Jump to content

The specified device does not exist as an installed service


Recommended Posts

Please Help!!

Vista....."Severe Alert" Ran McAfee and found trojan and removed. Could not run Mbam. Started in safe mode ram Mbam found/removed 2 trojans. No network connectivity, Any attempt to restart DNS etc returns "The specified device does not exist as an installed service". Ran HiJaCK THIS.

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 7:13:10 PM, on 5/23/2012

Platform: Windows Vista SP2 (WinNT 6.00.1906)

MSIE: Internet Explorer v9.00 (9.00.8112.16421)

Boot mode: Normal

Running processes:

C:\Program Files (x86)\Microsoft Money\System\Money Express.exe

C:\Program Files (x86)\Dell Video Chat\DellVideoChat.exe

C:\Program Files (x86)\The Weather Channel FW\Desktop\DesktopWeather.exe

C:\Program Files (x86)\Dell\Dell Webcam Manager\DellWMgr.exe

C:\Windows\SysWOW64\rundll32.exe

C:\DSI\FID-FARINA\inetupapp.exe

C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe

C:\DSI\FIDLITE\inetupapp.exe

C:\DSI\FIDLITE2\inetupapp.exe

C:\DSI\FIDLITE3\inetupapp.exe

C:\DSI\OLDREPLITE2\inetupapp.exe

C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

C:\Program Files (x86)\Java\jre6\bin\jusched.exe

C:\Windows\SysWOW64\rundll32.exe

C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

C:\Users\Sharon\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.c...client&ie=UTF-8

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: StartNowToolbarHelper - {6E13D095-45C3-4271-9475-F3B48227DD9F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll

O2 - BHO: WindowShopper - {74F475FA-6C75-43BD-AAB9-ECDA6184F600} - C:\Program Files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll

O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll

O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120426182648.dll

O2 - BHO: Browse For Change BHO - {912C156F-05CF-4B62-851A-96E167A677B0} - mscoree.dll (file missing)

O2 - BHO: Wajam IE BHO - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\wajam.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files (x86)\Dell\BAE\BAE.dll

O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O3 - Toolbar: StartNow Toolbar - {5911488E-9D1E-40ec-8CBB-06B231CC153F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll

O3 - Toolbar: (no name) - {06C7AD57-B655-418D-9AB8-9526A6D2E052} - (no file)

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files (x86)\Dell\Dell Webcam Manager\DellWMgr.exe" /s

O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe"

O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m

O4 - HKLM\..\Run: [OEM05Mon.exe] C:\Windows\OEM05Mon.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey

O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"

O4 - HKLM\..\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files (x86)\Microsoft Money\System\Money Express.exe"

O4 - HKCU\..\Run: [sightSpeed] "C:\Program Files (x86)\Dell Video Chat\DellVideoChat.exe" -bootmode

O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [DW6] "C:\Program Files (x86)\The Weather Channel FW\Desktop\DesktopWeather.exe"

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [kprcl] rundll32.exe "C:\Users\Sharon\AppData\Local\Temp\kprcl.dll",Wiz_SingleEntryUnzip

O4 - HKCU\..\Run: [nsutut] rundll32.exe "C:\Users\Sharon\AppData\Local\Temp\nsutut.dll",IntersectTri

O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe

O4 - Startup: Displaysoft Online Updates - c--DSI-FID-FARINA.lnk = C:\DSI\FID-FARINA\inetupapp.exe

O4 - Startup: Displaysoft Online Updates - C--DSI-FIDLITE.lnk = C:\DSI\FIDLITE\inetupapp.exe

O4 - Startup: Displaysoft Online Updates - c--DSI-FIDLITE2.lnk = C:\DSI\FIDLITE2\inetupapp.exe

O4 - Startup: Displaysoft Online Updates - c--DSI-FIDLITE3.lnk = C:\DSI\FIDLITE3\inetupapp.exe

O4 - Startup: Displaysoft Online Updates - c--DSI-OLDREPLITE.lnk = C:\DSI\OLDREPLITE\inetupapp.exe

O4 - Startup: Displaysoft Online Updates - c--DSI-OLDREPLITE2.lnk = C:\DSI\OLDREPLITE2\inetupapp.exe

O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Window Shopper - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - C:\Program Files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O15 - Trusted Zone: http://www.caldirectsecuredocs.com

O15 - Trusted Zone: http://microsite.coupons.com

O15 - Trusted Zone: http://www.ditechsecuredocs.com

O15 - Trusted Zone: http://www.ditechsecuredocs.net

O15 - Trusted Zone: http://www.docmagic.com

O15 - Trusted Zone: http://gateway.elynx.com

O15 - Trusted Zone: http://stest.lane100.elynx.com

O15 - Trusted Zone: http://stest.lane200.elynx.com

O15 - Trusted Zone: http://aegis.elynx.net

O15 - Trusted Zone: http://ctest.elynx.net

O15 - Trusted Zone: http://ctest.lane100.elynx.net

O15 - Trusted Zone: http://forms.elynx.net

O15 - Trusted Zone: http://gateway.elynx.net

O15 - Trusted Zone: http://gateway.ctest.elynx.net

O15 - Trusted Zone: http://gmacforms.elynx.net

O15 - Trusted Zone: http://pro.elynx.net

O15 - Trusted Zone: http://secure.elynx.net

O15 - Trusted Zone: http://ssctest.elynx.net

O15 - Trusted Zone: http://stest.elynx.net

O15 - Trusted Zone: http://usign.elynx.net

O15 - Trusted Zone: http://webpost.elynx.net

O15 - Trusted Zone: http://www.gmacmsecuredocs.com

O15 - Trusted Zone: http://www.gmacmsecuredocs.net

O15 - Trusted Zone: http://www.gmamcsecuredocs.com

O15 - Trusted Zone: http://mortgage-esign.us.hsbc.com

O15 - Trusted Zone: http://*.mcafee.com

O15 - Trusted Zone: http://loandocs.ss3.swiftsend.com

O15 - Trusted Zone: http://docs.swiftsend.com

O15 - Trusted Zone: http://gateway.swiftsend.com

O15 - Trusted Zone: http://loandocs.swiftsend.com

O15 - Trusted Zone: http://loandocs.ss3.swiftsend.com

O15 - Trusted Zone: http://www.swiftsend.com

O15 - Trusted Zone: http://docs.swiftsend2.com

O15 - Trusted Zone: http://loandocs.swiftsend2.com

O15 - Trusted Zone: http://products.swiftview.com

O15 - Trusted Zone: http://www.swiftview.com

O15 - Trusted Zone: http://www.wamuloandocs.com

O16 - DPF: {7DD62E58-5FA8-11D2-AFB7-00104B64F127} (Sview Control) - https://secure.elynx...ll_t_zhp_ss.exe

O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~2\mcafee\msc\mcsniepl.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)

O23 - Service: B-Service - Unknown owner - C:\Users\Sharon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D7RD6PBX\B-Service.exe (file missing)

O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)

O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe

O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files (x86)\Common Files\Motive\McciCMService.exe

O23 - Service: McciCMService64 - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe

O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe

O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe

O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe

O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe

O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe

O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: SessionLauncher - Unknown owner - C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe (file missing)

O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_4b8037c7\STacSV64.exe (file missing)

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: Toolbar Updater Service - Unknown owner - C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: WajamUpdater - Wajam - C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

End of file - 15763 bytes

Link to post
Share on other sites

  • Replies 106
  • Created
  • Last Reply

Top Posters In This Topic

Hello and :welcome:

We need to see some information about what is happening in your machine. Please perform the following scan:

  • Download DDS by sUBs from one of the following links. Save it to your desktop.

    [*]Double click on the DDS icon, allow it to run.

    [*]A small box will open, with an explaination about the tool. No input is needed, the scan is running.

    [*]Notepad will open with the results.

    [*]Follow the instructions that pop up for posting the results.

    [*]Close the program window, and delete the program from your desktop.

Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

Link to post
Share on other sites

Hello and :welcome:

We need to see some information about what is happening in your machine. Please perform the following scan:

  • Download DDS by sUBs from one of the following links. Save it to your desktop.

    [*]Double click on the DDS icon, allow it to run.

    [*]A small box will open, with an explaination about the tool. No input is needed, the scan is running.

    [*]Notepad will open with the results.

    [*]Follow the instructions that pop up for posting the results.

    [*]Close the program window, and delete the program from your desktop.

Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

Thank you Elise. I couldn't figure out how to attach. I hope this is OK. Thanks again,

.

DDS (Ver_2011-08-26.01) - NTFSAMD64 MINIMAL

Internet Explorer: 9.0.8112.16421

Run by Sharon at 6:52:29 on 2012-05-24

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.6077.5438 [GMT -4:00]

.

AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}

FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k rpcss

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\Explorer.EXE

C:\Windows\helppane.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\SysWOW64\cscript.exe

C:\Windows\system32\wbem\wmiprvse.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = https://www.google.com/webhp?sourceid=navclient&ie=UTF-8

uSearch Bar = Preserve

uWindow Title = Internet Explorer provided by Dell

mDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4081204

BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

BHO: StartNow Toolbar Helper: {6e13d095-45c3-4271-9475-f3b48227dd9f} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll

BHO: Window Shopper: {74f475fa-6c75-43bd-aab9-ecda6184f600} - C:\Program Files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll

BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll

BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120426182648.dll

BHO: Browse For Change BHO: {912c156f-05cf-4b62-851a-96e167a677b0} - mscoree.dll

BHO: Wajam: {a7a6995d-6ee1-4fd1-a258-49395d5bf99c} - C:\Program Files (x86)\Wajam\IE\wajam.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - C:\Program Files (x86)\Dell\BAE\BAE.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

TB: StartNow Toolbar: {5911488e-9d1e-40ec-8cbb-06b231cc153f} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll

TB: {06C7AD57-B655-418D-9AB8-9526A6D2E052} - No File

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

TB: {5BED3930-2E9E-76D8-BACC-80DF2188D455} - No File

TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

uRun: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

uRun: [MoneyAgent] "C:\Program Files (x86)\Microsoft Money\System\Money Express.exe"

uRun: [sightSpeed] "C:\Program Files (x86)\Dell Video Chat\DellVideoChat.exe" -bootmode

uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

uRun: [DW6] "C:\Program Files (x86)\The Weather Channel FW\Desktop\DesktopWeather.exe"

uRun: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe

uRun: [kprcl] rundll32.exe "C:\Users\Sharon\AppData\Local\Temp\kprcl.dll",Wiz_SingleEntryUnzip

uRun: [nsutut] rundll32.exe "C:\Users\Sharon\AppData\Local\Temp\nsutut.dll",IntersectTri

uRun: [sliMjbIOjKwyvCu] C:\ProgramData\SliMjbIOjKwyvCu.exe

mRun: [DELL Webcam Manager] "C:\Program Files (x86)\Dell\Dell Webcam Manager\DellWMgr.exe" /s

mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe"

mRun: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m

mRun: [OEM05Mon.exe] C:\Windows\OEM05Mon.exe

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"

mRun: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey

mRun: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"

mRun: [TaskTray]

mRun: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot

mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

StartupFolder: C:\Users\Sharon\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files\Dell\DellDock\DellDock.exe

StartupFolder: C:\Users\Sharon\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DIE9A5~1.LNK - C:\DSI\FID-FARINA\inetupapp.exe

StartupFolder: C:\Users\Sharon\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DISPLA~3.LNK - C:\DSI\FIDLITE\inetupapp.exe

StartupFolder: C:\Users\Sharon\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DISPLA~4.LNK - C:\DSI\FIDLITE2\inetupapp.exe

StartupFolder: C:\Users\Sharon\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DIA955~1.LNK - C:\DSI\FIDLITE3\inetupapp.exe

StartupFolder: C:\Users\Sharon\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DISPLA~1.LNK - C:\DSI\OLDREPLITE\inetupapp.exe

StartupFolder: C:\Users\Sharon\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DISPLA~2.LNK - C:\DSI\OLDREPLITE2\inetupapp.exe

StartupFolder: C:\Users\Sharon\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

mPolicies-explorer: NoActiveDesktop = 1 (0x1)

mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

IE: {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - C:\Program Files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll

Trusted Zone: caldirectsecuredocs.com\www

Trusted Zone: com\pennwest-edocs

Trusted Zone: com\swiftview

Trusted Zone: coupons.com\microsite

Trusted Zone: ditechsecuredocs.com\www

Trusted Zone: ditechsecuredocs.net\www

Trusted Zone: docmagic.com\www

Trusted Zone: elynx.com\gateway

Trusted Zone: elynx.com\stest.lane100

Trusted Zone: elynx.com\stest.lane200

Trusted Zone: elynx.net\aegis

Trusted Zone: elynx.net\ctest

Trusted Zone: elynx.net\ctest.lane100

Trusted Zone: elynx.net\forms

Trusted Zone: elynx.net\gateway

Trusted Zone: elynx.net\gateway.ctest

Trusted Zone: elynx.net\gmacforms

Trusted Zone: elynx.net\pro

Trusted Zone: elynx.net\secure

Trusted Zone: elynx.net\ssctest

Trusted Zone: elynx.net\stest

Trusted Zone: elynx.net\usign

Trusted Zone: elynx.net\webpost

Trusted Zone: gmacmsecuredocs.com\www

Trusted Zone: gmacmsecuredocs.net\www

Trusted Zone: gmamcsecuredocs.com\www

Trusted Zone: hsbc.com\mortgage-esign.us

Trusted Zone: internet

Trusted Zone: mcafee.com

Trusted Zone: real.com\rhap-app-4-0

Trusted Zone: real.com\rhapreg

Trusted Zone: sasrlink.com\www

Trusted Zone: ss3.swiftsend.com\loandocs

Trusted Zone: swiftsend.com\docs

Trusted Zone: swiftsend.com\gateway

Trusted Zone: swiftsend.com\loandocs

Trusted Zone: swiftsend.com\loandocs.ss3

Trusted Zone: swiftsend.com\www

Trusted Zone: swiftsend2.com\docs

Trusted Zone: swiftsend2.com\loandocs

Trusted Zone: swiftview.com\products

Trusted Zone: swiftview.com\www

Trusted Zone: wamuloandocs.com\www

DPF: {7DD62E58-5FA8-11D2-AFB7-00104B64F127} - hxxps://secure.elynx.net/viewer/installers/svinstall_t_zhp_ss.exe

TCP: DhcpNameServer = 192.168.1.254

TCP: Interfaces\{8F1048E6-5993-4463-B935-A81362C82E06} : DhcpNameServer = 192.168.1.254

Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\McAfee\MSC\McSnIePl.dll

Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll

Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll

BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File

BHO-X64: 0x1 - No File

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

BHO-X64: StartNow Toolbar Helper: {6E13D095-45C3-4271-9475-F3B48227DD9F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll

BHO-X64: StartNowToolbarHelper - No File

BHO-X64: Window Shopper: {74F475FA-6C75-43BD-AAB9-ECDA6184F600} - C:\Program Files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll

BHO-X64: WindowShopper - No File

BHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll

BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120426182648.dll

BHO-X64: scriptproxy - No File

BHO-X64: Browse For Change BHO: {912C156F-05CF-4B62-851A-96E167A677B0} - mscoree.dll

BHO-X64: Wajam: {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\wajam.dll

BHO-X64: Wajam IE BHO - No File

BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

BHO-X64: CBrowserHelperObject Object: {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files (x86)\Dell\BAE\BAE.dll

BHO-X64: Browser Address Error Redirector - No File

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

TB-X64: StartNow Toolbar: {5911488E-9D1E-40ec-8CBB-06B231CC153F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll

TB-X64: {06C7AD57-B655-418D-9AB8-9526A6D2E052} - No File

TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

TB-X64: {5BED3930-2E9E-76D8-BACC-80DF2188D455} - No File

TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

mRun-x64: [DELL Webcam Manager] "C:\Program Files (x86)\Dell\Dell Webcam Manager\DellWMgr.exe" /s

mRun-x64: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe"

mRun-x64: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m

mRun-x64: [OEM05Mon.exe] C:\Windows\OEM05Mon.exe

mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"

mRun-x64: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey

mRun-x64: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun-x64: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"

mRun-x64: [TaskTray]

mRun-x64: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot

mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=

FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)

FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?AF=110788&babsrc=HP_ss&mntrId=9ed8a32200000000000000221912be2a

FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?AF=110788&babsrc=adbartrp&mntrId=9ed8a32200000000000000221912be2a&q=

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 57273

FF - prefs.js: network.proxy.type - 0

FF - plugin: c:\progra~2\mcafee\msc\npMcSnFFPl.dll

FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll

FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll

FF - plugin: C:\Program Files (x86)\McAfee\Supportability\MVT\NPMVTPlugin.dll

FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npsview.dll

FF - plugin: C:\Program Files (x86)\SwiftView\npsview.dll

FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll

FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll

.

---- FIREFOX POLICIES ----

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110788

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.id - 9ed8a32200000000000000221912be2a

FF - user.js: extensions.BabylonToolbar_i.hardId - 9ed8a32200000000000000221912be2a

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15408

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:14:24

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

.

============= SERVICES / DRIVERS ===============

.

R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]

S0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]

S1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\system32\DRIVERS\mfenlfk.sys --> C:\Windows\system32\DRIVERS\mfenlfk.sys [?]

S1 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys --> C:\Windows\system32\drivers\mfewfpk.sys [?]

S2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-2-16 249936]

S2 McShield;McAfee McShield;C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe [2011-2-16 199272]

S2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2011-2-16 210584]

S2 mfevtp;McAfee Validation Trust Protection Service;"C:\Windows\system32\mfevtps.exe" --> C:\Windows\system32\mfevtps.exe [?]

S2 SessionLauncher;SessionLauncher;C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe --> C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [?]

S3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]

S3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]

S3 B-Service;B-Service;C:\Users\Sharon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D7RD6PBX\B-Service.exe --> C:\Users\Sharon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D7RD6PBX\B-Service.exe [?]

S3 cfwids;McAfee Inc. cfwids;C:\Windows\system32\drivers\cfwids.sys --> C:\Windows\system32\drivers\cfwids.sys [?]

S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-9-11 89920]

S3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys --> C:\Windows\system32\drivers\mfeavfk.sys [?]

S3 mfefirek;McAfee Inc. mfefirek;C:\Windows\system32\drivers\mfefirek.sys --> C:\Windows\system32\drivers\mfefirek.sys [?]

S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys --> C:\Windows\system32\drivers\mferkdet.sys [?]

S3 mferkdk;McAfee Inc. mferkdk;C:\Windows\system32\drivers\mferkdk.sys --> C:\Windows\system32\drivers\mferkdk.sys [?]

S3 mfesmfk;McAfee Inc. mfesmfk;C:\Windows\system32\drivers\mfesmfk.sys --> C:\Windows\system32\drivers\mfesmfk.sys [?]

S3 OEM05Afx;Provides a software interface to control audio effects of OEM005 camera.;\??\C:\Windows\system32\Drivers\OEM05Afx.sys --> C:\Windows\system32\Drivers\OEM05Afx.sys [?]

S3 OEM05Vfx;Creative Camera OEM005 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM05Vfx.sys --> C:\Windows\system32\DRIVERS\OEM05Vfx.sys [?]

S3 OEM05Vid;Creative Camera OEM005 Driver;C:\Windows\system32\DRIVERS\OEM05Vid.sys --> C:\Windows\system32\DRIVERS\OEM05Vid.sys [?]

S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]

S3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;C:\Windows\system32\DRIVERS\livecamv.sys --> C:\Windows\system32\DRIVERS\livecamv.sys [?]

S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-3-30 257696]

S4 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]

S4 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2008-9-23 155648]

S4 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-5-4 136176]

S4 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-5-4 136176]

S4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [2009-8-24 102608]

S4 McciCMService64;McciCMService64;C:\Program Files\Common Files\Motive\McciCMService.exe [2011-1-7 517632]

S4 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-2-16 249936]

S4 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-2-16 249936]

S4 RoxLiveShare10;LiveShare P2P Server 10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [2008-5-14 309744]

S4 RoxMediaDB10;RoxMediaDB10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-5-14 1120752]

S4 RoxWatch10;Roxio Hard Drive Watcher 10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [2008-5-14 166384]

.

=============== File Associations ===============

.

JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*

.

=============== Created Last 30 ================

.

2012-05-24 00:27:17 -------- d-----w- C:\$WINDOWS.~BT

2012-05-23 12:11:31 -------- d-----w- C:\Users\Sharon\AppData\Local\{682CD89D-A4D0-11E1-8270-B8AC6F996F26}

2012-05-23 12:10:43 -------- d-----w- C:\Users\Sharon\AppData\Local\Start

2012-05-23 12:10:43 -------- d-----w- C:\ProgramData\B7E8587A00047CF10023A3B1570F1C8B

2012-05-22 11:42:54 8955792 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BB8125EF-2731-4E4E-B9D7-CF0D1DC71118}\mpengine.dll

2012-05-11 12:03:04 1423744 ----a-w- C:\Windows\System32\drivers\tcpip.sys

2012-04-26 22:26:47 29272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\ScriptFF.dll

.

==================== Find3M ====================

.

2012-05-05 16:01:02 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2012-05-05 16:01:02 419488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2012-05-05 16:00:56 8744608 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe

2012-04-04 19:56:40 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys

2012-04-03 08:22:15 4699520 ----a-w- C:\Windows\System32\ntoskrnl.exe

2012-04-02 13:59:51 2766848 ----a-w- C:\Windows\System32\win32k.sys

2012-03-20 23:34:30 72576 ----a-w- C:\Windows\System32\drivers\partmgr.sys

2012-03-20 17:11:30 162192 ----a-w- C:\Windows\System32\mfevtps.exe

2012-03-01 15:39:45 327680 ----a-w- C:\Windows\System32\d3d10_1core.dll

2012-03-01 15:39:45 196096 ----a-w- C:\Windows\System32\d3d10_1.dll

2012-03-01 14:46:01 219648 ----a-w- C:\Windows\SysWow64\d3d10_1core.dll

2012-03-01 14:46:01 160768 ----a-w- C:\Windows\SysWow64\d3d10_1.dll

2012-02-29 15:37:41 5632 ----a-w- C:\Windows\System32\wmi.dll

2012-02-29 15:37:38 219136 ----a-w- C:\Windows\System32\wintrust.dll

2012-02-29 15:35:44 78848 ----a-w- C:\Windows\System32\imagehlp.dll

2012-02-29 15:11:45 5120 ----a-w- C:\Windows\SysWow64\wmi.dll

2012-02-29 15:11:42 172032 ----a-w- C:\Windows\SysWow64\wintrust.dll

2012-02-29 15:09:53 157696 ----a-w- C:\Windows\SysWow64\imagehlp.dll

2012-02-29 14:40:31 2002944 ----a-w- C:\Windows\System32\d3d10warp.dll

2012-02-29 14:09:35 834048 ----a-w- C:\Windows\System32\d2d1.dll

2012-02-29 14:08:47 1172480 ----a-w- C:\Windows\SysWow64\d3d10warp.dll

2012-02-29 14:06:08 1556480 ----a-w- C:\Windows\System32\DWrite.dll

2012-02-29 13:52:46 16384 ----a-w- C:\Windows\System32\drivers\fs_rec.sys

2012-02-29 13:44:50 683008 ----a-w- C:\Windows\SysWow64\d2d1.dll

2012-02-29 13:41:40 1069056 ----a-w- C:\Windows\SysWow64\DWrite.dll

2012-02-28 06:56:48 2311168 ----a-w- C:\Windows\System32\jscript9.dll

2012-02-28 06:49:56 1390080 ----a-w- C:\Windows\System32\wininet.dll

2012-02-28 06:48:57 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl

2012-02-28 06:42:55 2382848 ----a-w- C:\Windows\System32\mshtml.tlb

2012-02-28 01:18:55 1799168 ----a-w- C:\Windows\SysWow64\jscript9.dll

2012-02-28 01:11:21 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl

2012-02-28 01:11:07 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll

2012-02-28 01:03:16 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb

.

============= FINISH: 6:55:09.29 ===============

Link to post
Share on other sites

Hi, indeed a few things that don't belong there. :)

COMBOFIX

---------------

Please download ComboFix from one of these locations:


Bleepingcomputer
ForoSpyware

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on Combofix.exe and follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, or if you are running Vista, ComboFix will continue it's malware removal procedures.

Query_RC.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

RC_successful.gif

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\Combofix.txt in your next reply.

Link to post
Share on other sites

Hello, I just ran Combofix. The machine rebooted and

1) Theres a warning that "No amd graphics card is installed or is not functioning properly..."

2) There is an empty Combofix window that looks like shuffling cards, moving constantly

3) Can open Task Manager, but can't seem to use it. Can't do much of anything at all now.

4) Tried to start id safe mode, but comes up with 'start normally' and can not move the highlight with arrow keys to select other options.

UPDATE!

I was able to start in safe mode and will post the log:

ComboFix 12-05-24.02 - Sharon 05/24/2012 17:19:46.1.4 - x64 NETWORK

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.6077.5226 [GMT -4:00]

Running from: c:\users\Sharon\Desktop\ComboFix.exe

AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}

FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\program files (x86)\StartNow Toolbar

c:\program files (x86)\StartNow Toolbar\Resources\images\btn-msn.png

c:\program files (x86)\StartNow Toolbar\Resources\images\chevronButton.png

c:\program files (x86)\StartNow Toolbar\Resources\images\engine_images.png

c:\program files (x86)\StartNow Toolbar\Resources\images\engine_maps.png

c:\program files (x86)\StartNow Toolbar\Resources\images\engine_news.png

c:\program files (x86)\StartNow Toolbar\Resources\images\engine_videos.png

c:\program files (x86)\StartNow Toolbar\Resources\images\engine_web.png

c:\program files (x86)\StartNow Toolbar\Resources\images\icon_amazon.png

c:\program files (x86)\StartNow Toolbar\Resources\images\icon_ebay.png

c:\program files (x86)\StartNow Toolbar\Resources\images\icon_facebook.png

c:\program files (x86)\StartNow Toolbar\Resources\images\icon_games.png

c:\program files (x86)\StartNow Toolbar\Resources\images\icon_shopping.png

c:\program files (x86)\StartNow Toolbar\Resources\images\icon_travel.png

c:\program files (x86)\StartNow Toolbar\Resources\images\icon_twitter.png

c:\program files (x86)\StartNow Toolbar\Resources\images\separator.png

c:\program files (x86)\StartNow Toolbar\Resources\images\splitter.png

c:\program files (x86)\StartNow Toolbar\Resources\images\startnow_logo.png

c:\program files (x86)\StartNow Toolbar\Resources\installer.xml

c:\program files (x86)\StartNow Toolbar\Resources\protect\index.html

c:\program files (x86)\StartNow Toolbar\Resources\protect\NotIE6.css

c:\program files (x86)\StartNow Toolbar\Resources\protect\OnlyIE6.css

c:\program files (x86)\StartNow Toolbar\Resources\protect\SearchProtectIcon.png

c:\program files (x86)\StartNow Toolbar\Resources\protect\window.css

c:\program files (x86)\StartNow Toolbar\Resources\protect\window.js

c:\program files (x86)\StartNow Toolbar\Resources\reactivate\index.html

c:\program files (x86)\StartNow Toolbar\Resources\reactivate\LeftImage.png

c:\program files (x86)\StartNow Toolbar\Resources\reactivate\NotIE6.css

c:\program files (x86)\StartNow Toolbar\Resources\reactivate\OnlyIE6.css

c:\program files (x86)\StartNow Toolbar\Resources\reactivate\window.css

c:\program files (x86)\StartNow Toolbar\Resources\reactivate\window.js

c:\program files (x86)\StartNow Toolbar\Resources\searchbox\dropdown_button_normal.png

c:\program files (x86)\StartNow Toolbar\Resources\searchbox\searchbox_button_hover.png

c:\program files (x86)\StartNow Toolbar\Resources\searchbox\searchbox_button_normal.png

c:\program files (x86)\StartNow Toolbar\Resources\searchbox\searchbox_input_left.png

c:\program files (x86)\StartNow Toolbar\Resources\searchbox\searchbox_input_middle.png

c:\program files (x86)\StartNow Toolbar\Resources\toolbar.xml

c:\program files (x86)\StartNow Toolbar\Resources\toolbarbutton\hover_c.png

c:\program files (x86)\StartNow Toolbar\Resources\toolbarbutton\hover_l.png

c:\program files (x86)\StartNow Toolbar\Resources\toolbarbutton\hover_r.png

c:\program files (x86)\StartNow Toolbar\Resources\toolbarbutton\normal_c.png

c:\program files (x86)\StartNow Toolbar\Resources\toolbarbutton\normal_l.png

c:\program files (x86)\StartNow Toolbar\Resources\toolbarbutton\normal_r.png

c:\program files (x86)\StartNow Toolbar\Resources\update.xml

c:\program files (x86)\StartNow Toolbar\Toolbar32.dll

c:\program files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe

c:\program files (x86)\StartNow Toolbar\uninstall.dat

c:\users\Sharon\AppData\Local\Temp\kprcl.dll

c:\users\Sharon\AppData\Local\Temp\nsutut.dll

c:\users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Repair

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome.manifest

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\bar.js

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\bar.xul

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\buttons.js

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\constants.js

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\events.js

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\globals.js

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\btn-msn.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\engine_images.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\engine_maps.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\engine_news.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\engine_videos.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\engine_web.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\icon_amazon.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\icon_ebay.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\icon_facebook.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\icon_games.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\icon_shopping.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\icon_travel.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\icon_twitter.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\searchbox_button.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\img\startnow_logo.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\init.js

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\protect\index.html

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\protect\NotIE6.css

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\protect\OnlyIE6.css

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\protect\SearchProtectIcon.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\protect\window.css

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\protect\window.js

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\searchkeeper.js

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\searchkeeper.xul

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\xml\installer.xml

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\xml\toolbar.xml

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\locale\en-US\{F02577FF-29CE-4130-8171-B51D94ECA96E}.dtd

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\skin\butoon-hover-background.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\skin\overlay.css

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\skin\search.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\skin\searchBackground.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\skin\splitter.png

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\install.rdf

c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\searchplugins\bing-zugo.xml

c:\users\Sharon\AppData\Roaming\svfiles.log

c:\users\Sharon\Desktop\Scanner.lnk

c:\users\Sharon\GoToAssistDownloadHelper.exe

c:\users\Sharon\Taskmgr.exe

c:\windows\system\olepro32.dll

c:\windows\SysWow64\bidisp.dll

c:\windows\SysWow64\BSTIEPrintCtl1.dll

c:\windows\SysWow64\zip32.dll

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Service_Toolbar Updater Service

-------\Service_Toolbar Updater Service

.

.

((((((((((((((((((((((((( Files Created from 2012-04-25 to 2012-05-25 )))))))))))))))))))))))))))))))

.

.

2012-05-24 21:31 . 2012-05-24 22:05 -------- d-----w- c:\users\Sharon\AppData\Local\temp

2012-05-24 21:31 . 2012-05-24 21:31 -------- d-----w- c:\users\Public\AppData\Local\temp

2012-05-24 21:31 . 2012-05-24 21:31 -------- d-----w- c:\users\Dragonlady\AppData\Local\temp

2012-05-24 21:31 . 2012-05-24 21:31 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-05-24 00:27 . 2012-05-24 00:27 -------- d-----w- C:\$WINDOWS.~BT

2012-05-23 12:11 . 2012-05-23 12:11 -------- d-----w- c:\users\Sharon\AppData\Local\{682CD89D-A4D0-11E1-8270-B8AC6F996F26}

2012-05-23 12:10 . 2012-05-23 22:40 -------- d-----w- c:\users\Sharon\AppData\Local\Start

2012-05-23 12:10 . 2012-05-23 12:10 -------- d-----w- c:\programdata\B7E8587A00047CF10023A3B1570F1C8B

2012-05-22 11:42 . 2012-05-08 17:02 8955792 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BB8125EF-2731-4E4E-B9D7-CF0D1DC71118}\mpengine.dll

2012-05-11 12:03 . 2012-03-30 12:45 1423744 ----a-w- c:\windows\system32\drivers\tcpip.sys

2012-04-26 22:26 . 2012-03-20 17:06 29272 ----a-w- c:\program files (x86)\Mozilla Firefox\ScriptFF.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-05-05 16:01 . 2012-03-30 11:37 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-05-05 16:01 . 2011-06-14 11:40 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-05-05 16:00 . 2012-03-30 12:01 8744608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe

2012-04-04 19:56 . 2009-09-30 00:01 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-03-20 17:11 . 2011-02-16 12:45 162192 ----a-w- c:\windows\system32\mfevtps.exe

2012-02-29 15:37 . 2012-04-12 11:46 5632 ----a-w- c:\windows\system32\wmi.dll

2012-02-29 15:37 . 2012-04-12 11:46 219136 ----a-w- c:\windows\system32\wintrust.dll

2012-02-29 15:35 . 2012-04-12 11:46 78848 ----a-w- c:\windows\system32\imagehlp.dll

2012-02-29 15:11 . 2012-04-12 11:46 5120 ----a-w- c:\windows\SysWow64\wmi.dll

2012-02-29 15:11 . 2012-04-12 11:46 172032 ----a-w- c:\windows\SysWow64\wintrust.dll

2012-02-29 15:09 . 2012-04-12 11:46 157696 ----a-w- c:\windows\SysWow64\imagehlp.dll

2012-02-29 13:52 . 2012-04-12 11:46 16384 ----a-w- c:\windows\system32\drivers\fs_rec.sys

2012-02-28 06:56 . 2012-04-12 11:49 2311168 ----a-w- c:\windows\system32\jscript9.dll

2012-02-28 06:49 . 2012-04-12 11:49 1390080 ----a-w- c:\windows\system32\wininet.dll

2012-02-28 06:48 . 2012-04-12 11:49 1493504 ----a-w- c:\windows\system32\inetcpl.cpl

2012-02-28 06:42 . 2012-04-12 11:49 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-02-28 01:18 . 2012-04-12 11:49 1799168 ----a-w- c:\windows\SysWow64\jscript9.dll

2012-02-28 01:11 . 2012-04-12 11:49 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl

2012-02-28 01:11 . 2012-04-12 11:49 1127424 ----a-w- c:\windows\SysWow64\wininet.dll

2012-02-28 01:03 . 2012-04-12 11:49 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]

"MoneyAgent"="c:\program files (x86)\Microsoft Money\System\Money Express.exe" [2000-07-19 176183]

"SightSpeed"="c:\program files (x86)\Dell Video Chat\DellVideoChat.exe" [2008-08-15 4812664]

"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-05-04 39408]

"DW6"="c:\program files (x86)\The Weather Channel FW\Desktop\DesktopWeather.exe" [2011-06-08 822456]

"WMPNSCFG"="c:\program files (x86)\Windows Media Player\WMPNSCFG.exe" [bU]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"DELL Webcam Manager"="c:\program files (x86)\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]

"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2008-05-14 244208]

"Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2009-07-07 1779952]

"OEM05Mon.exe"="c:\windows\OEM05Mon.exe" [2007-08-22 36864]

"SunJavaUpdateSched"="c:\program files (x86)\Java\jre6\bin\jusched.exe" [2009-01-04 136600]

"Malwarebytes Anti-Malware (reboot)"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2012-04-04 981680]

"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1675160]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-26 336384]

"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]

"TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-11-26 296056]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]

.

c:\users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]

Displaysoft Online Updates - c--DSI-FID-FARINA.lnk - c:\dsi\FID-FARINA\inetupapp.exe [2010-12-23 757760]

Displaysoft Online Updates - C--DSI-FIDLITE.lnk - c:\dsi\FIDLITE\inetupapp.exe [2009-7-16 757760]

Displaysoft Online Updates - c--DSI-FIDLITE2.lnk - c:\dsi\FIDLITE2\inetupapp.exe [2009-7-16 757760]

Displaysoft Online Updates - c--DSI-FIDLITE3.lnk - c:\dsi\FIDLITE3\inetupapp.exe [2009-7-16 757760]

Displaysoft Online Updates - c--DSI-OLDREPLITE.lnk - c:\dsi\OLDREPLITE\inetupapp.exe [2009-7-16 757760]

Displaysoft Online Updates - c--DSI-OLDREPLITE2.lnk - c:\dsi\OLDREPLITE2\inetupapp.exe [2010-12-23 757760]

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

.

c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

R4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]

.

.

Contents of the 'Scheduled Tasks' folder

.

2012-05-24 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 16:01]

.

2012-05-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-04 19:45]

.

2012-05-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-04 19:45]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Defender"="DER\MSASCUI.EXE -HIDE" [X]

"(Default)"="" [bU]

"SysTrayApp"="c:\program files (x86)\IDT\WDM\sttray64.exe" [bU]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"LoadAppInit_DLLs"=0x0

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = https://www.google.c...client&ie=UTF-8

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: {{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll

Trusted Zone: caldirectsecuredocs.com\www

Trusted Zone: com\pennwest-edocs

Trusted Zone: com\swiftview

Trusted Zone: coupons.com\microsite

Trusted Zone: ditechsecuredocs.com\www

Trusted Zone: ditechsecuredocs.net\www

Trusted Zone: docmagic.com\www

Trusted Zone: elynx.com\gateway

Trusted Zone: elynx.com\stest.lane100

Trusted Zone: elynx.com\stest.lane200

Trusted Zone: elynx.net\aegis

Trusted Zone: elynx.net\ctest

Trusted Zone: elynx.net\ctest.lane100

Trusted Zone: elynx.net\forms

Trusted Zone: elynx.net\gateway

Trusted Zone: elynx.net\gateway.ctest

Trusted Zone: elynx.net\gmacforms

Trusted Zone: elynx.net\pro

Trusted Zone: elynx.net\secure

Trusted Zone: elynx.net\ssctest

Trusted Zone: elynx.net\stest

Trusted Zone: elynx.net\usign

Trusted Zone: elynx.net\webpost

Trusted Zone: gmacmsecuredocs.com\www

Trusted Zone: gmacmsecuredocs.net\www

Trusted Zone: gmamcsecuredocs.com\www

Trusted Zone: hsbc.com\mortgage-esign.us

Trusted Zone: internet

Trusted Zone: mcafee.com

Trusted Zone: real.com\rhap-app-4-0

Trusted Zone: real.com\rhapreg

Trusted Zone: sasrlink.com\www

Trusted Zone: ss3.swiftsend.com\loandocs

Trusted Zone: swiftsend.com\docs

Trusted Zone: swiftsend.com\gateway

Trusted Zone: swiftsend.com\loandocs

Trusted Zone: swiftsend.com\loandocs.ss3

Trusted Zone: swiftsend.com\www

Trusted Zone: swiftsend2.com\docs

Trusted Zone: swiftsend2.com\loandocs

Trusted Zone: swiftview.com\products

Trusted Zone: swiftview.com\www

Trusted Zone: wamuloandocs.com\www

TCP: DhcpNameServer = 192.168.1.254

DPF: {7DD62E58-5FA8-11D2-AFB7-00104B64F127} - hxxps://secure.elynx.net/viewer/installers/svinstall_t_zhp_ss.exe

CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll

FF - ProfilePath - c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=

FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)

FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?AF=110788&babsrc=HP_ss&mntrId=9ed8a32200000000000000221912be2a

FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?AF=110788&babsrc=adbartrp&mntrId=9ed8a32200000000000000221912be2a&q=

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 57273

FF - prefs.js: network.proxy.type - 0

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110788

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.id - 9ed8a32200000000000000221912be2a

FF - user.js: extensions.BabylonToolbar_i.hardId - 9ed8a32200000000000000221912be2a

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15408

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:14

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-{06C7AD57-B655-418D-9AB8-9526A6D2E052} - (no file)

Wow6432Node-HKCU-Run-SliMjbIOjKwyvCu - c:\programdata\SliMjbIOjKwyvCu.exe

Wow6432Node-HKLM-Run-TaskTray - (no file)

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

HKLM-Run-IAAnotif - OTIF.EXE

HKLM-Run-Dell DataSafe Online - E.EXE

AddRemove-iBryte_browseforchange - c:\program files (x86)\iBryte\browseforchange\uninstall.exe

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]

@Denied: (A 2) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]

@="Shockwave Flash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]

@Denied: (A 2) (Everyone)

@=""

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]

@="FlashBroker"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]

"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

.

Completion time: 2012-05-24 20:26:46 - machine was rebooted

ComboFix-quarantined-files.txt 2012-05-25 00:26

ComboFix2.txt 2011-03-24 22:58

ComboFix3.txt 2011-03-24 00:03

.

Pre-Run: 461,488,988,160 bytes free

Post-Run: 461,082,750,976 bytes free

.

- - End Of File - - BD1488A66CB92DFB5EDF00B65C981E60

Still no network connectivity, and getting the "Service does not exist as an installed service" error when trying to restart services etc

Link to post
Share on other sites

Does the F8 button seem to work (to bring up the advanced boot options)?

CF-SCRIPT

-------------

We need to execute a CF-script.

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Click Start > Run and in the box that opens type notepad and press enter. Copy/paste the text in the codebox below into it:

DDS::
IE: {{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll
Trusted Zone: caldirectsecuredocs.com\www
Trusted Zone: com\pennwest-edocs
Trusted Zone: com\swiftview
Trusted Zone: coupons.com\microsite
Trusted Zone: ditechsecuredocs.com\www
Trusted Zone: ditechsecuredocs.net\www
Trusted Zone: docmagic.com\www
Trusted Zone: elynx.com\gateway
Trusted Zone: elynx.com\stest.lane100
Trusted Zone: elynx.com\stest.lane200
Trusted Zone: elynx.net\aegis
Trusted Zone: elynx.net\ctest
Trusted Zone: elynx.net\ctest.lane100
Trusted Zone: elynx.net\forms
Trusted Zone: elynx.net\gateway
Trusted Zone: elynx.net\gateway.ctest
Trusted Zone: elynx.net\gmacforms
Trusted Zone: elynx.net\pro
Trusted Zone: elynx.net\secure
Trusted Zone: elynx.net\ssctest
Trusted Zone: elynx.net\stest
Trusted Zone: elynx.net\usign
Trusted Zone: elynx.net\webpost
Trusted Zone: gmacmsecuredocs.com\www
Trusted Zone: gmacmsecuredocs.net\www
Trusted Zone: gmamcsecuredocs.com\www
Trusted Zone: hsbc.com\mortgage-esign.us
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
Trusted Zone: sasrlink.com\www
Trusted Zone: ss3.swiftsend.com\loandocs
Trusted Zone: swiftsend.com\docs
Trusted Zone: swiftsend.com\gateway
Trusted Zone: swiftsend.com\loandocs
Trusted Zone: swiftsend.com\loandocs.ss3
Trusted Zone: swiftsend.com\www
Trusted Zone: swiftsend2.com\docs
Trusted Zone: swiftsend2.com\loandocs
Trusted Zone: swiftview.com\products
Trusted Zone: swiftview.com\www
Trusted Zone: wamuloandocs.com\www

Firefox::
FF - ProfilePath - c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?AF=110788&babsrc=HP_ss&mntrId=9ed8a32200000000000000221912be2a
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?AF=110788&babsrc=adbartrp&mntrId=9ed8a32200000000000000221912be2a&q=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 57273

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Link to post
Share on other sites

Hello Elise,

Can get into safe mode so ran the script. Log follows:

ComboFix 12-05-24.02 - Sharon 05/25/2012 6:22.1.4 - x64 NETWORK

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.6077.5238 [GMT -4:00]

Running from: c:\users\Sharon\Desktop\ComboFix.exe

Command switches used :: c:\users\Sharon\Desktop\CFScript.txt

AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}

FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\windows\SysWow64\bidisp.dll

.

.

((((((((((((((((((((((((( Files Created from 2012-04-25 to 2012-05-25 )))))))))))))))))))))))))))))))

.

.

2012-05-25 10:34 . 2012-05-25 10:34 -------- d-----w- c:\users\Public\AppData\Local\temp

2012-05-25 10:34 . 2012-05-25 10:34 -------- d-----w- c:\users\Dragonlady\AppData\Local\temp

2012-05-25 10:34 . 2012-05-25 10:34 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-05-25 01:48 . 2012-05-25 01:48 -------- d-----w- c:\users\Sharon\AppData\Local\Stardock_Corporation

2012-05-25 00:26 . 2012-05-25 10:43 -------- d-----w- c:\users\Sharon\AppData\Local\temp

2012-05-24 00:27 . 2012-05-24 00:27 -------- d-----w- C:\$WINDOWS.~BT

2012-05-23 12:11 . 2012-05-23 12:11 -------- d-----w- c:\users\Sharon\AppData\Local\{682CD89D-A4D0-11E1-8270-B8AC6F996F26}

2012-05-23 12:10 . 2012-05-23 22:40 -------- d-----w- c:\users\Sharon\AppData\Local\Start

2012-05-23 12:10 . 2012-05-23 12:10 -------- d-----w- c:\programdata\B7E8587A00047CF10023A3B1570F1C8B

2012-05-22 11:42 . 2012-05-08 17:02 8955792 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BB8125EF-2731-4E4E-B9D7-CF0D1DC71118}\mpengine.dll

2012-05-11 12:03 . 2012-03-30 12:45 1423744 ----a-w- c:\windows\system32\drivers\tcpip.sys

2012-04-26 22:26 . 2012-03-20 17:06 29272 ----a-w- c:\program files (x86)\Mozilla Firefox\ScriptFF.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-05-05 16:01 . 2012-03-30 11:37 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-05-05 16:01 . 2011-06-14 11:40 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-05-05 16:00 . 2012-03-30 12:01 8744608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe

2012-04-04 19:56 . 2009-09-30 00:01 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-03-20 17:11 . 2011-02-16 12:45 162192 ----a-w- c:\windows\system32\mfevtps.exe

2012-02-29 15:37 . 2012-04-12 11:46 5632 ----a-w- c:\windows\system32\wmi.dll

2012-02-29 15:37 . 2012-04-12 11:46 219136 ----a-w- c:\windows\system32\wintrust.dll

2012-02-29 15:35 . 2012-04-12 11:46 78848 ----a-w- c:\windows\system32\imagehlp.dll

2012-02-29 15:11 . 2012-04-12 11:46 5120 ----a-w- c:\windows\SysWow64\wmi.dll

2012-02-29 15:11 . 2012-04-12 11:46 172032 ----a-w- c:\windows\SysWow64\wintrust.dll

2012-02-29 15:09 . 2012-04-12 11:46 157696 ----a-w- c:\windows\SysWow64\imagehlp.dll

2012-02-29 13:52 . 2012-04-12 11:46 16384 ----a-w- c:\windows\system32\drivers\fs_rec.sys

2012-02-28 06:56 . 2012-04-12 11:49 2311168 ----a-w- c:\windows\system32\jscript9.dll

2012-02-28 06:49 . 2012-04-12 11:49 1390080 ----a-w- c:\windows\system32\wininet.dll

2012-02-28 06:48 . 2012-04-12 11:49 1493504 ----a-w- c:\windows\system32\inetcpl.cpl

2012-02-28 06:42 . 2012-04-12 11:49 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-02-28 01:18 . 2012-04-12 11:49 1799168 ----a-w- c:\windows\SysWow64\jscript9.dll

2012-02-28 01:11 . 2012-04-12 11:49 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl

2012-02-28 01:11 . 2012-04-12 11:49 1127424 ----a-w- c:\windows\SysWow64\wininet.dll

2012-02-28 01:03 . 2012-04-12 11:49 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]

"MoneyAgent"="c:\program files (x86)\Microsoft Money\System\Money Express.exe" [2000-07-19 176183]

"SightSpeed"="c:\program files (x86)\Dell Video Chat\DellVideoChat.exe" [2008-08-15 4812664]

"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-05-04 39408]

"DW6"="c:\program files (x86)\The Weather Channel FW\Desktop\DesktopWeather.exe" [2011-06-08 822456]

"WMPNSCFG"="c:\program files (x86)\Windows Media Player\WMPNSCFG.exe" [bU]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"DELL Webcam Manager"="c:\program files (x86)\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]

"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2008-05-14 244208]

"Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2009-07-07 1779952]

"OEM05Mon.exe"="c:\windows\OEM05Mon.exe" [2007-08-22 36864]

"SunJavaUpdateSched"="c:\program files (x86)\Java\jre6\bin\jusched.exe" [2009-01-04 136600]

"Malwarebytes Anti-Malware (reboot)"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2012-04-04 981680]

"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1675160]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-26 336384]

"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]

"TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-11-26 296056]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]

.

c:\users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]

Displaysoft Online Updates - c--DSI-FID-FARINA.lnk - c:\dsi\FID-FARINA\inetupapp.exe [2010-12-23 757760]

Displaysoft Online Updates - C--DSI-FIDLITE.lnk - c:\dsi\FIDLITE\inetupapp.exe [2009-7-16 757760]

Displaysoft Online Updates - c--DSI-FIDLITE2.lnk - c:\dsi\FIDLITE2\inetupapp.exe [2009-7-16 757760]

Displaysoft Online Updates - c--DSI-FIDLITE3.lnk - c:\dsi\FIDLITE3\inetupapp.exe [2009-7-16 757760]

Displaysoft Online Updates - c--DSI-OLDREPLITE.lnk - c:\dsi\OLDREPLITE\inetupapp.exe [2009-7-16 757760]

Displaysoft Online Updates - c--DSI-OLDREPLITE2.lnk - c:\dsi\OLDREPLITE2\inetupapp.exe [2010-12-23 757760]

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

.

c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

R4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]

.

.

Contents of the 'Scheduled Tasks' folder

.

2012-05-25 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 16:01]

.

2012-05-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-04 19:45]

.

2012-05-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-04 19:45]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IAAnotif"="OTIF.EXE" [bU]

"Dell DataSafe Online"="E.EXE" [bU]

"SysTrayApp"="c:\program files (x86)\IDT\WDM\sttray64.exe" [bU]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = https://www.google.com/webhp?sourceid=navclient&ie=UTF-8

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: {{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll

Trusted Zone: caldirectsecuredocs.com\www

Trusted Zone: com\pennwest-edocs

Trusted Zone: com\swiftview

Trusted Zone: coupons.com\microsite

Trusted Zone: ditechsecuredocs.com\www

Trusted Zone: ditechsecuredocs.net\www

Trusted Zone: docmagic.com\www

Trusted Zone: elynx.com\gateway

Trusted Zone: elynx.com\stest.lane100

Trusted Zone: elynx.com\stest.lane200

Trusted Zone: elynx.net\aegis

Trusted Zone: elynx.net\ctest

Trusted Zone: elynx.net\ctest.lane100

Trusted Zone: elynx.net\forms

Trusted Zone: elynx.net\gateway

Trusted Zone: elynx.net\gateway.ctest

Trusted Zone: elynx.net\gmacforms

Trusted Zone: elynx.net\pro

Trusted Zone: elynx.net\secure

Trusted Zone: elynx.net\ssctest

Trusted Zone: elynx.net\stest

Trusted Zone: elynx.net\usign

Trusted Zone: elynx.net\webpost

Trusted Zone: gmacmsecuredocs.com\www

Trusted Zone: gmacmsecuredocs.net\www

Trusted Zone: gmamcsecuredocs.com\www

Trusted Zone: hsbc.com\mortgage-esign.us

Trusted Zone: internet

Trusted Zone: mcafee.com

Trusted Zone: real.com\rhap-app-4-0

Trusted Zone: real.com\rhapreg

Trusted Zone: sasrlink.com\www

Trusted Zone: ss3.swiftsend.com\loandocs

Trusted Zone: swiftsend.com\docs

Trusted Zone: swiftsend.com\gateway

Trusted Zone: swiftsend.com\loandocs

Trusted Zone: swiftsend.com\loandocs.ss3

Trusted Zone: swiftsend.com\www

Trusted Zone: swiftsend2.com\docs

Trusted Zone: swiftsend2.com\loandocs

Trusted Zone: swiftview.com\products

Trusted Zone: swiftview.com\www

Trusted Zone: wamuloandocs.com\www

TCP: DhcpNameServer = 192.168.1.254

DPF: {7DD62E58-5FA8-11D2-AFB7-00104B64F127} - hxxps://secure.elynx.net/viewer/installers/svinstall_t_zhp_ss.exe

CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll

FF - ProfilePath - c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=

FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)

FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?AF=110788&babsrc=HP_ss&mntrId=9ed8a32200000000000000221912be2a

FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?AF=110788&babsrc=adbartrp&mntrId=9ed8a32200000000000000221912be2a&q=

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 57273

FF - prefs.js: network.proxy.type - 0

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110788

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.id - 9ed8a32200000000000000221912be2a

FF - user.js: extensions.BabylonToolbar_i.hardId - 9ed8a32200000000000000221912be2a

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15408

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:14

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-{06C7AD57-B655-418D-9AB8-9526A6D2E052} - (no file)

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]

@Denied: (A 2) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]

@="Shockwave Flash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]

@Denied: (A 2) (Everyone)

@=""

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]

@="FlashBroker"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]

"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

.

Completion time: 2012-05-25 07:02:46 - machine was rebooted

ComboFix-quarantined-files.txt 2012-05-25 11:02

ComboFix2.txt 2012-05-25 00:26

ComboFix3.txt 2011-03-24 22:58

ComboFix4.txt 2011-03-24 00:03

.

Pre-Run: 460,906,188,800 bytes free

Post-Run: 460,868,726,784 bytes free

.

- - End Of File - - 6214E8BD28A9B54586E748BCCE203BE1

Thank you.

Link to post
Share on other sites

Are you sure you copied all text correctly into Notepad? Be sure that the script appears exactly as in the codebox and try it again.

Also, lets see if we can diagnose the network problem.

Please download Farbar Service Scanner and run it on the computer with the issue.

  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update

    [*]Press "Scan".

    [*]It will create a log (FSS.txt) in the same directory the tool is run.

    [*]Please copy and paste the log to your reply.

Link to post
Share on other sites

Hello again,

I am relatively sure I copied and pasted it all, but I'll do it again this evening. (Not at that PC during the day) as well as the network troubleshooting. Here's something else. I noticed that when CF was running there was something like " Access denied. Run these options as administrator from command prompt". I may have the verbiage wrong but it's close. Then the next line said something about searching for a restore point, then it apparently ran as it should, to the untrained observer at least.

Thank you again for the help and support; battle to resume later today!

Link to post
Share on other sites

I think I have the same or a very similar problem since last Sunday. McAfee reported a Trojan. Ever since then, various problems:

- On start-up, error "ATI graphics driver not installed or not functioning".

- Unable to connect to the internet using wireless connection.

- Windows Security Center Service is turned off and when I try to turn it on, "The Windows Security Center services can't be started" message appears.

- When I try to open Services, "c:\\windows\system32\services.msc The specified service does not exist as an installed service" message appears.

I have no idea how to even start fixing this. Can anyone help? Thanks.

Link to post
Share on other sites

Here's the new log. I'm certain the entire script was copied and pasted into combofix:

ComboFix 12-05-24.02 - Sharon 05/25/2012 20:17:57.1.4 - x64 NETWORK

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.6077.5235 [GMT -4:00]

Running from: c:\users\Sharon\Desktop\ComboFix.exe

Command switches used :: c:\users\Sharon\Desktop\CFScript.txt

AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}

FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\windows\SysWow64\bidisp.dll

.

.

((((((((((((((((((((((((( Files Created from 2012-04-26 to 2012-05-26 )))))))))))))))))))))))))))))))

.

.

2012-05-26 00:30 . 2012-05-26 00:32 -------- d-----w- c:\users\Sharon\AppData\Local\temp

2012-05-26 00:30 . 2012-05-26 00:30 -------- d-----w- c:\users\Public\AppData\Local\temp

2012-05-26 00:30 . 2012-05-26 00:30 -------- d-----w- c:\users\Dragonlady\AppData\Local\temp

2012-05-26 00:30 . 2012-05-26 00:30 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-05-25 01:48 . 2012-05-25 01:48 -------- d-----w- c:\users\Sharon\AppData\Local\Stardock_Corporation

2012-05-24 00:27 . 2012-05-24 00:27 -------- d-----w- C:\$WINDOWS.~BT

2012-05-23 12:11 . 2012-05-23 12:11 -------- d-----w- c:\users\Sharon\AppData\Local\{682CD89D-A4D0-11E1-8270-B8AC6F996F26}

2012-05-23 12:10 . 2012-05-23 22:40 -------- d-----w- c:\users\Sharon\AppData\Local\Start

2012-05-23 12:10 . 2012-05-23 12:10 -------- d-----w- c:\programdata\B7E8587A00047CF10023A3B1570F1C8B

2012-05-22 11:42 . 2012-05-08 17:02 8955792 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BB8125EF-2731-4E4E-B9D7-CF0D1DC71118}\mpengine.dll

2012-05-11 12:03 . 2012-03-30 12:45 1423744 ----a-w- c:\windows\system32\drivers\tcpip.sys

2012-04-26 22:26 . 2012-03-20 17:06 29272 ----a-w- c:\program files (x86)\Mozilla Firefox\ScriptFF.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-05-05 16:01 . 2012-03-30 11:37 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-05-05 16:01 . 2011-06-14 11:40 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-05-05 16:00 . 2012-03-30 12:01 8744608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe

2012-04-04 19:56 . 2009-09-30 00:01 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-03-20 17:11 . 2011-02-16 12:45 162192 ----a-w- c:\windows\system32\mfevtps.exe

2012-02-29 15:37 . 2012-04-12 11:46 5632 ----a-w- c:\windows\system32\wmi.dll

2012-02-29 15:37 . 2012-04-12 11:46 219136 ----a-w- c:\windows\system32\wintrust.dll

2012-02-29 15:35 . 2012-04-12 11:46 78848 ----a-w- c:\windows\system32\imagehlp.dll

2012-02-29 15:11 . 2012-04-12 11:46 5120 ----a-w- c:\windows\SysWow64\wmi.dll

2012-02-29 15:11 . 2012-04-12 11:46 172032 ----a-w- c:\windows\SysWow64\wintrust.dll

2012-02-29 15:09 . 2012-04-12 11:46 157696 ----a-w- c:\windows\SysWow64\imagehlp.dll

2012-02-29 13:52 . 2012-04-12 11:46 16384 ----a-w- c:\windows\system32\drivers\fs_rec.sys

2012-02-28 06:56 . 2012-04-12 11:49 2311168 ----a-w- c:\windows\system32\jscript9.dll

2012-02-28 06:49 . 2012-04-12 11:49 1390080 ----a-w- c:\windows\system32\wininet.dll

2012-02-28 06:48 . 2012-04-12 11:49 1493504 ----a-w- c:\windows\system32\inetcpl.cpl

2012-02-28 06:42 . 2012-04-12 11:49 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-02-28 01:18 . 2012-04-12 11:49 1799168 ----a-w- c:\windows\SysWow64\jscript9.dll

2012-02-28 01:11 . 2012-04-12 11:49 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl

2012-02-28 01:11 . 2012-04-12 11:49 1127424 ----a-w- c:\windows\SysWow64\wininet.dll

2012-02-28 01:03 . 2012-04-12 11:49 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]

"MoneyAgent"="c:\program files (x86)\Microsoft Money\System\Money Express.exe" [2000-07-19 176183]

"SightSpeed"="c:\program files (x86)\Dell Video Chat\DellVideoChat.exe" [2008-08-15 4812664]

"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-05-04 39408]

"DW6"="c:\program files (x86)\The Weather Channel FW\Desktop\DesktopWeather.exe" [2011-06-08 822456]

"WMPNSCFG"="c:\program files (x86)\Windows Media Player\WMPNSCFG.exe" [bU]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"DELL Webcam Manager"="c:\program files (x86)\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]

"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2008-05-14 244208]

"Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2009-07-07 1779952]

"OEM05Mon.exe"="c:\windows\OEM05Mon.exe" [2007-08-22 36864]

"SunJavaUpdateSched"="c:\program files (x86)\Java\jre6\bin\jusched.exe" [2009-01-04 136600]

"Malwarebytes Anti-Malware (reboot)"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2012-04-04 981680]

"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1675160]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-26 336384]

"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]

"TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-11-26 296056]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]

.

c:\users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]

Displaysoft Online Updates - c--DSI-FID-FARINA.lnk - c:\dsi\FID-FARINA\inetupapp.exe [2010-12-23 757760]

Displaysoft Online Updates - C--DSI-FIDLITE.lnk - c:\dsi\FIDLITE\inetupapp.exe [2009-7-16 757760]

Displaysoft Online Updates - c--DSI-FIDLITE2.lnk - c:\dsi\FIDLITE2\inetupapp.exe [2009-7-16 757760]

Displaysoft Online Updates - c--DSI-FIDLITE3.lnk - c:\dsi\FIDLITE3\inetupapp.exe [2009-7-16 757760]

Displaysoft Online Updates - c--DSI-OLDREPLITE.lnk - c:\dsi\OLDREPLITE\inetupapp.exe [2009-7-16 757760]

Displaysoft Online Updates - c--DSI-OLDREPLITE2.lnk - c:\dsi\OLDREPLITE2\inetupapp.exe [2010-12-23 757760]

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

.

c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

R4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]

.

.

Contents of the 'Scheduled Tasks' folder

.

2012-05-26 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 16:01]

.

2012-05-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-04 19:45]

.

2012-05-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-04 19:45]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IAAnotif"="OTIF.EXE" [bU]

"Dell DataSafe Online"="E.EXE" [bU]

"SysTrayApp"="c:\program files (x86)\IDT\WDM\sttray64.exe" [bU]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = https://www.google.com/webhp?sourceid=navclient&ie=UTF-8

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: {{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll

Trusted Zone: caldirectsecuredocs.com\www

Trusted Zone: com\pennwest-edocs

Trusted Zone: com\swiftview

Trusted Zone: coupons.com\microsite

Trusted Zone: ditechsecuredocs.com\www

Trusted Zone: ditechsecuredocs.net\www

Trusted Zone: docmagic.com\www

Trusted Zone: elynx.com\gateway

Trusted Zone: elynx.com\stest.lane100

Trusted Zone: elynx.com\stest.lane200

Trusted Zone: elynx.net\aegis

Trusted Zone: elynx.net\ctest

Trusted Zone: elynx.net\ctest.lane100

Trusted Zone: elynx.net\forms

Trusted Zone: elynx.net\gateway

Trusted Zone: elynx.net\gateway.ctest

Trusted Zone: elynx.net\gmacforms

Trusted Zone: elynx.net\pro

Trusted Zone: elynx.net\secure

Trusted Zone: elynx.net\ssctest

Trusted Zone: elynx.net\stest

Trusted Zone: elynx.net\usign

Trusted Zone: elynx.net\webpost

Trusted Zone: gmacmsecuredocs.com\www

Trusted Zone: gmacmsecuredocs.net\www

Trusted Zone: gmamcsecuredocs.com\www

Trusted Zone: hsbc.com\mortgage-esign.us

Trusted Zone: internet

Trusted Zone: mcafee.com

Trusted Zone: real.com\rhap-app-4-0

Trusted Zone: real.com\rhapreg

Trusted Zone: sasrlink.com\www

Trusted Zone: ss3.swiftsend.com\loandocs

Trusted Zone: swiftsend.com\docs

Trusted Zone: swiftsend.com\gateway

Trusted Zone: swiftsend.com\loandocs

Trusted Zone: swiftsend.com\loandocs.ss3

Trusted Zone: swiftsend.com\www

Trusted Zone: swiftsend2.com\docs

Trusted Zone: swiftsend2.com\loandocs

Trusted Zone: swiftview.com\products

Trusted Zone: swiftview.com\www

Trusted Zone: wamuloandocs.com\www

TCP: DhcpNameServer = 192.168.1.254

DPF: {7DD62E58-5FA8-11D2-AFB7-00104B64F127} - hxxps://secure.elynx.net/viewer/installers/svinstall_t_zhp_ss.exe

CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll

FF - ProfilePath - c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=

FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)

FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?AF=110788&babsrc=HP_ss&mntrId=9ed8a32200000000000000221912be2a

FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?AF=110788&babsrc=adbartrp&mntrId=9ed8a32200000000000000221912be2a&q=

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 57273

FF - prefs.js: network.proxy.type - 0

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110788

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.id - 9ed8a32200000000000000221912be2a

FF - user.js: extensions.BabylonToolbar_i.hardId - 9ed8a32200000000000000221912be2a

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15408

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:14

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-{06C7AD57-B655-418D-9AB8-9526A6D2E052} - (no file)

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]

@Denied: (A 2) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]

@="Shockwave Flash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]

@Denied: (A 2) (Everyone)

@=""

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]

@="FlashBroker"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]

"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

.

Completion time: 2012-05-25 20:37:40 - machine was rebooted

ComboFix-quarantined-files.txt 2012-05-26 00:37

ComboFix2.txt 2012-05-25 11:02

ComboFix3.txt 2012-05-25 00:26

ComboFix4.txt 2011-03-24 22:58

ComboFix5.txt 2012-05-26 00:15

.

Pre-Run: 460,849,405,952 bytes free

Post-Run: 460,723,490,816 bytes free

.

- - End Of File - - 212ACFB0AF35746EA2B5592CCB31EA83

Here's the FSS log:

Farbar Service Scanner Version: 25-05-2012

Ran by Sharon (administrator) on 25-05-2012 at 20:39:16

Running from "C:\Users\Sharon\Desktop"

Microsoft® Windows Vista™ Home Premium Service Pack 2 (X64)

Boot Mode: Nerwork

****************************************************************

Internet Services:

============

Dnscache Service is not running. Checking service configuration:

Checking Start type: ATTENTION!=====> Unable to open Dnscache registry key. The service key does not exist.

Checking ImagePath: ATTENTION!=====> Unable to open Dnscache registry key. The service key does not exist.

Checking ServiceDll: ATTENTION!=====> Unable to open Dnscache registry key. The service key does not exist.

Dhcp Service is not running. Checking service configuration:

The start type of Dhcp service is OK.

The ImagePath of Dhcp service is OK.

The ServiceDll of Dhcp service is OK.

Nsi Service is not running. Checking service configuration:

Checking Start type: ATTENTION!=====> Unable to open Nsi registry key. The service key does not exist.

Checking ImagePath: ATTENTION!=====> Unable to open Nsi registry key. The service key does not exist.

Checking ServiceDll: ATTENTION!=====> Unable to open Nsi registry key. The service key does not exist.

Checking LEGACY_Nsi: ATTENTION!=====> Unable to open LEGACY_Nsi\0000 registry key. The key does not exist.

Connection Status:

==============

Localhost is blocked.

LAN connected.

Attempt to access Google IP returned error: Other errors

Attempt to access Yahoo IP returned error: Other errors

Windows Firewall:

=============

Firewall Disabled Policy:

==================

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"EnableFirewall"=DWORD:0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall"=DWORD:0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

"EnableFirewall"=DWORD:0

System Restore:

============

SDRSVC Service is not running. Checking service configuration:

The start type of SDRSVC service is OK.

The ImagePath of SDRSVC service is OK.

The ServiceDll of SDRSVC service is OK.

Checking LEGACY_SDRSVC: ATTENTION!=====> Unable to open LEGACY_SDRSVC\0000 registry key. The key does not exist.

VSS Service is not running. Checking service configuration:

The start type of VSS service is OK.

The ImagePath of VSS service is OK.

System Restore Disabled Policy:

========================

Security Center:

============

wscsvc Service is not running. Checking service configuration:

The start type of wscsvc service is OK.

The ImagePath of wscsvc service is OK.

The ServiceDll of wscsvc service is OK.

Checking LEGACY_wscsvc: ATTENTION!=====> Unable to open LEGACY_wscsvc\0000 registry key. The key does not exist.

Windows Update:

============

wuauserv Service is not running. Checking service configuration:

The start type of wuauserv service is OK.

The ImagePath of wuauserv service is OK.

The ServiceDll of wuauserv service is OK.

BITS Service is not running. Checking service configuration:

The start type of BITS service is OK.

The ImagePath of BITS service is OK.

The ServiceDll of BITS service is OK.

Checking LEGACY_BITS: ATTENTION!=====> Unable to open LEGACY_BITS\0000 registry key. The key does not exist.

EventSystem Service is not running. Checking service configuration:

The start type of EventSystem service is OK.

The ImagePath of EventSystem service is OK.

The ServiceDll of EventSystem service is OK.

Windows Autoupdate Disabled Policy:

============================

PlugPlay Service is not running. Checking service configuration:

Checking Start type: ATTENTION!=====> Unable to open PlugPlay registry key. The service key does not exist.

Checking ImagePath: ATTENTION!=====> Unable to open PlugPlay registry key. The service key does not exist.

File Check:

========

C:\Windows\System32\nsisvc.dll

[2008-01-20 22:49] - [2008-01-20 22:49] - 0024576 ____A (Microsoft Corporation) ACB62BAA1C319B17752553DF3026EEEB

C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit

C:\Windows\System32\dhcpcsvc.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0268288 ____A (Microsoft Corporation) 3ED0321127CE70ACDAABBF77E157C2A7

C:\Windows\System32\drivers\afd.sys

[2012-02-16 09:23] - [2012-01-03 10:25] - 0404992 ____A (Microsoft Corporation) C4F6CE6087760AD70960C9EB130E7943

C:\Windows\System32\drivers\tdx.sys => MD5 is legit

C:\Windows\System32\Drivers\tcpip.sys

[2012-05-11 08:03] - [2012-03-30 08:45] - 1423744 ____A (Microsoft Corporation) 46D448E9117464E4D3BBF36D7E3FA48E

C:\Windows\System32\dnsrslvr.dll

[2011-04-15 12:50] - [2011-03-02 12:12] - 0117760 ____A (Microsoft Corporation) 06230F1B721494A6DF8D47FD395BB1B0

C:\Windows\System32\mpssvc.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0603136 ____A (Microsoft Corporation) 897E3BAF68BA406A61682AE39C83900C

C:\Windows\System32\bfe.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0458240 ____A (Microsoft Corporation) FFB96C2589FFA60473EAD78B39FBDE29

C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit

C:\Windows\System32\SDRSVC.dll

[2008-01-20 22:47] - [2008-01-20 22:47] - 0128000 ____A (Microsoft Corporation) 4FF71B076A7760FE75EA5AE2D0EE0018

C:\Windows\System32\vssvc.exe

[2009-09-11 08:35] - [2009-04-11 03:11] - 1433600 ____A (Microsoft Corporation) B75232DAD33BFD95BF6F0A3E6BFF51E1

C:\Windows\System32\wscsvc.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0074752 ____A (Microsoft Corporation) 9EA3E6D0EF7A5C2B9181961052A4B01A

C:\Windows\System32\wbem\WMIsvc.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0221696 ____A (Microsoft Corporation) D2E7296ED1BD26D8DB2799770C077A02

C:\Windows\System32\wuaueng.dll

[2009-10-29 11:24] - [2009-08-06 22:24] - 2424024 ____A (Microsoft Corporation) FB3796754FE00F0BDC87A36F164A5F4D

C:\Windows\System32\qmgr.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 1081856 ____A (Microsoft Corporation) 6D316F4859634071CC25C4FD4589AD2C

C:\Windows\System32\es.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0361984 ____A (Microsoft Corporation) E12F22B73F153DECE721CD45EC05B4AF

C:\Windows\System32\cryptsvc.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0166912 ____A (Microsoft Corporation) 18918613E63F387CDE4D95CA7D49DCF7

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\System32\rpcss.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0719872 ____A (Microsoft Corporation) CF8B9A3A5E7DC57724A89D0C3E8CF9EF

**** End of log ****

Thanks again for the help.

Link to post
Share on other sites

The script didn't run successfully, but never mind that now, we'll fix it with another tool. However we will first need to make some major repairs to your Windows services, as many seem missing.

Please download the following files and double click on them to run. When asked to merge the information confirm. You'll receive a success message when done. Restart the computer and let me know how everything is running.

http://download.bleepingcomputer.com/win-services/vista/Dnscache.reg

http://download.bleepingcomputer.com/win-services/vista/nsi.reg

http://download.bleepingcomputer.com/win-services/vista/PlugPlay.reg

OTL

-----

Please download OTL from one of the following mirrors:

[*]Save it to your desktop.

[*]Double click on the otlicon.png icon on your desktop.

[*]Click the "Scan All Users" checkbox.

[*]Push the runscan.png button.

[*]Two reports will open, copy and paste them in a reply here:

  • OTL.txt <-- Will be opened
  • Extra.txt <-- Will be minimized

Link to post
Share on other sites

Hello Elise,

Still no network connectivity after installing registry entries. The "safely remove hardware icon is back and works to stop the flash drives again.

Hovering over the network icons returns" service does not exist as...." Also, if booted normally any security related icons, Malwarebytes, combofix etc, have a red,green, blue, yellow shield on them and return the "Service does not......." error. Must run everything in safe mode.

Logs:

OTL logfile created on: 5/26/2012 9:43:23 AM - Run 1

OTL by OldTimer - Version 3.2.43.1 Folder = C:\Users\Sharon\Desktop

64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.93 Gb Total Physical Memory | 5.24 Gb Available Physical Memory | 88.31% Memory free

11.98 Gb Paging File | 11.44 Gb Available in Paging File | 95.46% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 581.11 Gb Total Space | 430.14 Gb Free Space | 74.02% Space Free | Partition Type: NTFS

Drive D: | 15.00 Gb Total Space | 6.00 Gb Free Space | 40.02% Space Free | Partition Type: NTFS

Drive F: | 931.51 Gb Total Space | 855.69 Gb Free Space | 91.86% Space Free | Partition Type: NTFS

Drive G: | 1.88 Gb Total Space | 1.87 Gb Free Space | 99.76% Space Free | Partition Type: FAT

Drive H: | 983.72 Mb Total Space | 53.36 Mb Free Space | 5.42% Space Free | Partition Type: FAT

Computer Name: SHARON-PC | User Name: Sharon | Logged in as Administrator.

Boot Mode: SafeMode with Networking | Scan Mode: All users | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/05/26 09:27:42 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Sharon\Desktop\OTL.exe

========== Modules (No Company Name) ==========

========== Win32 Services (SafeList) ==========

SRV:64bit: - [2012/03/22 19:30:56 | 000,502,032 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)

SRV:64bit: - [2012/03/20 13:11:30 | 000,162,192 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)

SRV:64bit: - [2012/03/20 12:56:24 | 000,210,584 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)

SRV:64bit: - [2012/03/20 12:55:54 | 000,199,272 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)

SRV:64bit: - [2011/01/27 19:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McProxy)

SRV:64bit: - [2011/01/27 19:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNASvc)

SRV:64bit: - [2011/01/27 19:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNaiAnn)

SRV:64bit: - [2011/01/27 19:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (mcmscsvc)

SRV:64bit: - [2011/01/27 19:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McMPFSvc)

SRV:64bit: - [2011/01/26 18:55:36 | 000,203,776 | ---- | M] (AMD) [Disabled | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)

SRV:64bit: - [2008/09/23 23:09:52 | 000,155,648 | ---- | M] (Stardock Corporation) [Disabled | Stopped] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)

SRV:64bit: - [2008/09/17 06:24:58 | 000,246,272 | ---- | M] (IDT, Inc.) [Disabled | Stopped] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_4b8037c7\STacSV64.exe -- (STacSV)

SRV:64bit: - [2008/01/20 22:50:24 | 000,027,648 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\svchost.exe -- (WebClient)

SRV:64bit: - [2008/01/20 22:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)

SRV - [2012/05/05 12:01:02 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2012/02/13 12:56:36 | 000,109,064 | ---- | M] (Wajam) [Disabled | Stopped] -- C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe -- (WajamUpdater)

SRV - [2011/08/10 11:53:46 | 000,102,608 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe -- (McAfee SiteAdvisor Service)

SRV - [2009/03/30 00:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2008/05/14 11:32:18 | 000,309,744 | ---- | M] (Sonic Solutions) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe -- (RoxLiveShare10)

SRV - [2008/05/14 11:32:10 | 000,166,384 | ---- | M] (Sonic Solutions) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe -- (RoxWatch10)

SRV - [2008/05/14 11:31:38 | 001,120,752 | ---- | M] (Sonic Solutions) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe -- (RoxMediaDB10)

SRV - [2008/04/15 18:54:42 | 000,354,840 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®

========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/02/29 09:52:46 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2012/02/22 13:29:46 | 000,647,208 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)

DRV:64bit: - [2012/02/22 13:29:46 | 000,487,296 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)

DRV:64bit: - [2012/02/22 13:29:46 | 000,289,664 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)

DRV:64bit: - [2012/02/22 13:29:46 | 000,229,528 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)

DRV:64bit: - [2012/02/22 13:29:46 | 000,160,792 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)

DRV:64bit: - [2012/02/22 13:29:46 | 000,100,912 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)

DRV:64bit: - [2012/02/22 13:29:46 | 000,075,936 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\mfenlfk.sys -- (mfenlfk)

DRV:64bit: - [2012/02/22 13:29:46 | 000,065,264 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)

DRV:64bit: - [2011/01/26 19:37:20 | 009,085,952 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (R300)

DRV:64bit: - [2011/01/26 19:37:20 | 009,085,952 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (atikmdag)

DRV:64bit: - [2011/01/26 19:37:20 | 009,085,952 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (amdkmdag)

DRV:64bit: - [2011/01/26 18:13:32 | 000,299,520 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\atikmpag.sys -- (amdkmdap)

DRV:64bit: - [2009/09/16 10:22:40 | 000,049,480 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mfesmfk.sys -- (mfesmfk)

DRV:64bit: - [2009/09/16 10:15:38 | 000,040,904 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdk.sys -- (mferkdk)

DRV:64bit: - [2008/09/17 06:25:04 | 000,457,216 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\stwrt64.sys -- (STHDA)

DRV:64bit: - [2008/09/16 02:40:58 | 000,313,472 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\e1e6032e.sys -- (e1express) Intel®

DRV:64bit: - [2008/09/16 02:30:26 | 000,388,120 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iastor.sys -- (iaStor)

DRV:64bit: - [2008/04/08 04:00:00 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\PxHlpa64.sys -- (PxHlpa64)

DRV:64bit: - [2008/01/20 22:47:28 | 000,046,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)

DRV:64bit: - [2007/08/22 01:39:22 | 000,266,720 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\OEM05Vid.sys -- (OEM05Vid)

DRV:64bit: - [2007/08/22 01:39:18 | 000,012,288 | ---- | M] (EyePower Games Pte. Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\OEM05Vfx.sys -- (OEM05Vfx)

DRV:64bit: - [2007/08/22 01:39:06 | 000,212,864 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\OEM05Afx.sys -- (OEM05Afx)

DRV:64bit: - [2007/07/16 11:29:24 | 000,020,504 | ---- | M] (Hewlett Packard) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hpfx64bulk.sys -- (HPFXBULK)

DRV:64bit: - [2007/02/05 18:36:48 | 000,049,664 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\livecamv.sys -- (RLDesignVirtualAudioCableWdm)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}

IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7DKUS

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:57273

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:57273

IE - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/webhp?sourceid=navclient&ie=UTF-8

IE - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..\SearchScopes,DefaultScope = {DECA3892-BA8F-44b8-A993-A466AD694AE4}

IE - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&AF=110788&babsrc=SP_ss&mntrId=9ed8a32200000000000000221912be2a

IE - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7DKUS_en

IE - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}: "URL" = browseforchange/search/redirect/?type=default&user_id=c65deb8a-4fa0-4e49-905f-4ff711a59b78&query={searchTerms}

IE - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..\SearchScopes\{9A920ACA-1F14-4087-9163-71C19567E662}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ARCD&o=102810&src=kw&q={searchTerms}&locale=&apn_ptnrs=8W&apn_dtid=YYYYYYSTUS&apn_uid=73ec0ede-6ded-496e-bb3a-a5a69ab9997f&apn_sauid=2B64D980-3704-451C-BBA4-16AC79E2BF69

IE - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..\SearchScopes\{A59C167F-298F-30E1-8F0D-B7ED3F450647}: "URL" = http://www.startnow.com/s/?q={searchTerms}&src=defsearch&provider=Bing&provider_code=Z057&partner_id=333&product_id=519&affiliate_id=&channel=DPGL15&toolbar_id=200&toolbar_version=2.0&install_country=US&install_date=20110608&user_guid=D15B422698994E5C830A2F238248375E&machine_id=6ffa891ce2deb1aed1f9be2a9e8b769e&browser=IE&os=win&os_version=6.0-x64-SP2

IE - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?p={searchTerms}&fr=chr-atty

IE - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultEngine: "Yahoo"

FF - prefs.js..browser.search.defaultengine: "Ask.com"

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"

FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p="

FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"

FF - prefs.js..browser.search.param.yahoo-fr: "chrf-offrhap"

FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-offrhap"

FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"

FF - prefs.js..browser.search.useDBForOrder: true

FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?AF=110788&babsrc=HP_ss&mntrId=9ed8a32200000000000000221912be2a"

FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1

FF - prefs.js..extensions.enabledItems: {B7E247FA-8046-43A7-9581-32DC30BD2438}:1.9.1

FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313

FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.3

FF - prefs.js..extensions.enabledItems: textlinks@arcadeweb.com:1.0.0

FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.12.2.16749

FF - prefs.js..extensions.enabledItems: {5911488E-9D1E-40ec-8CBB-06B231CC153F}:2.0

FF - prefs.js..extensions.enabledItems: superfish@superfish.com:1.2.0.8

FF - prefs.js..keyword.URL: "http://search.babylon.com/?AF=110788&babsrc=adbartrp&mntrId=9ed8a32200000000000000221912be2a&q="

FF - prefs.js..network.proxy.http: "127.0.0.1"

FF - prefs.js..network.proxy.http_port: 57273

FF - prefs.js..network.proxy.type: 0

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_235.dll File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll ()

FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()

FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files (x86)\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)

FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.0.198: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.0.198: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.0.198: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.0.198: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.0.198: c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKLM\Software\MozillaPlugins\@swiftview.com/SwiftView: C:\Program Files (x86)\SwiftView\npsview.dll (SwiftView, Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKLM\Software\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files (x86)\Yahoo!\Common\npyaxmpb.dll File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\superfish@superfish.com: C:\ProgramDataMozilla\Extensions\superfish@superfish.com [2011/07/23 07:48:47 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/11/26 13:28:49 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/11/10 15:14:27 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/04/27 07:41:36 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/02/07 09:29:28 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/01 19:29:39 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{B7E247FA-8046-43A7-9581-32DC30BD2438}: C:\Users\Sharon\AppData\Local\{B7E247FA-8046-43A7-9581-32DC30BD2438} [2011/03/26 09:41:34 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{682CD89D-A4D0-11E1-8270-B8AC6F996F26}: C:\Users\Sharon\AppData\Local\{682CD89D-A4D0-11E1-8270-B8AC6F996F26}\ [2012/05/23 08:11:32 | 000,000,000 | ---D | M]

[2009/01/04 16:54:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sharon\AppData\Roaming\Mozilla\Extensions

[2012/03/09 17:15:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions

[2011/07/23 08:10:26 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2012/02/01 13:50:03 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}

[2012/03/09 17:15:01 | 000,000,000 | ---D | M] (Browse For Change) -- C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\browseforchange@browseforchange.com

[2012/03/09 17:15:05 | 000,000,000 | ---D | M] ("I Want This") -- C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\crossriderapp2258@crossrider.com

[2011/06/14 15:29:46 | 000,000,000 | ---D | M] ("ArcadeWeb") -- C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\extensions\textlinks@arcadeweb.com

[2011/07/23 07:48:42 | 000,002,570 | ---- | M] () -- C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\7adqiqrj.default\searchplugins\askcom.xml

[2009/01/04 16:53:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

[2011/07/23 07:48:47 | 000,000,000 | ---D | M] (Window Shopper - Powered by Superfish) -- C:\PROGRAMDATAMOZILLA\EXTENSIONS\SUPERFISH@SUPERFISH.COM

[2012/05/23 08:11:32 | 000,000,000 | ---D | M] (Mozilla Safe Browsing) -- C:\USERS\SHARON\APPDATA\LOCAL\{682CD89D-A4D0-11E1-8270-B8AC6F996F26}

File not found (No name found) -- C:\USERS\SHARON\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7ADQIQRJ.DEFAULT\EXTENSIONS\{5911488E-9D1E-40EC-8CBB-06B231CC153F}

[2012/02/07 09:29:26 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll

[2011/04/14 14:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll

[2011/07/15 09:32:21 | 000,466,944 | ---- | M] (Catalina Marketing Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\NPcol400.dll

[2011/03/18 15:32:12 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll

[2011/03/18 15:32:14 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll

[2012/02/01 15:56:01 | 000,758,856 | ---- | M] (SwiftView, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npsview.dll

[2012/03/09 17:14:15 | 000,002,310 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml

[2012/01/18 13:32:10 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

[2012/01/18 13:32:10 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}

CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.46\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.46\pdf.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.46\gcswf32.dll

CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll

CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll

CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll

CHR - plugin: Wajam (Enabled) = C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.21_0\plugins/WajamNPAPI.dll

CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll

CHR - plugin: CouponNetwork Coupon Activator Netscape Plugin v. 5.0.0.0 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll

CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll

CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll

CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll

CHR - plugin: RealPlayer HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll

CHR - plugin: SwiftView Plug-In (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npsview.dll

CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll

CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files (x86)\McAfee\Supportability\MVT\npmvtplugin.dll

CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll

CHR - plugin: RealNetworks Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll

CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~2\mcafee\msc\npmcsn~1.dll

CHR - Extension: YouTube = C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\

CHR - Extension: Google Search = C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\

CHR - Extension: SiteAdvisor = C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\

CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\

CHR - Extension: Wajam = C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.21_0\

CHR - Extension: Gmail = C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/05/25 20:32:09 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120426182648.dll (McAfee, Inc.)

O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.

O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)

O2 - BHO: (Window Shopper) - {74F475FA-6C75-43BD-AAB9-ECDA6184F600} - C:\Program Files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll (Superfish)

O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120426182648.dll (McAfee, Inc.)

O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\wajam.dll (Wajam)

O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)

O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files (x86)\Dell\BAE\BAE.dll (Dell Inc.)

O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)

O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

O3 - HKLM\..\Toolbar: (no name) - {06C7AD57-B655-418D-9AB8-9526A6D2E052} - No CLSID value found.

O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)

O3:64bit: - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

O4:64bit: - HKLM..\Run: [Dell DataSafe Online] E.EXE" /M File not found

O4:64bit: - HKLM..\Run: [iAAnotif] OTIF.EXE" File not found

O4:64bit: - HKLM..\Run: [sysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)

O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)

O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()

O4 - HKLM..\Run: [DELL Webcam Manager] C:\Program Files (x86)\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)

O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)

O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)

O4 - HKLM..\Run: [OEM05Mon.exe] C:\Windows\OEM05Mon.exe (Creative Technology Ltd.)

O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe (Sonic Solutions)

O4 - HKLM..\Run: [startCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)

O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)

O4 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000..\Run: [DW6] C:\Program Files (x86)\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)

O4 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000..\Run: [MoneyAgent] C:\Program Files (x86)\Microsoft Money\System\Money Express.exe (Microsoft Corporation)

O4 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000..\Run: [sightSpeed] C:\Program Files (x86)\Dell Video Chat\DellVideoChat.exe (Dell Inc. and SightSpeed Inc.)

O4 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found

O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found

O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found

O4 - Startup: C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)

O4 - Startup: C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Displaysoft Online Updates - c--DSI-FID-FARINA.lnk = C:\DSI\FID-FARINA\inetupapp.exe (Display Systems, Inc.)

O4 - Startup: C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Displaysoft Online Updates - C--DSI-FIDLITE.lnk = C:\DSI\FIDLITE\inetupapp.exe (Display Systems, Inc.)

O4 - Startup: C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Displaysoft Online Updates - c--DSI-FIDLITE2.lnk = C:\DSI\FIDLITE2\inetupapp.exe (Display Systems, Inc.)

O4 - Startup: C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Displaysoft Online Updates - c--DSI-FIDLITE3.lnk = C:\DSI\FIDLITE3\inetupapp.exe (Display Systems, Inc.)

O4 - Startup: C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Displaysoft Online Updates - c--DSI-OLDREPLITE.lnk = C:\DSI\OLDREPLITE\inetupapp.exe (Display Systems, Inc.)

O4 - Startup: C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Displaysoft Online Updates - c--DSI-OLDREPLITE2.lnk = C:\DSI\OLDREPLITE2\inetupapp.exe (Display Systems, Inc.)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O9 - Extra Button: Window Shopper - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - C:\Program Files (x86)\Superfish\Window Shopper\SuperfishIEAddon.dll (Superfish)

O15 - HKU\.DEFAULT\..Trusted Domains: caldirectsecuredocs.com ([www] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: caldirectsecuredocs.com ([www] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: com ([pennwest-edocs] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: com ([pennwest-edocs] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: com ([swiftview] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: ditechsecuredocs.com ([www] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: ditechsecuredocs.com ([www] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: ditechsecuredocs.net ([www] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: ditechsecuredocs.net ([www] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.com ([gateway] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.com ([gateway] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.com ([stest.lane100] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.com ([stest.lane100] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.com ([stest.lane200] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.com ([stest.lane200] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([aegis] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([aegis] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([ctest] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([ctest] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([ctest.lane100] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([ctest.lane100] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([forms] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([forms] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([gateway] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([gateway] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([gateway.ctest] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([gateway.ctest] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([gmacforms] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([gmacforms] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([pro] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([pro] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([secure] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([secure] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([ssctest] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([ssctest] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([stest] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([stest] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([usign] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([usign] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([webpost] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: elynx.net ([webpost] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: gmacmsecuredocs.com ([www] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: gmacmsecuredocs.com ([www] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: gmacmsecuredocs.net ([www] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: gmacmsecuredocs.net ([www] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: gmamcsecuredocs.com ([www] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: gmamcsecuredocs.com ([www] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: hsbc.com ([mortgage-esign.us] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: hsbc.com ([mortgage-esign.us] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: ss3.swiftsend.com ([loandocs] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: ss3.swiftsend.com ([loandocs] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftsend.com ([docs] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftsend.com ([docs] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftsend.com ([gateway] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftsend.com ([gateway] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftsend.com ([loandocs] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftsend.com ([loandocs] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftsend.com ([loandocs.ss3] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftsend.com ([loandocs.ss3] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftsend.com ([www] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftsend.com ([www] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftsend2.com ([docs] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftsend2.com ([docs] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftsend2.com ([loandocs] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftsend2.com ([loandocs] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftview.com ([products] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftview.com ([products] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftview.com ([www] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: swiftview.com ([www] https in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: wamuloandocs.com ([www] http in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: wamuloandocs.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: caldirectsecuredocs.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: caldirectsecuredocs.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: com ([pennwest-edocs] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: com ([pennwest-edocs] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: com ([swiftview] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: ditechsecuredocs.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: ditechsecuredocs.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: ditechsecuredocs.net ([www] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: ditechsecuredocs.net ([www] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.com ([gateway] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.com ([gateway] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.com ([stest.lane100] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.com ([stest.lane100] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.com ([stest.lane200] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.com ([stest.lane200] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([aegis] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([aegis] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([ctest] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([ctest] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([ctest.lane100] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([ctest.lane100] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([forms] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([forms] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([gateway] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([gateway] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([gateway.ctest] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([gateway.ctest] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([gmacforms] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([gmacforms] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([pro] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([pro] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([secure] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([secure] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([ssctest] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([ssctest] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([stest] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([stest] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([usign] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([usign] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([webpost] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: elynx.net ([webpost] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: gmacmsecuredocs.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: gmacmsecuredocs.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: gmacmsecuredocs.net ([www] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: gmacmsecuredocs.net ([www] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: gmamcsecuredocs.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: gmamcsecuredocs.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: hsbc.com ([mortgage-esign.us] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: hsbc.com ([mortgage-esign.us] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: ss3.swiftsend.com ([loandocs] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: ss3.swiftsend.com ([loandocs] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftsend.com ([docs] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftsend.com ([docs] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftsend.com ([gateway] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftsend.com ([gateway] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftsend.com ([loandocs] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftsend.com ([loandocs] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftsend.com ([loandocs.ss3] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftsend.com ([loandocs.ss3] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftsend.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftsend.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftsend2.com ([docs] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftsend2.com ([docs] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftsend2.com ([loandocs] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftsend2.com ([loandocs] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftview.com ([products] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftview.com ([products] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftview.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: swiftview.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: wamuloandocs.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: wamuloandocs.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-19\..Trusted Domains: caldirectsecuredocs.com ([www] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: caldirectsecuredocs.com ([www] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: com ([pennwest-edocs] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: com ([pennwest-edocs] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: com ([swiftview] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: ditechsecuredocs.com ([www] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: ditechsecuredocs.com ([www] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: ditechsecuredocs.net ([www] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: ditechsecuredocs.net ([www] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.com ([gateway] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.com ([gateway] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.com ([stest.lane100] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.com ([stest.lane100] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.com ([stest.lane200] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.com ([stest.lane200] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([aegis] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([aegis] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([ctest] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([ctest] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([ctest.lane100] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([ctest.lane100] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([forms] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([forms] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([gateway] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([gateway] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([gateway.ctest] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([gateway.ctest] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([gmacforms] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([gmacforms] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([pro] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([pro] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([secure] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([secure] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([ssctest] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([ssctest] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([stest] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([stest] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([usign] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([usign] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([webpost] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: elynx.net ([webpost] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: gmacmsecuredocs.com ([www] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: gmacmsecuredocs.com ([www] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: gmacmsecuredocs.net ([www] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: gmacmsecuredocs.net ([www] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: gmamcsecuredocs.com ([www] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: gmamcsecuredocs.com ([www] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: hsbc.com ([mortgage-esign.us] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: hsbc.com ([mortgage-esign.us] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: ss3.swiftsend.com ([loandocs] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: ss3.swiftsend.com ([loandocs] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftsend.com ([docs] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftsend.com ([docs] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftsend.com ([gateway] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftsend.com ([gateway] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftsend.com ([loandocs] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftsend.com ([loandocs] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftsend.com ([loandocs.ss3] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftsend.com ([loandocs.ss3] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftsend.com ([www] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftsend.com ([www] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftsend2.com ([docs] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftsend2.com ([docs] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftsend2.com ([loandocs] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftsend2.com ([loandocs] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftview.com ([products] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftview.com ([products] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftview.com ([www] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: swiftview.com ([www] https in )

O15 - HKU\S-1-5-19\..Trusted Domains: wamuloandocs.com ([www] http in )

O15 - HKU\S-1-5-19\..Trusted Domains: wamuloandocs.com ([www] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: caldirectsecuredocs.com ([www] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: caldirectsecuredocs.com ([www] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: com ([pennwest-edocs] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: com ([pennwest-edocs] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: com ([swiftview] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: ditechsecuredocs.com ([www] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: ditechsecuredocs.com ([www] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: ditechsecuredocs.net ([www] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: ditechsecuredocs.net ([www] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.com ([gateway] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.com ([gateway] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.com ([stest.lane100] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.com ([stest.lane100] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.com ([stest.lane200] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.com ([stest.lane200] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([aegis] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([aegis] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([ctest] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([ctest] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([ctest.lane100] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([ctest.lane100] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([forms] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([forms] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([gateway] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([gateway] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([gateway.ctest] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([gateway.ctest] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([gmacforms] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([gmacforms] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([pro] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([pro] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([secure] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([secure] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([ssctest] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([ssctest] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([stest] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([stest] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([usign] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([usign] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([webpost] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: elynx.net ([webpost] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: gmacmsecuredocs.com ([www] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: gmacmsecuredocs.com ([www] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: gmacmsecuredocs.net ([www] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: gmacmsecuredocs.net ([www] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: gmamcsecuredocs.com ([www] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: gmamcsecuredocs.com ([www] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: hsbc.com ([mortgage-esign.us] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: hsbc.com ([mortgage-esign.us] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: ss3.swiftsend.com ([loandocs] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: ss3.swiftsend.com ([loandocs] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftsend.com ([docs] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftsend.com ([docs] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftsend.com ([gateway] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftsend.com ([gateway] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftsend.com ([loandocs] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftsend.com ([loandocs] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftsend.com ([loandocs.ss3] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftsend.com ([loandocs.ss3] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftsend.com ([www] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftsend.com ([www] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftsend2.com ([docs] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftsend2.com ([docs] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftsend2.com ([loandocs] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftsend2.com ([loandocs] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftview.com ([products] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftview.com ([products] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftview.com ([www] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: swiftview.com ([www] https in )

O15 - HKU\S-1-5-20\..Trusted Domains: wamuloandocs.com ([www] http in )

O15 - HKU\S-1-5-20\..Trusted Domains: wamuloandocs.com ([www] https in )

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: caldirectsecuredocs.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: caldirectsecuredocs.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: com ([pennwest-edocs] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: com ([pennwest-edocs] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: com ([swiftview] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: coupons.com ([microsite] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: ditechsecuredocs.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: ditechsecuredocs.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: ditechsecuredocs.net ([www] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: ditechsecuredocs.net ([www] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: docmagic.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: docmagic.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.com ([gateway] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.com ([gateway] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.com ([stest.lane100] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.com ([stest.lane100] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.com ([stest.lane200] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.com ([stest.lane200] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([aegis] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([aegis] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([ctest] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([ctest] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([ctest.lane100] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([ctest.lane100] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([forms] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([forms] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([gateway] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([gateway] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([gateway.ctest] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([gateway.ctest] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([gmacforms] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([gmacforms] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([pro] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([pro] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([secure] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([secure] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([ssctest] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([ssctest] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([stest] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([stest] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([usign] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([usign] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([webpost] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: elynx.net ([webpost] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: gmacmsecuredocs.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: gmacmsecuredocs.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: gmacmsecuredocs.net ([www] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: gmacmsecuredocs.net ([www] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: gmamcsecuredocs.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: gmamcsecuredocs.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: hsbc.com ([mortgage-esign.us] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: hsbc.com ([mortgage-esign.us] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: internet ([]about in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: mcafee.com ([]http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: mcafee.com ([]https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: real.com ([rhap-app-4-0] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: real.com ([rhapreg] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: sasrlink.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: ss3.swiftsend.com ([loandocs] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: ss3.swiftsend.com ([loandocs] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftsend.com ([docs] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftsend.com ([docs] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftsend.com ([gateway] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftsend.com ([gateway] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftsend.com ([loandocs] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftsend.com ([loandocs] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftsend.com ([loandocs.ss3] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftsend.com ([loandocs.ss3] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftsend.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftsend.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftsend2.com ([docs] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftsend2.com ([docs] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftsend2.com ([loandocs] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftsend2.com ([loandocs] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftview.com ([products] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftview.com ([products] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftview.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: swiftview.com ([www] https in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: wamuloandocs.com ([www] http in Trusted sites)

O15 - HKU\S-1-5-21-1280911578-185664597-1390033846-1000\..Trusted Domains: wamuloandocs.com ([www] https in Trusted sites)

O16:64bit: - DPF: {7DD62E58-5FA8-11D2-AFB7-00104B64F126} http://products.swiftview.com/install.html?id=sv8/3_IN_1_CAB&ctx=&ref= (Reg Error: Key error.)

O16 - DPF: {7DD62E58-5FA8-11D2-AFB7-00104B64F127} https://secure.elynx.net/viewer/installers/svinstall_t_zhp_ss.exe (Sview Control)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8F1048E6-5993-4463-B935-A81362C82E06}: DhcpNameServer = 192.168.1.254

O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)

O18:64bit: - Protocol\Handler\gopher - No CLSID value found

O18:64bit: - Protocol\Handler\ms-help - No CLSID value found

O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found

O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)

O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)

O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)

O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)

O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)

O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)

O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img2.jpg

O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img2.jpg

O32 - HKLM CDRom: AutoRun - 1

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = ComFile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/05/26 09:42:44 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Sharon\Desktop\OTL.exe

[2012/05/26 09:25:40 | 000,000,000 | ---D | C] -- C:\Users\Sharon\Desktop\reg files5_26

[2012/05/25 20:37:42 | 000,000,000 | ---D | C] -- C:\Windows\temp

[2012/05/25 20:37:42 | 000,000,000 | ---D | C] -- C:\Users\Sharon\AppData\Local\temp

[2012/05/25 20:32:14 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN

[2012/05/24 21:48:53 | 000,000,000 | ---D | C] -- C:\Users\Sharon\AppData\Local\Stardock_Corporation

[2012/05/24 17:16:02 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe

[2012/05/24 17:16:02 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe

[2012/05/24 17:16:02 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe

[2012/05/24 17:15:55 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT

[2012/05/24 17:11:09 | 004,526,123 | R--- | C] (Swearware) -- C:\Users\Sharon\Desktop\ComboFix.exe

[2012/05/23 20:27:17 | 000,000,000 | ---D | C] -- C:\$WINDOWS.~BT

[2012/05/23 20:20:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee

[2012/05/23 08:11:31 | 000,000,000 | ---D | C] -- C:\Users\Sharon\AppData\Local\{682CD89D-A4D0-11E1-8270-B8AC6F996F26}

[2012/05/23 08:10:43 | 000,000,000 | ---D | C] -- C:\Users\Sharon\AppData\Local\Start

[2012/05/23 08:10:43 | 000,000,000 | ---D | C] -- C:\ProgramData\B7E8587A00047CF10023A3B1570F1C8B

[2012/05/11 08:01:57 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jnwmon.dll

[2012/05/11 08:01:53 | 001,556,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll

[2012/05/11 08:01:50 | 002,002,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll

[2012/05/11 08:01:50 | 000,834,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll

[2012/05/11 08:01:50 | 000,327,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll

[2012/05/11 08:01:48 | 000,196,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll

[2012/05/11 08:01:17 | 004,699,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe

[2012/05/07 15:17:31 | 000,000,000 | ---D | C] -- C:\Users\Sharon\Documents\2012-05-07

[2012/05/05 11:03:47 | 000,000,000 | ---D | C] -- C:\Users\Sharon\Documents\2012-05-05

[2012/05/04 10:40:32 | 000,000,000 | ---D | C] -- C:\Users\Sharon\Documents\CATICTemp

========== Files - Modified Within 30 Days ==========

[2012/05/26 09:37:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2012/05/26 09:35:30 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

[2012/05/26 09:35:30 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

[2012/05/26 09:34:06 | 000,690,960 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2012/05/26 09:34:06 | 000,595,446 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2012/05/26 09:34:06 | 000,101,144 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2012/05/26 09:31:58 | 000,001,614 | ---- | M] () -- C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Displaysoft Online Updates - C--DSI-FIDLITE.lnk

[2012/05/26 09:31:56 | 000,000,311 | ---- | M] () -- C:\Windows\epfax.ini

[2012/05/26 09:31:54 | 000,001,660 | ---- | M] () -- C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Displaysoft Online Updates - c--DSI-OLDREPLITE2.lnk

[2012/05/26 09:31:54 | 000,001,649 | ---- | M] () -- C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Displaysoft Online Updates - c--DSI-FID-FARINA.lnk

[2012/05/26 09:31:54 | 000,001,627 | ---- | M] () -- C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Displaysoft Online Updates - c--DSI-FIDLITE3.lnk

[2012/05/26 09:31:54 | 000,001,627 | ---- | M] () -- C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Displaysoft Online Updates - c--DSI-FIDLITE2.lnk

[2012/05/26 09:30:36 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

[2012/05/26 09:27:42 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Sharon\Desktop\OTL.exe

[2012/05/25 20:32:09 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts

[2012/05/25 20:13:00 | 000,337,661 | ---- | M] () -- C:\Users\Sharon\Desktop\FSS.exe

[2012/05/25 20:00:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job

[2012/05/25 19:58:05 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

[2012/05/24 17:06:54 | 004,526,123 | R--- | M] (Swearware) -- C:\Users\Sharon\Desktop\ComboFix.exe

[2012/05/24 06:39:16 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Sharon\Desktop\dds.scr

[2012/05/23 20:31:57 | 000,001,905 | ---- | M] () -- C:\Windows\diagwrn.xml

[2012/05/23 20:31:57 | 000,001,905 | ---- | M] () -- C:\Windows\diagerr.xml

[2012/05/23 18:28:52 | 000,000,732 | ---- | M] () -- C:\Users\Sharon\AppData\Local\d3d9caps64.dat

[2012/05/23 08:38:25 | 000,000,081 | ---- | M] () -- C:\Users\Sharon\AppData\Roaming\mbam.context.scan

[2012/05/22 07:36:13 | 000,001,649 | ---- | M] () -- C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Displaysoft Online Updates - c--DSI-OLDREPLITE.lnk

[2012/05/12 08:41:46 | 000,401,424 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT

[2012/05/07 15:17:52 | 000,333,804 | ---- | M] () -- C:\Users\Sharon\Documents\Sarah Dentist bill.pdf

[2012/05/05 12:01:02 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe

[2012/05/05 12:01:02 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

[2012/05/05 12:00:56 | 008,744,608 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe

[2012/05/04 10:17:24 | 000,127,660 | ---- | M] () -- C:\Users\Sharon\Documents\CATICTemp.PZIP

[2012/05/01 15:23:01 | 000,000,115 | ---- | M] () -- C:\Users\Sharon\AppData\Roaming\sview.ini

========== Files Created - No Company Name ==========

[2012/05/25 20:38:41 | 000,337,661 | ---- | C] () -- C:\Users\Sharon\Desktop\FSS.exe

[2012/05/24 17:16:02 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe

[2012/05/24 17:16:02 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe

[2012/05/24 17:16:02 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe

[2012/05/24 17:16:02 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe

[2012/05/24 17:16:02 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe

[2012/05/23 20:16:34 | 000,001,905 | ---- | C] () -- C:\Windows\diagwrn.xml

[2012/05/23 20:16:34 | 000,001,905 | ---- | C] () -- C:\Windows\diagerr.xml

[2012/05/23 08:37:37 | 000,000,081 | ---- | C] () -- C:\Users\Sharon\AppData\Roaming\mbam.context.scan

[2012/05/07 15:17:52 | 000,333,804 | ---- | C] () -- C:\Users\Sharon\Documents\Sarah Dentist bill.pdf

[2012/05/04 10:17:23 | 000,127,660 | ---- | C] () -- C:\Users\Sharon\Documents\CATICTemp.PZIP

[2012/01/31 10:59:54 | 000,000,041 | ---- | C] () -- C:\Windows\SysWow64\KM227125.DAT

[2012/01/31 10:59:54 | 000,000,041 | ---- | C] () -- C:\Windows\KM227125.DAT

[2011/08/02 19:40:30 | 000,173,209 | ---- | C] () -- C:\Windows\hppins13.dat

[2011/08/02 10:08:00 | 000,170,374 | ---- | C] () -- C:\Windows\hppins13.dat.temp

[2011/08/02 10:08:00 | 000,006,760 | ---- | C] () -- C:\Windows\hppmdl13.dat.temp

[2011/01/10 18:43:41 | 000,000,732 | ---- | C] () -- C:\Users\Sharon\AppData\Local\d3d9caps64.dat

[2010/12/20 22:27:20 | 000,003,113 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat

[2010/07/20 09:52:04 | 000,000,120 | ---- | C] () -- C:\Users\Sharon\AppData\Local\Dqogey.dat

[2010/07/20 09:52:04 | 000,000,000 | ---- | C] () -- C:\Users\Sharon\AppData\Local\Pbarep.bin

< End of report >

Link to post
Share on other sites

Both logs together were too large to post...here's the other:

Extras:

OTL Extras logfile created on: 5/26/2012 9:43:23 AM - Run 1

OTL by OldTimer - Version 3.2.43.1 Folder = C:\Users\Sharon\Desktop

64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.93 Gb Total Physical Memory | 5.24 Gb Available Physical Memory | 88.31% Memory free

11.98 Gb Paging File | 11.44 Gb Available in Paging File | 95.46% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 581.11 Gb Total Space | 430.14 Gb Free Space | 74.02% Space Free | Partition Type: NTFS

Drive D: | 15.00 Gb Total Space | 6.00 Gb Free Space | 40.02% Space Free | Partition Type: NTFS

Drive F: | 931.51 Gb Total Space | 855.69 Gb Free Space | 91.86% Space Free | Partition Type: NTFS

Drive G: | 1.88 Gb Total Space | 1.87 Gb Free Space | 99.76% Space Free | Partition Type: FAT

Drive H: | 983.72 Mb Total Space | 53.36 Mb Free Space | 5.42% Space Free | Partition Type: FAT

Computer Name: SHARON-PC | User Name: Sharon | Logged in as Administrator.

Boot Mode: SafeMode with Networking | Scan Mode: All users | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-1280911578-185664597-1390033846-1000\SOFTWARE\Classes\<extension>]

.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)

inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)

InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)

InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 0

"FirewallDisableNotify" = 0

"AntiVirusDisableNotify" = 0

"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]

"VistaSp2" = 79 52 68 5C 21 AE CB 01 [binary data]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirewallDisableNotify" = 0

"AntiVirusDisableNotify" = 0

"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"oobe_av" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"EnableFirewall" = 0

"DisableNotifications" = 0

"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 0

"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

"EnableFirewall" = 0

"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{05431D16-155F-436F-985E-C487254612FD}" = lport=139 | protocol=6 | dir=in | app=system |

"{214EFA2F-E450-4C7F-A575-580AE3D6F5E2}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{39E83632-A3D4-4F49-8C20-3B7D8B778B6F}" = lport=2869 | protocol=6 | dir=in | app=system |

"{3F08378D-F490-49F0-8710-91A83A099342}" = rport=445 | protocol=6 | dir=out | app=system |

"{50A0722D-F463-499E-895A-C3443C6F5E62}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{5294A6E5-328A-4EC9-B30F-01DEA54E59ED}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

"{59D60A50-D603-421C-B310-0224F40F0FB8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{6B1F39BA-757A-427A-8ADF-CF9E0359414D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |

"{6FC878F2-2C15-4DE0-A9A4-A0F5A5558F4C}" = rport=137 | protocol=17 | dir=out | app=system |

"{85E1C3A9-EF97-41EC-A64D-88CC13AE13E9}" = rport=138 | protocol=17 | dir=out | app=system |

"{A0E204E6-7005-4709-BE84-4D64E32CA65A}" = rport=10243 | protocol=6 | dir=out | app=system |

"{AD46327A-CFD5-4037-BD76-D1C9CEB12BA8}" = lport=10243 | protocol=6 | dir=in | app=system |

"{AE094484-6041-48B8-ADA8-E34F7CD4BB25}" = lport=445 | protocol=6 | dir=in | app=system |

"{B41C3A4B-C626-47A1-B8D0-D03E19957C03}" = lport=137 | protocol=17 | dir=in | app=system |

"{B67FB057-F5F9-4407-93D0-48124EB37BB7}" = lport=138 | protocol=17 | dir=in | app=system |

"{BB62E46C-A8D7-4C3A-8A55-C66A9FE39557}" = rport=139 | protocol=6 | dir=out | app=system |

"{DBD612E4-6530-478E-BE3F-3A4028492AF9}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{EA5BCB0F-2C24-4BAE-BFCF-9AD7EF0366C0}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{F371788D-BE8E-456D-9770-143739569961}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{01DF63BC-AC38-4EC5-B2A2-821826FBA8C0}" = protocol=17 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |

"{0320637A-FDA5-400C-A84D-837E60F0C293}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |

"{06D11211-20E3-4606-9DC7-B4B418A31F0E}" = dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |

"{0CABA7CF-6BA6-4D2A-AE3C-C9F8EF4F26DA}" = protocol=6 | dir=in | app=c:\dsi\oldreplite2\inetupapp.exe |

"{0E04334E-5C70-4C61-9A87-F31D48F4D423}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |

"{1192A206-D675-40C5-A270-FDA569B27443}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |

"{17FBF102-23B8-4C66-B0A6-B052D381D161}" = protocol=17 | dir=in | app=c:\dsi\fidlite3\inetupapp.exe |

"{1911D2F6-CF73-4A56-956E-8D48A1A489A0}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{19EF54F6-E8FF-43DC-A2DA-D656CE39BFBD}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{21953175-A652-48DD-90A3-BB1BA9257FBD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

"{2338289A-2655-442E-82EE-645688B60F3C}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |

"{3508F21C-83BD-4C6D-953D-C79E54A2A4E1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{36D400EE-E2A5-4613-8416-701A546FA72D}" = protocol=6 | dir=in | app=c:\dsi\fidlite2\inetupapp.exe |

"{38DD483B-9C4F-4768-AE98-A0F05D1ADF25}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |

"{3944C92F-998D-43CD-A869-662599E0FC6A}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{472A1FB4-4FE5-4055-96A7-EE45681719C3}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{4E2B32BB-3F6B-4B2E-AA99-7F2DEB118D5E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |

"{550FB8CC-74FE-403A-AF83-529C29649D3E}" = protocol=6 | dir=in | app=c:\program files (x86)\rhapsody\rhapsody.exe |

"{5A69C6F8-5C60-4015-B151-6F41433BAE43}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{603B22B2-C651-4811-990B-EBFED8730FD7}" = protocol=17 | dir=in | app=c:\dsi\oldreplite2\inetupapp.exe |

"{653EA1E9-72F7-4C05-9F29-AEC60F1890B3}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |

"{65406108-B03D-4A7C-B50E-2201F211D4CD}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |

"{65D43751-CEC9-413A-9FE6-40C113EF7158}" = protocol=17 | dir=in | app=c:\dsi\fidlite2\inetupapp.exe |

"{68F965C9-9DAC-4239-B938-7BDCBF7513BF}" = protocol=17 | dir=in | app=c:\program files (x86)\rhapsody\rhapsody.exe |

"{7800C526-0976-40E6-A992-D54CD17730A1}" = protocol=6 | dir=in | app=c:\dsi\fidlite3\inetupapp.exe |

"{792ED84E-87AB-4460-A599-87A99ED82D84}" = protocol=6 | dir=out | app=system |

"{7DD61042-B8AD-4A24-B466-A750BAA919E7}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |

"{83BEAA1B-C33B-4A12-BD15-434F18E38442}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{96082B7D-0578-4983-BB4F-422FAE18C201}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |

"{A16C1310-F7A5-40B1-93C2-349076974013}" = protocol=17 | dir=in | app=c:\dsi\oldreplite\inetupapp.exe |

"{AD470FE8-331F-42BC-A7DE-6C60480BB663}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |

"{B7B5523F-4EF2-47F3-AEBC-D6C072F9865A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

"{BA7D6F98-8AB6-4AF3-A672-CF03DB370905}" = protocol=6 | dir=in | app=c:\dsi\fidlite\inetupapp.exe |

"{BCA74B7E-77AD-442B-9964-176539454967}" = protocol=6 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |

"{BD698BF7-1E44-47BC-89D6-B4717F7731B8}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |

"{CC539A47-6490-4EDE-A676-ACAB0DBBFFF9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{D6808121-8B12-4EA0-B5BB-635C91DA3A71}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{DB872D8D-BC97-41A6-9722-F8FC570C72BA}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |

"{E2D69842-FE6C-4C53-A6B8-50FD8EA3D04B}" = dir=in | app=c:\program files (x86)\common files\mcafee\mna\mcnasvc.exe |

"{EFB1A026-EF76-487A-8748-AFB684651F62}" = protocol=17 | dir=in | app=c:\dsi\fidlite\inetupapp.exe |

"{FA9CFBF8-5F20-4BC1-8401-974F4FFD3FB1}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{FF4E0AB3-2B03-404C-939F-E2464BF10914}" = protocol=6 | dir=in | app=c:\dsi\oldreplite\inetupapp.exe |

"TCP Query User{064FE306-3E89-4D78-A343-72141E5C4C15}C:\program files (x86)\catic\prepexpress\prepsupport.exe" = protocol=6 | dir=in | app=c:\program files (x86)\catic\prepexpress\prepsupport.exe |

"TCP Query User{257072DB-38C5-4004-B578-667955DB6C92}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |

"TCP Query User{4335500D-86B4-4B70-84ED-5CC6FF5E6860}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |

"TCP Query User{4C081DAC-B9DC-489B-A1DC-E7AA6A1820BC}C:\program files (x86)\dell video chat\dellvideochat.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |

"TCP Query User{EE44A65E-9993-433C-A279-94DE75BF5CCE}C:\users\sharon\appdata\local\temp\lmir0001.tmp\lmi_rescue.exe" = protocol=6 | dir=in | app=c:\users\sharon\appdata\local\temp\lmir0001.tmp\lmi_rescue.exe |

"UDP Query User{1A65FC8E-0BAE-4996-85E5-8ED604535B6E}C:\program files (x86)\catic\prepexpress\prepsupport.exe" = protocol=17 | dir=in | app=c:\program files (x86)\catic\prepexpress\prepsupport.exe |

"UDP Query User{6CBB1297-9E70-44F9-8F09-CECF453053E3}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |

"UDP Query User{711ADE1C-0F28-4EA4-A035-DE6AB1A84C7F}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |

"UDP Query User{A02ABFEC-3D9C-4997-B83D-0C9B8B314E76}C:\program files (x86)\dell video chat\dellvideochat.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |

"UDP Query User{FE4E5F54-E3D5-4952-81F1-EDA323F17ABE}C:\users\sharon\appdata\local\temp\lmir0001.tmp\lmi_rescue.exe" = protocol=17 | dir=in | app=c:\users\sharon\appdata\local\temp\lmir0001.tmp\lmi_rescue.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{02AD9D20-03D2-4DE0-8793-E8253026AD86}" = EMCGadgets64

"{6F801026-6AF0-4520-9153-4C9B4CAAB361}" = HP LaserJet P2050 Series 6.0

"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007

"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007

"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007

"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager

"{99A5569D-9F86-4f32-A227-1538B731DA42}" = Canon MF4320-4350

"{AE57C044-8912-A181-A0E4-BC2DAB3A092A}" = ATI Catalyst Install Manager

"{B2C5B378-546F-75A7-7757-C1EAAFAF9E33}" = ccc-utility64

"{C788B026-20BD-4E96-B698-533F1D6C5013}" = 64 Bit HP CIO Components Installer

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319

"{F6CB42B9-F033-4152-8813-FF11DA8E6A78}" = Dell Dock

"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit

"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit

"ATT-RC" = ATT-RC Self Support Tool

"Creative OEM005" = Monitor Webcam (SP2208WFP) Driver (1.00.08.0720)

"CutePDF Writer Installation" = CutePDF Writer 2.7

"HPExtendedCapabilities" = HP Customer Participation Program 10.0

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data

"{098122AB-C605-4853-B441-C0A4EB359B75}" = DirectXInstallService

"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration

"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online

"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works

"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer

"{1D5E29AD-39A9-4D0A-A8B6-46A6FCD8C995}" = Live! Cam Avatar v1.0

"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools

"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer

"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java 6 Update 11

"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1

"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager

"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7

"{35870352-4116-4E80-AB2A-37A07ECE30E2}" = R-Viewer.1.6.3768

"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Browser Address Error Redirector

"{3FB3647F-B6A6-46B4-8613-A09BCFAB80F0}" = Roxio Creator Premier 10

"{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}" = Banctec Service Agreement

"{469EF13B-4AD0-48D7-AF89-6B92278293E2}" = Roxio Creator Premier

"{4DBDBBE4-723A-4AA2-9A27-17F5DD716206}" = FRED.Net

"{5FD89EA1-99C2-40EE-BBF5-20F8991ED756}" = Catalyst Control Center - Branding

"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector

"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator

"{664D6E1D-2A6C-D54D-31A5-B6BC30CEB0C6}" = CCC Help English

"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler

"{6767DFEE-8909-453A-B553-C7693912B2EB}" = Canon MF Toolbox 4.9.1.1.mf09

"{6817B93A-8497-11D4-AA25-00104B66574A}" = Displaysoft Main Install

"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder

"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio

"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime

"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com

"{7B9F5775-8C8C-2A4E-0CAB-74EA7AF5CB09}" = ccc-core-static

"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide

"{89B6F63A-7E0C-424A-9D39-C4EF59E96D78}" = hppQFolderP2050

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Roxio CinePlayer Decoder Pack

"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007

"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007

"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007

"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007

"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007

"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007

"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system

"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007

"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007

"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In

"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007

"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)

"{995F2783-8311-49BF-833E-DB659774B4F6}" = hppFonts

"{A1570454-ED12-4050-A7AC-9282C7AFB23C}" = Window Shopper

"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR

"{A73BDB2A-E4A7-4FE8-960E-6A5C8BF76FCB}" = XPS MiniView Gadget

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{AA945C94-285E-DE48-A30F-70105C6580DE}" = Catalyst Control Center Graphics Previews Common

"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.0

"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9

"{B314C339-8AEC-4069-8793-4478CD650CE1}" = GMD Print Utility

"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy

"{BB7C99CE-E975-4C67-A2DB-942A66ABC804}" = PrepExp

"{CC29B835-95A5-3CD9-087B-F94D7B9ECC9B}" = Catalyst Control Center InstallProxy

"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg

"{D085A1B6-90A4-11D3-82B7-00C04FA309DE}" = Microsoft Money 2001

"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch

"{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module

"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator Premier

"Adobe AIR" = Adobe AIR

"Advanced Audio FX Engine" = Advanced Audio FX Engine

"Advanced Video FX Engine" = Advanced Video FX Engine

"ATT-RC" = ATT-RC Self Support Tool

"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com

"Coupon Printer for Windows4.0" = Coupon Printer for Windows

"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows

"Dell Video Chat" = Dell Video Chat (remove only)

"Dell Webcam Center" = Dell Webcam Center

"Dell Webcam Manager" = Dell Webcam Manager

"DocMaster" = DocMaster 4.4

"Driver Performer_is1" = Driver Performer

"eLynx Ltd. Web Post Printer" = eLynx Ltd. Web Post Printer

"eLynx SMARTvue" = eLynx SMARTvue

"FNT-CT Rate Calculator_is1" = FNT-CT Rate Calculator 2.30

"FNTG-CT Rate Calculator_is1" = FNTG-CT Rate Calculator 2.80

"Google Chrome" = Google Chrome

"HijackThis" = HijackThis 2.0.2

"HOMESTUDENTR" = Microsoft Office Home and Student 2007

"iBryte_browseforchange" = Browse For Change

"InstallShield_{35870352-4116-4E80-AB2A-37A07ECE30E2}" = R-Viewer.1.6.3768

"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400

"McAfee Virtual Technician" = McAfee Virtual Technician

"Mozilla Firefox 10.0 (x86 en-US)" = Mozilla Firefox 10.0 (x86 en-US)

"MSC" = McAfee SecurityCenter

"PrepExpress 6.0" = PrepExpress 6.0

"PrepExpress 6.0 Update" = PrepExpress 6.0 Update

"Quick Title_is1" = Quick Title 2.30

"RealPlayer 15.0" = RealPlayer

"Rhapsody" = Rhapsody

"SwiftView" = SwiftView Viewer

"The Weather Channel Desktop 6" = The Weather Channel Desktop 6

"YInstHelper" = Yahoo! Install Manager

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1280911578-185664597-1390033846-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

"Wajam" = Wajam

========== Last 10 Event Log Errors ==========

[ Application Events ]

Error - 3/13/2011 10:18:54 AM | Computer Name = Sharon-PC | Source = WinMgmt | ID = 10

Description =

Error - 3/13/2011 9:20:53 PM | Computer Name = Sharon-PC | Source = WinMgmt | ID = 10

Description =

Error - 3/13/2011 9:21:40 PM | Computer Name = Sharon-PC | Source = Windows Search Service | ID = 3024

Description =

Error - 3/13/2011 9:21:50 PM | Computer Name = Sharon-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083

Description =

Error - 3/13/2011 10:00:47 PM | Computer Name = Sharon-PC | Source = EventSystem | ID = 4621

Description =

Error - 3/14/2011 8:48:08 AM | Computer Name = Sharon-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083

Description =

Error - 3/14/2011 8:49:12 AM | Computer Name = Sharon-PC | Source = WinMgmt | ID = 10

Description =

Error - 3/14/2011 8:29:40 PM | Computer Name = Sharon-PC | Source = EventSystem | ID = 4621

Description =

Error - 3/15/2011 7:39:37 AM | Computer Name = Sharon-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083

Description =

Error - 3/15/2011 7:40:08 AM | Computer Name = Sharon-PC | Source = WinMgmt | ID = 10

Description =

[ System Events ]

Error - 5/26/2012 9:29:54 AM | Computer Name = Sharon-PC | Source = Service Control Manager | ID = 7026

Description =

Error - 5/26/2012 9:31:56 AM | Computer Name = Sharon-PC | Source = Service Control Manager | ID = 7003

Description =

Error - 5/26/2012 9:37:55 AM | Computer Name = Sharon-PC | Source = DCOM | ID = 10005

Description =

Error - 5/26/2012 9:38:05 AM | Computer Name = Sharon-PC | Source = DCOM | ID = 10005

Description =

Error - 5/26/2012 9:38:07 AM | Computer Name = Sharon-PC | Source = DCOM | ID = 10005

Description =

Error - 5/26/2012 9:38:23 AM | Computer Name = Sharon-PC | Source = DCOM | ID = 10005

Description =

Error - 5/26/2012 9:38:27 AM | Computer Name = Sharon-PC | Source = Service Control Manager | ID = 7001

Description =

Error - 5/26/2012 9:38:27 AM | Computer Name = Sharon-PC | Source = Service Control Manager | ID = 7003

Description =

Error - 5/26/2012 9:38:27 AM | Computer Name = Sharon-PC | Source = Service Control Manager | ID = 7026

Description =

Error - 5/26/2012 9:38:41 AM | Computer Name = Sharon-PC | Source = DCOM | ID = 10005

Description =

< End of report >

Thanks for help and responsiveness!

Link to post
Share on other sites

Can you please post me a new FSS log.

Also, press Windows key + R, type devmgmt.msc and press enter.

Click View > Show Hidden Devices.

Now expand the Non Plug and Play category and look in the list for any devices that have a !, ? or X in front of them. List these devices in your next reply.

Link to post
Share on other sites

The only thing under non-plug and play is "Security Processor Loader Driver" with an ! in front of it.

New FSS log:

Farbar Service Scanner Version: 25-05-2012

Ran by Sharon (administrator) on 26-05-2012 at 10:21:50

Running from "C:\Users\Sharon\Desktop\Tools"

Microsoft® Windows Vista™ Home Premium Service Pack 2 (X64)

Boot Mode: Nerwork

****************************************************************

Internet Services:

============

Connection Status:

==============

Localhost is accessible.

LAN connected.

Google IP is accessible.

Yahoo IP is accessible.

Windows Firewall:

=============

Firewall Disabled Policy:

==================

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"EnableFirewall"=DWORD:0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall"=DWORD:0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

"EnableFirewall"=DWORD:0

System Restore:

============

SDRSVC Service is not running. Checking service configuration:

The start type of SDRSVC service is OK.

The ImagePath of SDRSVC service is OK.

The ServiceDll of SDRSVC service is OK.

Checking LEGACY_SDRSVC: ATTENTION!=====> Unable to open LEGACY_SDRSVC\0000 registry key. The key does not exist.

VSS Service is not running. Checking service configuration:

The start type of VSS service is OK.

The ImagePath of VSS service is OK.

System Restore Disabled Policy:

========================

Security Center:

============

wscsvc Service is not running. Checking service configuration:

The start type of wscsvc service is OK.

The ImagePath of wscsvc service is OK.

The ServiceDll of wscsvc service is OK.

Checking LEGACY_wscsvc: ATTENTION!=====> Unable to open LEGACY_wscsvc\0000 registry key. The key does not exist.

Windows Update:

============

wuauserv Service is not running. Checking service configuration:

The start type of wuauserv service is OK.

The ImagePath of wuauserv service is OK.

The ServiceDll of wuauserv service is OK.

BITS Service is not running. Checking service configuration:

The start type of BITS service is OK.

The ImagePath of BITS service is OK.

The ServiceDll of BITS service is OK.

Checking LEGACY_BITS: ATTENTION!=====> Unable to open LEGACY_BITS\0000 registry key. The key does not exist.

EventSystem Service is not running. Checking service configuration:

The start type of EventSystem service is OK.

The ImagePath of EventSystem service is OK.

The ServiceDll of EventSystem service is OK.

Windows Autoupdate Disabled Policy:

============================

File Check:

========

C:\Windows\System32\nsisvc.dll

[2008-01-20 22:49] - [2008-01-20 22:49] - 0024576 ____A (Microsoft Corporation) ACB62BAA1C319B17752553DF3026EEEB

C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit

C:\Windows\System32\dhcpcsvc.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0268288 ____A (Microsoft Corporation) 3ED0321127CE70ACDAABBF77E157C2A7

C:\Windows\System32\drivers\afd.sys

[2012-02-16 09:23] - [2012-01-03 10:25] - 0404992 ____A (Microsoft Corporation) C4F6CE6087760AD70960C9EB130E7943

C:\Windows\System32\drivers\tdx.sys => MD5 is legit

C:\Windows\System32\Drivers\tcpip.sys

[2012-05-11 08:03] - [2012-03-30 08:45] - 1423744 ____A (Microsoft Corporation) 46D448E9117464E4D3BBF36D7E3FA48E

C:\Windows\System32\dnsrslvr.dll

[2011-04-15 12:50] - [2011-03-02 12:12] - 0117760 ____A (Microsoft Corporation) 06230F1B721494A6DF8D47FD395BB1B0

C:\Windows\System32\mpssvc.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0603136 ____A (Microsoft Corporation) 897E3BAF68BA406A61682AE39C83900C

C:\Windows\System32\bfe.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0458240 ____A (Microsoft Corporation) FFB96C2589FFA60473EAD78B39FBDE29

C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit

C:\Windows\System32\SDRSVC.dll

[2008-01-20 22:47] - [2008-01-20 22:47] - 0128000 ____A (Microsoft Corporation) 4FF71B076A7760FE75EA5AE2D0EE0018

C:\Windows\System32\vssvc.exe

[2009-09-11 08:35] - [2009-04-11 03:11] - 1433600 ____A (Microsoft Corporation) B75232DAD33BFD95BF6F0A3E6BFF51E1

C:\Windows\System32\wscsvc.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0074752 ____A (Microsoft Corporation) 9EA3E6D0EF7A5C2B9181961052A4B01A

C:\Windows\System32\wbem\WMIsvc.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0221696 ____A (Microsoft Corporation) D2E7296ED1BD26D8DB2799770C077A02

C:\Windows\System32\wuaueng.dll

[2009-10-29 11:24] - [2009-08-06 22:24] - 2424024 ____A (Microsoft Corporation) FB3796754FE00F0BDC87A36F164A5F4D

C:\Windows\System32\qmgr.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 1081856 ____A (Microsoft Corporation) 6D316F4859634071CC25C4FD4589AD2C

C:\Windows\System32\es.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0361984 ____A (Microsoft Corporation) E12F22B73F153DECE721CD45EC05B4AF

C:\Windows\System32\cryptsvc.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0166912 ____A (Microsoft Corporation) 18918613E63F387CDE4D95CA7D49DCF7

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\System32\rpcss.dll

[2009-09-11 08:35] - [2009-04-11 03:11] - 0719872 ____A (Microsoft Corporation) CF8B9A3A5E7DC57724A89D0C3E8CF9EF

**** End of log **** Thanks

Link to post
Share on other sites

Here is the attach file:

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2011-08-26.01)

.

Microsoft® Windows Vista™ Home Premium

Boot Device: \Device\HarddiskVolume3

Install Date: 12/3/2008 2:49:00 PM

System Uptime: 5/26/2012 9:36:26 AM (2 hours ago)

.

Motherboard: Dell Inc. | | 0TP406

Processor: Intel® Core2 Quad CPU Q6600 @ 2.40GHz | CPU | 2394/1066mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 581 GiB total, 429.065 GiB free.

D: is FIXED (NTFS) - 15 GiB total, 6.003 GiB free.

E: is CDROM ()

F: is FIXED (NTFS) - 932 GiB total, 855.688 GiB free.

G: is Removable

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

RP1337: 4/20/2012 7:57:22 AM - Windows Update

RP1338: 4/21/2012 12:13:37 PM - Scheduled Checkpoint

RP1339: 4/22/2012 10:39:57 AM - Scheduled Checkpoint

RP1340: 4/24/2012 8:04:06 AM - Windows Update

RP1341: 4/26/2012 8:51:32 AM - Scheduled Checkpoint

RP1342: 4/27/2012 7:51:36 AM - Windows Update

RP1343: 4/28/2012 12:42:56 PM - Scheduled Checkpoint

RP1344: 4/29/2012 11:11:31 AM - Scheduled Checkpoint

RP1345: 4/30/2012 6:37:12 PM - Scheduled Checkpoint

RP1346: 5/1/2012 7:44:18 AM - Windows Update

RP1347: 5/3/2012 1:31:08 PM - Windows Update

RP1348: 5/4/2012 7:56:48 AM - Windows Update

RP1349: 5/5/2012 9:03:23 AM - Scheduled Checkpoint

RP1350: 5/6/2012 5:35:25 PM - Scheduled Checkpoint

RP1351: 5/7/2012 2:31:39 PM - Scheduled Checkpoint

RP1352: 5/8/2012 10:14:10 AM - Windows Update

RP1353: 5/9/2012 8:59:09 AM - Scheduled Checkpoint

RP1354: 5/10/2012 1:01:20 PM - Scheduled Checkpoint

RP1355: 5/11/2012 11:45:53 AM - Windows Update

RP1356: 5/11/2012 7:38:54 PM - Windows Update

RP1357: 5/12/2012 3:27:38 PM - Scheduled Checkpoint

RP1358: 5/13/2012 11:34:36 AM - Scheduled Checkpoint

RP1359: 5/15/2012 9:51:47 AM - Windows Update

RP1360: 5/16/2012 7:55:45 PM - Scheduled Checkpoint

RP1361: 5/17/2012 9:28:17 AM - Scheduled Checkpoint

RP1362: 5/18/2012 7:26:08 AM - Windows Update

RP1363: 5/19/2012 4:11:47 PM - Scheduled Checkpoint

RP1364: 5/20/2012 9:27:43 AM - Windows Update

RP1365: 5/21/2012 10:26:12 AM - Scheduled Checkpoint

RP1366: 5/22/2012 7:41:39 AM - Windows Update

RP1367: 5/22/2012 10:24:14 PM - Scheduled Checkpoint

RP1369: 5/23/2012 8:11:23 AM - Windows Defender Checkpoint

.

==== Installed Programs ======================

.

.

Update for Microsoft Office 2007 (KB2508958)

Acrobat.com

Adobe AIR

Adobe Reader 9.5.0

Advanced Audio FX Engine

Advanced Video FX Engine

ATI Catalyst Registration

ATT-RC Self Support Tool

Banctec Service Agreement

Browse For Change

Browser Address Error Redirector

Canon MF Toolbox 4.9.1.1.mf09

Catalyst Control Center - Branding

Catalyst Control Center Graphics Previews Common

Catalyst Control Center InstallProxy

ccc-core-static

CCC Help English

Compatibility Pack for the 2007 Office system

Coupon Printer for Windows

CustomerResearchQFolder

Dell DataSafe Online

Dell Getting Started Guide

Dell Video Chat (remove only)

Dell Webcam Center

Dell Webcam Manager

DirectXInstallService

Displaysoft Main Install

DocMaster 4.4

Driver Performer

eLynx Ltd. Web Post Printer

eLynx SMARTvue

FNT-CT Rate Calculator 2.30

FNTG-CT Rate Calculator 2.80

FRED.Net

GMD Print Utility

Google Chrome

Google Toolbar for Internet Explorer

Google Update Helper

HijackThis 2.0.2

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)

hppFonts

hppQFolderP2050

Java 6 Update 11

Java 6 Update 7

Live! Cam Avatar Creator

Live! Cam Avatar v1.0

Malwarebytes Anti-Malware version 1.61.0.1400

MarketResearch

McAfee SecurityCenter

McAfee Virtual Technician

Microsoft Money 2001

Microsoft Office 2007 Service Pack 3 (SP3)

Microsoft Office Excel MUI (English) 2007

Microsoft Office File Validation Add-In

Microsoft Office Home and Student 2007

Microsoft Office OneNote MUI (English) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office PowerPoint Viewer 2007 (English)

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office Word MUI (English) 2007

Microsoft Silverlight

Microsoft Works

Move Networks Media Player for Internet Explorer

Mozilla Firefox 10.0 (x86 en-US)

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

PrepExp

PrepExpress 6.0

PrepExpress 6.0 Update

Quick Title 2.30

R-Viewer.1.6.3768

RealNetworks - Microsoft Visual C++ 2008 Runtime

RealPlayer

RealUpgrade 1.1

Rhapsody

Roxio Activation Module

Roxio CinePlayer Decoder Pack

Roxio Creator Audio

Roxio Creator Copy

Roxio Creator Data

Roxio Creator Premier

Roxio Creator Premier 10

Roxio Creator Tools

Roxio Express Labeler

Roxio Update Manager

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)

Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition

Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition

Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition

Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition

Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition

Spelling Dictionaries Support For Adobe Reader 9

SwiftView Viewer

The Weather Channel Desktop 6

Update for 2007 Microsoft Office System (KB967642)

Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

Wajam

WebReg

Window Shopper

XPS MiniView Gadget

Yahoo! Install Manager

.

==== Event Viewer Messages From Past Week ========

.

5/26/2012 9:38:41 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

5/26/2012 9:38:27 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Beep spldr Wanarpv6

5/26/2012 9:38:27 AM, Error: Service Control Manager [7003] - The Internet Connection Sharing (ICS) service depends the following service: Netman. This service might not be installed.

5/26/2012 9:38:27 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.

5/26/2012 9:38:23 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}

5/26/2012 9:38:07 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}

5/26/2012 9:38:05 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

5/26/2012 9:37:55 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}

5/26/2012 9:31:56 AM, Error: Service Control Manager [7003] - The Windows Media Player Network Sharing Service service depends the following service: UPnPHost. This service might not be installed.

5/26/2012 9:29:54 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Beep

5/26/2012 9:29:44 AM, Error: Service Control Manager [7023] - The WebClient service terminated with the following error: The system cannot find the file specified.

5/26/2012 9:29:44 AM, Error: Service Control Manager [7023] - The seclogon service terminated with the following error: The specified procedure could not be found.

5/26/2012 9:29:44 AM, Error: Service Control Manager [7000] - The SessionLauncher service failed to start due to the following error: The system cannot find the path specified.

5/26/2012 10:12:17 AM, Error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration.

5/25/2012 9:35:14 AM, Error: Service Control Manager [7022] - The Human Interface Device Access service hung on starting.

5/25/2012 9:34:16 AM, Error: Service Control Manager [7024] - The ReadyBoost service terminated with service-specific error 0 (0x0).

5/25/2012 9:34:16 AM, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: Operation aborted

5/25/2012 9:34:16 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Workstation service which failed to start because of the following error: The dependency service does not exist or has been marked for deletion.

5/25/2012 8:33:50 PM, Error: Microsoft-Windows-TBS [16392] - An error occurred while starting the TBS. The error code was 0x8007000d.

5/25/2012 8:32:34 PM, Error: Service Control Manager [7003] - The Workstation service depends the following service: NSI. This service might not be installed.

5/25/2012 8:32:34 PM, Error: Service Control Manager [7003] - The Windows Driver Foundation - User-mode Driver Framework service depends the following service: PlugPlay. This service might not be installed.

5/25/2012 8:32:34 PM, Error: Service Control Manager [7003] - The Windows Audio Endpoint Builder service depends the following service: PlugPlay. This service might not be installed.

5/25/2012 8:32:34 PM, Error: Service Control Manager [7003] - The Telephony service depends the following service: PlugPlay. This service might not be installed.

5/25/2012 8:32:34 PM, Error: Service Control Manager [7003] - The Tablet PC Input Service service depends the following service: PlugPlay. This service might not be installed.

5/25/2012 8:32:34 PM, Error: Service Control Manager [7003] - The Network Location Awareness service depends the following service: NSI. This service might not be installed.

5/25/2012 8:32:34 PM, Error: Service Control Manager [7003] - The IP Helper service depends the following service: NSI. This service might not be installed.

5/25/2012 8:32:34 PM, Error: Service Control Manager [7003] - The DHCP Client service depends the following service: NSI. This service might not be installed.

5/25/2012 8:32:34 PM, Error: Service Control Manager [7001] - The Windows Audio service depends on the Windows Audio Endpoint Builder service which failed to start because of the following error: The dependency service does not exist or has been marked for deletion.

5/25/2012 8:30:08 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

5/25/2012 8:29:44 PM, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

5/25/2012 8:11:05 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Beep DfsC mfehidk mfenlfk mfewfpk NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr Tcpip tdx Wanarpv6 ws2ifsl

5/25/2012 8:11:05 PM, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.

5/25/2012 8:11:05 PM, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error: The dependency service or group failed to start.

5/25/2012 8:11:05 PM, Error: Service Control Manager [7001] - The TCP/IP Registry Compatibility service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.

5/25/2012 8:11:05 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.

5/25/2012 8:11:05 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.

5/25/2012 8:11:05 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.

5/25/2012 8:11:05 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.

5/25/2012 8:11:05 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.

5/25/2012 8:11:05 PM, Error: Service Control Manager [7001] - The McAfee Validation Trust Protection Service service depends on the McAfee Inc. mfehidk service which failed to start because of the following error: A device attached to the system is not functioning.

5/25/2012 8:11:05 PM, Error: Service Control Manager [7001] - The McAfee Personal Firewall Service service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start.

5/25/2012 8:11:05 PM, Error: Service Control Manager [7001] - The McAfee McShield service depends on the McAfee Validation Trust Protection Service service which failed to start because of the following error: The dependency service or group failed to start.

5/25/2012 8:11:05 PM, Error: Service Control Manager [7001] - The McAfee Firewall Core Service service depends on the McAfee Validation Trust Protection Service service which failed to start because of the following error: The dependency service or group failed to start.

5/25/2012 8:11:05 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.

5/25/2012 8:06:40 PM, Error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error: The dependency service does not exist or has been marked for deletion.

5/25/2012 6:55:08 AM, Error: EventLog [6008] - The previous system shutdown at 6:43:02 AM on 5/25/2012 was unexpected.

5/25/2012 4:08:35 PM, Error: Service Control Manager [7001] - The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error: The dependency service does not exist or has been marked for deletion.

5/24/2012 8:15:45 PM, Error: EventLog [6008] - The previous system shutdown at 6:05:18 PM on 5/24/2012 was unexpected.

5/24/2012 6:52:40 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DfsC mfehidk mfenlfk mfewfpk NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr Tcpip tdx Wanarpv6

5/24/2012 6:52:40 AM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.

5/24/2012 6:52:40 AM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.

5/24/2012 5:58:17 PM, Error: EventLog [6008] - The previous system shutdown at 5:54:08 PM on 5/24/2012 was unexpected.

5/24/2012 5:46:07 PM, Error: EventLog [6008] - The previous system shutdown at 5:43:02 PM on 5/24/2012 was unexpected.

5/24/2012 5:15:13 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: spldr Wanarpv6

5/23/2012 8:23:05 PM, Error: cdrom [11] - The driver detected a controller error on \Device\CdRom0.

5/23/2012 8:19:03 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service McNaiAnn with arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

5/23/2012 7:21:30 AM, Error: Microsoft-Windows-PrintSpooler [19] - The print spooler failed to share printer HP LaserJet P2050 Series PCL6 with shared resource name HP LaserJet P2050 Series PCL6. Error 2114. The printer cannot be used by others on the network.

5/23/2012 6:18:41 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service McAfee SiteAdvisor Service with arguments "" in order to run the server: {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C}

5/23/2012 5:35:24 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service McNaiAnn with arguments "" in order to run the server: {395633B1-EED9-4DFC-B67F-9788B51C9F06}

.

==== End Of File ===========================

Link to post
Share on other sites

I don't know how. Everything to do with anti-malware etc, ComboFix, DDsFSS, OTL, when viewed in normal mode (PC Booted normally) has the multi-colored shield superimposed on the icon. Clicking or trying to run them returns the error" The service does not exist as an installed service".

Is there some way to get around this? Maybe rename the .exe in safe mode and try in normal? I don't know.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.