<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Re: Is this PC infected?&#x27; in forum &#x27;Security Cleanup&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Re-Is-this-PC-infected-27324023</link>
<description></description>
<language>en</language>
<pubDate>Sun, 19 May 2013 17:14:10 EDT</pubDate>
<lastBuildDate>Sun, 19 May 2013 17:14:10 EDT</lastBuildDate>

<item>
<title>Re: Is this PC infected?</title>
<link>http://www.dslreports.com/forum/Re-Is-this-PC-infected-27330967</link>
<description><![CDATA[Jeffrey posted : Thank you very much for the help.  Much appreciated.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Is-this-PC-infected-27330967</guid>
<pubDate>Sun, 15 Jul 2012 13:18:19 EDT</pubDate>
</item>

<item>
<title>Re: Is this PC infected?</title>
<link>http://www.dslreports.com/forum/Re-Is-this-PC-infected-27330835</link>
<description><![CDATA[LoPhatPhuud posted : OK, we're finished. Cleanup instructions follow..<br><br><b>Cleaning Up:</b><br><br><i>Delete TFC</i>:<br><ul><li> Delete the TFC icon on your Desktop</ul><br><i>Delete OTL</i>:<br><ul><li> Double click the OTL icon on your Desktop<br><li> Press the 'Cleanup' button</ul>&#9;<br><i>Delete Security Check</i>:<br><ul><li> Delete the SecurityCheck icon on your Desktop</ul><br><i>Delete Malware Bytes</i>:<br><ul><li> We recommend that you keep MalwareBytes (MBAM) and run it every week. There is no charge to keep the program however the real time protection will stop after the trial period. Be sure to update the definitions before each use. If you decide not to keep MBAM, use Add/Remove Programs to uninstall it.</ul><br><i>Delete Sophos AntiRootkit</i><br><ul><li>If we asked you to run Sophos AntiRootkit program, uninstall it thru Add/Remove Programs.</ul><br><i>Other Programs</i>:<br><ul><li> If we asked you to install any other programs that are not removed by the OTL cleanup procedure, we will provide separate removal instructions.</ul><br><small>--<br>When angry count four; when very angry, swear.<br>Microsoft MVP/Consumer Security 2005-2011<br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Is-this-PC-infected-27330835</guid>
<pubDate>Sun, 15 Jul 2012 12:26:51 EDT</pubDate>
</item>

<item>
<title>Re: Is this PC infected?</title>
<link>http://www.dslreports.com/forum/Re-Is-this-PC-infected-27330802</link>
<description><![CDATA[Jeffrey posted : Here is the copy of the log from OTL after the last set of instructions.  It did ask for a reboot, so I did it.  Then on reboot, I Norton360 flagged OTL as a virus, which it wasn't, so I just had to deal with that.  (Oddly, 360 called OTL a virus from the first download link in the instructions at the top of this forum, but it called OTL "safe" from the second download link.)<br><br>Anyway, here is the OTL log that I found by going into Notepad and finding it in the _OTL folder from C:.<br><br><pre><br> <br>All processes killed<br>========== OTL ==========<br>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!<br>Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C04B7D22 -5AEC-4561-8F49-27F6269208F6}\ deleted successfully.<br>Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C04B7D22-5AEC-4561-8F49-27F6269208 F6}\ not found.<br>Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser  Helper Objects\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}\ deleted successfully.<br>Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B878 3A}\ deleted successfully.<br>Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{5BED3930- 2E9E-76D8-BACC-80DF2188D455} deleted successfully.<br>Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D4 55}\ deleted successfully.<br>Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\ {5BED3930-2E9E-76D8-BACC-80DF2188D455} deleted successfully.<br>Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D4 55}\ not found.<br>========== SERVICES/DRIVERS ==========<br>========== REGISTRY ==========<br>========== FILES ==========<br>========== COMMANDS ==========<br> <br>[EMPTYTEMP]<br> <br>User: All Users<br> <br>User: Default<br>->Temp folder emptied: 0 bytes<br>->Temporary Internet Files folder emptied: 0 bytes<br>->Flash cache emptied: 0 bytes<br> <br>User: Default User<br>->Temp folder emptied: 0 bytes<br>->Temporary Internet Files folder emptied: 0 bytes<br>->Flash cache emptied: 0 bytes<br> <br>User: kim<br>->Temp folder emptied: 6827635 bytes<br>->Temporary Internet Files folder emptied: 13028382 bytes<br>->Java cache emptied: 12049796 bytes<br>->Google Chrome cache emptied: 6260932 bytes<br>->Flash cache emptied: 107215 bytes<br> <br>User: Public<br> <br>%systemdrive% .tmp files removed: 0 bytes<br>%systemroot% .tmp files removed: 0 bytes<br>%systemroot%\System32 .tmp files removed: 0 bytes<br>%systemroot%\System32 (64bit) .tmp files removed: 12288 bytes<br>%systemroot%\System32\drivers .tmp files removed: 0 bytes<br>Windows Temp folder emptied: 851640 bytes<br>%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Inte rnet Files folder emptied: 36045734 bytes<br>RecycleBin emptied: 0 bytes<br> <br>Total Files Cleaned = 72.00 mb<br> <br> <br>[EMPTYFLASH]<br> <br>User: All Users<br> <br>User: Default<br>->Flash cache emptied: 0 bytes<br> <br>User: Default User<br>->Flash cache emptied: 0 bytes<br> <br>User: kim<br>->Flash cache emptied: 0 bytes<br> <br>User: Public<br> <br>Total Flash Files Cleaned = 0.00 mb<br> <br> <br>OTL by OldTimer - Version 3.2.53.1 log created on 07152012_085544<br> <br>Files\Folders moved on Reboot...<br>File move failed. C:\Users\kim\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be m oved on reboot.<br>C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\SN9D XSV9\ads[4].htm moved successfully.<br>C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\SN9D XSV9\ddc[1].htm moved successfully.<br>C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\J3B0 8Q6I\ads[2].htm moved successfully.<br>C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\J3B0 8Q6I\ads[3].htm moved successfully.<br>C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT mov ed successfully.<br>File move failed. C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Lo w\SuggestedSites.dat scheduled to be moved on reboot.<br> <br>PendingFileRenameOperations files...<br>[2012/07/14 16:07:01 | 000,000,000 | ---- | M] () C:\Users\kim\AppData\Local\Temp\FXSAPIDe bugLogFile.txt : Unable to obtain MD5<br>File C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 \SN9DXSV9\ads[4].htm not found!<br>File C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 \SN9DXSV9\ddc[1].htm not found!<br>File C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 \J3B08Q6I\ads[2].htm not found!<br>File C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 \J3B08Q6I\ads[3].htm not found!<br>File C:\Users\kim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DA T not found!<br>[2012/07/12 20:28:49 | 005,242,991 | ---- | M] () C:\Users\kim\AppData\Local\Microsoft\Win dows\Temporary Internet Files\Low\SuggestedSites.dat : Unable to obtain MD5<br> <br>Registry entries deleted on Reboot...<br></pre><br><br><small>--<br>He used to say that soul shine, is better than sunshine, better than moonshine, damn sure better than rain.<br><br><A HREF="http://www.2012hoax.org/">Debunking the 2012 hysteria.</a> | Always looking for a new job | Begging the Wilpons to sell the Mets.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Is-this-PC-infected-27330802</guid>
<pubDate>Sun, 15 Jul 2012 12:16:27 EDT</pubDate>
</item>

<item>
<title>Re: Is this PC infected?</title>
<link>http://www.dslreports.com/forum/Re-Is-this-PC-infected-27329419</link>
<description><![CDATA[LoPhatPhuud posted : OK, just some cleanup for junk the uninstallers dod not remove and we should be done.<br><br>Run OTL<br><UL TYPE=SQUARE><br>[*]Under the <b>Custom Scans/Fixes</b> box at the bottom, copy and paste the contents of the following box:<br><br><div class="code"><span class="codetext"><br>:OTL<br>IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = »toolbar.inbox.com/ search/dispatcher.aspx?tp=aus&qkw=%s&tbid=%tb_id&%language<br>IE - HKCU\..\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}: "URL" = »toolbar.i nbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=80110&lng=en<br>O2 - BHO: (TTB000000 Class) - {62960D20-6D0D-1AB4-4BF1-95B0B5B8783A} - C:\Users\kim\AppDat a\Local\Temp\low\COUPON~1.DLL File not found<br>O3 - HKLM\..\Toolbar: (CouponBar) - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - C:\Users\kim\ AppData\Local\Temp\low\CouponsBar.dll File not found<br>O3 - HKCU\..\Toolbar\WebBrowser: (CouponBar) - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - C: \Users\kim\AppData\Local\Temp\low\CouponsBar.dll File not found<br><br>:Services<br><br>:Reg<br><br>:Files<br><br>:Commands<br>[purity]<br>[emptytemp]<br>[EMPTYFLASH]<br>[Reboot]<br></span></div><br><br>[*]Then click the <b>Run Fix</b> button at the top<br>[*]Let the program run unhindered, reboot the PC when it is done<br>[*]Once you see a message box "Fix complete! Click OK to open the fix log."<br>[*]Click the OK button<br>[*]The log will open in Notepad (your default text editor).<br>{*]Save the log. Post a copy of that log in your next reply.<br></UL><br><br>Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process.<br><br>If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start-All Programs-Accessories-Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.<br><small>--<br>When angry count four; when very angry, swear.<br>Microsoft MVP/Consumer Security 2005-2011<br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Is-this-PC-infected-27329419</guid>
<pubDate>Sat, 14 Jul 2012 17:19:03 EDT</pubDate>
</item>

<item>
<title>Re: Is this PC infected?</title>
<link>http://www.dslreports.com/forum/Re-Is-this-PC-infected-27329363</link>
<description><![CDATA[Jeffrey posted : Thank you.  I removed that program, and here is the new OTL log.<br><br> <br>OTL logfile created on: 7/14/2012 4:10:41 PM - Run 2<br>OTL by OldTimer - Version 3.2.54.0     Folder = C:\Users\kim\Desktop<br>64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation<br>Internet Explorer (Version = 9.0.8112.16421)<br>Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br> <br>3.99 Gb Total Physical Memory | 2.41 Gb Available Physical Memory | 60.43% Memory free<br>7.98 Gb Paging File | 6.30 Gb Available in Paging File | 79.01% Paging File free<br>Paging file location(s): ?:\pagefile.sys [binary data]<br> <br>%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)<br>Drive C: | 453.72 Gb Total Space | 400.16 Gb Free Space | 88.20% Space Free | Partition Ty pe: NTFS<br>Drive D: | 11.95 Gb Total Space | 2.17 Gb Free Space | 18.19% Space Free | Partition Type:  NTFS<br> <br>Computer Name: KIM-PC | User Name: kim | Logged in as Administrator.<br>Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans<br>Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On |  File Age = 30 Days<br> <br>[color=#E56717]========== Processes (SafeList) ==========[/color]<br> <br>PRC - [2012/07/12 20:26:39 | 000,686,280 | ---- | M] (Adobe Systems Incorporated) -- C:\Wi ndows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_265_ActiveX.exe<br>PRC - [2012/07/11 21:46:46 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\kim\Desk top\OTL.exe<br>PRC - [2012/02/24 09:09:05 | 000,307,824 | ---- | M] (Google Inc.) -- C:\Program Files (x8 6)\Google\Google Toolbar\GoogleToolbarUser_32.exe<br>PRC - [2011/04/16 20:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) -- C:\Program  Files (x86)\Norton 360\Engine\5.2.2.3\ccsvchst.exe<br>PRC - [2011/03/28 18:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) -- C:\Progr am Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe<br>PRC - [2010/07/12 12:53:00 | 000,399,032 | ---- | M] (Cisco Systems, Inc.) -- C:\Program F iles (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe<br>PRC - [2010/03/03 20:16:06 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Fil es (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe<br>PRC - [2010/03/03 20:16:04 | 000,284,696 | ---- | M] (Intel Corporation) -- C:\Program Fil es (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe<br>PRC - [2009/12/01 20:49:52 | 000,210,216 | ---- | M] (CyberLink) -- c:\Program Files (x86) \Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe<br>PRC - [2009/10/20 14:50:34 | 000,128,296 | ---- | M] (CyberLink Corp.) -- c:\Program Files  (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe<br>PRC - [2009/06/03 15:35:16 | 000,430,080 | ---- | M] (Hewlett-Packard Company) -- C:\Progr am Files (x86)\PictureMover\Bin\PictureMover.exe<br>PRC - [2009/05/26 04:36:13 | 000,656,896 | ---- | M] () -- C:\Program Files (x86)\Hewlett- Packard\HP Remote Solution\HP_Remote_Solution.exe<br>PRC - [2009/03/17 04:26:16 | 000,759,728 | ---- | M] (Skinkers Communications) -- C:\Progr am Files (x86)\American Airlines DealFinder\American_Airlines_DealFinder.exe<br>PRC - [2008/11/20 13:47:28 | 000,062,768 | ---- | M] (Hewlett-Packard) -- C:\Program Files  (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe<br> <br> <br>[color=#E56717]========== Modules (No Company Name) ==========[/color]<br> <br>MOD - [2012/06/15 07:47:54 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms .ni.dll<br>MOD - [2012/06/14 08:25:17 | 014,340,608 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramewor k.ni.dll<br>MOD - [2012/06/14 08:25:01 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll<br>MOD - [2012/06/14 08:24:57 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll<br>MOD - [2012/05/12 09:54:36 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dl l<br>MOD - [2012/05/12 09:54:35 | 000,452,608 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\IAStorUtil\635b3aec298ad5e8c903b2323d79cc5a\IAStorUtil.ni.dll<br>MOD - [2012/05/12 09:49:50 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramewor k.Aero.ni.dll<br>MOD - [2012/05/12 09:49:37 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remot ing.ni.dll<br>MOD - [2012/05/12 09:49:36 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll<br>MOD - [2012/05/12 09:49:11 | 000,185,344 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\UIAutomationTypes\d8af9a65cf0ed85d47360796e2645a06\UIAutomationTypes.ni.dl l<br>MOD - [2012/05/12 09:49:03 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll<br>MOD - [2012/05/12 09:48:59 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll<br>MOD - [2012/05/12 09:48:56 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration .ni.dll<br>MOD - [2012/05/12 09:48:55 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll<br>MOD - [2012/05/12 09:48:50 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImage s_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll<br>MOD - [2012/02/07 09:00:21 | 000,036,920 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\HP .ActiveSupportLibrary\2.0.0.1__01a974bc1760f423\HP.ActiveSupportLibrary.dll<br>MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common F iles\Apple\Apple Application Support\zlib1.dll<br>MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common F iles\Apple\Apple Application Support\libxml2.dll<br>MOD - [2010/11/04 21:58:05 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\Syst em.Data\2.0.0.0__b77a5c561934e089\System.Data.dll<br>MOD - [2010/06/30 00:12:54 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Hewlett- Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll<br>MOD - [2010/06/30 00:12:52 | 000,131,072 | ---- | M] () -- C:\Program Files (x86)\Hewlett- Packard\HP Advisor\Pillars\ECenter\ECLibrary.dll<br>MOD - [2010/06/30 00:12:42 | 000,040,960 | ---- | M] () -- C:\Program Files (x86)\Hewlett- Packard\HP Advisor\MessagingServer.dll<br>MOD - [2010/06/30 00:12:40 | 000,036,864 | ---- | M] () -- C:\Program Files (x86)\Hewlett- Packard\HP Advisor\MessagingClients.dll<br>MOD - [2010/06/30 00:12:40 | 000,007,680 | ---- | M] () -- C:\Program Files (x86)\Hewlett- Packard\HP Advisor\RemotingClient.dll<br>MOD - [2010/06/30 00:12:40 | 000,005,632 | ---- | M] () -- C:\Program Files (x86)\Hewlett- Packard\HP Advisor\MessagingInterface.dll<br>MOD - [2010/06/30 00:12:36 | 000,018,944 | ---- | M] () -- C:\Program Files (x86)\Hewlett- Packard\HP Advisor\MessagingMessages.dll<br>MOD - [2010/06/30 00:12:18 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Hewlett- Packard\HP Advisor\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll<br>MOD - [2009/12/01 20:49:50 | 000,931,112 | ---- | M] () -- c:\Program Files (x86)\Hewlett- Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll<br>MOD - [2009/07/13 21:15:45 | 000,364,544 | ---- | M] () -- C:\Windows\SysWOW64\msjetoledb4 0.dll<br>MOD - [2009/06/03 15:43:14 | 001,703,936 | ---- | M] () -- C:\Users\kim\AppData\Roaming\Pi ctureMover\EN-US\Presentation.dll<br>MOD - [2009/06/03 15:34:18 | 003,764,224 | ---- | M] () -- C:\Users\kim\AppData\Roaming\Pi ctureMover\Bin\Core.dll<br>MOD - [2009/05/26 04:36:13 | 000,656,896 | ---- | M] () -- C:\Program Files (x86)\Hewlett- Packard\HP Remote Solution\HP_Remote_Solution.exe<br> <br> <br>[color=#E56717]========== Win32 Services (SafeList) ==========[/color]<br> <br>SRV:<b>64bit:</b> - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation)  [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)<br>SRV - [2012/07/12 20:26:39 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Dema nd | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (Adobe FlashPlayerUpdateSvc)<br>SRV - [2012/02/15 14:30:18 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped]  -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)<br>SRV - [2011/09/09 18:10:28 | 000,086,072 | ---- | M] (Hewlett-Packard Company) [Auto | Run ning] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- ( HP Support Assistant Service)<br>SRV - [2011/04/16 20:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) [Auto | Runnin g] -- C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe -- (N360)<br>SRV - [2011/03/28 18:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) [Auto | Run ning] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe )<br>SRV - [2010/07/12 12:53:00 | 000,399,032 | ---- | M] (Cisco Systems, Inc.) [Auto | Running ] -- C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent)<br>SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopp ed] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4. 0.30319_32)<br>SRV - [2010/03/03 20:16:06 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running]  -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe --  (IAStorDataMgrSvc) Intel(R)<br>SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | S topped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization _v2.0.50727_32)<br>SRV - [2009/05/22 14:02:20 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stop ped] -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe -- (GameCon soleService)<br> <br> <br>[color=#E56717]========== Driver Services (SafeList) ==========[/color]<br> <br>DRV:<b>64bit:</b> - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation)  [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)<br>DRV:<b>64bit:</b> - [2011/07/10 13:58:01 | 000,174,200 | ---- | M] (Symantec Corporation)  [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEv ent)<br>DRV:<b>64bit:</b> - [2011/07/06 12:44:00 | 000,034,288 | ---- | M] (GEAR Software Inc.) [K ernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiW DM)<br>DRV:<b>64bit:</b> - [2011/04/20 21:37:49 | 000,386,168 | ---- | M] (Symantec Corporation)  [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0502020.003\symnets.sy s -- (SymNetS)<br>DRV:<b>64bit:</b> - [2011/03/30 23:00:09 | 000,744,568 | R--- | M] (Symantec Corporation)  [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\N360x64\0502020.003\sr tsp64.sys -- (SRTSP)<br>DRV:<b>64bit:</b> - [2011/03/30 23:00:09 | 000,040,568 | R--- | M] (Symantec Corporation)  [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0502020.003\srtspx64.s ys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)<br>DRV:<b>64bit:</b> - [2011/03/14 22:31:23 | 000,912,504 | R--- | M] (Symantec Corporation)  [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\0502020.003\symefa6 4.sys -- (SymEFA)<br>DRV:<b>64bit:</b> - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)<br>DRV:<b>64bit:</b> - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)<br>DRV:<b>64bit:</b> - [2011/02/18 16:36:58 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel |  On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)<br>DRV:<b>64bit:</b> - [2011/01/27 02:47:10 | 000,450,680 | R--- | M] (Symantec Corporation)  [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\0502020.003\symds64.sys  -- (SymDS)<br>DRV:<b>64bit:</b> - [2011/01/27 01:07:06 | 000,171,128 | R--- | M] (Symantec Corporation)  [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0502020.003\ironx64.sy s -- (SymIRON)<br>DRV:<b>64bit:</b> - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Compan y) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)<br>DRV:<b>64bit:</b> - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation)  [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) <br>DRV:<b>64bit:</b> - [2010/07/12 12:53:00 | 000,027,640 | ---- | M] (Cisco Systems, Inc.) [ Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpnva64.sys -- (vpnva)<br>DRV:<b>64bit:</b> - [2010/05/26 10:39:08 | 000,006,144 | ---- | M] (Sophos Plc) [Kernel |  On_Demand | Stopped] -- C:\Windows\SysNative\9DEE.tmp -- (MEMSWEEP2)<br>DRV:<b>64bit:</b> - [2010/03/03 19:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Ke rnel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)<br>DRV:<b>64bit:</b> - [2009/08/20 20:05:06 | 000,239,616 | ---- | M] (Realtek                                             ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\driv ers\Rt64win7.sys -- (RTL8167)<br>DRV:<b>64bit:</b> - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.)  [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)<br>DRV:<b>64bit:</b> - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kern el | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)<br>DRV:<b>64bit:</b> - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [K ernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)<br>DRV:<b>64bit:</b> - [2009/06/16 07:32:14 | 006,112,672 | ---- | M] (Intel Corporation) [Ke rnel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)<br>DRV:<b>64bit:</b> - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation)  [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)<br>DRV:<b>64bit:</b> - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation)  [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)<br>DRV:<b>64bit:</b> - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation)  [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)<br>DRV:<b>64bit:</b> - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Wor ks, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- ( hcw85cir)<br>DRV - [2012/06/18 20:01:13 | 001,161,376 | ---- | M] (Symantec Corporation) [Kernel | Syst em | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.2 9\Definitions\BASHDefs\20120711.002\BHDrvx64.sys -- (BHDrvx64)<br>DRV - [2012/06/14 14:39:24 | 000,509,088 | ---- | M] (Symantec Corporation) [Kernel | Syst em | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.2 9\Definitions\IPSDefs\20120713.001\IDSviA64.sys -- (IDSVia64)<br>DRV - [2012/05/31 08:06:57 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | Syst em | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys  -- (eeCtrl)<br>DRV - [2012/05/31 08:06:57 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_D emand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtil RebootDrv.sys -- (EraserUtilRebootDrv)<br>DRV - [2012/05/15 22:10:35 | 002,068,600 | ---- | M] (Symantec Corporation) [Kernel | On_D emand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1. 0.29\Definitions\VirusDefs\20120713.035\ex64.sys -- (NAVEX15)<br>DRV - [2012/05/15 22:10:35 | 000,120,440 | ---- | M] (Symantec Corporation) [Kernel | On_D emand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1. 0.29\Definitions\VirusDefs\20120713.035\eng64.sys -- (NAVENG)<br>DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System  | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)<br> <br> <br>[color=#E56717]========== Standard Registry (SafeList) ==========[/color]<br> <br> <br>[color=#E56717]========== Internet Explorer ==========[/color]<br> <br>IE:<b>64bit:</b> - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http: //ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt<br>IE:<b>64bit:</b> - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.r" >ie.r</A> edirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt<br>IE:<b>64bit:</b> - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA99 90}<br>IE:<b>64bit:</b> - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = ht tp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?} &ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7<br>IE:<b>64bit:</b> - HKLM\..\SearchScopes\{A8ED5BDF-C010-494C-B6B3-DD198D35270D}: "URL" = ht tp://www.ask.com/web?q={searchterms}&l=dis&o=ushpd<br>IE:<b>64bit:</b> - HKLM\..\SearchScopes\{E715678E-6F58-4CEF-AB9F-F1F4D371F022}: "URL" = ht tp://www.bing.com/search?q={searchTerms}&FORM=HPDTDF&pc=HPDTDF&src=IE-SearchBox<br>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect" >ie.redirect</A>. hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt<br>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank .htm<br>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com" >ie.redirect.hp.com</A> /svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt<br>IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}<br>IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = &raquo;<A HREF="http://www.googl" >www.googl</A> e.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEnco ding}&oe={outputEncoding}&sourceid=ie7<br>IE - HKLM\..\SearchScopes\{A8ED5BDF-C010-494C-B6B3-DD198D35270D}: "URL" = &raquo;<A HREF="http://www.ask.c" >www.ask.c</A> om/web?q={searchterms}&l=dis&o=ushpd<br>IE - HKLM\..\SearchScopes\{E715678E-6F58-4CEF-AB9F-F1F4D371F022}: "URL" = &raquo;<A HREF="http://www.bing" >www.bing</A>. com/search?q={searchTerms}&FORM=HPDTDF&pc=HPDTDF&src=IE-SearchBox<br> <br>IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect" >ie.redirect</A>. hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt<br>IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://toolbar.inbox.com/" >toolbar.inbox.com/</A> search/dispatcher.aspx?tp=aus&qkw=%s&tbid=%tb_id&%language<br>IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com" >ie.redirect.hp.com</A> /svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt<br>IE - HKCU\..\URLSearchHook: {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No CLSID value found<br>IE - HKCU\..\SearchScopes,DefaultScope = {E715678E-6F58-4CEF-AB9F-F1F4D371F022}<br>IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = &raquo;<A HREF="http://www.googl" >www.googl</A> e.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEnco ding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_en<br>IE - HKCU\..\SearchScopes\{A8ED5BDF-C010-494C-B6B3-DD198D35270D}: "URL" = &raquo;<A HREF="http://www.ask.c" >www.ask.c</A> om/web?q={searchterms}&l=dis&o=ushpd<br>IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = &raquo;<A HREF="http://www.ask.c" >www.ask.c</A> om/web?q={SEARCHTERMS}&o=15527&l=dis&prt=360&chn=retail&geo=US&ver=5<br>IE - HKCU\..\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}: "URL" = &raquo;<A HREF="http://toolbar.i" >toolbar.i</A> nbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=80110&lng=en<br>IE - HKCU\..\SearchScopes\{E715678E-6F58-4CEF-AB9F-F1F4D371F022}: "URL" = &raquo;<A HREF="http://www.bing" >www.bing</A>. com/search?q={searchTerms}&FORM=HPDTDF&pc=HPDTDF&src=IE-SearchBox<br>IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0<br>IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = * .local<br> <br> <br>[color=#E56717]========== FireFox ==========[/color]<br> <br>FF:<b>64bit:</b> - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not  found<br>FF:<b>64bit:</b> - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Prog ram Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)<br>FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found<br>FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iT unes\Mozilla Plugins\npitunes.dll ()<br>FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Go ogle\Google Earth\plugin\npgeplugin.dll (Google)<br>FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\b in\new_plugin\npjp2.dll (Sun Microsystems, Inc.)<br>FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found<br>FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86 )\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)<br>FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Fi les (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)<br>FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Fi les (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)<br>FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Re ader\AIR\nppdf32.dll (Adobe Systems Inc.)<br> <br>FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-4176 4D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSF FPlgn\ [2012/05/04 11:50:39 | 000,000,000 | ---D | M]<br>FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2 F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFF Plgn_2011_7_9_4 [2012/07/14 15:46:50 | 000,000,000 | ---D | M]<br> <br> <br>[color=#E56717]========== Chrome  ==========[/color]<br> <br>CHR - homepage: &raquo;<A HREF="http://www.google.com/" >www.google.com/</A><br> <br>O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\dri vers\etc\hosts<br>O2:<b>64bit:</b> - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} -  C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)<br>O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files ( x86)\Norton 360\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)<br>O2 - BHO: (TTB000000 Class) - {62960D20-6D0D-1AB4-4BF1-95B0B5B8783A} - C:\Users\kim\AppDat a\Local\Temp\low\COUPON~1.DLL File not found<br>O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Pr ogram Files (x86)\Norton 360\Engine\5.2.2.3\ips\ipsbho.dll (Symantec Corporation)<br>O2 - BHO: (hpBHO Class) - {ABD3B5E1-B268-407B-A150-2641DAB8D898} - C:\Program Files (x86)\ Common Files\Homepage Protection\HomepageProtection.dll (AOL Products)<br>O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Fil es (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)<br>O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f}  - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)<br>O3:<b>64bit:</b> - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD 4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)<br>O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8 414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)<br>O3 - HKLM\..\Toolbar: (CouponBar) - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - C:\Users\kim\ AppData\Local\Temp\low\CouponsBar.dll File not found<br>O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Progr am Files (x86)\Norton 360\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)<br>O3:<b>64bit:</b> - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18 -009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google  Inc.)<br>O3 - HKCU\..\Toolbar\WebBrowser: (CouponBar) - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - C: \Users\kim\AppData\Local\Temp\low\CouponsBar.dll File not found<br>O4:<b>64bit:</b> - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corpora tion)<br>O4:<b>64bit:</b> - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corpora tion)<br>O4:<b>64bit:</b> - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corp oration)<br>O4:<b>64bit:</b> - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\ SmartMenu.exe ()<br>O4 - HKLM..\Run: []  File not found<br>O4 - HKLM..\Run: [American Airlines DealFinder] C:\Program Files (x86)\American Airlines D ealFinder\American_Airlines_DealFinder.exe (Skinkers Communications)<br>O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application S upport\APSDaemon.exe (Apple Inc.)<br>O4 - HKLM..\Run: [HP Remote Solution] C:\Program Files (x86)\Hewlett-Packard\HP Remote Sol ution\HP_Remote_Solution.exe ()<br>O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.ex e (Hewlett-Packard)<br>O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technolo gy\IAStorIcon.exe (Intel Corporation)<br>O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Onlin e Backup\Activation\NobuActivation.exe (Symantec Corporation)<br>O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITr ansfer\MUIStartMenu.exe (CyberLink Corp.)<br>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1<br>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChan ges = 1<br>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehavior Admin = 5<br>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehavior User = 3<br>O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Progr am Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A. )<br>O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5}  - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Techno logies S.A.)<br>O10:<b>64bit:</b> - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program File s\Bonjour\mdnsNSP.dll (Apple Inc.)<br>O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\ mdnsNSP.dll (Apple Inc.)<br>O13<b>64bit:</b> - gopher Prefix: missing<br>O13 - gopher Prefix: missing<br>O16 - DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} &raquo;<A HREF="https://access.ise.com/CACHE/stc/2/binar" >access.ise.com/CACHE/stc/2/binar</A> ies/vpnweb.cab (Cisco AnyConnect VPN Client Web Control)<br>O16 - DPF: {705EC6D4-B138-4079-A307-EF13E4889A82} &raquo;<A HREF="https://access.ise.com/CACHE/sdesktop/in" >access.ise.com/CACHE/sdesktop/in</A> stall/binaries/instweb.cab (CSD ActiveX Installer)<br>O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} &raquo;<A HREF="http://download.eset.com/special/eos/Onl" >download.eset.com/special/eos/Onl</A> ineScanner.cab (OnlineScanner Control)<br>O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} &raquo;<A HREF="http://java.sun.com/update/1.6.0/jinstal" >java.sun.com/update/1.6.0/jinstal</A> l-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)<br>O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} &raquo;<A HREF="http://java.sun.com/update/1.6.0/jinstal" >java.sun.com/update/1.6.0/jinstal</A> l-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)<br>O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} &raquo;<A HREF="http://java.sun.com/update/1.6.0/jinstal" >java.sun.com/update/1.6.0/jinstal</A> l-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)<br>O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} &raquo;<A HREF="http://platformdl.adobe.com/NOS/getPlusP" >platformdl.adobe.com/NOS/getPlusP</A> lus/1.6/gp.cab (Reg Error: Key error.)<br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 208.67.22 0.220 167.206.254.1<br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EAAA253F-3C4D-4C3F-BE1D-913601 7FB020}: DhcpNameServer = 208.67.222.222 208.67.220.220 167.206.254.1<br>O18:<b>64bit:</b> - Protocol\Handler\ms-itss - No CLSID value found<br>O18:<b>64bit:</b> - Protocol\Handler\skype4com - No CLSID value found<br>O18:<b>64bit:</b> - Protocol\Handler\skype-ie-addon-data - No CLSID value found<br>O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files  (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)<br>O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Pro gram Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S. A.)<br>O20:<b>64bit:</b> - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Micro soft Corporation)<br>O20:<b>64bit:</b> - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Wind ows\SysNative\userinit.exe (Microsoft Corporation)<br>O20:<b>64bit:</b> - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windo ws\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)<br>O20:<b>64bit:</b> - HKLM Winlogon: VMApplet - (/pagefile) -  File not found<br>O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft  Corporation)<br>O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microso ft Corporation)<br>O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found<br>O20:<b>64bit:</b> - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNativ e\igfxdev.dll (Intel Corporation)<br>O21:<b>64bit:</b> - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID va lue found.<br>O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.<br>O32 - HKLM CDRom: AutoRun - 1<br>O33 - MountPoints2\{708dab56-26f5-11e1-9dd6-90e6ba13fd8e}\Shell - "" = AutoRun<br>O33 - MountPoints2\{708dab56-26f5-11e1-9dd6-90e6ba13fd8e}\Shell\AutoRun\command - "" = J:\ TL_Bootstrap.exe<br>O34 - HKLM BootExecute: (autocheck autochk *)<br>O35:<b>64bit:</b> - HKLM\..comfile [open] -- "%1" %*<br>O35:<b>64bit:</b> - HKLM\..exefile [open] -- "%1" %*<br>O35 - HKLM\..comfile [open] -- "%1" %*<br>O35 - HKLM\..exefile [open] -- "%1" %*<br>O37:<b>64bit:</b> - HKLM\...com [@ = comfile] -- "%1" %*<br>O37:<b>64bit:</b> - HKLM\...exe [@ = exefile] -- "%1" %*<br>O37 - HKLM\...com [@ = comfile] -- "%1" %*<br>O37 - HKLM\...exe [@ = exefile] -- "%1" %*<br>O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)<br>O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)<br>O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)<br> <br>[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]<br> <br>[2012/07/13 18:54:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start M enu\Programs\Sophos<br>[2012/07/13 18:54:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sophos<br>[2012/07/12 20:26:39 | 000,426,184 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\ SysWow64\FlashPlayerApp.exe<br>[2012/07/11 21:54:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET<br>[2012/07/11 21:50:16 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\mshtmled.dll<br>[2012/07/11 21:50:16 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWo w64\mshtmled.dll<br>[2012/07/11 21:50:15 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\ieui.dll<br>[2012/07/11 21:50:15 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\url.dll<br>[2012/07/11 21:50:15 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWo w64\url.dll<br>[2012/07/11 21:50:15 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWo w64\ieui.dll<br>[2012/07/11 21:50:14 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\ieUnatt.exe<br>[2012/07/11 21:50:14 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWo w64\ieUnatt.exe<br>[2012/07/11 21:50:13 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\jscript9.dll<br>[2012/07/11 21:50:13 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\inetcpl.cpl<br>[2012/07/11 21:50:13 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWo w64\inetcpl.cpl<br>[2012/07/11 21:50:13 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\jscript.dll<br>[2012/07/11 21:50:13 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWo w64\jscript.dll<br>[2012/07/11 21:46:46 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\kim\Desktop\OT L.exe<br>[2012/07/11 21:22:08 | 000,000,000 | ---D | C] -- C:\Users\kim\AppData\Roaming\Malwarebyte s<br>[2012/07/11 21:22:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start M enu\Programs\Malwarebytes' Anti-Malware<br>[2012/07/11 21:22:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes<br>[2012/07/11 21:22:02 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\Sy sNative\drivers\mbam.sys<br>[2012/07/11 21:22:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Ant i-Malware<br>[2012/07/11 21:16:00 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\ncrypt.dll<br>[2012/07/11 21:15:57 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWo w64\msxml3r.dll<br>[2012/07/11 21:15:57 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\msxml3r.dll<br>[2012/07/11 21:15:53 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\cdosys.dll<br>[2012/07/11 21:15:53 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWo w64\cdosys.dll<br>[2012/07/02 09:34:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start M enu\Programs\QuickTime<br>[2012/06/21 07:42:05 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\wucltux.dll<br>[2012/06/21 07:42:05 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\wuauclt.exe<br>[2012/06/21 07:42:05 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\wups2.dll<br>[2012/06/21 07:41:54 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\wuapi.dll<br>[2012/06/21 07:41:54 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\wudriver.dll<br>[2012/06/21 07:41:54 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\wups.dll<br>[2012/06/21 07:41:43 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\wuwebv.dll<br>[2012/06/21 07:41:43 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNa tive\wuapp.exe<br>[2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]<br> <br>[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]<br> <br>[2012/07/14 16:06:50 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMach ineCore.job<br>[2012/07/14 15:54:01 | 000,015,984 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-49 7e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0<br>[2012/07/14 15:54:01 | 000,015,984 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-49 7e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0<br>[2012/07/14 15:53:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMach ineUA.job<br>[2012/07/14 15:50:57 | 000,726,444 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup .INI<br>[2012/07/14 15:50:57 | 000,624,162 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat<br>[2012/07/14 15:50:57 | 000,106,538 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat<br>[2012/07/14 15:46:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat<br>[2012/07/14 15:46:38 | 3213,537,280 | -HS- | M] () -- C:\hiberfil.sys<br>[2012/07/14 15:45:31 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player U pdater.job<br>[2012/07/13 18:53:16 | 000,000,000 | ---- | M] () -- C:\install.rdf<br>[2012/07/12 20:26:39 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\ SysWow64\FlashPlayerApp.exe<br>[2012/07/12 20:26:39 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\ SysWow64\FlashPlayerCPLApp.cpl<br>[2012/07/12 20:25:39 | 000,329,176 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT<br>[2012/07/11 21:46:46 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\kim\Desktop\OT L.exe<br>[2012/07/11 21:44:59 | 000,001,180 | ---- | M] () -- C:\Users\kim\Desktop\My Pictures - Sh ortcut.lnk<br>[2012/07/11 21:44:55 | 000,001,153 | ---- | M] () -- C:\Users\kim\Desktop\My Music - Short cut.lnk<br>[2012/07/11 21:44:47 | 000,001,193 | ---- | M] () -- C:\Users\kim\Desktop\My Documents - S hortcut.lnk<br>[2012/07/11 21:22:03 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes  Anti-Malware.lnk<br>[2012/07/11 21:21:43 | 000,002,016 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader  9.lnk<br>[2012/07/04 10:11:21 | 000,000,324 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForkim. job<br>[2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\Sy sNative\drivers\mbam.sys<br>[2012/07/02 09:34:24 | 000,001,847 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Pla yer.lnk<br>[2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]<br> <br>[color=#E56717]========== Files Created - No Company Name ==========[/color]<br> <br>[2012/07/13 18:53:16 | 000,000,000 | ---- | C] () -- C:\install.rdf<br>[2012/07/12 20:26:41 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player U pdater.job<br>[2012/07/11 21:44:59 | 000,001,180 | ---- | C] () -- C:\Users\kim\Desktop\My Pictures - Sh ortcut.lnk<br>[2012/07/11 21:44:55 | 000,001,153 | ---- | C] () -- C:\Users\kim\Desktop\My Music - Short cut.lnk<br>[2012/07/11 21:44:47 | 000,001,193 | ---- | C] () -- C:\Users\kim\Desktop\My Documents - S hortcut.lnk<br>[2012/07/11 21:22:03 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes  Anti-Malware.lnk<br>[2012/07/11 21:21:12 | 000,002,016 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader  9.lnk<br>[2012/07/11 21:21:11 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Star t Menu\Programs\Adobe Reader 9.lnk<br>[2012/07/02 09:34:24 | 000,001,847 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Pla yer.lnk<br>[2012/01/21 13:10:43 | 000,014,358 | ---- | C] () -- C:\Users\kim\AppData\Local\tmpDOWNSIZ ED_0120122136[1]_navi.JPG<br>[2012/01/21 13:10:30 | 000,029,401 | ---- | C] () -- C:\Users\kim\AppData\Local\tmpDOWNSIZ ED_0120122136[1].JPG<br>[2012/01/21 13:10:30 | 000,028,104 | ---- | C] () -- C:\Users\kim\AppData\Local\tmpDOWNSIZ ED_0120122136[1].0<br>[2011/11/13 21:08:36 | 001,939,766 | ---- | C] () -- C:\Users\kim\AppData\Local\tmpM,ANNUA LHEALTHASSESS.0<br>[2011/11/13 21:08:36 | 000,407,504 | ---- | C] () -- C:\Users\kim\AppData\Local\tmpM,ANNUA LHEALTHASSESS.JPG<br>[2011/05/15 22:10:07 | 000,001,854 | ---- | C] () -- C:\Users\kim\AppData\Roaming\GhostObj GAFix.xml<br>[2010/08/15 10:02:13 | 000,001,212 | ---- | C] () -- C:\Users\kim\AppData\Roaming\wklnhst. dat<br>[2009/11/08 10:14:39 | 000,129,173 | ---- | C] () -- C:\Users\kim\AppData\Local\tmpHWEEN3[ 1].JPG<br> <br>[color=#E56717]========== LOP Check ==========[/color]<br> <br>[2009/12/31 22:17:40 | 000,000,000 | ---D | M] -- C:\Users\kim\AppData\Roaming\American Ai rlines DealFinder<br>[2011/07/31 11:13:04 | 000,000,000 | ---D | M] -- C:\Users\kim\AppData\Roaming\com.adobe.m auby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1<br>[2009/11/01 20:47:07 | 000,000,000 | ---D | M] -- C:\Users\kim\AppData\Roaming\PictureMove r<br>[2010/08/15 10:02:14 | 000,000,000 | ---D | M] -- C:\Users\kim\AppData\Roaming\Template<br>[2009/11/16 17:47:14 | 000,000,000 | ---D | M] -- C:\Users\kim\AppData\Roaming\WinBatch<br>[2012/05/01 07:55:50 | 000,000,552 | ---- | M] () -- C:\Windows\Tasks\PCDRScheduledMainten ance.job<br>[2011/09/16 21:23:19 | 000,032,646 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT<br> <br>[color=#E56717]========== Purity Check ==========[/color]<br> <br> <br> End of report <br> <br><br><small>--<br>He used to say that soul shine, is better than sunshine, better than moonshine, damn sure better than rain.<br><br><A HREF="http://www.2012hoax.org/">Debunking the 2012 hysteria.</a> | Always looking for a new job | Begging the Wilpons to sell the Mets.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Is-this-PC-infected-27329363</guid>
<pubDate>Sat, 14 Jul 2012 16:55:44 EDT</pubDate>
</item>

<item>
<title>Re: Is this PC infected?</title>
<link>http://www.dslreports.com/forum/Re-Is-this-PC-infected-27328768</link>
<description><![CDATA[LoPhatPhuud posted : Everything looks ok. <br><br>One more item to remove via Add/Remove Programs:<br>Inbox Toolbar<br><br>Once you have  that removed, run OTL again, and post the new log in this thread. Note that there will not be a new Extras log.<br><small>--<br>When angry count four; when very angry, swear.<br>Microsoft MVP/Consumer Security 2005-2011<br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Is-this-PC-infected-27328768</guid>
<pubDate>Sat, 14 Jul 2012 11:19:32 EDT</pubDate>
</item>

<item>
<title>Re: Is this PC infected?</title>
<link>http://www.dslreports.com/forum/Re-Is-this-PC-infected-27328738</link>
<description><![CDATA[Jeffrey posted : <div class="bquote"><said>said by <a href="/profile/555588" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=555588');">LoPhatPhuud</a>:</said><p><b>First:</b><br>Please use Add/Remove Programs to uninstall the programs listed below. All have adware and privacy issues.<br><br>"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows<br>"SelectRebatesUninstall" = ShopAtHome SelectRebates<br>"TTB000001.TTB000001Toolbar" = CouponBar<br><br></p></div>Done.<br><br><div class="bquote"><said>said by <a href="/profile/555588" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=555588');">LoPhatPhuud</a>:</said><p><b>Second:</b><br>Download and run Sophos AntiRootkit. Post the log in this thread, even if nothing is found.<br><br>You find link(s) and instructions here:<br>&raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/16564">Rootkit Detection Applications</A><br> </p></div>Done.  <br><br>I installed and ran Sophos Anti-Rootkit, but it would only let me check "Windows Registry" and "Local Hard Drives".  The "Running Processes" box was greyed-out.<br><br><pre><br> <br>ophos Anti-Rootkit Version 1.5.4  (c) 2009 Sophos Plc<br>Started logging on 7/13/2012 at 18:55:01 PM<br>User "kim" on computer "KIM-PC"<br>Windows version 6.1 SP 1.0 Service Pack 1 build 7601 SM=0x300 PT=0x1 WOW64<br>Info:	Starting registry scan.<br>Info:	Starting disk scan of C: (NTFS).<br>Hidden:	file C:\ProgramData\Norton\00000082\00000121\000005d6\cltLMS1.dat<br>Hidden:	file C:\ProgramData\Norton\00000082\00000121\000005d6\cltLMS2.dat<br>Hidden:	file C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\De finitions\VirusDefs\20120711.018\VersionInfo.dat<br>Hidden:	file C:\Windows\SysWOW64\en-US\osk.exe.mui<br>Hidden:	file C:\Windows\System32\nshipsec.dll<br>Info:	Starting disk scan of D: (NTFS).<br>Hidden:	file D:\hp\Apps\APP04585\src\ISSetup.dll<br>Hidden:	file D:\hp\Apps\APP04585\src\Power2Go.Gadget\images\audio\audio0001.png<br>Stopped logging on 7/14/2012 at 10:45:28 AM<br> <br></pre><br><br>(The scan didn't really take over-night, but I fell asleep and it looks like the PC went to sleep itself, and paused the scan.)<br><br><small>--<br>He used to say that soul shine, is better than sunshine, better than moonshine, damn sure better than rain.<br><br><A HREF="http://www.2012hoax.org/">Debunking the 2012 hysteria.</a> | Always looking for a new job | Begging the Wilpons to sell the Mets.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Is-this-PC-infected-27328738</guid>
<pubDate>Sat, 14 Jul 2012 11:01:16 EDT</pubDate>
</item>

<item>
<title>Re: Is this PC infected?</title>
<link>http://www.dslreports.com/forum/Re-Is-this-PC-infected-27325440</link>
<description><![CDATA[LoPhatPhuud posted : The logs are clean of anything major. There are a few items, however, that need to be removed. Also I want to do a deeper check for rootkits as a safety measure.<br><br><b>First:</b><br>Please use Add/Remove Programs to uninstall the programs listed below. All have adware and privacy issues.<br><br>"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows<br>"SelectRebatesUninstall" = ShopAtHome SelectRebates<br>"TTB000001.TTB000001Toolbar" = CouponBar<br><br><b>Second:</b><br>Download and run Sophos AntiRootkit. Post the log in this thread, even if nothing is found.<br><br>You find link(s) and instructions here:<br>&raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/16564">Rootkit Detection Applications</A><br><small>--<br>When angry count four; when very angry, swear.<br>Microsoft MVP/Consumer Security 2005-2011<br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Is-this-PC-infected-27325440</guid>
<pubDate>Fri, 13 Jul 2012 10:35:34 EDT</pubDate>
</item>

<item>
<title>Re: Is this PC infected?</title>
<link>http://www.dslreports.com/forum/Re-Is-this-PC-infected-27324035</link>
<description><![CDATA[Jeffrey posted : <B><U>EXTRAS.TXT</B></U><br><br>OTL Extras logfile created on: 7/11/2012 9:47:31 PM - Run 1<br>OTL by OldTimer - Version 3.2.54.0     Folder = C:\Users\kim\Desktop<br>64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation<br>Internet Explorer (Version = 9.0.8112.16421)<br>Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br> <br>3.99 Gb Total Physical Memory | 1.80 Gb Available Physical Memory | 45.12% Memory free<br>7.98 Gb Paging File | 6.00 Gb Available in Paging File | 75.19% Paging File free<br>Paging file location(s): ?:\pagefile.sys [binary data]<br> <br>%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)<br>Drive C: | 453.72 Gb Total Space | 398.72 Gb Free Space | 87.88% Space Free | Partition Type: NTFS<br>Drive D: | 11.95 Gb Total Space | 2.17 Gb Free Space | 18.19% Space Free | Partition Type: NTFS<br> <br>Computer Name: KIM-PC | User Name: kim | Logged in as Administrator.<br>Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans<br>Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days<br> <br>[color=#E56717]========== Extra Registry (SafeList) ==========[/color]<br> <br> <br>[color=#E56717]========== File Associations ==========[/color]<br> <br><b>64bit:</b> [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]<br>.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)<br>.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)<br> <br>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]<br>.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)<br>.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)<br> <br>[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]<br>.html [@ = ChromeHTML] -- Reg Error: Key error. File not found<br> <br>[color=#E56717]========== Shell Spawning ==========[/color]<br> <br><b>64bit:</b> [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]<br>batfile [open] -- "%1" %*<br>cmdfile [open] -- "%1" %*<br>comfile [open] -- "%1" %*<br>exefile [open] -- "%1" %*<br>helpfile [open] -- Reg Error: Key error.<br>htmlfile [edit] -- Reg Error: Key error.<br>htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"<br>http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)<br>https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)<br>inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)<br>InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)<br>InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)<br>piffile [open] -- "%1" %*<br>regfile [merge] -- Reg Error: Key error.<br>scrfile [config] -- "%1"<br>scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l<br>scrfile [open] -- "%1" /S<br>txtfile [edit] -- Reg Error: Key error.<br>Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1<br>Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)<br>Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br>Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br>Folder [explore] -- Reg Error: Value error.<br>Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br> <br>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]<br>batfile [open] -- "%1" %*<br>cmdfile [open] -- "%1" %*<br>comfile [open] -- "%1" %*<br>cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)<br>exefile [open] -- "%1" %*<br>helpfile [open] -- Reg Error: Key error.<br>htmlfile [edit] -- Reg Error: Key error.<br>htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"<br>http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)<br>https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)<br>inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)<br>piffile [open] -- "%1" %*<br>regfile [merge] -- Reg Error: Key error.<br>scrfile [config] -- "%1"<br>scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l<br>scrfile [open] -- "%1" /S<br>txtfile [edit] -- Reg Error: Key error.<br>Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1<br>Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)<br>Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br>Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br>Folder [explore] -- Reg Error: Value error.<br>Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br> <br>[color=#E56717]========== Security Center Settings ==========[/color]<br> <br><b>64bit:</b> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]<br>"cval" = 1<br> <br><b>64bit:</b> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]<br> <br><b>64bit:</b> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]<br>"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]<br>"AntiVirusOverride" = 0<br>"AntiSpywareOverride" = 0<br>"FirewallOverride" = 0<br> <br><b>64bit:</b> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]<br> <br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]<br> <br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]<br> <br>[color=#E56717]========== Firewall Settings ==========[/color]<br> <br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]<br>"DisableNotifications" = 0<br>"EnableFirewall" = 1<br> <br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]<br>"DisableNotifications" = 0<br>"EnableFirewall" = 1<br> <br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]<br>"DisableNotifications" = 0<br>"EnableFirewall" = 1<br> <br>[color=#E56717]========== Authorized Applications List ==========[/color]<br> <br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]<br>"C:\Program Files (x86)\American Airlines DealFinder\American_Airlines_DealFinder.exe" = C:\Program Files (x86)\American Airlines DealFinder\American_Airlines_DealFinder.exe -- (Skinkers Communications)<br>"C:\Program Files (x86)\American Airlines DealFinder\American_Airlines_DealFinder.exe" = C:\Program Files (x86)\American Airlines DealFinder\American_Airlines_DealFinder.exe -- (Skinkers Communications)<br> <br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]<br>"C:\Program Files (x86)\American Airlines DealFinder\American_Airlines_DealFinder.exe" = C:\Program Files (x86)\American Airlines DealFinder\American_Airlines_DealFinder.exe -- (Skinkers Communications)<br>"C:\Program Files (x86)\American Airlines DealFinder\American_Airlines_DealFinder.exe" = C:\Program Files (x86)\American Airlines DealFinder\American_Airlines_DealFinder.exe -- (Skinkers Communications)<br> <br> <br>[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]<br> <br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]<br>"{0123D01B-9FDB-4D89-9182-7DD0186000EF}" = rport=139 | protocol=6 | dir=out | app=system | <br>"{1AF780D4-DC33-462D-857C-1158A8B4765E}" = lport=2869 | protocol=6 | dir=in | app=system | <br>"{3187C89F-BE6C-4115-A8E4-59256725AF24}" = rport=445 | protocol=6 | dir=out | app=system | <br>"{3327741C-E000-4024-B9A1-61B0BF775F15}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | <br>"{38713877-20EB-43E8-9D2E-9D325ADC7A85}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | <br>"{3ACB6018-B801-41CE-BF35-3D6A7B991B33}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | <br>"{496A5525-8B11-4498-87E9-198D01897CA2}" = lport=445 | protocol=6 | dir=in | app=system | <br>"{543E0CFD-AF41-4D92-9045-B7C67250246E}" = lport=10243 | protocol=6 | dir=in | app=system | <br>"{658F0FA4-63AD-4F28-BDC2-C1FC692F9430}" = rport=138 | protocol=17 | dir=out | app=system | <br>"{6B4AFB30-9429-479B-ADA3-A11993504559}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | <br>"{6FBB2945-F8B9-4617-AA0A-56DDEAF2E636}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | <br>"{7034A96B-027D-4B76-A20A-CF96EF7AB826}" = lport=138 | protocol=17 | dir=in | app=system | <br>"{7B6DBD1E-C3CB-4886-A1B0-F89FD4D1D3ED}" = lport=137 | protocol=17 | dir=in | app=system | <br>"{7BF04354-CA46-4753-93B8-D659B33B0A39}" = rport=10243 | protocol=6 | dir=out | app=system | <br>"{A118F8F1-BB60-499F-8749-B2121CF4E0F3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | <br>"{AF30EA06-52D9-4E96-B520-9899AF0AEF49}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | <br>"{B2B7BB87-83BF-45D7-9ED0-DE06D37B6232}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | <br>"{C5426BD3-FA22-46D4-A188-080175D56FA3}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | <br>"{CBEF0ED1-0258-4766-BDDF-A6B6F487CCCF}" = rport=137 | protocol=17 | dir=out | app=system | <br>"{D153C395-D1A8-4CFA-9069-D12A2FF12293}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | <br>"{D5FB5BDA-7E8B-43DD-9B9D-D6D5C2E15A81}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | <br>"{D61D9534-B27C-4213-BA1E-16AE94F6262E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | <br>"{F0BCBB61-DFB1-4CAB-B396-0DD412248B58}" = lport=139 | protocol=6 | dir=in | app=system | <br> <br>[color=#E56717]========== Vista Active Application Exception List ==========[/color]<br> <br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]<br>"{09465775-2867-42A9-935F-C31A01C89643}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | <br>"{13A9AC43-A5A5-49FE-BF27-2851F5508CB7}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe | <br>"{17626CE9-DE35-4555-86EA-9BECBB936462}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | <br>"{1995747A-A66A-4118-AA79-D53B5A615722}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | <br>"{1BAF501C-0C99-4217-BB6F-FB94AC9B9918}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | <br>"{25CC5245-A258-4FFA-96BC-4582E8258371}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | <br>"{326FA30D-9501-4DD6-A89F-A19EEB058361}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe | <br>"{363E2750-E3FF-4F69-B927-FC104D6CB7E6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | <br>"{3F512A65-E71B-4455-9964-63DF18393931}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe | <br>"{4065D34D-3CBC-4FD1-B47C-236A970F649D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | <br>"{46A32259-CB4D-46DA-B7A7-D31394591A52}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | <br>"{473723DE-5F21-4A49-8DDA-BD333B4B43D3}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | <br>"{48B89C30-B9B7-4BE4-89E2-CBC3828750D4}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | <br>"{4A028820-CCF8-4F1F-8994-EE5D8F611C73}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe | <br>"{4B258193-1DCA-4409-8029-128D912F7A55}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe | <br>"{4BBC4292-49A4-4124-B874-FDC81866C7CE}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | <br>"{586CC949-E695-4BF3-BDC9-660B3A71AEBB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | <br>"{5A4BBCA3-C4FB-4AD6-8D03-8B665C1B9D30}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | <br>"{5CB216D6-80F9-4567-BF5E-B51AC379B6DC}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe | <br>"{5EFC787D-53DB-407C-968D-65EAD107CC94}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe | <br>"{605789A6-2FB7-4A97-994B-7B6DCD0D3876}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | <br>"{62BB38EB-3714-446E-8C98-5F39130DB581}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe | <br>"{65FD7CD5-7EDA-493F-BB5C-BAE64B8EC91E}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe | <br>"{7184B98C-BCE4-4415-AE77-829E01FA9198}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | <br>"{7E9B213B-5C1B-4625-8E57-1897874680CD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | <br>"{80855AD1-9519-476F-8964-5FE3756097BC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | <br>"{8465BFCF-D3B9-4642-9033-9CFE4DC34240}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe | <br>"{85C9FA15-69BD-46B9-A243-3B83CD3B61FD}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe | <br>"{88CD7623-3B49-4A66-B2F3-ED64478BEB12}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | <br>"{930B7BD4-711F-4D0D-B36C-620E0FB9C94D}" = protocol=6 | dir=out | app=system | <br>"{970E5F6C-8F82-4568-99FD-8A5E83BD3D2A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | <br>"{9DDC311C-99D3-411D-B339-AE42437975AB}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | <br>"{9F252303-670F-4898-9A3F-9C336CA334D9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | <br>"{A05ED65F-1B57-40D6-84CA-E849E531EBF8}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe | <br>"{B10B035F-5C23-4CB7-887D-D0CD852943F3}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | <br>"{BA02F517-797F-4F47-9D8B-727370A43F5C}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | <br>"{BE4B3CE7-7C5B-416D-890F-647DD0757D4D}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe | <br>"{CA1A5CEF-84CC-48BA-9FFA-BD3CF020C4C5}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe | <br>"{CBD5BA76-0B38-4CB2-9AA1-4D6B6E8EDC8A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | <br>"{DD31F8E9-3961-4E8C-AE33-6913C1F30C61}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | <br>"{EB32928F-4DF1-4D44-940A-5B6CBDC1909E}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe | <br>"{FC63B8ED-AAC5-4DD5-ADAD-50373268EADC}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe | <br>"{FFD26CBB-A4CA-48EC-A2B3-3D3B4C9CD5B0}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe | <br>"TCP Query User{2AB5CF94-452E-45C3-873A-3F5177192F5E}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | <br>"UDP Query User{2540F9CC-366B-4374-BAEB-730A48E3D649}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | <br> <br>[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]<br> <br>64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]<br>"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)<br>"{26280024-DFB7-4967-90DB-7F9C6660D01E}" = HP MediaSmart SmartMenu<br>"{4BDE7544-0A08-4AD9-8A8F-4B7944471C36}" = iTunes<br>"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161<br>"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour<br>"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17<br>"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570<br>"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight<br>"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175<br>"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)<br>"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053<br>"{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}" = Apple Mobile Device Support<br>"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148<br>"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile<br>"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit<br>"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile<br>"OfficeTrial" = Microsoft Office Home and Student 60 day trial<br>"PC-Doctor for Windows" = Hardware Diagnostic Tools<br> <br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]<br>"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148<br>"{065717D4-B980-434B-B778-0F14FBDB4AC3}" = Cisco AnyConnect VPN Client<br>"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements<br>"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime<br>"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works<br>"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer<br>"{1896E712-2B3D-45eb-BCE9-542742A51032}" = PictureMover<br>"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe<br>"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer<br>"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 26<br>"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes<br>"{37D59F62-2FC7-412D-AA55-3D0E6A9BD9C7}" = Microsoft Live Search Toolbar<br>"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology<br>"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go<br>"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor<br>"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = PowerRecover<br>"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater<br>"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth<br>"{612AD33D-9824-4E87-8396-92374E91C4BB}_is1" = Inbox Toolbar<br>"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com<br>"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.2.0<br>"{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}" = HP Support Assistant<br>"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable<br>"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br>"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update<br>"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570<br>"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system<br>"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)<br>"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br>"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161<br>"{9DEF9686-CCB2-47B7-BF83-B49EA21FA016}" = HP MediaSmart Demo<br>"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR<br>"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper<br>"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.1<br>"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video<br>"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call<br>"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer<br>"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information<br>"{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Activate Norton Online Backup<br>"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint<br>"{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution<br>"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector<br>"{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software<br>"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update<br>"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD<br>"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar<br>"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)<br>"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support<br>"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype&#153; 5.8<br>"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver<br>"{F3B912F5-EB57-45AA-B3D1-EB532BCF6EF8}" = HP Setup<br>"Adobe AIR" = Adobe AIR<br>"American Airlines DealFinder" = American Airlines DealFinder (remove only)<br>"CameraWindowDC" = Canon Utilities CameraWindow DC<br>"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX<br>"CameraWindowLauncher" = Canon Utilities CameraWindow<br>"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder<br>"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com<br>"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows<br>"ESET Online Scanner" = ESET Online Scanner v3<br>"Google Chrome" = Google Chrome<br>"Homepage Protection" = Homepage Protection<br>"HP Remote Solution" = HP Remote Solution<br>"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe<br>"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes<br>"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go<br>"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video<br>"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint<br>"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector<br>"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD<br>"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300<br>"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX<br>"MyCamera" = Canon Utilities MyCamera<br>"MyCameraDC" = Canon Utilities MyCamera DC<br>"N360" = Norton 360<br>"PhotoStitch" = Canon Utilities PhotoStitch<br>"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX<br>"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX<br>"SelectRebatesUninstall" = ShopAtHome SelectRebates<br>"TTB000001.TTB000001Toolbar" = CouponBar<br>"WildTangent hp Master Uninstall" = HP Games<br>"YTdetect" = Yahoo! Detect<br>"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX<br>"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility<br> <br>[color=#E56717]========== Last 20 Event Log Errors ==========[/color]<br> <br>[ Application Events ]<br>Error - 6/25/2012 11:17:34 AM | Computer Name = kim-PC | Source = Bonjour Service | ID = 100<br>Description = Task Scheduling Error: m->NextScheduledSPRetry 4555<br> <br>Error - 6/25/2012 11:17:35 AM | Computer Name = kim-PC | Source = Bonjour Service | ID = 100<br>Description = Task Scheduling Error: Continuously busy for more than a second<br> <br>Error - 6/25/2012 11:17:35 AM | Computer Name = kim-PC | Source = Bonjour Service | ID = 100<br>Description = Task Scheduling Error: m->NextScheduledEvent 5553<br> <br>Error - 6/25/2012 11:17:35 AM | Computer Name = kim-PC | Source = Bonjour Service | ID = 100<br>Description = Task Scheduling Error: m->NextScheduledSPRetry 5553<br> <br>Error - 6/25/2012 11:17:36 AM | Computer Name = kim-PC | Source = Bonjour Service | ID = 100<br>Description = Task Scheduling Error: Continuously busy for more than a second<br> <br>Error - 6/25/2012 11:17:36 AM | Computer Name = kim-PC | Source = Bonjour Service | ID = 100<br>Description = Task Scheduling Error: m->NextScheduledEvent 6552<br> <br>Error - 6/25/2012 11:17:36 AM | Computer Name = kim-PC | Source = Bonjour Service | ID = 100<br>Description = Task Scheduling Error: m->NextScheduledSPRetry 6552<br> <br>Error - 6/25/2012 11:17:37 AM | Computer Name = kim-PC | Source = Bonjour Service | ID = 100<br>Description = Task Scheduling Error: Continuously busy for more than a second<br> <br>Error - 6/25/2012 11:17:37 AM | Computer Name = kim-PC | Source = Bonjour Service | ID = 100<br>Description = Task Scheduling Error: m->NextScheduledEvent 7550<br> <br>Error - 6/25/2012 11:17:37 AM | Computer Name = kim-PC | Source = Bonjour Service | ID = 100<br>Description = Task Scheduling Error: m->NextScheduledSPRetry 7550<br> <br>[ Hewlett-Packard Events ]<br>Error - 5/13/2012 3:14:40 PM | Computer Name = kim-PC | Source = HPSF.exe | ID = 2000<br>Description = HP Error ID: -2147467262HPSF.exe   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Message: Unable to cast object<br> of type 'System.DBNull' to type 'System.String'.  StackTrace:   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Source: HP.SupportAssistant.Common<br><br>Name:<br> HPSF.exe  Version: 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support<br> Framework\HPSF.exe  Format: en-US  RAM: 4086  Ram Utilization: 20  TargetSite: Void SaveSessionInfo(System.Data.DataRow,<br> Boolean, HP.SupportAssistant.Common.CustomerExperience.HPSASession)  <br> <br>Error - 5/16/2012 7:51:13 AM | Computer Name = kim-PC | Source = HPSF.exe | ID = 4000<br>Description = <br> <br>Error - 5/16/2012 7:54:31 AM | Computer Name = kim-PC | Source = HPSF.exe | ID = 4000<br>Description = <br> <br>Error - 5/16/2012 8:03:15 AM | Computer Name = kim-PC | Source = HPSF.exe | ID = 2000<br>Description = HP Error ID: -2147467262HPSF.exe   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Message: Unable to cast object<br> of type 'System.DBNull' to type 'System.String'.  StackTrace:   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Source: HP.SupportAssistant.Common<br><br>Name:<br> HPSF.exe  Version: 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support<br> Framework\HPSF.exe  Format: en-US  RAM: 4086  Ram Utilization: 40  TargetSite: Void SaveSessionInfo(System.Data.DataRow,<br> Boolean, HP.SupportAssistant.Common.CustomerExperience.HPSASession)  <br> <br>Error - 5/16/2012 8:03:15 AM | Computer Name = kim-PC | Source = HPSF.exe | ID = 2000<br>Description = HP Error ID: -2147467262HPSF.exe   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Message: Unable to cast object<br> of type 'System.DBNull' to type 'System.String'.  StackTrace:   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Source: HP.SupportAssistant.Common<br><br>Name:<br> HPSF.exe  Version: 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support<br> Framework\HPSF.exe  Format: en-US  RAM: 4086  Ram Utilization: 40  TargetSite: Void SaveSessionInfo(System.Data.DataRow,<br> Boolean, HP.SupportAssistant.Common.CustomerExperience.HPSASession)  <br> <br>Error - 5/21/2012 8:24:08 PM | Computer Name = kim-PC | Source = HPSF.exe | ID = 2000<br>Description = HP Error ID: -2147467262   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Message: Unable to cast object<br> of type 'System.DBNull' to type 'System.String'.  StackTrace:   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Source: HP.SupportAssistant.Common<br><br>Name:<br> HPSF.exe  Version: 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support<br> Framework\HPSF.exe  Format: en-US  RAM: 4086  Ram Utilization: 40  TargetSite: Void SaveSessionInfo(System.Data.DataRow,<br> Boolean, HP.SupportAssistant.Common.CustomerExperience.HPSASession)  <br> <br>Error - 5/21/2012 8:24:09 PM | Computer Name = kim-PC | Source = HPSF.exe | ID = 2000<br>Description = HP Error ID: -2147467262HPSF.exe   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Message: Unable to cast object<br> of type 'System.DBNull' to type 'System.String'.  StackTrace:   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Source: HP.SupportAssistant.Common<br><br>Name:<br> HPSF.exe  Version: 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support<br> Framework\HPSF.exe  Format: en-US  RAM: 4086  Ram Utilization: 40  TargetSite: Void SaveSessionInfo(System.Data.DataRow,<br> Boolean, HP.SupportAssistant.Common.CustomerExperience.HPSASession)  <br> <br>Error - 5/27/2012 12:04:03 PM | Computer Name = kim-PC | Source = HPSF.exe | ID = 2000<br>Description = HP Error ID: -2147467262   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Message: Unable to cast object<br> of type 'System.DBNull' to type 'System.String'.  StackTrace:   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Source: HP.SupportAssistant.Common<br><br>Name:<br> HPSF.exe  Version: 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support<br> Framework\HPSF.exe  Format: en-US  RAM: 4086  Ram Utilization: 30  TargetSite: Void SaveSessionInfo(System.Data.DataRow,<br> Boolean, HP.SupportAssistant.Common.CustomerExperience.HPSASession)  <br> <br>Error - 5/27/2012 12:04:03 PM | Computer Name = kim-PC | Source = HPSF.exe | ID = 2000<br>Description = HP Error ID: -2147467262HPSF.exe   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Message: Unable to cast object<br> of type 'System.DBNull' to type 'System.String'.  StackTrace:   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Source: HP.SupportAssistant.Common<br><br>Name:<br> HPSF.exe  Version: 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support<br> Framework\HPSF.exe  Format: en-US  RAM: 4086  Ram Utilization: 30  TargetSite: Void SaveSessionInfo(System.Data.DataRow,<br> Boolean, HP.SupportAssistant.Common.CustomerExperience.HPSASession)  <br> <br>Error - 6/3/2012 11:35:52 AM | Computer Name = kim-PC | Source = HPSF.exe | ID = 2000<br>Description = HP Error ID: -2147467262   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Message: Unable to cast object<br> of type 'System.DBNull' to type 'System.String'.  StackTrace:   at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow<br> dr, Boolean bOnlyDetected, HPSASession SFSession)  Source: HP.SupportAssistant.Common<br><br>Name:<br> HPSF.exe  Version: 06.00.01.01  Path: C:\Program Files (x86)\Hewlett-Packard\HP Support<br> Framework\HPSF.exe  Format: en-US  RAM: 4086  Ram Utilization: 30  TargetSite: Void SaveSessionInfo(System.Data.DataRow,<br> Boolean, HP.SupportAssistant.Common.CustomerExperience.HPSASession)  <br> <br>[ System Events ]<br>Error - 9/5/2011 11:00:52 AM | Computer Name = kim-PC | Source = cdrom | ID = 262151<br>Description = The device, \Device\CdRom0, has a bad block.<br> <br>Error - 9/6/2011 8:19:11 AM | Computer Name = kim-PC | Source = Service Control Manager | ID = 7009<br>Description = A timeout was reached (30000 milliseconds) while waiting for the Windows<br> Error Reporting Service service to connect.<br> <br>Error - 9/6/2011 8:20:15 AM | Computer Name = kim-PC | Source = DCOM | ID = 10010<br>Description = <br> <br>Error - 9/28/2011 10:48:50 PM | Computer Name = kim-PC | Source = Service Control Manager | ID = 7011<br>Description = A timeout (30000 milliseconds) was reached while waiting for a transaction<br> response from the lmhosts service.<br> <br>Error - 10/4/2011 8:01:57 AM | Computer Name = kim-PC | Source = Service Control Manager | ID = 7031<br>Description = The Apple Mobile Device service terminated unexpectedly.  It has done<br> this 1 time(s).  The following corrective action will be taken in 60000 milliseconds:<br> Restart the service.<br> <br>Error - 10/4/2011 8:02:06 AM | Computer Name = kim-PC | Source = Service Control Manager | ID = 7031<br>Description = The Apple Mobile Device service terminated unexpectedly.  It has done<br> this 2 time(s).  The following corrective action will be taken in 60000 milliseconds:<br> Restart the service.<br> <br>Error - 10/4/2011 8:03:06 AM | Computer Name = kim-PC | Source = Service Control Manager | ID = 7032<br>Description = The Service Control Manager tried to take a corrective action (Restart<br> the service) after the unexpected termination of the Apple Mobile Device service,<br> but this action failed with the following error:   %%1056<br> <br>Error - 10/15/2011 10:59:37 PM | Computer Name = kim-PC | Source = Service Control Manager | ID = 7011<br>Description = A timeout (30000 milliseconds) was reached while waiting for a transaction<br> response from the ShellHWDetection service.<br> <br>Error - 10/30/2011 10:32:29 AM | Computer Name = kim-PC | Source = Service Control Manager | ID = 7031<br>Description = The Apple Mobile Device service terminated unexpectedly.  It has done<br> this 1 time(s).  The following corrective action will be taken in 60000 milliseconds:<br> Restart the service.<br> <br>Error - 10/30/2011 12:51:17 PM | Computer Name = kim-PC | Source = DCOM | ID = 10010<br>Description = <br> <br> <br>< End of report ><br><br><B><U>CHECKUP.TXT</B></U><br><br> Results of screen317's Security Check version 0.99.24  <br> Windows 7  x64 (UAC is enabled)  <br> Internet Explorer 9  <br><b>`````````````````````````````` <br>[u]Antivirus/Firewall Check:[/u]</b> <br> Windows Firewall Enabled!  <br> ESET Online Scanner v3   <br> Norton 360     <br> [size=1]WMI entry may not exist for antivirus; attempting automatic update.[/size] <br><b>``````````````````````````````` <br>[u]Anti-malware/Other Utilities Check:[/u]</b> <br> Java(TM) 6 Update 26  <br> [color=red]<b>Out of date Java installed!</b>[/color] <br><b>```````````````````````````````` <br>Process Check:  <br>[u]objlist.exe by Laurent[/u]</b> <br> Norton ccSvcHst.exe <br> ESET ESET Online Scanner OnlineCmdLineScanner.exe  <br><b>``````````End of Log````````````</b> <br><br><B><U>ESET ONLINE SCANNER</B></U>(FOUND NOTHING)<br><br>ESETSmartInstaller@High as CAB hook log:<br>OnlineScanner64.ocx - registred OK<br>OnlineScanner.ocx - registred OK<br><small>--<br>He used to say that soul shine, is better than sunshine, better than moonshine, damn sure better than rain.<br><br><A HREF="http://www.2012hoax.org/">Debunking the 2012 hysteria.</a> | Always looking for a new job | Begging the Wilpons to sell the Mets.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Is-this-PC-infected-27324035</guid>
<pubDate>Thu, 12 Jul 2012 20:48:20 EDT</pubDate>
</item>

<item>
<title>Is this PC infected?</title>
<link>http://www.dslreports.com/forum/Is-this-PC-infected-27324023</link>
<description><![CDATA[Jeffrey posted : Hi,<br><br>A coworker asked me to checkout her PC, so I said yes.  I'm a bit puzzled by this one, but here are the facts:<br><br>My coworker came to me and said that she clicked on an email from her friend.  It was from her friend, but it was a spam message and my coworker didn't realize it.  She clicked on the link within the email, and immediately something came on the screen telling her she's infected, buy this software to get rid of it, and she can't "open anything".  I tell her, "yeah, just give me the PC, I'll fix it for you" because I've done a bunch of these for people; sometimes they're so bad, I just wipe and reload, but it's fixed and they're happy.  At any rate...<br><br>I turned this machine on, and it booted right to the desktop with no problems.  No popups, no obvious suspicious activity or applications.  In short, I don't see a problem.  At any rate, I peeked around a bit, still couldn't find anything, so I decided to do right by her and do a "tune up" of sorts.  This is a ~3 year old nice HP desktop in excellent working order.   At the same time, I wanted to check with you guys/gals here to make sure there isn't something I'm missing.  My coworker is a very novice PC user, so I'm confident she saw what she saw.  With that said, I can't find anything. :)  So here we go:<br><br>The only curious thing I did find was that Norton Internet Security is installed, and as of 7/11 (2 days after giving me the machine) it has 365 days of protection left.  I guess it's possible that she installed this and didn't tell me, and NIS removed the issue(s), but I could find nothing of value in the NIS quarantine logs.<br><br>I ran TFC as requested, and the machine rebooted.  Following the rest of the mandatory steps, here goes:<br><br><b><u>MBAM LOG</B></U><br>Malwarebytes Anti-Malware 1.62.0.1300<br>www.malwarebytes.org<br><br>Database version: v2012.07.12.01<br><br>Windows 7 Service Pack 1 x64 NTFS<br>Internet Explorer 9.0.8112.16421<br>kim :: KIM-PC [administrator]<br><br>7/11/2012 10:18:01 PM<br>mbam-log-2012-07-11 (22-18-01).txt<br><br>Scan type: Full scan (C:\|D:\|)<br>Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM<br>Scan options disabled: P2P<br>Objects scanned: 378467<br>Time elapsed: 1 hour(s), 29 minute(s), 48 second(s)<br><br>Memory Processes Detected: 0<br>(No malicious items detected)<br><br>Memory Modules Detected: 0<br>(No malicious items detected)<br><br>Registry Keys Detected: 0<br>(No malicious items detected)<br><br>Registry Values Detected: 0<br>(No malicious items detected)<br><br>Registry Data Items Detected: 0<br>(No malicious items detected)<br><br>Folders Detected: 0<br>(No malicious items detected)<br><br>Files Detected: 0<br>(No malicious items detected)<br><br>(end)<br><br><B><U>OTL.TXT</B></U><br><br>OTL logfile created on: 7/11/2012 9:47:31 PM - Run 1<br>OTL by OldTimer - Version 3.2.54.0     Folder = C:\Users\kim\Desktop<br>64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation<br>Internet Explorer (Version = 9.0.8112.16421)<br>Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br> <br>3.99 Gb Total Physical Memory | 1.80 Gb Available Physical Memory | 45.12% Memory free<br>7.98 Gb Paging File | 6.00 Gb Available in Paging File | 75.19% Paging File free<br>Paging file location(s): ?:\pagefile.sys [binary data]<br> <br>%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)<br>Drive C: | 453.72 Gb Total Space | 398.72 Gb Free Space | 87.88% Space Free | Partition Type: NTFS<br>Drive D: | 11.95 Gb Total Space | 2.17 Gb Free Space | 18.19% Space Free | Partition Type: NTFS<br> <br>Computer Name: KIM-PC | User Name: kim | Logged in as Administrator.<br>Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans<br>Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days<br> <br>[color=#E56717]========== Processes (SafeList) ==========[/color]<br> <br>PRC - [2012/07/11 21:46:46 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\kim\Desktop\OTL.exe<br>PRC - [2012/02/24 09:09:05 | 000,307,824 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe<br>PRC - [2011/12/10 14:46:28 | 000,247,968 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe<br>PRC - [2011/04/16 20:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccsvchst.exe<br>PRC - [2011/03/28 18:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe<br>PRC - [2010/08/09 15:25:36 | 000,885,216 | ---- | M] () -- C:\Program Files (x86)\SelectRebates\SelectRebates.exe<br>PRC - [2010/07/12 12:53:00 | 000,399,032 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe<br>PRC - [2010/03/03 20:16:06 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe<br>PRC - [2010/03/03 20:16:04 | 000,284,696 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe<br>PRC - [2009/12/01 20:49:52 | 000,210,216 | ---- | M] (CyberLink) -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe<br>PRC - [2009/10/20 14:50:34 | 000,128,296 | ---- | M] (CyberLink Corp.) -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe<br>PRC - [2009/06/03 15:35:16 | 000,430,080 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe<br>PRC - [2009/05/26 04:36:13 | 000,656,896 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe<br>PRC - [2009/03/17 04:26:16 | 000,759,728 | ---- | M] (Skinkers Communications) -- C:\Program Files (x86)\American Airlines DealFinder\American_Airlines_DealFinder.exe<br>PRC - [2008/11/20 13:47:28 | 000,062,768 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe<br> <br> <br>[color=#E56717]========== Modules (No Company Name) ==========[/color]<br> <br>MOD - [2012/06/15 07:47:54 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll<br>MOD - [2012/06/14 08:25:17 | 014,340,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll<br>MOD - [2012/06/14 08:25:01 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll<br>MOD - [2012/06/14 08:24:57 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll<br>MOD - [2012/05/12 09:54:36 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll<br>MOD - [2012/05/12 09:54:35 | 000,452,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\635b3aec298ad5e8c903b2323d79cc5a\IAStorUtil.ni.dll<br>MOD - [2012/05/12 09:49:50 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll<br>MOD - [2012/05/12 09:49:37 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll<br>MOD - [2012/05/12 09:49:36 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll<br>MOD - [2012/05/12 09:49:11 | 000,185,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\d8af9a65cf0ed85d47360796e2645a06\UIAutomationTypes.ni.dll<br>MOD - [2012/05/12 09:49:03 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll<br>MOD - [2012/05/12 09:48:59 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll<br>MOD - [2012/05/12 09:48:56 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll<br>MOD - [2012/05/12 09:48:55 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll<br>MOD - [2012/05/12 09:48:50 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll<br>MOD - [2012/02/07 09:00:21 | 000,036,920 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\HP.ActiveSupportLibrary\2.0.0.1__01a974bc1760f423\HP.ActiveSupportLibrary.dll<br>MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll<br>MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll<br>MOD - [2010/11/04 21:58:05 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll<br>MOD - [2010/08/09 15:25:36 | 000,885,216 | ---- | M] () -- C:\Program Files (x86)\SelectRebates\SelectRebates.exe<br>MOD - [2010/08/09 15:25:36 | 000,177,616 | ---- | M] () -- C:\Program Files (x86)\SelectRebates\SRebates.dll<br>MOD - [2010/06/30 00:12:54 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll<br>MOD - [2010/06/30 00:12:52 | 000,131,072 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\ECenter\ECLibrary.dll<br>MOD - [2010/06/30 00:12:42 | 000,040,960 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingServer.dll<br>MOD - [2010/06/30 00:12:40 | 000,036,864 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingClients.dll<br>MOD - [2010/06/30 00:12:40 | 000,007,680 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\RemotingClient.dll<br>MOD - [2010/06/30 00:12:40 | 000,005,632 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingInterface.dll<br>MOD - [2010/06/30 00:12:36 | 000,018,944 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingMessages.dll<br>MOD - [2010/06/30 00:12:18 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll<br>MOD - [2009/12/01 20:49:50 | 000,931,112 | ---- | M] () -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll<br>MOD - [2009/07/13 21:15:45 | 000,364,544 | ---- | M] () -- C:\Windows\SysWOW64\msjetoledb40.dll<br>MOD - [2009/06/03 15:43:14 | 001,703,936 | ---- | M] () -- C:\Users\kim\AppData\Roaming\PictureMover\EN-US\Presentation.dll<br>MOD - [2009/06/03 15:34:18 | 003,764,224 | ---- | M] () -- C:\Users\kim\AppData\Roaming\PictureMover\Bin\Core.dll<br>MOD - [2009/05/26 04:36:13 | 000,656,896 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe<br> <br> <br>[color=#E56717]========== Win32 Services (SafeList) ==========[/color]<br> <br>SRV:<b>64bit:</b> - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)<br>SRV - [2012/02/15 14:30:18 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)<br>SRV - [2011/09/09 18:10:28 | 000,086,072 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)<br>SRV - [2011/04/16 20:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe -- (N360)<br>SRV - [2011/03/28 18:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe)<br>SRV - [2010/07/12 12:53:00 | 000,399,032 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent)<br>SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)<br>SRV - [2010/03/03 20:16:06 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R)<br>SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)<br>SRV - [2009/05/22 14:02:20 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe -- (GameConsoleService)<br> <br> <br>[color=#E56717]========== Driver Services (SafeList) ==========[/color]<br> <br>DRV:<b>64bit:</b> - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)<br>DRV:<b>64bit:</b> - [2011/07/10 13:58:01 | 000,174,200 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)<br>DRV:<b>64bit:</b> - [2011/07/06 12:44:00 | 000,034,288 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)<br>DRV:<b>64bit:</b> - [2011/04/20 21:37:49 | 000,386,168 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0502020.003\symnets.sys -- (SymNetS)<br>DRV:<b>64bit:</b> - [2011/03/30 23:00:09 | 000,744,568 | R--- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\N360x64\0502020.003\srtsp64.sys -- (SRTSP)<br>DRV:<b>64bit:</b> - [2011/03/30 23:00:09 | 000,040,568 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0502020.003\srtspx64.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)<br>DRV:<b>64bit:</b> - [2011/03/14 22:31:23 | 000,912,504 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\0502020.003\symefa64.sys -- (SymEFA)<br>DRV:<b>64bit:</b> - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)<br>DRV:<b>64bit:</b> - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)<br>DRV:<b>64bit:</b> - [2011/02/18 16:36:58 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)<br>DRV:<b>64bit:</b> - [2011/01/27 02:47:10 | 000,450,680 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\0502020.003\symds64.sys -- (SymDS)<br>DRV:<b>64bit:</b> - [2011/01/27 01:07:06 | 000,171,128 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0502020.003\ironx64.sys -- (SymIRON)<br>DRV:<b>64bit:</b> - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)<br>DRV:<b>64bit:</b> - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)<br>DRV:<b>64bit:</b> - [2010/07/12 12:53:00 | 000,027,640 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpnva64.sys -- (vpnva)<br>DRV:<b>64bit:</b> - [2010/03/03 19:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)<br>DRV:<b>64bit:</b> - [2009/08/20 20:05:06 | 000,239,616 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)<br>DRV:<b>64bit:</b> - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)<br>DRV:<b>64bit:</b> - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)<br>DRV:<b>64bit:</b> - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)<br>DRV:<b>64bit:</b> - [2009/06/16 07:32:14 | 006,112,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)<br>DRV:<b>64bit:</b> - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)<br>DRV:<b>64bit:</b> - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)<br>DRV:<b>64bit:</b> - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)<br>DRV:<b>64bit:</b> - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)<br>DRV - [2012/06/18 20:01:13 | 001,161,376 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20120711.001\BHDrvx64.sys -- (BHDrvx64)<br>DRV - [2012/06/14 14:39:24 | 000,509,088 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20120711.001\IDSviA64.sys -- (IDSVia64)<br>DRV - [2012/05/31 08:06:57 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)<br>DRV - [2012/05/31 08:06:57 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)<br>DRV - [2012/05/15 22:10:35 | 002,068,600 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120711.018\ex64.sys -- (NAVEX15)<br>DRV - [2012/05/15 22:10:35 | 000,120,440 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120711.018\eng64.sys -- (NAVENG)<br>DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)<br> <br> <br>[color=#E56717]========== Standard Registry (SafeList) ==========[/color]<br> <br> <br>[color=#E56717]========== Internet Explorer ==========[/color]<br> <br>IE:<b>64bit:</b> - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;&pf=cndt</A><br>IE:<b>64bit:</b> - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;&pf=cndt</A><br>IE:<b>64bit:</b> - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}<br>IE:<b>64bit:</b> - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = &raquo;<A HREF="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7" >www.google.com/search?q={searchT&middot;&middot;&middot;ceid=ie7</A><br>IE:<b>64bit:</b> - HKLM\..\SearchScopes\{A8ED5BDF-C010-494C-B6B3-DD198D35270D}: "URL" = &raquo;<A HREF="http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd" >www.ask.com/web?q={searchterms}&&middot;&middot;&middot;&o=ushpd</A><br>IE:<b>64bit:</b> - HKLM\..\SearchScopes\{E715678E-6F58-4CEF-AB9F-F1F4D371F022}: "URL" = &raquo;<A HREF="http://www.bing.com/search?q={searchTerms}&FORM=HPDTDF&pc=HPDTDF&src=IE-SearchBox" >www.bing.com/search?q={searchTer&middot;&middot;&middot;earchBox</A><br>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;&pf=cndt</A><br>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;&pf=cndt</A><br>IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}<br>IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = &raquo;<A HREF="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7" >www.google.com/search?q={searchT&middot;&middot;&middot;ceid=ie7</A><br>IE - HKLM\..\SearchScopes\{A8ED5BDF-C010-494C-B6B3-DD198D35270D}: "URL" = &raquo;<A HREF="http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd" >www.ask.com/web?q={searchterms}&&middot;&middot;&middot;&o=ushpd</A><br>IE - HKLM\..\SearchScopes\{E715678E-6F58-4CEF-AB9F-F1F4D371F022}: "URL" = &raquo;<A HREF="http://www.bing.com/search?q={searchTerms}&FORM=HPDTDF&pc=HPDTDF&src=IE-SearchBox" >www.bing.com/search?q={searchTer&middot;&middot;&middot;earchBox</A><br> <br>IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;&pf=cndt</A><br>IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=%tb_id&%language" >toolbar.inbox.com/search/dispatc&middot;&middot;&middot;language</A><br>IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;&pf=cndt</A><br>IE - HKCU\..\URLSearchHook: {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\Program Files (x86)\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)<br>IE - HKCU\..\SearchScopes,DefaultScope = {E715678E-6F58-4CEF-AB9F-F1F4D371F022}<br>IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = &raquo;<A HREF="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_en" >www.google.com/search?q={searchT&middot;&middot;&middot;7ADRA_en</A><br>IE - HKCU\..\SearchScopes\{A8ED5BDF-C010-494C-B6B3-DD198D35270D}: "URL" = &raquo;<A HREF="http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd" >www.ask.com/web?q={searchterms}&&middot;&middot;&middot;&o=ushpd</A><br>IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = &raquo;<A HREF="http://www.ask.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=360&chn=retail&geo=US&ver=5" >www.ask.com/web?q={SEARCHTERMS}&&middot;&middot;&middot;US&ver=5</A><br>IE - HKCU\..\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}: "URL" = &raquo;<A HREF="http://toolbar.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=80110&lng=en" >toolbar.inbox.com/search/dispatc&middot;&middot;&middot;0&lng=en</A><br>IE - HKCU\..\SearchScopes\{E715678E-6F58-4CEF-AB9F-F1F4D371F022}: "URL" = &raquo;<A HREF="http://www.bing.com/search?q={searchTerms}&FORM=HPDTDF&pc=HPDTDF&src=IE-SearchBox" >www.bing.com/search?q={searchTer&middot;&middot;&middot;earchBox</A><br>IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0<br>IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local<br> <br> <br>[color=#E56717]========== FireFox ==========[/color]<br> <br>FF:<b>64bit:</b> - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found<br>FF:<b>64bit:</b> - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)<br>FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found<br>FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()<br>FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)<br>FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)<br>FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found<br>FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)<br>FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)<br>FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)<br>FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)<br> <br>FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2012/05/04 11:50:39 | 000,000,000 | ---D | M]<br>FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn_2011_7_9_4 [2012/07/11 21:10:17 | 000,000,000 | ---D | M]<br> <br> <br>[color=#E56717]========== Chrome  ==========[/color]<br> <br>CHR - homepage: &raquo;<A HREF="http://www.google.com/" >www.google.com/</A><br> <br>O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts<br>O2:<b>64bit:</b> - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)<br>O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)<br>O2 - BHO: (TTB000000 Class) - {62960D20-6D0D-1AB4-4BF1-95B0B5B8783A} - C:\Users\kim\AppData\Local\Temp\low\COUPON~1.DLL File not found<br>O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ips\ipsbho.dll (Symantec Corporation)<br>O2 - BHO: (hpBHO Class) - {ABD3B5E1-B268-407B-A150-2641DAB8D898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll (AOL Products)<br>O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)<br>O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)<br>O2 - BHO: (Inbox Toolbar) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\Program Files (x86)\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)<br>O2 - BHO: (ShopAtHomeIEHelper Class) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files (x86)\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome)<br>O3:<b>64bit:</b> - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)<br>O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)<br>O3 - HKLM\..\Toolbar: (CouponBar) - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - C:\Users\kim\AppData\Local\Temp\low\CouponsBar.dll File not found<br>O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)<br>O3 - HKLM\..\Toolbar: (ShopAtHome Toolbar) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files (x86)\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome)<br>O3 - HKLM\..\Toolbar: (&Inbox Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files (x86)\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)<br>O3:<b>64bit:</b> - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)<br>O3 - HKCU\..\Toolbar\WebBrowser: (CouponBar) - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - C:\Users\kim\AppData\Local\Temp\low\CouponsBar.dll File not found<br>O3 - HKCU\..\Toolbar\WebBrowser: (ShopAtHome Toolbar) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - C:\Program Files (x86)\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome)<br>O4:<b>64bit:</b> - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)<br>O4:<b>64bit:</b> - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)<br>O4:<b>64bit:</b> - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)<br>O4:<b>64bit:</b> - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()<br>O4 - HKLM..\Run: []  File not found<br>O4 - HKLM..\Run: [American Airlines DealFinder] C:\Program Files (x86)\American Airlines DealFinder\American_Airlines_DealFinder.exe (Skinkers Communications)<br>O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)<br>O4 - HKLM..\Run: [HP Remote Solution] C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe ()<br>O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)<br>O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)<br>O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)<br>O4 - HKLM..\Run: [SelectRebates] C:\Program Files (x86)\SelectRebates\SelectRebates.exe ()<br>O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)<br>O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)<br>O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)<br>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1<br>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1<br>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5<br>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3<br>O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)<br>O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)<br>O10:<b>64bit:</b> - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)<br>O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)<br>O13<b>64bit:</b> - gopher Prefix: missing<br>O13 - gopher Prefix: missing<br>O16 - DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} &raquo;<A HREF="https://access.ise.com/CACHE/stc/2/binaries/vpnweb.cab" >access.ise.com/CACHE/stc/2/binar&middot;&middot;&middot;nweb.cab</A> (Cisco AnyConnect VPN Client Web Control)<br>O16 - DPF: {705EC6D4-B138-4079-A307-EF13E4889A82} &raquo;<A HREF="https://access.ise.com/CACHE/sdesktop/install/binaries/instweb.cab" >access.ise.com/CACHE/sdesktop/in&middot;&middot;&middot;tweb.cab</A> (CSD ActiveX Installer)<br>O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} &raquo;<A HREF="http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab" >java.sun.com/update/1.6.0/jinsta&middot;&middot;&middot;i586.cab</A> (Java Plug-in 1.6.0_26)<br>O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} &raquo;<A HREF="http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab" >java.sun.com/update/1.6.0/jinsta&middot;&middot;&middot;i586.cab</A> (Java Plug-in 1.6.0_26)<br>O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} &raquo;<A HREF="http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab" >java.sun.com/update/1.6.0/jinsta&middot;&middot;&middot;i586.cab</A> (Java Plug-in 1.6.0_26)<br>O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} &raquo;<A HREF="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" >platformdl.adobe.com/NOS/getPlus&middot;&middot;&middot;6/gp.cab</A> (Reg Error: Key error.)<br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 208.67.220.220 167.206.254.1<br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EAAA253F-3C4D-4C3F-BE1D-9136017FB020}: DhcpNameServer = 208.67.222.222 208.67.220.220 167.206.254.1<br>O18:<b>64bit:</b> - Protocol\Handler\inbox - No CLSID value found<br>O18:<b>64bit:</b> - Protocol\Handler\ms-itss - No CLSID value found<br>O18:<b>64bit:</b> - Protocol\Handler\skype4com - No CLSID value found<br>O18:<b>64bit:</b> - Protocol\Handler\skype-ie-addon-data - No CLSID value found<br>O18 - Protocol\Handler\inbox {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\Program Files (x86)\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)<br>O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)<br>O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)<br>O20:<b>64bit:</b> - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)<br>O20:<b>64bit:</b> - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)<br>O20:<b>64bit:</b> - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)<br>O20:<b>64bit:</b> - HKLM Winlogon: VMApplet - (/pagefile) -  File not found<br>O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)<br>O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)<br>O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found<br>O20:<b>64bit:</b> - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)<br>O21:<b>64bit:</b> - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.<br>O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.<br>O32 - HKLM CDRom: AutoRun - 1<br>O33 - MountPoints2\{708dab56-26f5-11e1-9dd6-90e6ba13fd8e}\Shell - "" = AutoRun<br>O33 - MountPoints2\{708dab56-26f5-11e1-9dd6-90e6ba13fd8e}\Shell\AutoRun\command - "" = J:\TL_Bootstrap.exe<br>O34 - HKLM BootExecute: (autocheck autochk *)<br>O35:<b>64bit:</b> - HKLM\..comfile [open] -- "%1" %*<br>O35:<b>64bit:</b> - HKLM\..exefile [open] -- "%1" %*<br>O35 - HKLM\..comfile [open] -- "%1" %*<br>O35 - HKLM\..exefile [open] -- "%1" %*<br>O37:<b>64bit:</b> - HKLM\...com [@ = comfile] -- "%1" %*<br>O37:<b>64bit:</b> - HKLM\...exe [@ = exefile] -- "%1" %*<br>O37 - HKLM\...com [@ = comfile] -- "%1" %*<br>O37 - HKLM\...exe [@ = exefile] -- "%1" %*<br>O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)<br>O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)<br>O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)<br> <br>[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]<br> <br>[2012/07/11 21:54:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET<br>[2012/07/11 21:54:08 | 000,000,000 | -H-D | C] -- C:\Windows\AxInstSV<br>[2012/07/11 21:46:46 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\kim\Desktop\OTL.exe<br>[2012/07/11 21:22:08 | 000,000,000 | ---D | C] -- C:\Users\kim\AppData\Roaming\Malwarebytes<br>[2012/07/11 21:22:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware<br>[2012/07/11 21:22:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes<br>[2012/07/11 21:22:02 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys<br>[2012/07/11 21:22:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware<br>[2012/07/11 21:15:53 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdosys.dll<br>[2012/07/11 21:15:53 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cdosys.dll<br>[2012/07/02 09:34:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime<br>[2012/06/21 07:42:05 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll<br>[2012/06/21 07:42:05 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe<br>[2012/06/21 07:42:05 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll<br>[2012/06/21 07:41:54 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll<br>[2012/06/21 07:41:54 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll<br>[2012/06/21 07:41:54 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll<br>[2012/06/21 07:41:43 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll<br>[2012/06/21 07:41:43 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe<br>[2012/06/14 07:49:58 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe<br>[2012/06/14 07:49:57 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe<br>[2012/06/14 07:49:57 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe<br>[2012/06/14 07:49:49 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll<br>[2012/06/14 07:49:49 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll<br>[2012/06/14 07:49:49 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe<br>[2012/06/14 07:49:35 | 003,216,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll<br>[2012/06/14 07:48:08 | 001,462,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll<br>[2012/06/14 07:48:08 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll<br>[2012/06/13 08:09:01 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll<br>[2012/06/13 08:09:01 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll<br>[2012/06/13 08:09:01 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll<br>[2012/06/13 08:09:01 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll<br>[2012/06/13 08:09:00 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll<br>[2012/06/13 08:09:00 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll<br>[2012/06/13 08:09:00 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe<br>[2012/06/13 08:09:00 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe<br>[2012/06/13 08:08:58 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll<br>[2012/06/13 08:08:58 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl<br>[2012/06/13 08:08:58 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl<br>[2012/06/13 08:08:58 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll<br>[2012/06/13 08:08:57 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll<br> <br>[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]<br> <br>[2012/07/11 21:54:40 | 002,095,484 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\0502020.003\Cat.DB<br>[2012/07/11 21:53:09 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job<br>[2012/07/11 21:46:46 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\kim\Desktop\OTL.exe<br>[2012/07/11 21:44:59 | 000,001,180 | ---- | M] () -- C:\Users\kim\Desktop\My Pictures - Shortcut.lnk<br>[2012/07/11 21:44:55 | 000,001,153 | ---- | M] () -- C:\Users\kim\Desktop\My Music - Shortcut.lnk<br>[2012/07/11 21:44:47 | 000,001,193 | ---- | M] () -- C:\Users\kim\Desktop\My Documents - Shortcut.lnk<br>[2012/07/11 21:22:03 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk<br>[2012/07/11 21:21:43 | 000,002,016 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk<br>[2012/07/11 21:20:20 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job<br>[2012/07/11 21:17:30 | 000,015,984 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0<br>[2012/07/11 21:17:30 | 000,015,984 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0<br>[2012/07/11 21:15:40 | 000,726,444 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI<br>[2012/07/11 21:15:40 | 000,624,162 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat<br>[2012/07/11 21:15:40 | 000,106,538 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat<br>[2012/07/11 21:10:10 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat<br>[2012/07/11 21:10:06 | 3213,537,280 | -HS- | M] () -- C:\hiberfil.sys<br>[2012/07/04 10:11:21 | 000,000,324 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForkim.job<br>[2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys<br>[2012/07/02 09:34:24 | 000,001,847 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk<br>[2012/06/15 07:47:11 | 000,329,176 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT<br>[2012/06/12 19:17:36 | 000,002,379 | ---- | M] () -- C:\Users\Public\Desktop\Norton 360.lnk<br> <br>[color=#E56717]========== Files Created - No Company Name ==========[/color]<br> <br>[2012/07/11 21:44:59 | 000,001,180 | ---- | C] () -- C:\Users\kim\Desktop\My Pictures - Shortcut.lnk<br>[2012/07/11 21:44:55 | 000,001,153 | ---- | C] () -- C:\Users\kim\Desktop\My Music - Shortcut.lnk<br>[2012/07/11 21:44:47 | 000,001,193 | ---- | C] () -- C:\Users\kim\Desktop\My Documents - Shortcut.lnk<br>[2012/07/11 21:22:03 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk<br>[2012/07/11 21:21:12 | 000,002,016 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk<br>[2012/07/11 21:21:11 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk<br>[2012/07/02 09:34:24 | 000,001,847 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk<br>[2012/01/21 13:10:43 | 000,014,358 | ---- | C] () -- C:\Users\kim\AppData\Local\tmpDOWNSIZED_0120122136[1]_navi.JPG<br>[2012/01/21 13:10:30 | 000,029,401 | ---- | C] () -- C:\Users\kim\AppData\Local\tmpDOWNSIZED_0120122136[1].JPG<br>[2012/01/21 13:10:30 | 000,028,104 | ---- | C] () -- C:\Users\kim\AppData\Local\tmpDOWNSIZED_0120122136[1].0<br>[2011/11/13 21:08:36 | 001,939,766 | ---- | C] () -- C:\Users\kim\AppData\Local\tmpM,ANNUALHEALTHASSESS.0<br>[2011/11/13 21:08:36 | 000,407,504 | ---- | C] () -- C:\Users\kim\AppData\Local\tmpM,ANNUALHEALTHASSESS.JPG<br>[2011/05/15 22:10:07 | 000,001,854 | ---- | C] () -- C:\Users\kim\AppData\Roaming\GhostObjGAFix.xml<br>[2010/08/15 10:02:13 | 000,001,212 | ---- | C] () -- C:\Users\kim\AppData\Roaming\wklnhst.dat<br>[2009/11/08 10:14:39 | 000,129,173 | ---- | C] () -- C:\Users\kim\AppData\Local\tmpHWEEN3[1].JPG<br> <br>[color=#E56717]========== LOP Check ==========[/color]<br> <br>[2009/12/31 22:17:40 | 000,000,000 | ---D | M] -- C:\Users\kim\AppData\Roaming\American Airlines DealFinder<br>[2011/07/31 11:13:04 | 000,000,000 | ---D | M] -- C:\Users\kim\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1<br>[2009/11/01 20:47:07 | 000,000,000 | ---D | M] -- C:\Users\kim\AppData\Roaming\PictureMover<br>[2010/08/15 10:02:14 | 000,000,000 | ---D | M] -- C:\Users\kim\AppData\Roaming\Template<br>[2009/11/16 17:47:14 | 000,000,000 | ---D | M] -- C:\Users\kim\AppData\Roaming\WinBatch<br>[2012/05/01 07:55:50 | 000,000,552 | ---- | M] () -- C:\Windows\Tasks\PCDRScheduledMaintenance.job<br>[2011/09/16 21:23:19 | 000,032,646 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT<br> <br>[color=#E56717]========== Purity Check ==========[/color]<br> <br> <br><br>< End of report ><br><small>--<br>He used to say that soul shine, is better than sunshine, better than moonshine, damn sure better than rain.<br><br><A HREF="http://www.2012hoax.org/">Debunking the 2012 hysteria.</a> | Always looking for a new job | Begging the Wilpons to sell the Mets.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Is-this-PC-infected-27324023</guid>
<pubDate>Thu, 12 Jul 2012 20:46:24 EDT</pubDate>
</item>

</channel>
</rss>
