Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Searchnu hijack


  • This topic is locked This topic is locked
24 replies to this topic

#1 bhengr

bhengr

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 22 June 2012 - 07:13 PM

Hello,

Windows 7 laptop has searchnu/406

Try to download dds.scr but it does not respond.
Downloaded file from GMER link but the file name is fe5sotix so was not sure that this is the correct file.
Need help getting started.

running windows 7 and chrome, norton AV
spouse ran malwarebyte before I saw the problem
I removed all installed iLivid applications that were installed earlier today

Cannot manually reset the home page search hijack
Spouse somehow using malwarebytes to stop the hijack communication with the hijack site
May be mistaken but it appears that the hijack is changing the web address by changing the searchnu/406 to searchnu/407 etc...although not sure.

Help! And thanks in advance.

Bruce

BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:43 PM

Posted 23 June 2012 - 07:26 AM

Greetings and Welcome to The Forums!!

My name is Gringo and I'll be glad to help you with your computer problems.

I have put together somethings for you to keep in mind while I am helping you to make things go easier and faster for both of us

  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the Watch Topic Button, select Immediate Notification, and click on Proceed. This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of hartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.

The next thing I would like you to do is run this for me - http://download.bleepingcomputer.com/grinler/unhide.exe after it is complete restart the computer and continue with these steps

Security Check

  • Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.




Download and run OTL

Download OTL by Old Timer and save it to your Desktop.
  • Double click on OTL.exe to run it.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Under the Custom Scan box paste this in

    %TEMP%\smtmp\*.* /s

  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTL.txt <-- Will be opened and the that I need posted back here
    • Extra.txt <-- Will be minimized - save this one on your desktop in case I ask for it later
  • Please post the contents of OTListIt.txt in your next reply.


information and logs:

  • In your next post I need the following

  • .logs from OTL
  • let me know of any problems you may have had

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 bhengr

bhengr
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 23 June 2012 - 09:24 AM

Thank you Gringo!...for your help!

I also saved the extras.txt file from the OTL scan to my desktop. No problems executing any of the files. Norton did not like OTL because it said I was only one of 4 people to use it...but I ignored the warning and it processed without any issues.

I'll also mention that Chrome our primary browser. We don't use explorer.

Bruce

Here is the first log.
_______________________________________________________________
Unhide by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Unhide.exe can be found at this link:
http://www.bleepingcomputer.com/forums/topic405109.html

Program started at: 06/23/2012 09:25:52 AM
Windows Version: Windows 7

Please be patient while your files are made visible again.

Processing the C:\ drive
Finished processing the C:\ drive. 359937 files processed.

Processing the D:\ drive
Finished processing the D:\ drive. 88 files processed.

Processing the E:\ drive
Finished processing the E:\ drive. 17 files processed.

Processing the G:\ drive
Finished processing the G:\ drive. 71722 files processed.

The C:\Users\Howrey\AppData\Local\Temp\smtmp\ folder does not exist!!
Unhide cannot restore your missing shortcuts!!
Please see this topic in order to learn how to restore default
Start Menu shortcuts: http://www.bleepingcomputer.com/forums/topic405109.html

Searching for Windows Registry changes made by FakeHDD rogues.
- Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
* NoActiveDesktopChanges policy was found and deleted!
- Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced

Restarting Explorer.exe in order to apply changes.

Program finished at: 06/23/2012 09:35:33 AM
Execution time: 0 hours(s), 9 minute(s), and 40 seconds(s)
_____________________________________________________________________

Second log...

Results of screen317's Security Check version 0.99.42
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Norton Security Suite
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.61.0.1400
Java™ 6 Update 33
Java version out of Date!
Adobe Flash Player 10 Flash Player out of Date!
Adobe Reader X (10.1.2)
Google Chrome 19.0.1084.52
Google Chrome 19.0.1084.56
Google Chrome plugins...
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````
_____________________________________________________________________________________

Third log.

OTL logfile created on: 6/23/2012 10:02:18 AM - Run 1
OTL by OldTimer - Version 3.2.52.0 Folder = C:\Users\Howrey\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 2.23 Gb Available Physical Memory | 58.68% Memory free
7.61 Gb Paging File | 5.62 Gb Available in Paging File | 73.93% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.28 Gb Total Space | 293.05 Gb Free Space | 64.79% Space Free | Partition Type: NTFS
Drive D: | 13.18 Gb Total Space | 2.19 Gb Free Space | 16.63% Space Free | Partition Type: NTFS
Drive E: | 99.02 Mb Total Space | 95.10 Mb Free Space | 96.04% Space Free | Partition Type: FAT32
Drive G: | 931.28 Gb Total Space | 725.16 Gb Free Space | 77.87% Space Free | Partition Type: FAT32

Computer Name: HPLAPTOP | User Name: Howrey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Howrey\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Howrey\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Users\Howrey\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Norton Security Suite\Engine\5.2.1.3\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\pdf.dll ()
MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\libglesv2.dll ()
MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\libegl.dll ()
MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\avutil-51.dll ()
MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\avformat-54.dll ()
MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\avcodec-54.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (hpsrv) -- C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (STacSV) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (btwdins) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AESTFilters) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (Akamai) -- c:\program files (x86)\common files\akamai/netsession_win_80c2ffa.dll ()
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (HP Support Assistant Service) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (N360) -- C:\Program Files (x86)\Norton Security Suite\Engine\5.2.1.3\ccSvcHst.exe (Symantec Corporation)
SRV - (HPDrvMntSvc.exe) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (GameConsoleService) -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (AdobeActiveFileMonitor9.0) -- C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (STacSV) -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\STacSV64.exe (IDT, Inc.)
SRV - (UNS) Intel® -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (HPSLPSVC) -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (AESTFilters) -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\AESTSr64.exe (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (SymNetS) -- C:\Windows\SysNative\drivers\N360x64\0502010.003\symnets.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\N360x64\0502010.003\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\Windows\SysNative\drivers\N360x64\0502010.003\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) -- C:\Windows\SysNative\drivers\N360x64\0502010.003\symefa64.sys (Symantec Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (SymDS) -- C:\Windows\SysNative\drivers\N360x64\0502010.003\symds64.sys (Symantec Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (SymIRON) -- C:\Windows\SysNative\drivers\N360x64\0502010.003\ironx64.sys (Symantec Corporation)
DRV:64bit: - (hpdskflt) -- C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) -- C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (sscdmdm) -- C:\Windows\SysNative\drivers\sscdmdm.sys (MCCI Corporation)
DRV:64bit: - (sscdbus) SAMSUNG USB Composite Device driver (WDM) -- C:\Windows\SysNative\drivers\sscdbus.sys (MCCI Corporation)
DRV:64bit: - (sscdmdfl) -- C:\Windows\SysNative\drivers\sscdmdfl.sys (MCCI Corporation)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (Impcd) -- C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel® -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (btwrchid) -- C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (btwl2cap) -- C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (HECIx64) Intel® -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (enecir) -- C:\Windows\SysNative\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (SrvHsfV92) -- C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) -- C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (yukonw7) -- C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) Intel® -- C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (dc3d) MS Hardware Device Detection Driver (USB) -- C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (NuidFltr) -- C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (Point64) -- C:\Windows\SysNative\drivers\point64k.sys (Microsoft Corporation)
DRV:64bit: - (HpqKbFiltr) -- C:\Windows\SysNative\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (BHDrvx64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20120619.001\BHDrvx64.sys (Symantec Corporation)
DRV - (IDSVia64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20120622.001\IDSviA64.sys (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120622.033\ex64.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120622.033\eng64.sys (Symantec Corporation)
DRV - (RSUSBSTOR) -- C:\Windows\SysWOW64\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE:64bit: - HKLM\..\SearchScopes\{7BB21EAE-EF34-448F-B77A-1848EA35DEA1}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{075FEACF-D8DC-65DF-C6F1-0BB288E5787D}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms}
IE - HKLM\..\SearchScopes\{7BB21EAE-EF34-448F-B77A-1848EA35DEA1}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
IE - HKLM\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}


IE - HKU\.DEFAULT\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

IE - HKU\S-1-5-18\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

IE - HKU\S-1-5-19\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}

IE - HKU\S-1-5-20\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}

IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page =
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\URLSearchHook: {b9d63c58-90cc-428b-8d3b-cbb88eb07e7e} - No CLSID value found
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes,Backup.Old.DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes\{075FEACF-D8DC-65DF-C6F1-0BB288E5787D}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes\{2ED1569D-74DD-4966-8F7E-470F8CAD3519}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes\{7BB21EAE-EF34-448F-B77A-1848EA35DEA1}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421;<local>


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Users\Howrey\AppData\Local\HuluDesktop\instances\0.9.10.1\nphdplg.dll (Hulu LLC)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Howrey\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Howrey\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Howrey\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/02/28 17:01:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2012/02/09 08:51:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_8_3 [2012/06/23 09:39:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/02/28 17:01:28 | 000,000,000 | ---D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: NPLastPass (Enabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\1.90.7_0\nplastpass.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: CouponNetwork Coupon Activator Netscape Plugin v. 5.0.0.0 (Enabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\Application\plugins\NPcol400.dll
CHR - plugin: CouponNetwork Coupon Activator Netscape Plugin v. 5.0.0.0 (Enabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\Application\plugins\NPcol500.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Howrey\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Howrey\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Hulu Desktop (Enabled) = C:\Users\Howrey\AppData\Local\HuluDesktop\instances\0.9.10.1\nphdplg.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: LastPass = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\2.0.1_1\
CHR - Extension: Dark abstract theme = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnneafiffajmgfkidbdfpfkehpodbhkd\1.2\
CHR - Extension: Gmail = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (VideoFileDownload) - {47CEEE9C-3B9B-492C-95CA-1AC3A99D154C} - C:\Program Files (x86)\OApps\bho_project.dll (VideoFileDownload)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\5.2.1.3\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\5.2.1.3\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll File not found
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\5.2.1.3\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\Toolbar\WebBrowser: (no name) - {B9D63C58-90CC-428B-8D3B-CBB88EB07E7E} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001..\Run: [Akamai NetSession Interface] C:\Users\Howrey\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001..\Run: [SansaDispatch] C:\Users\Howrey\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Howrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Howrey\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5A0FE5B6-CA36-46A8-9038-E8049D52F1B6}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/05 13:19:36 | 000,000,052 | RHS- | M] () - G:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{3f4e5f46-52ac-11e0-b026-e169b1754ac0}\Shell - "" = AutoRun
O33 - MountPoints2\{3f4e5f46-52ac-11e0-b026-e169b1754ac0}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{9b97044a-7384-11e1-930c-002713797fe7}\Shell - "" = AutoRun
O33 - MountPoints2\{9b97044a-7384-11e1-930c-002713797fe7}\Shell\AutoRun\command - "" = G:\Setup.exe -- [2008/12/03 13:38:50 | 000,319,488 | ---- | M] (Western Digital Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/06/23 09:44:27 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Howrey\Desktop\OTL.exe
[2012/06/23 08:59:58 | 000,476,936 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\npdeployJava1.dll
[2012/06/23 08:59:58 | 000,157,448 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2012/06/23 08:59:58 | 000,149,256 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2012/06/23 08:59:58 | 000,149,256 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2012/06/22 18:27:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2012/06/22 18:27:57 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/06/22 17:45:16 | 000,000,000 | ---D | C] -- C:\Users\Howrey\.smplayer
[2012/06/22 12:47:25 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess
[2012/06/22 10:05:15 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Roaming\WinRAR
[2012/06/22 09:58:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OApps
[2012/06/22 09:57:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Funmoods
[2012/06/22 09:44:14 | 000,000,000 | ---D | C] -- C:\Users\Howrey\Documents\Graboid
[2012/06/22 09:40:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Graboid Inc
[2012/06/22 09:39:43 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\Geckofx
[2012/06/22 09:39:41 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Roaming\Mozilla
[2012/06/22 09:38:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2012/06/22 09:36:46 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\Ilivid Player
[2012/06/22 09:19:29 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2012/06/22 09:19:29 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2012/06/22 09:19:29 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2012/06/22 09:19:24 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2012/06/22 09:19:23 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2012/06/22 09:19:23 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2012/06/22 09:18:52 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2012/06/22 09:18:52 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2012/06/14 00:45:15 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/06/14 00:45:15 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/06/14 00:45:15 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/06/14 00:45:15 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/06/14 00:45:14 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/06/14 00:45:14 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/06/14 00:45:14 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012/06/14 00:45:14 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012/06/14 00:45:13 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012/06/14 00:45:13 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012/06/14 00:45:12 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012/06/14 00:45:12 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/06/14 00:45:12 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/06/13 07:37:42 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
[2012/06/13 07:37:42 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
[2012/06/13 07:37:42 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe
[2012/06/13 07:37:33 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012/06/13 07:37:31 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012/06/13 07:37:29 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012/06/13 07:37:24 | 003,216,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2012/06/13 07:37:14 | 001,462,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2012/06/13 07:37:12 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2012/06/09 16:44:21 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{7161921B-E134-4F42-838C-78CD2E18F3F8}
[2012/06/09 16:44:11 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{39F0F5EF-959A-4909-B3C9-FA179D55C4AE}
[2012/06/08 17:09:08 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{2438094A-6FEA-46EA-9610-458FB79967AE}
[2012/06/08 17:08:57 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{06F8A87F-89ED-4A47-84D8-583D000C27DC}
[2012/06/07 15:08:02 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{0CA87D3A-F05C-4CF5-846A-9521D5A6DC24}
[2012/06/07 15:07:53 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{318349E9-1145-4480-BA10-950807E8704E}
[2012/06/06 15:56:32 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{80EEDB06-D41A-43EE-8782-0A53B002305A}
[2012/06/06 15:56:22 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{4874C080-E817-42E1-80B9-E88DF549840F}
[2012/06/02 15:22:06 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{E97C3721-5FF9-40E1-B490-EA4F702861E7}
[2012/06/02 15:21:56 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{8A3672FC-3351-45C5-9314-AD5C4B1FC213}
[2012/06/02 15:21:05 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{6B0E3FCC-D57A-49F5-81C1-40F6989CFACB}
[2012/06/02 15:20:55 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{7956B238-2E02-4498-A91B-2F2497E99C08}
[2012/06/02 15:04:06 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{88A9A8A3-5CDA-475D-8D13-4475350D206F}
[2012/06/02 15:03:56 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{855BA2E5-E957-4B46-9E58-E9C70CD8B7FB}
[2012/06/02 00:19:11 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{E05278C2-D8B4-40A6-8AC6-3C95125BD8DE}
[2012/06/02 00:19:02 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{467C06D0-D0D3-4167-93AF-AE18CBB2D4CD}
[2012/06/02 00:17:23 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{06D2E959-E7DC-4549-A723-2AFB4F5CA7C3}
[2012/06/02 00:17:13 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{BCFEA152-108B-4817-ADE6-12A053F5FB75}
[2012/06/02 00:15:53 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{0A72795D-FDD2-4B97-8F3B-4FF1EAFEEE4A}
[2012/06/02 00:15:43 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{50F3C703-4157-4575-A455-353001D197CA}
[2012/06/02 00:13:28 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{128F3A0A-5761-4603-946A-5CB59661AA35}
[2012/06/02 00:13:17 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{246AA358-6B3D-4340-866F-0F0BAA196A4F}
[2012/06/02 00:12:41 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{43D49908-24D6-4607-B0BB-C1AB1B66305C}
[2012/06/02 00:12:31 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{33966D57-DDB4-4F76-987B-CDE6B4B72C4E}
[2012/06/02 00:10:53 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{00E333B2-F64B-4B99-B087-6DDE2AF6F234}
[2012/06/02 00:10:44 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{396E069C-C712-4882-8444-22D7084A720F}
[2012/06/02 00:06:40 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{BFD4B609-6280-4EEF-A40C-6B1CECF03766}
[2012/06/02 00:02:40 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{2B83F3A6-C108-4BF0-98C6-3DB6AB1A1C10}
[2012/06/02 00:02:31 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{AD1E1EE0-1669-4FD4-AAA9-4B98FE6DD7AE}
[2012/06/02 00:01:11 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CC2B5BAF-084E-4FA9-AF45-BD5611E873B8}
[2012/06/02 00:01:01 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{EE0FE2F1-C34C-46C9-A82E-9D49C1C3DFF6}
[2012/06/01 23:57:46 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{B2921A07-F898-4885-88D4-E3B1DC5FA5D1}
[2012/06/01 23:57:36 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{FB1D0259-E889-4395-9D83-1D3D1F1F925B}
[2012/06/01 23:56:27 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{765DC91A-49DD-41C2-AD34-B62CD06B8821}
[2012/06/01 23:56:18 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{A11F5125-7D88-4AEF-87E5-C08783254DE9}
[2012/06/01 23:54:53 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{9D8E45F5-EE6B-49FF-A1F5-9EEBA412337D}
[2012/06/01 23:54:43 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{185E98E5-F98F-43ED-89A4-55CFA1607935}
[2012/06/01 23:53:50 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{351ECD31-E34F-45F0-BB01-2355813429B2}
[2012/06/01 23:53:40 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{DBFF1E3D-F772-411E-9049-E27F77BECFC9}
[2012/06/01 23:52:34 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{EFABBB2C-902C-4015-9638-F47BF7ECB81F}
[2012/06/01 23:52:24 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{63B59240-9BBA-48EF-9394-CE2AF40E5365}
[2012/06/01 23:51:37 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{71F1B644-0856-4B75-9E9F-7DA7D9385302}
[2012/06/01 23:51:27 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{A46CF1F9-B680-4C1D-B925-E9012656FA1B}
[2012/06/01 23:49:36 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{783A2979-D81E-47FF-BAC7-9130E15C1344}
[2012/06/01 23:49:26 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{71D27975-0B7A-47EE-85E7-07EA11B9BB8C}
[2012/06/01 23:47:23 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{E49F753D-C54E-421F-8D69-7DA3F7C3EA17}
[2012/06/01 23:47:14 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{79E8C0FE-7735-4AFF-82F9-373B278D5C93}
[2012/06/01 23:45:11 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{0EEBEEF5-E75B-45C3-87EC-DFFD6FEA710B}
[2012/06/01 23:45:01 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{87F52C3F-FC74-4670-B38D-53FC13F932F6}
[2012/06/01 23:40:37 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{559DBC3C-17FA-4204-91F0-225AA0F6FEBD}
[2012/06/01 23:40:28 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{37FE6526-E9C4-4F26-ACBA-58730A1BD490}
[2012/06/01 23:39:16 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{1108206B-31D2-4F48-A2EC-73E786FBD9FB}
[2012/06/01 23:39:06 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{A0E687B3-0B03-4D3D-BA18-9438DD2796E7}
[2012/06/01 23:38:13 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{3E4316E5-767A-4342-9794-48B7F32802A0}
[2012/06/01 23:38:03 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{54E6C4A1-8C69-4E02-8203-BBCDFD5329C9}
[2012/06/01 23:36:54 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{62886716-4F19-4E0C-976F-8F9682A49133}
[2012/06/01 23:36:44 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{B248F0FE-1058-44DB-ADD5-EFBFEDE52F46}
[2012/06/01 23:35:37 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{DA63DE8B-8D7A-4BC3-833D-5E6C64725122}
[2012/06/01 23:35:27 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{E8C73FAC-10DF-4ABF-BDFD-84DBEFC5DD5E}
[2012/06/01 23:34:39 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{2E72A5C1-4724-4704-B045-AD8A96FA4CAD}
[2012/06/01 23:34:30 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{977A46E4-C5F8-4990-B1A9-73F447043032}
[2012/06/01 23:22:48 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{6D51B7E7-7B99-4368-8672-D69996938BB8}
[2012/06/01 23:22:38 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{C3542E71-5118-4FB6-AB36-DE12CA6A873A}
[2012/06/01 23:21:12 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{28A51427-04A3-4C78-8F5D-AD11BAB9DDBE}
[2012/06/01 23:21:01 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{33113385-164C-4DFC-9988-15B7C2F1F2C4}
[2012/06/01 23:12:49 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{26046AB9-FF03-474B-9A05-858A19B62811}
[2012/06/01 23:12:39 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{D49436C9-D7DC-427D-813D-C00915270330}
[2012/06/01 23:06:39 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{441C7DAF-3116-44AB-81F9-D205BDF1EB3A}
[2012/06/01 23:06:30 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{3C2ECA86-FD5D-4316-9B8D-DE254B890F1E}
[2012/06/01 23:01:28 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{D7092C62-7EA5-425E-BA35-75C8510D97A1}
[2012/06/01 23:01:18 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{F74FC52E-4A96-45D3-9E89-18379F37637A}
[2012/06/01 22:51:02 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{FACBF969-27EB-42E9-A295-4398088E208D}
[2012/06/01 22:50:52 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{405C55EA-6F05-455A-AC4D-820C9209543E}
[2012/06/01 22:45:13 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{72336468-483D-43DF-A47A-3883BDD4CBEA}
[2012/06/01 22:45:03 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{927981E1-3B5B-4EBA-83B2-4FF3DF0C328F}
[2012/06/01 22:42:15 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{31140646-9892-4741-AA8C-3E7DA1582E0B}
[2012/06/01 22:42:05 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{9ADC7A3B-BD08-4CA0-9019-C930AC1921FF}
[2012/06/01 22:41:07 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{65640219-474C-4C03-B300-5FCFD1CDF057}
[2012/06/01 22:40:57 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{EAF4EC56-8647-4D77-8025-A421B2C34286}
[2012/06/01 22:36:05 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{013CDEB2-563E-42E6-A0BF-219971FE5FD1}
[2012/06/01 22:35:17 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{345663BC-0575-45C6-8CE4-C9B37F7AD439}
[2012/06/01 22:35:07 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{E2450831-997C-4755-8675-CD225964A86C}
[2012/06/01 22:29:52 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{F44412F6-A054-4051-8BED-2833569D7C69}
[2012/06/01 22:29:43 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CD84CEC2-F9E8-4896-8BCA-9D0D2EA406FD}
[2012/06/01 22:29:06 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{21C028BF-8007-4138-B8DA-23EE4606D1BD}
[2012/06/01 22:28:56 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{08EF5330-0A89-472A-BECC-960B38933301}
[2012/06/01 22:27:26 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{B42CE132-E0B7-4A1B-8719-95FDA307F0A0}
[2012/06/01 22:27:16 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{C71511C1-670C-48B9-9095-6E6489010967}
[2012/06/01 22:25:33 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CBC0865F-B69A-48F3-B312-DEB50C4C2774}
[2012/06/01 22:25:23 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{67A6A02F-D620-4D9E-A1CD-3F069F0801C8}
[2012/06/01 22:18:56 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{B3D68521-820F-4C94-B8A1-078BAE046074}
[2012/06/01 22:18:46 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{208B5E37-C61F-4D1A-9FF3-2511D1B108C5}
[2012/06/01 22:18:01 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{BEA83B68-4EC0-4E1A-B025-138E44C44966}
[2012/06/01 22:17:51 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{13D25BB9-50B5-4E7A-BCE3-3FEA9FBC727B}
[2012/06/01 22:17:11 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{7760770C-D9FE-466D-9CC7-5CA0D996CEC5}
[2012/06/01 22:17:02 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{F9474BBB-1D56-4733-B6A6-31E2B00ED7CF}
[2012/06/01 22:14:50 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{B1B8AEBA-4BCB-428D-ADEB-59AF952D78F8}
[2012/06/01 22:14:40 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CC834C0E-E60C-4DDE-B7CE-D5D96D6D097A}
[2012/06/01 22:14:07 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{594BB9E8-2533-4AFA-BB0D-0FBA4FD46F9B}
[2012/06/01 22:13:57 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{433B905D-67AD-4F2A-9B77-328C95BFC6D6}
[2012/06/01 22:05:34 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CB288644-2CB4-40C9-B8D8-6E0B08E7F08A}
[2012/06/01 22:05:24 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{981D0EB7-DB68-4E5E-9B2A-9D7AE7F0A1E9}
[2012/06/01 22:04:16 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{27175B23-F97C-45FB-975F-316D3AF3D026}
[2012/06/01 22:04:06 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{B48E80D5-79BB-4DC6-98F0-8B8A3A9CEF61}
[2012/06/01 22:02:59 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{A7744EBE-3DCE-4A5E-8407-69ADBAE700A7}
[2012/06/01 22:02:49 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{F22F339F-6DFC-46BA-BCCE-C741B736C5EC}
[2012/06/01 22:01:23 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{DA39BFF3-4CA0-4144-98E0-4A551186BF9D}
[2012/06/01 22:01:13 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{0E836EAC-4682-4EAA-B934-1DA5321C0176}
[2012/06/01 22:00:11 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{7FAEB349-9805-4843-A2F8-90C4BC5B7FE4}
[2012/06/01 22:00:01 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{2B1A99E7-F104-4010-A4D2-BE7694EB7D91}
[2012/06/01 21:52:47 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{766B5072-934D-48FD-AB51-17B927E71C8B}
[2012/06/01 21:52:37 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{178B1B57-5843-436E-84BF-7F3AA54A727A}
[2012/06/01 21:52:05 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{499C7466-D42C-4CBB-BD2F-4A8FEE387F22}
[2012/06/01 21:51:55 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{C85CFA3D-890B-41D2-9035-5CEFA1963E9D}
[2012/06/01 21:47:04 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{C3D9A315-643E-40EC-ACB3-C24A00D401B9}
[2012/06/01 21:46:54 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{226987AD-EB15-4B3E-A2D2-28FD986D0ED2}
[2012/06/01 21:41:08 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{470074D6-C27D-4B8A-8BA2-E9E64136660D}
[2012/06/01 21:40:58 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CBE06949-2DA0-440E-8DA3-41DA4536DABB}
[2012/06/01 21:39:54 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{403635F0-9B21-421A-AAD5-CF0F5A231DEE}
[2012/06/01 21:39:44 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{8B46E9F4-5A27-4073-B3ED-5EA70AC00E13}
[2012/06/01 21:38:11 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{A39F7072-3A6A-42A6-9EA4-D059AD55BA8D}
[2012/06/01 21:38:01 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CA051F50-9E22-4B01-B09D-F77A388E6312}
[2012/06/01 21:37:01 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{0E3A2D10-FEBE-413A-A912-415DE9F4D029}
[2012/06/01 21:36:52 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CDA73F08-B006-4DC4-A799-EBDF55726C1B}
[2012/06/01 21:29:46 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{9C622B84-4DF3-43B3-AF47-72C076FAE63B}
[2012/06/01 21:29:36 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{3951AFBA-91AD-4C41-AADE-784AC5F7358A}
[2012/06/01 21:26:14 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{59147FE9-66EF-4B74-AC2E-D05DD29BB232}
[2012/06/01 21:26:04 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{C32BCB87-6E33-43B9-A498-6FAC27849CD8}
[2012/06/01 21:25:46 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{6F563883-F340-42B2-8131-1F1CC98655B6}
[2012/06/01 21:25:36 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CC67EC58-A3B7-416A-BEDF-E226A9D3A0F7}
[2012/05/30 21:01:27 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{F7CBA22F-BA5E-4372-B7B6-74D52AA22350}
[2012/05/30 21:01:16 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{0D89A84A-7744-4C21-B46F-892C7D39832E}
[2012/05/25 22:05:47 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{6D44BB68-ADCD-4525-9B37-E65BD23283FE}
[2012/05/25 22:05:38 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{C77D9BEB-9ED3-4554-B056-664EF3D5860D}
[2012/05/25 22:04:40 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{11A67BDF-B381-4A16-BFB1-8547A0F5895C}
[2012/05/25 22:04:30 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{DB96A8CD-5624-4358-A662-C67CE0E2B1AD}
[2012/05/25 22:03:37 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{168A5B6E-0D4B-4AB4-9FE4-F5A80D91994A}
[2012/05/25 22:03:27 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{F6D5F874-A52D-42B6-908A-880D74C9A5BD}
[2012/05/25 21:08:31 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{A936EF10-7907-44CF-B342-3366680F2A96}
[2012/05/25 21:08:21 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{D1D50919-125B-4C1E-96EE-90D9740F14DC}
[2012/05/25 19:49:39 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CDC3456D-C070-4827-84AC-20F9C8787585}
[2012/05/25 19:49:28 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{3665C28A-557F-450A-8490-B07F55CCEEDA}
[2012/05/24 20:36:40 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{8CE87806-FBC3-4FB3-B98F-8B84C493EB71}
[2012/05/24 20:36:30 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{E008792D-E256-43CB-8B08-613500CA07A3}
[2012/05/24 20:20:15 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{7A82DFC9-7355-4311-BE26-5E3E4370411E}
[2012/05/24 20:20:05 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{5F49C945-D44D-4A06-9315-D445EEE10592}
[2012/05/24 20:07:06 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{F5C96590-FFA0-41B0-B4DA-B2D8456D29DD}
[2012/05/24 20:06:56 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{61BD5F23-B994-4309-AE87-521F29B0A615}
[16 C:\Users\Howrey\Documents\*.tmp files -> C:\Users\Howrey\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/06/23 09:46:24 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/23 09:46:24 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/23 09:44:28 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Howrey\Desktop\OTL.exe
[2012/06/23 09:43:31 | 000,881,475 | ---- | M] () -- C:\Users\Howrey\Desktop\SecurityCheck.exe
[2012/06/23 09:38:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/23 09:38:34 | 3063,046,144 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/23 09:15:32 | 000,738,832 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/23 09:15:32 | 000,632,696 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/06/23 09:15:32 | 000,110,644 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/06/23 09:10:01 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3097100386-4279238605-4106125582-1001UA.job
[2012/06/23 08:59:47 | 000,476,936 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\npdeployJava1.dll
[2012/06/23 08:59:47 | 000,472,840 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll
[2012/06/23 08:59:47 | 000,157,448 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2012/06/23 08:59:47 | 000,149,256 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2012/06/23 08:59:47 | 000,149,256 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2012/06/22 19:33:04 | 000,000,000 | ---- | M] () -- C:\Users\Howrey\defogger_reenable
[2012/06/22 19:10:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3097100386-4279238605-4106125582-1001Core.job
[2012/06/22 18:27:57 | 000,002,981 | ---- | M] () -- C:\Users\Howrey\Desktop\HiJackThis.lnk
[2012/06/22 10:47:09 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/22 09:57:15 | 000,302,425 | ---- | M] () -- C:\Users\Howrey\AppData\Local\funmoods-speeddial.crx
[2012/06/22 09:57:15 | 000,031,470 | ---- | M] () -- C:\Users\Howrey\AppData\Local\funmoods.crx
[2012/06/20 13:51:41 | 000,001,296 | ---- | M] () -- C:\Users\Howrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2012/06/14 20:04:08 | 000,438,520 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/10 18:08:06 | 000,001,050 | ---- | M] () -- C:\Users\Howrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/06/10 18:07:59 | 000,001,020 | ---- | M] () -- C:\Users\Howrey\Desktop\Dropbox.lnk
[2012/06/10 18:05:33 | 000,000,336 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForHowrey.job
[2012/06/02 18:19:46 | 000,038,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2012/06/02 18:19:42 | 000,057,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2012/06/02 18:19:42 | 000,044,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2012/06/02 18:19:23 | 000,701,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2012/06/02 18:15:31 | 002,622,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2012/06/02 18:15:08 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2012/06/02 15:19:42 | 000,186,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2012/06/02 15:15:12 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[16 C:\Users\Howrey\Documents\*.tmp files -> C:\Users\Howrey\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/06/23 09:43:30 | 000,881,475 | ---- | C] () -- C:\Users\Howrey\Desktop\SecurityCheck.exe
[2012/06/22 19:33:04 | 000,000,000 | ---- | C] () -- C:\Users\Howrey\defogger_reenable
[2012/06/22 18:27:57 | 000,002,981 | ---- | C] () -- C:\Users\Howrey\Desktop\HiJackThis.lnk
[2012/06/22 10:47:09 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/22 09:57:53 | 000,302,425 | ---- | C] () -- C:\Users\Howrey\AppData\Local\funmoods-speeddial.crx
[2012/06/22 09:57:38 | 000,031,470 | ---- | C] () -- C:\Users\Howrey\AppData\Local\funmoods.crx
[2012/03/05 13:28:23 | 003,693,389 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0230.JPG
[2011/05/12 15:02:40 | 000,001,940 | ---- | C] () -- C:\Users\Howrey\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/03/19 21:18:11 | 000,001,854 | ---- | C] () -- C:\Users\Howrey\AppData\Roaming\GhostObjGAFix.xml
[2011/02/03 14:34:12 | 000,000,164 | ---- | C] () -- C:\Windows\SysWow64\psconv.ini
[2010/12/13 10:09:36 | 000,430,996 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0273_CROPQUAD.JPG
[2010/12/12 15:07:07 | 003,164,285 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0033_(2).JPG
[2010/12/12 15:04:48 | 000,005,149 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmp41262_419810891719_546171719_5336847_5651237_N_CROP.JPG
[2010/12/12 15:04:48 | 000,005,110 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmp41262_419810891719_546171719_5336847_5651237_N_CROP.0
[2010/12/12 15:03:51 | 000,108,963 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmp41262_419810891719_546171719_5336847_5651237_N.JPG
[2010/12/12 15:02:32 | 000,034,645 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpCHRISTAMS PIC '10.JPG
[2010/11/26 18:16:24 | 000,000,218 | ---- | C] () -- C:\Users\Howrey\.recently-used.xbel
[2010/11/26 18:12:45 | 000,003,683 | ---- | C] () -- C:\Users\Howrey\Budget.20101126171245.xac
[2010/11/26 18:12:40 | 000,003,579 | ---- | C] () -- C:\Users\Howrey\Budget.20101126171240.xac
[2010/11/26 18:12:17 | 000,003,683 | ---- | C] () -- C:\Users\Howrey\Budget
[2010/10/26 10:07:46 | 000,455,429 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDZIESUPEK BID 2.JPG
[2010/10/26 10:07:46 | 000,451,841 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDZIESUPEK BID 2.0
[2010/10/15 14:27:34 | 000,555,770 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpVOGEL BID.1
[2010/10/15 14:27:32 | 000,574,287 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpVOGEL BID.JPG
[2010/10/15 14:27:32 | 000,547,544 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpVOGEL BID.0
[2010/10/06 08:10:21 | 000,007,606 | ---- | C] () -- C:\Users\Howrey\AppData\Local\Resmon.ResmonCfg
[2010/08/23 09:15:37 | 000,070,428 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0313_(2)_CROP_CROP.JPG
[2010/08/23 09:14:08 | 000,689,140 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0271.JPG
[2010/08/23 09:14:07 | 002,895,247 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0271.0
[2010/08/23 09:07:38 | 000,849,520 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0175.JPG
[2010/08/23 09:07:37 | 002,912,294 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0175.0
[2010/08/23 09:01:10 | 002,481,702 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0073.JPG
[2010/05/10 17:57:20 | 000,070,192 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC05465_CROP.JPG
[2010/05/10 17:57:19 | 000,068,948 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC05465_CROP.0
[2010/04/20 18:29:58 | 000,677,465 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpAUSTIN BID.JPG
[2010/04/20 18:29:58 | 000,661,013 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpAUSTIN BID.0
[2010/04/19 10:24:57 | 000,885,132 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0468_(1).JPG
[2010/04/19 10:24:56 | 003,181,173 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0468_(1).0
[2010/04/19 10:21:46 | 000,082,895 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0313_(2)_CROP.JPG
[2010/04/19 10:20:46 | 001,963,113 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0313_(2).JPG
[2010/04/19 10:18:36 | 002,888,900 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0269.JPG
[2010/04/19 10:17:02 | 000,901,025 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0259_(2)_CROP.JPG
[2010/04/19 10:15:55 | 001,131,357 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0259_(2).JPG
[2010/04/19 10:14:25 | 003,558,841 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0256.JPG
[2010/04/19 10:10:23 | 000,434,424 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0273_CROPCROP.JPG
[2010/04/19 10:08:15 | 003,057,466 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0273.JPG
[2010/04/19 10:05:30 | 003,114,140 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0236_(1).JPG
[2010/04/19 09:59:54 | 001,157,709 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0922_(1)_CROP.JPG
[2010/04/19 09:58:35 | 003,053,282 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0921_(1).JPG
[2010/04/19 09:55:09 | 003,075,642 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0922_(1).JPG
[2010/04/19 09:36:47 | 003,240,895 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0274.JPG
[2010/04/19 09:36:47 | 003,240,895 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0274.0
[2010/04/18 21:32:29 | 000,822,933 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0286.JPG
[2010/04/18 21:32:28 | 002,928,770 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0286.0
[2010/04/18 21:11:17 | 000,811,146 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0104_(2).JPG
[2010/04/18 21:11:16 | 002,952,002 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0104_(2).0
[2010/03/28 21:31:54 | 000,000,099 | ---- | C] () -- C:\Users\Howrey\jagex_runescape_preferences2.dat
[2010/03/28 21:31:54 | 000,000,000 | ---- | C] () -- C:\Users\Howrey\jagex__preferences3.dat
[2010/03/28 21:30:43 | 000,000,046 | ---- | C] () -- C:\Users\Howrey\jagex_runescape_preferences.dat
[2010/02/12 23:11:56 | 000,004,674 | ---- | C] () -- C:\Users\Howrey\AppData\Roaming\wklnhst.dat

========== Custom Scans ==========

< %TEMP%\smtmp\*.* /s >

< End of report >

#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:43 PM

Posted 23 June 2012 - 11:25 AM

Hello

I Would like you to do the following.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links. I want you to save it to the desktop and run it from there.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#5 bhengr

bhengr
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 23 June 2012 - 07:18 PM

Hello Gringo,

Combofix ran without any issues. I did have to uninstall Norton to shut it down. I'll reinstall after this post.

Opened Chrome and the searchnu/406 hijack is still there. Tried to manually change it but was unable.

Here is the combofix log.

Bruce


ComboFix 12-06-23.05 - Howrey 06/23/2012 19:53:23.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3895.2662 [GMT -4:00]
Running from: c:\users\Howrey\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Howrey\AppData\Roaming\.#
c:\users\Howrey\Documents\~WRL0005.tmp
c:\users\Howrey\Documents\~WRL0006.tmp
c:\users\Howrey\Documents\~WRL0592.tmp
c:\users\Howrey\Documents\~WRL0755.tmp
c:\users\Howrey\Documents\~WRL1019.tmp
c:\users\Howrey\Documents\~WRL1458.tmp
c:\users\Howrey\Documents\~WRL1526.tmp
c:\users\Howrey\Documents\~WRL1972.tmp
c:\users\Howrey\Documents\~WRL2144.tmp
c:\users\Howrey\Documents\~WRL2361.tmp
c:\users\Howrey\Documents\~WRL2667.tmp
c:\users\Howrey\Documents\~WRL2783.tmp
c:\users\Howrey\Documents\~WRL2808.tmp
c:\users\Howrey\Documents\~WRL2885.tmp
c:\users\Howrey\Documents\~WRL2958.tmp
c:\users\Howrey\Documents\~WRL3224.tmp
c:\users\Public\videos\HP MediaSmart Demo.exe
c:\windows\SysWow64\Ir50_qc.1
c:\windows\SysWow64\Ir50_qcx.1
.
.
((((((((((((((((((((((((( Files Created from 2012-05-24 to 2012-06-24 )))))))))))))))))))))))))))))))
.
.
2012-06-24 00:00 . 2012-06-24 00:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-24 00:00 . 2012-06-24 00:00 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-06-23 12:59 . 2012-06-23 12:59 476936 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-06-22 22:27 . 2012-06-22 22:27 388096 ----a-r- c:\users\Howrey\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-06-22 22:27 . 2012-06-22 22:27 -------- d-----w- c:\program files (x86)\Trend Micro
2012-06-22 21:45 . 2012-06-22 21:45 -------- d-----w- c:\users\Howrey\.smplayer
2012-06-22 16:47 . 2012-06-22 16:47 -------- d-----w- c:\programdata\boost_interprocess
2012-06-22 13:58 . 2012-06-22 16:42 -------- d-----w- c:\program files (x86)\OApps
2012-06-22 13:57 . 2012-06-22 13:57 -------- d-----w- c:\program files (x86)\Funmoods
2012-06-22 13:40 . 2012-06-22 13:40 -------- d-----w- c:\programdata\Graboid Inc
2012-06-22 13:39 . 2012-06-22 13:39 -------- d-----w- c:\users\Howrey\AppData\Local\Geckofx
2012-06-22 13:38 . 2012-06-22 13:38 -------- d-----w- c:\program files (x86)\VideoLAN
2012-06-22 13:36 . 2012-06-22 13:36 -------- d-----w- c:\users\Howrey\AppData\Local\Ilivid Player
2012-06-22 13:19 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-22 13:19 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-22 13:19 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-22 13:19 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-22 13:19 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-22 13:19 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-22 13:19 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-22 13:18 . 2012-06-02 19:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-22 13:18 . 2012-06-02 19:15 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-06-13 11:37 . 2012-04-26 05:41 77312 ----a-w- c:\windows\system32\rdpwsx.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-23 12:59 . 2010-05-20 01:27 472840 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-04-17 14:27 . 2010-02-13 18:06 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2012-04-17 14:27 . 2010-04-12 00:33 4283672 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2012-04-17 14:27 . 2012-03-05 17:39 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2012-04-04 19:56 . 2010-02-13 20:02 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-30 11:35 . 2012-05-09 11:22 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{47CEEE9C-3B9B-492C-95CA-1AC3A99D154C}]
2012-06-20 01:01 92160 ----a-w- c:\program files (x86)\OApps\bho_project.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Howrey\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Howrey\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Howrey\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-06-16 2736128]
"HPADVISOR"="c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-09-29 1685048]
"Akamai NetSession Interface"="c:\users\Howrey\AppData\Local\Akamai\netsession_win.exe" [2012-05-26 4327744]
"SansaDispatch"="c:\users\Howrey\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe" [2012-03-10 79872]
"MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HPCam_Menu"="c:\program files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-11-24 323640]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2010-03-23 500792]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\users\Howrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Howrey\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-9-4 1081632]
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-23 270336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-09 86072]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x]
R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64k.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-02 225280]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\AESTSr64.exe [2009-03-03 89600]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-10-01 2320920]
S3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [x]
S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-06-16 17:38 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3097100386-4279238605-4106125582-1001Core.job
- c:\users\Howrey\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-12 03:58]
.
2012-06-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3097100386-4279238605-4106125582-1001UA.job
- c:\users\Howrey\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-12 03:58]
.
2012-06-10 c:\windows\Tasks\HPCeeScheduleForHowrey.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 03:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Howrey\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Howrey\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Howrey\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Howrey\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-10-24 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-10-24 390168]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-10-24 408600]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2009-08-25 610872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-10 171520]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-05-21 2342800]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-05-26 2314120]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-07-29 497648]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-10-21 487424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.funmoods.com/?f=1&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://start.funmoods.com/?f=1&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421;<local>
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e} - (no file)
Toolbar-10 - (no file)
Toolbar-10 - (no file)
WebBrowser-{B9D63C58-90CC-428B-8D3B-CBB88EB07E7E} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_80c2ffa.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-06-23 20:02:03
ComboFix-quarantined-files.txt 2012-06-24 00:02
.
Pre-Run: 314,813,124,608 bytes free
Post-Run: 314,662,944,768 bytes free
.
- - End Of File - - 6741722931FF89FB928DC02457412F99

#6 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:43 PM

Posted 23 June 2012 - 08:36 PM

Hello

Lets get a deeper look into the system and see if something shows up.

Download and run OTL

Download OTL by Old Timer and save it to your Desktop.
  • Double click on OTL.exe to run it.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTL.txt <-- Will be opened and the that I need posted back here
    • Extra.txt <-- Will be minimized - save this one on your desktop in case I ask for it later
  • Please post the contents of OTL.txt in your next reply.

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#7 bhengr

bhengr
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 23 June 2012 - 09:09 PM

Hello Gringo,

Reinstalled norton. Had to re download software from Xfinity. They forced use of "constant guard". So it is on the computer now.

Then ran OTL. It ran with no issues. Here is the log.
Bruce

OTL logfile created on: 6/23/2012 9:51:48 PM - Run 2
OTL by OldTimer - Version 3.2.52.0 Folder = C:\Users\Howrey\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 1.57 Gb Available Physical Memory | 41.26% Memory free
7.61 Gb Paging File | 5.20 Gb Available in Paging File | 68.39% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.28 Gb Total Space | 292.32 Gb Free Space | 64.63% Space Free | Partition Type: NTFS
Drive D: | 13.18 Gb Total Space | 2.19 Gb Free Space | 16.63% Space Free | Partition Type: NTFS
Drive E: | 99.02 Mb Total Space | 95.10 Mb Free Space | 96.04% Space Free | Partition Type: FAT32

Computer Name: HPLAPTOP | User Name: Howrey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Public\Downloads\Norton\{3A7FA539-8005-4603-87D2-SOS1-NSSv6}\Norton_Download_Manager[1].exe (Symantec Corporation)
PRC - C:\Users\Howrey\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Constant Guard Protection Suite\IDVaultSvc.exe (White Sky, Inc.)
PRC - C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe (White Sky, Inc.)
PRC - C:\Users\Howrey\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Users\Howrey\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Norton Security Suite\Engine\6.0.0.145\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\SFT\GuardedID\GIDD.exe (StrikeForce Technologies Inc.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\f2f8201dd3453250dfd9ed1afce630a0\WindowsFormsIntegration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\e3e5aa45736b95804bf6bb7eca08a57b\System.WorkflowServices.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\761fd1afc17f11bf6d49c3a7d16465ca\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll ()
MOD - C:\Program Files (x86)\Constant Guard Protection Suite\IdVaultCore.XmlSerializers.dll ()
MOD - C:\Program Files (x86)\Constant Guard Protection Suite\sqlite3.dll ()
MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\pdf.dll ()
MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\libglesv2.dll ()
MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\libegl.dll ()
MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\avutil-51.dll ()
MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\avformat-54.dll ()
MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\avcodec-54.dll ()
MOD - C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\gcswf32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\ed560b26f2f86b3f07b7f6d384f92275\System.ServiceModel.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\626d0ac2f4ada682d7ca6c4ebf821469\CustomMarshalers.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\2ce8210219c7123610072357358df470\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\72a24b45e11d64eb2bc840aae9419ba5\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\107779ca2708d2b31b2e1560e47f6d15\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\9e7bf69d97febe4ed1a288c787e5d9ca\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\80fae9f16f80075535e72458ef293f7a\System.Transactions.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ca2eff60beb3ba00a529a2d42dceca22\UIAutomationProvider.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2ec98ab0193d64e95b7d09d094deed97\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\054fcff18035c210487b0888e6461192\System.Security.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll ()
MOD - C:\Windows\SysWOW64\EasyHook32.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (hpsrv) -- C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (STacSV) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (btwdins) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AESTFilters) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (IDVaultSvc) -- C:\Program Files (x86)\Constant Guard Protection Suite\IDVaultSvc.exe (White Sky, Inc.)
SRV - (Akamai) -- c:\program files (x86)\common files\akamai/netsession_win_80c2ffa.dll ()
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (N360) -- C:\Program Files (x86)\Norton Security Suite\Engine\6.0.0.145\ccSvcHst.exe (Symantec Corporation)
SRV - (HP Support Assistant Service) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (HPDrvMntSvc.exe) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (GameConsoleService) -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (AdobeActiveFileMonitor9.0) -- C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (STacSV) -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\STacSV64.exe (IDT, Inc.)
SRV - (UNS) Intel® -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (HPSLPSVC) -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (AESTFilters) -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\AESTSr64.exe (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (SymEFA) -- C:\Windows\SysNative\drivers\N360x64\0600000.091\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\N360x64\0600000.091\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\Windows\SysNative\drivers\N360x64\0600000.091\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) -- C:\Windows\SysNative\drivers\N360x64\0600000.091\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) -- C:\Windows\SysNative\drivers\N360x64\0600000.091\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (ccSet_N360) -- C:\Windows\SysNative\drivers\N360x64\0600000.091\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) -- C:\Windows\SysNative\drivers\N360x64\0600000.091\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (GIDv2) -- C:\Windows\SysNative\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (hpdskflt) -- C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) -- C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (sscdmdm) -- C:\Windows\SysNative\drivers\sscdmdm.sys (MCCI Corporation)
DRV:64bit: - (sscdbus) SAMSUNG USB Composite Device driver (WDM) -- C:\Windows\SysNative\drivers\sscdbus.sys (MCCI Corporation)
DRV:64bit: - (sscdmdfl) -- C:\Windows\SysNative\drivers\sscdmdfl.sys (MCCI Corporation)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (Impcd) -- C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel® -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (btwrchid) -- C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (btwl2cap) -- C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (HECIx64) Intel® -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (enecir) -- C:\Windows\SysNative\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (SrvHsfV92) -- C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) -- C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (yukonw7) -- C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) Intel® -- C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (dc3d) MS Hardware Device Detection Driver (USB) -- C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (NuidFltr) -- C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (Point64) -- C:\Windows\SysNative\drivers\point64k.sys (Microsoft Corporation)
DRV:64bit: - (HpqKbFiltr) -- C:\Windows\SysNative\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20120622.005\ex64.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20120622.005\eng64.sys (Symantec Corporation)
DRV - (BHDrvx64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20111201.001\BHDrvx64.sys (Symantec Corporation)
DRV - (IDSVia64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20111130.012\IDSviA64.sys (Symantec Corporation)
DRV - (RSUSBSTOR) -- C:\Windows\SysWOW64\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE:64bit: - HKLM\..\SearchScopes\{7BB21EAE-EF34-448F-B77A-1848EA35DEA1}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{075FEACF-D8DC-65DF-C6F1-0BB288E5787D}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms}
IE - HKLM\..\SearchScopes\{7BB21EAE-EF34-448F-B77A-1848EA35DEA1}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>



IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page =
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://xfinity.comcast.net/?cid=cgps06232012
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes,Backup.Old.DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes\{075FEACF-D8DC-65DF-C6F1-0BB288E5787D}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes\{2ED1569D-74DD-4966-8F7E-470F8CAD3519}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes\{7BB21EAE-EF34-448F-B77A-1848EA35DEA1}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421;<local>


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Users\Howrey\AppData\Local\HuluDesktop\instances\0.9.10.1\nphdplg.dll (Hulu LLC)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Howrey\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Howrey\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Howrey\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/02/28 17:01:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPlgn\ [2012/06/23 21:46:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\coFFPlgn\ [2012/06/23 21:46:44 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/02/28 17:01:28 | 000,000,000 | ---D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: NPLastPass (Enabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\1.90.7_0\nplastpass.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: CouponNetwork Coupon Activator Netscape Plugin v. 5.0.0.0 (Enabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\Application\plugins\NPcol400.dll
CHR - plugin: CouponNetwork Coupon Activator Netscape Plugin v. 5.0.0.0 (Enabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\Application\plugins\NPcol500.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Users\Howrey\AppData\Local\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Howrey\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Howrey\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Hulu Desktop (Enabled) = C:\Users\Howrey\AppData\Local\HuluDesktop\instances\0.9.10.1\nphdplg.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: LastPass = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\2.0.1_1\
CHR - Extension: Dark abstract theme = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnneafiffajmgfkidbdfpfkehpodbhkd\1.2\
CHR - Extension: Norton Identity Protection = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.0.140_0\
CHR - Extension: Gmail = C:\Users\Howrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/06/23 20:00:14 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (VideoFileDownload) - {47CEEE9C-3B9B-492C-95CA-1AC3A99D154C} - C:\Program Files (x86)\OApps\bho_project.dll (VideoFileDownload)
O2 - BHO: (XFINITY Toolbar) - {4b9bcce8-a70b-402a-a7e1-db96831ee26f} - C:\Program Files (x86)\xfin_portal\comcastdx.dll ()
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\6.0.0.145\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\6.0.0.145\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Constant Guard Protection Suite (COM)) - {B84CDBE7-1B46-494B-A188-01D4C52DEB61} - C:\ProgramData\White Sky, Inc\ID Vault\IEBHO1.1.613.0\NativeBHO.dll (WhiteSky)
O2 - BHO: (Updater For XFIN_PORTAL) - {bb46be07-13eb-4c49-b0f0-fc78b9ea4983} - C:\Program Files (x86)\xfin_portal\auxi\comcastAu.dll (Visicom Media)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (XFINITY Toolbar) - {4b9bcce8-a70b-402a-a7e1-db96831ee26f} - C:\Program Files (x86)\xfin_portal\comcastdx.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\6.0.0.145\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [GIDDesktop] C:\Program Files (x86)\SFT\GuardedID\gidd.exe (StrikeForce Technologies Inc.)
O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001..\Run: [Akamai NetSession Interface] C:\Users\Howrey\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001..\Run: [SansaDispatch] C:\Users\Howrey\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - Startup: C:\Users\Howrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Howrey\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5A0FE5B6-CA36-46A8-9038-E8049D52F1B6}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/06/23 21:46:07 | 000,175,736 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2012/06/23 21:46:07 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2012/06/23 21:46:07 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2012/06/23 21:45:47 | 001,092,728 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\0600000.091\SymEFA64.sys
[2012/06/23 21:45:47 | 000,738,936 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\0600000.091\srtsp64.sys
[2012/06/23 21:45:47 | 000,451,192 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\0600000.091\SymDS64.sys
[2012/06/23 21:45:47 | 000,405,624 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\0600000.091\symnets.sys
[2012/06/23 21:45:47 | 000,190,072 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\0600000.091\Ironx64.sys
[2012/06/23 21:45:47 | 000,167,048 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\0600000.091\ccSetx64.sys
[2012/06/23 21:45:47 | 000,037,496 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\0600000.091\srtspx64.sys
[2012/06/23 21:45:40 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\N360x64
[2012/06/23 21:45:40 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\N360x64\0600000.091
[2012/06/23 21:45:39 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Suite
[2012/06/23 21:45:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Security Suite
[2012/06/23 21:45:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NortonInstaller
[2012/06/23 20:26:30 | 000,000,000 | ---D | C] -- C:\ProgramData\IsolatedStorage
[2012/06/23 20:26:30 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\ID Vault
[2012/06/23 20:25:48 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Roaming\ID Vault
[2012/06/23 20:25:33 | 000,467,224 | ---- | C] (StrikeForce Technologies Inc.) -- C:\Windows\SysNative\GIDHOOK64.DLL
[2012/06/23 20:25:33 | 000,446,752 | ---- | C] (StrikeForce Technologies Inc.) -- C:\Windows\SysNative\GIDHookLogon64.dll
[2012/06/23 20:25:33 | 000,206,608 | ---- | C] (StrikeForce Technologies Inc.) -- C:\Windows\SysNative\GIDBIN1.DLL
[2012/06/23 20:25:33 | 000,102,160 | ---- | C] (StrikeForce Technologies Inc.) -- C:\Windows\SysNative\GIDBIN3.DLL
[2012/06/23 20:25:33 | 000,065,816 | ---- | C] (StrikeForce Technologies Inc.) -- C:\Windows\SysNative\GIDLogonCP64.dll
[2012/06/23 20:25:33 | 000,029,288 | ---- | C] (StrikeForce Technologies, Inc.) -- C:\Windows\SysNative\drivers\gidv2.sys
[2012/06/23 20:25:24 | 000,000,000 | ---D | C] -- C:\ProgramData\GID
[2012/06/23 20:25:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SFT
[2012/06/23 20:25:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\xfin_portal
[2012/06/23 20:25:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Constant Guard Protection Suite
[2012/06/23 20:24:47 | 000,000,000 | ---D | C] -- C:\ProgramData\White Sky, Inc
[2012/06/23 20:05:29 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/06/23 19:50:43 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/06/23 19:50:43 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/06/23 19:50:43 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/06/23 19:42:14 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/06/23 19:41:53 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/06/23 14:53:35 | 004,565,820 | R--- | C] (Swearware) -- C:\Users\Howrey\Desktop\ComboFix.exe
[2012/06/23 09:44:27 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Howrey\Desktop\OTL.exe
[2012/06/23 08:59:58 | 000,476,936 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\npdeployJava1.dll
[2012/06/23 08:59:58 | 000,157,448 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2012/06/23 08:59:58 | 000,149,256 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2012/06/23 08:59:58 | 000,149,256 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2012/06/22 18:27:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2012/06/22 18:27:57 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/06/22 17:45:16 | 000,000,000 | ---D | C] -- C:\Users\Howrey\.smplayer
[2012/06/22 12:47:25 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess
[2012/06/22 10:05:15 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Roaming\WinRAR
[2012/06/22 09:58:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OApps
[2012/06/22 09:57:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Funmoods
[2012/06/22 09:44:14 | 000,000,000 | ---D | C] -- C:\Users\Howrey\Documents\Graboid
[2012/06/22 09:40:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Graboid Inc
[2012/06/22 09:39:43 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\Geckofx
[2012/06/22 09:39:41 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Roaming\Mozilla
[2012/06/22 09:38:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2012/06/22 09:36:46 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\Ilivid Player
[2012/06/22 09:19:29 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2012/06/22 09:19:29 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2012/06/22 09:19:29 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2012/06/22 09:19:24 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2012/06/22 09:19:23 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2012/06/22 09:19:23 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2012/06/22 09:18:52 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2012/06/22 09:18:52 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2012/06/14 00:45:15 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/06/14 00:45:15 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/06/14 00:45:15 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/06/14 00:45:15 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/06/14 00:45:14 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/06/14 00:45:14 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/06/14 00:45:14 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012/06/14 00:45:14 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012/06/14 00:45:13 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012/06/14 00:45:13 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012/06/14 00:45:12 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012/06/14 00:45:12 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/06/14 00:45:12 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/06/13 07:37:42 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
[2012/06/13 07:37:42 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
[2012/06/13 07:37:42 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe
[2012/06/13 07:37:33 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012/06/13 07:37:31 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012/06/13 07:37:29 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012/06/13 07:37:24 | 003,216,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2012/06/13 07:37:14 | 001,462,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2012/06/13 07:37:12 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2012/06/09 16:44:21 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{7161921B-E134-4F42-838C-78CD2E18F3F8}
[2012/06/09 16:44:11 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{39F0F5EF-959A-4909-B3C9-FA179D55C4AE}
[2012/06/08 17:09:08 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{2438094A-6FEA-46EA-9610-458FB79967AE}
[2012/06/08 17:08:57 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{06F8A87F-89ED-4A47-84D8-583D000C27DC}
[2012/06/07 15:08:02 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{0CA87D3A-F05C-4CF5-846A-9521D5A6DC24}
[2012/06/07 15:07:53 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{318349E9-1145-4480-BA10-950807E8704E}
[2012/06/06 15:56:32 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{80EEDB06-D41A-43EE-8782-0A53B002305A}
[2012/06/06 15:56:22 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{4874C080-E817-42E1-80B9-E88DF549840F}
[2012/06/02 15:22:06 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{E97C3721-5FF9-40E1-B490-EA4F702861E7}
[2012/06/02 15:21:56 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{8A3672FC-3351-45C5-9314-AD5C4B1FC213}
[2012/06/02 15:21:05 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{6B0E3FCC-D57A-49F5-81C1-40F6989CFACB}
[2012/06/02 15:20:55 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{7956B238-2E02-4498-A91B-2F2497E99C08}
[2012/06/02 15:04:06 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{88A9A8A3-5CDA-475D-8D13-4475350D206F}
[2012/06/02 15:03:56 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{855BA2E5-E957-4B46-9E58-E9C70CD8B7FB}
[2012/06/02 00:19:11 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{E05278C2-D8B4-40A6-8AC6-3C95125BD8DE}
[2012/06/02 00:19:02 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{467C06D0-D0D3-4167-93AF-AE18CBB2D4CD}
[2012/06/02 00:17:23 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{06D2E959-E7DC-4549-A723-2AFB4F5CA7C3}
[2012/06/02 00:17:13 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{BCFEA152-108B-4817-ADE6-12A053F5FB75}
[2012/06/02 00:15:53 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{0A72795D-FDD2-4B97-8F3B-4FF1EAFEEE4A}
[2012/06/02 00:15:43 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{50F3C703-4157-4575-A455-353001D197CA}
[2012/06/02 00:13:28 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{128F3A0A-5761-4603-946A-5CB59661AA35}
[2012/06/02 00:13:17 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{246AA358-6B3D-4340-866F-0F0BAA196A4F}
[2012/06/02 00:12:41 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{43D49908-24D6-4607-B0BB-C1AB1B66305C}
[2012/06/02 00:12:31 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{33966D57-DDB4-4F76-987B-CDE6B4B72C4E}
[2012/06/02 00:10:53 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{00E333B2-F64B-4B99-B087-6DDE2AF6F234}
[2012/06/02 00:10:44 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{396E069C-C712-4882-8444-22D7084A720F}
[2012/06/02 00:06:40 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{BFD4B609-6280-4EEF-A40C-6B1CECF03766}
[2012/06/02 00:02:40 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{2B83F3A6-C108-4BF0-98C6-3DB6AB1A1C10}
[2012/06/02 00:02:31 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{AD1E1EE0-1669-4FD4-AAA9-4B98FE6DD7AE}
[2012/06/02 00:01:11 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CC2B5BAF-084E-4FA9-AF45-BD5611E873B8}
[2012/06/02 00:01:01 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{EE0FE2F1-C34C-46C9-A82E-9D49C1C3DFF6}
[2012/06/01 23:57:46 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{B2921A07-F898-4885-88D4-E3B1DC5FA5D1}
[2012/06/01 23:57:36 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{FB1D0259-E889-4395-9D83-1D3D1F1F925B}
[2012/06/01 23:56:27 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{765DC91A-49DD-41C2-AD34-B62CD06B8821}
[2012/06/01 23:56:18 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{A11F5125-7D88-4AEF-87E5-C08783254DE9}
[2012/06/01 23:54:53 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{9D8E45F5-EE6B-49FF-A1F5-9EEBA412337D}
[2012/06/01 23:54:43 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{185E98E5-F98F-43ED-89A4-55CFA1607935}
[2012/06/01 23:53:50 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{351ECD31-E34F-45F0-BB01-2355813429B2}
[2012/06/01 23:53:40 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{DBFF1E3D-F772-411E-9049-E27F77BECFC9}
[2012/06/01 23:52:34 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{EFABBB2C-902C-4015-9638-F47BF7ECB81F}
[2012/06/01 23:52:24 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{63B59240-9BBA-48EF-9394-CE2AF40E5365}
[2012/06/01 23:51:37 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{71F1B644-0856-4B75-9E9F-7DA7D9385302}
[2012/06/01 23:51:27 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{A46CF1F9-B680-4C1D-B925-E9012656FA1B}
[2012/06/01 23:49:36 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{783A2979-D81E-47FF-BAC7-9130E15C1344}
[2012/06/01 23:49:26 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{71D27975-0B7A-47EE-85E7-07EA11B9BB8C}
[2012/06/01 23:47:23 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{E49F753D-C54E-421F-8D69-7DA3F7C3EA17}
[2012/06/01 23:47:14 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{79E8C0FE-7735-4AFF-82F9-373B278D5C93}
[2012/06/01 23:45:11 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{0EEBEEF5-E75B-45C3-87EC-DFFD6FEA710B}
[2012/06/01 23:45:01 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{87F52C3F-FC74-4670-B38D-53FC13F932F6}
[2012/06/01 23:40:37 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{559DBC3C-17FA-4204-91F0-225AA0F6FEBD}
[2012/06/01 23:40:28 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{37FE6526-E9C4-4F26-ACBA-58730A1BD490}
[2012/06/01 23:39:16 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{1108206B-31D2-4F48-A2EC-73E786FBD9FB}
[2012/06/01 23:39:06 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{A0E687B3-0B03-4D3D-BA18-9438DD2796E7}
[2012/06/01 23:38:13 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{3E4316E5-767A-4342-9794-48B7F32802A0}
[2012/06/01 23:38:03 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{54E6C4A1-8C69-4E02-8203-BBCDFD5329C9}
[2012/06/01 23:36:54 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{62886716-4F19-4E0C-976F-8F9682A49133}
[2012/06/01 23:36:44 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{B248F0FE-1058-44DB-ADD5-EFBFEDE52F46}
[2012/06/01 23:35:37 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{DA63DE8B-8D7A-4BC3-833D-5E6C64725122}
[2012/06/01 23:35:27 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{E8C73FAC-10DF-4ABF-BDFD-84DBEFC5DD5E}
[2012/06/01 23:34:39 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{2E72A5C1-4724-4704-B045-AD8A96FA4CAD}
[2012/06/01 23:34:30 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{977A46E4-C5F8-4990-B1A9-73F447043032}
[2012/06/01 23:22:48 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{6D51B7E7-7B99-4368-8672-D69996938BB8}
[2012/06/01 23:22:38 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{C3542E71-5118-4FB6-AB36-DE12CA6A873A}
[2012/06/01 23:21:12 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{28A51427-04A3-4C78-8F5D-AD11BAB9DDBE}
[2012/06/01 23:21:01 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{33113385-164C-4DFC-9988-15B7C2F1F2C4}
[2012/06/01 23:12:49 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{26046AB9-FF03-474B-9A05-858A19B62811}
[2012/06/01 23:12:39 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{D49436C9-D7DC-427D-813D-C00915270330}
[2012/06/01 23:06:39 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{441C7DAF-3116-44AB-81F9-D205BDF1EB3A}
[2012/06/01 23:06:30 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{3C2ECA86-FD5D-4316-9B8D-DE254B890F1E}
[2012/06/01 23:01:28 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{D7092C62-7EA5-425E-BA35-75C8510D97A1}
[2012/06/01 23:01:18 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{F74FC52E-4A96-45D3-9E89-18379F37637A}
[2012/06/01 22:51:02 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{FACBF969-27EB-42E9-A295-4398088E208D}
[2012/06/01 22:50:52 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{405C55EA-6F05-455A-AC4D-820C9209543E}
[2012/06/01 22:45:13 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{72336468-483D-43DF-A47A-3883BDD4CBEA}
[2012/06/01 22:45:03 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{927981E1-3B5B-4EBA-83B2-4FF3DF0C328F}
[2012/06/01 22:42:15 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{31140646-9892-4741-AA8C-3E7DA1582E0B}
[2012/06/01 22:42:05 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{9ADC7A3B-BD08-4CA0-9019-C930AC1921FF}
[2012/06/01 22:41:07 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{65640219-474C-4C03-B300-5FCFD1CDF057}
[2012/06/01 22:40:57 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{EAF4EC56-8647-4D77-8025-A421B2C34286}
[2012/06/01 22:36:05 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{013CDEB2-563E-42E6-A0BF-219971FE5FD1}
[2012/06/01 22:35:17 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{345663BC-0575-45C6-8CE4-C9B37F7AD439}
[2012/06/01 22:35:07 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{E2450831-997C-4755-8675-CD225964A86C}
[2012/06/01 22:29:52 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{F44412F6-A054-4051-8BED-2833569D7C69}
[2012/06/01 22:29:43 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CD84CEC2-F9E8-4896-8BCA-9D0D2EA406FD}
[2012/06/01 22:29:06 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{21C028BF-8007-4138-B8DA-23EE4606D1BD}
[2012/06/01 22:28:56 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{08EF5330-0A89-472A-BECC-960B38933301}
[2012/06/01 22:27:26 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{B42CE132-E0B7-4A1B-8719-95FDA307F0A0}
[2012/06/01 22:27:16 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{C71511C1-670C-48B9-9095-6E6489010967}
[2012/06/01 22:25:33 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CBC0865F-B69A-48F3-B312-DEB50C4C2774}
[2012/06/01 22:25:23 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{67A6A02F-D620-4D9E-A1CD-3F069F0801C8}
[2012/06/01 22:18:56 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{B3D68521-820F-4C94-B8A1-078BAE046074}
[2012/06/01 22:18:46 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{208B5E37-C61F-4D1A-9FF3-2511D1B108C5}
[2012/06/01 22:18:01 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{BEA83B68-4EC0-4E1A-B025-138E44C44966}
[2012/06/01 22:17:51 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{13D25BB9-50B5-4E7A-BCE3-3FEA9FBC727B}
[2012/06/01 22:17:11 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{7760770C-D9FE-466D-9CC7-5CA0D996CEC5}
[2012/06/01 22:17:02 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{F9474BBB-1D56-4733-B6A6-31E2B00ED7CF}
[2012/06/01 22:14:50 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{B1B8AEBA-4BCB-428D-ADEB-59AF952D78F8}
[2012/06/01 22:14:40 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CC834C0E-E60C-4DDE-B7CE-D5D96D6D097A}
[2012/06/01 22:14:07 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{594BB9E8-2533-4AFA-BB0D-0FBA4FD46F9B}
[2012/06/01 22:13:57 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{433B905D-67AD-4F2A-9B77-328C95BFC6D6}
[2012/06/01 22:05:34 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CB288644-2CB4-40C9-B8D8-6E0B08E7F08A}
[2012/06/01 22:05:24 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{981D0EB7-DB68-4E5E-9B2A-9D7AE7F0A1E9}
[2012/06/01 22:04:16 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{27175B23-F97C-45FB-975F-316D3AF3D026}
[2012/06/01 22:04:06 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{B48E80D5-79BB-4DC6-98F0-8B8A3A9CEF61}
[2012/06/01 22:02:59 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{A7744EBE-3DCE-4A5E-8407-69ADBAE700A7}
[2012/06/01 22:02:49 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{F22F339F-6DFC-46BA-BCCE-C741B736C5EC}
[2012/06/01 22:01:23 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{DA39BFF3-4CA0-4144-98E0-4A551186BF9D}
[2012/06/01 22:01:13 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{0E836EAC-4682-4EAA-B934-1DA5321C0176}
[2012/06/01 22:00:11 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{7FAEB349-9805-4843-A2F8-90C4BC5B7FE4}
[2012/06/01 22:00:01 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{2B1A99E7-F104-4010-A4D2-BE7694EB7D91}
[2012/06/01 21:52:47 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{766B5072-934D-48FD-AB51-17B927E71C8B}
[2012/06/01 21:52:37 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{178B1B57-5843-436E-84BF-7F3AA54A727A}
[2012/06/01 21:52:05 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{499C7466-D42C-4CBB-BD2F-4A8FEE387F22}
[2012/06/01 21:51:55 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{C85CFA3D-890B-41D2-9035-5CEFA1963E9D}
[2012/06/01 21:47:04 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{C3D9A315-643E-40EC-ACB3-C24A00D401B9}
[2012/06/01 21:46:54 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{226987AD-EB15-4B3E-A2D2-28FD986D0ED2}
[2012/06/01 21:41:08 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{470074D6-C27D-4B8A-8BA2-E9E64136660D}
[2012/06/01 21:40:58 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CBE06949-2DA0-440E-8DA3-41DA4536DABB}
[2012/06/01 21:39:54 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{403635F0-9B21-421A-AAD5-CF0F5A231DEE}
[2012/06/01 21:39:44 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{8B46E9F4-5A27-4073-B3ED-5EA70AC00E13}
[2012/06/01 21:38:11 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{A39F7072-3A6A-42A6-9EA4-D059AD55BA8D}
[2012/06/01 21:38:01 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CA051F50-9E22-4B01-B09D-F77A388E6312}
[2012/06/01 21:37:01 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{0E3A2D10-FEBE-413A-A912-415DE9F4D029}
[2012/06/01 21:36:52 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CDA73F08-B006-4DC4-A799-EBDF55726C1B}
[2012/06/01 21:29:46 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{9C622B84-4DF3-43B3-AF47-72C076FAE63B}
[2012/06/01 21:29:36 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{3951AFBA-91AD-4C41-AADE-784AC5F7358A}
[2012/06/01 21:26:14 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{59147FE9-66EF-4B74-AC2E-D05DD29BB232}
[2012/06/01 21:26:04 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{C32BCB87-6E33-43B9-A498-6FAC27849CD8}
[2012/06/01 21:25:46 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{6F563883-F340-42B2-8131-1F1CC98655B6}
[2012/06/01 21:25:36 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CC67EC58-A3B7-416A-BEDF-E226A9D3A0F7}
[2012/05/30 21:01:27 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{F7CBA22F-BA5E-4372-B7B6-74D52AA22350}
[2012/05/30 21:01:16 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{0D89A84A-7744-4C21-B46F-892C7D39832E}
[2012/05/25 22:05:47 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{6D44BB68-ADCD-4525-9B37-E65BD23283FE}
[2012/05/25 22:05:38 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{C77D9BEB-9ED3-4554-B056-664EF3D5860D}
[2012/05/25 22:04:40 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{11A67BDF-B381-4A16-BFB1-8547A0F5895C}
[2012/05/25 22:04:30 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{DB96A8CD-5624-4358-A662-C67CE0E2B1AD}
[2012/05/25 22:03:37 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{168A5B6E-0D4B-4AB4-9FE4-F5A80D91994A}
[2012/05/25 22:03:27 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{F6D5F874-A52D-42B6-908A-880D74C9A5BD}
[2012/05/25 21:08:31 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{A936EF10-7907-44CF-B342-3366680F2A96}
[2012/05/25 21:08:21 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{D1D50919-125B-4C1E-96EE-90D9740F14DC}
[2012/05/25 19:49:39 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{CDC3456D-C070-4827-84AC-20F9C8787585}
[2012/05/25 19:49:28 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\{3665C28A-557F-450A-8490-B07F55CCEEDA}

========== Files - Modified Within 30 Days ==========

[2012/06/23 21:46:27 | 002,135,843 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\Cat.DB
[2012/06/23 21:46:07 | 000,175,736 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2012/06/23 21:46:07 | 000,007,488 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2012/06/23 21:46:07 | 000,000,855 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2012/06/23 21:46:03 | 000,002,516 | ---- | M] () -- C:\Users\Public\Desktop\Norton Security Suite.lnk
[2012/06/23 21:10:04 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3097100386-4279238605-4106125582-1001UA.job
[2012/06/23 20:37:01 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/23 20:37:01 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/23 20:33:06 | 000,001,362 | ---- | M] () -- C:\Users\Howrey\Desktop\Norton Installation Files.lnk
[2012/06/23 20:29:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/23 20:29:19 | 3063,046,144 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/23 20:25:13 | 000,002,283 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Constant Guard.lnk
[2012/06/23 20:25:13 | 000,002,265 | ---- | M] () -- C:\Users\Public\Desktop\Constant Guard.lnk
[2012/06/23 20:00:14 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/06/23 19:10:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3097100386-4279238605-4106125582-1001Core.job
[2012/06/23 14:53:41 | 004,565,820 | R--- | M] (Swearware) -- C:\Users\Howrey\Desktop\ComboFix.exe
[2012/06/23 09:44:28 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Howrey\Desktop\OTL.exe
[2012/06/23 09:43:31 | 000,881,475 | ---- | M] () -- C:\Users\Howrey\Desktop\SecurityCheck.exe
[2012/06/23 09:15:32 | 000,738,832 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/23 09:15:32 | 000,632,696 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/06/23 09:15:32 | 000,110,644 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/06/23 08:59:47 | 000,476,936 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\npdeployJava1.dll
[2012/06/23 08:59:47 | 000,472,840 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll
[2012/06/23 08:59:47 | 000,157,448 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2012/06/23 08:59:47 | 000,149,256 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2012/06/23 08:59:47 | 000,149,256 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2012/06/22 19:33:04 | 000,000,000 | ---- | M] () -- C:\Users\Howrey\defogger_reenable
[2012/06/22 18:27:57 | 000,002,981 | ---- | M] () -- C:\Users\Howrey\Desktop\HiJackThis.lnk
[2012/06/22 10:47:09 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/22 09:57:15 | 000,302,425 | ---- | M] () -- C:\Users\Howrey\AppData\Local\funmoods-speeddial.crx
[2012/06/22 09:57:15 | 000,031,470 | ---- | M] () -- C:\Users\Howrey\AppData\Local\funmoods.crx
[2012/06/20 13:51:41 | 000,001,296 | ---- | M] () -- C:\Users\Howrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2012/06/14 20:04:08 | 000,438,520 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/10 18:08:06 | 000,001,050 | ---- | M] () -- C:\Users\Howrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/06/10 18:07:59 | 000,001,020 | ---- | M] () -- C:\Users\Howrey\Desktop\Dropbox.lnk
[2012/06/10 18:05:33 | 000,000,336 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForHowrey.job
[2012/06/02 18:19:46 | 000,038,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2012/06/02 18:19:42 | 000,057,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2012/06/02 18:19:42 | 000,044,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2012/06/02 18:19:23 | 000,701,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2012/06/02 18:15:31 | 002,622,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2012/06/02 18:15:08 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2012/06/02 15:19:42 | 000,186,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2012/06/02 15:15:12 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe

========== Files Created - No Company Name ==========

[2012/06/23 21:46:08 | 002,135,843 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\Cat.DB
[2012/06/23 21:46:07 | 000,007,488 | ---- | C] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2012/06/23 21:46:07 | 000,000,855 | ---- | C] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2012/06/23 21:46:03 | 000,002,516 | ---- | C] () -- C:\Users\Public\Desktop\Norton Security Suite.lnk
[2012/06/23 21:45:40 | 000,007,496 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\SymDS64.cat
[2012/06/23 21:45:40 | 000,007,468 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\ccSetx64.cat
[2012/06/23 21:45:40 | 000,007,462 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\srtspx64.cat
[2012/06/23 21:45:40 | 000,007,460 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\SymEFA64.cat
[2012/06/23 21:45:40 | 000,007,458 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\symnet64.cat
[2012/06/23 21:45:40 | 000,007,458 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\srtsp64.cat
[2012/06/23 21:45:40 | 000,007,450 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\iron.cat
[2012/06/23 21:45:40 | 000,004,782 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\SymVTcer.dat
[2012/06/23 21:45:40 | 000,003,434 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\SymEFA.inf
[2012/06/23 21:45:40 | 000,002,852 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\SymDS.inf
[2012/06/23 21:45:40 | 000,001,441 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\SymNet.inf
[2012/06/23 21:45:40 | 000,001,438 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\srtsp64.inf
[2012/06/23 21:45:40 | 000,001,420 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\srtspx64.inf
[2012/06/23 21:45:40 | 000,000,853 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\ccSetx64.inf
[2012/06/23 21:45:40 | 000,000,772 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\Iron.inf
[2012/06/23 21:45:40 | 000,000,172 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\0600000.091\isolate.ini
[2012/06/23 20:33:05 | 000,001,362 | ---- | C] () -- C:\Users\Howrey\Desktop\Norton Installation Files.lnk
[2012/06/23 20:25:33 | 000,109,064 | ---- | C] () -- C:\Windows\SysNative\EasyHook64.dll
[2012/06/23 20:25:13 | 000,002,283 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Constant Guard.lnk
[2012/06/23 20:25:13 | 000,002,277 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Constant Guard.lnk
[2012/06/23 20:25:13 | 000,002,265 | ---- | C] () -- C:\Users\Public\Desktop\Constant Guard.lnk
[2012/06/23 19:50:43 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/06/23 19:50:43 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/06/23 19:50:43 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/06/23 19:50:43 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/06/23 19:50:43 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/06/23 09:43:30 | 000,881,475 | ---- | C] () -- C:\Users\Howrey\Desktop\SecurityCheck.exe
[2012/06/22 19:33:04 | 000,000,000 | ---- | C] () -- C:\Users\Howrey\defogger_reenable
[2012/06/22 18:27:57 | 000,002,981 | ---- | C] () -- C:\Users\Howrey\Desktop\HiJackThis.lnk
[2012/06/22 10:47:09 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/22 09:57:53 | 000,302,425 | ---- | C] () -- C:\Users\Howrey\AppData\Local\funmoods-speeddial.crx
[2012/06/22 09:57:38 | 000,031,470 | ---- | C] () -- C:\Users\Howrey\AppData\Local\funmoods.crx
[2012/03/05 13:28:23 | 003,693,389 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0230.JPG
[2011/05/12 15:02:40 | 000,001,940 | ---- | C] () -- C:\Users\Howrey\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/03/19 21:18:11 | 000,001,854 | ---- | C] () -- C:\Users\Howrey\AppData\Roaming\GhostObjGAFix.xml
[2011/02/03 14:34:12 | 000,000,164 | ---- | C] () -- C:\Windows\SysWow64\psconv.ini
[2010/12/13 10:09:36 | 000,430,996 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0273_CROPQUAD.JPG
[2010/12/12 15:07:07 | 003,164,285 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0033_(2).JPG
[2010/12/12 15:04:48 | 000,005,149 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmp41262_419810891719_546171719_5336847_5651237_N_CROP.JPG
[2010/12/12 15:04:48 | 000,005,110 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmp41262_419810891719_546171719_5336847_5651237_N_CROP.0
[2010/12/12 15:03:51 | 000,108,963 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmp41262_419810891719_546171719_5336847_5651237_N.JPG
[2010/12/12 15:02:32 | 000,034,645 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpCHRISTAMS PIC '10.JPG
[2010/11/26 18:16:24 | 000,000,218 | ---- | C] () -- C:\Users\Howrey\.recently-used.xbel
[2010/11/26 18:12:45 | 000,003,683 | ---- | C] () -- C:\Users\Howrey\Budget.20101126171245.xac
[2010/11/26 18:12:40 | 000,003,579 | ---- | C] () -- C:\Users\Howrey\Budget.20101126171240.xac
[2010/11/26 18:12:17 | 000,003,683 | ---- | C] () -- C:\Users\Howrey\Budget
[2010/10/26 10:07:46 | 000,455,429 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDZIESUPEK BID 2.JPG
[2010/10/26 10:07:46 | 000,451,841 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDZIESUPEK BID 2.0
[2010/10/15 14:27:34 | 000,555,770 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpVOGEL BID.1
[2010/10/15 14:27:32 | 000,574,287 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpVOGEL BID.JPG
[2010/10/15 14:27:32 | 000,547,544 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpVOGEL BID.0
[2010/10/06 08:10:21 | 000,007,606 | ---- | C] () -- C:\Users\Howrey\AppData\Local\Resmon.ResmonCfg
[2010/08/23 09:15:37 | 000,070,428 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0313_(2)_CROP_CROP.JPG
[2010/08/23 09:14:08 | 000,689,140 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0271.JPG
[2010/08/23 09:14:07 | 002,895,247 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0271.0
[2010/08/23 09:07:38 | 000,849,520 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0175.JPG
[2010/08/23 09:07:37 | 002,912,294 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0175.0
[2010/08/23 09:01:10 | 002,481,702 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0073.JPG
[2010/05/10 17:57:20 | 000,070,192 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC05465_CROP.JPG
[2010/05/10 17:57:19 | 000,068,948 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC05465_CROP.0
[2010/04/20 18:29:58 | 000,677,465 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpAUSTIN BID.JPG
[2010/04/20 18:29:58 | 000,661,013 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpAUSTIN BID.0
[2010/04/19 10:24:57 | 000,885,132 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0468_(1).JPG
[2010/04/19 10:24:56 | 003,181,173 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0468_(1).0
[2010/04/19 10:21:46 | 000,082,895 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0313_(2)_CROP.JPG
[2010/04/19 10:20:46 | 001,963,113 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0313_(2).JPG
[2010/04/19 10:18:36 | 002,888,900 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0269.JPG
[2010/04/19 10:17:02 | 000,901,025 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0259_(2)_CROP.JPG
[2010/04/19 10:15:55 | 001,131,357 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0259_(2).JPG
[2010/04/19 10:14:25 | 003,558,841 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0256.JPG
[2010/04/19 10:10:23 | 000,434,424 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0273_CROPCROP.JPG
[2010/04/19 10:08:15 | 003,057,466 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0273.JPG
[2010/04/19 10:05:30 | 003,114,140 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0236_(1).JPG
[2010/04/19 09:59:54 | 001,157,709 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0922_(1)_CROP.JPG
[2010/04/19 09:58:35 | 003,053,282 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0921_(1).JPG
[2010/04/19 09:55:09 | 003,075,642 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0922_(1).JPG
[2010/04/19 09:36:47 | 003,240,895 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0274.JPG
[2010/04/19 09:36:47 | 003,240,895 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0274.0
[2010/04/18 21:32:29 | 000,822,933 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0286.JPG
[2010/04/18 21:32:28 | 002,928,770 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0286.0
[2010/04/18 21:11:17 | 000,811,146 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0104_(2).JPG
[2010/04/18 21:11:16 | 002,952,002 | ---- | C] () -- C:\Users\Howrey\AppData\Local\tmpDSC_0104_(2).0
[2010/03/28 21:31:54 | 000,000,099 | ---- | C] () -- C:\Users\Howrey\jagex_runescape_preferences2.dat
[2010/03/28 21:31:54 | 000,000,000 | ---- | C] () -- C:\Users\Howrey\jagex__preferences3.dat
[2010/03/28 21:30:43 | 000,000,046 | ---- | C] () -- C:\Users\Howrey\jagex_runescape_preferences.dat
[2010/02/12 23:11:56 | 000,004,674 | ---- | C] () -- C:\Users\Howrey\AppData\Roaming\wklnhst.dat

< End of report >

#8 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:43 PM

Posted 24 June 2012 - 11:56 AM

Hello

Run this custom script and when it is complete I need to know how the computer is doing

Run OTL Script

  • Double-click OTL.exe to start the program.
  • Copy and Paste the following code into the Posted Image textbox. Do not include the word Code
    :OTL
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Reg Error: Key error.)
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
    O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    IE:64bit: - HKLM\..\SearchScopes\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
    IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
    IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    IE - HKLM\..\SearchScopes\{075FEACF-D8DC-65DF-C6F1-0BB288E5787D}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms}
    IE - HKLM\..\SearchScopes\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
    IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
    IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes,Backup.Old.DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes\{075FEACF-D8DC-65DF-C6F1-0BB288E5787D}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms}
    IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
    IE - HKU\S-1-5-21-3097100386-4279238605-4106125582-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzutAtN2Y1L1Qzu0CyEtCyB0F0EyEtB0AyBzz0D0ByE0AyDtN0D0TzutBtDtCtBtDyCtBtB&cr=259735636
    [2012/06/22 09:57:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Funmoods
    [2012/06/22 09:36:46 | 000,000,000 | ---D | C] -- C:\Users\Howrey\AppData\Local\Ilivid Player
    [2012/06/22 09:57:15 | 000,302,425 | ---- | M] () -- C:\Users\Howrey\AppData\Local\funmoods-speeddial.crx
    [2012/06/22 09:57:15 | 000,031,470 | ---- | M] () -- C:\Users\Howrey\AppData\Local\funmoods.crx
    :Files
    ipconfig /flushdns /c
    :Commands
    [PURITY]
    [emptyjava]
    [EMPTYFLASH]
    
  • Then click the Run Fix button at the top.
  • Click Posted Image.
  • OTL may ask to reboot the machine. Please do so if asked.
  • The report should appear in Notepad after the reboot.Copy and Paste that report in your next reply.

Let me know How things are doing

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#9 bhengr

bhengr
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 24 June 2012 - 01:23 PM

Hello Gringo,

OTL with script ran without any problem. It didn't require a reboot. When I opened Chrome, the searchnu/406 hijack was still there. I rebooted the computer to see if that made a difference. It didn't. Here is the log.

Thanks, Bruce

========== OTL ==========
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
File Protocol\Handler\wlpg - No CLSID value found not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{075FEACF-D8DC-65DF-C6F1-0BB288E5787D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{075FEACF-D8DC-65DF-C6F1-0BB288E5787D}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
HKEY_USERS\S-1-5-21-3097100386-4279238605-4106125582-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_USERS\S-1-5-21-3097100386-4279238605-4106125582-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3097100386-4279238605-4106125582-1001\Software\Microsoft\Internet Explorer\SearchScopes\{075FEACF-D8DC-65DF-C6F1-0BB288E5787D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{075FEACF-D8DC-65DF-C6F1-0BB288E5787D}\ not found.
Registry key HKEY_USERS\S-1-5-21-3097100386-4279238605-4106125582-1001\Software\Microsoft\Internet Explorer\SearchScopes\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8F6B9819-1FF0-4AD7-A3BF-7D407E0CD28A}\ not found.
Registry key HKEY_USERS\S-1-5-21-3097100386-4279238605-4106125582-1001\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
C:\Program Files (x86)\Funmoods\1.5.23.22\bh folder moved successfully.
C:\Program Files (x86)\Funmoods\1.5.23.22 folder moved successfully.
C:\Program Files (x86)\Funmoods folder moved successfully.
C:\Users\Howrey\AppData\Local\Ilivid Player folder moved successfully.
C:\Users\Howrey\AppData\Local\funmoods-speeddial.crx moved successfully.
C:\Users\Howrey\AppData\Local\funmoods.crx moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Howrey\Desktop\cmd.bat deleted successfully.
C:\Users\Howrey\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYJAVA]

User: Administrator

User: All Users

User: Default

User: Default User

User: Howrey
->Java cache emptied: 37459083 bytes

User: Public

Total Java Files Cleaned = 36.00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default
->Flash cache emptied: 56502 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Howrey
->Flash cache emptied: 179643 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.52.0 log created on 06242012_141220

#10 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:43 PM

Posted 24 June 2012 - 09:14 PM

greetings


I want you to uninstall chrome and if asked about user data or settings then remove those also


restart the computer and reinstall chrome and check for the hijack



gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#11 bhengr

bhengr
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 24 June 2012 - 09:47 PM

Hi Gringo,

Hijack is gone! Anything else that I need to do to make sure this thing is gone?

It was interesting that IE would not let me download chrome. I had to use Safari. Is IE somehow infected? Or is that just Bill Gates attempt to protect his billions?

Thank you, Bruce

#12 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:43 PM

Posted 24 June 2012 - 10:09 PM

Greetings,

There could be something with IE so lets reset it to be sure - let me know when this is complete and we will move on

first I would like you to go here and click on the fixit button - http://support.microsoft.com/kb/923737


Then I want you to do the following

  • Start Internet Explorer.
  • click on safety
  • click on delete browsing history
  • make sure all boxes are checked
  • click on Tools,
  • click Internet Options.
  • On the Advanced tab, click Reset
  • put a check mark next to Delete Personal Settings
  • click Reset to confirm
  • when complete click the close button
  • restart IE


Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#13 bhengr

bhengr
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 24 June 2012 - 10:27 PM

Hi Gringo,

Completed the IE fixit and then reset manually as you instructed. No issues with either!

Anything else I need to do? :)

Bruce

#14 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:43 PM

Posted 24 June 2012 - 10:37 PM

Hello

I Would like you to do the following.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links. I want you to save it to the desktop and run it from there.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#15 bhengr

bhengr
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 24 June 2012 - 11:24 PM

Hi Gringo,

Computer seems to be behaving normally. No issues running combofix. It did not require a reboot. Here is the log file.

Thanks, Bruce


ComboFix 12-06-23.05 - Howrey 06/25/2012 0:10.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3895.2530 [GMT -4:00]
Running from: c:\users\Howrey\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Howrey\AppData\Roaming\.#
.
.
((((((((((((((((((((((((( Files Created from 2012-05-25 to 2012-06-25 )))))))))))))))))))))))))))))))
.
.
2012-06-25 04:16 . 2012-06-25 04:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-25 04:16 . 2012-06-25 04:16 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-06-24 18:12 . 2012-06-24 18:12 -------- d-----w- C:\_OTL
2012-06-24 00:26 . 2012-06-25 03:51 -------- d-----w- c:\users\Howrey\AppData\Local\ID Vault
2012-06-24 00:26 . 2012-06-24 00:26 -------- d-----w- c:\programdata\IsolatedStorage
2012-06-24 00:25 . 2012-06-25 03:50 -------- d-----w- c:\users\Howrey\AppData\Roaming\ID Vault
2012-06-24 00:25 . 2012-06-24 00:25 -------- d-----w- c:\program files (x86)\xfin_portal
2012-06-24 00:25 . 2012-06-25 03:51 -------- d-----w- c:\program files (x86)\Constant Guard Protection Suite
2012-06-24 00:24 . 2012-06-24 00:24 -------- d-----w- c:\programdata\White Sky, Inc
2012-06-23 12:59 . 2012-06-23 12:59 476936 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-06-22 22:27 . 2012-06-22 22:27 388096 ----a-r- c:\users\Howrey\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-06-22 22:27 . 2012-06-22 22:27 -------- d-----w- c:\program files (x86)\Trend Micro
2012-06-22 21:45 . 2012-06-22 21:45 -------- d-----w- c:\users\Howrey\.smplayer
2012-06-22 16:47 . 2012-06-22 16:47 -------- d-----w- c:\programdata\boost_interprocess
2012-06-22 13:58 . 2012-06-22 16:42 -------- d-----w- c:\program files (x86)\OApps
2012-06-22 13:40 . 2012-06-22 13:40 -------- d-----w- c:\programdata\Graboid Inc
2012-06-22 13:39 . 2012-06-22 13:39 -------- d-----w- c:\users\Howrey\AppData\Local\Geckofx
2012-06-22 13:38 . 2012-06-22 13:38 -------- d-----w- c:\program files (x86)\VideoLAN
2012-06-22 13:19 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-22 13:19 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-22 13:19 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-22 13:19 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-22 13:19 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-22 13:19 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-22 13:19 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-22 13:18 . 2012-06-02 19:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-22 13:18 . 2012-06-02 19:15 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-06-13 11:37 . 2012-04-26 05:41 77312 ----a-w- c:\windows\system32\rdpwsx.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-23 12:59 . 2010-05-20 01:27 472840 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-04-17 14:27 . 2010-02-13 18:06 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2012-04-17 14:27 . 2010-04-12 00:33 4283672 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2012-04-17 14:27 . 2012-03-05 17:39 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2012-04-04 19:56 . 2010-02-13 20:02 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-30 11:35 . 2012-05-09 11:22 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-06-24_00.00.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2012-06-24 02:25 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-06-22 13:58 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-06-24 02:25 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-06-22 13:58 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-06-24 02:25 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-06-22 13:58 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-01-09 23:08 . 2012-06-25 03:55 61322 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-06-25 04:03 53082 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-02-11 02:22 . 2012-06-25 03:55 20278 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3097100386-4279238605-4106125582-1001_UserData.bin
- 2010-01-21 09:30 . 2012-06-23 13:35 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-01-21 09:30 . 2012-06-25 03:23 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-01-21 09:30 . 2012-06-23 13:35 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-01-21 09:30 . 2012-06-25 03:23 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-06-23 13:35 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-06-25 03:23 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-06-23 23:48 . 2012-06-23 23:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-06-25 04:01 . 2012-06-25 04:01 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-06-25 04:01 . 2012-06-25 04:01 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-06-23 23:48 . 2012-06-23 23:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2012-06-23 23:47 405728 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-06-25 04:00 405728 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-06-04 03:08 . 2012-06-25 02:54 931028 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3097100386-4279238605-4106125582-1001-12288.dat
- 2011-06-04 03:08 . 2011-09-28 00:07 931028 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3097100386-4279238605-4106125582-1001-12288.dat
+ 2010-02-11 02:54 . 2012-06-25 04:00 3357520 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2010-02-11 02:54 . 2012-06-25 04:00 6668076 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3097100386-4279238605-4106125582-1001-8192.dat
+ 2011-06-04 03:08 . 2012-06-25 03:30 3283547 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3097100386-4279238605-4106125582-1001-4096.dat
+ 2011-06-06 16:55 . 2011-06-06 16:55 1189004 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\JSByteCodeWin.bin
+ 2012-04-04 13:32 . 2012-04-04 13:32 16613376 c:\windows\Installer\2bec2.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Howrey\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Howrey\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Howrey\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-06-16 2736128]
"HPADVISOR"="c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-09-29 1685048]
"Akamai NetSession Interface"="c:\users\Howrey\AppData\Local\Akamai\netsession_win.exe" [2012-05-26 4327744]
"SansaDispatch"="c:\users\Howrey\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe" [2012-03-10 79872]
"MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HPCam_Menu"="c:\program files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-11-24 323640]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2010-03-23 500792]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\users\Howrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Howrey\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-9-4 1081632]
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-23 270336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x]
R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64k.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-02 225280]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\AESTSr64.exe [2009-03-03 89600]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-09 86072]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-10-01 2320920]
S3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [x]
S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-06-16 17:38 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3097100386-4279238605-4106125582-1001Core.job
- c:\users\Howrey\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-25 02:33]
.
2012-06-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3097100386-4279238605-4106125582-1001UA.job
- c:\users\Howrey\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-25 02:33]
.
2012-06-10 c:\windows\Tasks\HPCeeScheduleForHowrey.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 03:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Howrey\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Howrey\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Howrey\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Howrey\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-10-24 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-10-24 390168]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-10-24 408600]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2009-08-25 610872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-10 171520]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-05-21 2342800]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-05-26 2314120]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-07-29 497648]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-10-21 487424]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mStart Page =
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421;<local>
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_80c2ffa.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-06-25 00:18:38
ComboFix-quarantined-files.txt 2012-06-25 04:18
ComboFix2.txt 2012-06-24 00:02
.
Pre-Run: 314,744,745,984 bytes free
Post-Run: 314,716,602,368 bytes free
.
- - End Of File - - 2E24D70350E1DCECD8FE6EA75C0086D3




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users