1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved google won't run in FF 8

Discussion in 'Malware and Virus Removal Archive' started by rgn, 2011/12/07.

  1. 2011/12/07
    rgn

    rgn Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    212
    Likes Received:
    0
    [Resolved] google won't run in FF 8

    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 8328

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    12/7/2011 11:58:48 AM
    mbam-log-2011-12-07 (11-58-48).txt

    Scan type: Quick scan
    Objects scanned: 189989
    Time elapsed: 28 minute(s), 40 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 5
    Registry Values Infected: 0
    Registry Data Items Infected: 2
    Folders Infected: 12
    Files Infected: 232

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47a3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Error Fix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Error Fix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ( "%1" /S) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1 ") -> Quarantined and deleted successfully.

    Folders Infected:
    c:\documents and settings\robert niemi\application data\error fix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\pcobackups (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410 (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-03 12-31-440 (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Results (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\program files\error fix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\program files\error fix\PW (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\program files\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    c:\program files\funwebproducts\Installr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    c:\program files\funwebproducts\Installr\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Files Infected:
    c:\documents and settings\robert niemi\application data\error fix\spy_ignore.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-02 19-28-020.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-02 19-51-370.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-03 11-07-180.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-03 12-00-000.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-03 12-00-010.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-04 12-00-000.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-04 12-00-010.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-05 12-00-030.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-05 12-00-050.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-07 15-20-370.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-08 12-00-000.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-08 12-00-020.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-09 12-00-000.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-10 12-00-000.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-10 12-00-010.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-10 18-24-150.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-11 12-00-030.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-11 12-00-050.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-12 12-00-040.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-12 12-00-060.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-13 12-00-030.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-13 12-00-050.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-14 12-00-040.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-14 12-00-050.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-15 12-00-070.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-15 12-00-090.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-16 12-00-060.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-17 12-00-050.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-17 12-00-060.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-18 12-00-040.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-18 12-00-060.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-19 12-00-040.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-19 12-00-070.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-20 12-00-040.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-20 12-00-070.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-21 12-00-050.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-21 12-00-070.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-22 12-00-020.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-22 12-00-040.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-23 12-00-040.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-23 12-00-050.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-24 12-00-040.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-25 12-00-010.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-25 12-00-030.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-26 12-00-010.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-26 12-00-030.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-27 12-00-030.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-27 12-00-040.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-28 12-00-020.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-28 12-00-030.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-29 12-00-050.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-29 12-00-070.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-30 12-00-050.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-30 12-00-070.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-09 12-00-010.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-16 12-00-070.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Logs\2010-11-24 12-00-020.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\filelist.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-0.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-1.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-10.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-100.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-101.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-102.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-103.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-104.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-105.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-106.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-107.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-108.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-109.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-11.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-110.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-111.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-112.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-113.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-26.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-27.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-28.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-29.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-3.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-30.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-31.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-32.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-33.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-34.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-35.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-36.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-37.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-38.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-39.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-4.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-40.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-41.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-42.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-44.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-45.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-46.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-47.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-48.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-49.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-5.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-50.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-51.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-52.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-53.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-54.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-55.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-56.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-57.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-58.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-59.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-6.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-60.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-62.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-63.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-64.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-65.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-66.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-67.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-68.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-69.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-7.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-70.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-71.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-72.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-73.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-74.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-75.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-76.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-77.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-78.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-79.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-80.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-81.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-82.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-83.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-84.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-85.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-86.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-87.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-88.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-89.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-9.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-90.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-91.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-92.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-93.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-94.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-95.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-96.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-97.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-98.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-99.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-114.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-132.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-150.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-25.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-43.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-61.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-8.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-115.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-116.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-117.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-118.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-119.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-12.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-120.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-121.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-122.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-123.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-124.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-125.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-126.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-127.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-128.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-129.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-13.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-130.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-131.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-133.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-134.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-135.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-136.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-137.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-138.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-139.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-14.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-140.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-141.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-142.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-143.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-144.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-145.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-146.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-147.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-148.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-149.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-15.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-151.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-152.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-153.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-154.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-155.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-156.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-157.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-158.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-159.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-16.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-160.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-161.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-17.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-18.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-19.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-2.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-20.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-21.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-22.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-23.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-02 19-39-410\regb-24.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\quarantinew\2010-11-03 12-31-440\filelist.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Results\Evidence.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Results\Junk.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Results\Registry.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\documents and settings\robert niemi\application data\error fix\Results\Update.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\program files\error fix\PW\general.html (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\program files\error fix\PW\optimizations.html (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\program files\error fix\PW\privacy.html (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\program files\error fix\PW\scheduler.html (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\program files\error fix\PW\startup.html (Rogue.ErrorFix) -> Quarantined and deleted successfully.
    c:\program files\error fix\PW\wizard.css (Rogue.ErrorFix) -> Quarantined and deleted successfully.

    GMER 1.0.15.15641 - http://www.gmer.net
    Rootkit quick scan 2011-12-07 12:37:05
    Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e FUJITSU_MHW2160BJ_FFS_G2 rev.0085001C
    Running: up8dw7kf.exe; Driver: C:\DOCUME~1\ROBERT~1\LOCALS~1\Temp\ageyiaob.sys


    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
    AttachedDevice \Driver\Tcpip \Device\Ip WRkrn.sys (Webroot SecureAnywhere/Webroot)
    AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Tcp WRkrn.sys (Webroot SecureAnywhere/Webroot)
    AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Udp WRkrn.sys (Webroot SecureAnywhere/Webroot)
    AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\RawIp WRkrn.sys (Webroot SecureAnywhere/Webroot)
    AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
    AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 WRkrn.sys (Webroot SecureAnywhere/Webroot)
    AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 WRkrn.sys (Webroot SecureAnywhere/Webroot)

    ---- EOF - GMER 1.0.15 ----

    aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
    Run date: 2011-12-07 14:15:55
    -----------------------------
    14:15:55.765 OS Version: Windows 5.1.2600 Service Pack 3
    14:15:55.765 Number of processors: 2 586 0xF0D
    14:15:55.765 ComputerName: ROBERT-1270A79B UserName: Robert Niemi
    14:15:56.765 Initialize success
    14:17:00.015 AVAST engine defs: 11120701
    14:17:06.781 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
    14:17:06.781 Disk 0 Vendor: FUJITSU_MHW2160BJ_FFS_G2 0085001C Size: 152627MB BusType: 3
    14:17:08.812 Disk 0 MBR read successfully
    14:17:08.812 Disk 0 MBR scan
    14:17:08.890 Disk 0 Windows XP default MBR code
    14:17:08.890 Disk 0 scanning sectors +312576705
    14:17:09.000 Disk 0 scanning C:\WINDOWS\system32\drivers
    14:17:25.437 Service scanning
    14:17:26.593 Service WRkrn C:\WINDOWS\System32\drivers\WRkrn.sys **LOCKED** 32
    14:17:27.093 Modules scanning
    14:17:33.656 Disk 0 trace - called modules:
    14:17:33.656 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
    14:17:33.656 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a528ab8]
    14:17:33.656 3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x8a529d98]
    14:17:34.859 AVAST engine scan C:\WINDOWS
    14:17:40.000 AVAST engine scan C:\WINDOWS\system32
    14:19:33.875 AVAST engine scan C:\WINDOWS\system32\drivers
    14:19:53.281 AVAST engine scan C:\Documents and Settings\Robert Niemi
    14:34:00.437 AVAST engine scan C:\Documents and Settings\All Users
    14:38:27.781 Scan finished successfully
    17:16:34.281 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Robert Niemi\Desktop\MBR.dat "
    17:16:34.281 The log file has been saved successfully to "C:\Documents and Settings\Robert Niemi\Desktop\aswMBR.txt "
     
    rgn,
    #1
  2. 2011/12/07
    rgn

    rgn Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    212
    Likes Received:
    0
    .
    DDS (Ver_2011-08-26.01) - NTFSx86
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_29
    Run by Robert Niemi at 17:19:46 on 2011-12-07
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.918 [GMT -7:00]
    .
    AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    AV: Webroot SecureAnywhere *Enabled/Updated* {D486329C-1488-4CEB-9CC8-D662B732D904}
    .
    ============== Running Processes ===============
    .
    C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
    C:\Program Files\AVG\AVG2012\avgcsrvx.exe
    C:\Program Files\Webroot\WRSA.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\system32\svchost.exe -k netsvcs
    svchost.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
    svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\AVG\AVG2012\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Cox\Secure Online Backup for Windows\Filesystem Watcher\DigiData.FilesystemWatcher.Service.Watcher.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\AVG\AVG2012\avgnsx.exe
    C:\Program Files\AVG\AVG2012\avgemcx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Kodak\AiO\center\KodakSvc.exe
    C:\WINDOWS\System32\svchost.exe -k HPZ12
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Cox\Secure Online Backup for Windows\Scheduler\OnlineBackup.SchedulerService.exe
    C:\WINDOWS\System32\svchost.exe -k HPZ12
    C:\Program Files\Secunia\PSI\PSIA.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
    C:\Program Files\Kodak\AiO\Center\EKDiscovery.exe
    C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
    C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
    C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    svchost.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\Program Files\Dell\MediaDirect\PCMService.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\SoftSwift\Enhanced Windows Backup\EWBackup.exe
    C:\Program Files\AVG\AVG2012\avgtray.exe
    C:\Program Files\Cox\Secure Online Backup for Windows\Auto Update\OnlineBackup.UpdateSystemTray.exe
    C:\Program Files\Cox\Secure Online Backup for Windows\vewatch.exe
    C:\Program Files\AVG Secure Search\vprot.exe
    C:\Program Files\Webroot\WRSA.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\program files\real\realplayer\update\realsched.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Secunia\PSI\psi_tray.exe
    C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\Program Files\Secunia\PSI\sua.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    C:\Program Files\AVG\AVG2012\avgcsrvx.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\Documents and Settings\Robert Niemi\My Documents\Downloads\aswMBR.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uDefault_Search_URL = hxxp://www.google.com/ie
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant = hxxp://www.google.com/ie
    uURLSearchHooks: H - No File
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\8.0.0.40\AVG Secure Search_toolbar.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\8.0.0.40\AVG Secure Search_toolbar.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    {e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [SpybotSD TeaTimer] "c:\program files\spybot - search & destroy\TeaTimer.exe "
    uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe "
    uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
    uRun: [Google Update] "c:\documents and settings\robert niemi\local settings\application data\google\update\GoogleUpdate.exe" /c
    mRun: [NvCplDaemon] "RUNDLL32.EXE" c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [nwiz] "nwiz.exe" /installquiet
    mRun: [NVHotkey] "rundll32.exe" nvHotkey.dll,Start
    mRun: [NvMediaCenter] "RUNDLL32.EXE" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
    mRun: [SigmatelSysTrayApp] "%ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe "
    mRun: [LogitechCommunicationsManager] "c:\program files\common files\logitech\lcommgr\Communications_Helper.exe "
    mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
    mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe "
    mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe "
    mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
    mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
    mRun: [Broadcom Wireless Manager UI] "c:\windows\system32\WLTRAY.exe "
    mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe "
    mRun: [Conime] %windir%\system32\conime.exe
    mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
    mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe "
    mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam10\QuickCam10.exe" /hide
    mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
    mRun: [EWBACKUP] "c:\program files\softswift\enhanced windows backup\EWBackup.exe" /Q /START
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe "
    mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe "
    mRun: [Online Backup Auto Update] "c:\program files\cox\secure online backup for windows\auto update\OnlineBackup.UpdateSystemTray.exe "
    mRun: [Vault Explorer Cache Watcher] "c:\program files\cox\secure online backup for windows\vewatch.exe "
    mRun: [vProt] "c:\program files\avg secure search\vprot.exe "
    mRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
    mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [WRSVC] "c:\program files\webroot\WRSA.exe" -ul
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe "
    mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe "
    dRun: [Picasa Media Detector] c:\program files\picasa2\PicasaMediaDetector.exe
    StartupFolder: c:\docume~1\robert~1\startm~1\programs\startup\buffal~1.lnk - c:\program files\buffalo\hdbackup\HDBackup.exe
    StartupFolder: c:\docume~1\robert~1\startm~1\programs\startup\secure~1.lnk - c:\program files\cox\secure online backup for windows\syncnshare\OnlineBackup.SyncNShare.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} - hxxps://h20364.www2.hp.com/CSMWeb/Customer/cabs/HPISDataManager.CAB
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1219612989109
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
    TCP: Interfaces\{C7509ECE-E677-4B99-8EBF-EA3F5B96AF3E} : DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
    Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\8.0.1\ViProtocol.dll
    AppInit_DLLs: c:\progra~1\google\google~2\goec62~1.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\documents and settings\robert niemi\application data\mozilla\firefox\profiles\f7u16t3c.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    FF - prefs.js: browser.startup.homepage - hxxp://www.cnn.com/
    FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bdb2ff5f9-2bc3-4fa5-9631-f81eb0783247%7D&mid=aae3105e875147d19325d1570ad78eba-e57502c99e91e0771e8eb3d72d6fe5ba10bcec2a&ds=AVG&v=8.0.0.34.1&lang=en&pr=fr&d=2011-10-09%2012%3A13%3A11&sap=ku&q=
    FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
    FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
    FF - component: c:\documents and settings\robert niemi\application data\mozilla\firefox\profiles\f7u16t3c.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
    FF - component: c:\documents and settings\robert niemi\application data\mozilla\firefox\profiles\f7u16t3c.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll
    FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
    FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
    FF - plugin: c:\documents and settings\robert niemi\application data\move networks\plugins\npqmp071503000010.dll
    FF - plugin: c:\documents and settings\robert niemi\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll
    FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll
    FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
    FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
    FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
    FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
    FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
    FF - plugin: c:\program files\picasa2\npPicasa2.dll
    FF - plugin: c:\program files\picasa2\npPicasa3.dll
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - true
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 23120]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592]
    R0 WRkrn;WRkrn;c:\windows\system32\drivers\WRkrn.sys [2011-11-1 107336]
    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 230608]
    R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 40016]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-4-5 295248]
    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
    R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
    R2 FilesystemWatcher;Filesystem Watcher;c:\program files\cox\secure online backup for windows\filesystem watcher\DigiData.FilesystemWatcher.Service.Watcher.exe [2011-7-16 24576]
    R2 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-8-18 30192]
    R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\kodak\aio\center\EKDiscovery.exe [2009-5-4 279960]
    R2 KodakSvc;Kodak AiO Device Service;c:\program files\kodak\aio\center\KodakSvc.exe [2009-4-17 32768]
    R2 OnlineBackupSchedulerService;Online Backup Scheduler;c:\program files\cox\secure online backup for windows\scheduler\OnlineBackup.SchedulerService.exe [2011-7-17 24576]
    R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2010-12-21 987704]
    R2 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2010-12-21 399416]
    R2 vToolbarUpdater;vToolbarUpdater;c:\program files\common files\avg secure search\vtoolbarupdater\8.0.1\ToolbarUpdater.exe [2011-10-9 246600]
    R2 WRSVC;WRSVC;c:\program files\webroot\WRSA.exe [2011-11-1 637208]
    R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-4-14 134608]
    R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24272]
    R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 16720]
    R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]
    S1 SASDIFSV;SASDIFSV; [x]
    S1 SASKUTIL;SASKUTIL; [x]
    S2 gupdate1c9dcb12a09c418;Google Update Service (gupdate1c9dcb12a09c418);c:\program files\google\update\GoogleUpdate.exe [2009-5-24 133104]
    S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-5-24 133104]
    S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
    S3 SASENUM;SASENUM; [x]
    .
    =============== File Associations ===============
    .
    JSEFile=NOTEPAD.EXE %1
    VBEFile=NOTEPAD.EXE %1
    VBSFile=NOTEPAD.EXE %1
    .
    =============== Created Last 30 ================
    .
    2011-12-07 18:27:45 -------- d-----w- c:\documents and settings\robert niemi\application data\Malwarebytes
    2011-12-07 18:27:32 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
    2011-12-07 18:27:26 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-12-07 18:27:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-11-30 03:16:32 -------- d-----w- c:\documents and settings\robert niemi\application data\WindSolutions
    2011-11-30 03:16:30 -------- d-----w- c:\documents and settings\all users\application data\WindSolutions
    2011-11-27 16:37:43 11776 ----a-w- c:\program files\mozilla firefox\plugins\nprjplug.dll
    2011-11-27 16:37:08 -------- d-----w- c:\program files\common files\xing shared
    2011-11-27 16:36:50 150696 ----a-w- c:\program files\mozilla firefox\plugins\nppl3260.dll
    2011-11-27 16:36:31 108544 ----a-w- c:\program files\mozilla firefox\plugins\nprpjplug.dll
    2011-11-26 19:53:08 -------- d-----w- c:\program files\iTunes
    2011-11-13 20:02:45 -------- d-----w- C:\2db9745ffc895c5306baaa6d7273
    2011-11-11 21:36:36 -------- d-----w- c:\program files\Magical Jelly Bean
    2011-11-09 23:24:11 -------- d-----w- c:\windows\system32\cache
    .
    ==================== Find3M ====================
    .
    2011-12-07 17:49:41 141272 ----a-w- c:\windows\system32\WRusr.dll
    2011-12-07 17:49:41 107336 ----a-w- c:\windows\system32\drivers\WRkrn.sys
    2011-11-27 16:36:16 499712 ----a-w- c:\windows\system32\msvcp71.dll
    2011-11-27 16:36:16 348160 ----a-w- c:\windows\system32\msvcr71.dll
    2011-11-14 20:05:22 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-10-24 21:29:02 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2011-10-24 21:29:02 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-10-07 13:23:48 230608 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2011-10-04 13:21:42 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
    2011-10-03 12:06:03 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-10-03 09:37:52 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
    2011-09-26 18:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
    2011-09-26 18:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
    2011-09-26 18:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
    2011-09-13 13:30:10 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
    .
    ============= FINISH: 17:21:31.89 ===============
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 8/11/2008 7:49:05 PM
    System Uptime: 12/7/2011 12:42:14 PM (5 hours ago)
    .
    Motherboard: Dell Inc. | | 0WY040
    Processor: Intel(R) Core(TM)2 Duo CPU T5270 @ 1.40GHz | Microprocessor | 1396/200mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 146 GiB total, 90.848 GiB free.
    D: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Broadcom 440x 10/100 Integrated Controller
    Device ID: PCI\VEN_14E4&DEV_170C&SUBSYS_02281028&REV_02\4&28D6DE3B&0&00F0
    Manufacturer: Broadcom
    Name: Broadcom 440x 10/100 Integrated Controller
    PNP Device ID: PCI\VEN_14E4&DEV_170C&SUBSYS_02281028&REV_02\4&28D6DE3B&0&00F0
    Service: bcm4sbxp
    .
    ==== System Restore Points ===================
    .
    RP1403: 9/9/2011 12:00:27 PM - Software Distribution Service 3.0
    RP1404: 9/10/2011 12:00:22 PM - Software Distribution Service 3.0
    RP1405: 9/11/2011 12:00:21 PM - Software Distribution Service 3.0
    RP1406: 9/12/2011 12:00:50 PM - Software Distribution Service 3.0
    RP1407: 9/13/2011 12:00:22 PM - Software Distribution Service 3.0
    RP1408: 9/14/2011 12:46:01 PM - System Checkpoint
    RP1409: 9/15/2011 12:00:27 PM - Software Distribution Service 3.0
    RP1410: 9/16/2011 11:39:17 AM - Software Distribution Service 3.0
    RP1411: 9/17/2011 12:00:23 PM - Software Distribution Service 3.0
    RP1412: 9/18/2011 12:00:26 PM - Software Distribution Service 3.0
    RP1413: 9/18/2011 4:52:20 PM - Software Distribution Service 3.0
    RP1414: 9/19/2011 12:00:24 PM - Software Distribution Service 3.0
    RP1415: 9/20/2011 12:00:40 PM - Software Distribution Service 3.0
    RP1416: 9/21/2011 12:00:26 PM - Software Distribution Service 3.0
    RP1417: 9/21/2011 2:10:41 PM - Software Distribution Service 3.0
    RP1418: 9/22/2011 12:00:22 PM - Software Distribution Service 3.0
    RP1419: 9/23/2011 7:40:06 AM - Software Distribution Service 3.0
    RP1420: 9/25/2011 12:00:24 PM - Software Distribution Service 3.0
    RP1421: 9/26/2011 12:00:31 PM - Software Distribution Service 3.0
    RP1422: 9/27/2011 3:01:17 PM - Software Distribution Service 3.0
    RP1423: 9/28/2011 12:00:31 PM - Software Distribution Service 3.0
    RP1424: 9/28/2011 4:04:52 PM - Installed Solution Disk
    RP1425: 9/29/2011 12:00:20 PM - Software Distribution Service 3.0
    RP1426: 9/29/2011 2:47:24 PM - Installed Solution Disk
    RP1427: 9/30/2011 12:00:37 PM - Software Distribution Service 3.0
    RP1428: 10/1/2011 12:00:23 PM - Software Distribution Service 3.0
    RP1429: 10/2/2011 12:00:27 PM - Software Distribution Service 3.0
    RP1430: 10/3/2011 12:00:34 PM - Software Distribution Service 3.0
    RP1431: 10/4/2011 12:00:25 PM - Software Distribution Service 3.0
    RP1432: 10/5/2011 9:20:27 AM - Software Distribution Service 3.0
    RP1433: 10/5/2011 12:00:37 PM - Software Distribution Service 3.0
    RP1434: 10/6/2011 12:00:21 PM - Software Distribution Service 3.0
    RP1435: 10/7/2011 12:00:35 PM - Software Distribution Service 3.0
    RP1436: 10/8/2011 12:00:24 PM - Software Distribution Service 3.0
    RP1437: 10/9/2011 11:46:33 AM - Installed AVG 2012
    RP1438: 10/9/2011 11:47:42 AM - Removed AVG 2011
    RP1439: 10/9/2011 11:53:35 AM - Installed AVG 2012
    RP1440: 10/9/2011 12:20:07 PM - Removed AVG 2011
    RP1441: 10/9/2011 12:57:16 PM - Software Distribution Service 3.0
    RP1442: 10/10/2011 12:00:36 PM - Software Distribution Service 3.0
    RP1443: 10/11/2011 12:00:23 PM - Software Distribution Service 3.0
    RP1444: 10/12/2011 12:46:02 PM - System Checkpoint
    RP1445: 10/13/2011 12:00:23 PM - Software Distribution Service 3.0
    RP1446: 10/13/2011 2:57:30 PM - Software Distribution Service 3.0
    RP1447: 10/14/2011 12:00:31 PM - Software Distribution Service 3.0
    RP1448: 10/14/2011 3:24:09 PM - Software Distribution Service 3.0
    RP1449: 10/15/2011 1:00:20 PM - Software Distribution Service 3.0
    RP1450: 10/16/2011 1:00:21 PM - Software Distribution Service 3.0
    RP1451: 10/17/2011 1:00:46 PM - Software Distribution Service 3.0
    RP1452: 10/18/2011 1:00:20 PM - Software Distribution Service 3.0
    RP1453: 10/19/2011 1:00:31 PM - Software Distribution Service 3.0
    RP1454: 10/20/2011 1:00:25 PM - Software Distribution Service 3.0
    RP1455: 10/20/2011 2:06:58 PM - Installed iTunes
    RP1456: 10/20/2011 5:29:45 PM - Software Distribution Service 3.0
    RP1457: 10/21/2011 1:01:05 PM - Software Distribution Service 3.0
    RP1458: 10/21/2011 2:31:31 PM - Software Distribution Service 3.0
    RP1459: 10/22/2011 1:00:20 PM - Software Distribution Service 3.0
    RP1460: 10/23/2011 1:00:22 PM - Software Distribution Service 3.0
    RP1461: 10/24/2011 1:01:09 PM - Software Distribution Service 3.0
    RP1462: 10/24/2011 2:57:52 PM - Software Distribution Service 3.0
    RP1463: 10/25/2011 1:00:28 PM - Software Distribution Service 3.0
    RP1464: 10/26/2011 1:01:32 PM - Software Distribution Service 3.0
    RP1465: 10/27/2011 1:00:35 PM - Software Distribution Service 3.0
    RP1466: 10/28/2011 1:00:31 PM - Software Distribution Service 3.0
    RP1467: 10/29/2011 1:00:20 PM - Software Distribution Service 3.0
    RP1468: 10/30/2011 1:00:31 PM - Software Distribution Service 3.0
    RP1469: 10/31/2011 1:01:33 PM - Software Distribution Service 3.0
    RP1470: 11/1/2011 1:00:23 PM - Software Distribution Service 3.0
    RP1471: 11/2/2011 1:00:22 PM - Software Distribution Service 3.0
    RP1472: 11/2/2011 4:08:13 PM - Software Distribution Service 3.0
    RP1473: 11/3/2011 1:00:17 PM - Software Distribution Service 3.0
    RP1474: 11/4/2011 1:00:18 PM - Software Distribution Service 3.0
    RP1475: 11/6/2011 4:11:53 PM - System Checkpoint
    RP1476: 11/7/2011 1:00:17 PM - Software Distribution Service 3.0
    RP1477: 11/8/2011 1:00:18 PM - Software Distribution Service 3.0
    RP1478: 11/9/2011 1:00:37 PM - Software Distribution Service 3.0
    RP1479: 11/10/2011 1:00:18 PM - Software Distribution Service 3.0
    RP1480: 11/11/2011 11:28:40 AM - Software Distribution Service 3.0
    RP1481: 11/11/2011 1:33:24 PM - Software Distribution Service 3.0
    RP1482: 11/12/2011 1:00:18 PM - Software Distribution Service 3.0
    RP1483: 11/13/2011 1:00:21 PM - Software Distribution Service 3.0
    RP1484: 11/13/2011 2:04:00 PM - Software Distribution Service 3.0
    RP1485: 11/14/2011 1:00:45 PM - Software Distribution Service 3.0
    RP1486: 11/15/2011 1:00:19 PM - Software Distribution Service 3.0
    RP1487: 11/16/2011 1:00:20 PM - Software Distribution Service 3.0
    RP1488: 11/17/2011 1:00:21 PM - Software Distribution Service 3.0
    RP1489: 11/17/2011 2:21:39 PM - Software Distribution Service 3.0
    RP1490: 11/18/2011 1:00:25 PM - Software Distribution Service 3.0
    RP1491: 11/19/2011 2:46:11 PM - Software Distribution Service 3.0
    RP1492: 11/20/2011 6:04:23 PM - Software Distribution Service 3.0
    RP1493: 11/21/2011 1:02:06 PM - Software Distribution Service 3.0
    RP1494: 11/22/2011 1:00:18 PM - Software Distribution Service 3.0
    RP1495: 11/23/2011 1:00:22 PM - Software Distribution Service 3.0
    RP1496: 11/24/2011 1:00:18 PM - Software Distribution Service 3.0
    RP1497: 11/25/2011 1:00:20 PM - Software Distribution Service 3.0
    RP1498: 11/26/2011 1:00:21 PM - Software Distribution Service 3.0
    RP1499: 11/27/2011 1:00:18 PM - Software Distribution Service 3.0
    RP1500: 11/28/2011 1:00:21 PM - Software Distribution Service 3.0
    RP1501: 11/29/2011 1:00:19 PM - Software Distribution Service 3.0
    RP1502: 11/29/2011 2:54:58 PM - Installed Java(TM) 6 Update 29
    RP1503: 11/30/2011 1:00:58 PM - Software Distribution Service 3.0
    RP1504: 12/1/2011 1:00:19 PM - Software Distribution Service 3.0
    RP1505: 12/2/2011 1:00:26 PM - Software Distribution Service 3.0
    RP1506: 12/3/2011 1:00:17 PM - Software Distribution Service 3.0
    RP1507: 12/4/2011 1:00:21 PM - Software Distribution Service 3.0
    RP1508: 12/5/2011 1:00:39 PM - Software Distribution Service 3.0
    RP1509: 12/6/2011 1:00:19 PM - Software Distribution Service 3.0
    RP1510: 12/7/2011 1:00:17 PM - Software Distribution Service 3.0
    .
    ==== Installed Programs ======================
    .
    32 Bit HP CIO Components Installer
    Acrobat.com
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 11 Plugin
    Adobe Reader X (10.1.1)
    aiofw
    aioprnt
    aioscnnr
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    Auslogics BoostSpeed
    Auslogics Disk Defrag
    Auslogics Disk Defrag ScreenSaver
    Auslogics Duplicate File Finder
    Auslogics Registry Defrag
    AVG 2012
    AVG PC Tuneup 2011
    AVG Security Toolbar
    Bonjour
    Broadcom 440x 10/100 Integrated Controller
    BUFFALO Disk Backup Utility
    C4USelfUpdater
    Camera Window
    Canon Camera Window for ZoomBrowser EX
    Canon PhotoRecord
    Canon Utilities File Viewer Utility 1.3
    Canon Utilities PhotoStitch 3.1
    Canon Utilities RemoteCapture 2.7
    Canon Utilities ZoomBrowser EX
    CCleaner
    center
    Compatibility Pack for the 2007 Office system
    Conexant HDA D330 MDC V.92 Modem
    Cox Secure Online Backup for Windows
    Dell Driver Download Manager
    Dell Resource CD
    Dell Support Center (Support Software)
    Dell Touchpad
    Dell Wireless WLAN Card Utility
    Enhanced Windows Backup
    File Viewer Utility 1.3
    FoxyTunes for Firefox
    Google Chrome
    Google Desktop
    Google Earth
    Google Toolbar for Internet Explorer
    Google Update Helper
    Google Updater
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    InfraRecorder
    iPod for Windows 2006-03-23
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 29
    KODAK All-in-One Printer Software
    ksDIP
    Logitech Audio Echo Cancellation Component
    Logitech QuickCam
    Logitech Video Enumerator
    Logitech® Camera Driver
    Magical Jelly Bean KeyFinder
    Malwarebytes' Anti-Malware version 1.51.2.1300
    MediaDirect
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2572067)
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Easy Assist v2
    Microsoft IntelliPoint 7.1
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Live Meeting 2007
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office XP Professional
    Microsoft Silverlight
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    MobileMe Control Panel
    Move Media Player
    Mozilla Firefox 8.0 (x86 en-US)
    Mozilla Thunderbird (8.0)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP2 and SOAP Toolkit 3.0
    MSXML 6 Service Pack 2 (KB954459)
    My 3D Christmas Tree Animated Wallpaper
    NVIDIA Drivers
    PhotoStitch
    Picasa 3
    PreReq
    QuickSet
    QuickTime
    RealNetworks - Microsoft Visual C++ 2008 Runtime
    RealPlayer
    RealUpgrade 1.1
    RemoteCapture 2.7.3
    Secunia PSI (2.0.0.1003)
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Windows Internet Explorer 7 (KB938127-v2)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 8 (KB2183461)
    Security Update for Windows Internet Explorer 8 (KB2360131)
    Security Update for Windows Internet Explorer 8 (KB2416400)
    Security Update for Windows Internet Explorer 8 (KB2482017)
    Security Update for Windows Internet Explorer 8 (KB2497640)
    Security Update for Windows Internet Explorer 8 (KB2510531)
    Security Update for Windows Internet Explorer 8 (KB2530548)
    Security Update for Windows Internet Explorer 8 (KB2544521)
    Security Update for Windows Internet Explorer 8 (KB2559049)
    Security Update for Windows Internet Explorer 8 (KB2586448)
    Security Update for Windows Internet Explorer 8 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB972260)
    Security Update for Windows Internet Explorer 8 (KB974455)
    Security Update for Windows Internet Explorer 8 (KB976325)
    Security Update for Windows Internet Explorer 8 (KB978207)
    Security Update for Windows Internet Explorer 8 (KB981332)
    Security Update for Windows Internet Explorer 8 (KB982381)
    Security Update for Windows XP (KB2544893-v2)
    SigmaTel Audio
    Skype web features
    Skypeâ„¢ 4.2
    SpeedFan (remove only)
    Spybot - Search & Destroy
    System Checkup 3.0
    TBS WMP Plug-in
    UMVPLStandalone
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows Internet Explorer 8 (KB971180)
    Update for Windows Internet Explorer 8 (KB976662)
    Update for Windows Internet Explorer 8 (KB976749)
    Update for Windows Internet Explorer 8 (KB980182)
    Update for Windows XP (KB2641690)
    Video Poker for Winners
    WebFldrs XP
    Webroot SecureAnywhere
    Windows Backup Utility
    Windows Defender
    Windows Imaging Component
    Windows Installer Clean Up
    Windows Internet Explorer 8
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    .
    ==== Event Viewer Messages From Past Week ========
    .
    12/4/2011 9:29:21 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Dnscache service.
    12/4/2011 4:45:08 PM, error: NetBT [4321] - The name "MSHOME :1d" could not be registered on the Interface with IP address 192.168.1.102. The machine with the IP address 192.168.1.103 did not allow the name to be claimed by this machine.
    12/4/2011 1:59:56 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SASDIFSV SASKUTIL
    12/4/2011 1:59:56 PM, error: Service Control Manager [7023] - The HID Input Service service terminated with the following error: The system cannot find the file specified.
    12/4/2011 1:59:56 PM, error: Service Control Manager [7001] - The ClipBook service depends on the Network DDE service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    12/2/2011 4:01:59 PM, error: nv [14] - Unknown error on CMDre 00000000 00000400 00010000 00000004 00000084
    .
    ==== End Of File ===========================
     
    rgn,
    #2

  3. to hide this advert.

  4. 2011/12/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    =============================================================

    You're running two AV programs, AVG and Webroot.
    One of the has to go.
    If AVG make sure to use AVG Remover: http://www.avg.com/us-en/utilities

    When done....

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode (How to...)

    2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  5. 2011/12/08
    rgn

    rgn Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    212
    Likes Received:
    0
    google won't open

    How do I disable Script blocking?

    This seems like such a risky operation for a rookie to perform. I'm afraid of ending up with a disabled laptop. What will happen to my system if I opt not to clean out this Malware?
     
    Last edited: 2011/12/08
    rgn,
    #4
  6. 2011/12/08
    Westside

    Westside Inactive Alumni

    Joined:
    2003/03/30
    Messages:
    4,506
    Likes Received:
    14
    Do you have the No Script add-on? If so, disable it.
     
  7. 2011/12/08
    rgn

    rgn Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    212
    Likes Received:
    0
    google won't load

    How do I get the download to install directly to the desktop?
     
    rgn,
    #6
  8. 2011/12/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Download wherever you want and then move the file to your desktop.

    You have two such programs running, Spybot and Windows Defender.

    Disable TeaTimer, as it'll interfere with the cleaning process:
    Right click Spybot's TeaTimer System Tray Icon.
    Click Exit Spybot-S&D Resident.
    TeaTimer closes.
    NOTE. If on re-boot, Spybot inquires about registry change(s), allow it.

    Alternatively, I suggest, you uninstall Spybot since it's a tool of the past.

    ============================================================

    Disable Windows Defender, as it'll interfere with cleaning process:
    - Open Windows Defender by clicking the Start, clicking All Programs, and then clicking Windows Defender.
    - Click Tools
    then...

    ++ Windows XP:
    - Click General Settings
    - Scroll down to Real Time Protection Options
    - Uncheck Turn on Real Time Protection
    - After you uncheck this, click on the Save button
    - Close Windows Defender

    ++ Windows Vista:
    - Click Options
    - Under Administrator options, clear the Use Windows Defender check box, and then click Save.

    Enable Windows Defender, when all cleaning is done.
     
  9. 2011/12/09
    rgn

    rgn Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    212
    Likes Received:
    0
    google won't load in FF8

    My google search engine is working now. So, is Bing, and yahoo. Do I need to continue this process, or consider it fixed?
    Bob
     
    rgn,
    #8
  10. 2011/12/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    If you read my rules carefully....
     
  11. 2011/12/09
    rgn

    rgn Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    212
    Likes Received:
    0
    google won't load in FF8

    I continue with the cleaning.
     
    rgn,
    #10
  12. 2011/12/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OK......
    I need Combofix log then.
     
  13. 2011/12/10
    rgn

    rgn Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    212
    Likes Received:
    0
    google won't run in FF8

    ComboFix 11-12-10.01 - Robert Niemi 12/10/2011 12:14:54.1.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1450 [GMT -7:00]
    Running from: c:\documents and settings\Robert Niemi\Desktop\ComboFix.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters\Driver Detective\Downloads
    c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters\Driver Detective\Downloads\R173730 .exe
    c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters\Driver Detective\Downloads\R173730 .exe.dat
    c:\documents and settings\All Users\Application Data\TEMP
    c:\documents and settings\All Users\Application Data\TEMP\AVG\avgfinst.dat
    c:\documents and settings\All Users\Application Data\TEMP\AVG\avi7.avg
    c:\documents and settings\All Users\Application Data\TEMP\AVG\crt_x64.msi
    c:\documents and settings\All Users\Application Data\TEMP\AVG\files.dat
    c:\documents and settings\All Users\Application Data\TEMP\AVG\incavi.avm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_cz.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_da.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_fr.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ge.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_hu.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_id.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_in.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_it.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_jp.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ko.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ms.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_nl.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pb.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pl.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pt.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ru.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sc.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sk.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sp.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_tr.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_us.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zh.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zt.htm
    c:\documents and settings\All Users\Application Data\TEMP\AVG\microavi.avg
    c:\documents and settings\All Users\Application Data\TEMP\AVG\miniavi.avg
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.dat
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.exe
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.ini
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupcz.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupda.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupfr.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupge.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setuphu.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupid.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupin.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupit.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupjp.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupko.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupms.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupnl.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setuppb.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setuppl.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setuppt.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupru.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupsc.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupsk.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupsp.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setuptr.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupus.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupzh.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\setupzt.lns
    c:\documents and settings\All Users\Application Data\TEMP\AVG\vcredis1.cab
    c:\documents and settings\All Users\Application Data\TEMP\AVG\vcredist.msi
    c:\documents and settings\Robert Niemi\Application Data\PriceGong
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\1.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\2229.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\3911.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\a.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\b.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\c.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\d.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\e.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\f.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\g.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\h.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\i.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\j.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\k.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\l.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\m.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\mru.xml
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\n.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\o.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\p.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\q.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\r.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\s.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\t.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\u.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\v.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\w.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\wlu.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\x.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\y.txt
    c:\documents and settings\Robert Niemi\Application Data\PriceGong\Data\z.txt
    c:\documents and settings\Robert Niemi\GoToAssistDownloadHelper.exe
    c:\documents and settings\Robert Niemi\WINDOWS
    c:\windows\system32\Cache
    c:\windows\system32\Cache\272512937d9e61a4.fb
    c:\windows\system32\Cache\287204568329e189.fb
    c:\windows\system32\Cache\28bc8f716fd76a47.fb
    c:\windows\system32\Cache\2c53092c95605355.fb
    c:\windows\system32\Cache\3917078cb68ec657.fb
    c:\windows\system32\Cache\590ba23ce359fd0c.fb
    c:\windows\system32\Cache\610289e025a3ee9a.fb
    c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
    c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
    c:\windows\system32\Cache\94a67d894296d228.fb
    c:\windows\system32\Cache\ad10a52aff5e038d.fb
    c:\windows\system32\Cache\d201ef9910cd39de.fb
    c:\windows\system32\Cache\d2e94710a5708128.fb
    c:\windows\system32\Cache\d79b9dfe81484ec4.fb
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Legacy_NPF
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-11-10 to 2011-12-10 )))))))))))))))))))))))))))))))
    .
    .
    2011-12-07 18:27 . 2011-12-07 18:27 -------- d-----w- c:\documents and settings\Robert Niemi\Application Data\Malwarebytes
    2011-12-07 18:27 . 2011-12-07 18:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2011-12-07 18:27 . 2011-12-07 18:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-12-07 18:27 . 2011-09-01 00:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-11-30 03:16 . 2011-12-04 19:16 -------- d-----w- c:\documents and settings\Robert Niemi\Application Data\WindSolutions
    2011-11-30 03:16 . 2011-11-30 03:20 -------- d-----w- c:\documents and settings\All Users\Application Data\WindSolutions
    2011-11-29 21:56 . 2011-11-29 21:56 -------- d-----w- c:\program files\Common Files\Java
    2011-11-27 16:37 . 2011-11-27 16:37 11776 ----a-w- c:\program files\Mozilla Firefox\plugins\nprjplug.dll
    2011-11-27 16:37 . 2011-11-27 16:37 -------- d-----w- c:\program files\Common Files\xing shared
    2011-11-27 16:36 . 2011-11-27 16:36 150696 ----a-w- c:\program files\Mozilla Firefox\plugins\nppl3260.dll
    2011-11-27 16:36 . 2011-11-27 16:36 108544 ----a-w- c:\program files\Mozilla Firefox\plugins\nprpjplug.dll
    2011-11-26 19:53 . 2011-11-26 19:54 -------- d-----w- c:\program files\iTunes
    2011-11-14 20:04 . 2011-11-14 20:04 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Solid State Networks
    2011-11-13 20:02 . 2011-11-13 20:02 -------- d-----w- C:\2db9745ffc895c5306baaa6d7273
    2011-11-11 21:36 . 2011-11-11 21:37 -------- d-----w- c:\program files\Magical Jelly Bean
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-11-27 16:36 . 2008-08-12 03:36 499712 ----a-w- c:\windows\system32\msvcp71.dll
    2011-11-27 16:36 . 2008-08-12 03:36 348160 ----a-w- c:\windows\system32\msvcr71.dll
    2011-11-14 20:05 . 2011-05-17 01:42 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-10-24 21:29 . 2011-10-24 21:29 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2011-10-24 21:29 . 2011-10-24 21:29 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2011-10-10 14:22 . 2008-08-12 02:44 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-10-03 12:06 . 2010-04-17 20:38 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-10-03 09:37 . 2010-04-02 16:22 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2011-09-28 07:06 . 2004-08-12 13:56 599040 ----a-w- c:\windows\system32\crypt32.dll
    2011-09-26 18:41 . 2008-07-30 02:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
    2011-09-26 18:41 . 2004-08-12 14:02 220160 ----a-w- c:\windows\system32\oleacc.dll
    2011-09-26 18:41 . 2004-08-12 14:02 20480 ----a-w- c:\windows\system32\oleaccrc.dll
    2011-11-09 03:23 . 2011-03-28 22:27 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    2010-08-24 07:31 . 2008-08-19 01:08 119808 -c--a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg "= "c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-26 68856]
    "Skype "= "c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26194728]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2007-11-17 8495104]
    "nwiz "= "nwiz.exe" [2007-11-17 1626112]
    "NVHotkey "= "nvHotkey.dll" [2007-11-17 86016]
    "NvMediaCenter "= "c:\windows\system32\NvMcTray.dll" [2007-11-17 81920]
    "SigmatelSysTrayApp "= "c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
    "LogitechCommunicationsManager "= "c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-06-26 497200]
    "Google Desktop Search "= "c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-24 30192]
    "dscactivate "= "c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-02-14 16384]
    "SynTPEnh "= "c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-10-26 1024000]
    "DellSupportCenter "= "c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
    "Broadcom Wireless Manager UI "= "c:\windows\system32\WLTRAY.exe" [2008-06-02 2220032]
    "PCMService "= "c:\program files\Dell\MediaDirect\PCMService.exe" [2007-11-01 189736]
    "Conime "= "c:\windows\system32\conime.exe" [2008-04-14 27648]
    "EKIJ5000StatusMonitor "= "c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2009-04-08 1511424]
    "IntelliPoint "= "c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-11-05 1468256]
    "LogitechQuickCamRibbon "= "c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2006-06-26 614960]
    "Dell QuickSet "= "c:\program files\Dell\QuickSet\quickset.exe" [2007-07-20 1228800]
    "EWBACKUP "= "c:\program files\SoftSwift\Enhanced Windows Backup\EWBackup.exe" [2006-02-01 315392]
    "Adobe ARM "= "c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    "Online Backup Auto Update "= "c:\program files\Cox\Secure Online Backup for Windows\Auto Update\OnlineBackup.UpdateSystemTray.exe" [2011-07-17 233472]
    "Vault Explorer Cache Watcher "= "c:\program files\Cox\Secure Online Backup for Windows\vewatch.exe" [2011-03-23 28672]
    "DWQueuedReporting "= "c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
    "APSDaemon "= "c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
    "QuickTime Task "= "c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
    "iTunesHelper "= "c:\program files\iTunes\iTunesHelper.exe" [2011-11-13 421736]
    "TkBellExe "= "c:\program files\real\realplayer\update\realsched.exe" [2011-11-27 296056]
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "Picasa Media Detector "= "c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968]
    .
    c:\documents and settings\Robert Niemi\Start Menu\Programs\Startup\
    BUFFALO Disk Backup Utility.lnk - c:\program files\BUFFALO\HDBackup\HDBackup.exe [2004-7-28 204800]
    Secure Online Backup.lnk - c:\program files\Cox\Secure Online Backup for Windows\SyncNShare\OnlineBackup.SyncNShare.exe [2011-7-17 273560]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
    Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2010-12-21 291896]
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @= "Service "
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Robert Niemi^Start Menu^Programs^Startup^Memeo AutoBackup Launcher.lnk]
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe "=
    "c:\\Program Files\\Messenger\\msmsgs.exe "=
    "c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe "=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe "=
    "c:\\Program Files\\Cox\\Secure Online Backup for Windows\\SyncNShare\\OnlineBackup.SyncNShare.exe "=
    "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe "=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    "c:\\Program Files\\iTunes\\iTunes.exe "=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe "=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "9322:TCP "= 9322:TCP:EKDiscovery
    .
    R2 FilesystemWatcher;Filesystem Watcher;c:\program files\Cox\Secure Online Backup for Windows\Filesystem Watcher\DigiData.FilesystemWatcher.Service.Watcher.exe [7/16/2011 11:59 PM 24576]
    R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\Kodak\AiO\Center\EKDiscovery.exe [5/4/2009 12:15 PM 279960]
    R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\AiO\Center\KodakSvc.exe [4/17/2009 12:08 PM 32768]
    R2 OnlineBackupSchedulerService;Online Backup Scheduler;c:\program files\Cox\Secure Online Backup for Windows\Scheduler\OnlineBackup.SchedulerService.exe [7/17/2011 12:06 AM 24576]
    R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\psia.exe [12/21/2010 5:04 AM 987704]
    R2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [12/21/2010 5:04 AM 399416]
    R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [9/1/2010 1:30 AM 15544]
    S1 SASDIFSV;SASDIFSV; [x]
    S1 SASKUTIL;SASKUTIL; [x]
    S2 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [8/18/2008 6:08 PM 30192]
    S2 gupdate1c9dcb12a09c418;Google Update Service (gupdate1c9dcb12a09c418);c:\program files\Google\Update\GoogleUpdate.exe [5/24/2009 1:45 PM 133104]
    S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [5/24/2009 1:45 PM 133104]
    S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
    S3 SASENUM;SASENUM; [x]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    hpdevmgmt REG_MULTI_SZ hpqcxs08
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-12-03 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 00:57]
    .
    2011-12-10 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-19 03:14]
    .
    2011-12-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-24 20:44]
    .
    2011-12-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-24 20:44]
    .
    2011-12-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1770027372-839522115-1004Core.job
    - c:\documents and settings\Robert Niemi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-06 20:45]
    .
    2011-12-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1770027372-839522115-1004UA.job
    - c:\documents and settings\Robert Niemi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-06 20:45]
    .
    2011-11-28 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20]
    .
    2011-12-10 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1708537768-1770027372-839522115-1004.job
    - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-08 23:14]
    .
    2011-12-08 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1708537768-1770027372-839522115-1004.job
    - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-08 23:14]
    .
    2011-12-10 c:\windows\Tasks\User_Feed_Synchronization-{AA52A37D-5D4F-4BC0-9A31-B58F5B91BB30}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-14 11:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uDefault_Search_URL = hxxp://www.google.com/ie
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
    TCP: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
    DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    FF - ProfilePath - c:\documents and settings\Robert Niemi\Application Data\Mozilla\Firefox\Profiles\f7u16t3c.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    FF - prefs.js: browser.startup.homepage - hxxp://www.cnn.com/
    FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bdb2ff5f9-2bc3-4fa5-9631-f81eb0783247%7D&mid=aae3105e875147d19325d1570ad78eba-e57502c99e91e0771e8eb3d72d6fe5ba10bcec2a&ds=AVG&v=8.0.0.34.1&lang=en&pr=fr&d=2011-10-09%2012%3A13%3A11&sap=ku&q=
    FF - user.js: yahoo.homepage.dontask - true
    .
    .
    ------- File Associations -------
    .
    JSEFile=NOTEPAD.EXE %1
    .
    - - - - ORPHANS REMOVED - - - -
    .
    URLSearchHooks-CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
    Notify-avgrsstarter - (no file)
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-12-10 12:22
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-1708537768-1770027372-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(744)
    c:\windows\System32\BCMLogon.dll
    .
    - - - - - - - > 'explorer.exe'(8500)
    c:\windows\system32\WININET.dll
    c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
    c:\progra~1\WINDOW~2\wmpband.dll
    c:\windows\system32\ieframe.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
    c:\windows\system32\mshtml.dll
    c:\windows\system32\msls31.dll
    c:\program files\Cox\Secure Online Backup for Windows\DigiData.Vault.VaultExplorer.dll
    c:\program files\Cox\Secure Online Backup for Windows\LogicNP.EZNamespaceExtensions.dll
    c:\windows\assembly\GAC_MSIL\DigiData.Vault.Adapter\1.0.11.0__9020972b7d9d3317\DigiData.Vault.Adapter.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\System32\WLTRYSVC.EXE
    c:\windows\System32\bcmwltry.exe
    c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
    c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\nvsvc32.exe
    c:\program files\Dell Support Center\bin\sprtsvc.exe
    c:\windows\system32\rundll32.exe
    c:\windows\system32\RUNDLL32.EXE
    c:\program files\iPod\bin\iPodService.exe
    c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe
    c:\windows\system32\wbem\wmiapsrv.exe
    c:\program files\Logitech\QuickCam10\COCIManager.exe
    .
    **************************************************************************
    .
    Completion time: 2011-12-10 12:31:48 - machine was rebooted
    ComboFix-quarantined-files.txt 2011-12-10 19:31
    .
    Pre-Run: 98,209,267,712 bytes free
    Post-Run: 105,876,885,504 bytes free
    .
    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT= "Microsoft Windows Recovery Console" /cmdcons
    UnsupportedDebug= "do not select this" /debug
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS= "Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
    .
    - - End Of File - - 2F81DC9F7A9E29CB13FF109A9AA900CC
     
    rgn,
    #12
  14. 2011/12/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Looks good :)

    Any current issues?

    You can reinstall AVG at any time now.

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  15. 2011/12/10
    rgn

    rgn Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    212
    Likes Received:
    0
    2:13:31 PM - Run 1
    OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Robert Niemi\Desktop
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 1.36 Gb Available Physical Memory | 67.95% Memory free
    5.84 Gb Paging File | 5.17 Gb Available in Paging File | 88.53% Paging File free
    Paging file location(s): C:\pagefile.sys 4092 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 146.47 Gb Total Space | 98.17 Gb Free Space | 67.03% Space Free | Partition Type: NTFS

    Computer Name: ROBERT-1270A79B | User Name: Robert Niemi | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2011/12/10 14:03:19 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Robert Niemi\Desktop\OTL.exe
    PRC - [2011/11/27 09:36:19 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\real\realplayer\Update\realsched.exe
    PRC - [2011/10/24 20:29:16 | 002,415,456 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
    PRC - [2011/10/18 06:14:54 | 001,229,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
    PRC - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
    PRC - [2011/09/08 20:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
    PRC - [2011/08/15 06:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
    PRC - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
    PRC - [2011/07/17 00:06:32 | 000,233,472 | ---- | M] () -- C:\Program Files\Cox\Secure Online Backup for Windows\Auto Update\OnlineBackup.UpdateSystemTray.exe
    PRC - [2011/07/17 00:06:32 | 000,024,576 | ---- | M] () -- C:\Program Files\Cox\Secure Online Backup for Windows\Scheduler\OnlineBackup.SchedulerService.exe
    PRC - [2011/07/16 23:59:02 | 000,024,576 | ---- | M] (DigiData Corp.) -- C:\Program Files\Cox\Secure Online Backup for Windows\Filesystem Watcher\DigiData.FilesystemWatcher.Service.Watcher.exe
    PRC - [2011/03/23 14:08:26 | 000,028,672 | ---- | M] (DigiData Corp.) -- C:\Program Files\Cox\Secure Online Backup for Windows\vewatch.exe
    PRC - [2010/12/21 05:04:30 | 000,987,704 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\psia.exe
    PRC - [2010/12/21 05:04:30 | 000,399,416 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\sua.exe
    PRC - [2010/12/21 05:04:30 | 000,291,896 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\psi_tray.exe
    PRC - [2009/05/21 11:13:58 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    PRC - [2009/05/04 12:15:26 | 000,279,960 | ---- | M] (Eastman Kodak Company) -- C:\Program Files\Kodak\AiO\Center\EKDiscovery.exe
    PRC - [2009/04/17 12:08:26 | 000,032,768 | ---- | M] (Eastman Kodak Company) -- C:\Program Files\Kodak\AiO\Center\KodakSvc.exe
    PRC - [2009/04/07 17:27:30 | 001,511,424 | ---- | M] (Eastman Kodak Company) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
    PRC - [2008/08/14 00:04:44 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2007/11/01 15:39:28 | 000,189,736 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Dell\MediaDirect\PCMService.exe
    PRC - [2007/07/20 16:55:46 | 001,228,800 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\quickset.exe
    PRC - [2007/05/10 10:22:32 | 000,405,504 | ---- | M] (SigmaTel, Inc.) -- C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
    PRC - [2006/06/26 10:34:58 | 000,166,448 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\QuickCam10\COCIManager.exe
    PRC - [2006/06/26 10:34:40 | 000,614,960 | ---- | M] () -- C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
    PRC - [2006/06/26 10:33:42 | 000,099,888 | ---- | M] (Logitech Inc.) -- c:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe
    PRC - [2006/06/26 10:33:32 | 000,243,248 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
    PRC - [2006/06/26 09:46:04 | 000,497,200 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
    PRC - [2006/02/01 11:04:54 | 000,315,392 | ---- | M] (SoftSwift Ltd) -- C:\Program Files\SoftSwift\Enhanced Windows Backup\EWBackup.exe
    PRC - [2004/07/28 07:02:00 | 000,204,800 | ---- | M] (BUFFALO INC.) -- C:\Program Files\BUFFALO\HDBackup\HDBackup.exe


    ========== Modules (No Company Name) ==========

    MOD - [2011/10/13 12:45:56 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_2cdabbfb\mscorlib.dll
    MOD - [2011/10/13 12:45:42 | 000,835,584 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_6a8b6ac6\system.drawing.dll
    MOD - [2011/10/13 12:44:32 | 002,088,960 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_535b743a\system.xml.dll
    MOD - [2011/10/13 12:43:39 | 003,018,752 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_4b9f592d\system.windows.forms.dll
    MOD - [2011/10/13 12:42:29 | 000,061,440 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\custommarshalers\1.0.5000.0__b03f5f7f11d50a3a_009f2009\custommarshalers.dll
    MOD - [2011/10/13 12:03:49 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_a758ffd4\system.dll
    MOD - [2011/10/13 12:03:22 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
    MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    MOD - [2011/08/22 19:02:28 | 000,053,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DigiData\1.6.1.0__9020972b7d9d3317\DigiData.dll
    MOD - [2011/08/22 19:02:27 | 000,049,152 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DigiData.Vault.Adapter\1.0.11.0__9020972b7d9d3317\DigiData.Vault.Adapter.dll
    MOD - [2011/08/22 19:02:27 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DigiData.Vault.VaultExplorer.Cache.Controller\1.0.0.0__9020972b7d9d3317\DigiData.Vault.VaultExplorer.Cache.Controller.dll
    MOD - [2011/08/22 19:02:25 | 000,077,824 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DigiData.Vault.Problems\1.2.0.0__9020972b7d9d3317\DigiData.Vault.Problems.dll
    MOD - [2011/07/17 00:06:32 | 000,233,472 | ---- | M] () -- C:\Program Files\Cox\Secure Online Backup for Windows\Auto Update\OnlineBackup.UpdateSystemTray.exe
    MOD - [2011/07/17 00:06:32 | 000,024,576 | ---- | M] () -- C:\Program Files\Cox\Secure Online Backup for Windows\Scheduler\OnlineBackup.SchedulerService.exe
    MOD - [2011/07/17 00:06:24 | 000,036,864 | ---- | M] () -- C:\Program Files\Cox\Secure Online Backup for Windows\Auto Update\OnlineBackup.UpdateMonitor.dll
    MOD - [2011/07/17 00:06:12 | 000,032,768 | ---- | M] () -- C:\Program Files\Cox\Secure Online Backup for Windows\Auto Update\OnlineBackup.Updater.dll
    MOD - [2011/07/17 00:04:40 | 000,036,864 | ---- | M] () -- C:\Program Files\Cox\Secure Online Backup for Windows\Auto Update\OnlineBackup.Controls.Buttons.dll
    MOD - [2011/07/17 00:04:06 | 000,024,576 | ---- | M] () -- C:\Program Files\Cox\Secure Online Backup for Windows\Scheduler\OnlineBackup.Scheduler.dll
    MOD - [2011/07/17 00:02:58 | 000,094,208 | ---- | M] () -- C:\Program Files\Cox\Secure Online Backup for Windows\Scheduler\OnlineBackup.Common.dll
    MOD - [2011/07/17 00:02:58 | 000,094,208 | ---- | M] () -- C:\Program Files\Cox\Secure Online Backup for Windows\Auto Update\OnlineBackup.Common.dll
    MOD - [2011/07/17 00:02:34 | 000,069,632 | ---- | M] () -- C:\Program Files\Cox\Secure Online Backup for Windows\Scheduler\OnlineBackup.ThemeManager.dll
    MOD - [2011/07/17 00:02:34 | 000,069,632 | ---- | M] () -- C:\Program Files\Cox\Secure Online Backup for Windows\Auto Update\OnlineBackup.ThemeManager.dll
    MOD - [2011/07/16 23:59:04 | 000,045,056 | ---- | M] () -- C:\Program Files\Cox\Secure Online Backup for Windows\Scheduler\TaskScheduler.dll
    MOD - [2011/03/23 14:08:36 | 001,994,752 | ---- | M] () -- C:\Program Files\Cox\Secure Online Backup for Windows\DigiData.Vault.VaultExplorer.dll
    MOD - [2010/08/25 12:41:13 | 000,034,816 | ---- | M] () -- C:\Program Files\Google\Google Desktop Search\gzlib.dll
    MOD - [2009/05/14 19:34:52 | 000,090,624 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\TaskScheduler\492cc6ff06cbf3d60a1acc384eb877a5\TaskScheduler.ni.dll
    MOD - [2009/05/14 19:34:49 | 000,294,400 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Localization\aa55aa1b545979db312173a72a2ca55a\Localization.ni.dll
    MOD - [2009/05/14 19:34:48 | 000,051,712 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Kodak.Diagnostics\553c7049800cee048f3b0fe565ef7ed9\Kodak.Diagnostics.ni.dll
    MOD - [2009/05/14 19:34:45 | 000,807,424 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Kodak.Utilities\4edecb8fa766456cc175b2eb7ada9e3b\Kodak.Utilities.ni.dll
    MOD - [2009/05/14 19:34:42 | 000,026,112 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Kodak.Automation\ca95812a8d373285b1f04d74b5ae67da\Kodak.Automation.ni.dll
    MOD - [2008/12/06 12:33:43 | 000,771,584 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\3736ba3ecac186f9c5d85f01bda2be98\System.Runtime.Remoting.ni.dll
    MOD - [2008/09/01 21:34:42 | 001,840,128 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\1dad08772eb89d48a8a0cfe9b0467eb0\System.Web.Services.ni.dll
    MOD - [2008/09/01 21:34:14 | 011,791,360 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\50ea744ffc3cb7f09b027fd6c5c93b2b\System.Web.ni.dll
    MOD - [2008/09/01 21:33:58 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\a9e71dda6389403be4db7b567592e3b8\System.ServiceProcess.ni.dll
    MOD - [2008/09/01 21:33:32 | 001,800,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\df1efcbac5973454c608890f72eb994d\System.Deployment.ni.dll
    MOD - [2008/09/01 21:31:30 | 000,970,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\cb4cb21d14767292e079366a5d3d76cd\System.Configuration.ni.dll
    MOD - [2008/09/01 20:23:44 | 005,449,728 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\36f3953f24d4f0b767bf172331ad6f3e\System.Xml.ni.dll
    MOD - [2008/09/01 20:23:26 | 012,428,800 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\9a254c455892c02355ab0ab0f0727c5b\System.Windows.Forms.ni.dll
    MOD - [2008/09/01 20:22:58 | 001,587,200 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\6978f2e90f13bc720d57fa6895c911e2\System.Drawing.ni.dll
    MOD - [2008/09/01 20:15:52 | 007,867,392 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\aa7926460a336408c8041330ad90929d\System.ni.dll
    MOD - [2008/09/01 20:15:36 | 011,485,184 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\9adb89fa22fd5b4ce433b5aca7fb1b07\mscorlib.ni.dll
    MOD - [2008/09/01 20:09:53 | 005,025,792 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    MOD - [2008/08/13 15:29:32 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
    MOD - [2008/08/13 15:29:31 | 000,466,944 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
    MOD - [2008/08/13 15:29:30 | 002,052,096 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
    MOD - [2008/08/13 15:29:28 | 000,299,008 | ---- | M] () -- c:\windows\assembly\gac\microsoft.visualbasic\7.0.5000.0__b03f5f7f11d50a3a\microsoft.visualbasic.dll
    MOD - [2008/08/13 15:27:22 | 000,033,792 | ---- | M] () -- c:\windows\assembly\gac\custommarshalers\1.0.5000.0__b03f5f7f11d50a3a\custommarshalers.dll
    MOD - [2008/06/02 11:42:54 | 000,143,360 | ---- | M] () -- C:\WINDOWS\system32\preflib.dll
    MOD - [2008/06/02 11:42:40 | 000,753,664 | ---- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll
    MOD - [2007/07/20 16:56:14 | 000,098,304 | ---- | M] () -- C:\Program Files\Dell\QuickSet\dadkeyb.dll
    MOD - [2006/06/26 10:34:46 | 000,988,720 | ---- | M] () -- C:\Program Files\Logitech\QuickCam10\QuickCam10Res.dll
    MOD - [2006/06/26 10:34:40 | 000,614,960 | ---- | M] () -- C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
    MOD - [2005/10/13 13:53:36 | 000,090,223 | ---- | M] () -- C:\Program Files\Dell\QuickSet\preflibcl.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
    SRV - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
    SRV - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
    SRV - [2011/07/17 00:06:32 | 000,024,576 | ---- | M] () [Auto | Running] -- C:\Program Files\Cox\Secure Online Backup for Windows\Scheduler\OnlineBackup.SchedulerService.exe -- (OnlineBackupSchedulerService)
    SRV - [2011/07/16 23:59:02 | 000,024,576 | ---- | M] (DigiData Corp.) [Auto | Running] -- C:\Program Files\Cox\Secure Online Backup for Windows\Filesystem Watcher\DigiData.FilesystemWatcher.Service.Watcher.exe -- (FilesystemWatcher)
    SRV - [2010/12/21 05:04:30 | 000,987,704 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
    SRV - [2010/12/21 05:04:30 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\sua.exe -- (Secunia Update Agent)
    SRV - [2009/05/04 12:15:26 | 000,279,960 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\Program Files\Kodak\AiO\Center\EKDiscovery.exe -- (Kodak AiO Network Discovery Service)
    SRV - [2009/04/17 12:08:26 | 000,032,768 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\Program Files\Kodak\AiO\center\KodakSvc.exe -- (KodakSvc)
    SRV - [2008/08/14 00:04:44 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
    SRV - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
    SRV - [2006/06/26 10:33:56 | 000,091,696 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)
    SRV - [2006/06/26 10:33:42 | 000,099,888 | ---- | M] (Logitech Inc.) [Auto | Running] -- c:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
    DRV - [2011/10/07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
    DRV - [2011/10/04 06:21:42 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
    DRV - [2011/09/13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
    DRV - [2011/08/08 06:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
    DRV - [2011/07/11 01:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
    DRV - [2011/07/11 01:14:28 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
    DRV - [2011/07/11 01:14:28 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
    DRV - [2011/07/11 01:14:26 | 000,134,608 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
    DRV - [2011/03/18 09:08:54 | 000,025,240 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
    DRV - [2010/09/01 01:30:58 | 000,015,544 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\psi_mf.sys -- (PSI)
    DRV - [2008/06/02 11:42:52 | 001,287,552 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
    DRV - [2008/04/13 11:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
    DRV - [2007/05/10 10:24:34 | 001,222,840 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
    DRV - [2006/11/21 04:25:44 | 000,045,568 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
    DRV - [2006/11/15 00:16:24 | 000,032,256 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
    DRV - [2006/11/14 19:42:46 | 000,043,520 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
    DRV - [2006/11/14 17:35:20 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
    DRV - [2006/11/02 16:47:36 | 000,989,696 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
    DRV - [2006/11/02 16:47:00 | 000,209,152 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
    DRV - [2006/11/02 16:46:56 | 000,730,112 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
    DRV - [2006/06/26 10:33:40 | 000,023,472 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
    DRV - [2006/06/26 10:33:36 | 001,952,816 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVMVdrv.sys -- (LVMVDrv)
    DRV - [2006/06/26 10:33:28 | 001,587,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Lvckap.sys -- (LVcKap)
    DRV - [2006/06/22 15:29:47 | 000,961,072 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC) Logitech QuickCam Fusion(UVC)
    DRV - [2006/06/22 15:29:47 | 000,020,272 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvcflt.sys -- (FilterService)
    DRV - [2006/06/22 15:29:46 | 000,038,960 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
    DRV - [2006/06/22 15:29:43 | 000,055,984 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvselsus.sys -- (lvselsus)
    DRV - [2006/06/22 15:29:40 | 001,413,424 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvpopflt.sys -- (lvpopflt)
    DRV - [2005/08/12 17:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
    DRV - [1996/04/03 12:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr9/*http://www.yahoo.com/ext/search/search.html
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultengine: "Ask.com "
    FF - prefs.js..browser.search.defaultenginename: "Ask.com "
    FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= "
    FF - prefs.js..browser.search.order.1: "Ask.com "
    FF - prefs.js..browser.search.useDBForOrder: true
    FF - prefs.js..browser.startup.homepage: "http://www.cnn.com/ "
    FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:7
    FF - prefs.js..extensions.enabledItems: smarterwiki@wikiatic.com:4.3.5
    FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
    FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7Bdb2ff5f9-2bc3-4fa5-9631-f81eb0783247%7D&mid=aae3105e875147d19325d1570ad78eba-e57502c99e91e0771e8eb3d72d6fe5ba10bcec2a&ds=AVG&v=8.0.0.34.1&lang=en&pr=fr&d=2011-10-09%2012%3A13%3A11&sap=ku&q= "


    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0: C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.)
    FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Robert Niemi\Application Data\Move Networks\plugins\npqmp071503000010.dll (Move Networks)
    FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.0.198: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.0.198: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKLM\Software\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
    FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Robert Niemi\Application Data\Move Networks\plugins\npqmp071503000010.dll (Move Networks)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/12/10 12:44:15 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/11/27 09:37:02 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/08 20:23:41 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/02 15:27:59 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/10/30 15:58:19 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\avgthb@avg.com: C:\Program Files\AVG\AVG2012\Thunderbird\ [2011/12/10 12:43:55 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\moveplayer@movenetworks.com: C:\Documents and Settings\Robert Niemi\Application Data\Move Networks [2009/10/01 16:37:14 | 000,000,000 | ---D | M]

    [2010/04/01 10:47:15 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Robert Niemi\Application Data\Mozilla\Extensions
    [2010/04/01 10:47:15 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Robert Niemi\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
    [2011/10/26 18:02:41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Robert Niemi\Application Data\Mozilla\Firefox\Profiles\f7u16t3c.default\extensions
    [2011/06/29 12:18:37 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Robert Niemi\Application Data\Mozilla\Firefox\Profiles\f7u16t3c.default\extensions\{20a3bf34-ac82-45ab-b3e8-73574f0a745e}-trash
    [2011/10/26 18:02:41 | 000,000,000 | ---D | M] (AddThis) -- C:\Documents and Settings\Robert Niemi\Application Data\Mozilla\Firefox\Profiles\f7u16t3c.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
    [2011/11/29 14:55:53 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2008/08/12 18:51:35 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
    [2011/11/29 14:55:53 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
    [2009/08/07 15:52:54 | 000,000,000 | ---D | M] (The Browser Highlighter) -- C:\Program Files\Mozilla Firefox\extensions\browserhighlighter@ebay.com
    [2009/07/30 05:04:02 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
    [2011/11/08 20:23:40 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
    [2011/10/03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
    [2008/08/31 18:24:11 | 000,221,184 | ---- | M] (CNN) -- C:\Program Files\mozilla firefox\plugins\NPTURNMED.dll
    [2011/03/28 15:27:50 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
    [2011/11/08 20:23:40 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

    ========== Chrome ==========

    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:eek:riginalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
    CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\gcswf32.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
    CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
    CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
    CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
    CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
    CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
    CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
    CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
    CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
    CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
    CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\pdf.dll
    CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
    CHR - plugin: Windows Genuine Advantage (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
    CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
    CHR - plugin: Turner Media Plugin 1.0.0.10 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
    CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
    CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
    CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
    CHR - plugin: Move Streaming Media Player (Enabled) = C:\Documents and Settings\Robert Niemi\Application Data\Move Networks\plugins\npqmp071503000010.dll
    CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
    CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
    CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
    CHR - plugin: Picasa (Enabled) = C:\Program Files\Picasa2\npPicasa2.dll
    CHR - plugin: Picasa (Enabled) = C:\Program Files\Picasa2\npPicasa3.dll
    CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\Program Files\Yahoo!\Common\npyaxmpb.dll
    CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
    CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
    CHR - plugin: Default Plug-in (Enabled) = default_plugin
    CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
    CHR - Extension: AVG Safe Search = C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1857_0\
    CHR - Extension: Star Gazing = C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mblmlcbknbnfebdfjnolmcapmdofhmme\1.1_0\
     
    rgn,
    #14
  16. 2011/12/10
    rgn

    rgn Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    212
    Likes Received:
    0
    google won't run in FF8

    O1 HOSTS File: ([2011/12/10 12:22:45 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
    O4 - HKLM..\Run: [Conime] C:\WINDOWS\system32\conime.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
    O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
    O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
    O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
    O4 - HKLM..\Run: [EWBACKUP] C:\Program Files\SoftSwift\Enhanced Windows Backup\EWBackup.exe (SoftSwift Ltd)
    O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe (Logitech Inc.)
    O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam10\QuickCam10.exe ()
    O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
    O4 - HKLM..\Run: [NVHotkey] "rundll32.exe" nvHotkey.dll,Start File not found
    O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
    O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
    O4 - HKLM..\Run: [Online Backup Auto Update] C:\Program Files\Cox\Secure Online Backup for Windows\Auto Update\OnlineBackup.UpdateSystemTray.exe ()
    O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
    O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
    O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
    O4 - HKLM..\Run: [Vault Explorer Cache Watcher] C:\Program Files\Cox\Secure Online Backup for Windows\vewatch.exe (DigiData Corp.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk = C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
    O4 - Startup: C:\Documents and Settings\Robert Niemi\Start Menu\Programs\Startup\BUFFALO Disk Backup Utility.lnk = C:\Program Files\BUFFALO\HDBackup\HDBackup.exe (BUFFALO INC.)
    O4 - Startup: C:\Documents and Settings\Robert Niemi\Start Menu\Programs\Startup\Secure Online Backup.lnk = C:\Program Files\Cox\Secure Online Backup for Windows\SyncNShare\OnlineBackup.SyncNShare.exe (Cox)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
    O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Reg Error: Key error.)
    O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} https://h20364.www2.hp.com/CSMWeb/Customer/cabs/HPISDataManager.CAB (Hewlett-Packard Online Support Services)
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1219612989109 (MUWebControl Class)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C7509ECE-E677-4B99-8EBF-EA3F5B96AF3E}: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
    O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
    O24 - Desktop WallPaper: C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2008/08/11 19:46:51 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    File not found -- C:\Documents and Settings\Robert Niemi\Desktop\photo-organizer_158-208b.
    [2011/12/10 14:03:08 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Robert Niemi\Desktop\OTL.exe
    [2011/12/10 12:44:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2012
    [2011/12/10 12:43:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
    [2011/12/10 12:12:51 | 000,000,000 | RHSD | C] -- C:\cmdcons
    [2011/12/10 12:10:11 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2011/12/10 12:10:11 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2011/12/10 12:10:11 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2011/12/10 12:10:11 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2011/12/10 12:09:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2011/12/10 12:04:48 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2011/12/10 12:02:51 | 004,334,705 | R--- | C] (Swearware) -- C:\Documents and Settings\Robert Niemi\Desktop\ComboFix.exe
    [2011/12/07 17:19:46 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Robert Niemi\Start Menu\Programs\Administrative Tools
    [2011/12/07 11:27:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Niemi\Application Data\Malwarebytes
    [2011/12/07 11:27:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2011/12/07 11:27:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2011/12/07 11:27:26 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2011/12/07 11:27:26 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2011/11/29 20:16:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Niemi\Application Data\WindSolutions
    [2011/11/29 20:16:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\WindSolutions
    [2011/11/29 14:56:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
    [2011/11/27 09:37:08 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
    [2011/11/27 09:36:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Real
    [2011/11/26 12:54:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
    [2011/11/26 12:53:08 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
    [2011/11/14 13:04:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Solid State Networks
    [2011/11/13 13:02:45 | 000,000,000 | ---D | C] -- C:\2db9745ffc895c5306baaa6d7273
    [2011/11/11 14:36:36 | 000,000,000 | ---D | C] -- C:\Program Files\Magical Jelly Bean
    [2011/11/11 14:36:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\KeyFinder
    [2011/11/10 23:16:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
    [2011/11/10 20:38:37 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Robert Niemi\Recent
    [5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    File not found -- C:\Documents and Settings\Robert Niemi\Desktop\photo-organizer_158-208b.
    [2011/12/10 14:14:00 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
    [2011/12/10 14:13:03 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    [2011/12/10 14:12:16 | 000,001,006 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1770027372-839522115-1004UA.job
    [2011/12/10 14:09:11 | 000,000,436 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{AA52A37D-5D4F-4BC0-9A31-B58F5B91BB30}.job
    [2011/12/10 14:03:19 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Robert Niemi\Desktop\OTL.exe
    [2011/12/10 12:48:54 | 072,255,911 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
    [2011/12/10 12:44:16 | 000,000,702 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
    [2011/12/10 12:41:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2011/12/10 12:24:11 | 000,028,504 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
    [2011/12/10 12:22:45 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2011/12/10 12:22:22 | 000,000,292 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1708537768-1770027372-839522115-1004.job
    [2011/12/10 12:22:18 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    [2011/12/10 12:22:10 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2011/12/10 12:22:05 | 2145,427,456 | -HS- | M] () -- C:\hiberfil.sys
    [2011/12/10 12:12:57 | 000,000,327 | RHS- | M] () -- C:\boot.ini
    [2011/12/10 12:09:35 | 004,334,705 | R--- | M] (Swearware) -- C:\Documents and Settings\Robert Niemi\Desktop\ComboFix.exe
    [2011/12/10 09:12:07 | 000,000,954 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1770027372-839522115-1004Core.job
    [2011/12/08 13:29:52 | 000,000,300 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1708537768-1770027372-839522115-1004.job
    [2011/12/07 17:16:34 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Robert Niemi\Desktop\MBR.dat
    [2011/12/07 12:28:39 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\Robert Niemi\Desktop\up8dw7kf.exe
    [2011/12/07 11:27:34 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2011/12/07 09:06:26 | 000,028,504 | ---- | M] () -- C:\WINDOWS\System32\nvModes.dat
    [2011/12/06 12:04:07 | 000,021,504 | ---- | M] () -- C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/12/05 12:09:45 | 000,000,107 | ---- | M] () -- C:\Documents and Settings\Robert Niemi\Application Data\Microsoft\Internet Explorer\Quick Launch\Google.url
    [2011/12/05 12:09:15 | 000,000,107 | ---- | M] () -- C:\Documents and Settings\Robert Niemi\Desktop\Google.url
    [2011/12/05 10:05:33 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\null
    [2011/12/04 13:11:48 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2011/12/03 14:42:23 | 000,103,598 | ---- | M] () -- C:\Documents and Settings\Robert Niemi\Desktop\100_1783.JPG
    [2011/12/02 16:42:31 | 000,000,788 | ---- | M] () -- C:\Documents and Settings\Robert Niemi\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
    [2011/12/02 09:19:46 | 000,502,754 | -H-- | M] () -- C:\Documents and Settings\Robert Niemi\My Documents\ZbThumbnail.info
    [2011/12/02 09:19:11 | 000,002,427 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
    [2011/11/29 08:47:16 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
    [2011/11/28 04:00:00 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
    [2011/11/27 09:36:23 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\WINDOWS\System32\pncrt.dll
    [2011/11/22 21:22:24 | 000,127,457 | -H-- | M] () -- C:\Documents and Settings\Robert Niemi\Desktop\ZbThumbnail.info
    [2011/11/20 18:06:35 | 000,002,681 | ---- | M] () -- C:\Documents and Settings\Robert Niemi\Application Data\Microsoft\Internet Explorer\Quick Launch\VPW.lnk
    [2011/11/13 12:38:17 | 000,119,502 | ---- | M] () -- C:\Documents and Settings\Robert Niemi\My Documents\football camden.jpg
    [5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2011/12/10 12:48:54 | 072,255,911 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
    [2011/12/10 12:44:16 | 000,000,702 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
    [2011/12/10 12:12:57 | 000,000,211 | ---- | C] () -- C:\Boot.bak
    [2011/12/10 12:12:53 | 000,260,272 | RHS- | C] () -- C:\cmldr
    [2011/12/10 12:10:11 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2011/12/10 12:10:11 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2011/12/10 12:10:11 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2011/12/10 12:10:11 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2011/12/10 12:10:11 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2011/12/07 17:16:34 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Robert Niemi\Desktop\MBR.dat
    [2011/12/07 12:28:35 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\Robert Niemi\Desktop\up8dw7kf.exe
    [2011/12/07 11:27:34 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2011/12/05 12:09:45 | 000,000,107 | ---- | C] () -- C:\Documents and Settings\Robert Niemi\Application Data\Microsoft\Internet Explorer\Quick Launch\Google.url
    [2011/12/05 12:08:48 | 000,000,107 | ---- | C] () -- C:\Documents and Settings\Robert Niemi\Desktop\Google.url
    [2011/12/03 14:42:23 | 000,103,598 | ---- | C] () -- C:\Documents and Settings\Robert Niemi\Desktop\100_1783.JPG
    [2011/12/02 16:42:31 | 000,000,788 | ---- | C] () -- C:\Documents and Settings\Robert Niemi\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
    [2011/11/13 12:38:12 | 000,119,502 | ---- | C] () -- C:\Documents and Settings\Robert Niemi\My Documents\football camden.jpg
    [2011/03/08 19:12:36 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
    [2010/12/22 19:06:54 | 000,000,156 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
    [2010/12/22 19:05:57 | 000,000,804 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
    [2010/08/21 17:01:48 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\housecall.guid.cache
    [2009/09/17 19:37:57 | 000,022,036 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
    [2009/05/14 19:34:29 | 000,012,800 | ---- | C] () -- C:\WINDOWS\System32\EKDeviceServices.dll
    [2009/05/07 19:22:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpqEmlSz.INI
    [2009/02/05 19:14:44 | 000,000,135 | ---- | C] () -- C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\fusioncache.dat
    [2008/11/23 08:59:51 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
    [2008/09/27 14:33:26 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
    [2008/09/27 14:33:25 | 000,024,064 | ---- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
    [2008/09/27 14:33:24 | 000,753,664 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
    [2008/09/25 17:44:55 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
    [2008/08/18 18:12:49 | 000,021,504 | ---- | C] () -- C:\Documents and Settings\Robert Niemi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2008/08/16 12:26:55 | 000,007,262 | ---- | C] () -- C:\WINDOWS\hpomdl21.dat.temp
    [2008/08/16 10:11:51 | 000,562,858 | ---- | C] () -- C:\WINDOWS\hpoins21.dat.temp
    [2008/08/14 18:32:26 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
    [2008/08/12 18:53:26 | 000,001,160 | ---- | C] () -- C:\WINDOWS\mozver.dat
    [2008/08/12 18:51:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
    [2008/08/12 15:45:31 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
    [2008/08/12 15:39:58 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2008/08/12 15:31:51 | 000,022,334 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
    [2008/08/11 20:37:02 | 000,198,144 | ---- | C] () -- C:\WINDOWS\System32\_psisdecd.dll
    [2008/08/11 20:17:03 | 000,028,504 | ---- | C] () -- C:\WINDOWS\System32\nvModes.dat
    [2008/08/11 20:16:17 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
    [2008/08/11 20:16:17 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
    [2008/08/11 20:16:16 | 001,018,804 | ---- | C] () -- C:\WINDOWS\System32\nvucode.bin
    [2008/08/11 20:16:16 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
    [2008/08/11 20:16:14 | 001,474,560 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
    [2008/08/11 20:16:14 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
    [2008/08/11 20:16:11 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
    [2008/08/11 20:16:10 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
    [2008/08/11 20:16:09 | 001,626,112 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
    [2008/08/11 20:15:12 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
    [2008/08/11 19:49:10 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2008/08/11 19:43:46 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2008/08/11 12:36:32 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2008/08/11 12:35:08 | 000,134,072 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2008/01/14 16:47:06 | 000,099,712 | ---- | C] () -- C:\WINDOWS\HPBroker.dll
    [2006/09/20 01:25:44 | 000,012,416 | ---- | C] () -- C:\WINDOWS\hpwscr05.dat
    [2006/06/26 10:33:40 | 000,023,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
    [2005/08/26 14:28:34 | 000,143,360 | ---- | C] () -- C:\WINDOWS\unzip.exe
    [2005/08/26 14:28:20 | 000,024,576 | ---- | C] () -- C:\WINDOWS\shortcut.exe
    [2005/08/26 14:27:58 | 000,045,056 | ---- | C] () -- C:\WINDOWS\devenum.exe
    [2004/08/12 07:11:42 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
    [2004/08/12 07:11:41 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
    [2004/08/12 07:04:52 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
    [2004/08/12 07:03:21 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
    [2004/08/12 07:03:20 | 000,441,692 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
    [2004/08/12 07:03:20 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
    [2004/08/12 07:03:19 | 000,071,462 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
    [2004/08/12 07:02:25 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
    [2004/08/12 06:59:52 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
    [2004/08/12 06:59:46 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
    [2004/08/12 06:57:10 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
    [2004/08/12 06:56:48 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
    [2004/07/27 18:31:00 | 000,005,816 | ---- | C] () -- C:\WINDOWS\UN040622.INI
    [2001/07/07 03:00:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
    [1996/04/03 12:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

    ========== LOP Check ==========

    [2009/12/10 17:34:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Applications
    [2011/12/10 12:48:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012
    [2010/09/13 14:05:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
    [2008/08/11 20:11:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Citrix
    [2011/06/07 15:07:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
    [2011/08/22 19:02:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DigiData
    [2009/04/20 19:00:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
    [2009/05/11 21:30:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Eastman Kodak Company
    [2011/12/04 12:18:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iolo
    [2009/11/09 16:01:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Karen's Power Tools
    [2009/05/11 21:32:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\kds_kodak
    [2009/08/23 10:18:52 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Memeo
    [2011/12/10 12:49:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
    [2008/12/06 12:33:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
    [2011/03/27 19:39:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SoftSwift
    [2008/08/24 17:14:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
    [2011/11/29 20:20:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WindSolutions
    [2011/12/10 12:06:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WRData
    [2010/04/02 10:09:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    [2009/09/10 16:35:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    [2009/05/22 15:41:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
    [2010/04/12 19:20:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Niemi\Application Data\Auslogics
    [2011/10/24 11:24:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Niemi\Application Data\AVG
    [2011/10/09 11:59:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Niemi\Application Data\AVG2012
    [2010/08/12 09:29:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Niemi\Application Data\AVG9
    [2011/08/22 19:03:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Niemi\Application Data\DigiData
    [2009/08/19 15:53:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Niemi\Application Data\Foxit
    [2011/02/27 17:15:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Niemi\Application Data\InfraRecorder
    [2011/09/15 18:42:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Niemi\Application Data\iolo
    [2010/04/01 10:47:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Niemi\Application Data\Thunderbird
    [2008/09/01 20:24:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Niemi\Application Data\uniblue
    [2011/12/04 12:16:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Niemi\Application Data\WindSolutions
    [2011/09/29 12:46:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Niemi\Application Data\Worksimaging
    [2011/11/28 04:00:00 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
    [2011/12/10 14:09:11 | 000,000,436 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{AA52A37D-5D4F-4BC0-9A31-B58F5B91BB30}.job

    ========== Purity Check ==========



    < End of report >
     
    rgn,
    #15
  17. 2011/12/10
    rgn

    rgn Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    212
    Likes Received:
    0
    google won't run in FF8

    OTL Extras logfile created on: 12/10/2011 2:13:31 PM - Run 1
    OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Robert Niemi\Desktop
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 1.36 Gb Available Physical Memory | 67.95% Memory free
    5.84 Gb Paging File | 5.17 Gb Available in Paging File | 88.53% Paging File free
    Paging file location(s): C:\pagefile.sys 4092 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 146.47 Gb Total Space | 98.17 Gb Free Space | 67.03% Space Free | Partition Type: NTFS

    Computer Name: ROBERT-1270A79B | User Name: Robert Niemi | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    exefile [open] -- "%1" %*
    https [open] -- E:\PROGRA~1\MOZILL~1\FIREFOX.EXE -requestPending -osint -url "%1 "
    InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
    "Start" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
    "Start" = 2

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
    "139:TCP" = 139:TCP:*:Enabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:*:Enabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:*:Enabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:*:Enabled:mad:xpsp2res.dll,-22002

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22008
    "9322:TCP" = 9322:TCP:*:Enabled:EKDiscovery
    "139:TCP" = 139:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22002

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files\Dell\MediaDirect\PCMService.exe" = C:\Program Files\Dell\MediaDirect\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program -- (CyberLink Corp.)
    "C:\Program Files\Mozilla Thunderbird\thunderbird.exe" = C:\Program Files\Mozilla Thunderbird\thunderbird.exe:*:Enabled:Mozilla Thunderbird -- (Mozilla Messaging)
    "C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
    "C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google)
    "C:\Program Files\Cox\Secure Online Backup for Windows\SyncNShare\OnlineBackup.SyncNShare.exe" = C:\Program Files\Cox\Secure Online Backup for Windows\SyncNShare\OnlineBackup.SyncNShare.exe:*:Enabled:Backup -- (Cox)
    "C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)
    "C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.)
    "C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 -- (AVG Technologies CZ, s.r.o.)
    "C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.)
    "C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:personal E-mail Scanner -- (AVG Technologies CZ, s.r.o.)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{074AED0D-DD1C-432A-B38D-F8733604033F}" = aioscnnr
    "{09BDEEF0-5590-457D-89A9-5DB2742F9BBF}" = 32 Bit HP CIO Components Installer
    "{10934A28-0CC6-4B98-A14F-76B3546003AF}" = ksDIP
    "{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
    "{12B09031-A7E1-43B1-AC8C-A202B676B556}" = RemoteCapture 2.7.3
    "{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java(TM) 6 Update 29
    "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
    "{3127F76D-5335-4AC7-BD1E-2F5247A23C24}" = iTunes
    "{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
    "{326957C7-83FD-4550-A59A-849B7B4297DE}" = Microsoft Easy Assist v2
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
    "{48B41C3A-9A92-4B81-B653-C97FEB85C910}" = C4USelfUpdater
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4AC7B4E7-59B7-4E48-A60D-263C486FC33A}_is1" = System Checkup 3.0
    "{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
    "{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
    "{56BA241F-580C-43D2-8403-947241AAE633}" = center
    "{59B73DDC-593A-4D02-B9CA-1D8C9F912324}" = aioprnt
    "{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
    "{5C474A83-A45F-470C-9AC8-2BD1C251BF9A}" = Skypeâ„¢ 4.2
    "{5F1ECD36-0DFA-4C58-830B-0F089083407F}" = AVG 2012
    "{612B9183-67A9-4B44-9877-2F059E35B86A}" = Broadcom 440x 10/100 Integrated Controller
    "{6845255F-15CC-4DD1-94D5-D38F370118B3}_is1" = Auslogics Duplicate File Finder
    "{7057ABC2-EFF3-4E43-9806-8BCB6EEA9FE6}" = Microsoft IntelliPoint 7.1
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1" = Auslogics BoostSpeed
    "{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
    "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
    "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
    "{80F28669-97B7-4CC9-B256-1F1BCFB7FDCF}" = AVG 2012
    "{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8AC049F7-1383-45C3-9E7D-F93CA667F9E1}" = UMVPLStandalone
    "{8C2690CF-5B74-4F93-8139-7B5644CD6A3B}" = MobileMe Control Panel
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
    "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{97DED0D8-B530-4137-8AD0-F3978F6EFA8E}" = File Viewer Utility 1.3
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
    "{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{A34D17F9-0328-4F71-B4E9-E515EF34AB12}_is1" = Auslogics Disk Defrag ScreenSaver
    "{A454733F-BE60-47FD-8C60-DD910FE1151E}" = Video Poker for Winners
    "{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
    "{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
    "{A833A505-4D7A-41F5-9362-A2F8DFFE6E9B}" = Camera Window
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
    "{BE66348A-E83F-4982-941F-DFF2F742B851}" = Microsoft Office Live Meeting 2007
    "{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}" = Canon Utilities ZoomBrowser EX
    "{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{D627784F-B3EE-44E8-96B1-9509B991EA34}_is1" = Auslogics Registry Defrag
    "{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
    "{DDFC1938-6B7B-4419-8D81-108B5B8D47C0}" = Enhanced Windows Backup
    "{DE6B7599-D3EF-4436-8836-BAA0B0D7768D}" = aiofw
    "{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
    "{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK All-in-One Printer Software
    "{E173E4C5-FB43-4B3E-AC08-CCCE4CE54825}" = Cox Secure Online Backup for Windows
    "{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
    "{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
    "{EC42ED6A-751D-45C0-A4F9-8CD00E4690FC}" = Logitech QuickCam
    "{F11A403B-0DE9-4953-B790-7A2F014FBB2B}" = PhotoStitch
    "{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
    "AVG" = AVG 2012
    "Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card Utility
    "CCleaner" = CCleaner
    "CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
    "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
    "FoxyTunesForFirefox" = FoxyTunes for Firefox
    "Google Desktop" = Google Desktop
    "Google Updater" = Google Updater
    "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
    "ie8" = Windows Internet Explorer 8
    "InfraRecorder" = InfraRecorder
    "InstallShield_{12B09031-A7E1-43B1-AC8C-A202B676B556}" = Canon Utilities RemoteCapture 2.7
    "InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
    "InstallShield_{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
    "InstallShield_{97DED0D8-B530-4137-8AD0-F3978F6EFA8E}" = Canon Utilities File Viewer Utility 1.3
    "InstallShield_{A833A505-4D7A-41F5-9362-A2F8DFFE6E9B}" = Canon Camera Window for ZoomBrowser EX
    "InstallShield_{F11A403B-0DE9-4953-B790-7A2F014FBB2B}" = Canon Utilities PhotoStitch 3.1
    "KeyFinder_is1" = Magical Jelly Bean KeyFinder
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
    "Mozilla Thunderbird (8.0)" = Mozilla Thunderbird (8.0)
    "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
    "My 3D Christmas Tree Animated Wallpaper" = My 3D Christmas Tree Animated Wallpaper
    "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
    "NVIDIA Drivers" = NVIDIA Drivers
    "PhotoRecord" = Canon PhotoRecord
    "Picasa 3" = Picasa 3
    "QcDrv" = Logitech® Camera Driver
    "RealPlayer 15.0" = RealPlayer
    "Secunia PSI" = Secunia PSI (2.0.0.1003)
    "SpeedFan" = SpeedFan (remove only)
    "SynTPDeinstKey" = Dell Touchpad
    "UN040622" = BUFFALO Disk Backup Utility
    "WIC" = Windows Imaging Component
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

    ========== HKEY_CURRENT_USER Uninstall List ==========

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "f031ef6ac137efc5" = Dell Driver Download Manager
    "Google Chrome" = Google Chrome
    "Move Media Player" = Move Media Player

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 12/10/2011 1:53:54 PM | Computer Name = ROBERT-1270A79B | Source = Bonjour Service | ID = 100
    Description = Client application bug: DNSServiceResolve(KodakESP7+1544._smb._tcp.local.)
    active for over two minutes. This places considerable burden on the network.

    Error - 12/10/2011 2:29:48 PM | Computer Name = ROBERT-1270A79B | Source = Bonjour Service | ID = 100
    Description = Client application bug: DNSServiceResolve(KodakESP7+1544._pdl-datastream._tcp.local.)
    active for over two minutes. This places considerable burden on the network.

    Error - 12/10/2011 2:29:48 PM | Computer Name = ROBERT-1270A79B | Source = Bonjour Service | ID = 100
    Description = Client application bug: DNSServiceResolve(KodakESP7+1544._scanner._tcp.local.)
    active for over two minutes. This places considerable burden on the network.

    Error - 12/10/2011 2:29:48 PM | Computer Name = ROBERT-1270A79B | Source = Bonjour Service | ID = 100
    Description = Client application bug: DNSServiceResolve(KodakESP7+1544._smb._tcp.local.)
    active for over two minutes. This places considerable burden on the network.

    Error - 12/10/2011 2:44:17 PM | Computer Name = ROBERT-1270A79B | Source = Bonjour Service | ID = 100
    Description = Client application bug: DNSServiceResolve(KodakESP7+1544._pdl-datastream._tcp.local.)
    active for over two minutes. This places considerable burden on the network.

    Error - 12/10/2011 2:44:17 PM | Computer Name = ROBERT-1270A79B | Source = Bonjour Service | ID = 100
    Description = Client application bug: DNSServiceResolve(KodakESP7+1544._scanner._tcp.local.)
    active for over two minutes. This places considerable burden on the network.

    Error - 12/10/2011 2:44:17 PM | Computer Name = ROBERT-1270A79B | Source = Bonjour Service | ID = 100
    Description = Client application bug: DNSServiceResolve(KodakESP7+1544._smb._tcp.local.)
    active for over two minutes. This places considerable burden on the network.

    Error - 12/10/2011 3:25:26 PM | Computer Name = ROBERT-1270A79B | Source = Bonjour Service | ID = 100
    Description = Client application bug: DNSServiceResolve(KodakESP7+1544._pdl-datastream._tcp.local.)
    active for over two minutes. This places considerable burden on the network.

    Error - 12/10/2011 3:25:26 PM | Computer Name = ROBERT-1270A79B | Source = Bonjour Service | ID = 100
    Description = Client application bug: DNSServiceResolve(KodakESP7+1544._scanner._tcp.local.)
    active for over two minutes. This places considerable burden on the network.

    Error - 12/10/2011 3:25:26 PM | Computer Name = ROBERT-1270A79B | Source = Bonjour Service | ID = 100
    Description = Client application bug: DNSServiceResolve(KodakESP7+1544._smb._tcp.local.)
    active for over two minutes. This places considerable burden on the network.

    [ System Events ]
    Error - 12/7/2011 3:08:41 PM | Computer Name = ROBERT-1270A79B | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    SASDIFSV SASKUTIL

    Error - 12/7/2011 3:43:39 PM | Computer Name = ROBERT-1270A79B | Source = Service Control Manager | ID = 7001
    Description = The ClipBook service depends on the Network DDE service which failed
    to start because of the following error: %%1058

    Error - 12/7/2011 3:43:39 PM | Computer Name = ROBERT-1270A79B | Source = Service Control Manager | ID = 7023
    Description = The HID Input Service service terminated with the following error:
    %%2

    Error - 12/7/2011 3:43:39 PM | Computer Name = ROBERT-1270A79B | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    SASDIFSV SASKUTIL

    Error - 12/10/2011 2:41:58 PM | Computer Name = ROBERT-1270A79B | Source = Service Control Manager | ID = 7001
    Description = The ClipBook service depends on the Network DDE service which failed
    to start because of the following error: %%1058

    Error - 12/10/2011 2:41:58 PM | Computer Name = ROBERT-1270A79B | Source = Service Control Manager | ID = 7023
    Description = The HID Input Service service terminated with the following error:
    %%2

    Error - 12/10/2011 2:41:59 PM | Computer Name = ROBERT-1270A79B | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    SASDIFSV SASKUTIL

    Error - 12/10/2011 3:04:16 PM | Computer Name = ROBERT-1270A79B | Source = Service Control Manager | ID = 7034
    Description = The Logitech Process Monitor service terminated unexpectedly. It
    has done this 1 time(s).

    Error - 12/10/2011 3:14:44 PM | Computer Name = ROBERT-1270A79B | Source = Service Control Manager | ID = 7034
    Description = The Dell Wireless WLAN Tray Service service terminated unexpectedly.
    It has done this 1 time(s).

    Error - 12/10/2011 3:22:34 PM | Computer Name = ROBERT-1270A79B | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    SASDIFSV SASKUTIL


    < End of report >
     
    rgn,
    #16
  18. 2011/12/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You didn't say:
    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      FF - prefs.js..browser.search.defaultengine:  "Ask.com "
      FF - prefs.js..browser.search.defaultenginename:  "Ask.com "
      FF - prefs.js..browser.search.order.1:  "Ask.com "
      O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
      O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
      O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/s...irector/sw.cab (Reg Error: Key error.)
      O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
      O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
      O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      [2008/09/01 20:24:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Niemi\Application Data\uniblue
      
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ==============================================================

    Last scans....

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
  19. 2011/12/11
    rgn

    rgn Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    212
    Likes Received:
    0
    google won't run in FF8

    I didn't see the second page to the post.

    The search engines do work now. The only difference that I've seen so far. FF8 seems to load faster.
     
    rgn,
    #18
  20. 2011/12/11
    rgn

    rgn Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    212
    Likes Received:
    0
    google won't run in FF8

    Do I need to disable avg, firewall or open pages?
     
    rgn,
    #19
  21. 2011/12/11
    rgn

    rgn Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    212
    Likes Received:
    0
    google won't open in FF8

    All processes killed
    Error: Unable to interpret <Code:> in the current context!
    ========== OTL ==========
    Prefs.js: "Ask.com" removed from browser.search.defaultengine
    Prefs.js: "Ask.com" removed from browser.search.defaultenginename
    Prefs.js: "Ask.com" removed from browser.search.order.1
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\localhost\ deleted successfully.
    Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\GD\\http deleted successfully.
    Starting removal of ActiveX control {166B1BCA-3F9C-11CF-8075-444553540000}
    C:\WINDOWS\Downloaded Program Files\swdir.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{166B1BCA-3F9C-11CF-8075-444553540000}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found.
    Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
    C:\WINDOWS\Downloaded Program Files\erma.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Starting removal of ActiveX control {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
    Starting removal of ActiveX control {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found.
    Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
    C:\WINDOWS\Downloaded Program Files\gp.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    C:\Documents and Settings\Robert Niemi\Application Data\uniblue\speed up my pc 4 folder moved successfully.
    C:\Documents and Settings\Robert Niemi\Application Data\uniblue folder moved successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes
    ->Flash cache emptied: 56509 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 49286 bytes
    ->Flash cache emptied: 343 bytes

    User: log

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 82054 bytes

    User: Robert Niemi
    ->Temp folder emptied: 16832 bytes
    ->Temporary Internet Files folder emptied: 6821572 bytes
    ->Java cache emptied: 343837 bytes
    ->FireFox cache emptied: 53061748 bytes
    ->Google Chrome cache emptied: 144369308 bytes
    ->Flash cache emptied: 36013 bytes

    User: Sarah
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes
    ->FireFox cache emptied: 38157408 bytes
    ->Flash cache emptied: 1744 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 2162283 bytes
    %systemroot%\System32 .tmp files removed: 3770897 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 803074 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 48445794 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 640998 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 285.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: LocalService
    ->Flash cache emptied: 0 bytes

    User: log

    User: NetworkService

    User: Robert Niemi
    ->Flash cache emptied: 0 bytes

    User: Sarah
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.31.0 log created on 12112011_112535

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
     
    rgn,
    #20

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.