1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Internet Explorer Has Stopped working

Discussion in 'Malware and Virus Removal Archive' started by snookie28, 2009/09/03.

  1. 2009/09/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I feel your pain, but please, continue :)
     
  2. 2009/09/05
    snookie28

    snookie28 Inactive Thread Starter

    Joined:
    2002/06/28
    Messages:
    245
    Likes Received:
    0
    Internet Explorer stops working

    [2009/08/18 23:23:10 | 00,616,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\blackbox.dll
    [2009/08/18 23:23:10 | 00,481,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cmdial32.dll
    [2009/08/18 23:23:10 | 00,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rmcast.sys
    [2009/08/18 23:23:10 | 00,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rassstp.sys
    [2009/08/18 23:23:10 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\watchdog.sys
    [2009/08/18 23:23:09 | 02,438,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oobefldr.dll
    [2009/08/18 23:23:09 | 00,521,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cmdial32.dll
    [2009/08/18 23:23:09 | 00,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wdmaud.drv
    [2009/08/18 23:23:09 | 00,095,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SCardSvr.dll
    [2009/08/18 23:23:09 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\conime.exe
    [2009/08/18 23:23:09 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsCtfMonitor.dll
    [2009/08/18 23:23:08 | 02,535,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSVidCtl.dll
    [2009/08/18 23:23:08 | 01,544,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSVidCtl.dll
    [2009/08/18 23:23:08 | 00,281,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\raschap.dll
    [2009/08/18 23:23:08 | 00,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontext.dll
    [2009/08/18 23:23:08 | 00,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdWSD.dll
    [2009/08/18 23:23:08 | 00,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wscsvc.dll
    [2009/08/18 23:23:07 | 00,657,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVXENCD.DLL
    [2009/08/18 23:23:07 | 00,547,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wiaaut.dll
    [2009/08/18 23:23:07 | 00,409,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskcomp.dll
    [2009/08/18 23:23:07 | 00,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\unimdm.tsp
    [2009/08/18 23:23:07 | 00,202,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanui.dll
    [2009/08/18 23:23:07 | 00,187,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\nwifi.sys
    [2009/08/18 23:23:07 | 00,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlgpclnt.dll
    [2009/08/18 23:23:07 | 00,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cipher.exe
    [2009/08/18 23:23:06 | 01,702,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
    [2009/08/18 23:23:06 | 00,688,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmsdk.dll
    [2009/08/18 23:23:06 | 00,259,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rasppp.dll
    [2009/08/18 23:23:06 | 00,137,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dsprop.dll
    [2009/08/18 23:23:05 | 02,153,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oobefldr.dll
    [2009/08/18 23:23:05 | 00,425,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shwebsvc.dll
    [2009/08/18 23:23:05 | 00,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanmsm.dll
    [2009/08/18 23:23:05 | 00,158,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\softkbd.dll
    [2009/08/18 23:23:05 | 00,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\l2nacp.dll
    [2009/08/18 23:23:05 | 00,054,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dimsroam.dll
    [2009/08/18 23:23:04 | 00,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\modemui.dll
    [2009/08/18 23:23:04 | 00,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\btpanui.dll
    [2009/08/18 23:23:04 | 00,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shsetup.dll
    [2009/08/18 23:23:03 | 00,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\input.dll
    [2009/08/18 23:23:03 | 00,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rasmontr.dll
    [2009/08/18 23:23:03 | 00,155,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rasmontr.dll
    [2009/08/18 23:23:02 | 06,103,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\chtbrkr.dll
    [2009/08/18 23:23:02 | 00,533,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmsdk.dll
    [2009/08/18 23:23:02 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscandui.dll
    [2009/08/18 23:23:02 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NcdProp.dll
    [2009/08/18 23:23:01 | 00,542,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\blackbox.dll
    [2009/08/18 23:23:01 | 00,178,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\credui.dll
    [2009/08/18 23:23:01 | 00,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlgpclnt.dll
    [2009/08/18 23:23:01 | 00,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dataclen.dll
    [2009/08/18 23:23:01 | 00,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cscapi.dll
    [2009/08/18 23:23:01 | 00,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\findstr.exe
    [2009/08/18 23:23:00 | 00,339,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
    [2009/08/18 23:23:00 | 00,303,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpeffects.dll
    [2009/08/18 23:23:00 | 00,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstask.dll
    [2009/08/18 23:23:00 | 00,227,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpg2splt.ax
    [2009/08/18 23:23:00 | 00,180,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netplwiz.dll
    [2009/08/18 23:23:00 | 00,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSDMon.dll
    [2009/08/18 23:23:00 | 00,105,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adsmsext.dll
    [2009/08/18 23:23:00 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\deskmon.dll
    [2009/08/18 23:22:59 | 02,226,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\networkexplorer.dll
    [2009/08/18 23:22:59 | 00,274,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AUDIOKSE.dll
    [2009/08/18 23:22:59 | 00,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpdwcn.dll
    [2009/08/18 23:22:59 | 00,214,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceTypes.dll
    [2009/08/18 23:22:59 | 00,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wpcsvc.dll
    [2009/08/18 23:22:59 | 00,113,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msctfui.dll
    [2009/08/18 23:22:59 | 00,058,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cipher.exe
    [2009/08/18 23:22:59 | 00,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ifmon.dll
    [2009/08/18 23:22:58 | 00,946,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMADMOD.DLL
    [2009/08/18 23:22:58 | 00,414,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscp.dll
    [2009/08/18 23:22:58 | 00,217,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\InkEd.dll
    [2009/08/18 23:22:58 | 00,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gpresult.exe
    [2009/08/18 23:22:58 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\logagent.exe
    [2009/08/18 23:22:58 | 00,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wscapi.dll
    [2009/08/18 23:22:58 | 00,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\version.dll
    [2009/08/18 23:22:57 | 00,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmnet.dll
    [2009/08/18 23:22:57 | 00,313,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\thawbrkr.dll
    [2009/08/18 23:22:57 | 00,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mdminst.dll
    [2009/08/18 23:22:57 | 00,203,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wpdwcn.dll
    [2009/08/18 23:22:57 | 00,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
    [2009/08/18 23:22:57 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msimtf.dll
    [2009/08/18 23:22:56 | 00,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\credui.dll
    [2009/08/18 23:22:56 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\softkbd.dll
    [2009/08/18 23:22:56 | 00,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\logagent.exe
    [2009/08/18 23:22:56 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sendmail.dll
    [2009/08/18 23:22:55 | 00,403,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MediaMetadataHandler.dll
    [2009/08/18 23:22:55 | 00,356,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MediaMetadataHandler.dll
    [2009/08/18 23:22:55 | 00,214,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSDMon.dll
    [2009/08/18 23:22:55 | 00,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSAC3ENC.DLL
    [2009/08/18 23:22:55 | 00,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msctfui.dll
    [2009/08/18 23:22:55 | 00,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rshx32.dll
    [2009/08/18 23:22:55 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rasdial.exe
    [2009/08/18 23:22:54 | 00,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmmgrtn.dll
    [2009/08/18 23:22:54 | 00,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax
    [2009/08/18 23:22:54 | 00,105,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dmsynth.dll
    [2009/08/18 23:22:54 | 00,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\olepro32.dll
    [2009/08/18 23:22:54 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cscdll.dll
    [2009/08/18 23:22:53 | 00,418,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmdev.dll
    [2009/08/18 23:22:53 | 00,200,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\input.dll
    [2009/08/18 23:22:53 | 00,166,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\puiapi.dll
    [2009/08/18 23:22:53 | 00,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mprapi.dll
    [2009/08/18 23:22:53 | 00,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\smb.sys
    [2009/08/18 23:22:53 | 00,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FwRemoteSvr.dll
    [2009/08/18 23:22:53 | 00,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\deskadp.dll
    [2009/08/18 23:22:53 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll
    [2009/08/18 23:22:52 | 00,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMSPDMOD.DLL
    [2009/08/18 23:22:52 | 00,758,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMADMOD.DLL
    [2009/08/18 23:22:52 | 00,116,736 | ---- | C] (Microsoft) -- C:\Windows\SysNative\SMBHelperClass.dll
    [2009/08/18 23:22:52 | 00,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mprapi.dll
    [2009/08/18 23:22:52 | 00,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdSSDP.dll
    [2009/08/18 23:22:52 | 00,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wshbth.dll
    [2009/08/18 23:22:52 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\version.dll
    [2009/08/18 23:22:52 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fc.exe
    [2009/08/18 23:22:52 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msisip.dll
    [2009/08/18 23:22:51 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax
    [2009/08/18 23:22:51 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bthci.dll
    [2009/08/18 23:22:50 | 00,291,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eapp3hst.dll
    [2009/08/18 23:22:50 | 00,212,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wdmaud.drv
    [2009/08/18 23:22:50 | 00,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dmusic.dll
    [2009/08/18 23:22:50 | 00,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gpapi.dll
    [2009/08/18 23:22:50 | 00,068,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdSSDP.dll
    [2009/08/18 23:22:50 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MsCtfMonitor.dll
    [2009/08/18 23:22:49 | 02,247,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\networkexplorer.dll
    [2009/08/18 23:22:49 | 00,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpps.dll
    [2009/08/18 23:22:49 | 00,231,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wscntfy.dll
    [2009/08/18 23:22:49 | 00,187,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eapp3hst.dll
    [2009/08/18 23:22:49 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tintlgnt.ime
    [2009/08/18 23:22:49 | 00,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxg.sys
    [2009/08/18 23:22:49 | 00,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PNPXAssoc.dll
    [2009/08/18 23:22:49 | 00,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dot3cfg.dll
    [2009/08/18 23:22:49 | 00,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidclass.sys
    [2009/08/18 23:22:49 | 00,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\l2nacp.dll
    [2009/08/18 23:22:49 | 00,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ftp.exe
    [2009/08/18 23:22:49 | 00,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cscapi.dll
    [2009/08/18 23:22:49 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\tdi.sys
    [2009/08/18 23:22:49 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msjint40.dll
    [2009/08/18 23:22:49 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CHxReadingStringIME.dll
    [2009/08/18 23:22:48 | 00,105,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceClassExtension.dll
    [2009/08/18 23:22:48 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceClassExtension.dll
    [2009/08/18 23:22:48 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rrinstaller.exe
    [2009/08/18 23:22:48 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rrinstaller.exe
    [2009/08/18 23:22:48 | 00,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ftp.exe
    [2009/08/18 23:22:48 | 00,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cscdll.dll
    [2009/08/18 23:22:47 | 00,347,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmnet.dll
    [2009/08/18 23:22:47 | 00,194,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
    [2009/08/18 23:22:47 | 00,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceTypes.dll
    [2009/08/18 23:22:47 | 00,143,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mydocs.dll
    [2009/08/18 23:22:47 | 00,083,456 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\SMBHelperClass.dll
    [2009/08/18 23:22:47 | 00,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Storprop.dll
    [2009/08/18 23:22:47 | 00,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rasdiag.dll
    [2009/08/18 23:22:47 | 00,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hbaapi.dll
    [2009/08/18 23:22:47 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsdchngr.dll
    [2009/08/18 23:22:47 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rasdial.exe
    [2009/08/18 23:22:46 | 00,211,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eappcfg.dll
    [2009/08/18 23:22:46 | 00,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eappcfg.dll
    [2009/08/18 23:22:46 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdWCN.dll
    [2009/08/18 23:22:46 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdWCN.dll
    [2009/08/18 23:22:46 | 00,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dot3cfg.dll
    [2009/08/18 23:22:46 | 00,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\bthudtask.exe
    [2009/08/18 23:22:46 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ipconfig.exe
    [2009/08/18 23:22:46 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CHxReadingStringIME.dll
    [2009/08/18 23:22:45 | 00,506,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSMPEG2ENC.DLL
    [2009/08/18 23:22:45 | 00,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SLLUA.exe
    [2009/08/18 23:22:45 | 00,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSAC3ENC.DLL
    [2009/08/18 23:22:45 | 00,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfps.dll
    [2009/08/18 23:22:45 | 00,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nslookup.exe
    [2009/08/18 23:22:45 | 00,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tscupgrd.exe
    [2009/08/18 23:22:45 | 00,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\networkitemfactory.dll
    [2009/08/18 23:22:45 | 00,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\slcinst.dll
    [2009/08/18 23:22:45 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\networkitemfactory.dll
    [2009/08/18 23:22:44 | 00,104,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eappgnui.dll
    [2009/08/18 23:22:44 | 00,093,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eappgnui.dll
    [2009/08/18 23:22:44 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tscupgrd.exe
    [2009/08/18 23:22:44 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\slcinst.dll
    [2009/08/18 23:22:44 | 00,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ocsetup.exe
    [2009/08/18 23:22:44 | 00,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ocsetup.exe
    [2009/08/18 23:22:44 | 00,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfpmp.exe
    [2009/08/18 23:22:44 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FwRemoteSvr.dll
    [2009/08/18 23:22:43 | 00,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dfsc.sys
    [2009/08/18 23:22:43 | 00,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdeploy.dll
    [2009/08/18 23:22:43 | 00,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\hbaapi.dll
    [2009/08/18 23:22:43 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msacm32.drv
    [2009/08/18 23:22:43 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfpmp.exe
    [2009/08/18 23:22:43 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msacm32.drv
    [2009/08/18 23:22:43 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mmcico.dll
    [2009/08/18 23:22:42 | 00,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cbsra.exe
    [2009/08/18 23:22:42 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bitsigd.dll
    [2009/08/18 23:22:42 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wscapi.dll
    [2009/08/18 23:22:42 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gpupdate.exe
    [2009/08/18 23:22:40 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vss_ps.dll
    [2009/08/18 23:22:40 | 00,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bthudtask.exe
    [2009/08/18 23:22:40 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\NcdProp.dll
    [2009/08/18 23:22:40 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iscsilog.dll
    [2009/08/18 23:22:38 | 00,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpps.dll
    [2009/08/18 23:22:38 | 00,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbcconf.dll
    [2009/08/18 23:22:38 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbcconf.dll
    [2009/08/18 23:22:38 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vdmdbg.dll
    [2009/08/18 23:22:38 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetppui.dll
    [2009/08/18 23:22:38 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\slwga.dll
    [2009/08/18 23:22:37 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\RNDISMP.sys
    [2009/08/18 23:22:37 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbohci.sys
    [2009/08/18 23:22:37 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\midimap.dll
    [2009/08/18 23:22:37 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winrnr.dll
    [2009/08/18 23:22:37 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usb8023.sys
    [2009/08/18 23:22:37 | 00,009,212 | ---- | C] () -- C:\Windows\SysWow64\RacUR.xml
    [2009/08/18 23:22:37 | 00,009,212 | ---- | C] () -- C:\Windows\SysNative\RacUR.xml
    [2009/08/18 23:22:36 | 00,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\cdrom.sys
    [2009/08/18 23:22:36 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\midimap.dll
    [2009/08/18 23:22:33 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys
    [2009/08/18 23:22:32 | 00,068,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\stream.sys
    [2009/08/18 23:22:32 | 00,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\raspppoe.sys
    [2009/08/18 23:22:32 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
    [2009/08/18 23:22:30 | 00,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\f3ahvoas.dll
    [2009/08/18 23:22:29 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\f3ahvoas.dll
    [2009/08/18 23:22:29 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msimsg.dll
    [2009/08/18 23:22:29 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msimsg.dll
    [2009/08/18 23:22:29 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mferror.dll
    [2009/08/18 23:22:29 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mferror.dll
    [2009/08/18 23:22:06 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wdscore.dll
    [2009/08/18 23:22:01 | 00,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drvstore.dll
    [2009/08/18 23:21:34 | 00,936,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SmiEngine.dll
    [2009/08/18 23:21:32 | 00,293,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wdscore.dll
    [2009/08/18 23:21:32 | 00,138,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PkgMgr.exe
    [2009/08/18 23:21:27 | 00,315,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drvstore.dll
    [2009/08/18 11:24:08 | 00,001,833 | ---- | C] () -- C:\Users\Public\Desktop\Play The Secret of Margrave Manor.lnk
    [2009/08/15 12:05:22 | 00,001,895 | ---- | C] () -- C:\Users\Public\Desktop\Play Autumn's Treasures - The Jade Coin.lnk
    [2009/08/14 13:14:28 | 01,689,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
    [2009/08/14 13:14:27 | 00,656,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kerberos.dll
    [2009/08/14 13:14:26 | 00,499,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\kerberos.dll
    [2009/08/14 13:14:26 | 00,269,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msv1_0.dll
    [2009/08/14 13:14:25 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msv1_0.dll
    [2009/08/14 13:14:25 | 00,205,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wdigest.dll
    [2009/08/14 13:14:25 | 00,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wdigest.dll
    [2009/08/14 13:14:24 | 00,515,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ksecdd.sys
    [2009/08/14 13:14:24 | 00,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\schannel.dll
    [2009/08/14 13:14:24 | 00,270,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\schannel.dll
    [2009/08/14 13:14:23 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
    [2009/08/14 13:14:23 | 00,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secur32.dll
    [2009/08/14 13:14:23 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsass.exe
    [2009/08/13 21:42:52 | 00,001,661 | ---- | C] () -- C:\Users\Public\Desktop\Play City Style.lnk
    [2009/08/13 15:35:36 | 00,000,000 | ---D | C] -- C:\ZCDivXtoDVD
    [2009/08/13 08:39:04 | 00,000,130 | ---- | C] () -- C:\Users\Beverly\Desktop\Armory Studio, Adams, Mass.url
    [2009/08/13 01:23:46 | 02,424,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
    [2009/08/13 01:23:44 | 02,066,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
    [2009/08/13 01:23:43 | 00,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aaclient.dll
    [2009/08/13 01:23:43 | 00,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\aaclient.dll
    [2009/08/13 01:23:42 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll
    [2009/08/13 01:23:42 | 00,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll
    [2009/08/13 01:23:34 | 00,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\atl.dll
    [2009/08/13 01:23:34 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\atl.dll
    [2009/08/13 01:23:30 | 00,203,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wkssvc.dll
    [2009/08/13 01:23:25 | 00,093,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mciavi32.dll
    [2009/08/13 01:23:25 | 00,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\avicap32.dll
    [2009/08/13 01:23:24 | 00,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\avifil32.dll
    [2009/08/13 01:23:24 | 00,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\avifil32.dll
    [2009/08/13 01:23:06 | 13,428,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
    [2009/08/13 01:23:01 | 10,626,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
    [2009/08/13 01:22:58 | 00,368,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpdxm.dll
    [2009/08/13 01:22:58 | 00,313,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpdxm.dll
    [2009/08/13 01:22:56 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwmp.dll
    [2009/08/13 01:22:56 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spwmp.dll
    [2009/08/13 01:22:55 | 08,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
    [2009/08/13 01:22:55 | 00,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdxm.ocx
    [2009/08/13 01:22:55 | 00,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxmasf.dll
    [2009/08/13 01:22:55 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdxm.ocx
    [2009/08/13 01:22:55 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxmasf.dll
    [2009/08/13 01:22:54 | 08,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
    [2009/08/13 01:22:53 | 00,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdxm.tlb
    [2009/08/13 01:22:53 | 00,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdxm.tlb
    [2009/08/13 01:22:53 | 00,018,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\amcompat.tlb
    [2009/08/13 01:22:53 | 00,018,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\amcompat.tlb
    [2009/08/12 00:30:20 | 02,101,045 | ---- | C] () -- C:\Users\Beverly\Documents\100_3751.JPG
    [2009/08/12 00:30:20 | 02,097,656 | ---- | C] () -- C:\Users\Beverly\Documents\100_3855.JPG
    [2009/08/12 00:30:20 | 02,078,167 | ---- | C] () -- C:\Users\Beverly\Documents\100_3897.JPG
    [2009/08/12 00:30:20 | 02,074,542 | ---- | C] () -- C:\Users\Beverly\Documents\100_3750.JPG
    [2009/08/12 00:30:20 | 02,063,062 | ---- | C] () -- C:\Users\Beverly\Documents\100_3854.JPG
    [2009/08/12 00:30:20 | 02,055,599 | ---- | C] () -- C:\Users\Beverly\Documents\100_3755.JPG
    [2009/08/12 00:30:20 | 02,046,929 | ---- | C] () -- C:\Users\Beverly\Documents\100_3863.JPG
    [2009/08/12 00:30:20 | 02,006,436 | ---- | C] () -- C:\Users\Beverly\Documents\100_3862.JPG
    [2009/08/12 00:30:20 | 01,976,651 | ---- | C] () -- C:\Users\Beverly\Documents\100_3752.JPG
    [2009/08/12 00:30:20 | 01,893,578 | ---- | C] () -- C:\Users\Beverly\Documents\100_3857.JPG
    [2009/08/12 00:30:20 | 01,874,234 | ---- | C] () -- C:\Users\Beverly\Documents\100_3749.JPG
    [2009/08/12 00:30:20 | 01,861,739 | ---- | C] () -- C:\Users\Beverly\Documents\100_3886.JPG
    [2009/08/12 00:30:20 | 01,792,922 | ---- | C] () -- C:\Users\Beverly\Documents\100_3882.JPG
    [2009/08/12 00:30:20 | 01,738,328 | ---- | C] () -- C:\Users\Beverly\Documents\100_3748.JPG
    [2009/08/12 00:30:20 | 01,713,826 | ---- | C] () -- C:\Users\Beverly\Documents\100_3884.JPG
    [2009/08/12 00:30:20 | 01,694,346 | ---- | C] () -- C:\Users\Beverly\Documents\100_3860.JPG
    [2009/08/12 00:30:20 | 01,688,685 | ---- | C] () -- C:\Users\Beverly\Documents\100_3747.JPG
    [2009/08/12 00:30:20 | 01,638,341 | ---- | C] () -- C:\Users\Beverly\Documents\100_3864.JPG
    [2009/08/12 00:30:20 | 01,602,895 | ---- | C] () -- C:\Users\Beverly\Documents\100_3859.JPG
    [2009/08/12 00:30:20 | 01,593,438 | ---- | C] () -- C:\Users\Beverly\Documents\100_3896.JPG
    [2009/08/12 00:30:20 | 01,571,928 | ---- | C] () -- C:\Users\Beverly\Documents\100_3858.JPG
    [2009/08/12 00:30:20 | 01,564,513 | ---- | C] () -- C:\Users\Beverly\Documents\100_3753.JPG
    [2009/08/12 00:30:20 | 01,560,793 | ---- | C] () -- C:\Users\Beverly\Documents\100_3881.JPG
    [2009/08/12 00:30:20 | 01,453,269 | ---- | C] () -- C:\Users\Beverly\Documents\100_3743.JPG
    [2009/08/12 00:30:20 | 01,435,079 | ---- | C] () -- C:\Users\Beverly\Documents\100_3856.JPG
    [2009/08/12 00:30:20 | 01,426,693 | ---- | C] () -- C:\Users\Beverly\Documents\100_3883.JPG
    [2009/08/12 00:30:20 | 01,420,257 | ---- | C] () -- C:\Users\Beverly\Documents\100_3894.JPG
    [2009/08/12 00:30:20 | 01,410,863 | ---- | C] () -- C:\Users\Beverly\Documents\100_3745.JPG
    [2009/08/12 00:30:20 | 01,364,867 | ---- | C] () -- C:\Users\Beverly\Documents\100_3782.JPG
    [2009/08/12 00:30:20 | 01,358,433 | ---- | C] () -- C:\Users\Beverly\Documents\100_3754.JPG
    [2009/08/12 00:30:20 | 01,330,685 | ---- | C] () -- C:\Users\Beverly\Documents\100_3744.JPG
    [2009/08/12 00:30:20 | 01,310,494 | ---- | C] () -- C:\Users\Beverly\Documents\100_3877.JPG
    [2009/08/12 00:30:20 | 01,306,840 | ---- | C] () -- C:\Users\Beverly\Documents\100_3887.JPG
    [2009/08/12 00:30:20 | 01,301,632 | ---- | C] () -- C:\Users\Beverly\Documents\100_3746.JPG
    [2009/08/12 00:30:20 | 01,290,269 | ---- | C] () -- C:\Users\Beverly\Documents\100_3865.JPG
    [2009/08/12 00:30:20 | 01,202,751 | ---- | C] () -- C:\Users\Beverly\Documents\100_3873.JPG
    [2009/08/12 00:30:20 | 01,134,134 | ---- | C] () -- C:\Users\Beverly\Documents\100_3892.JPG
    [2009/08/12 00:30:20 | 01,122,530 | ---- | C] () -- C:\Users\Beverly\Documents\100_3872.JPG
    [2009/08/12 00:30:20 | 01,107,524 | ---- | C] () -- C:\Users\Beverly\Documents\100_3861.JPG
    [2009/08/12 00:30:20 | 01,080,408 | ---- | C] () -- C:\Users\Beverly\Documents\100_3893.JPG
    [2009/08/12 00:30:20 | 01,077,700 | ---- | C] () -- C:\Users\Beverly\Documents\100_3888.JPG
    [2009/08/12 00:30:20 | 01,077,233 | ---- | C] () -- C:\Users\Beverly\Documents\100_3876.JPG
    [2009/08/12 00:30:20 | 00,977,643 | ---- | C] () -- C:\Users\Beverly\Documents\100_3869.JPG
    [2009/08/12 00:30:20 | 00,958,456 | ---- | C] () -- C:\Users\Beverly\Documents\100_3902.JPG
    [2009/08/12 00:30:20 | 00,940,762 | ---- | C] () -- C:\Users\Beverly\Documents\100_3870.JPG
    [2009/08/12 00:30:20 | 00,931,934 | ---- | C] () -- C:\Users\Beverly\Documents\100_3901.JPG
    [2009/08/12 00:30:20 | 00,929,521 | ---- | C] () -- C:\Users\Beverly\Documents\100_3898.JPG
    [2009/08/12 00:30:20 | 00,929,022 | ---- | C] () -- C:\Users\Beverly\Documents\100_3866.JPG
    [2009/08/12 00:30:20 | 00,912,901 | ---- | C] () -- C:\Users\Beverly\Documents\100_3756.JPG
    [2009/08/12 00:30:20 | 00,898,278 | ---- | C] () -- C:\Users\Beverly\Documents\100_3867.JPG
    [2009/08/12 00:30:20 | 00,874,599 | ---- | C] () -- C:\Users\Beverly\Documents\100_3871.JPG
    [2009/08/12 00:30:20 | 00,824,248 | ---- | C] () -- C:\Users\Beverly\Documents\100_3868.JPG
    [2009/08/12 00:30:20 | 00,798,454 | ---- | C] () -- C:\Users\Beverly\Documents\100_3891.JPG
    [2009/08/12 00:30:20 | 00,779,139 | ---- | C] () -- C:\Users\Beverly\Documents\100_3879.JPG
    [2009/08/12 00:30:20 | 00,774,119 | ---- | C] () -- C:\Users\Beverly\Documents\100_3900.JPG
    [2009/08/12 00:30:20 | 00,770,597 | ---- | C] () -- C:\Users\Beverly\Documents\100_3889.JPG
    [2009/08/12 00:30:20 | 00,732,363 | ---- | C] () -- C:\Users\Beverly\Documents\100_3895.JPG
    [2009/08/12 00:30:20 | 00,718,245 | ---- | C] () -- C:\Users\Beverly\Documents\100_3880.JPG
    [2009/08/12 00:30:20 | 00,715,943 | ---- | C] () -- C:\Users\Beverly\Documents\100_3899.JPG
    [2009/08/12 00:30:20 | 00,695,323 | ---- | C] () -- C:\Users\Beverly\Documents\100_3890.JPG
    [2009/08/12 00:30:20 | 00,653,881 | ---- | C] () -- C:\Users\Beverly\Documents\100_3885.JPG
    [2009/08/12 00:30:20 | 00,642,542 | ---- | C] () -- C:\Users\Beverly\Documents\100_3878.JPG
    [2009/08/12 00:30:20 | 00,620,673 | ---- | C] () -- C:\Users\Beverly\Documents\100_3874.JPG
    [2009/08/12 00:30:20 | 00,464,175 | ---- | C] () -- C:\Users\Beverly\Documents\100_3875.JPG
    [2009/08/12 00:30:02 | 00,000,000 | ---D | C] -- C:\Users\Beverly\Documents\Prov.RI
    [2009/08/12 00:30:01 | 00,843,923 | ---- | C] () -- C:\Users\Beverly\Documents\100_3608.JPG
    [2009/08/12 00:30:01 | 00,000,000 | ---D | C] -- C:\Users\Beverly\Documents\Kitty
    [2009/08/12 00:30:01 | 00,000,000 | ---D | C] -- C:\Users\Beverly\Documents\EASTER AT LORI'S
    [2009/08/12 00:30:00 | 00,000,000 | ---D | C] -- C:\Users\Beverly\Documents\Xmas 08
    [2009/08/12 00:29:57 | 00,000,000 | ---D | C] -- C:\Users\Beverly\Documents\Moms 81
    [2009/08/12 00:29:54 | 01,021,259 | ---- | C] () -- C:\Users\Beverly\Documents\100_3679.JPG
    [2009/08/12 00:29:54 | 00,995,294 | ---- | C] () -- C:\Users\Beverly\Documents\100_3903.JPG
    [2009/08/12 00:29:54 | 00,821,042 | ---- | C] () -- C:\Users\Beverly\Documents\100_3681.JPG
    [2009/08/12 00:29:54 | 00,762,991 | ---- | C] () -- C:\Users\Beverly\Documents\100_3682.JPG
    [2009/08/12 00:29:54 | 00,640,868 | ---- | C] () -- C:\Users\Beverly\Documents\100_3680.JPG
    [2009/08/12 00:29:54 | 00,488,283 | ---- | C] () -- C:\Users\Beverly\Documents\100_3683.JPG
    [2009/08/12 00:29:54 | 00,485,751 | ---- | C] () -- C:\Users\Beverly\Documents\100_3684.JPG
    [2009/08/12 00:29:54 | 00,000,000 | ---D | C] -- C:\Users\Beverly\Documents\Loris
    [2009/08/11 23:39:01 | 00,000,000 | ---D | C] -- C:\ProgramData\ZwangiSearch
    [2009/08/11 23:39:01 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\ZwangiSearch
    [2009/08/10 23:53:22 | 00,000,228 | ---- | C] () -- C:\Users\Beverly\Desktop\http--www.coffeecow.com-PublicPages-ProductListing.aspxSubCategoryID=27.url
    [2009/08/10 23:53:09 | 00,000,129 | ---- | C] () -- C:\Users\Beverly\Desktop\Shop Keurig KCup Coffee Selections at CoffeeWiz.com.url
    [2009/08/09 22:52:19 | 00,318,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CF9103.exe
    [2009/08/09 22:52:04 | 00,000,000 | ---D | C] -- C:\Qoobox
    [2009/08/08 20:32:19 | 00,000,144 | ---- | C] () -- C:\Users\Beverly\Desktop\The Perfect Cup Sweepstakes.url
    [2009/08/07 23:30:22 | 00,000,245 | ---- | C] () -- C:\Users\Beverly\Desktop\CD Burners - Free Downloads on ZDNet Shareware, Trialware, Evaluation Software.url
    [2009/08/07 23:29:23 | 00,000,882 | ---- | C] () -- C:\Users\Beverly\Desktop\ZC DivX to DVD Creator.lnk
    [2009/08/07 23:29:13 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\ZC DivX to DVD Creator
    [2009/08/07 00:18:57 | 00,000,189 | ---- | C] () -- C:\Users\Beverly\Desktop\The Cheapskate - CNET News.url
    [2009/05/31 19:33:23 | 00,000,321 | ---- | C] () -- C:\Windows\SysWow64\XMLConfig_SYSID.ini
    [2009/04/21 18:26:56 | 00,031,088 | ---- | C] () -- C:\Windows\SysWow64\wrLZMA.dll
    [2009/04/05 10:32:38 | 00,000,187 | ---- | C] () -- C:\Windows\wininit.ini
    [2009/03/10 23:25:13 | 00,125,440 | ---- | C] () -- C:\Windows\dx7ogl32.dll
    [2008/01/20 22:50:05 | 00,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
    [2006/11/02 08:34:27 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
    [2006/11/02 08:34:27 | 00,000,144 | ---- | C] () -- C:\Windows\win.ini
    [2005/02/05 16:46:00 | 00,004,608 | ---- | C] () -- C:\Windows\fgexec.dll
    < End of report >
     

  3. to hide this advert.

  4. 2009/09/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OMG...you finished :)
    Let me take a look....
     
  5. 2009/09/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    While I'm reviewing the log, let me know how the computer is doing.
     
  6. 2009/09/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Unless you willingly installed Kontiki Player....
    Go Start>Control Panel>Add\Remove ( "Programs and Features" in Vista), and uninstall Sky Anytime (if present).
    Download, and run KClean.exe: http://static.sky.com/kclean/KClean.exe to remove Kontiki from your computer.
    NOTE: Kontiki is know resource hog.

    While in "Programs and Features ", uninstall ZwangiSearch.
    Uninstall all older Java versions except for ver. 6 update 15

    Make sure, Firefox is closed....
    Open Windows Explorer, navigate to:
    C:\Users\Beverly\AppData\Roaming\mozilla\Firefox\Profiles\tty9pkll.default
    Open prefs.js file in Notepad.
    Find, and delete following lines:
    - browser.search.selectedEngine: "MyWebSearch "
    - keyword.URL: "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZKxdm176YYUS&fl=0&ptb=9C21RrBJEr9CAPqhtqRDNw&st=kwd&o=kwd &url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&si=39168&searchfor= "

    When done, go File>Save.

    Navigate to:
    C:\Users\Beverly\AppData\Roaming\Mozilla\FireFox\Profiles\tty9pkll.default\ searchplugins
    Delete mywebsearch.xml file.


    When done....
    Download HijackThis:
    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
    by clicking on Download HijackThis Installer
    Install, and run it.
    Post HijackTHis log.
    Do NOT attempt to fix anything!

    NOTE. If you're using Vista, right click on HijackThis, and click Run as Administrator

    HJT is not fully compatible with 64-bit OS, but it's good enough for me to perform final cleaning.
     
  7. 2009/09/06
    snookie28

    snookie28 Inactive Thread Starter

    Joined:
    2002/06/28
    Messages:
    245
    Likes Received:
    0
    Internet Explorer stops working

    have to get ready for work; when I went to close out Firefox, which ran fine..no problems with the "Internet Explorer stopped working" window, popping up until i went into that to continue with the rest of the post. I will continue with this later.....you have been great! Will get back to you later and try to finish. Running so much better...talk to you later....snookie28
     
  8. 2009/09/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No problem :)
     
  9. 2009/09/06
    snookie28

    snookie28 Inactive Thread Starter

    Joined:
    2002/06/28
    Messages:
    245
    Likes Received:
    0
    Internet Explorer stops working

    Internet Explorer NOT doing well. When I closed FireFox to open Windows explorer I kept having the same problem with the message window popping up:confused: Now what?? Snookie.....I will try working with it more....will keep you informed.
     
  10. 2009/09/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    What message are you getting, when trying to open Windows Explorer?
     
  11. 2009/09/06
    snookie28

    snookie28 Inactive Thread Starter

    Joined:
    2002/06/28
    Messages:
    245
    Likes Received:
    0
    Internet explorer has to close

    Internet Explorer has stopped working
    A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available. Then I click close program. The window that has this message in it is titled Microsoft Windows.
    After I close another box comes up to say Internet Exlorere was closed
    To help protect your computer, Data Execution Prevention has closed Internet Explorer. Click to learn more.
    It says Internet Explorer has closed this webpage to help protect your computer. A malfunctioning or malicious add-on has caused this to close this web page. Then it give me 3 choices:
    Go to your home page
    Try to return to antivirus.com
    More Info.
    Once before it asked me if I wanted to re-start my last scession and I swear about 10 windows opened.:confused: This Is wierd.
     
  12. 2009/09/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I thought, you had problems with Windows Explorer as well.
    Don't worry about IE for now.
    Work on my steps, I gave you.
     
  13. 2009/09/06
    snookie28

    snookie28 Inactive Thread Starter

    Joined:
    2002/06/28
    Messages:
    245
    Likes Received:
    0
    Internet Explorer not responding

    silly me...I thought it was the same thing:confused:
     
  14. 2009/09/06
    snookie28

    snookie28 Inactive Thread Starter

    Joined:
    2002/06/28
    Messages:
    245
    Likes Received:
    0
    Internet Explorer has to close

    ok.....Did not find Skyanytime; downloaded KClean.exe and removed Kontiki;uninstalled Zwangisearch and too out older versions of Java except for ver.6 update 15. I copied and pasted prefs.js in notepad but nothing came up. Also had trouble finding the other Items.....I copied and pasted and maybe I was just pasteing to the wrong place. I did try to do a few things In Explorer so that I could take out mywebsearches,etc.but couldn't find that either.
    So......do you want me to go ahead and download HijackThis or continue and try to delete the Items you advised me to?
    Thank you
     
  15. 2009/09/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No. Give me a moment, and I'll prepare a script for you to run.
     
  16. 2009/09/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      PRC - [2009/01/02 08:05:42 | 03,098,152 | ---- | M] (Kontiki Inc.) -- C:\Program Files (x86)\Kontiki\KService.exe
      PRC - [2009/04/14 23:06:02 | 00,028,762 | ---- | M] (MyWebSearch.com) -- C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE
      PRC - [2009/09/02 15:34:10 | 00,054,760 | ---- | M] () -- C:\ProgramData\ZwangiSearch\zwangi125.exe
      PRC - [2009/09/02 15:34:10 | 00,054,760 | ---- | M] () -- C:\Program Files (x86)\ZwangiSearch\zwangi.exe
      PRC - [2009/04/14 23:06:02 | 00,032,838 | ---- | M] (MyWebSearch.com) -- C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE
      PRC - [2009/01/02 08:05:40 | 01,041,960 | ---- | M] (Kontiki Inc.) -- C:\Program Files (x86)\Kontiki\KHost.exe
      PRC - [2009/04/14 23:06:01 | 00,024,688 | ---- | M] (MyWebSearch.com) -- C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
      SRV - [2009/01/02 08:05:42 | 03,098,152 | ---- | M] (Kontiki Inc.) -- C:\Program Files (x86)\Kontiki\KService.exe -- (KService [Auto | Running])
      SRV - [2009/04/14 23:06:02 | 00,028,762 | ---- | M] (MyWebSearch.com) -- C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE -- (MyWebSearchService [Auto | Running])
      SRV - [2009/09/02 15:34:10 | 00,054,760 | ---- | M] () -- C:\ProgramData\ZwangiSearch\zwangi125.exe -- (ZwangiSearch Service [Auto | Running])
      IE - URLSearchHook: {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - Reg Error: Key error. File not found
      O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com)
      O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)
      O2 - BHO: (no name) - MRI_DISABLED - No CLSID value found.
      O3 - HKLM\..\Toolbar: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)
      O3 - HKCU\..\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)
      O4 - HKLM..\Run: [My Web Search Bar Search Scope Monitor] C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (MyWebSearch.com)
      O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com)
      O4 - HKLM..\Run: [MyWebSearch Plugin] C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (MyWebSearch.com)
      O4 - HKCU..\Run: [kdx] C:\Program Files (x86)\Kontiki\KHost.exe (Kontiki Inc.)
      O4 - HKCU..\Run: [MyWebSearch Email Plugin] C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com)
      
      
      :Services
      
      :Reg
      
      :Files
      C:\Program Files (x86)\Kontiki\KService.exe
      C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE
      C:\ProgramData\ZwangiSearch\zwangi125.exe
      C:\Program Files (x86)\ZwangiSearch\zwangi.exe
      C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE
      C:\Program Files (x86)\Kontiki\KHost.exe
      C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
      
      :Commands
      [purity]
      [emptytemp]
      [Reboot]
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
     
  17. 2009/09/06
    snookie28

    snookie28 Inactive Thread Starter

    Joined:
    2002/06/28
    Messages:
    245
    Likes Received:
    0
    Internet Explorer stops working

    All processes killed
    ========== OTL ==========
    No active process named explorer.exe was found!
    No active process named KService.exe was found!
    No active process named MWSSVC.EXE was found!
    No active process named zwangi125.exe was found!
    No active process named zwangi.exe was found!
    No active process named MWSOEMON.EXE was found!
    No active process named KHost.exe was found!
    No active process named M3SRCHMN.EXE was found!
    Service\Driver KService not found.
    Service\Driver KService not found.
    File C:\Program Files (x86)\Kontiki\KService.exe not found.
    Service\Driver MyWebSearchService not found.
    Service\Driver MyWebSearchService not found.
    File C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE not found.
    Service\Driver ZwangiSearch Service not found.
    Service\Driver ZwangiSearch Service not found.
    File C:\ProgramData\ZwangiSearch\zwangi125.exe not found.
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{d51d388b-f5dc-471a-a1ce-5e2d671091c0} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}\ not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}\ not found.
    File C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\ not found.
    File C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\MRI_DISABLED\ deleted successfully.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{07B18EA9-A523-4961-B6BB-170DE4475CCA} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\ not found.
    File C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL not found.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{07B18EA9-A523-4961-B6BB-170DE4475CCA} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\ not found.
    File C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\My Web Search Bar Search Scope Monitor deleted successfully.
    File C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Email Plugin not found.
    File C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Plugin not found.
    File C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3PLUGIN.DLL not found.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\kdx not found.
    File C:\Program Files (x86)\Kontiki\KHost.exe not found.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Email Plugin not found.
    File C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE not found.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    File\Folder C:\Program Files (x86)\Kontiki\KService.exe not found.
    File\Folder C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE not found.
    File\Folder C:\ProgramData\ZwangiSearch\zwangi125.exe not found.
    File\Folder C:\Program Files (x86)\ZwangiSearch\zwangi.exe not found.
    File\Folder C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE not found.
    File\Folder C:\Program Files (x86)\Kontiki\KHost.exe not found.
    File\Folder C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: AppData

    User: Beverly
    File delete failed. C:\Users\Beverly\AppData\Local\Temp\ppcrlui_5292_2 scheduled to be deleted on reboot.
    ->Temp folder emptied: 4494897 bytes
    File delete failed. C:\Users\Beverly\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    ->Temporary Internet Files folder emptied: 29040912 bytes
    ->Java cache emptied: 260317033 bytes
    ->FireFox cache emptied: 83570982 bytes
    ->Google Chrome cache emptied: 43571930 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    Windows Temp folder emptied: 1128928 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 402.60 mb


    OTL by OldTimer - Version 3.0.10.7 log created on 09062009_220712

    Files\Folders moved on Reboot...
    C:\Users\Beverly\AppData\Local\Temp\ppcrlui_5292_2 moved successfully.

    Registry entries deleted on Reboot...
     
  18. 2009/09/06
    snookie28

    snookie28 Inactive Thread Starter

    Joined:
    2002/06/28
    Messages:
    245
    Likes Received:
    0
    Internet Explorer stops working

    OTL logfile created on: 9/6/2009 10:17:51 PM - Run 5
    OTL by OldTimer - Version 3.0.10.7 Folder = C:\Users\Beverly\Desktop
    64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18813)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.75 Gb Total Physical Memory | 2.17 Gb Available Physical Memory | 57.81% Memory free
    4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 359.69 Gb Total Space | 218.09 Gb Free Space | 60.63% Space Free | Partition Type: NTFS
    Drive D: | 12.91 Gb Total Space | 1.62 Gb Free Space | 12.51% Space Free | Partition Type: NTFS
    E: Drive not present or media not loaded
    Drive F: | 596.02 Gb Total Space | 477.19 Gb Free Space | 80.06% Space Free | Partition Type: FAT32
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: BEVERLY-PC
    Current User Name: Beverly
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Include 64bit Scans
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 14 Days
    Output = Standard
    Quick Scan

    ========== Processes (SafeList) ==========

    PRC - [2009/06/07 16:08:46 | 01,205,760 | ---- | M] (Webroot Software, Inc. ) -- C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe
    PRC - [2009/05/15 09:57:18 | 00,067,456 | ---- | M] () -- C:\Program Files\Search Guard PlusU\sgpupdaters.exe
    PRC - [2009/02/06 17:02:14 | 00,109,056 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    PRC - [2008/06/09 14:21:58 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    PRC - [2008/10/06 12:54:52 | 00,365,952 | ---- | M] () -- C:\Program Files (x86)\SMINST\BLService.exe
    PRC - [2008/06/29 19:10:18 | 00,241,734 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
    PRC - [2009/05/19 11:36:18 | 00,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    PRC - [2009/04/21 18:26:52 | 04,048,240 | ---- | M] (Webroot Software, Inc. (www.webroot.com)) -- C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe
    PRC - [2008/12/12 18:06:40 | 00,642,856 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
    PRC - [2008/06/09 14:16:32 | 02,363,392 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
    PRC - [2009/01/12 12:27:06 | 00,972,344 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
    PRC - [2009/03/28 09:22:40 | 00,171,448 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    PRC - [2008/04/28 21:19:18 | 00,167,936 | ---- | M] (Blinkx Limited) -- C:\Program Files (x86)\Blinkx\blinkx.exe
    PRC - [2009/07/10 13:49:24 | 00,323,584 | ---- | M] (Eastman Kodak Company) -- C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    PRC - [2008/09/26 06:36:40 | 01,148,200 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
    PRC - [2008/09/25 22:41:44 | 01,152,296 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
    PRC - [2008/09/25 22:42:24 | 00,189,736 | ---- | M] (CyberLink) -- C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
    PRC - [2008/08/01 19:14:02 | 00,202,032 | ---- | M] ( Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    PRC - [2008/04/15 17:51:00 | 00,488,752 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    PRC - [2008/09/23 17:21:52 | 00,468,264 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\Hp\QuickPlay\QPService.exe
    PRC - [2009/03/28 09:20:42 | 01,838,592 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
    PRC - [2007/02/20 21:18:32 | 00,366,400 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Picasa2\PicasaMediaDetector.exe
    PRC - [2009/02/27 17:10:28 | 00,035,696 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
    PRC - [2008/12/12 18:06:40 | 00,642,856 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe
    PRC - [2008/12/14 09:29:00 | 00,467,240 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files (x86)\Pure Networks\Network Magic\nmapp.exe
    PRC - [2009/07/10 13:59:22 | 00,195,072 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
    PRC - [2009/05/13 15:40:36 | 06,345,840 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeperUI.exe
    PRC - [2008/05/01 19:25:56 | 00,165,192 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
    PRC - [2009/03/28 09:20:42 | 01,838,592 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
    PRC - [2007/09/26 10:34:40 | 00,316,720 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
    PRC - [2008/04/03 14:33:26 | 00,193,840 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
    PRC - [2008/04/11 12:04:54 | 00,685,360 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
    PRC - [2008/06/19 18:04:50 | 00,014,376 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
    PRC - [2009/04/21 18:26:50 | 00,165,232 | ---- | M] (Webroot Software, Inc. (www.webroot.com)) -- C:\Program Files (x86)\Webroot\WebrootSecurity\SSU.EXE
    PRC - [2009/07/30 07:26:38 | 00,908,280 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    PRC - [2009/09/04 09:34:56 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Users\Beverly\Desktop\OTL.exe

    ========== Win32 Services (SafeList) ==========

    SRV:64bit: - [2008/10/15 07:39:50 | 00,089,088 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_5730ce9f\AESTSr64.exe -- (AESTFilters [Auto | Running])
    SRV:64bit: - [2007/12/11 16:11:30 | 00,015,872 | ---- | M] (Agere Systems) -- C:\Windows\SysNative\agr64svc.exe -- (AgereModemAudio [Auto | Running])
    SRV:64bit: - [2008/09/16 23:14:32 | 00,905,216 | ---- | M] (ATI Technologies Inc.) -- C:\Windows\SysNative\Ati2evxx.exe -- (Ati External Event Utility [Auto | Running])
    SRV:64bit: - [2009/04/11 03:11:13 | 00,053,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\bthserv.dll -- (BthServ [Auto | Running])
    SRV:64bit: - [2008/03/18 20:25:40 | 00,023,040 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\SysNative\Hpservice.exe -- (hpsrv [Auto | Running])
    SRV:64bit: - [2008/10/15 07:39:52 | 00,279,040 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_5730ce9f\STacSV64.exe -- (STacSV [Auto | Running])
    SRV:64bit: - [2008/01/20 22:47:32 | 00,383,544 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Running])
    SRV:64bit: - [2008/01/20 22:52:15 | 01,216,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Running])
    SRV - [2009/02/06 17:02:14 | 00,109,056 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon [Auto | Running])
    SRV - [2009/03/30 00:42:14 | 00,066,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
    SRV - [2009/03/30 00:39:54 | 00,089,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64 [On_Demand | Stopped])
    SRV - [2008/04/03 14:33:26 | 00,193,840 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe -- (Com4QLBEx [On_Demand | Running])
    SRV - [2008/01/20 22:51:36 | 00,344,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [On_Demand | Stopped])
    SRV - [2008/01/20 22:51:36 | 00,153,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped])
    SRV - [2006/11/02 11:03:48 | 00,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Auto | Stopped])
    SRV - [2009/02/18 14:40:04 | 00,042,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Running])
    SRV - [2009/06/05 20:07:28 | 00,250,616 | ---- | M] (WildTangent, Inc.) -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe -- (GameConsoleService [On_Demand | Stopped])
    SRV - [2009/03/28 09:20:42 | 01,838,592 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager [On_Demand | Stopped])
    SRV - [2009/03/28 09:22:33 | 00,138,168 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
    SRV - [2008/06/16 11:02:28 | 00,094,208 | ---- | M] (Hewlett-Packard) -- c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe -- (HP Health Check Service [Auto | Running])
    SRV - [2008/05/01 19:25:56 | 00,165,192 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe -- (hpqwmiex [On_Demand | Running])
    SRV - [2004/10/22 06:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) -- C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
    SRV - [2009/02/18 14:39:11 | 00,857,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
    SRV - [2006/11/02 05:46:05 | 00,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\keyiso.dll -- (KeyIso [On_Demand | Running])
    SRV - [2008/06/09 14:21:58 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
    SRV - [2006/11/02 09:34:14 | 00,000,000 | ---D | M] -- C:\Windows\SysWow64\Msdtc -- (MSDTC [Unknown | Stopped])
    SRV - [2009/04/11 02:28:23 | 00,592,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\netlogon.dll -- (Netlogon [On_Demand | Stopped])
    SRV - [2008/12/12 18:06:40 | 00,642,856 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice [Auto | Running])
    SRV - [2008/10/06 12:54:52 | 00,365,952 | ---- | M] () -- C:\Program Files (x86)\SMINST\BLService.exe -- (Recovery Service for Windows [Auto | Running])
    SRV - [2008/06/29 19:10:18 | 00,241,734 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe -- (RichVideo [Auto | Running])
    SRV - [2009/05/19 11:36:18 | 00,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort [Auto | Running])
    SRV - [2006/11/02 02:35:15 | 00,060,994 | ---- | M] () -- C:\Windows\SysWow64\Wbem\vds.mof -- (vds [On_Demand | Stopped])
    SRV - [2006/11/02 02:35:15 | 00,055,846 | ---- | M] () -- C:\Windows\SysWow64\Wbem\vss.mof -- (VSS [On_Demand | Stopped])
    SRV - [2009/04/21 18:26:52 | 04,048,240 | ---- | M] (Webroot Software, Inc. (www.webroot.com)) -- C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe -- (WebrootSpySweeperService [Auto | Running])
    SRV - [2009/06/07 16:08:46 | 01,205,760 | ---- | M] (Webroot Software, Inc. ) -- C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -- (WRConsumerService [Auto | Running])

    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
    IE - URLSearchHook: {a6e4a4eb-d169-4e99-8988-250fcbafe767} - C:\Program Files (x86)\isoHunt\tbiso0.dll (Conduit Ltd.)
    IE - URLSearchHook: {b23920f4-4c2f-412b-9450-1d7028d5454e} - C:\Program Files (x86)\TorrentReactor.Net\tbTor0.dll (Conduit Ltd.)
    IE - URLSearchHook: {f592709f-ff4a-4862-b659-4afabda56312} - C:\Program Files (x86)\Mininova\tbMin0.dll (Conduit Ltd.)

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://pogo.com/?site=pogop
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.search.selectedEngine: "MyWebSearch "
    FF - prefs.js..extensions.enabledItems: {DFF722C4-4A11-41A7-9939-C83A06B09897}:1.0
    FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
    FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.2
    FF - prefs.js..keyword.URL: "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZKxdm176YYUS&fl=0&ptb=9C21RrBJEr9CAPqhtqRDNw&st=kwd&o=kwd&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&si=39168&searchfor= "

    FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/25 11:22:03 | 00,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/09/04 11:36:03 | 00,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2009/09/05 20:53:29 | 00,000,000 | ---D | M]

    [2009/05/02 00:04:51 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\mozilla\Extensions
    [2009/05/02 00:04:51 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
    [2009/09/06 21:34:14 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\mozilla\Firefox\Profiles\tty9pkll.default\extensions
    [2009/09/04 11:54:42 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\mozilla\Firefox\Profiles\tty9pkll.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    [2009/09/04 23:02:32 | 00,009,949 | ---- | M] () -- C:\Users\Beverly\AppData\Roaming\Mozilla\FireFox\Profiles\tty9pkll.default\searchplugins\mywebsearch.xml
    [2009/09/04 11:36:10 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions
    [2009/09/04 11:36:01 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    [2009/09/04 11:36:10 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions\{DFF722C4-4A11-41A7-9939-C83A06B09897}
    [2009/07/30 07:26:53 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
    [2009/07/30 07:26:54 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
    [2009/07/30 07:26:55 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll
    [2009/07/30 03:24:20 | 00,001,394 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
    [2009/07/30 03:24:20 | 00,002,193 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml
    [2009/07/30 03:24:20 | 00,001,534 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml
    [2009/07/30 03:24:20 | 00,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
    [2009/07/30 03:24:20 | 00,002,371 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
    [2009/07/30 03:24:20 | 00,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
    [2009/07/30 03:24:20 | 00,000,792 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml
    [2009/09/04 11:36:10 | 00,002,381 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\zwangi125.xml

    O1 HOSTS File: (736 bytes) - C:\Windows\SysNative\drivers\etc\Hosts
    O1 - Hosts: ::1 localhost
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
    O2 - BHO: (PCCBHO.CPCCBHO) - {22FC6CE8-7D47-479F-B74A-BFBB04ADB9AF} - C:\Program Files (x86)\Winferno\PC Confidential\PCCBHO.dll (Capital Intellect Inc)
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
    O2 - BHO: (isoHunt Toolbar) - {a6e4a4eb-d169-4e99-8988-250fcbafe767} - C:\Program Files (x86)\isoHunt\tbiso0.dll (Conduit Ltd.)
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files (x86)\google\googletoolbar1.dll (Google Inc.)
    O2 - BHO: (TorrentReactor.Net Toolbar) - {b23920f4-4c2f-412b-9450-1d7028d5454e} - C:\Program Files (x86)\TorrentReactor.Net\tbTor0.dll (Conduit Ltd.)
    O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
    O2 - BHO: (Ask.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (NetAssistantBHO Class) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files (x86)\My.Freeze.com NetAssistant\NetAssistant.dll (W3i, LLC)
    O2 - BHO: (Search Assistant) - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:\Program Files\SGPSA\BHO.dll (MTWB)
    O2 - BHO: (Mininova Toolbar) - {f592709f-ff4a-4862-b659-4afabda56312} - C:\Program Files (x86)\Mininova\tbMin0.dll (Conduit Ltd.)
    O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
    O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files (x86)\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
    O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files (x86)\google\googletoolbar1.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (isoHunt Toolbar) - {a6e4a4eb-d169-4e99-8988-250fcbafe767} - C:\Program Files (x86)\isoHunt\tbiso0.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (TorrentReactor.Net Toolbar) - {b23920f4-4c2f-412b-9450-1d7028d5454e} - C:\Program Files (x86)\TorrentReactor.Net\tbTor0.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Ask.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
    O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O3 - HKLM\..\Toolbar: (Mininova Toolbar) - {f592709f-ff4a-4862-b659-4afabda56312} - C:\Program Files (x86)\Mininova\tbMin0.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files (x86)\google\googletoolbar1.dll (Google Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (isoHunt Toolbar) - {A6E4A4EB-D169-4E99-8988-250FCBAFE767} - C:\Program Files (x86)\isoHunt\tbiso0.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (TorrentReactor.Net Toolbar) - {B23920F4-4C2F-412B-9450-1D7028D5454E} - C:\Program Files (x86)\TorrentReactor.Net\tbTor0.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Ask.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
    O3 - HKCU\..\Toolbar\WebBrowser: (Mininova Toolbar) - {F592709F-FF4A-4862-B659-4AFABDA56312} - C:\Program Files (x86)\Mininova\tbMin0.dll (Conduit Ltd.)
    O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
    O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
    O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
    O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [4oD] C:\Program Files (x86)\Kontiki\KHost.exe File not found
    O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
    O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
    O4 - HKLM..\Run: [DVDAgent] C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
    O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe (Google)
    O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
    O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.)
    O4 - HKLM..\Run: [nmapp] C:\Program Files (x86)\Pure Networks\Network Magic\nmapp.exe (Cisco Systems, Inc.)
    O4 - HKLM..\Run: [nmctxth] C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
    O4 - HKLM..\Run: [Picasa Media Detector] C:\Program Files (x86)\Picasa2\PicasaMediaDetector.exe (Google Inc.)
    O4 - HKLM..\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)
    O4 - HKLM..\Run: [QPService] C:\Program Files (x86)\HP\QuickPlay\QPService.exe (CyberLink Corp.)
    O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
    O4 - HKLM..\Run: [SpySweeper] C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeperUI.exe (Webroot Software, Inc.)
    O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
    O4 - HKLM..\Run: [TSMAgent] C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
    O4 - HKLM..\Run: [UCam_Menu] C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
    O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
    O4 - HKCU..\Run: [blinkxgate] C:\Program Files (x86)\Blinkx\blinkx.exe (Blinkx Limited)
    O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
    O4 - HKCU..\Run: [FileHippo.com] C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe (FileHippo.com)
    O4 - HKCU..\Run: [HPAdvisor] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe (Hewlett-Packard)
    O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
    O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (Google Inc.)
    O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
    O4 - Startup: C:\Users\Beverly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Memeo AutoBackup Launcher.lnk = C:\Users\Beverly\AppData\Roaming\Microsoft\Installer\{39A908FD-7322-41AE-B374-C7A076B2FC97}\NewShortcut4_51A847D327C24F7797772AF2A4E486ED.exe (Macrovision Corporation)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
    O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
    O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O8 - Extra context menu item: &Search - Reg Error: Value error. File not found
    O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
    O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9:64bit: - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9:64bit: - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9 - Extra 'Tools' menuitem : PC Confidential - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files (x86)\Winferno\PC Confidential\PCConfidential.exe (Capital Intellect, Inc)
    O9 - Extra Button: PC Confidential - {925DAB62-F9AC-4221-806A-057BFB1014AA} - C:\Program Files (x86)\Winferno\PC Confidential\PCConfidential.exe (Capital Intellect, Inc)
    O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWow64\wshbth.dll (Microsoft Corporation)
    O13 - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
    O15 - HKCU\..Trusted Ranges: 1 range(s) not assigned to a zone.
    O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} http://www.facebook.com/controls/contactx.dll (ContactExtractor Class)
    O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.92.226.40 24.92.226.41
    O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
    O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
    O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
    O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\amd64\puresp4.dll (Cisco Systems, Inc.)
    O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
    O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
    O20 - AppInit_DLLs: (c:\progra~1\google\google~1\goec62~1.dll) - c:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
    O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files (x86)\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
    O30:64bit: - LSA: Authentication Packages - (ows\S) - File not found
    O30 - LSA: Authentication Packages - (ows\S) - File not found
    O30:64bit: - LSA: Security Packages - (T2㐀㠵ᘨ) - File not found
    O30:64bit: - LSA: Security Packages - (協歰⹧汤l<뻯㠵ᘨ㠵ᘨ&) - File not found
    O30:64bit: - LSA: Security Packages - (洔) - File not found
    O30:64bit: - LSA: Security Packages - () - File not found
    O30 - LSA: Security Packages - (T2㐀㠵ᘨ) - File not found
    O30 - LSA: Security Packages - (協歰⹧汤l<뻯㠵ᘨ㠵ᘨ&) - File not found
    O30 - LSA: Security Packages - (洔) - File not found
    O30 - LSA: Security Packages - () - File not found
    O31 - SafeBoot: AlternateShell - cmd.exe
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2008/04/01 13:53:24 | 00,000,071 | -H-- | M] () - F:\autorun.inf -- [ FAT32 ]
    O32 - AutoRun File - [2008/10/28 09:57:34 | 00,000,000 | ---D | M] - F:\autorun -- [ FAT32 ]
    O33 - MountPoints2\{d84e0e90-0bdf-11de-9d04-002186defa94}\Shell - " " = AutoRun
    O33 - MountPoints2\{d84e0e90-0bdf-11de-9d04-002186defa94}\Shell\AutoRun\command - " " = G:\LaunchU3.exe -- File not found
    O33 - MountPoints2\{e8356ff4-1aed-11de-8163-002186defa94}\Shell\AutoRun\command - " " = F:\wd_windows_tools\WDSetup.exe -- [2008/06/19 12:46:02 | 01,760,476 | ---- | M] (Western Digital Corporation )
    O33 - MountPoints2\{e83570f2-1aed-11de-8163-002186defa94}\Shell\AutoRun\command - " " = F:\wd_windows_tools\WDSetup.exe -- [2008/06/19 12:46:02 | 01,760,476 | ---- | M] (Western Digital Corporation )
    O33 - MountPoints2\F\Shell\AutoRun\command - " " = F:\wd_windows_tools\WDSetup.exe -- [2008/06/19 12:46:02 | 01,760,476 | ---- | M] (Western Digital Corporation )
    O34 - HKLM BootExecute: (autocheck) - File not found
    O34 - HKLM BootExecute: (autochk) - C:\Windows\SysWow64\autochk.exe (Microsoft Corporation)
    O34 - HKLM BootExecute: (*) - File not found

    ========== Files/Folders - Created Within 14 Days ==========

    [2009/09/06 22:07:12 | 00,000,000 | ---D | C] -- C:\_OTL
    [2009/09/06 22:02:12 | 00,514,048 | ---- | C] (OldTimer Tools) -- C:\Users\Beverly\Desktop\OTL.exe
    [2009/09/05 18:24:02 | 00,000,000 | ---D | C] -- C:\Users\Beverly\AppData\Roaming\Malwarebytes
    [2009/09/05 18:24:00 | 00,000,808 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2009/09/05 18:23:57 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
    [2009/09/05 18:23:55 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2009/09/05 18:23:54 | 00,022,040 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2009/09/05 18:23:54 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2009/09/05 18:11:57 | 05,067,929 | -H-- | C] () -- C:\Users\Beverly\AppData\Local\IconCache.db
    [2009/09/05 18:00:47 | 40,242,58560 | -HS- | C] () -- C:\hiberfil.sys
    [2009/09/05 03:57:14 | 00,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
    [2009/09/05 03:56:29 | 00,000,904 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2009/09/05 03:56:26 | 00,000,000 | ---D | C] -- C:\Users\Beverly\AppData\Roaming\SUPERAntiSpyware.com
    [2009/09/05 03:56:26 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\SUPERAntiSpyware
    [2009/09/05 03:54:12 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
    [2009/09/04 11:49:49 | 00,001,768 | ---- | C] () -- C:\Users\Beverly\Desktop\Update Checker.lnk
    [2009/09/04 11:49:48 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\FileHippo.com
    [2009/09/04 11:36:25 | 00,000,000 | ---D | C] -- C:\Users\Beverly\AppData\Local\Mozilla
    [2009/09/04 11:36:04 | 00,001,738 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
    [2009/09/04 11:35:58 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
    [2009/09/02 23:28:17 | 00,359,932 | ---- | C] () -- C:\Users\Beverly\Desktop\dds.pif
    [2009/09/02 22:12:32 | 00,000,000 | ---D | C] -- C:\Users\Beverly\Documents\IEFix[1]
    [2009/09/02 21:36:51 | 00,000,242 | ---- | C] () -- C:\Users\Beverly\Desktop\Dalton, Massachusetts -- Transfer Station.url
    [2009/09/02 20:59:27 | 00,000,224 | ---- | C] () -- C:\Users\Beverly\Desktop\Free Toolbar Download Big Fish Games.url
    [2009/09/01 23:20:22 | 00,000,440 | ---- | C] () -- C:\Windows\tasks\PCConfidential.job
    [2009/09/01 23:20:11 | 00,000,000 | ---D | C] -- C:\Users\Beverly\AppData\Local\Downloaded Installations
    [2009/09/01 23:20:01 | 00,835,584 | ---- | C] (Capital Intellect Inc) -- C:\Windows\SysWow64\WINCTL4.OCX
    [2009/09/01 23:20:01 | 00,495,616 | ---- | C] (Capital Intellect Inc) -- C:\Windows\SysWow64\WINUTIL5.DLL
    [2009/09/01 23:20:01 | 00,393,216 | ---- | C] (Capital Intellect Inc) -- C:\Windows\SysWow64\WINLCTL5.DLL
    [2009/09/01 23:20:01 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Winferno
    [2009/09/01 23:19:58 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Winferno
    [2009/09/01 13:45:38 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\BfgBar
    [2009/09/01 13:45:27 | 00,000,059 | ---- | C] () -- C:\Users\Beverly\AppData\Local\Tempdir
    [2009/08/31 23:44:33 | 00,001,117 | ---- | C] () -- C:\Users\Beverly\Desktop\Mahjong Garden Deluxe - Shortcut.lnk
    [2009/08/29 21:06:09 | 00,000,000 | ---D | C] -- C:\Users\Beverly\AppData\Roaming\Pogo Games
    [2009/08/29 21:05:35 | 00,001,996 | ---- | C] () -- C:\Users\Beverly\Desktop\Mahjong Garden Deluxe.lnk
    [2009/08/29 17:16:01 | 00,001,878 | ---- | C] () -- C:\Users\Public\Desktop\Mahjong Garden To Go.lnk
    [2009/08/29 17:15:59 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Pogo Games
    [2009/08/24 22:40:34 | 00,000,206 | ---- | C] () -- C:\Users\Beverly\Desktop\Latest torrents - Torrent Reactor.url

    ========== Files - Modified Within 14 Days ==========

    [2009/09/06 22:18:52 | 00,690,960 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2009/09/06 22:18:52 | 00,595,684 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2009/09/06 22:18:52 | 00,101,350 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2009/09/06 22:13:31 | 00,000,440 | ---- | M] () -- C:\Windows\tasks\PCConfidential.job
    [2009/09/06 22:13:08 | 00,000,320 | ---- | M] () -- C:\ProgramData\hpqp.ini
    [2009/09/06 22:12:59 | 00,002,537 | ---- | M] () -- C:\Users\Beverly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Memeo AutoBackup Launcher.lnk
    [2009/09/06 22:12:33 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
    [2009/09/06 22:12:29 | 00,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    [2009/09/06 22:12:29 | 00,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    [2009/09/06 22:12:19 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2009/09/06 22:12:14 | 40,242,58560 | -HS- | M] () -- C:\hiberfil.sys
    [2009/09/06 22:10:59 | 00,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
    [2009/09/06 22:10:52 | 05,067,929 | -H-- | M] () -- C:\Users\Beverly\AppData\Local\IconCache.db
    [2009/09/06 19:32:52 | 00,122,880 | ---- | M] () -- C:\Users\Beverly\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2009/09/06 19:03:26 | 00,000,422 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{B37DC7B4-48BD-4D31-8A79-2AADB5DCAF5D}.job
    [2009/09/06 00:00:00 | 00,000,398 | ---- | M] () -- C:\Windows\tasks\NeroLiveEpgUpdate-Beverly-PC_Beverly.job
    [2009/09/05 18:24:00 | 00,000,808 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2009/09/05 03:56:29 | 00,000,904 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2009/09/04 11:49:49 | 00,001,768 | ---- | M] () -- C:\Users\Beverly\Desktop\Update Checker.lnk
    [2009/09/04 11:36:04 | 00,001,738 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
    [2009/09/04 09:34:56 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Users\Beverly\Desktop\OTL.exe
    [2009/09/03 23:00:02 | 00,001,686 | ---- | M] () -- C:\Windows\tasks\wrSpySweeper_L970EB5F5FC5E400EB9CB22FE59CD6939.job
    [2009/09/02 23:28:19 | 00,359,932 | ---- | M] () -- C:\Users\Beverly\Desktop\dds.pif
    [2009/09/02 21:36:52 | 00,000,242 | ---- | M] () -- C:\Users\Beverly\Desktop\Dalton, Massachusetts -- Transfer Station.url
    [2009/09/02 20:59:27 | 00,000,224 | ---- | M] () -- C:\Users\Beverly\Desktop\Free Toolbar Download Big Fish Games.url
    [2009/09/02 19:29:01 | 00,000,342 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForBeverly.job
    [2009/09/01 22:49:23 | 00,001,460 | ---- | M] () -- C:\Users\Beverly\Desktop\DivX Movies.lnk
    [2009/09/01 13:45:27 | 00,000,059 | ---- | M] () -- C:\Users\Beverly\AppData\Local\Tempdir
    [2009/08/31 23:44:33 | 00,001,117 | ---- | M] () -- C:\Users\Beverly\Desktop\Mahjong Garden Deluxe - Shortcut.lnk
    [2009/08/31 01:01:35 | 00,001,672 | ---- | M] () -- C:\Windows\tasks\wrSpySweeper_L9B62016C024947E58767943BF8512F7A.job
    [2009/08/29 21:05:35 | 00,001,996 | ---- | M] () -- C:\Users\Beverly\Desktop\Mahjong Garden Deluxe.lnk
    [2009/08/29 21:05:35 | 00,001,102 | ---- | M] () -- C:\Users\Beverly\Desktop\Pogo Games.lnk
    [2009/08/29 17:16:01 | 00,001,878 | ---- | M] () -- C:\Users\Public\Desktop\Mahjong Garden To Go.lnk
    [2009/08/28 21:44:20 | 00,000,265 | ---- | M] () -- C:\Users\Beverly\Desktop\7-Day Forecast for Latitude 42.49°N and Longitude 73.16°W.url
    [2009/08/26 15:30:02 | 00,000,873 | ---- | M] () -- C:\Users\Beverly\Desktop\contacts - Shortcut.lnk
    [2009/08/24 22:40:34 | 00,000,206 | ---- | M] () -- C:\Users\Beverly\Desktop\Latest torrents - Torrent Reactor.url

    ========== LOP Check ==========

    [2009/09/05 18:24:02 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming
    [2009/03/07 11:24:01 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\.wyzo
    [2009/07/23 13:20:49 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\Arcsoft
    [2009/03/06 13:54:16 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\ATI
    [2009/08/27 23:23:40 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\Azureus
    [2009/03/24 23:34:50 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\Big Fish
    [2009/05/06 22:45:17 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\blinkx
    [2009/06/01 23:25:08 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\CyberLink
    [2009/06/08 23:42:44 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\EA
    [2009/06/24 00:45:48 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\ERS G-Studio
    [2009/04/19 18:44:39 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\Gaijin Ent
    [2009/06/09 20:39:21 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\GAMESHASTRA
    [2009/07/29 00:21:51 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\GRETECH
    [2009/05/03 19:50:03 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\HiT-MM
    [2009/04/03 01:05:58 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\InfraRecorder
    [2009/03/10 23:23:29 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\Laconic Software
    [2009/03/19 23:41:19 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\Lost in the City
    [2009/07/05 15:39:33 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\MahJong Suite
    [2006/11/02 11:07:25 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\Media Center Programs
    [2009/07/17 14:54:29 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\PhotoChances
    [2009/07/07 17:11:30 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\pixelStorm
    [2009/05/12 20:38:37 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\PlayFirst
    [2009/04/28 23:21:43 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\Playrix Entertainment
    [2009/08/29 21:06:09 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\Pogo Games
    [2009/05/02 00:04:47 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\Radical Software Ltd
    [2009/03/26 19:46:30 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\SerpentOfIsis
    [2009/07/24 01:26:15 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\Skinux
    [2009/04/17 18:23:03 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\Skunk Studios
    [2009/03/19 19:45:03 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\SpinTop
    [2009/05/10 21:59:44 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\Twintale Entertainment
    [2009/03/17 08:59:15 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\U3
    [2009/04/12 23:31:02 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\Ubisoft
    [2009/08/24 22:24:17 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\uTorrent
    [2009/04/16 14:38:33 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\WildTangent
    [2009/04/16 14:40:03 | 00,000,000 | ---D | M] -- C:\Users\Beverly\AppData\Roaming\WildTangentv1002
    [2009/08/20 13:28:39 | 00,000,404 | ---- | M] () -- C:\Windows\Tasks\EasyShare Registration Task.job
    [2009/09/02 19:29:01 | 00,000,342 | ---- | M] () -- C:\Windows\Tasks\HPCeeScheduleForBeverly.job
    [2009/09/06 00:00:00 | 00,000,398 | ---- | M] () -- C:\Windows\Tasks\NeroLiveEpgUpdate-Beverly-PC_Beverly.job
    [2009/09/06 22:13:31 | 00,000,440 | ---- | M] () -- C:\Windows\Tasks\PCConfidential.job
    [2009/09/06 22:12:33 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT
    [2009/09/06 22:10:59 | 00,032,558 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
    [2009/09/06 19:03:26 | 00,000,422 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{B37DC7B4-48BD-4D31-8A79-2AADB5DCAF5D}.job
    [2009/09/03 23:00:02 | 00,001,686 | ---- | M] () -- C:\Windows\Tasks\wrSpySweeper_L970EB5F5FC5E400EB9CB22FE59CD6939.job
    [2009/08/31 01:01:35 | 00,001,672 | ---- | M] () -- C:\Windows\Tasks\wrSpySweeper_L9B62016C024947E58767943BF8512F7A.job

    ========== Purity Check ==========



    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 99 bytes -> C:\ProgramData\Temp:551BED5F
    @Alternate Data Stream - 98 bytes -> C:\ProgramData\Temp:BA05E0C4
    @Alternate Data Stream - 98 bytes -> C:\ProgramData\Temp:1DEE6B65
    @Alternate Data Stream - 96 bytes -> C:\ProgramData\Temp:60A4BB64
    @Alternate Data Stream - 96 bytes -> C:\ProgramData\Temp:3FD496E1
    @Alternate Data Stream - 96 bytes -> C:\ProgramData\Temp:3D36932D
    @Alternate Data Stream - 95 bytes -> C:\ProgramData\Temp:ECCE99EF
    @Alternate Data Stream - 95 bytes -> C:\ProgramData\Temp:4F7D133D
    @Alternate Data Stream - 94 bytes -> C:\ProgramData\Temp:3991CD7D
    @Alternate Data Stream - 220 bytes -> C:\ProgramData\Temp:F5E90ED3
    @Alternate Data Stream - 219 bytes -> C:\ProgramData\Temp:48D30F15
    @Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:0AC32449
    @Alternate Data Stream - 205 bytes -> C:\ProgramData\Temp:C22674B6
    @Alternate Data Stream - 205 bytes -> C:\ProgramData\Temp:6F1F66C0
    @Alternate Data Stream - 203 bytes -> C:\ProgramData\Temp:FB97DB91
    @Alternate Data Stream - 173 bytes -> C:\ProgramData\Temp:4EFDF5FB
    @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:5D458568
    @Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:C928F3BE
    @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:4911317F
    @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:237E4B91
    @Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:5D351BC6
    @Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:47BC930A
    @Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:8944C195
    @Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:0E684AC9
    @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:A58B27C9
    @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:D92485C9
    @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:BF2E2F0E
    @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:225CD7D5
    @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:F1DEA771
    @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:69AF9D20
    @Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:375FC7E7
    @Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:97C4F81F
    @Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:132714FA
    @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:E91ADC66
    @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:D48500F8
    @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:C07A6A6B
    @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:5E9B629B
    @Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:FD000392
    @Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:CF61CE5A
    @Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:7AA6FC81
    @Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:090FB735
    @Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:E80802C7
    @Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:7B2BB690
    @Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:569CEE83
    @Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:5EF1AD34
    @Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:1C6CB897
    @Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:F437A62A
    @Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:D9FA218A
    @Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:02A78DF6
    @Alternate Data Stream - 106 bytes -> C:\ProgramData\Temp:177313FB
    @Alternate Data Stream - 106 bytes -> C:\ProgramData\Temp:08FAADE1
    @Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:55E1514E
    @Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:EE39C93C
    @Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:E3CEEC4C
    @Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:4FE42FFC
    @Alternate Data Stream - 102 bytes -> C:\ProgramData\Temp:6710EF08
    @Alternate Data Stream - 102 bytes -> C:\ProgramData\Temp:2F141B68
    @Alternate Data Stream - 101 bytes -> C:\ProgramData\Temp:3C5ABDC7
    @Alternate Data Stream - 100 bytes -> C:\ProgramData\Temp:D0668210
    < End of report >
    Scan before quick scan
     
  19. 2009/09/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Very well. Still some stuff left though...

    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      FF - prefs.js..browser.search.selectedEngine:  "MyWebSearch "
      FF - prefs.js..keyword.URL:  "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZKxdm176YYUS&fl=0&ptb=9C21RrBJEr9CAPqhtqRDNw&st=kwd&o=kwd &url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&si=39168&searchfor= "
      [2009/09/04 11:36:10 | 00,002,381 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\zwangi125.xml
      O2 - BHO: (Search Assistant) - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:\Program Files\SGPSA\BHO.dll (MTWB)
      O4 - HKLM..\Run: [4oD] C:\Program Files (x86)\Kontiki\KHost.exe File not found
      O8 - Extra context menu item: &Search - Reg Error: Value error. File not found
      
      
      :Services
      
      :Reg
      
      :Files
      
      :Commands
      [purity]
      [emptytemp]
      [Reboot]
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
     
  20. 2009/09/06
    snookie28

    snookie28 Inactive Thread Starter

    Joined:
    2002/06/28
    Messages:
    245
    Likes Received:
    0
    Internet Explorer stops working

    All processes killed
    ========== OTL ==========
    No active process named explorer.exe was found!
    Prefs.js: "MyWebSearch" removed from browser.search.selectedEngine
    Prefs.js: "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZKxdm176YYUS&fl=0&ptb=9C21RrBJEr9CAPqhtqRDNw&st=kwd&o=kwd &url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&si=39168&searchfor=" removed from keyword.URL
    C:\Program Files (x86)\mozilla firefox\searchplugins\zwangi125.xml moved successfully.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0626A63-410B-45E2-99A1-3F2475B2D695}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F0626A63-410B-45E2-99A1-3F2475B2D695}\ deleted successfully.
    C:\Program Files\SGPSA\BHO.dll unregistered successfully.
    C:\Program Files\SGPSA\BHO.dll moved successfully.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\4oD deleted successfully.
    Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Search\ deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: AppData

    User: Beverly
    File delete failed. C:\Users\Beverly\AppData\Local\Temp\ppcrlui_6044_2 scheduled to be deleted on reboot.
    ->Temp folder emptied: 302474 bytes
    File delete failed. C:\Users\Beverly\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    ->Temporary Internet Files folder emptied: 1323971 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 66802406 bytes
    ->Google Chrome cache emptied: 0 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    File delete failed. C:\Windows\temp\7bd805bc.$$$ scheduled to be deleted on reboot.
    Windows Temp folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 65.26 mb


    OTL by OldTimer - Version 3.0.10.7 log created on 09062009_231916

    Files\Folders moved on Reboot...
    C:\Users\Beverly\AppData\Local\Temp\ppcrlui_6044_2 moved successfully.
    File\Folder C:\Windows\temp\7bd805bc.$$$ not found!

    Registry entries deleted on Reboot...
     
  21. 2009/09/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Very good. I don't need new OTL log. Just hold on.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.