-08-12 01:05 . 2010-06-28 16:30 64512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22720_none_025cfbd4bb00d87c\WininetPlugin.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 28160 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22720_none_025cfbd4bb00d87c\jsproxy.dll
+ 2008-08-11 11:02 . 2008-08-11 11:02 64512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18498_none_018fae19a214ccb3\WininetPlugin.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 28160 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18498_none_018fae19a214ccb3\jsproxy.dll
+ 2008-01-21 01:58 . 2010-08-14 16:56 74548 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-08-21 22:24 . 2010-08-14 16:57 18080 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1042238982-2704989617-889929576-1000_UserData.bin
+ 2010-03-26 01:30 . 2010-03-26 01:30 42368 c:\windows\System32\drivers\MpNWMon.sys
+ 2007-09-02 11:55 . 2010-08-14 16:53 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-08-09 17:58 . 2010-08-14 16:53 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-07-12 02:45 . 2010-07-18 00:25 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-09-02 11:55 . 2010-07-18 00:25 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-09-02 11:55 . 2010-08-14 16:53 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-07-07 00:05 . 2010-08-13 17:38 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-07-07 00:05 . 2010-07-14 21:17 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-07-07 00:05 . 2010-08-13 17:38 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-07-07 00:05 . 2010-07-14 21:17 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-07-07 00:05 . 2010-08-13 17:38 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-07-07 00:05 . 2010-07-14 21:17 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-08-21 22:31 . 2010-08-13 14:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-08-21 22:31 . 2010-07-17 14:47 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-08-21 22:31 . 2010-07-17 14:47 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-08-21 22:31 . 2010-08-13 14:14 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-08-21 22:31 . 2010-08-13 14:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-08-21 22:31 . 2010-07-17 14:47 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-08-24 21:11 . 2010-06-11 17:22 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-08-24 21:11 . 2010-08-14 17:01 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-08-24 21:11 . 2010-06-11 17:22 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-08-24 21:11 . 2010-08-14 17:01 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-08-24 21:11 . 2010-08-14 17:01 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
- 2009-08-24 21:11 . 2010-06-11 17:22 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
- 2010-06-11 17:21 . 2010-06-11 17:21 35600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2010-08-12 13:44 . 2010-08-12 13:44 35600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2009-08-14 18:58 . 2010-08-14 17:05 25214 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\MSWorks.exe
- 2009-08-14 18:58 . 2009-08-22 17:31 25214 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\MSWorks.exe
+ 2006-10-27 19:11 . 2006-10-27 19:11 21264 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\WRD12EXE.EXE
+ 2010-08-13 14:54 . 2010-08-13 14:54 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\cf552934b75cb6b61f08e3354af8ab38\UIAutomationProvider.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\f393e672479ce6ba2f7dfb5e4f3116b7\System.Windows.Presentation.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\c5cd985c876a7bffc61898614694059c\System.Web.DynamicData.Design.ni.dll
+ 2010-08-13 14:55 . 2010-08-13 14:55 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\04bea9cca189a163d0c16e891ad2fdc8\System.ComponentModel.DataAnnotations.ni.dll
+ 2010-08-13 14:55 . 2010-08-13 14:55 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\a899daa177f7bf5c6958dc5969e3a3de\System.AddIn.Contract.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 44032 c:\windows\assembly\NativeImages_v2.0.50727_32\stdole\e6acb23a203e892f501d0924fcc12f2c\stdole.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\156b0418acf284f30f7602a8378b52fd\PresentationFontCache.ni.exe
+ 2010-08-13 14:54 . 2010-08-13 14:54 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5d23c64bac1fd4b0b2bcb1b9d83e6cf6\PresentationCFFRasterizer.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:54 79872 c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\b8c20b6ea36a8097e743cd22a16de151\napcrypt.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\c648ec7ca268d909186339d7002c0810\Microsoft.Vsa.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\8133699911f51e80280dfeab3e5d7ab4\Microsoft.VisualC.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\a356e8fb2f59ff46079840306184cbcb\Microsoft.Build.Framework.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\3c2132d7b78b099112e669342aff5524\Microsoft.Build.Framework.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 68608 c:\windows\assembly\NativeImages_v2.0.50727_32\loadmxf\406368ba3f73633200eea9195292a828\loadmxf.ni.exe
+ 2010-08-13 14:52 . 2010-08-13 14:52 57856 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\5602e95333639ce92b0dd1ea5d7fde7a\ehiUserXp.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiReplay\a46cac19a4d8b6b690fdf79b3617f292\ehiReplay.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 23552 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtCOM\4c5668bbcf91950113bf75e5a31a4dc4\ehiExtCOM.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtCOM\a5996401de2fe555bf9f1a3356603c62\ehExtCOM.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\1885a95e9314f393e86670da9930e08f\dfsvc.ni.exe
+ 2010-08-13 14:49 . 2010-08-13 14:49 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2565dad071661e3881888abd594e9e9d\Accessibility.ni.dll
+ 2010-08-12 01:04 . 2010-06-11 16:31 2048 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6002.22422_none_8acabb6dad2870a4\msxml3r.dll
+ 2006-11-02 08:26 . 2006-11-02 09:41 2048 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6002.18269_none_8a1cdf129424f4d8\msxml3r.dll
+ 2010-08-12 01:04 . 2010-06-11 15:25 2048 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.22709_none_8900eb63afeb94ff\msxml3r.dll
+ 2006-11-02 08:26 . 2006-11-02 09:41 2048 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.18490_none_880cf8e6971f1251\msxml3r.dll
+ 2010-02-15 15:36 . 2010-07-24 14:47 6700 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1042238982-2704989617-889929576-1001_UserData.bin
+ 2010-07-24 23:37 . 2010-07-24 23:37 9560 c:\windows\System32\networklist\icons\{C9BA03F1-AD2D-44A0-8C13-3DEEA1DAADD3}_48.bin
+ 2010-07-24 23:37 . 2010-07-24 23:37 4280 c:\windows\System32\networklist\icons\{C9BA03F1-AD2D-44A0-8C13-3DEEA1DAADD3}_32.bin
+ 2010-07-24 23:37 . 2010-07-24 23:37 2456 c:\windows\System32\networklist\icons\{C9BA03F1-AD2D-44A0-8C13-3DEEA1DAADD3}_24.bin
+ 2010-07-25 04:25 . 2010-07-25 04:25 9560 c:\windows\System32\networklist\icons\{B3E9DFD4-84B2-407F-9965-812B2C5003A0}_48.bin
+ 2010-07-25 04:25 . 2010-07-25 04:25 4280 c:\windows\System32\networklist\icons\{B3E9DFD4-84B2-407F-9965-812B2C5003A0}_32.bin
+ 2010-07-25 04:25 . 2010-07-25 04:25 2456 c:\windows\System32\networklist\icons\{B3E9DFD4-84B2-407F-9965-812B2C5003A0}_24.bin
+ 2010-07-25 00:17 . 2010-07-25 00:17 9560 c:\windows\System32\networklist\icons\{1601C27C-A7FB-4062-9D6C-0B415F13E4A1}_48.bin
+ 2010-07-25 00:17 . 2010-07-25 00:17 4280 c:\windows\System32\networklist\icons\{1601C27C-A7FB-4062-9D6C-0B415F13E4A1}_32.bin
+ 2010-07-25 00:17 . 2010-07-25 00:17 2456 c:\windows\System32\networklist\icons\{1601C27C-A7FB-4062-9D6C-0B415F13E4A1}_24.bin
- 2010-07-18 00:37 . 2010-07-18 00:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-08-14 16:53 . 2010-08-14 16:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-08-14 16:53 . 2010-08-14 16:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-07-18 00:37 . 2010-07-18 00:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-08-12 01:04 . 2010-05-19 11:41 388936 c:\windows\winsxs\x86_netfx-sos_dll_b03f5f7f11d50a3a_6.0.6002.22409_none_fcfd41ec14d22069\SOS.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 388936 c:\windows\winsxs\x86_netfx-sos_dll_b03f5f7f11d50a3a_6.0.6002.18260_none_13d1b793fb247173\SOS.dll
+ 2010-08-12 01:04 . 2010-05-19 11:39 989016 c:\windows\winsxs\x86_netfx-mscordacwks_b03f5f7f11d50a3a_6.0.6002.22409_none_142efa2b20dd4454\mscordacwks.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 989016 c:\windows\winsxs\x86_netfx-mscordacwks_b03f5f7f11d50a3a_6.0.6002.18260_none_2b036fd3072f955e\mscordacwks.dll
+ 2010-08-12 01:05 . 2010-05-28 16:14 197632 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6002.22414_none_6f0c0c64eeb82f1d\ir32_32.dll
+ 2006-11-02 12:34 . 2006-11-02 12:34 197632 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6002.18263_none_6e4b5dcdd5c4048a\ir32_32.dll
+ 2010-08-12 01:05 . 2010-05-27 19:11 197632 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6001.22702_none_6d2e69d4f18b8b5a\ir32_32.dll
+ 2006-11-02 12:34 . 2006-11-02 12:34 197632 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6001.18483_none_6c4f4a27d8adea21\ir32_32.dll
+ 2010-08-12 01:04 . 2010-06-16 16:39 912776 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22425_none_b57d8e037cb5db63\tcpip.sys
+ 2010-08-12 01:04 . 2010-06-16 16:04 905088 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18272_none_b4baded863c37e22\tcpip.sys
+ 2010-08-12 01:04 . 2010-06-16 15:55 902032 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys
+ 2010-08-12 01:04 . 2010-06-16 15:59 898952 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18493_none_b2bfcb7c66ac7d10\tcpip.sys
+ 2010-08-12 01:04 . 2010-06-18 15:14 145408 c:\windows\winsxs\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6002.22427_none_dc4e15b40cc980e1\srv2.sys
+ 2010-08-12 01:04 . 2010-06-18 15:04 144896 c:\windows\winsxs\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6002.18274_none_db8b6688f3d723a0\srv2.sys
+ 2010-08-12 01:04 . 2010-06-18 14:51 145408 c:\windows\winsxs\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6001.22715_none_da7073240f9cdd1e\srv2.sys
+ 2010-08-12 01:04 . 2010-06-18 14:43 144896 c:\windows\winsxs\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6001.18495_none_d990532cf6c0228e\srv2.sys
+ 2010-08-12 01:04 . 2010-06-18 15:14 303104 c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6002.22427_none_dc58e5a00cc164f0\srv.sys
+ 2010-08-12 01:04 . 2010-06-18 15:04 302080 c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6002.18274_none_db963674f3cf07af\srv.sys
+ 2010-08-12 01:04 . 2010-06-18 14:51 303104 c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6001.22715_none_da7b43100f94c12d\srv.sys
+ 2010-08-12 01:04 . 2010-06-18 14:43 302080 c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6001.18495_none_d99b2318f6b8069d\srv.sys
+ 2010-08-12 01:05 . 2010-06-11 16:33 275456 c:\windows\winsxs\x86_microsoft-windows-security-schannel_31bf3856ad364e35_6.0.6002.22422_none_2472c5e16b952529\schannel.dll
+ 2010-08-12 01:05 . 2010-06-11 16:16 274944 c:\windows\winsxs\x86_microsoft-windows-security-schannel_31bf3856ad364e35_6.0.6002.18269_none_23c4e9865291a95d\schannel.dll
+ 2010-08-12 01:05 . 2010-06-11 15:26 274944 c:\windows\winsxs\x86_microsoft-windows-security-schannel_31bf3856ad364e35_6.0.6001.22709_none_22a8f5d76e584984\schannel.dll
+ 2010-08-12 01:05 . 2010-06-11 15:31 274432 c:\windows\winsxs\x86_microsoft-windows-security-schannel_31bf3856ad364e35_6.0.6001.18490_none_21b5035a558bc6d6\schannel.dll
+ 2010-08-12 01:04 . 2010-06-16 15:11 438272 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22713_none_cda6490a43adceb3\IKEEXT.DLL
+ 2010-08-12 01:04 . 2010-06-16 15:10 595456 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22713_none_cda6490a43adceb3\FWPUCLNT.DLL
+ 2010-08-12 01:04 . 2010-06-16 15:09 328704 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22713_none_cda6490a43adceb3\BFE.DLL
+ 2010-08-12 01:04 . 2010-06-16 15:55 220040 c:\windows\winsxs\x86_microsoft-windows-netio-infrastructure_31bf3856ad364e35_6.0.6001.22713_none_571d45f6ce707e09\netio.sys
+ 2010-08-12 01:04 . 2010-06-17 18:30 195072 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.22426_none_f4c2683b236c5a9c\WMM2AE.dll
+ 2010-08-12 01:04 . 2010-06-17 16:27 150016 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.22426_none_f4c2683b236c5a9c\MOVIEMK.exe
+ 2009-09-17 20:22 . 2009-04-11 06:28 195072 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.18273_none_f3ffb9100a79fd5b\WMM2AE.dll
+ 2010-08-12 01:04 . 2010-06-17 16:16 150016 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.18273_none_f3ffb9100a79fd5b\MOVIEMK.exe
+ 2010-08-12 01:04 . 2010-06-17 17:24 195072 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.22714_none_f2e4c5ab263fb6d9\WMM2AE.dll
+ 2010-08-12 01:04 . 2010-06-17 16:03 150016 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.22714_none_f2e4c5ab263fb6d9\MOVIEMK.exe
+ 2008-01-21 02:25 . 2008-01-21 02:25 195072 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.18494_none_f204a5b40d62fc49\WMM2AE.dll
+ 2010-08-12 01:04 . 2010-06-17 15:49 150016 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.18494_none_f204a5b40d62fc49\MOVIEMK.exe
+ 2010-08-12 01:05 . 2010-06-29 16:00 180736 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.22434_none_66f6181ac477a650\ieui.dll
+ 2010-06-10 18:58 . 2010-05-04 19:10 180736 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.18278_none_66453ae1ab76de7f\ieui.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 180736 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.22720_none_651674f6c74ccfdf\ieui.dll
+ 2008-01-21 02:24 . 2008-01-21 02:24 180736 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.18498_none_6449273bae60c416\ieui.dll
+ 2010-08-12 01:05 . 2010-06-28 16:30 129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.22720_none_4817b2b0a5b1f6d9\sqmapi.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 271360 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.22720_none_4817b2b0a5b1f6d9\iertutil.dll
+ 2008-01-21 02:24 . 2008-01-21 02:24 129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18498_none_474a64f58cc5eb10\sqmapi.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 270848 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18498_none_474a64f58cc5eb10\iertutil.dll
+ 2010-08-12 01:05 . 2010-06-28 16:29 146432 c:\windows\winsxs\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6001.22720_none_379a70832d50dc47\occache.dll
+ 2010-08-12 01:05 . 2010-06-28 16:15 146432 c:\windows\winsxs\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6001.18498_none_36cd22c81464d07e\occache.dll
+ 2010-08-12 01:05 . 2010-06-28 16:33 634656 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22720_none_2fd60860332c475f\iexplore.exe
+ 2010-08-12 01:05 . 2010-06-28 16:19 634648 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18498_none_2f08baa51a403b96\iexplore.exe
+ 2010-08-12 01:05 . 2010-06-29 16:01 477184 c:\windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6002.22434_none_4a7c94e259bd61fb\mshtmled.dll
+ 2010-08-12 01:05 . 2010-06-29 15:44 477184 c:\windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6002.18278_none_49cbb7a940bc9a2a\mshtmled.dll
+ 2010-08-12 01:05 . 2010-06-28 16:28 476672 c:\windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6001.22720_none_489cf1be5c928b8a\mshtmled.dll
+ 2010-08-12 01:05 . 2010-06-28 16:14 476672 c:\windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6001.18498_none_47cfa40343a67fc1\mshtmled.dll
+ 2010-08-12 01:05 . 2010-06-28 16:28 458240 c:\windows\winsxs\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6001.22720_none_605a92a353a42b34\msfeeds.dll
+ 2010-08-12 01:05 . 2010-06-28 16:14 458240 c:\windows\winsxs\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6001.18498_none_5f8d44e83ab81f6b\msfeeds.dll
+ 2010-08-12 01:05 . 2010-06-29 16:00 193024 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_6.0.6002.22434_none_3f17302a0866774f\iepeers.dll
+ 2010-08-12 01:05 . 2010-06-29 15:43 193024 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_6.0.6002.18278_none_3e6652f0ef65af7e\iepeers.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 193024 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_6.0.6001.22720_none_3d378d060b3ba0de\iepeers.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 193024 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_6.0.6001.18498_none_3c6a3f4af24f9515\iepeers.dll
+ 2010-08-12 01:05 . 2010-06-29 16:00 380928 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.22434_none_fde5c1d282172940\ieapfltr.dll
+ 2010-08-12 01:05 . 2010-06-29 15:43 380928 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.18278_none_fd34e4996916616f\ieapfltr.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 380928 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.22720_none_fc061eae84ec52cf\ieapfltr.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 380928 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.18498_none_fb38d0f36c004706\ieapfltr.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 161792 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.22720_none_aea62a241ff3b022\ieakui.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 230400 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.22720_none_aea62a241ff3b022\ieaksie.dll
+ 2006-11-02 07:27 . 2006-11-02 09:39 161792 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.18498_none_add8dc690707a459\ieakui.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 230400 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.18498_none_add8dc690707a459\ieaksie.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 389120 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6001.22720_none_74c474d070aaf943\iedkcs32.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 389120 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6001.18498_none_73f7271557beed7a\iedkcs32.dll
+ 2010-08-12 01:05 . 2010-06-29 16:05 834560 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22434_none_043c9ef8b82baeed\wininet.dll
+ 2010-08-12 01:05 . 2010-06-29 15:47 834048 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18278_none_038bc1bf9f2ae71c\wininet.dll
+ 2010-08-12 01:05 . 2010-06-28 16:30 834048 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22720_none_025cfbd4bb00d87c\wininet.dll
+ 2010-08-12 01:05 . 2010-06-28 16:17 833024 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18498_none_018fae19a214ccb3\wininet.dll
+ 2010-08-12 01:05 . 2010-06-28 16:28 671232 c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.22720_none_e139aefb95a07158\mstime.dll
+ 2010-08-12 01:05 . 2010-06-28 16:14 671232 c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.18498_none_e06c61407cb4658f\mstime.dll
+ 2009-09-17 20:22 . 2009-03-30 04:42 311296 c:\windows\winsxs\msil_mscorlib.resources_b77a5c561934e089_6.0.6002.22409_fr-fr_a8afccd9f1058ad5\mscorlib.Resources.dll
+ 2009-09-17 20:22 . 2009-03-30 04:42 311296 c:\windows\winsxs\msil_mscorlib.resources_b77a5c561934e089_6.0.6002.18260_fr-fr_bf844281d757dbdf\mscorlib.Resources.dll
+ 2009-08-22 23:27 . 2010-08-06 02:04 180088 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2009-08-22 00:25 . 2010-08-13 17:37 321868 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2006-11-02 13:05 . 2010-08-14 16:57 100812 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 10:33 . 2010-08-13 17:40 742954 c:\windows\System32\perfc009.dat
+ 2010-08-12 01:05 . 2010-06-29 15:44 477184 c:\windows\System32\mshtmled.dll
- 2010-06-10 18:58 . 2010-05-04 19:12 477184 c:\windows\System32\mshtmled.dll
+ 2010-08-01 03:04 . 2010-08-01 03:04 231888 c:\windows\System32\Macromed\Flash\FlashUtil10h_ActiveX.exe
+ 2010-08-01 03:04 . 2010-08-01 03:04 311760 c:\windows\System32\Macromed\Flash\FlashUtil10h_ActiveX.dll
- 2010-06-10 18:58 . 2010-05-04 19:10 193024 c:\windows\System32\iepeers.dll
+ 2010-08-12 01:05 . 2010-06-29 15:43 193024 c:\windows\System32\iepeers.dll
+ 2010-08-12 01:05 . 2010-06-29 15:43 380928 c:\windows\System32\ieapfltr.dll
- 2010-06-10 18:58 . 2010-05-04 19:10 380928 c:\windows\System32\ieapfltr.dll
+ 2006-11-02 12:47 . 2010-08-12 17:15 311040 c:\windows\System32\FNTCACHE.DAT
- 2006-11-02 12:47 . 2010-07-11 23:19 311040 c:\windows\System32\FNTCACHE.DAT
+ 2010-03-26 01:30 . 2010-03-26 01:30 151216 c:\windows\System32\drivers\MpFilter.sys
+ 2010-08-06 17:21 . 2010-08-06 17:31 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2010-04-29 23:00 . 2009-09-04 06:59 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2010-08-03 15:54 . 2010-08-03 15:54 272384 c:\windows\Installer\24d074.msi
+ 2010-08-03 15:53 . 2010-08-03 15:53 254976 c:\windows\Installer\24d06e.msi
+ 2010-08-01 03:03 . 2010-08-01 03:03 424960 c:\windows\Installer\1a18a2d.msi

DaReelDeel
2010-08-14, 20:55
Here is the second half of the log.

c:\windows\Installer\{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}\iTunesIco.exe
+ 2009-08-24 21:11 . 2010-08-14 17:01 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-08-24 21:11 . 2010-06-11 17:22 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-08-24 21:11 . 2010-06-11 17:22 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-08-24 21:11 . 2010-08-14 17:01 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-08-24 21:11 . 2010-08-14 17:01 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2009-08-24 21:11 . 2010-06-11 17:22 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2009-08-24 21:11 . 2010-06-11 17:22 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-08-24 21:11 . 2010-08-14 17:01 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2009-08-14 18:58 . 2009-08-22 17:31 693600 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksWP.exe
+ 2009-08-14 18:58 . 2010-08-14 17:05 693600 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksWP.exe
+ 2009-08-14 18:58 . 2010-08-14 17:05 947552 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\wksss.exe
- 2009-08-14 18:58 . 2009-08-22 17:31 947552 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\wksss.exe
- 2009-08-14 18:58 . 2009-08-22 17:31 709984 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksCal.exe
+ 2009-08-14 18:58 . 2010-08-14 17:05 709984 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksCal.exe
+ 2007-06-21 05:04 . 2007-06-21 05:04 173408 c:\windows\Installer\$PatchCache$\Managed\0DC8CB51B56A0D742ADD098A4295F08A\9.7.621\F378_WkProof.dll
+ 2007-06-22 05:48 . 2007-06-22 05:48 972128 c:\windows\Installer\$PatchCache$\Managed\0DC8CB51B56A0D742ADD098A4295F08A\9.7.621\F20987_wkwpqd.dll
+ 2007-06-21 05:04 . 2007-06-21 05:04 161120 c:\windows\Installer\$PatchCache$\Managed\0DC8CB51B56A0D742ADD098A4295F08A\9.7.621\F20985_wkwpqrtf.dll
+ 2010-08-13 14:59 . 2010-08-13 14:59 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\96e88a5f9dbbcfdb736568e69d43cff9\WsatConfig.ni.exe
+ 2010-08-13 14:59 . 2010-08-13 14:59 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\60ecc5c53d5ba77c9c40d01e5af58246\WindowsFormsIntegration.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\9df5076cb69aeb3101fd624ad4f499b0\UIAutomationTypes.ni.dll
+ 2010-08-13 14:59 . 2010-08-13 14:59 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\a45d53185f7690a65a8c1bb758f14d40\UIAutomationClient.ni.dll
+ 2010-08-13 14:59 . 2010-08-13 14:59 235520 c:\windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\282b33969e987f3c2dafaa2e5c5f728b\TaskScheduler.ni.dll
+ 2010-08-13 14:59 . 2010-08-13 14:59 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\5fc514748fdde7be8871044e0102f208\System.Xml.Linq.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\07efa566dfb7e3367085d310e55f677f\System.Web.Routing.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\7735dbcd7f5280a01ec1e9ebfbfd9564\System.Web.RegularExpressions.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\cb9bb30db142c3f856202fae6efd755d\System.Web.Extensions.Design.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\309dc95f10521331d7813e54946d164d\System.Web.Entity.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\3bbf6be655c227fed53b4d7c1758b741\System.Web.Entity.Design.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\2598e27d1f0d6cf86b1f2ea605379b49\System.Web.DynamicData.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\371304d76734059d69e93c7c7c5f3f87\System.Web.Abstractions.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\9f38a2b0adadce82d09209811af4043e\System.Transactions.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\33891c1f2a8120a3b7bb463cc6f97438\System.ServiceProcess.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\b5d2d15c9453a01b8761bf19afd1ccb6\System.Security.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\e6beeb0283ef0a1e2c1b65fa05bf2876\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6c2e750e360af7a54a6713cf66920869\System.Runtime.Remoting.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\a151e0db5d00543aecc4eaae05d8c7b1\System.Net.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\dab204b4ba2212740f4c0f1563f37696\System.Messaging.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\7187abb11454f0dece04ed04dea43929\System.Management.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\4aead7d6a1a6ab1c9e73c6c5f0dc8c1b\System.Management.Instrumentation.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\937481e0aef42993453207c3a0f8bc55\System.IO.Log.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\96102bf56b1e4d8924eac8818ea68820\System.IdentityModel.Selectors.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\32e6bf88bb0dcdad040abc8ad97cab83\System.EnterpriseServices.Wrapper.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\32e6bf88bb0dcdad040abc8ad97cab83\System.EnterpriseServices.ni.dll
+ 2010-08-12 17:27 . 2010-08-12 17:27 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\373c6551ad640a1de178a5f7becd41fd\System.Drawing.Design.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\a96524c7c097d56fcc70dd505debcc1d\System.DirectoryServices.Protocols.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\51747c9fabada4a2f0c4def76613c6cd\System.DirectoryServices.AccountManagement.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\eed47170f4b867402cbb44915f45f298\System.Data.Services.Design.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3097f90ab5e29e5eb0d8c433000acf16\System.Data.Services.Client.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\6c294d7fba114025a3f4f330cf541c7e\System.Data.Entity.Design.ni.dll
+ 2010-08-13 14:55 . 2010-08-13 14:55 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\e404c37e48fe5eafa395333520045a24\System.Data.DataSetExtensions.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\ca467e23bbfcffac8809b9e21dcbd9a6\System.Configuration.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\5904e3d51b6d7628ed01c0f5345e5ff6\System.Configuration.Install.ni.dll
+ 2010-08-13 14:55 . 2010-08-13 14:55 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\b56f5ff3e814e0a4e83231153cde0d0e\System.AddIn.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\aa85f92b421a8ca0af79b376f37e51fb\sysglobl.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\3229c727887ebc9f4065e0cd12d05e2d\SMSvcHost.ni.exe
+ 2010-08-13 14:51 . 2010-08-13 14:51 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\93c834845cbbddae777d614b2d0f8f95\SMDiagnostics.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\70e0d7f2c857c3566aa82053c199e696\ServiceModelReg.ni.exe
+ 2010-08-12 17:20 . 2010-08-12 17:20 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\bc66d228134a22312c0e1b66dedb6355\PresentationFramework.Royale.ni.dll
+ 2010-08-12 17:20 . 2010-08-12 17:20 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\6d23ebf0175664d7a8579e2762cae3d0\PresentationFramework.Luna.ni.dll
+ 2010-08-12 17:19 . 2010-08-12 17:19 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\60e971a87bbff522188ae9c6985f40b9\PresentationFramework.Aero.ni.dll
+ 2010-08-12 17:19 . 2010-08-12 17:19 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2748627bab39e441420b5cdf329c6be1\PresentationFramework.Classic.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 724992 c:\windows\assembly\NativeImages_v2.0.50727_32\napsnap\2f105c5bb0901401129bf03e8e71cc94\napsnap.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 110080 c:\windows\assembly\NativeImages_v2.0.50727_32\napinit\974e310546d192d00c5fd8b1f9650e79\napinit.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 115712 c:\windows\assembly\NativeImages_v2.0.50727_32\naphlpr\61baa41cfd0504ef33ec7e13df3c170d\naphlpr.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\2a571636031f617332a0abbaf5c3f084\MSBuild.ni.exe
+ 2010-08-13 14:52 . 2010-08-13 14:52 285184 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\d986a5602301ae525f12aab511e93c4e\MMCFxCommon.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\28d7f58060857b4cf2c63be26048cb65\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 227840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\9c02ac74b4f52ae5cf0f2660be7810be\Microsoft.MediaCenter.Shell.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 659968 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\5a227376c67a644a05e9154d3d850b2d\Microsoft.MediaCenter.Sports.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\15ee9ad3f763e25098d89605ba99702c\Microsoft.MediaCenter.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 558592 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\6f1906228f69deb64dd61d0e5131e503\Microsoft.ManagementConsole.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\6c824af5aeae3dd7beb68403481e4067\Microsoft.Build.Utilities.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\287c1915da744bdf10ec4feb443d17cb\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 888320 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\b6fc09b42edaabcc0f8f6ed5cd825736\Microsoft.Build.Engine.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\9684b6d4d7467b94b04faf8e477bab0f\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 238592 c:\windows\assembly\NativeImages_v2.0.50727_32\Mcx2Dvcs\c3c8102a4cbdea2ab1aa4d89bf86ed92\Mcx2Dvcs.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 254976 c:\windows\assembly\NativeImages_v2.0.50727_32\mcupdate\f07dac825e440c785869077bb7dcefed\mcupdate.ni.exe
+ 2010-08-13 14:52 . 2010-08-13 14:52 225280 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstoredb\45534af3333fa890ea204a596ae1e5e6\mcstoredb.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 642560 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstore\591041993cfe14fe8dcbea7d2081908f\mcstore.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 543744 c:\windows\assembly\NativeImages_v2.0.50727_32\EventViewer\dbb5ef49b7916ce0a2cf60ff3afb5e70\EventViewer.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 103936 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiWUapi\132b716b550c2dc96f34cdf14ed8317a\ehiWUapi.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 338432 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiwmp\b5f6733da0da72ead97a0f58e1b40df1\ehiwmp.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 797696 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiVidCtl\0804b988efb74339c7d05caec7d6a174\ehiVidCtl.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 965632 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiProxy\d51895c8f10f165aa7d9d2cdb7dc0083\ehiProxy.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 565760 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiPlay\da82144c320425d06fa6ea20372cf368\ehiPlay.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 160768 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\42a72017d8679378086420169f6ab2d6\ehiExtens.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 243200 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtHost\f1081a83479e0a0abedc41b910a01138\ehExtHost.ni.exe
+ 2010-08-13 14:52 . 2010-08-13 14:52 305152 c:\windows\assembly\NativeImages_v2.0.50727_32\ehepgdat\a2fc62ad63f3c13b83b6006db80641bd\ehepgdat.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 220160 c:\windows\assembly\NativeImages_v2.0.50727_32\ehCIR\9fc65e7d119c6abccc56530451a61e5c\ehCIR.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\df51961ed496f46601dd0bb255a31161\CustomMarshalers.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\7212937280ee06b0ef45b41651516be8\ComSvcConfig.ni.exe
+ 2010-08-13 14:49 . 2010-08-13 14:49 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\BDATunePIA\ba32856173defc992995032a2c8fe78b\BDATunePIA.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\c36ac9c6cd9b8d58c34fa0c965770c18\AspNetMMCExt.ni.dll
+ 2010-08-12 01:04 . 2010-05-19 11:41 5819728 c:\windows\winsxs\x86_netfx-mscorwks_dll_b03f5f7f11d50a3a_6.0.6002.22409_none_1b6ad74448dc3881\mscorwks.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 5813072 c:\windows\winsxs\x86_netfx-mscorwks_dll_b03f5f7f11d50a3a_6.0.6002.18260_none_323f4cec2f2e898b\mscorwks.dll
+ 2010-08-12 01:04 . 2010-05-19 11:39 4550656 c:\windows\winsxs\x86_mscorlib_b77a5c561934e089_6.0.6002.22409_none_b0c40856db54d3fc\mscorlib.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 4550656 c:\windows\winsxs\x86_mscorlib_b77a5c561934e089_6.0.6002.18260_none_c7987dfec1a72506\mscorlib.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 1093120 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfc80u.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 1105920 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfc80.dll
+ 2010-08-12 01:04 . 2010-06-21 13:47 2045952 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6002.22428_none_bb55f649b0d3b032\win32k.sys
+ 2010-08-12 01:04 . 2010-06-21 13:37 2037760 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6002.18275_none_ba93471e97e152f1\win32k.sys
+ 2010-08-12 01:04 . 2010-06-21 13:25 2036736 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6001.22716_none_b97853b9b3a70c6f\win32k.sys
+ 2010-08-12 01:04 . 2010-06-21 13:18 2036736 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6001.18496_none_b89833c29aca51df\win32k.sys
+ 2010-08-12 01:04 . 2010-06-08 18:04 3550600 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22420_none_6e8adbdfca772e22\ntoskrnl.exe
+ 2010-08-12 01:04 . 2010-06-08 18:04 3601792 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22420_none_6e8adbdfca772e22\ntkrnlpa.exe
+ 2010-08-12 01:04 . 2010-06-08 17:35 3548040 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18267_none_6ddcff84b173b256\ntoskrnl.exe
+ 2010-08-12 01:04 . 2010-06-08 17:35 3600768 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18267_none_6ddcff84b173b256\ntkrnlpa.exe
+ 2010-08-12 01:04 . 2010-06-08 16:47 3548552 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22707_none_6cc10bd5cd3a527d\ntoskrnl.exe
+ 2010-08-12 01:04 . 2010-06-08 16:47 3600784 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22707_none_6cc10bd5cd3a527d\ntkrnlpa.exe
+ 2010-08-12 01:04 . 2010-06-08 17:00 3545992 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18488_none_6be1ec28b45cb144\ntoskrnl.exe
+ 2010-08-12 01:04 . 2010-06-08 17:00 3598216 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18488_none_6be1ec28b45cb144\ntkrnlpa.exe
+ 2010-08-12 01:04 . 2010-07-13 10:54 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22447_none_f4d3f69181d85824\OESpamFilter.dat
+ 2010-08-12 01:04 . 2010-07-13 10:53 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18281_none_f419167468e092ed\OESpamFilter.dat
+ 2010-08-12 01:04 . 2010-07-13 10:53 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22729_none_f3052515849ffdcc\OESpamFilter.dat
+ 2010-08-12 01:04 . 2010-07-13 10:52 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18500_none_f28823a26b7a44ea\OESpamFilter.dat
+ 2010-08-12 01:04 . 2010-06-11 16:31 1248768 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6002.22422_none_8acabb6dad2870a4\msxml3.dll
+ 2010-08-12 01:04 . 2010-06-11 16:15 1248768 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6002.18269_none_8a1cdf129424f4d8\msxml3.dll
+ 2010-08-12 01:04 . 2010-06-11 15:25 1257472 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.22709_none_8900eb63afeb94ff\msxml3.dll
+ 2010-08-12 01:04 . 2010-06-11 15:30 1257472 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.18490_none_880cf8e6971f1251\msxml3.dll
+ 2010-08-12 01:05 . 2010-06-29 16:00 6081536 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.22434_none_66f6181ac477a650\ieframe.dll
+ 2010-08-12 01:05 . 2010-06-29 15:43 6080000 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.18278_none_66453ae1ab76de7f\ieframe.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 6072832 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.22720_none_651674f6c74ccfdf\ieframe.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 6069248 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.18498_none_6449273bae60c416\ieframe.dll
+ 2010-08-12 01:05 . 2010-06-29 16:01 3604480 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.22434_none_1596be1738821823\mshtml.dll
+ 2010-08-12 01:05 . 2010-06-29 15:44 3603456 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.18278_none_14e5e0de1f815052\mshtml.dll
+ 2010-08-12 01:05 . 2010-06-28 16:28 3588608 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22720_none_13b71af33b5741b2\mshtml.dll
+ 2010-08-12 01:05 . 2010-06-28 16:14 3586560 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18498_none_12e9cd38226b35e9\mshtml.dll
+ 2009-08-22 16:08 . 2009-06-18 06:57 2452872 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.22434_none_fde5c1d282172940\ieapfltr.dat
+ 2009-08-22 16:08 . 2009-06-18 06:57 2452872 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.18278_none_fd34e4996916616f\ieapfltr.dat
+ 2009-08-22 16:08 . 2009-06-18 06:57 2452872 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.22720_none_fc061eae84ec52cf\ieapfltr.dat
+ 2009-08-22 16:08 . 2009-06-18 06:57 2452872 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.18498_none_fb38d0f36c004706\ieapfltr.dat
+ 2010-08-12 01:05 . 2010-06-29 16:05 1176576 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6002.22434_none_b736c356ed22885a\urlmon.dll
+ 2010-08-12 01:05 . 2010-06-29 15:46 1176064 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6002.18278_none_b685e61dd421c089\urlmon.dll
+ 2010-08-12 01:05 . 2010-06-28 16:30 1175552 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.22720_none_b5572032eff7b1e9\urlmon.dll
+ 2010-08-12 01:05 . 2010-06-28 16:17 1174528 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.18498_none_b489d277d70ba620\urlmon.dll
+ 2010-08-12 01:05 . 2010-06-29 15:46 1176064 c:\windows\System32\urlmon.dll
- 2010-06-10 18:58 . 2010-05-04 19:15 1176064 c:\windows\System32\urlmon.dll
+ 2006-11-02 10:22 . 2010-08-13 02:57 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2006-11-02 10:22 . 2010-07-16 03:36 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 10:33 . 2010-08-13 17:40 2435422 c:\windows\System32\perfh009.dat
+ 2010-08-12 01:05 . 2010-06-29 15:44 3603456 c:\windows\System32\mshtml.dll
- 2010-06-10 18:58 . 2010-05-04 19:10 6080000 c:\windows\System32\ieframe.dll
+ 2010-08-12 01:05 . 2010-06-29 15:43 6080000 c:\windows\System32\ieframe.dll
+ 2006-11-02 12:47 . 2010-08-12 17:17 4296641 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
- 2006-11-02 12:47 . 2010-04-27 22:04 4296641 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
+ 2010-08-12 01:04 . 2010-05-21 10:56 5813072 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
- 2010-04-29 23:00 . 2009-09-04 06:58 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2010-07-09 21:28 . 2010-07-09 21:28 2151424 c:\windows\Installer\5ada1.msp
+ 2010-07-11 00:14 . 2010-07-11 00:14 2850816 c:\windows\Installer\5a57d.msp
+ 2010-08-01 20:16 . 2010-08-01 20:16 5731328 c:\windows\Installer\14f1dbb.msi
+ 2009-08-24 21:11 . 2010-08-14 17:01 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-08-24 21:11 . 2010-06-11 17:22 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-08-14 18:58 . 2009-08-22 17:31 1099104 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksSb.exe
+ 2009-08-14 18:58 . 2010-08-14 17:05 1099104 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksSb.exe
- 2009-08-14 18:58 . 2009-08-22 17:31 1242464 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\wksdb.exe
+ 2009-08-14 18:58 . 2010-08-14 17:05 1242464 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\wksdb.exe
+ 2007-06-22 05:44 . 2007-06-22 05:44 2901344 c:\windows\Installer\$PatchCache$\Managed\0DC8CB51B56A0D742ADD098A4295F08A\9.7.621\F22194_wksssdb.dll
+ 2006-10-27 19:11 . 2006-10-27 19:11 4235560 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\WRD12CNV.DLL
+ 2010-08-12 17:18 . 2010-08-12 17:18 3325952 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\c7397dc3e95ddda32dd9ad6c3ce38019\WindowsBase.ni.dll
+ 2010-08-13 14:59 . 2010-08-13 14:59 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\0f599411410c58b574703eb522bc318e\UIAutomationClientsideProviders.ni.dll
+ 2010-08-12 17:18 . 2010-08-12 17:18 7949824 c:\windows\assembly\NativeImages_v2.0.50727_32\System\ed6ae2749d12c4729ee43ff339de4bb8\System.ni.dll
+ 2010-08-12 17:27 . 2010-08-12 17:27 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\88593f5f0fc6de5d5f4a85aa2b1466f3\System.Xml.ni.dll
+ 2010-08-13 14:59 . 2010-08-13 14:59 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\c2f18081b5d836e6231fd79b684a6f86\System.WorkflowServices.ni.dll
+ 2010-08-12 17:27 . 2010-08-12 17:27 1911296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\dd88f37f1c35c4c449dbbdacb8c5dccc\System.Workflow.Runtime.ni.dll
+ 2010-08-12 17:27 . 2010-08-12 17:27 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\04a684bdfb5938f0052650cb253983bf\System.Workflow.ComponentModel.ni.dll
+ 2010-08-12 17:27 . 2010-08-12 17:27 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\77e3806584727e882dd8f0d04beb2abe\System.Workflow.Activities.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\2479988f1fa243fe4b9c8b261620191d\System.Web.Services.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\7f1540fb7e3f32852e885e54e032d3cb\System.Web.Mobile.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 2403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\1092e6f0382fd93a027cd450466971b1\System.Web.Extensions.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\f030a2f4334cf1d2cd15f6f0c79985ae\System.Speech.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 1705984 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\cf2b1dc50e5b12378dcc342ecb1f4624\System.ServiceModel.Web.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 2346496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\ea3e8cee7c10a120515149a633a7a2de\System.Runtime.Serialization.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\8a321bc80e196ea1a25ecc4c0ce12568\System.Printing.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\7000f5568c75ad5357d7d443e265456b\System.IdentityModel.ni.dll
+ 2010-08-12 17:27 . 2010-08-12 17:27 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\887fa2d6b76e7302b0c664effad4f91f\System.Drawing.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\9f571d6b546818ce10a382f55137eaa7\System.DirectoryServices.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\7fe837b36e9ba44dcee7b5465d17282e\System.Deployment.ni.dll
+ 2010-08-12 17:20 . 2010-08-12 17:20 6621696 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\cc009a955f4b35c344c2f9aaf453f329\System.Data.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\7916ad24cf12bd19b73abefe981a0e30\System.Data.SqlXml.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\0c5f04a4016dfaa3ac079f34bfaaf28b\System.Data.Services.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 1119232 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\fb8da45f3873169a502db3cb492b25a0\System.Data.OracleClient.ni.dll
+ 2010-08-12 17:20 . 2010-08-12 17:20 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\94d9826184cb0d2772324c098814d218\System.Data.Linq.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\17e7810a55cc31245af28625d1d8c666\System.Data.Entity.ni.dll
+ 2010-08-12 17:20 . 2010-08-12 17:20 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\f6e32268d4b0127287d722e41bb6b58b\System.Core.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 2146816 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\c56cdd40df48edbfeb58f11f8ef023b9\ReachFramework.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\c0ae6dcf0d17a79db705a0cf01c8d301\PresentationUI.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\85dfa2585edc672cf9d66573de4ca266\PresentationBuildTasks.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 2538496 c:\windows\assembly\NativeImages_v2.0.50727_32\Narrator\de94a577713ca374c08d2512d69e1643\Narrator.ni.exe
+ 2010-08-13 14:53 . 2010-08-13 14:53 1536512 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCEx\a301ed86595ddc85b07e4aab9cf4e251\MMCEx.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 6340096 c:\windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\3b25fb301c8ebd1da13b7769f6c6678e\MIGUIControls.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 1711616 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\2a92f46eb0e385a2eafd9b92ad0bedf4\Microsoft.VisualBasic.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\20ec66c02bbe2d66bfecb98b95394e02\Microsoft.Transactions.Bridge.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 5486080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\0cf5f49c556724a4506e989775020925\Microsoft.MediaCenter.UI.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\bca1f9fffa3059a8c36db7c1cd78ba8e\Microsoft.JScript.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink\e2191bf9847c0a0af1410ff266678957\Microsoft.Ink.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\a6f49ce5533655922d675c3c957106c8\Microsoft.Build.Tasks.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\95d9b86433cabf54e4a7de11daa91030\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\00969e3f4559c1a79394b1170e158cbb\Microsoft.Build.Engine.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 1732608 c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\34109895a5e9a9d3350e5662f1020279\ehRecObj.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 2130432 c:\windows\assembly\NativeImages_v2.0.50727_32\ehepg\4f4ff2af819d88ddf166a5d98417686e\ehepg.ni.dll
- 2010-04-29 23:00 . 2009-09-04 06:58 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2010-08-03 13:28 . 2010-07-26 18:04 11587072 c:\windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6002.22454_none_6e6736812864c2a8\shell32.dll
+ 2010-08-03 13:28 . 2010-07-26 15:51 11584512 c:\windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6002.18287_none_6dc028ea0f5cc58f\shell32.dll
+ 2010-08-03 13:28 . 2010-07-26 16:56 11586560 c:\windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6001.22735_none_6c9764bb2b2d4ef9\shell32.dll
+ 2010-08-03 13:28 . 2010-07-26 16:55 11581440 c:\windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6001.18505_none_6c2e35ce11f75e35\shell32.dll
+ 2010-08-12 01:05 . 2010-06-17 18:27 10926592 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.22426_none_f4c2683b236c5a9c\MOVIEMK.dll
+ 2010-08-12 01:05 . 2010-06-17 18:08 10926592 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.18273_none_f3ffb9100a79fd5b\MOVIEMK.dll
+ 2010-08-12 01:05 . 2010-06-17 17:22 10926592 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.22714_none_f2e4c5ab263fb6d9\MOVIEMK.dll
+ 2010-08-12 01:05 . 2010-06-17 17:15 10926592 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.18494_none_f204a5b40d62fc49\MOVIEMK.dll
+ 2010-08-03 13:28 . 2010-07-26 15:51 11584512 c:\windows\System32\shell32.dll
+ 2006-11-02 10:24 . 2010-08-03 18:09 35962312 c:\windows\System32\mrt.exe
+ 2010-07-11 00:06 . 2010-07-11 00:06 10120192 c:\windows\Installer\5ad7e.msp
+ 2010-08-12 17:27 . 2010-08-12 17:27 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d9ab6e29eba6cb0d8459fcbb2c40c1a7\System.Windows.Forms.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 11801088 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\e1ea6e4d25161658e08fc8d2fa64ec73\System.Web.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 17404416 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\d1cad83b4223917ed45765ee942dc824\System.ServiceModel.ni.dll
+ 2010-08-12 17:26 . 2010-08-12 17:26 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\7964468060d9f7a9b177eb1c6827936a\System.Design.ni.dll
+ 2010-08-12 17:19 . 2010-08-12 17:19 14328832 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c87cc40b22b2b014f9c0ade54773b6ea\PresentationFramework.ni.dll
+ 2010-08-12 17:19 . 2010-08-12 17:19 12216832 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\e53b9c43b17c02a75f2358a24047dd52\PresentationCore.ni.dll
+ 2010-08-12 17:18 . 2010-08-12 17:18 11490816 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\98bbdd8c400493ad228b8283665cc9da\mscorlib.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 11588096 c:\windows\assembly\NativeImages_v2.0.50727_32\ehshell\533e0c125f72bccb38eac041552250bb\ehshell.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-02-26 2289664]
"Google Update"="c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-08-21 133104]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-26 49152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-05 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"RogersServicepointAgent.exe"="c:\program files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" [2009-02-27 3228912]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-06-12 468264]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-06-01 1093208]

c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-7-31 139776]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):2f,48,75,21,55,e6,ca,01

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1ca2cdcaf95cfe9;Google Update Service (gupdate1ca2cdcaf95cfe9);c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 133104]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-04-26 361808]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-26 42368]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-05-09 43040]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-02-26 21:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-08-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-09-03 21:21]

2010-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 21:22]

2010-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 21:22]

2010-08-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job
- c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-21 23:27]

2010-08-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job
- c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-21 23:27]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
uInternet Settings,ProxyOverride = <local>;*.local
IE: {{612F6E5C-B314-4bab-93D1-D266AAFBE700} - c:\program files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe
FF - ProfilePath - c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll
FF - plugin: c:\users\Darlin\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-14 14:40
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-08-14 14:44:01
ComboFix-quarantined-files.txt 2010-08-14 18:43
ComboFix2.txt 2010-07-18 01:09

Pre-Run: 138,762,579,968 bytes free
Post-Run: 138,721,267,712 bytes free

- - End Of File - - 6056C2298D7CCC299612718DBAC27536

DaReelDeel
2010-08-14, 21:02
Here is the new HijackThis log.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:18:18 PM, on 22/07/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RogersServicepointAgent.exe] "C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" /AUTORUN
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Google Update] "C:\Users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [pacqwen] rundll32 "C:\Users\Darlin\AppData\Roaming\nb-NOM.dll",UDPNTWWWQJ
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Run YoukuDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe (file missing)
O9 - Extra 'Tools' menuitem: Youku Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: intu-qt2009 - {03947252-2355-4E9B-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1ca2cdcaf95cfe9) (gupdate1ca2cdcaf95cfe9) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 11316 bytes

ken545
2010-08-14, 21:53
It looks like something we removed earlier is came back. Disable the TeaTimer and leave it disabled, when were done I will link you to another free program to install that will do the same thing but won't get in your face as much

Do this first...Important

Disable the TeaTimer, leave it disabled, do not turn it back on until we're done or it will prevent fixes from taking

Run Spybot-S&D in Advanced Mode.
If it is not already set to do this Go to the Mode menu select "Advanced Mode"
On the left hand side, Click on Tools
Then click on the Resident Icon in the List
Uncheck "Resident TeaTimer" and OK any prompts.
Restart your computer.<--You need to do this for it to take effect

Please do not proceed until the TeaTimer is disabled




Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.


R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555

O4 - HKCU\..\Run: [pacqwen] rundll32 "C:\Users\Darlin\AppData\Roaming\nb-NOM.dll",UDPNTWWWQJ


C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies <-- Go into this folder and delete all cookies but not the cookie folder. Before you do make sure you write down user names and passwords for sites you frequent or you wont be able to access them unless you remember the passwords and usernames


Reboot and post a new HJT log please, if your still getting redirected to SearchPro let me know. I will have to have someone else look at this, I see no entries for SearchPro in any of your logs.

You never updated to IE8 ???

DaReelDeel
2010-08-15, 22:25
Hi. I have a problem. I disabled TeaTimer and restarted the computer as instructed. But when I did a system scan only and looked for the entries you asked me to delete, they weren't there. I kept doing system scans and looked at every single entry, but no luck. I just deleted the cookies and did a new system scan with a log. Here it is. Oh...and when I did updates on my laptop, I thought it updated IE to IE8. I'll try to update it again.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:20:19 PM, on 15/08/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RogersServicepointAgent.exe] "C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" /AUTORUN
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Google Update] "C:\Users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Run YoukuDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe (file missing)
O9 - Extra 'Tools' menuitem: Youku Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: intu-qt2009 - {03947252-2355-4E9B-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1ca2cdcaf95cfe9) (gupdate1ca2cdcaf95cfe9) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 10231 bytes

ken545
2010-08-15, 23:43
Run OTL and post a new log please

DaReelDeel
2010-08-16, 15:21
Hi. Here is the new OTL log.


OTL logfile created on: 16/08/2010 9:13:45 AM - Run 6
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Darlin\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 58.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.54 Gb Total Space | 128.56 Gb Free Space | 57.51% Space Free | Partition Type: NTFS
Drive D: | 9.35 Gb Total Space | 1.70 Gb Free Space | 18.16% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DARLIN-PC
Current User Name: Darlin
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Darlin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
PRC - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\SMINST\BLService.exe ()
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Darlin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\WINDOWS\System32\FntCache.dll (Microsoft Corporation)
SRV - (YahooAUService) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (Recovery Service for Windows) -- C:\WINDOWS\SMINST\BLService.exe ()
SRV - (Automatic LiveUpdate Scheduler) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (RPSKT) Security Services Driver (x86) -- C:\Windows\System32\DRIVERS\rp_skt32.sys File not found
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (catchme) -- C:\Users\Darlin\AppData\Local\Temp\catchme.sys File not found
DRV - (MpFilter) -- C:\WINDOWS\System32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (MpNWMon) -- C:\WINDOWS\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (BCM43XX) -- C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (BCM43XV) -- C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (nvlddmkm) -- C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (RTSTOR) -- C:\WINDOWS\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (CnxtHdAudService) -- C:\WINDOWS\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (NVHDA) -- C:\WINDOWS\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (nvsmu) -- C:\WINDOWS\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (SynTP) -- C:\WINDOWS\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (NVENETFD) -- C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\WINDOWS\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HSFHWAZL) -- C:\WINDOWS\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (HSF_DPV) -- C:\WINDOWS\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) -- C:\WINDOWS\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) -- C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqRemHid) -- C:\WINDOWS\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (PID_0928) Labtec WebCam(PID_0928) -- C:\WINDOWS\System32\drivers\LV561AV.SYS (Labtec Inc.)
DRV - (LVUSBSta) -- C:\WINDOWS\System32\drivers\LVUSBSta.sys (Labtec Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local

FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009/09/11 16:51:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/09 19:03:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/09 19:03:01 | 000,000,000 | ---D | M]

[2010/03/17 16:27:38 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Extensions
[2009/08/21 19:44:39 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Extensions\mozswing@mozswing.org
[2010/08/11 21:56:53 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions
[2010/07/28 12:11:31 | 000,000,000 | ---D | M] (TwitterBar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}
[2010/04/27 17:10:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2010/03/18 20:51:56 | 000,000,000 | ---D | M] (AniWeather) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}
[2010/05/25 20:18:05 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/03/28 14:09:55 | 000,000,000 | ---D | M] (ScrapBook) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2010/07/31 23:04:28 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/03/18 21:34:21 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2010/03/18 21:01:38 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2010/06/08 11:09:24 | 000,000,000 | ---D | M] (ReminderFox) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
[2010/07/28 12:11:30 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/06/30 22:17:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/07/28 12:11:31 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/03/18 21:34:21 | 000,000,000 | ---D | M] (Pixlr Grabber) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{d47a9f51-8281-43fa-f450-f28ef8735e9a}
[2010/06/02 19:11:22 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/04/12 10:07:01 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/05/15 21:16:08 | 000,000,000 | ---D | M] (DVDVideoSoft Toolbar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] (FoxTab) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2010/07/28 12:11:45 | 000,000,000 | ---D | M] (SearchPreview) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
[2010/07/28 12:11:31 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\FirefoxAddon@similarWeb.com
[2010/03/18 21:39:06 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\googletube@googletube.com
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\illimitux@illimitux.net
[2010/04/12 10:07:29 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\isreaditlater@ideashower.com
[2010/04/14 10:14:52 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\personas@christopher.beard
[2010/06/29 16:36:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com
[2010/06/29 16:36:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com-trash
[2010/03/18 21:01:33 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\SkipScreen@SkipScreen
[2010/06/16 15:38:34 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\smarterwiki@wikiatic.com
[2010/07/28 12:11:30 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\unplug@compunach
[2010/06/16 15:38:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\videosurf_enhanced@videosurf.com
[2010/04/21 10:16:53 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\YoutubeDownloader@PeterOlayev.com
[2010/03/05 15:29:29 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] (TwitterBar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2010/03/05 15:04:55 | 000,000,000 | ---D | M] (TV-Fox) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{2f17f610-5e97-4fed-828f-9940b7b577a4}
[2010/03/04 17:52:58 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{99210d54-6321-41e8-bd1b-2b4c55874efb}
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] (QuickWiki) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{EE223D7A-F30F-11DD-8F0A-D2AD55D89593}
[2010/03/04 17:52:58 | 000,000,000 | ---D | M] (FoxTab) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\en-CA@dictionaries.addons.mozilla.org
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\FirefoxAddon@myfacebook.com
[2010/03/04 17:53:01 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\FirefoxAddon@similarWeb.com
[2010/03/04 18:20:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\firefox-extension@shareaholic.com
[2010/03/04 18:20:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\googletube@googletube.com
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\illimitux@illimitux.net
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\isreaditlater@ideashower.com
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\personas@christopher.beard
[2010/03/04 17:53:00 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\piclens@cooliris.com
[2010/03/04 17:53:01 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\quickdrag@mozilla.ktechcomputing.com
[2010/03/04 18:20:45 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\firefox-extension@shareaholic.com\chrome
[2010/03/04 18:32:31 | 000,007,972 | ---- | M] () -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\searchplugins\oneriot-social-web-search.xml
[2010/03/04 17:43:36 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/02/21 06:22:32 | 000,712,704 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll

O1 HOSTS File: ([2010/08/09 13:00:58 | 000,000,698 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [RogersServicepointAgent.exe] C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Run YoukuDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe File not found
O9 - Extra 'Tools' menuitem : Youku Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 64.71.255.198 192.168.1.1
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Darlin\Pictures\wild_shutterstock_8532871.jpg
O24 - Desktop BackupWallPaper: C:\Users\Darlin\Pictures\wild_shutterstock_8532871.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/11 09:46:21 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/08/16 09:12:14 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Darlin\Desktop\OTL.exe
[2010/08/14 19:29:59 | 000,000,000 | ---D | C] -- C:\My Music
[2010/08/14 19:29:44 | 000,123,392 | ---- | C] (RealNetworks) -- C:\Windows\System32\rmoc3260.dll
[2010/08/14 19:29:40 | 000,024,576 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\prefscpl.cpl
[2010/08/14 19:29:40 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2010/08/14 19:29:40 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2010/08/14 19:29:28 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\System32\pncrt.dll
[2010/08/14 19:29:22 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Real
[2010/08/14 19:29:14 | 000,000,000 | ---D | C] -- C:\Program Files\Real
[2010/08/14 19:28:01 | 000,057,344 | ---- | C] (Micronas Intermetall) -- C:\Windows\System32\mi-sc4.acm
[2010/08/14 19:28:01 | 000,010,135 | ---- | C] (Windows (R) 2000 DDK provider) -- C:\Windows\System32\drivers\SECYPUSB.sys
[2010/08/14 14:44:04 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010/08/14 14:43:12 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010/08/14 14:28:00 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010/08/14 14:27:25 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/08/11 21:05:18 | 000,081,920 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll
[2010/08/11 21:05:08 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2010/08/11 21:05:08 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieencode.dll
[2010/08/11 21:05:07 | 000,380,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2010/08/11 21:04:58 | 002,037,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2010/08/11 21:04:55 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtutils.dll
[2010/08/11 21:04:38 | 003,600,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2010/08/11 21:04:37 | 003,548,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2010/08/03 11:53:55 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010/08/01 16:15:08 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/07/31 23:09:04 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Yahoo
[2010/07/31 23:04:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo! Companion
[2010/07/31 23:03:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo!
[2010/07/31 15:24:56 | 000,000,000 | ---D | C] -- C:\_OTM
[2010/07/22 14:17:32 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/07/22 13:01:49 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2010/07/19 14:09:04 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/07/18 15:12:02 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Apple
[2010/07/18 14:54:21 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Adobe
[2010/07/18 13:28:51 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Apple Computer
[2010/07/18 12:48:42 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Roaming\Malwarebytes
[2010/07/18 12:48:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/07/18 12:48:30 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/17 20:50:15 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/07/17 20:50:15 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/07/17 20:50:15 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/07/17 20:50:08 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/07/17 20:49:37 | 000,000,000 | ---D | C] -- C:\Qoobox
[4 C:\Users\Darlin\Documents\*.tmp files -> C:\Users\Darlin\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/16 09:13:36 | 008,388,608 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat
[2010/08/16 09:12:17 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Darlin\Desktop\OTL.exe
[2010/08/16 08:56:01 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/16 08:52:59 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010/08/16 08:51:56 | 000,002,255 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/08/16 08:50:23 | 000,000,246 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2010/08/16 08:49:36 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2010/08/16 08:49:36 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/08/16 08:49:33 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/16 08:49:01 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/16 08:49:00 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/16 08:49:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job
[2010/08/16 08:48:54 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/08/16 08:48:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/08/16 08:48:42 | 2951,110,656 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/15 23:22:44 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/08/15 23:22:41 | 000,524,288 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TMContainer00000000000000000001.regtrans-ms
[2010/08/15 23:22:41 | 000,065,536 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TM.blf
[2010/08/15 23:22:36 | 002,675,049 | -H-- | M] () -- C:\Users\Darlin\AppData\Local\IconCache.db
[2010/08/15 19:57:05 | 002,508,566 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/08/15 19:57:05 | 000,780,938 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/08/15 19:57:05 | 000,062,236 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2010/08/15 19:57:05 | 000,019,286 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2010/08/15 19:57:04 | 000,059,822 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/08/15 17:49:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job
[2010/08/14 19:29:58 | 000,000,871 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\RealPlayer Basic.lnk
[2010/08/14 19:29:44 | 000,123,392 | ---- | M] (RealNetworks) -- C:\Windows\System32\rmoc3260.dll
[2010/08/14 19:29:40 | 000,024,576 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\prefscpl.cpl
[2010/08/14 19:29:40 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2010/08/14 19:29:40 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2010/08/14 19:29:28 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\Windows\System32\pncrt.dll
[2010/08/14 14:40:49 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/08/13 16:37:36 | 273,266,934 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/08/13 13:37:51 | 000,001,356 | ---- | M] () -- C:\Users\Darlin\AppData\Local\d3d9caps.dat
[2010/08/12 13:15:33 | 000,311,040 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/08/11 21:50:25 | 000,002,047 | ---- | M] () -- C:\Users\Darlin\Desktop\Google Chrome.lnk
[2010/08/11 21:50:25 | 000,002,009 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/08/09 13:00:58 | 000,000,698 | ---- | M] () -- C:\Windows\System32\drivers\etc\HOSTS
[2010/08/08 18:06:18 | 000,000,943 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/08/01 16:16:01 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/07/31 23:03:45 | 000,000,966 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/07/29 18:44:36 | 000,013,312 | ---- | M] () -- C:\Users\Darlin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/28 18:38:07 | 002,512,767 | ---- | M] () -- C:\Users\Darlin\Documents\Canadian Achievements.pptx
[2010/07/22 19:06:22 | 000,030,720 | ---- | M] () -- C:\Users\Darlin\Documents\Water Consumption.doc
[2010/07/22 19:06:13 | 000,014,769 | ---- | M] () -- C:\Users\Darlin\Documents\Final Unit Essay.docx
[2010/07/22 14:17:32 | 000,001,874 | ---- | M] () -- C:\Users\Darlin\Desktop\HijackThis.lnk
[2010/07/21 17:04:41 | 000,020,148 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 6 Activity 3.docx
[2010/07/20 22:25:46 | 000,019,373 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 5 Activity 5.docx
[2010/07/20 19:57:21 | 000,023,377 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 5 Activity 3.docx
[2010/07/20 14:39:39 | 000,038,252 | ---- | M] () -- C:\Users\Darlin\Documents\Charter.rtf
[4 C:\Users\Darlin\Documents\*.tmp files -> C:\Users\Darlin\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/14 19:29:58 | 000,000,871 | ---- | C] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\RealPlayer Basic.lnk
[2010/08/14 19:28:01 | 000,081,408 | ---- | C] () -- C:\Windows\System32\secumax.dll
[2010/08/02 20:08:00 | 000,002,255 | ---- | C] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/08/01 16:16:01 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/07/31 23:03:45 | 000,000,966 | ---- | C] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/07/27 23:08:14 | 002,512,767 | ---- | C] () -- C:\Users\Darlin\Documents\Canadian Achievements.pptx
[2010/07/22 19:06:13 | 000,014,769 | ---- | C] () -- C:\Users\Darlin\Documents\Final Unit Essay.docx
[2010/07/22 16:16:18 | 000,030,720 | ---- | C] () -- C:\Users\Darlin\Documents\Water Consumption.doc
[2010/07/22 14:17:32 | 000,001,874 | ---- | C] () -- C:\Users\Darlin\Desktop\HijackThis.lnk
[2010/07/21 17:04:41 | 000,020,148 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 6 Activity 3.docx
[2010/07/21 14:45:52 | 2951,110,656 | -HS- | C] () -- C:\hiberfil.sys
[2010/07/20 22:25:44 | 000,019,373 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 5 Activity 5.docx
[2010/07/20 19:56:30 | 000,023,377 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 5 Activity 3.docx
[2010/07/20 14:39:39 | 000,038,252 | ---- | C] () -- C:\Users\Darlin\Documents\Charter.rtf
[2010/07/17 20:50:15 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010/07/17 20:50:15 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/07/17 20:50:15 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/07/17 20:50:15 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/07/17 20:50:15 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/07/12 09:25:28 | 000,000,008 | ---- | C] () -- C:\Users\Darlin\AppData\Roaming\vdnxlf.dat
[2010/07/11 17:46:31 | 000,000,088 | ---- | C] () -- C:\Windows\wininit.ini
[2010/07/09 23:20:48 | 000,088,576 | RHS- | C] () -- C:\Users\Darlin\AppData\Roaming\nb-NOM.dll
[2010/03/06 21:39:05 | 000,007,916 | -HS- | C] () -- C:\Users\Darlin\AppData\Local\8mtxM1
[2010/03/04 19:20:11 | 000,001,536 | ---- | C] () -- C:\Users\Darlin\AppData\Roaming\Sketchpad 5 Preferences.dat
[2010/01/26 18:01:45 | 000,000,000 | ---- | C] () -- C:\Users\Darlin\AppData\Local\Scaqutafuzaca.bin
[2010/01/26 18:01:44 | 000,000,120 | ---- | C] () -- C:\Users\Darlin\AppData\Local\Fweyuxuzede.dat
[2009/11/18 16:40:24 | 000,013,312 | ---- | C] () -- C:\Users\Darlin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/02 23:13:27 | 000,005,184 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2009/09/17 16:23:53 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/09/11 19:18:19 | 000,000,248 | ---- | C] () -- C:\Users\Darlin\AppData\Roaming\wklnhst.dat
[2009/09/05 19:41:30 | 000,048,670 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/09/05 19:39:30 | 000,048,670 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/08/24 16:51:58 | 000,001,356 | ---- | C] () -- C:\Users\Darlin\AppData\Local\d3d9caps.dat
[2009/08/21 18:23:44 | 000,000,000 | ---- | C] () -- C:\Users\Darlin\AppData\Local\QSwitch.txt
[2009/08/21 18:23:44 | 000,000,000 | ---- | C] () -- C:\Users\Darlin\AppData\Local\DSwitch.txt
[2009/08/21 18:23:44 | 000,000,000 | ---- | C] () -- C:\Users\Darlin\AppData\Local\AtStart.txt
[2008/08/11 10:06:45 | 000,002,084 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2008/01/20 22:24:38 | 000,033,794 | ---- | C] () -- C:\Windows\System32\unelwin.dll
[2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/03/09 05:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2005/01/19 09:30:54 | 000,009,255 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini

========== Files - Unicode (All) ==========
[2009/10/02 23:23:37 | 000,000,036 | ---- | M] ()(C:\Windows\System32\?????????????????????????????????????????????????) -- C:\Windows\System32\㩃停潲牧浡䘠汩獥剜杯牥⁳湏楬敮倠潲整瑣潩屮潒敧獲传汮湩⁥牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩⹷潣普杩
[2009/10/02 23:23:37 | 000,000,036 | ---- | C] ()(C:\Windows\System32\?????????????????????????????????????????????????) -- C:\Windows\System32\㩃停潲牧浡䘠汩獥剜杯牥⁳湏楬敮倠潲整瑣潩屮潒敧獲传汮湩⁥牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩⹷潣普杩
< End of report >

ken545
2010-08-16, 18:45
Run OTL

Under the Custom Scans/Fixes box at the bottom, paste in the following



:OTL
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
[2010/01/26 18:01:45 | 000,000,000 | ---- | C] () -- C:\Users\Darlin\AppData\Local\Scaqutafuzaca.bin
[2010/01/26 18:01:44 | 000,000,120 | ---- | C] () -- C:\Users\Darlin\AppData\Local\Fweyuxuzede.dat

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
Let the program run unhindered, reboot when it is done
Post the log its created please

DaReelDeel
2010-08-17, 18:54
Hi. I ran the custom fix on OTL. Here is the log.

All processes killed
========== OTL ==========
No active process named Explorer.EXE was found!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
C:\Users\Darlin\AppData\Local\Scaqutafuzaca.bin moved successfully.
C:\Users\Darlin\AppData\Local\Fweyuxuzede.dat moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Bhing or J.A
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Darlin
->Temp folder emptied: 736362 bytes
->Temporary Internet Files folder emptied: 72693135 bytes
->Java cache emptied: 7140 bytes
->FireFox cache emptied: 12953784 bytes
->Google Chrome cache emptied: 26802799 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 75947 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: TEMP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: TEMP.Darlin-PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: TEMP.Darlin-PC.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 478433 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 3752596 bytes

Total Files Cleaned = 112.00 mb


OTL by OldTimer - Version 3.2.10.0 log created on 08172010_124355

Files\Folders moved on Reboot...
C:\Users\Darlin\AppData\Local\Temp\ehmsas.txt moved successfully.
C:\Users\Darlin\AppData\Local\Temp\VGX450A.tmp moved successfully.

Registry entries deleted on Reboot...

ken545
2010-08-17, 19:06
Any difference, you need to let me know

DaReelDeel
2010-08-18, 15:14
I am still getting the error messages and getting redirected to other search engine sites.

ken545
2010-08-18, 18:44
Hi,

I am almost certain that what you have is a variant of the TDSS Rootkit but I am not happy with the GMER scans you have been submitting .

Download TDSSKiller and save it to your Desktop.
http://support.kaspersky.com/downloads/utils/tdsskiller.zip

Extract the file and run it.
Once completed it will create a log in your C:\ drive
Please post the contents of that log

DaReelDeel
2010-08-19, 18:50
Hi. Here is the the TDSSKiller log.


2010/08/19 12:46:17.0494 TDSS rootkit removing tool 2.4.1.2 Aug 16 2010 09:46:23
2010/08/19 12:46:17.0494 ================================================================================
2010/08/19 12:46:17.0494 SystemInfo:
2010/08/19 12:46:17.0494
2010/08/19 12:46:17.0494 OS Version: 6.0.6002 ServicePack: 2.0
2010/08/19 12:46:17.0494 Product type: Workstation
2010/08/19 12:46:17.0494 ComputerName: DARLIN-PC
2010/08/19 12:46:17.0494 UserName: Darlin
2010/08/19 12:46:17.0494 Windows directory: C:\Windows
2010/08/19 12:46:17.0494 System windows directory: C:\Windows
2010/08/19 12:46:17.0494 Processor architecture: Intel x86
2010/08/19 12:46:17.0494 Number of processors: 2
2010/08/19 12:46:17.0494 Page size: 0x1000
2010/08/19 12:46:17.0494 Boot type: Normal boot
2010/08/19 12:46:17.0494 ================================================================================
2010/08/19 12:46:18.0602 Initialize success
2010/08/19 12:46:30.0161 ================================================================================
2010/08/19 12:46:30.0161 Scan started
2010/08/19 12:46:30.0161 Mode: Manual;
2010/08/19 12:46:30.0161 ================================================================================
2010/08/19 12:46:31.0019 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2010/08/19 12:46:31.0456 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2010/08/19 12:46:31.0768 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2010/08/19 12:46:32.0065 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2010/08/19 12:46:32.0439 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2010/08/19 12:46:32.0845 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
2010/08/19 12:46:33.0016 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2010/08/19 12:46:33.0313 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2010/08/19 12:46:33.0671 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2010/08/19 12:46:33.0999 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2010/08/19 12:46:34.0436 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2010/08/19 12:46:34.0919 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2010/08/19 12:46:35.0543 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
2010/08/19 12:46:35.0933 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2010/08/19 12:46:36.0620 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2010/08/19 12:46:36.0932 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2010/08/19 12:46:37.0462 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2010/08/19 12:46:37.0915 BCM43XV (a176653093b28e4deb9f3d81cb4056ec) C:\Windows\system32\DRIVERS\bcmwl6.sys
2010/08/19 12:46:38.0149 BCM43XX (a176653093b28e4deb9f3d81cb4056ec) C:\Windows\system32\DRIVERS\bcmwl6.sys
2010/08/19 12:46:38.0461 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2010/08/19 12:46:38.0991 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2010/08/19 12:46:39.0568 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
2010/08/19 12:46:39.0896 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2010/08/19 12:46:40.0317 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2010/08/19 12:46:40.0520 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2010/08/19 12:46:40.0754 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2010/08/19 12:46:41.0097 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2010/08/19 12:46:41.0596 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2010/08/19 12:46:41.0861 BthEnum (cce53afc28347cc18ea139972e5b5e5a) C:\Windows\system32\DRIVERS\BthEnum.sys
2010/08/19 12:46:42.0127 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2010/08/19 12:46:42.0407 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
2010/08/19 12:46:42.0735 BTHPORT (ac8a1689d5efc4d214201155a78d8f4b) C:\Windows\system32\Drivers\BTHport.sys
2010/08/19 12:46:42.0969 BTHUSB (288c1f74e3e2eed6c7b54eb3aac70856) C:\Windows\system32\Drivers\BTHUSB.sys
2010/08/19 12:46:43.0375 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2010/08/19 12:46:43.0811 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2010/08/19 12:46:44.0201 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
2010/08/19 12:46:44.0498 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2010/08/19 12:46:45.0137 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
2010/08/19 12:46:45.0980 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2010/08/19 12:46:46.0261 CnxtHdAudService (1adf6f4852e7d7e2e8ac481bdb970586) C:\Windows\system32\drivers\CHDRT32.sys
2010/08/19 12:46:46.0775 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
2010/08/19 12:46:47.0041 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2010/08/19 12:46:47.0368 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2010/08/19 12:46:48.0148 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
2010/08/19 12:46:48.0788 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2010/08/19 12:46:49.0162 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys
2010/08/19 12:46:49.0521 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys
2010/08/19 12:46:50.0020 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys
2010/08/19 12:46:50.0535 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2010/08/19 12:46:51.0097 DXGKrnl (5c7e2097b91d689ded7a6ff90f0f3a25) C:\Windows\System32\drivers\dxgkrnl.sys
2010/08/19 12:46:51.0845 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2010/08/19 12:46:52.0407 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2010/08/19 12:46:52.0953 eeCtrl (96bcd90ed9235a21629effde5e941fb1) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
2010/08/19 12:46:53.0499 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2010/08/19 12:46:54.0029 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2010/08/19 12:46:54.0341 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2010/08/19 12:46:54.0809 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2010/08/19 12:46:55.0277 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2010/08/19 12:46:56.0011 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2010/08/19 12:46:56.0229 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2010/08/19 12:46:56.0276 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2010/08/19 12:46:56.0432 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2010/08/19 12:46:56.0775 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2010/08/19 12:46:57.0243 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2010/08/19 12:46:57.0976 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2010/08/19 12:46:58.0288 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
2010/08/19 12:46:58.0475 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2010/08/19 12:46:58.0881 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2010/08/19 12:46:59.0146 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2010/08/19 12:46:59.0318 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2010/08/19 12:46:59.0723 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2010/08/19 12:47:00.0269 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
2010/08/19 12:47:00.0987 HpqRemHid (115c0933b3ed51dfbec4449348c8065b) C:\Windows\system32\DRIVERS\HpqRemHid.sys
2010/08/19 12:47:01.0283 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
2010/08/19 12:47:02.0141 HSF_DPV (cc267848cb3508e72762be65734e764d) C:\Windows\system32\DRIVERS\HSX_DPV.sys
2010/08/19 12:47:02.0531 HSXHWAZL (a2882945cc4b6e3e4e9e825590438888) C:\Windows\system32\DRIVERS\HSXHWAZL.sys
2010/08/19 12:47:03.0015 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2010/08/19 12:47:03.0405 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2010/08/19 12:47:03.0873 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2010/08/19 12:47:04.0325 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2010/08/19 12:47:04.0731 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2010/08/19 12:47:05.0121 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2010/08/19 12:47:05.0324 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2010/08/19 12:47:05.0371 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2010/08/19 12:47:05.0839 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2010/08/19 12:47:06.0229 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2010/08/19 12:47:06.0385 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2010/08/19 12:47:07.0227 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2010/08/19 12:47:07.0414 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2010/08/19 12:47:07.0508 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2010/08/19 12:47:07.0633 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2010/08/19 12:47:07.0679 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2010/08/19 12:47:07.0851 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
2010/08/19 12:47:08.0007 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2010/08/19 12:47:08.0225 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2010/08/19 12:47:08.0335 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2010/08/19 12:47:08.0366 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2010/08/19 12:47:08.0537 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2010/08/19 12:47:08.0600 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2010/08/19 12:47:08.0662 LVUSBSta (c7fcb579956b7fde002e6e9de36728d3) C:\Windows\system32\drivers\lvusbsta.sys
2010/08/19 12:47:08.0865 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
2010/08/19 12:47:09.0005 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2010/08/19 12:47:09.0083 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2010/08/19 12:47:09.0146 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2010/08/19 12:47:09.0239 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2010/08/19 12:47:09.0286 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2010/08/19 12:47:09.0317 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2010/08/19 12:47:09.0427 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2010/08/19 12:47:09.0536 MpFilter (c98301ad8173a2235a9ab828955c32bb) C:\Windows\system32\DRIVERS\MpFilter.sys
2010/08/19 12:47:09.0645 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2010/08/19 12:47:09.0739 MpNWMon (aeb186afff5d9cfed823c15d846aac3b) C:\Windows\system32\DRIVERS\MpNWMon.sys
2010/08/19 12:47:09.0848 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2010/08/19 12:47:09.0910 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2010/08/19 12:47:09.0988 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2010/08/19 12:47:10.0113 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys
2010/08/19 12:47:10.0175 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2010/08/19 12:47:10.0207 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2010/08/19 12:47:10.0253 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
2010/08/19 12:47:10.0363 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2010/08/19 12:47:10.0472 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2010/08/19 12:47:10.0597 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2010/08/19 12:47:10.0659 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2010/08/19 12:47:10.0815 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2010/08/19 12:47:10.0862 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2010/08/19 12:47:10.0971 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2010/08/19 12:47:11.0065 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2010/08/19 12:47:11.0158 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2010/08/19 12:47:11.0283 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2010/08/19 12:47:11.0408 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2010/08/19 12:47:11.0564 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2010/08/19 12:47:11.0673 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2010/08/19 12:47:11.0751 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2010/08/19 12:47:11.0907 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2010/08/19 12:47:12.0001 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2010/08/19 12:47:12.0110 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2010/08/19 12:47:12.0547 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2010/08/19 12:47:13.0217 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2010/08/19 12:47:13.0576 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2010/08/19 12:47:14.0278 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2010/08/19 12:47:15.0152 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2010/08/19 12:47:15.0682 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2010/08/19 12:47:16.0181 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2010/08/19 12:47:16.0556 NVENETFD (ae78a7285df03a277415fc62f8ce8f24) C:\Windows\system32\DRIVERS\nvmfdx32.sys
2010/08/19 12:47:16.0993 NVHDA (b0dd52428bf564f5fc5ee331060be2a6) C:\Windows\system32\drivers\nvhda32v.sys
2010/08/19 12:47:18.0709 nvlddmkm (9dac05d828e56801fd6ce5fdfced64af) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2010/08/19 12:47:19.0535 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2010/08/19 12:47:20.0269 nvsmu (0fb6bf3ab170fc5bd403d25e134eafde) C:\Windows\system32\DRIVERS\nvsmu.sys
2010/08/19 12:47:20.0705 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2010/08/19 12:47:21.0220 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2010/08/19 12:47:22.0624 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
2010/08/19 12:47:23.0373 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2010/08/19 12:47:23.0638 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2010/08/19 12:47:24.0122 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2010/08/19 12:47:24.0668 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2010/08/19 12:47:25.0495 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
2010/08/19 12:47:25.0682 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2010/08/19 12:47:25.0807 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2010/08/19 12:47:26.0259 PID_0928 (03e86718bb5aa2716c7349a854ff6203) C:\Windows\system32\DRIVERS\LV561AV.SYS
2010/08/19 12:47:26.0696 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2010/08/19 12:47:27.0117 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\DRIVERS\processr.sys
2010/08/19 12:47:27.0679 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2010/08/19 12:47:28.0661 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2010/08/19 12:47:29.0473 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2010/08/19 12:47:29.0878 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2010/08/19 12:47:30.0393 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2010/08/19 12:47:30.0814 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2010/08/19 12:47:31.0438 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2010/08/19 12:47:31.0828 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2010/08/19 12:47:32.0780 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2010/08/19 12:47:33.0544 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2010/08/19 12:47:33.0809 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
2010/08/19 12:47:34.0277 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2010/08/19 12:47:34.0792 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2010/08/19 12:47:35.0525 RFCOMM (23f486726da7a9b2f3ec7326421a9c36) C:\Windows\system32\DRIVERS\rfcomm.sys
2010/08/19 12:47:36.0181 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2010/08/19 12:47:36.0383 RTSTOR (b0538dea03e088b80482ca939f4e8740) C:\Windows\system32\drivers\RTSTOR.SYS
2010/08/19 12:47:36.0820 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2010/08/19 12:47:37.0366 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2010/08/19 12:47:37.0663 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2010/08/19 12:47:37.0865 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2010/08/19 12:47:38.0271 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2010/08/19 12:47:38.0723 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2010/08/19 12:47:38.0848 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2010/08/19 12:47:38.0973 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2010/08/19 12:47:39.0160 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2010/08/19 12:47:39.0441 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2010/08/19 12:47:39.0691 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2010/08/19 12:47:39.0987 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2010/08/19 12:47:40.0611 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2010/08/19 12:47:40.0985 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2010/08/19 12:47:41.0516 srv (96a5e2c642af8f591a7366429809506b) C:\Windows\system32\DRIVERS\srv.sys
2010/08/19 12:47:41.0906 srv2 (71da2d64880c97e5ffc3c81761632751) C:\Windows\system32\DRIVERS\srv2.sys
2010/08/19 12:47:42.0608 srvnet (0c5ab1892ae0fa504218db094bf6d041) C:\Windows\system32\DRIVERS\srvnet.sys
2010/08/19 12:47:43.0060 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2010/08/19 12:47:43.0622 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2010/08/19 12:47:43.0918 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2010/08/19 12:47:44.0495 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2010/08/19 12:47:44.0823 SynTP (00b19f27858f56181edb58b71a7c67a0) C:\Windows\system32\DRIVERS\SynTP.sys
2010/08/19 12:47:45.0322 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2010/08/19 12:47:45.0899 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2010/08/19 12:47:46.0414 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2010/08/19 12:47:46.0929 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2010/08/19 12:47:47.0366 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2010/08/19 12:47:47.0959 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2010/08/19 12:47:48.0598 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2010/08/19 12:47:49.0129 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2010/08/19 12:47:49.0394 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2010/08/19 12:47:49.0628 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2010/08/19 12:47:49.0862 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2010/08/19 12:47:50.0065 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2010/08/19 12:47:50.0361 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2010/08/19 12:47:50.0595 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2010/08/19 12:47:50.0907 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2010/08/19 12:47:51.0094 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2010/08/19 12:47:51.0344 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2010/08/19 12:47:51.0593 USBAAPL (e8c1b9ebac65288e1b51e8a987d98af6) C:\Windows\system32\Drivers\usbaapl.sys
2010/08/19 12:47:51.0890 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2010/08/19 12:47:52.0077 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2010/08/19 12:47:52.0373 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2010/08/19 12:47:52.0623 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2010/08/19 12:47:53.0060 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
2010/08/19 12:47:53.0621 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
2010/08/19 12:47:54.0074 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2010/08/19 12:47:54.0667 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2010/08/19 12:47:55.0010 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
2010/08/19 12:47:55.0244 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
2010/08/19 12:47:55.0509 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2010/08/19 12:47:55.0883 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
2010/08/19 12:47:56.0117 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
2010/08/19 12:47:56.0414 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2010/08/19 12:47:56.0617 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2010/08/19 12:47:56.0804 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2010/08/19 12:47:57.0007 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2010/08/19 12:47:57.0241 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
2010/08/19 12:47:57.0506 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2010/08/19 12:47:57.0709 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2010/08/19 12:47:57.0740 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2010/08/19 12:47:57.0943 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
2010/08/19 12:47:58.0130 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2010/08/19 12:47:58.0567 winachsf (0acd399f5db3df1b58903cf4949ab5a8) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
2010/08/19 12:47:58.0972 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2010/08/19 12:47:59.0222 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
2010/08/19 12:47:59.0487 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2010/08/19 12:47:59.0877 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2010/08/19 12:48:00.0189 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys
2010/08/19 12:48:00.0329 ================================================================================
2010/08/19 12:48:00.0329 Scan finished
2010/08/19 12:48:00.0329 ================================================================================

ken545
2010-08-19, 22:11
Nothing found.

If your still being redirected and getting error messages, I need you to write down the error messages your getting word for word and also exactly what sites your being redirected to

DaReelDeel
2010-08-21, 20:27
I have gotten these messages many times when I visit sites I regularly visit like facebook, hotmail, or twitter.

Oops! Google Chrome could not find twitter.com
This webpage is not available.

I have been getting redirected to a variety of sites. Here is some of the sites that I got redirected too.

This webpage is not available.

The webpage at http://c.enhance.com/c?e1=dxqnWIGdXOwMnj0uSBDCOyIiDrNg3gDvkIUN1HyRU3vp52wIqfYpgdkKmsVGClVjYPyB2zKg4K5PcqldK0isyqWeFSLSaditMjJjQ4thVxQ2SYNPYTLrXBWV0yCq5M0u34rNbduBCpSKXkunGtZ4XaAAaynRjcUJcrPRbLkmPvAGnhtTLfLGnbuGwq1xOxqTXELDknwTBJuqCLV53hwiE40QzxbsCmMUFfQMkevAFaS1pCurpBT50kK2Hag3IhzZrYTdA1mlNrn3hZAvz40IPQOnyqKCObywfziQ0duKhHWAdMgKynrvJLD421s5hJB2ClScWGcuwMHNZMZjqSM0TzcBqRpFdOUb2bSvY2nWJsuZAzUhSwWnkMzTCjVLmSIBbXdlCsOczKKByGUupThlPzGhvBUhUh3hPgCTN3RvFUaHiCCKvxqaZJBClZtBOTqAIrUIxpeUFNjal4HxIDt2XgxkPzYcVkotBMwLUZsTfw3aEs1hLoxqK2th0EHqyLELIJUO3kwodmUuLqqxVBbZYII1pEbeERRc3GJgRTJzz4nubXKvD5VBgpTQlsZbGIhd5hxnbwarrE3XCT0cDGzhifsEG1qDF1sOHIHt1AIFAOkhTpqKEkOtSkCkHQVJ54vhCQktA&h=3ETD4cw2RAYZtpAng&b=2422999 might be temporarily down or it may have moved permanently to a new web address.

http://www.cafemom.com/group/416/forums/read/12036580/Live_Positively_Vote_for_your_favorite_park?utm_medium=sem2&utm_s

ken545
2010-08-21, 21:23
Try this

Please download Kenco.exe by jpshortstuff and save it to your desktop.
http://jpshortstuff.247fixes.com/Kenco.exe

* Double-click on Kenco.exe to run it (if you get a security warning, click run).
* You will see a black command window and shortly thereafter, a logfile (kenco.log) will open in Notepad. The log will be saved on your desktop.
* In order to complete the cleaning process, Kenco.exe may need to reboot your computer.
* Please copy and paste the contents of kenco.log in your next reply.

DaReelDeel
2010-08-22, 20:53
Here is the log created by Kenco. Also I have been redirected to this site multiple times. http://gathi.131.blueseek.com/jump2/?affiliate=gathi&subid=131&terms=letmewatchthis

Kenco by jpshortstuff (31.12.09.1)
Log created at 14:45 on 22/08/2010 (Darlin)

========== Task Unlocker ==========

========== KencoScan ==========

========== C:\Windows\Tasks ==========
Google Software Updater.job -> [21:21 03/09/2009] 868 bytes
GoogleUpdateTaskMachineCore.job -> [21:30 03/09/2009] 882 bytes
GoogleUpdateTaskMachineUA.job -> [21:30 03/09/2009] 886 bytes
GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job -> [23:27 21/08/2009] 860 bytes
GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job -> [23:27 21/08/2009] 912 bytes

-=E.O.F=-

ken545
2010-08-22, 21:46
That bugger is hiding as I dont see it in any of your scans

Please do a scan with Kaspersky Online Scanner (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) or from Here. (http://www.kaspersky.com/virusscanner)

Click on the Accept button and install any components it needs.
The program will install and then begin downloading the latest definition files.
After the files have been downloaded on the left side of the page in the Scan section select My Computer.
This will start the program and scan your system.
The scan will take a while, so be patient and let it run. (At times it may appear to stall)
Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.

Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.


Once the scan is complete, click on View scan report To obtain the report:
Click on: Save Report As
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply.



http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif

DaReelDeel
2010-08-25, 03:41
Hi, here is the Kaspersky scan report.


--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Tuesday, August 24, 2010
Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, August 24, 2010 17:23:00
Records in database: 4142486
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Objects scanned: 218565
Threats found: 1
Infected objects found: 1
Suspicious objects found: 0
Scan duration: 06:17:59


File name / Threat / Threats count
C:\Users\Darlin\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report1678f0c6\Report.cab Infected: Trojan.Win32.FakeAV.aam 1

Selected area has been scanned.

ken545
2010-08-25, 07:51
C:\Users\Darlin\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report1678f0c6\Report.cab <--Delete this file but leave it in the Recycle Bin for a few days in case we need to restore it.

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1 (http://jpshortstuff.247fixes.com/GooredFix.exe)
Download Mirror #2 (http://downloads.securitycadets.com/GooredFix.exe)
Ensure all Firefox windows are closed.
To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
When prompted to run the scan, click Yes.
GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).




Then run DDS again and post a fresh log please

ken545
2010-08-25, 13:28
Hi,

I have had another helper look at this and offer some suggestions.

Follow the instruction on my prior post and run Goodedfix and post the report, but hold off at the moment running DDS, we can look at that as a final check when were done.

What I need you to do if you are using a router ( let me know if you are ) is to reset it, you had a hijack that hijacked your hosts file and it may have effected your router. There should be a little hole on the back of the router or it can be a little button, either way if its a button you need to press and hold if for about a minute and it will reset, if its a hole then you can insert a paper clip , that will reset it also, then you will have to reinstall it to get your internet back.


After you do that then run this quick scan and post the log, this will check your master boot record to see if its infected

Download MBRCheck (http://ad13.geekstogo.com/MBRCheck.exe) to your desktop

Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
It will show a Black screen with some information that will contain either the below line if no problem is found:
Done! Press ENTER to exit...
Or you will see more information like below if a problem is found:
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
Copy and Paste the log for me to see please

DaReelDeel
2010-08-27, 04:41
Hi. I haven't gotten to resetting the router yet because I am getting my desktop fixed. I am getting it back sometime next week. If there is any way to reinstall the router on my laptop, I will do it as soon as I get home from my trip. I did however run the Gooredfix. Here is the log.

GooredFix by jpshortstuff (03.07.10.1)
Log created at 09:02 on 25/08/2010 (Darlin)
Firefox version 3.6.6 (en-US)

========== GooredScan ==========


========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [21:43 04/03/2010]
{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [18:15 21/08/2010]

C:\Users\Darlin\Application Data\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\
FirefoxAddon@similarWeb.com [16:11 28/07/2010]
googletube@googletube.com [01:39 19/03/2010]
illimitux@illimitux.net [00:51 19/03/2010]
isreaditlater@ideashower.com [14:07 12/04/2010]
personas@christopher.beard [14:14 14/04/2010]
piclens@cooliris.com [20:36 29/06/2010]
piclens@cooliris.com-trash [20:36 29/06/2010]
SkipScreen@SkipScreen [01:42 25/08/2010]
smarterwiki@wikiatic.com [01:42 25/08/2010]
unplug@compunach [01:42 25/08/2010]
videosurf_enhanced@videosurf.com [19:38 16/06/2010]
YoutubeDownloader@PeterOlayev.com [01:42 25/08/2010]
{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37} [01:42 25/08/2010]
{20a82645-c095-46ed-80e3-08825760534b} [21:10 27/04/2010]
{29c4afe1-db19-4298-8785-fcc94d1d6c1d} [00:51 19/03/2010]
{4176DFF4-4698-11DE-BEEB-45DA55D89593} [01:42 25/08/2010]
{46551EC9-40F0-4e47-8E18-8E5CF550CFB8} [01:42 25/08/2010]
{53A03D43-5363-4669-8190-99061B2DEBA5} [18:09 28/03/2010]
{635abd67-4fe9-1b23-4f01-e679fa7484c1} [03:04 01/08/2010]
{6AC85730-7D0F-4de0-B3FA-21142DD85326} [01:34 19/03/2010]
{9AA46F4F-4DC7-4c06-97AF-5035170634FE} [01:01 19/03/2010]
{ada4b710-8346-4b82-8199-5de2b400a6ae} [01:42 25/08/2010]
{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [16:11 28/07/2010]
{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} [02:17 01/07/2010]
{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [16:11 28/07/2010]
{d47a9f51-8281-43fa-f450-f28ef8735e9a} [01:34 19/03/2010]
{DDC359D1-844A-42a7-9AA1-88A850A938A8} [23:11 02/06/2010]
{e4a8a97b-f2ed-450b-b12d-ee082ba24781} [14:06 12/04/2010]
{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} [01:16 16/05/2010]
{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a} [00:51 19/03/2010]
{EF522540-89F5-46b9-B6FE-1829E2B572C6} [16:11 28/07/2010]

C:\Users\Darlin\Application Data\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\
en-CA@dictionaries.addons.mozilla.org [22:20 04/03/2010]
firefox-extension@shareaholic.com [22:20 04/03/2010]
FirefoxAddon@myfacebook.com [21:52 04/03/2010]
FirefoxAddon@similarWeb.com [21:53 04/03/2010]
googletube@googletube.com [22:20 04/03/2010]
illimitux@illimitux.net [22:20 04/03/2010]
isreaditlater@ideashower.com [21:52 04/03/2010]
personas@christopher.beard [21:52 04/03/2010]
piclens@cooliris.com [21:52 04/03/2010]
quickdrag@mozilla.ktechcomputing.com [21:53 04/03/2010]
{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37} [22:20 04/03/2010]
{20a82645-c095-46ed-80e3-08825760534b} [21:52 04/03/2010]
{29c4afe1-db19-4298-8785-fcc94d1d6c1d} [21:52 04/03/2010]
{2f17f610-5e97-4fed-828f-9940b7b577a4} [19:04 05/03/2010]
{46551EC9-40F0-4e47-8E18-8E5CF550CFB8} [21:52 04/03/2010]
{99210d54-6321-41e8-bd1b-2b4c55874efb} [22:20 04/03/2010]
{9AA46F4F-4DC7-4c06-97AF-5035170634FE} [22:20 04/03/2010]
{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} [21:52 04/03/2010]
{EE223D7A-F30F-11DD-8F0A-D2AD55D89593} [22:20 04/03/2010]
{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a} [21:52 04/03/2010]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [17:05 22/08/2009]
"smartwebprinting@hp.com"="C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2" [20:51 11/09/2009]

-=E.O.F=-

ken545
2010-08-27, 11:18
Hi,

Your router should work on your laptop even though its disconnected from the desktop. It looks like its a wireless one. If its plugged into the power, can you access the internet on your laptop with it, if so is your laptop being redirected to the sites that your desktop is ?

DaReelDeel
2010-08-28, 17:13
My router still works even if it's not connected to my desktop. I can use it as long as it's plugged in. I talked to my brother and his desktop uses our WiFi too. He says he's also being redirected to the same sites.

ken545
2010-08-28, 17:35
You need to reset the router

DaReelDeel
2010-08-29, 21:55
Will I be able to reinstall the router on my laptop?

ken545
2010-08-30, 00:29
Hi,

Looks like your router is infected and needs to be reset. Most times a wireless router can be set up on a desktop with that desktop gaining access to the internet through a cable unless the desktop has a wireless receiver. Once the router is set up, you can access that wireless signal with any laptop that is wireless capable.

This is what you need to do, all us forums work together, post here at WhatheTech in there Network forum, give them info on your router as far as make and model, you can link them to this thread and tell them that I helped you and we determined that the router is infected and needs to be reset and then reinstalled, you may or may not need the set up disk that came with your router. This site like Safer is free but you will need to register.
http://forums.whatthetech.com/index.php?showforum=128



Once they have you reset and reintalled, post back here and let me know how your doing

ken545
2010-09-11, 14:11
Have you resolved your router problem ?

tashi
2010-09-14, 17:47
Nine pages of help. Thank you Ken. :)