Jump to content

how to make sure threats are gone


Recommended Posts

Hello kearbear and :welcome:! My name is Maniac and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.

Please open Malwarebytes' Anti-Malware, open Logs tab and double click on the line which is realted to your last scan (check the date). Post the entire content of the log in your next reply here.

Also, follow the instructions here and post the log files from DDS:

http://forums.malwarebytes.org/index.php?showtopic=9573

Link to post
Share on other sites

btw I'm still going slow after removing those 7 files.

Here is the log:

Malwarebytes Anti-Malware 1.70.0.1100

www.malwarebytes.org

Database version: v2013.01.14.10

Windows Vista Service Pack 2 x86 NTFS (Safe Mode/Networking)

Internet Explorer 9.0.8112.16421

kearbear :: KEARBEAR-LT [administrator]

1/15/2013 8:35:09 PM

mbam-log-2013-01-15 (20-35-09).txt

Scan type: Full scan (C:\|D:\|E:\|)

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 584573

Time elapsed: 3 hour(s), 24 minute(s), 18 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 1

HKCU\Software\AppDataLow\Software\MyWebSearch (PUP.MyWebsearch) -> Quarantined and deleted successfully.

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 6

C:\Users\kearbear\Documents\carrie.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Users\kearbear\Downloads\DownloadManager_Setup.exe (PUP.Bundle.Installer.OI) -> Quarantined and deleted successfully.

C:\Users\kearbear\Downloads\video_downloader (1).exe (PUP.BundleInstaller.VG) -> Quarantined and deleted successfully.

C:\Users\kearbear\Downloads\video_downloader (2).exe (PUP.BundleInstaller.VG) -> Quarantined and deleted successfully.

C:\Users\kearbear\Downloads\video_downloader.exe (PUP.BundleInstaller.VG) -> Quarantined and deleted successfully.

C:\Users\kearbear\Downloads\plugins\IWONSetup2.3.50.42.ZLfox000.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.

(end)

Here is the DDS:

DDS (Ver_2012-11-20.01) - NTFS_x86

Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.11.2

Run by kearbear at 20:51:56 on 2013-01-16

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3453.1128 [GMT -5:00]

.

AV: Norton Security Suite *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Norton Security Suite *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

FW: Norton Security Suite *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

.

============== Running Processes ================

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\Ati2evxx.exe

C:\Windows\system32\Ati2evxx.exe

C:\Windows\system32\SLsvc.exe

C:\Windows\System32\WLTRYSVC.EXE

C:\Windows\System32\bcmwltry.exe

C:\Windows\system32\brsvc01a.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\brss01a.exe

C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe

C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Windows\system32\aestsrv.exe

C:\Program Files\ATI\WebPAM\jetty\extra\win32\Wrapper.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Windows\system32\CSHelper.exe

C:\Program Files\Common Files\Dell\MySQL\bin\mysqld.exe

C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe

C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE

C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe

C:\Program Files\ATI\WebPAM\_jvm\bin\java.exe

C:\Windows\system32\lxdicoms.exe

C:\Program Files\Maxtor\Sync\SyncServices.exe

C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\6.4.0.9\ccSvcHst.exe

C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe

C:\Program Files\Common Files\Motive\pcCMService.exe

C:\Program Files\Common Files\Motive\pcServiceHost.exe

C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\6.4.0.9\ccSvcHst.exe

C:\Program Files\Samsung\AllShare\AllShareDMS\AllShareDMS.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\STacSV.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\Wavexpress\TVTonic\WXRSS.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\DRIVERS\xaudio.exe

C:\Program Files\Common Files\Dell\apache\bin\httpd.exe

C:\Program Files\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe

C:\Program Files\Common Files\Dell\apache\bin\httpd.exe

C:\Windows\System32\alg.exe

C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

C:\Program Files\Comcast\pcTrayApp.exe

C:\Program Files\Epson Software\Event Manager\EEventManager.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Windows\System32\spool\drivers\w32x86\3\E_TATIHWA.EXE

C:\Program Files\Constant Guard Protection Suite\IDVault.exe

C:\Program Files\Digital Line Detect\DLG.exe

C:\Program Files\Dell\QuickSet\quickset.exe

C:\Program Files\Southwest Airlines\Ding\Ding.exe

C:\Windows\system32\DllHost.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Windows\ehome\ehsched.exe

C:\Windows\ehome\ehRecvr.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Users\kearbear\Downloads\msert.exe

C:\Users\kearbear\Downloads\msert.exe

C:\Windows\System32\cleanmgr.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k rpcss

C:\Windows\System32\svchost.exe -k secsvcs

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k WerSvcGroup

C:\Windows\system32\svchost.exe -k imgsvc

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.google.com/

uWindow Title = Windows Internet Explorer provided by Qwest

uDefault_Page_URL = hxxp://qwest.live.com

mStart Page = hxxp://qwest.live.com

mDefault_Page_URL = hxxp://qwest.live.com

BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>

BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll

BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\program files\norton security suite\norton security suite\engine\6.4.0.9\coieplg.dll

BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - c:\program files\norton security suite\norton security suite\engine\6.4.0.9\ips\ipsbho.dll

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll

BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll

BHO: Constant Guard Protection Suite: {B84CDBE7-1B46-494B-A188-01D4C52DEB61} - c:\programdata\white sky, inc\id vault\iebho1.12.1012.1\NativeBHO.dll

BHO: CBrowserHelperObject Object: {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\program files\bae\BAE.dll

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll

TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\program files\norton security suite\norton security suite\engine\6.4.0.9\coieplg.dll

uRun: [EPLTarget\P0000000000000000] c:\windows\system32\spool\drivers\w32x86\3\e_tatihwa.exe /ept "epltarget\P0000000000000000" /M "WorkForce 545"

mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [LTCM Client] c:\program files\ltcm client\ltcmClient.exe /startup

mRun: [Comcast_McciTrayApp] "c:\program files\comcast\pcTrayApp.exe"

mRun: [EEventManager] "c:\program files\epson software\event manager\EEventManager.exe"

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [iSUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup

StartupFolder: c:\users\kearbear\appdata\roaming\micros~1\windows\startm~1\programs\startup\ding!.lnk - c:\program files\southwest airlines\ding\Ding.exe

StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\consta~1.lnk - c:\program files\constant guard protection suite\IDVault.exe

StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe

StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe

mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0

mPolicies-System: EnableUIADesktopToggle = dword:0

IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000

IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

.

INFO: HKCU has more than 50 listed domains.

If you wish to scan all of them, select the 'Force scan all domains' option.

.

DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB

DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} - hxxp://www.infospace.com/mypoints.main/tbar/mypointsSetup.exe

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab

TCP: NameServer = 192.168.15.1 192.168.1.1

TCP: Interfaces\{A45A3AFA-B775-453B-885D-48AF076411EC} : DHCPNameServer = 192.168.15.1 192.168.1.1

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll

Notify: GoToAssist - c:\program files\citrix\gotoassist\508\G2AWinLogon.dll

LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg

.

============= SERVICES / DRIVERS ===============

.

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0604000.009\symds.sys [2012-10-9 340088]

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0604000.009\symefa.sys [2012-10-9 924320]

R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.0.0.145\definitions\bashdefs\20130111.001\BHDrvx86.sys [2013-1-15 995488]

R1 ccSet_N360;Norton Security Suite Settings Manager;c:\windows\system32\drivers\n360\0604000.009\ccsetx86.sys [2012-10-9 132768]

R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.0.0.145\definitions\ipsdefs\20130116.002\IDSvix86.sys [2013-1-16 386720]

R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0604000.009\ironx86.sys [2012-10-9 149624]

R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0604000.009\symtdiv.sys [2012-10-9 345208]

R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\common files\abbyy\finereadersprint\9.00\licensing\NetworkLicenseServer.exe [2009-5-14 759048]

R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2011-8-20 73728]

R2 Apache2.2;Remote Access Media Server;c:\program files\common files\dell\apache\bin\httpd.exe [2007-9-21 15872]

R2 ATIWebPAM;ATI WebPAM;c:\program files\ati\webpam\jetty\extra\win32\Wrapper.exe [2003-9-29 110592]

R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [2009-2-6 266240]

R2 dsl-db;Remote Access DB;c:\program files\common files\dell\mysql\bin\mysqld.exe [2007-9-14 5730304]

R2 dsl-fs-sync;Remote Access File Sync Service;c:\program files\common files\dell\remote access file sync service\dsl_fs_sync.exe [2009-4-13 189680]

R2 EPSON_PM_RPCV4_05;EPSON V3 Service4(05);c:\program files\common files\epson\epw!3 ssrp\E_JT50RP.EXE [2012-2-26 130944]

R2 EpsonCustomerParticipation;EpsonCustomerParticipation;c:\program files\epson\epsoncustomerparticipation\EPCP.exe [2011-6-9 521600]

R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-15 21504]

R2 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe -service --> c:\windows\system32\lxdicoms.exe -service [?]

R2 N360;Norton Security Suite;c:\program files\norton security suite\norton security suite\engine\6.4.0.9\ccsvchst.exe [2012-10-9 138272]

R2 OpenCASE Media Agent;OpenCASE Media Agent;c:\program files\opencase\opencase media agent\MediaAgent.exe [2008-3-17 765576]

R2 pcCMService;pcCMService;c:\program files\common files\motive\pcCMService.exe [2012-5-31 368640]

R2 pcServiceHost;pcServiceHost;c:\program files\common files\motive\pcServiceHost.exe [2012-6-22 342016]

R2 SamsungAllShareV2.0;Samsung AllShare PC;c:\program files\samsung\allshare\allsharedms\AllShareDMS.exe [2011-7-16 24992]

R2 WXRSS;TVTonic RSS;c:\program files\wavexpress\tvtonic\WXRSS.exe [2008-8-2 142336]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2013-1-15 106656]

R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2013-1-16 40776]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 IDVaultSvc;CGPS Service;c:\program files\constant guard protection suite\IDVaultSvc.exe [2012-10-16 61552]

S3 AllShare;SAMSUNG AllShare Service;c:\program files\samsung\samsung pc share manager\WiselinkPro.exe [2010-7-16 6638080]

S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2012-6-6 39272]

S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840]

S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\microsoft fix it center\Matsvc.exe [2011-6-13 267568]

S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2007-6-20 17920]

S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2007-1-23 7680]

S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2007-5-7 42112]

S3 PCDSRVC{E9D79540-57D5953E-06020200}_0;PCDSRVC{E9D79540-57D5953E-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [2012-8-17 22640]

S3 SimpleSlideShowServer;SimpleSlideShowServer;c:\program files\samsung\allshare\AllShareSlideShowService.exe [2011-7-16 27584]

S3 WaveATSC;Lumanate Wave NTSC/ATSC Combo Device;c:\windows\system32\drivers\WaveATSC.sys [2007-9-4 441600]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]

.

=============== Created Last 30 ================

.

2013-01-17 01:47:22 40776 -c--a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2013-01-15 19:34:44 -------- dc--a-w- c:\users\kearbear\appdata\local\{242130AA-AF78-4095-9810-266AED1DDB99}

2013-01-15 07:09:11 6812136 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{b1ced686-1122-41ef-8c7d-db0b538cf239}\mpengine.dll

2013-01-14 17:59:35 94112 -c--a-w- c:\windows\system32\WindowsAccessBridge.dll

2013-01-13 09:55:05 -------- dcsh--w- C:\$RECYCLE.BIN

2013-01-13 09:42:10 -------- dc----w- c:\program files\Microsoft ATS

2013-01-13 08:55:30 -------- dc----w- c:\windows\MATS

2013-01-13 08:55:24 -------- dc----w- c:\program files\Microsoft Fix it Center

2013-01-09 18:03:32 2048000 -c--a-w- c:\windows\system32\win32k.sys

2013-01-09 18:02:26 204288 -c--a-w- c:\windows\system32\ncrypt.dll

2013-01-09 17:53:48 1400832 -c--a-w- c:\windows\system32\msxml6.dll

2013-01-01 20:42:24 -------- dc----w- c:\users\kearbear\appdata\local\{5765F828-7E0A-4DCC-9173-4FEFF71087EE}

2012-12-22 01:39:43 -------- dc--a-w- c:\users\kearbear\appdata\local\{5B418265-DBFB-41D9-AC14-CEA01421BDEA}

2012-12-20 23:26:18 34304 -c--a-w- c:\windows\system32\atmlib.dll

2012-12-20 23:26:18 293376 -c--a-w- c:\windows\system32\atmfd.dll

2012-12-20 13:03:15 -------- dc----w- c:\users\kearbear\appdata\local\{A18CAC8A-D3C9-45A1-A3FB-E3DF58528FDE}

2012-12-20 11:19:44 7450888 -c--a-w- c:\program files\common files\windows live\.cache\d6aab6801cddea302\bingbarsetup.exe

2012-12-20 11:18:43 15712 -c--a-w- c:\program files\common files\windows live\.cache\c50336501cddea301\MeshBetaRemover.exe

2012-12-20 09:16:57 -------- dc----w- c:\users\kearbear\appdata\local\{43039300-2920-4E63-9633-152AD63C48BA}

2012-12-18 14:28:14 186584 -c--a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll

2012-12-18 14:28:14 186584 -c--a-w- c:\program files\internet explorer\plugins\nppdf32.dll

.

==================== Find3M ====================

.

2013-01-09 03:06:25 697864 -c--a-w- c:\windows\system32\FlashPlayerApp.exe

2013-01-09 03:06:24 74248 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-12-14 21:49:28 21104 -c--a-w- c:\windows\system32\drivers\mbam.sys

2012-11-14 02:09:22 1800704 -c--a-w- c:\windows\system32\jscript9.dll

2012-11-14 01:58:15 1427968 -c--a-w- c:\windows\system32\inetcpl.cpl

2012-11-14 01:57:37 1129472 -c--a-w- c:\windows\system32\wininet.dll

2012-11-14 01:49:25 142848 -c--a-w- c:\windows\system32\ieUnatt.exe

2012-11-14 01:48:27 420864 -c--a-w- c:\windows\system32\vbscript.dll

2012-11-14 01:44:42 2382848 -c--a-w- c:\windows\system32\mshtml.tlb

2012-11-13 01:29:51 2048 -c--a-w- c:\windows\system32\tzres.dll

2012-11-02 10:18:17 376320 -c--a-w- c:\windows\system32\dpnet.dll

2012-11-02 08:26:06 23040 -c--a-w- c:\windows\system32\dpnsvr.exe

2012-10-27 01:56:48 821736 -c--a-w- c:\windows\system32\npdeployJava1.dll

2012-10-27 01:56:47 746984 -c--a-w- c:\windows\system32\deployJava1.dll

.

============= FINISH: 20:58:55.62 ===============

Link to post
Share on other sites

Sorry about that.

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2012-11-20.01)

.

Microsoft® Windows Vista™ Home Premium

Boot Device: \Device\HarddiskVolume3

Install Date: 9/4/2007 2:04:04 AM

System Uptime: 1/16/2013 8:13:40 PM (0 hours ago)

.

Motherboard: Dell Inc. | | 0RT951

Processor: AMD Turion 64 X2 Mobile Technology TL-56 | Microprocessor | 1800/100mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 136 GiB total, 11.895 GiB free.

D: is FIXED (NTFS) - 10 GiB total, 5.632 GiB free.

E: is CDROM ()

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

.

==== Installed Programs ======================

.

Update for Microsoft Office 2007 (KB2508958)

7-Zip 9.22beta

ABBYY FineReader 6.0 Sprint

ABBYY FineReader 9.0 Sprint

Acrobat.com

Actiontec Gateway

Adobe AIR

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Media Player

Adobe Reader X (10.1.5)

Adobe Shockwave Player 11.6

Advanced Audio FX Engine

Advanced Video FX Engine

Amazon Kindle

Amazon Unbox Video

ArcSoft MediaConverter 2

ArcSoft MediaConverter 7

ArtistScope Plugin FX 42

ATI PCI Express (3GIO) Filter Driver

Auto Care

AVerMedia MCE Encoder x86 3.0.1.0

AVS Update Manager 1.0

AVS Video Converter 6

AVS Video Converter 8

AVS4YOU Software Navigator 1.4

Banctec Service Agreement

BitTorrent

Bonjour

Boxee

Broadcom 440x 10/100 Integrated Controller

Broadcom Management Programs

Catalyst Control Center Localization Chinese Standard

Catalyst Control Center Localization Chinese Traditional

Catalyst Control Center Localization Dutch

Catalyst Control Center Localization Finnish

Catalyst Control Center Localization French

Catalyst Control Center Localization German

Catalyst Control Center Localization Italian

Catalyst Control Center Localization Japanese

Catalyst Control Center Localization Korean

Catalyst Control Center Localization Norwegian

Catalyst Control Center Localization Portuguese

Catalyst Control Center Localization Russian

Catalyst Control Center Localization Spanish

Catalyst Control Center Localization Swedish

ccc-Branding

ccc-core-static

CCC Help Chinese Standard

CCC Help Chinese Traditional

CCC Help Danish

CCC Help Dutch

CCC Help English

CCC Help Finnish

CCC Help French

CCC Help German

CCC Help Italian

CCC Help Japanese

CCC Help Korean

CCC Help Norwegian

CCC Help Portuguese

CCC Help Russian

CCC Help Spanish

CCC Help Swedish

CCleaner

Cisco Connect

Client ActiveX Components

CNET TechTracker

Combined Community Codec Pack 2008-09-21 16:18

Comcast Access

Conexant HDA D330 MDC V.92 Modem

Constant Guard Protection Suite

D3DX10

Dell DataSafe Online

Dell Driver Download Manager

Dell Remote Access

Dell Support Center

Dell System Customization Wizard

Dell Touchpad

DELL Webcam Center

DELL Webcam Manager

Dell Wireless WLAN Card

Dell WUSB

DellSupport

Digital Line Detect

DING!

DivX Converter

DivX Plus DirectShow Filters

DivX Setup

DivX Version Checker

Double Solitaire 2.00

Driver Detective

EasySolve

eMule

Epson Connect

Epson Customer Participation

Epson Download Navigator

Epson Event Manager

Epson FAX Utility

Epson PC-FAX Driver

EPSON Scan

EPSON WorkForce 545 Series Printer Uninstall

EpsonNet Print

Games, Music, & Photos Launcher

Garmin Communicator Plugin

Garmin POI Loader

Garmin USB Drivers

Garmin WebUpdater

Google Chrome

Google Update Helper

GoToAssist 8.0.0.508

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)

HyperLoad - Mah Jongg

IrfanView (remove only)

Java 7 Update 11

Java Auto Updater

Junk Mail filter update

K-Lite Mega Codec Pack 4.2.5

Laptop Integrated Webcam Driver (1.04.01.1011)

Live! Cam Avatar v1.0

LTCM Client

Malwarebytes Anti-Malware version 1.70.0.1100

Map Button (Windows Live Toolbar)

Maxtor Manager

Media Player Codec Pack 4.0.2

MediaDirect

Mesh Runtime

Messenger Companion

Microsoft .NET Framework 3.5 SP1

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Extended

Microsoft Application Error Reporting

Microsoft Automated Troubleshooting Services Shim

Microsoft Fix it Center

Microsoft Office 2007 Service Pack 3 (SP3)

Microsoft Office Access MUI (English) 2007

Microsoft Office Access Setup Metadata MUI (English) 2007

Microsoft Office Excel MUI (English) 2007

Microsoft Office File Validation Add-In

Microsoft Office Home and Student 2007

Microsoft Office Live Add-in 1.5

Microsoft Office OneNote MUI (English) 2007

Microsoft Office Outlook MUI (English) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office PowerPoint Viewer 2007 (English)

Microsoft Office Professional 2007

Microsoft Office Professional 2007 Trial

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

Microsoft Office Publisher MUI (English) 2007

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office Word MUI (English) 2007

Microsoft Silverlight

Microsoft SkyDrive

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2005 Redistributable - KB2467175

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319

Modem Diagnostic Tool

Move Media Player

MP3 Rocket

MSVCRT

MSXML 4.0 SP2 (KB927978)

MSXML 4.0 SP2 (KB936181)

MSXML 4.0 SP2 (KB941833)

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

Netflix in Windows Media Center

Norton Security Suite

OGA Notifier 2.0.0048.0

OpenCASE Media Agent

OutlookAddinSetup

Picture Package Music Transfer

Pie Auto Updater 1.0

Plex Media Server

PopCap Browser Plugin

Product Documentation Launcher

QuickConnect

QuickSet

RealNetworks - Microsoft Visual C++ 2005 Runtime

RealNetworks - Microsoft Visual C++ 2008 Runtime

RealPlayer

RealUpgrade 1.1

Revo Uninstaller 1.93

Roxio Creator Audio

Roxio Creator BDAV Plugin

Roxio Creator Copy

Roxio Creator Data

Roxio Creator DE

Roxio Creator Tools

Roxio Drag-to-Disc

Roxio Express Labeler

Roxio MyDVD DE

Roxio Update Manager

Samsung AllShare

SAMSUNG PC Share Manager

Security Update for CAPICOM (KB931906)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Security Update for Microsoft .NET Framework 4 Extended (KB2736428)

Security Update for Microsoft .NET Framework 4 Extended (KB2742595)

Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition

Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition

Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition

Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition

Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition

Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition

Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition

Segoe UI

SigmaTel Audio

Singlesnet

SIW version 2011.09.16

Smart Menus (Windows Live Toolbar)

Sonic Activation Module

Sony Picture Utility

Spotify

Starz Play

swMSM

System Checkup 3.3

The Weather Channel App

The Weather Channel Desktop 6

Trillian

TVTonic

Update for 2007 Microsoft Office System (KB967642)

Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

Update for Microsoft Office 2007 Help for Common Features (KB963673)

Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition

Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition

Update for Microsoft Office Access 2007 Help (KB963663)

Update for Microsoft Office Excel 2007 Help (KB963678)

Update for Microsoft Office OneNote 2007 Help (KB963670)

Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition

Update for Microsoft Office Outlook 2007 Help (KB963677)

Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2760586) 32-Bit Edition

Update for Microsoft Office Powerpoint 2007 Help (KB963669)

Update for Microsoft Office Publisher 2007 Help (KB963667)

Update for Microsoft Office Script Editor Help (KB963671)

Update for Microsoft Office Word 2007 Help (KB963665)

URL Assistant

User's Guides

VC80CRTRedist - 8.0.50727.6195

Visual C++ 2008 x86 Runtime - (v9.0.30729)

Visual C++ 2008 x86 Runtime - v9.0.30729.01

Vuze

Web Games Player Plugin

WebPAM

Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)

Windows Live Communications Platform

Windows Live Essentials

Windows Live Family Safety

Windows Live Favorites for Windows Live Toolbar

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Mail

Windows Live Mesh

Windows Live Mesh ActiveX Control for Remote Connections

Windows Live Messenger

Windows Live Messenger Companion Core

Windows Live MIME IFilter

Windows Live Movie Maker

Windows Live OneCare safety scanner

Windows Live Photo Common

Windows Live Photo Gallery

Windows Live PIMT Platform

Windows Live Remote Client

Windows Live Remote Client Resources

Windows Live Remote Service

Windows Live Remote Service Resources

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live Sync

Windows Live Toolbar Extension (Windows Live Toolbar)

Windows Live Toolbar Feed Detector (Windows Live Toolbar)

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

Windows Media Player Firefox Plugin

Windows Resource Kit Tools - SubInAcl.exe

WinRAR 4.01 (32-bit)

Wise Disk Cleaner 6.15

Wise PC Engineer 6.4.2

WLTB Custom Buttons

Wootalyzer!

Xfinity TV Downloads Media Manager 2.1.0.97

Xvid MPEG-4 Video Codec

Zoosk Messenger

Zultrax P2P

.

==== End Of File ===========================

Link to post
Share on other sites

DDS (Ver_2012-11-20.01) - NTFS_x86

Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.11.2

Run by kearbear at 17:46:21 on 2013-01-18

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3453.1381 [GMT -5:00]

.

AV: Norton Security Suite *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Norton Security Suite *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

FW: Norton Security Suite *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

.

============== Running Processes ================

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\Ati2evxx.exe

C:\Windows\system32\Ati2evxx.exe

C:\Windows\system32\SLsvc.exe

C:\Windows\System32\WLTRYSVC.EXE

C:\Windows\System32\bcmwltry.exe

C:\Windows\system32\brsvc01a.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\brss01a.exe

C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Windows\system32\aestsrv.exe

C:\Windows\system32\Dwm.exe

C:\Program Files\ATI\WebPAM\jetty\extra\win32\Wrapper.exe

C:\Windows\Explorer.EXE

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Windows\system32\CSHelper.exe

C:\Program Files\Common Files\Dell\MySQL\bin\mysqld.exe

C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe

C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe

C:\Windows\system32\lxdicoms.exe

C:\Program Files\Maxtor\Sync\SyncServices.exe

C:\Program Files\ATI\WebPAM\_jvm\bin\java.exe

C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\6.4.0.9\ccSvcHst.exe

C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe

C:\Program Files\Comcast\pcTrayApp.exe

C:\Program Files\Epson Software\Event Manager\EEventManager.exe

C:\Program Files\Norton Security Suite\Norton Security Suite\Engine\6.4.0.9\ccSvcHst.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Constant Guard Protection Suite\IDVault.exe

C:\Program Files\Digital Line Detect\DLG.exe

C:\Program Files\Dell\QuickSet\quickset.exe

C:\Program Files\Southwest Airlines\Ding\Ding.exe

C:\Program Files\Common Files\Motive\pcCMService.exe

C:\Program Files\Common Files\Motive\pcServiceHost.exe

C:\Windows\system32\STacSV.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\Wavexpress\TVTonic\WXRSS.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\DRIVERS\xaudio.exe

C:\Program Files\Common Files\Dell\apache\bin\httpd.exe

C:\Program Files\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe

C:\Program Files\Common Files\Dell\apache\bin\httpd.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\System32\alg.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\system32\UI0Detect.exe

C:\Windows\system32\DllHost.exe

C:\Windows\ehome\ehsched.exe

C:\Windows\ehome\ehRecvr.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Mozilla Firefox\plugin-container.exe

C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe

C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe

C:\Windows\System32\calc.exe

C:\Users\kearbear\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k rpcss

C:\Windows\System32\svchost.exe -k secsvcs

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k WerSvcGroup

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.google.com/

uWindow Title = Windows Internet Explorer provided by Qwest

uDefault_Page_URL = hxxp://qwest.live.com

mStart Page = hxxp://qwest.live.com

mDefault_Page_URL = hxxp://qwest.live.com

BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>

BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll

BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\program files\norton security suite\norton security suite\engine\6.4.0.9\coieplg.dll

BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - c:\program files\norton security suite\norton security suite\engine\6.4.0.9\ips\ipsbho.dll

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll

BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll

BHO: Constant Guard Protection Suite: {B84CDBE7-1B46-494B-A188-01D4C52DEB61} - c:\programdata\white sky, inc\id vault\iebho1.12.1012.1\NativeBHO.dll

BHO: CBrowserHelperObject Object: {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\program files\bae\BAE.dll

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll

TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\program files\norton security suite\norton security suite\engine\6.4.0.9\coieplg.dll

mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [LTCM Client] c:\program files\ltcm client\ltcmClient.exe /startup

mRun: [Comcast_McciTrayApp] "c:\program files\comcast\pcTrayApp.exe"

mRun: [EEventManager] "c:\program files\epson software\event manager\EEventManager.exe"

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [iSUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup

StartupFolder: c:\users\kearbear\appdata\roaming\micros~1\windows\startm~1\programs\startup\ding!.lnk - c:\program files\southwest airlines\ding\Ding.exe

StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\consta~1.lnk - c:\program files\constant guard protection suite\IDVault.exe

StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe

StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe

mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0

mPolicies-System: EnableUIADesktopToggle = dword:0

IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000

IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

.

INFO: HKCU has more than 50 listed domains.

If you wish to scan all of them, select the 'Force scan all domains' option.

.

DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB

DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} - hxxp://www.infospace.com/mypoints.main/tbar/mypointsSetup.exe

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab

TCP: NameServer = 192.168.15.1 192.168.1.1

TCP: Interfaces\{A45A3AFA-B775-453B-885D-48AF076411EC} : DHCPNameServer = 192.168.15.1 192.168.1.1

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll

Notify: GoToAssist - c:\program files\citrix\gotoassist\508\G2AWinLogon.dll

LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\users\kearbear\appdata\roaming\mozilla\firefox\profiles\m38zcixh.default\

FF - prefs.js: browser.search.selectedEngine - Bing

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z192&form=ZGAADF&install_date=20111011&q=

FF - prefs.js: network.proxy.type - 0

FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll

FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll

FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll

FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll

FF - component: c:\users\kearbear\appdata\roaming\mozilla\firefox\profiles\m38zcixh.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCoreGecko19.dll

FF - component: c:\users\kearbear\appdata\roaming\mozilla\firefox\profiles\m38zcixh.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll

FF - plugin: c:\progra~1\meadco~1\npmeadax.dll

FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll

FF - plugin: c:\program files\common files\motive\npMotive.dll

FF - plugin: c:\program files\common files\motive\npMotiveRequest.dll

FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll

FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll

FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll

FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll

FF - plugin: c:\program files\microsoft silverlight\5.1.10516.0\npctrlui.dll

FF - plugin: c:\program files\microsoft\office live\npOLW.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npArtistScope42.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll

FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll

FF - plugin: c:\program files\mozilla firefox\plugins\nppopcaploader.dll

FF - plugin: c:\program files\mozilla firefox\plugins\nprpplugin.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npzylomgamesplayer.dll

FF - plugin: c:\program files\real\realplayer\netscape6\nprpplugin.dll

FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll

FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll

FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll

FF - plugin: c:\programdata\zylom\zylomgamesplayer\npzylomgamesplayer.dll

FF - plugin: c:\users\kearbear\appdata\local\google\update\1.3.21.123\npGoogleUpdate3.dll

FF - plugin: c:\users\kearbear\appdata\roaming\move networks\plugins\npqmp071706000001.dll

FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_270.dll

FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_146.dll

FF - ExtSQL: 2012-12-09 16:34; {c71ff04d-f001-1fc1-1fc1-c71ff04df001}; c:\users\kearbear\appdata\roaming\mozilla\firefox\profiles\m38zcixh.default\extensions\{c71ff04d-f001-1fc1-1fc1-c71ff04df001}.xpi

FF - ExtSQL: 2013-01-12 11:31; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.0.0.145\coFFPlgn

FF - ExtSQL: !HIDDEN! 2009-07-01 22:33; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension

.

---- FIREFOX POLICIES ----

FF - user.js: google.toolbar.linkdoctor.enabled - false

.

============= SERVICES / DRIVERS ===============

.

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0604000.009\symds.sys [2012-10-9 340088]

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0604000.009\symefa.sys [2012-10-9 924320]

R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.0.0.145\definitions\bashdefs\20130111.001\BHDrvx86.sys [2013-1-15 995488]

R1 ccSet_N360;Norton Security Suite Settings Manager;c:\windows\system32\drivers\n360\0604000.009\ccsetx86.sys [2012-10-9 132768]

R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_6.0.0.145\definitions\ipsdefs\20130117.001\IDSvix86.sys [2013-1-18 386720]

R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0604000.009\ironx86.sys [2012-10-9 149624]

R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0604000.009\symtdiv.sys [2012-10-9 345208]

R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\common files\abbyy\finereadersprint\9.00\licensing\NetworkLicenseServer.exe [2009-5-14 759048]

R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2011-8-20 73728]

R2 Apache2.2;Remote Access Media Server;c:\program files\common files\dell\apache\bin\httpd.exe [2007-9-21 15872]

R2 ATIWebPAM;ATI WebPAM;c:\program files\ati\webpam\jetty\extra\win32\Wrapper.exe [2003-9-29 110592]

R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [2009-2-6 266240]

R2 dsl-db;Remote Access DB;c:\program files\common files\dell\mysql\bin\mysqld.exe [2007-9-14 5730304]

R2 dsl-fs-sync;Remote Access File Sync Service;c:\program files\common files\dell\remote access file sync service\dsl_fs_sync.exe [2009-4-13 189680]

R2 EpsonCustomerParticipation;EpsonCustomerParticipation;c:\program files\epson\epsoncustomerparticipation\EPCP.exe [2011-6-9 521600]

R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-15 21504]

R2 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe -service --> c:\windows\system32\lxdicoms.exe -service [?]

R2 N360;Norton Security Suite;c:\program files\norton security suite\norton security suite\engine\6.4.0.9\ccsvchst.exe [2012-10-9 138272]

R2 OpenCASE Media Agent;OpenCASE Media Agent;c:\program files\opencase\opencase media agent\MediaAgent.exe [2008-3-17 765576]

R2 pcCMService;pcCMService;c:\program files\common files\motive\pcCMService.exe [2012-5-31 368640]

R2 pcServiceHost;pcServiceHost;c:\program files\common files\motive\pcServiceHost.exe [2012-6-22 342016]

R2 WXRSS;TVTonic RSS;c:\program files\wavexpress\tvtonic\WXRSS.exe [2008-8-2 142336]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 IDVaultSvc;CGPS Service;c:\program files\constant guard protection suite\IDVaultSvc.exe [2012-10-16 61552]

S2 SamsungAllShareV2.0;Samsung AllShare PC;c:\program files\samsung\allshare\allsharedms\AllShareDMS.exe [2011-7-16 24992]

S3 AllShare;SAMSUNG AllShare Service;c:\program files\samsung\samsung pc share manager\WiselinkPro.exe [2010-7-16 6638080]

S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2012-6-6 39272]

S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840]

S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\microsoft fix it center\Matsvc.exe [2011-6-13 267568]

S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2007-6-20 17920]

S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2007-1-23 7680]

S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2007-5-7 42112]

S3 PCDSRVC{E9D79540-57D5953E-06020200}_0;PCDSRVC{E9D79540-57D5953E-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [2012-8-17 22640]

S3 SimpleSlideShowServer;SimpleSlideShowServer;c:\program files\samsung\allshare\AllShareSlideShowService.exe [2011-7-16 27584]

S3 WaveATSC;Lumanate Wave NTSC/ATSC Combo Device;c:\windows\system32\drivers\WaveATSC.sys [2007-9-4 441600]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]

.

=============== Created Last 30 ================

.

2013-01-18 20:55:54 -------- dc----w- c:\windows\system32\MpEngineStore

2013-01-18 01:40:23 81408 -c--a-w- c:\windows\system32\E_TD4BHWA.DLL

2013-01-15 19:34:44 -------- dc--a-w- c:\users\kearbear\appdata\local\{242130AA-AF78-4095-9810-266AED1DDB99}

2013-01-15 07:09:11 6812136 ------w- c:\programdata\microsoft\windows defender\definition updates\{b1ced686-1122-41ef-8c7d-db0b538cf239}\mpengine.dll

2013-01-14 17:59:35 94112 -c--a-w- c:\windows\system32\WindowsAccessBridge.dll

2013-01-13 09:55:05 -------- dcsh--w- C:\$RECYCLE.BIN

2013-01-13 09:42:10 -------- dc----w- c:\program files\Microsoft ATS

2013-01-13 08:55:30 -------- dc----w- c:\windows\MATS

2013-01-13 08:55:24 -------- dc----w- c:\program files\Microsoft Fix it Center

2013-01-09 18:03:32 2048000 -c--a-w- c:\windows\system32\win32k.sys

2013-01-09 18:02:26 204288 -c--a-w- c:\windows\system32\ncrypt.dll

2013-01-09 17:53:48 1400832 -c--a-w- c:\windows\system32\msxml6.dll

2013-01-01 20:42:24 -------- dc----w- c:\users\kearbear\appdata\local\{5765F828-7E0A-4DCC-9173-4FEFF71087EE}

2012-12-22 01:39:43 -------- dc--a-w- c:\users\kearbear\appdata\local\{5B418265-DBFB-41D9-AC14-CEA01421BDEA}

2012-12-20 23:26:18 34304 -c--a-w- c:\windows\system32\atmlib.dll

2012-12-20 23:26:18 293376 -c--a-w- c:\windows\system32\atmfd.dll

2012-12-20 13:03:15 -------- dc----w- c:\users\kearbear\appdata\local\{A18CAC8A-D3C9-45A1-A3FB-E3DF58528FDE}

2012-12-20 11:19:44 7450888 -c--a-w- c:\program files\common files\windows live\.cache\d6aab6801cddea302\bingbarsetup.exe

2012-12-20 11:18:43 15712 -c--a-w- c:\program files\common files\windows live\.cache\c50336501cddea301\MeshBetaRemover.exe

2012-12-20 09:16:57 -------- dc----w- c:\users\kearbear\appdata\local\{43039300-2920-4E63-9633-152AD63C48BA}

.

==================== Find3M ====================

.

2013-01-18 01:36:48 95232 -c--a-w- c:\windows\system32\E_TLBHWA.DLL

2013-01-09 03:06:25 697864 -c--a-w- c:\windows\system32\FlashPlayerApp.exe

2013-01-09 03:06:24 74248 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-12-14 21:49:28 21104 -c--a-w- c:\windows\system32\drivers\mbam.sys

2012-11-14 02:09:22 1800704 -c--a-w- c:\windows\system32\jscript9.dll

2012-11-14 01:58:15 1427968 -c--a-w- c:\windows\system32\inetcpl.cpl

2012-11-14 01:57:37 1129472 -c--a-w- c:\windows\system32\wininet.dll

2012-11-14 01:49:25 142848 -c--a-w- c:\windows\system32\ieUnatt.exe

2012-11-14 01:48:27 420864 -c--a-w- c:\windows\system32\vbscript.dll

2012-11-14 01:44:42 2382848 -c--a-w- c:\windows\system32\mshtml.tlb

2012-11-13 01:29:51 2048 -c--a-w- c:\windows\system32\tzres.dll

2012-11-02 10:18:17 376320 -c--a-w- c:\windows\system32\dpnet.dll

2012-11-02 08:26:06 23040 -c--a-w- c:\windows\system32\dpnsvr.exe

2012-10-27 01:56:48 821736 -c--a-w- c:\windows\system32\npdeployJava1.dll

2012-10-27 01:56:47 746984 -c--a-w- c:\windows\system32\deployJava1.dll

.

============= FINISH: 17:48:44.80 ===============

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2012-11-20.01)

.

Microsoft® Windows Vista™ Home Premium

Boot Device: \Device\HarddiskVolume3

Install Date: 9/4/2007 2:04:04 AM

System Uptime: 1/18/2013 4:17:52 PM (1 hours ago)

.

Motherboard: Dell Inc. | | 0RT951

Processor: AMD Turion 64 X2 Mobile Technology TL-56 | Microprocessor | 1800/100mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 136 GiB total, 17.941 GiB free.

D: is FIXED (NTFS) - 10 GiB total, 5.632 GiB free.

E: is CDROM ()

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

.

==== Installed Programs ======================

.

Update for Microsoft Office 2007 (KB2508958)

7-Zip 9.22beta

ABBYY FineReader 6.0 Sprint

ABBYY FineReader 9.0 Sprint

Acrobat.com

Actiontec Gateway

Adobe AIR

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Media Player

Adobe Reader X (10.1.5)

Adobe Shockwave Player 11.6

Advanced Audio FX Engine

Advanced Video FX Engine

Amazon Kindle

Amazon Unbox Video

ArcSoft MediaConverter 2

ArcSoft MediaConverter 7

ArtistScope Plugin FX 42

ATI PCI Express (3GIO) Filter Driver

Auto Care

AVerMedia MCE Encoder x86 3.0.1.0

AVS Update Manager 1.0

AVS Video Converter 6

AVS Video Converter 8

AVS4YOU Software Navigator 1.4

Banctec Service Agreement

Bonjour

Broadcom 440x 10/100 Integrated Controller

Broadcom Management Programs

Catalyst Control Center Localization Chinese Standard

Catalyst Control Center Localization Chinese Traditional

Catalyst Control Center Localization Dutch

Catalyst Control Center Localization Finnish

Catalyst Control Center Localization French

Catalyst Control Center Localization German

Catalyst Control Center Localization Italian

Catalyst Control Center Localization Japanese

Catalyst Control Center Localization Korean

Catalyst Control Center Localization Norwegian

Catalyst Control Center Localization Portuguese

Catalyst Control Center Localization Russian

Catalyst Control Center Localization Spanish

Catalyst Control Center Localization Swedish

ccc-Branding

ccc-core-static

CCC Help Chinese Standard

CCC Help Chinese Traditional

CCC Help Danish

CCC Help Dutch

CCC Help English

CCC Help Finnish

CCC Help French

CCC Help German

CCC Help Italian

CCC Help Japanese

CCC Help Korean

CCC Help Norwegian

CCC Help Portuguese

CCC Help Russian

CCC Help Spanish

CCC Help Swedish

CCleaner

Cisco Connect

Client ActiveX Components

CNET TechTracker

Combined Community Codec Pack 2008-09-21 16:18

Comcast Access

Conexant HDA D330 MDC V.92 Modem

Constant Guard Protection Suite

D3DX10

Dell DataSafe Online

Dell Driver Download Manager

Dell Remote Access

Dell Support Center

Dell System Customization Wizard

Dell Touchpad

DELL Webcam Center

DELL Webcam Manager

Dell Wireless WLAN Card

Dell WUSB

DellSupport

Digital Line Detect

DING!

DivX Converter

DivX Plus DirectShow Filters

DivX Setup

DivX Version Checker

Double Solitaire 2.00

Driver Detective

EasySolve

Epson Connect

Epson Customer Participation

Epson Download Navigator

Epson Event Manager

Epson FAX Utility

Epson PC-FAX Driver

EPSON Scan

EPSON WorkForce 545 Series Printer Uninstall

EpsonNet Print

Games, Music, & Photos Launcher

Garmin Communicator Plugin

Garmin POI Loader

Garmin USB Drivers

Garmin WebUpdater

Google Chrome

Google Update Helper

GoToAssist 8.0.0.508

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)

HyperLoad - Mah Jongg

IrfanView (remove only)

Java 7 Update 11

Java Auto Updater

Junk Mail filter update

K-Lite Mega Codec Pack 4.2.5

Laptop Integrated Webcam Driver (1.04.01.1011)

Live! Cam Avatar v1.0

LTCM Client

Malwarebytes Anti-Malware version 1.70.0.1100

Map Button (Windows Live Toolbar)

Maxtor Manager

Media Player Codec Pack 4.0.2

MediaDirect

Mesh Runtime

Messenger Companion

Microsoft .NET Framework 3.5 SP1

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Extended

Microsoft Application Error Reporting

Microsoft Automated Troubleshooting Services Shim

Microsoft Fix it Center

Microsoft Office 2007 Service Pack 3 (SP3)

Microsoft Office Access MUI (English) 2007

Microsoft Office Access Setup Metadata MUI (English) 2007

Microsoft Office Excel MUI (English) 2007

Microsoft Office File Validation Add-In

Microsoft Office Home and Student 2007

Microsoft Office Live Add-in 1.5

Microsoft Office OneNote MUI (English) 2007

Microsoft Office Outlook MUI (English) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office PowerPoint Viewer 2007 (English)

Microsoft Office Professional 2007

Microsoft Office Professional 2007 Trial

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

Microsoft Office Publisher MUI (English) 2007

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office Word MUI (English) 2007

Microsoft Silverlight

Microsoft SkyDrive

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2005 Redistributable - KB2467175

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319

Modem Diagnostic Tool

Move Media Player

Mozilla Firefox 14.0 (x86 en-US)

Mozilla Maintenance Service

MSVCRT

MSXML 4.0 SP2 (KB927978)

MSXML 4.0 SP2 (KB936181)

MSXML 4.0 SP2 (KB941833)

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

Netflix in Windows Media Center

Norton Security Suite

OGA Notifier 2.0.0048.0

OpenCASE Media Agent

OutlookAddinSetup

Picture Package Music Transfer

Pie Auto Updater 1.0

Plex Media Server

PopCap Browser Plugin

Product Documentation Launcher

QuickConnect

QuickSet

RealNetworks - Microsoft Visual C++ 2005 Runtime

RealNetworks - Microsoft Visual C++ 2008 Runtime

RealPlayer

RealUpgrade 1.1

Revo Uninstaller 1.93

Roxio Creator Audio

Roxio Creator BDAV Plugin

Roxio Creator Copy

Roxio Creator Data

Roxio Creator DE

Roxio Creator Tools

Roxio Drag-to-Disc

Roxio Express Labeler

Roxio MyDVD DE

Roxio Update Manager

Samsung AllShare

SAMSUNG PC Share Manager

Security Update for CAPICOM (KB931906)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Security Update for Microsoft .NET Framework 4 Extended (KB2736428)

Security Update for Microsoft .NET Framework 4 Extended (KB2742595)

Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition

Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition

Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition

Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition

Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition

Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition

Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition

Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition

Segoe UI

SigmaTel Audio

Singlesnet

SIW version 2011.09.16

Smart Menus (Windows Live Toolbar)

Sonic Activation Module

Sony Picture Utility

Spotify

Starz Play

swMSM

System Checkup 3.3

The Weather Channel App

The Weather Channel Desktop 6

Trillian

TVTonic

Update for 2007 Microsoft Office System (KB967642)

Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

Update for Microsoft Office 2007 Help for Common Features (KB963673)

Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition

Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition

Update for Microsoft Office Access 2007 Help (KB963663)

Update for Microsoft Office Excel 2007 Help (KB963678)

Update for Microsoft Office OneNote 2007 Help (KB963670)

Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition

Update for Microsoft Office Outlook 2007 Help (KB963677)

Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2760586) 32-Bit Edition

Update for Microsoft Office Powerpoint 2007 Help (KB963669)

Update for Microsoft Office Publisher 2007 Help (KB963667)

Update for Microsoft Office Script Editor Help (KB963671)

Update for Microsoft Office Word 2007 Help (KB963665)

URL Assistant

User's Guides

VC80CRTRedist - 8.0.50727.6195

Visual C++ 2008 x86 Runtime - (v9.0.30729)

Visual C++ 2008 x86 Runtime - v9.0.30729.01

Web Games Player Plugin

WebPAM

Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)

Windows Live Communications Platform

Windows Live Essentials

Windows Live Family Safety

Windows Live Favorites for Windows Live Toolbar

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Mail

Windows Live Mesh

Windows Live Mesh ActiveX Control for Remote Connections

Windows Live Messenger

Windows Live Messenger Companion Core

Windows Live MIME IFilter

Windows Live Movie Maker

Windows Live OneCare safety scanner

Windows Live Photo Common

Windows Live Photo Gallery

Windows Live PIMT Platform

Windows Live Remote Client

Windows Live Remote Client Resources

Windows Live Remote Service

Windows Live Remote Service Resources

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live Sync

Windows Live Toolbar Extension (Windows Live Toolbar)

Windows Live Toolbar Feed Detector (Windows Live Toolbar)

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

Windows Media Player Firefox Plugin

Windows Resource Kit Tools - SubInAcl.exe

Wise Disk Cleaner 6.15

Wise PC Engineer 6.4.2

WLTB Custom Buttons

Wootalyzer!

Xfinity TV Downloads Media Manager 2.1.0.97

Xvid MPEG-4 Video Codec

Zoosk Messenger

.

==== End Of File ===========================

Link to post
Share on other sites

Step 1

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Step 2

Please do the following in Normal mode instead of Safe mode:

  • Launch Malwarebytes' Anti-Malware
  • Go to Update tab and select Check for Updates. If an update is found, it will download and install the latest version.
  • Go to Scanner tab and select Perform Quick Scan, then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer,please do so immediately.

In your next reply, post the following log files:

  • Junkware Removal Tool log
  • Malwarebytes' Anti-Malware log

Link to post
Share on other sites

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu

Version: 4.4.4 (01.17.2013:1)

OS: Windows Vista Home Premium x86

Ran by kearbear on Fri 01/18/2013 at 18:36:31.03

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~ Services

~~~ Registry Values

Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\toolbar\webbrowser\\{ba14329e-9550-4989-b3f2-9732e92d17cc}

~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_current_user\software\conduit

Successfully deleted: [Registry Key] hkey_local_machine\software\freeze.com

Successfully deleted: [Registry Key] hkey_current_user\software\zugo

Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\fun web products

Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\lowregistry\dealio

Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478d38-c3f9-4efb-9b51-7695eca05670}

Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{112a7e09-6595-d1c3-2c4e-cdfd9e56b66c}

Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{171debeb-c3d4-40b7-ac73-056a5eba4a7e}

Successfully deleted: [Registry Key] hkey_classes_root\clsid\{9afb8248-617f-460d-9366-d71cdeda3179}

Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{afbcb7e0-f91a-4951-9f31-58fee57a25c4}

Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{afbcb7e0-f91a-4951-9f31-58fee57a25c4}

~~~ Files

Successfully deleted: [File] "C:\Program Files\mozilla firefox\plugins\npmozcouponprinter.dll"

~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"

Successfully deleted: [Folder] "C:\ProgramData\trymedia"

Successfully deleted: [Folder] "C:\Users\kearbear\AppData\Roaming\opencandy"

Successfully deleted: [Folder] "C:\Users\kearbear\appdata\local\opencandy"

Successfully deleted: [Folder] "C:\Users\kearbear\appdata\locallow\boost_interprocess"

Successfully deleted: [Folder] "C:\Users\kearbear\appdata\locallow\funwebproducts"

Successfully deleted: [Folder] "C:\Users\kearbear\appdata\locallow\mywebsearch"

Successfully deleted: [Folder] "C:\Users\kearbear\appdata\locallow\shoppingreport"

Successfully deleted: [Folder] "C:\Users\kearbear\appdata\locallow\toolbar4"

Successfully deleted: [Folder] "C:\Users\kearbear\appdata\locallow\vuze_remote"

Successfully deleted: [Folder] "C:\Program Files\trymedia"

Successfully deleted: [Folder] "C:\Program Files\webenhancements"

Successfully deleted: [Folder] "C:\Users\kearbear\appdata\locallow\asktoolbar"

~~~ FireFox

Successfully deleted: [File] "C:\Program Files\Mozilla Firefox\searchplugins\bing.xml.old"

Successfully deleted: [File] C:\Users\kearbear\AppData\Roaming\mozilla\firefox\profiles\m38zcixh.default\user.js

Successfully deleted: [File] C:\Users\kearbear\AppData\Roaming\mozilla\firefox\profiles\m38zcixh.default\searchplugins\bing-zugo.xml

Successfully deleted: [Folder] C:\Users\kearbear\AppData\Roaming\mozilla\firefox\profiles\m38zcixh.default\extensions\engine@conduit.com

Successfully deleted the following from C:\Users\kearbear\AppData\Roaming\mozilla\firefox\profiles\m38zcixh.default\prefs.js

user_pref("CT2504091.AboutPrivacyUrl", "http://www.conduit.com/privacy/Default.aspx");

user_pref("CT2504091.CTID", "CT2504091");

user_pref("CT2504091.CurrentServerDate", "22-11-2010");

user_pref("CT2504091.DialogsAlignMode", "LTR");

user_pref("CT2504091.DownloadReferralCookieData", "");

user_pref("CT2504091.EMailNotifierPollDate", "Sun Nov 21 2010 23:28:12 GMT-0800 (Pacific Standard Time)");

user_pref("CT2504091.FeedLastCount129079840422964131", 10);

user_pref("CT2504091.FeedPollDate128891351169457140", "Sun Nov 21 2010 22:52:50 GMT-0800 (Pacific Standard Time)");

user_pref("CT2504091.FeedPollDate129079840422964131", "Sun Nov 21 2010 22:52:50 GMT-0800 (Pacific Standard Time)");

user_pref("CT2504091.FeedTTL128891351169457140", 40);

user_pref("CT2504091.FirstServerDate", "22-11-2010");

user_pref("CT2504091.FirstTime", true);

user_pref("CT2504091.FirstTimeFF3", true);

user_pref("CT2504091.FirstTimeSettingsDone", true);

user_pref("CT2504091.FixPageNotFoundErrors", true);

user_pref("CT2504091.GroupingServerCheckInterval", 1440);

user_pref("CT2504091.GroupingServiceUrl", "http://grouping.services.conduit.com/");

user_pref("CT2504091.Initialize", true);

user_pref("CT2504091.InitializeCommonPrefs", true);

user_pref("CT2504091.InstallationAndCookieDataSentCount", 3);

user_pref("CT2504091.InstallationType", "UnknownIntegration");

user_pref("CT2504091.InstalledDate", "Sun Nov 21 2010 17:08:16 GMT-0800 (Pacific Standard Time)");

user_pref("CT2504091.IsGrouping", false);

user_pref("CT2504091.IsMulticommunity", false);

user_pref("CT2504091.IsOpenThankYouPage", false);

user_pref("CT2504091.IsOpenUninstallPage", false);

user_pref("CT2504091.LanguagePackLastCheckTime", "Sun Nov 21 2010 17:08:17 GMT-0800 (Pacific Standard Time)");

user_pref("CT2504091.LanguagePackReloadIntervalMM", 1440);

user_pref("CT2504091.LanguagePackServiceUrl", "http://translation.users.conduit.com/Translation.ashx");

user_pref("CT2504091.LastLogin_2.7.2.0", "Sun Nov 21 2010 21:08:18 GMT-0800 (Pacific Standard Time)");

user_pref("CT2504091.LatestVersion", "2.6.0.14");

user_pref("CT2504091.Locale", "en-us");

user_pref("CT2504091.LoginCache", 4);

user_pref("CT2504091.MCDetectTooltipHeight", "83");

user_pref("CT2504091.MCDetectTooltipUrl", "http://@EB_INSTALL_LINK@/rank/tooltip/?version=1");

user_pref("CT2504091.MCDetectTooltipWidth", "295");

user_pref("CT2504091.SearchEngine", "Search||http://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2504091&octid=EB_ORIGINAL_CTID&SearchSource=1");

user_pref("CT2504091.SearchFromAddressBarIsInit", true);

user_pref("CT2504091.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&q=");

user_pref("CT2504091.SearchInNewTabEnabled", true);

user_pref("CT2504091.SearchInNewTabIntervalMM", 1440);

user_pref("CT2504091.SearchInNewTabLastCheckTime", "Sun Nov 21 2010 17:08:22 GMT-0800 (Pacific Standard Time)");

user_pref("CT2504091.SearchInNewTabServiceUrl", "http://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");

user_pref("CT2504091.SearchInNewTabUsageUrl", "http://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");

user_pref("CT2504091.SettingsCheckIntervalMin", 120);

user_pref("CT2504091.SettingsLastCheckTime", "Sun Nov 21 2010 17:08:12 GMT-0800 (Pacific Standard Time)");

user_pref("CT2504091.SettingsLastUpdate", "1289439748");

user_pref("CT2504091.ThirdPartyComponentsInterval", 504);

user_pref("CT2504091.ThirdPartyComponentsLastCheck", "Sun Nov 21 2010 17:08:11 GMT-0800 (Pacific Standard Time)");

user_pref("CT2504091.ThirdPartyComponentsLastUpdate", "1246790578");

user_pref("CT2504091.TrusteLinkUrl", "http://www.truste.org/pvr.php?page=validate&softwareProgramId=101&sealid=112");

user_pref("CT2504091.UserID", "UN33856384783839597");

user_pref("CT2504091.ValidationData_Toolbar", 0);

user_pref("CT2504091.alertChannelId", "897164");

user_pref("CT2504091.clientLogIsEnabled", true);

user_pref("CT2504091.clientLogServiceUrl", "http://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");

user_pref("CT2504091.myStuffEnabled", true);

user_pref("CT2504091.myStuffPublihserMinWidth", 400);

user_pref("CT2504091.myStuffSearchUrl", "http://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");

user_pref("CT2504091.myStuffServiceIntervalMM", 1440);

user_pref("CT2504091.myStuffServiceUrl", "http://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");

user_pref("CT2504091.uninstallLogServiceUrl", "http://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");

user_pref("CommunityToolbar.ETag.http://Translation.engine.conduit-services.com/?browser=FF&lut=5/11/2011 9:23:53 AM&locale=en-US", "\"20de97ad5aab14e190dff9aab4b4ee58\"");

user_pref("CommunityToolbar.ETag.http://alerts.conduit-services.com/?aid=897164&fid=892962", "\"0\"");

user_pref("CommunityToolbar.ETag.http://alerts.conduit-services.com/root/897164/892962/US", "\"0\"");

user_pref("CommunityToolbar.ETag.http://alerts.conduit-services.com/root/909619/905414/US", "\"0\"");

user_pref("CommunityToolbar.ETag.http://contextmenu.app.conduit-services.com/apps/TranslatedApps.ashx?productId=1&name=appContextMenu2.0&locale=en-US", "\"e9038757a98600cb7a03

user_pref("CommunityToolbar.ETag.http://contextmenu.engine.conduit-services.com/apps/TranslatedApps.ashx?productId=1&name=engineContextMenu2.0&locale=en-US", "\"08e4082eeb52d6

user_pref("CommunityToolbar.ETag.http://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"01ffa8b1cc6cb1:0\"");

user_pref("CommunityToolbar.ETag.http://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"807dc126dd28cc1:0\"");

user_pref("CommunityToolbar.ETag.http://settings.engine.conduit-services.com/?browser=FF&lut=0", "634356118310000000");

user_pref("CommunityToolbar.ETag.http://settings.engine.conduit-services.com/?browser=FF&lut=3/13/2011 11:17:11 AM", "634356118310000000");

user_pref("CommunityToolbar.ETag.http://tracking.usage.app.conduit-services.com/FirstTime.ashx?current=True", "\"7802d5901b7483ef7461f4ff82138567\"");

user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");

user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com");

user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");

user_pref("CommunityToolbar.IsEngineShown", true);

user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);

user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");

user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com");

user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");

user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.properties");

user_pref("CommunityToolbar.ToolbarsList", "CT2504091,ConduitEngine");

user_pref("CommunityToolbar.ToolbarsList2", "CT2504091");

user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Sun Mar 27 2011 18:39:59 GMT-0700 (Pacific Daylight Time)");

user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);

user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed Jun 22 2011 11:01:39 GMT-0400 (Eastern Daylight Time)");

user_pref("CommunityToolbar.alert.clientsServerUrl", "http://alert.client.conduit.com");

user_pref("CommunityToolbar.alert.locale", "en");

user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);

user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Jun 22 2011 11:01:22 GMT-0400 (Eastern Daylight Time)");

user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");

user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);

user_pref("CommunityToolbar.alert.servicesServerUrl", "http://alert.services.conduit.com");

user_pref("CommunityToolbar.alert.showTrayIcon", false);

user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);

user_pref("CommunityToolbar.alert.userId", "{0a170333-95f0-43d4-b958-1a41821a6fa5}");

user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);

user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);

user_pref("ConduitEngine.AppTrackingLastCheckTime", "Wed Jun 22 2011 11:01:41 GMT-0400 (Eastern Daylight Time)");

user_pref("ConduitEngine.CTID", "ConduitEngine");

user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Wed Jun 22 2011 11:01:28 GMT-0400 (Eastern Daylight Time)");

user_pref("ConduitEngine.FirstServerDate", "03/28/2011 04");

user_pref("ConduitEngine.FirstTime", true);

user_pref("ConduitEngine.FirstTimeFF3", true);

user_pref("ConduitEngine.HasUserGlobalKeys", true);

user_pref("ConduitEngine.Initialize", true);

user_pref("ConduitEngine.InitializeCommonPrefs", true);

user_pref("ConduitEngine.InstalledDate", "Sun Mar 27 2011 18:38:28 GMT-0700 (Pacific Daylight Time)");

user_pref("ConduitEngine.IsMulticommunity", false);

user_pref("ConduitEngine.IsOpenThankYouPage", false);

user_pref("ConduitEngine.IsOpenUninstallPage", true);

user_pref("ConduitEngine.LanguagePackLastCheckTime", "Wed Jun 22 2011 11:01:28 GMT-0400 (Eastern Daylight Time)");

user_pref("ConduitEngine.LastLogin_3.3.3.2", "Wed Jun 22 2011 17:01:25 GMT-0400 (Eastern Daylight Time)");

user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);

user_pref("ConduitEngine.SettingsLastCheckTime", "Wed Jun 22 2011 17:01:25 GMT-0400 (Eastern Daylight Time)");

user_pref("ConduitEngine.UserID", "UN44541679560265546");

user_pref("ConduitEngine.componentAlertEnabled", false);

user_pref("ConduitEngine.engineLocale", "en-US");

user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Wed Jun 22 2011 11:01:28 GMT-0400 (Eastern Daylight Time)");

user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Wed Jun 22 2011 19:01:22 GMT-0400 (Eastern Daylight Time)");

user_pref("ConduitEngine.initDone", true);

user_pref("ConduitEngine.isAppTrackingManagerOn", true);

user_pref("ConduitEngine.usagesFlag", 2);

user_pref("extensions.adblockpluspopupaddon.rules", "snapdollars.com;1;BLOCK;WINDOWS|redbaronpizzapromo.com;1;BLOCK;WINDOWS|google.com;1;BLOCK;WINDOWS|survey.acnielsenonline.c

user_pref("extensions.enabledItems", "{8545daff-ad1e-493f-a37e-eed1ac79682b}:1.0,{c28e494b-b576-541b-6006-38bc871aff54}:4.6.6.6,{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}:6.0.04,{

user_pref("extensions.engine@conduit.com.install-event-fired", true);

user_pref("extensions.toolbar@ask.com.install-event-fired", true);

user_pref("socialfixer.526174216/cached_content/donate_pagelet", "{\"expires_on\":1345373518932,\"content\":\"<div style=\\\"background-color:#ffffcc;border:1px solid #cccc99;

user_pref("socialfixer.526174216/typeahead_new", "for (;;);{\"__ar\":1,\"payload\":{\"entries\":[{\"uid\":525652128,\"photo\":\"https:\\/\\/fbcdn-profile-a.akamaihd.net\\/hpro

Emptied folder: C:\Users\kearbear\AppData\Roaming\mozilla\firefox\profiles\m38zcixh.default\minidumps [30 files]

~~~ Event Viewer Logs were cleared

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on Fri 01/18/2013 at 18:43:51.97

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Malwarebytes Anti-Malware 1.70.0.1100

www.malwarebytes.org

Database version: v2013.01.18.11

Windows Vista Service Pack 2 x86 NTFS

Internet Explorer 9.0.8112.16421

kearbear :: KEARBEAR-LT [administrator]

1/18/2013 6:48:53 PM

mbam-log-2013-01-18 (18-48-53).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 235935

Time elapsed: 13 minute(s), 1 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

Link to post
Share on other sites

Note: Please do not run this tool without special supervision and instructions of someone authorized to do so. Otherwise, you could end up with serious problems. For more details, read this article: ComboFix usage, Questions, Help? - Look here

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingc...to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please post the C:\ComboFix.txt in your next reply for further review.

Note: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

Link to post
Share on other sites

ComboFix 13-01-17.04 - kearbear 01/19/2013 15:18:39.1.2 - x86

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3453.1624 [GMT -5:00]

Running from: c:\users\kearbear\Downloads\ComboFix.exe

AV: Norton Security Suite *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

FW: Norton Security Suite *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

SP: Norton Security Suite *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\programdata\PCDr\6032\AddOnDownloaded\18d25bc5-acbb-424f-a6c6-d04a97765094.dll

c:\programdata\PCDr\6032\AddOnDownloaded\2141cd58-3a24-481f-8ca2-8b466c9b797f.dll

c:\programdata\PCDr\6032\AddOnDownloaded\2d2ff7e2-f0f8-4f32-a28e-e44234dd3300.dll

c:\programdata\PCDr\6032\AddOnDownloaded\3e137363-345c-454a-a474-2da300d9297a.dll

c:\programdata\PCDr\6032\AddOnDownloaded\65a823a3-a5fc-440a-b276-153555251042.dll

c:\programdata\PCDr\6032\AddOnDownloaded\918ee45c-eb0a-4e61-97ad-c1849c2623ee.dll

c:\programdata\PCDr\6032\AddOnDownloaded\b0654984-096d-4244-a127-3364577b6279.dll

c:\programdata\PCDr\6032\AddOnDownloaded\b967e9c4-897a-42c8-96d2-4ceb543f8cdb.dll

c:\programdata\PCDr\6032\AddOnDownloaded\e3146f6d-11b3-4a00-a026-1ba8b4bb00ff.dll

c:\programdata\PCDr\6032\AddOnDownloaded\ea058b56-dc30-479c-af0f-bcf27aed08df.dll

c:\programdata\PCDr\6032\AddOnDownloaded\f4d48f15-9f33-4b3f-a84f-bc8b2800e772.dll

c:\users\kearbear\AppData\Local\baotznh_nav.dat

c:\users\kearbear\AppData\Local\eyrdejsrqa_nav.dat

c:\users\kearbear\Documents\~WRL0002.tmp

c:\users\kearbear\GoToAssistDownloadHelper.exe

c:\windows\system32\drivers\etc\hosts.ics

c:\windows\system32\SET228B.tmp

c:\windows\system32\spool\prtprocs\w32x86\ppbiPr.dll

c:\windows\wininit.ini

.

.

((((((((((((((((((((((((( Files Created from 2012-12-19 to 2013-01-19 )))))))))))))))))))))))))))))))

.

.

2013-01-19 21:21 . 2013-01-19 21:22 -------- dc----w- c:\users\kearbear\AppData\Local\temp

2013-01-19 21:21 . 2013-01-19 21:21 -------- dc----w- c:\users\RA Media Server\AppData\Local\temp

2013-01-19 21:21 . 2013-01-19 21:21 -------- dc----w- c:\users\Default\AppData\Local\temp

2013-01-19 19:22 . 2013-01-19 19:22 -------- dc--a-w- c:\users\kearbear\AppData\Local\Zemana

2013-01-19 19:20 . 2013-01-06 01:39 25936 -c--a-w- c:\windows\system32\drivers\KeyCrypt32.sys

2013-01-19 19:20 . 2013-01-19 19:20 -------- dc----w- c:\program files\KeyCryptSDK

2013-01-19 19:20 . 2013-01-06 01:39 7369552 -c--a-w- c:\windows\system32\ZALSDKCore.dll

2013-01-19 19:20 . 2013-01-19 19:20 -------- dc----w- c:\windows\system32\ZALSDK_uninst

2013-01-19 19:20 . 2013-01-19 19:20 82320 -c--a-w- c:\windows\system32\drivers\AntiLog32.sys

2013-01-19 01:38 . 2013-01-19 19:49 -------- dc----w- c:\programdata\Xerox

2013-01-19 00:43 . 2013-01-15 07:49 6991832 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CE042A5A-07AC-4D18-B0DC-0FB16CE68D8A}\mpengine.dll

2013-01-18 23:36 . 2013-01-18 23:36 -------- dc----w- c:\windows\ERUNT

2013-01-18 23:35 . 2013-01-18 23:35 -------- dc----w- C:\JRT

2013-01-18 20:55 . 2013-01-18 21:16 -------- dc----w- c:\windows\system32\MpEngineStore

2013-01-18 01:40 . 2013-01-18 01:36 81408 -c--a-w- c:\windows\system32\E_TD4BHWA.DLL

2013-01-14 17:59 . 2013-01-12 08:30 94112 -c--a-w- c:\windows\system32\WindowsAccessBridge.dll

2013-01-13 09:42 . 2013-01-13 09:42 -------- dc----w- c:\program files\Microsoft ATS

2013-01-13 08:55 . 2013-01-13 08:55 -------- dc----w- c:\windows\MATS

2013-01-13 08:55 . 2013-01-13 08:55 -------- dc----w- c:\program files\Microsoft Fix it Center

2013-01-09 18:03 . 2012-11-23 01:35 2048000 -c--a-w- c:\windows\system32\win32k.sys

2013-01-09 18:02 . 2012-11-20 04:22 204288 -c--a-w- c:\windows\system32\ncrypt.dll

2013-01-09 17:53 . 2012-11-02 10:19 1400832 -c--a-w- c:\windows\system32\msxml6.dll

2012-12-20 23:26 . 2012-12-16 13:12 34304 -c--a-w- c:\windows\system32\atmlib.dll

2012-12-20 23:26 . 2012-12-16 10:50 293376 -c--a-w- c:\windows\system32\atmfd.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-01-18 01:36 . 2012-02-26 06:36 95232 -c--a-w- c:\windows\system32\E_TLBHWA.DLL

2013-01-09 03:06 . 2012-03-29 22:25 697864 -c--a-w- c:\windows\system32\FlashPlayerApp.exe

2013-01-09 03:06 . 2011-05-26 20:04 74248 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-12-14 21:49 . 2011-08-23 09:43 21104 -c--a-w- c:\windows\system32\drivers\mbam.sys

2012-11-14 02:09 . 2012-12-12 01:22 1800704 -c--a-w- c:\windows\system32\jscript9.dll

2012-11-14 01:58 . 2012-12-12 01:22 1427968 -c--a-w- c:\windows\system32\inetcpl.cpl

2012-11-14 01:57 . 2012-12-12 01:22 1129472 -c--a-w- c:\windows\system32\wininet.dll

2012-11-14 01:49 . 2012-12-12 01:22 142848 -c--a-w- c:\windows\system32\ieUnatt.exe

2012-11-14 01:48 . 2012-12-12 01:22 420864 -c--a-w- c:\windows\system32\vbscript.dll

2012-11-14 01:44 . 2012-12-12 01:22 2382848 -c--a-w- c:\windows\system32\mshtml.tlb

2012-11-13 01:29 . 2012-12-12 00:23 2048 -c--a-w- c:\windows\system32\tzres.dll

2012-11-02 10:18 . 2012-12-12 00:23 376320 -c--a-w- c:\windows\system32\dpnet.dll

2012-11-02 08:26 . 2012-12-12 00:23 23040 -c--a-w- c:\windows\system32\dpnsvr.exe

2012-10-27 01:56 . 2012-06-18 04:08 821736 -c--a-w- c:\windows\system32\npdeployJava1.dll

2012-10-27 01:56 . 2010-04-17 02:54 746984 -c--a-w- c:\windows\system32\deployJava1.dll

2012-07-10 23:06 . 2013-01-18 22:28 136672 -c--a-w- c:\program files\mozilla firefox\components\browsercomps.dll

2008-06-27 21:59 . 2008-08-20 02:20 163840 -c--a-w- c:\program files\mozilla firefox\components\nsgkff30_meter2.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]

@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"

[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]

2012-09-24 12:19 220608 -c--a-w- c:\users\kearbear\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]

@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"

[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]

2012-09-24 12:19 220608 -c--a-w- c:\users\kearbear\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]

@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"

[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]

2012-09-24 12:19 220608 -c--a-w- c:\users\kearbear\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]

"LTCM Client"="c:\program files\LTCM Client\ltcmClient.exe" [2011-04-07 2756864]

"Comcast_McciTrayApp"="c:\program files\Comcast\pcTrayApp.exe" [2012-06-12 1966592]

"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2010-10-12 979328]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]

"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]

.

c:\users\kearbear\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

DING!.lnk - c:\program files\Southwest Airlines\Ding\Ding.exe [2006-6-22 462848]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Constant Guard.lnk - c:\program files\Constant Guard Protection Suite\IDVault.exe [2013-1-14 3982376]

Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-9-4 50688]

QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2007-7-20 1180952]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\progra~1\KEYCRY~1\KeyCrypt32(1).dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"wave1"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ \0

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

@="Service"

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Dell Remote Access.lnk]

backup=c:\windows\pss\Dell Remote Access.lnk.CommonStartup

backupExtension=.CommonStartup

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Dell Remote Access.lnk

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Ultrawideband Control Center.lnk]

backup=c:\windows\pss\Ultrawideband Control Center.lnk.CommonStartup

backupExtension=.CommonStartup

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Ultrawideband Control Center.lnk

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk

backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup

backupExtension=.CommonStartup

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AllShareAgent]

2011-07-16 15:52 282512 -c--a-w- c:\program files\Samsung\AllShare\AllShareAgent.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]

2007-04-18 03:31 159744 ----a-w- c:\program files\DellTPad\Apoint.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]

2007-03-21 19:33 1548288 ----a-w- c:\windows\System32\WLTRAY.EXE

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]

2011-07-28 23:08 1259376 -c--a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]

2008-01-19 07:33 125952 ----a-w- c:\windows\ehome\ehtray.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]

2006-10-03 16:37 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]

2012-12-14 21:49 824232 -c--a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mxomssmenu]

2008-07-21 23:54 169312 -c--a-w- c:\program files\Maxtor\OneTouch Status\MaxMenuMgr.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEM02Mon.exe]

2007-05-10 09:01 36864 ----a-w- c:\windows\OEM02Mon.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]

2007-08-20 16:58 184320 -c----w- c:\program files\Dell\MediaDirect\PCMService.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pie Auto Updater]

2006-09-28 03:26 77824 -c--a-w- c:\program files\PieAutoUpdater\PieAutoUpdater.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]

2007-09-13 21:44 405504 -c--a-w- c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]

2006-11-10 17:35 90112 -c--a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]

2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=""

"FirewallOverride"=""

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]

"AntiVirusOverride"=dword:00000001

"AntiSpywareOverride"=dword:00000001

.

S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [x]

S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [x]

.

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - ANTILOG32

*NewlyCreated* - KEYCRYPT

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

.

Contents of the 'Scheduled Tasks' folder

.

2013-01-19 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 03:06]

.

2013-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-02 21:53]

.

2013-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-02 21:53]

.

2013-01-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-769808361-2590750930-1259732834-1000Core.job

- c:\users\kearbear\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-30 07:42]

.

2013-01-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-769808361-2590750930-1259732834-1000UA.job

- c:\users\kearbear\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-30 07:42]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

mStart Page = hxxp://qwest.live.com

uInternet Settings,ProxyOverride = *.local;<local>

IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

Trusted Zone: adecco.com\*.xpert

TCP: DhcpNameServer = 192.168.15.1 192.168.1.1

FF - ProfilePath - c:\users\kearbear\AppData\Roaming\Mozilla\Firefox\Profiles\m38zcixh.default\

FF - prefs.js: browser.search.selectedEngine - Bing

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z192&form=ZGAADF&install_date=20111011&q=

FF - prefs.js: network.proxy.type - 0

FF - ExtSQL: 2012-12-09 16:34; {c71ff04d-f001-1fc1-1fc1-c71ff04df001}; c:\users\kearbear\AppData\Roaming\Mozilla\Firefox\Profiles\m38zcixh.default\extensions\{c71ff04d-f001-1fc1-1fc1-c71ff04df001}.xpi

FF - ExtSQL: 2013-01-12 11:31; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\coFFPlgn

FF - ExtSQL: !HIDDEN! 2009-07-01 22:33; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

.

- - - - ORPHANS REMOVED - - - -

.

WebBrowser-{A057A204-BACC-4D26-CEC4-75A487FD6484} - (no file)

Notify-GoToAssist - c:\program files\Citrix\GoToAssist\508\G2AWinLogon.dll

SafeBoot-WudfPf

SafeBoot-WudfRd

MSConfigStartUp-BrMfcWnd - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe

MSConfigStartUp-ControlCenter3 - c:\program files\Brother\ControlCenter3\brctrcen.exe

MSConfigStartUp-dellsupportcenter - c:\program files\Dell Support Center\bin\sprtcmd.exe

MSConfigStartUp-dscactivate - c:\program files\Dell Support Center\gs_agent\custom\dsca.exe

MSConfigStartUp-FaxCenterServer - c:\program files\\Lexmark Fax Solutions\fm3032.exe

MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe

MSConfigStartUp-NortonUpdateAgent - c:\programdata\Norton\NUA.exe

MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe

AddRemove-The Weather Channel Desktop 6 - c:\program files\The Weather Channel FW\Desktop\TheWeatherChannelCustomUninstall.exe

AddRemove-{F46BF5EA-0B4E-4A41-8C4B-3B127346E30F} - c:\users\kearbear\AppData\Local\{2853BFD5-3865-45EB-A4E3-967D4A9B969A}\NBCDirectInstaller.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2013-01-19 16:22

Windows 6.0.6002 Service Pack 2 NTFS

.

scanning hidden processes ...

.

? [31560]

? [42832]

? [52884]

c:\combofix\pev.3XE [63316] 0xB92F0380

? [63636]

? [63644]

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\N360]

"ImagePath"="\"c:\program files\Norton Security Suite\Norton Security Suite\Engine\6.4.0.9\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Norton Security Suite\Engine\6.4.0.9\diMaster.dll\" /prefetch:1"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCD5SRVC{FBEA8B78-1B22F121-05040104}]

"ImagePath"="\??\c:\progra~1\DELLSU~2\HWDiag\bin\PCD5SRVC.pkms"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCDSRVC{E9D79540-57D5953E-06020200}_0]

"ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="YMP.Media"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Microsoft\DbgagD\1*]

"value"="?\09\05\1e\006\13"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

"MSCurrentCountry"=dword:000000b5

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'lsass.exe'(768)

c:\windows\System32\BCMLogon.dll

.

Completion time: 2013-01-19 16:59:16

ComboFix-quarantined-files.txt 2013-01-19 21:59

.

Pre-Run: 18,849,230,848 bytes free

Post-Run: 18,948,374,528 bytes free

.

- - End Of File - - 60493E2A53A01260052A11853318D865

Link to post
Share on other sites

Please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan

  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\ESET\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic

Link to post
Share on other sites

Things are much better thank you. There are still a few issues. Start up is still slow. Not as slow as it was but still takes a little bit to start up. Folders won't stay how I choose them. For example, in My Docs it keeps coming up with Genre Artist, # and Album. I change it to how I like to see it and each time I log back on it's been changed back. Also, some folders are split alphabetically and I'm not sure how to get rid of the lines. For example it would have 0-9, A-H, M-Z. This is not exact but similar.No crashes for a few days now.

Link to post
Share on other sites

  • 2 weeks later...

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.