Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

system errors and bad images [Closed]


  • This topic is locked This topic is locked

#1
Gauze

Gauze

    Member

  • Member
  • PipPip
  • 41 posts
i can't run slui.exe, i can't run disk check or sfc. i can't uninstall the update kb971033.
I started a topic similar to this yesterday but I don't know if it was in the right forum and i didn't post this otl logfile. Sorry.
OTL logfile created on: 7/1/2012 3:21:24 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Shannon\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 2.51 Gb Available Physical Memory | 66.02% Memory free
7.61 Gb Paging File | 6.14 Gb Available in Paging File | 80.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.03 Gb Total Space | 225.91 Gb Free Space | 80.96% Space Free | Partition Type: NTFS
Drive D: | 186.54 Gb Total Space | 170.80 Gb Free Space | 91.56% Space Free | Partition Type: NTFS
Drive E: | 164.85 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: SHANNON-PC | User Name: Shannon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/07/01 15:20:56 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Shannon\Downloads\OTL.exe
PRC - [2012/06/19 17:32:30 | 003,048,136 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012/06/18 17:47:23 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/03/28 17:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
PRC - [2010/03/25 23:06:16 | 000,729,664 | ---- | M] (Symantec Corporation) -- C:\Program Files (x86)\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS\A5E82D02\17.0.0.136\InstStub.exe
PRC - [2010/01/15 08:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009/10/06 02:08:42 | 000,210,216 | ---- | M] (CyberLink) -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/10/01 00:01:32 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/10/01 00:01:30 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/08/24 18:49:41 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
PRC - [2009/07/08 22:55:26 | 000,323,584 | -H-- | M] (DeviceVM, Inc.) -- C:\SPLASH.SYS\config\DVMExportService.exe


========== Modules (No Company Name) ==========

MOD - [2012/06/18 17:47:23 | 002,042,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012/03/21 13:57:07 | 008,527,520 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2012/02/20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/02/20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009/10/06 02:08:38 | 000,931,112 | ---- | M] () -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/10/21 03:35:26 | 000,240,640 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\stacsv64.exe -- (STacSV)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/08 16:49:02 | 000,030,520 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\Windows\SysNative\hpservice.exe -- (hpsrv)
SRV:64bit: - [2009/03/03 06:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\AESTSr64.exe -- (AESTFilters)
SRV - [2012/06/19 17:32:30 | 003,048,136 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/06/18 17:47:23 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/06/07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011/09/09 17:10:28 | 000,086,072 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)
SRV - [2011/03/28 17:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe)
SRV - [2010/11/20 08:21:35 | 000,204,800 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\WebClnt.dll -- (WebClient)
SRV - [2010/11/04 21:52:14 | 000,856,400 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/01/15 08:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/10/21 03:35:26 | 000,240,640 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\STacSV64.exe -- (STacSV)
SRV - [2009/10/01 00:01:32 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel®
SRV - [2009/10/01 00:01:30 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel®
SRV - [2009/08/24 18:49:41 | 000,126,392 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe -- (NIS)
SRV - [2009/07/08 22:55:26 | 000,323,584 | -H-- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\SPLASH.SYS\config\DVMExportService.exe -- (DvmMDES)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/05 20:07:28 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/03/03 06:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\AESTSr64.exe -- (AESTFilters)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/02/15 11:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 05:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010/03/25 22:41:43 | 002,838,008 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/11/12 16:07:18 | 000,200,736 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)
DRV:64bit: - [2009/11/12 16:07:10 | 000,232,480 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2009/11/06 02:15:40 | 000,291,328 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/10/30 15:23:16 | 007,770,048 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/10/21 03:35:26 | 000,501,760 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2009/10/12 22:00:52 | 000,151,040 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2009/09/26 10:42:58 | 000,233,984 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel®
DRV:64bit: - [2009/09/17 16:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel®
DRV:64bit: - [2009/08/29 20:16:41 | 000,504,880 | R--- | M] (Symantec Corporation) [File_System | System | Stopped] -- C:\Windows\SysNative\drivers\NISx64\1100000.088\srtsp64.sys -- (SRTSP)
DRV:64bit: - [2009/08/29 20:16:41 | 000,032,304 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1100000.088\srtspx64.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:64bit: - [2009/08/07 09:24:14 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/08 16:49:08 | 000,030,008 | ---- | M] (Hewlett-Packard) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hpdskflt.sys -- (hpdskflt)
DRV:64bit: - [2009/07/08 16:48:50 | 000,041,272 | ---- | M] (Hewlett-Packard) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelerometer.sys -- (Accelerometer)
DRV:64bit: - [2009/06/29 14:17:00 | 000,070,656 | ---- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\enecir.sys -- (enecir)
DRV:64bit: - [2009/06/19 22:09:57 | 001,394,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:64bit: - [2009/06/10 17:01:06 | 001,146,880 | ---- | M] (LSI Corp) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
DRV:64bit: - [2009/06/10 16:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009/06/10 16:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel®
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/05/12 22:39:00 | 000,239,152 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2009/04/29 12:48:32 | 000,018,432 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2009/09/27 16:47:24 | 000,021,624 | -H-- | M] (DeviceVM, Inc.) [Kernel | System | Running] -- C:\SPLASH.SYS\config\dvmio.sys -- (DVMIO)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0814F5D2-2789-4635-883E-0EB9DD77C8F4}
IE:64bit: - HKLM\..\SearchScopes\{0814F5D2-2789-4635-883E-0EB9DD77C8F4}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{FBF5D941-EEE5-4238-A8FE-D03863BE53EF}: "URL" = http://www.ask.com/w...}&l=dis&o=ushpl
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\SearchScopes,DefaultScope = {0814F5D2-2789-4635-883E-0EB9DD77C8F4}
IE - HKLM\..\SearchScopes\{0814F5D2-2789-4635-883E-0EB9DD77C8F4}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{FBF5D941-EEE5-4238-A8FE-D03863BE53EF}: "URL" = http://www.ask.com/w...}&l=dis&o=ushpl

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://xfinity.comca...id=cgps03182012
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {0814F5D2-2789-4635-883E-0EB9DD77C8F4}
IE - HKCU\..\SearchScopes\{0814F5D2-2789-4635-883E-0EB9DD77C8F4}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{67F0BDB9-F91D-47CE-B3B4-88F83D28D781}: "URL" = http://websearch.ask...25-3B9E4076201E
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sear
IE - HKCU\..\SearchScopes\{6FAE19DC-81B4-4AC2-8A17-8592CDF8B3B8}: "URL" = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\..\SearchScopes\{FBF5D941-EEE5-4238-A8FE-D03863BE53EF}: "URL" = http://www.ask.com/w...}&l=dis&o=ushpl
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "https://www.google.com/"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.10.1\npHDPlg.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/05 15:28:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4C0766D3-67A7-45a3-85A2-752F77312F32}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/18 17:47:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/18 17:47:23 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012/03/18 21:46:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Shannon\AppData\Roaming\Mozilla\Extensions
[2012/06/29 18:26:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Shannon\AppData\Roaming\Mozilla\Firefox\Profiles\ocrayjvc.default\extensions
[2012/01/03 16:27:44 | 000,002,333 | ---- | M] () -- C:\Users\Shannon\AppData\Roaming\Mozilla\Firefox\Profiles\ocrayjvc.default\searchplugins\askcom.xml
[2012/06/29 18:20:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/06/21 22:19:06 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/06/29 18:04:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/06/18 17:47:23 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/03/13 00:38:32 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/03/13 00:38:32 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.0.0.136\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.0.0.136\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {B84CDBE7-1B46-494B-A188-01D4C52DEB61} - No CLSID value found.
O2 - BHO: (no name) - {bb46be07-13eb-4c49-b0f0-fc78b9ea4983} - No CLSID value found.
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.0.0.136\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Nikon Message Center 2] C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe (Nikon Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicr...osoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_33)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9DF0AC44-2D12-48A1-8B31-7094AEEA4137}: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D07AC45E-5617-45A8-B148-CB7CF039A504}: DhcpNameServer = 100.100.2.5
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe ()
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/07/01 14:53:35 | 000,000,000 | ---D | C] -- C:\Windows\LastGood
[2012/07/01 05:27:07 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012/06/25 23:43:42 | 000,000,000 | ---D | C] -- C:\361c4d2b1b8c358883b1f1e6c23ed0
[2012/06/21 22:18:58 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\Skype
[2012/06/21 22:18:55 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2012/06/21 22:18:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/06/21 22:18:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012/06/21 22:18:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2012/06/13 12:39:36 | 000,000,000 | ---D | C] -- C:\cf76aa460c70306968ce499e663fc55e
[2012/06/07 08:11:36 | 000,000,000 | ---D | C] -- C:\8145a31605d16fd0464e

========== Files - Modified Within 30 Days ==========

[2012/07/01 15:22:41 | 000,000,177 | -H-- | M] () -- C:\dvmexp.idx
[2012/07/01 15:16:49 | 000,594,592 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/01 15:16:49 | 000,493,340 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/07/01 15:16:49 | 000,106,756 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/07/01 15:12:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/01 15:12:23 | 3062,984,704 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/01 14:49:00 | 000,023,568 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/01 14:49:00 | 000,023,568 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/01 05:33:43 | 000,355,072 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/01 05:31:05 | 000,113,244 | ---- | M] () -- C:\Users\Shannon\Documents\cc_20120701_053050.reg
[2012/07/01 05:27:07 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/29 17:04:08 | 000,000,036 | ---- | M] () -- C:\Users\Shannon\AppData\Local\housecall.guid.cache
[2012/06/26 18:31:45 | 000,000,020 | -H-- | M] () -- C:\ProgramData\PKP_DLet.DAT
[2012/06/25 22:53:16 | 000,001,365 | ---- | M] () -- C:\Users\Shannon\Desktop\Norton Installation Files.lnk
[2012/06/21 22:18:55 | 000,002,515 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2012/06/21 00:11:13 | 000,001,130 | ---- | M] () -- C:\Users\Shannon\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2012/06/21 00:11:13 | 000,001,106 | ---- | M] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2012/06/21 00:04:45 | 000,000,020 | -H-- | M] () -- C:\ProgramData\PKP_DLev.DAT

========== Files Created - No Company Name ==========

[2012/07/01 05:30:55 | 000,113,244 | ---- | C] () -- C:\Users\Shannon\Documents\cc_20120701_053050.reg
[2012/07/01 05:27:07 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/29 17:04:08 | 000,000,036 | ---- | C] () -- C:\Users\Shannon\AppData\Local\housecall.guid.cache
[2012/06/21 22:18:55 | 000,002,515 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2012/05/14 22:01:11 | 004,163,590 | ---- | C] () -- C:\Users\Shannon\AppData\Local\tmpCSC_0271.JPG
[2012/05/13 20:58:04 | 000,614,435 | ---- | C] () -- C:\Users\Shannon\AppData\Local\tmpDSC_0053_CROP.JPG
[2012/05/13 20:56:23 | 000,996,637 | ---- | C] () -- C:\Users\Shannon\AppData\Local\tmpDSC_0053.JPG
[2012/05/11 15:58:02 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Jazz Kit
[2012/05/11 15:58:02 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Jazz
[2012/05/11 15:58:02 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Iterate Items
[2012/05/11 15:58:02 | 000,000,268 | RH-- | C] () -- C:\Users\Shannon\AppData\Roaming\Internet Plug-Ins
[2012/05/11 15:58:02 | 000,000,268 | RH-- | C] () -- C:\Users\Shannon\AppData\Roaming\Instrument Library
[2012/05/11 15:58:02 | 000,000,268 | RH-- | C] () -- C:\Users\Shannon\AppData\Roaming\Installer Plugin
[2012/05/11 15:58:02 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLev.DAT
[2012/05/11 15:58:02 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLet.DAT
[2012/05/11 15:58:02 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLes.DAT
[2012/05/11 15:58:02 | 000,000,012 | RH-- | C] () -- C:\ProgramData\MIDI Devices
[2012/05/11 15:58:02 | 000,000,012 | RH-- | C] () -- C:\ProgramData\MAS
[2012/05/11 15:58:02 | 000,000,012 | RH-- | C] () -- C:\ProgramData\Limiter
[2012/03/25 18:52:14 | 000,434,176 | ---- | C] () -- C:\Windows\SysWow64\ieapfltr.dll
[2012/03/25 18:52:14 | 000,066,048 | ---- | C] () -- C:\Windows\SysWow64\icardie.dll
[2012/03/25 00:16:21 | 000,295,264 | ---- | C] () -- C:\Windows\SysWow64\PresentationHost.exe
[2012/03/25 00:16:21 | 000,099,176 | ---- | C] () -- C:\Windows\SysWow64\PresentationHostProxy.dll
[2012/03/25 00:16:16 | 000,049,488 | ---- | C] () -- C:\Windows\SysWow64\netfxperf.dll
[2012/03/25 00:16:14 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\CertEnroll.dll
[2012/03/25 00:16:13 | 001,619,456 | ---- | C] () -- C:\Windows\SysWow64\WMVDECOD.DLL
[2012/03/25 00:16:13 | 000,782,336 | ---- | C] () -- C:\Windows\SysWow64\webservices.dll
[2012/03/25 00:16:13 | 000,739,328 | ---- | C] () -- C:\Windows\SysWow64\WMSPDMOD.DLL
[2012/03/25 00:16:13 | 000,427,520 | ---- | C] () -- C:\Windows\SysWow64\PortableDeviceStatus.dll
[2012/03/25 00:16:13 | 000,327,680 | ---- | C] () -- C:\Windows\SysWow64\wimserv.exe
[2012/03/25 00:16:13 | 000,247,808 | ---- | C] () -- C:\Windows\SysWow64\ReAgent.dll
[2012/03/25 00:16:13 | 000,105,984 | ---- | C] () -- C:\Windows\SysWow64\WPDShServiceObj.dll
[2012/03/25 00:16:13 | 000,098,304 | ---- | C] () -- C:\Windows\SysWow64\fphc.dll
[2012/03/25 00:16:13 | 000,022,016 | ---- | C] () -- C:\Windows\SysWow64\ReAgentc.exe
[2012/03/25 00:16:13 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\WMVSDECD.DLL
[2012/03/25 00:16:13 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\WMADMOD.DLL
[2012/03/25 00:16:13 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\wlanui.dll
[2012/03/25 00:16:13 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\wlanpref.dll
[2012/03/25 00:16:13 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\PortableDeviceApi.dll
[2012/03/25 00:16:12 | 000,350,720 | ---- | C] () -- C:\Windows\SysWow64\WPDSp.dll
[2012/03/25 00:16:12 | 000,335,872 | ---- | C] () -- C:\Windows\SysWow64\WinSATAPI.dll
[2012/03/25 00:16:12 | 000,204,800 | ---- | C] () -- C:\Windows\SysWow64\WebClnt.dll
[2012/03/25 00:16:12 | 000,198,144 | ---- | C] () -- C:\Windows\SysWow64\wpdwcn.dll
[2012/03/25 00:16:12 | 000,109,568 | ---- | C] () -- C:\Windows\SysWow64\wiavideo.dll
[2012/03/25 00:16:12 | 000,051,200 | ---- | C] () -- C:\Windows\twain_32.dll
[2012/03/25 00:16:12 | 000,031,744 | ---- | C] () -- C:\Windows\SysWow64\msvidc32.dll
[2012/03/25 00:16:12 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\wiadefui.dll
[2012/03/25 00:16:11 | 002,157,568 | ---- | C] () -- C:\Windows\SysWow64\themecpl.dll
[2012/03/25 00:16:11 | 000,160,256 | ---- | C] () -- C:\Windows\SysWow64\vdsbas.dll
[2012/03/25 00:16:11 | 000,120,320 | ---- | C] () -- C:\Windows\SysWow64\msvfw32.dll
[2012/03/25 00:16:11 | 000,091,648 | ---- | C] () -- C:\Windows\SysWow64\avifil32.dll
[2012/03/25 00:16:11 | 000,084,480 | ---- | C] () -- C:\Windows\SysWow64\mciavi32.dll
[2012/03/25 00:16:11 | 000,082,944 | ---- | C] () -- C:\Windows\SysWow64\iccvid.dll
[2012/03/25 00:16:11 | 000,026,624 | ---- | C] () -- C:\Windows\SysWow64\userinit.exe
[2012/03/25 00:16:11 | 000,013,312 | ---- | C] () -- C:\Windows\SysWow64\msrle32.dll
[2012/03/25 00:16:11 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\usercpl.dll
[2012/03/25 00:16:10 | 000,072,192 | ---- | C] () -- C:\Windows\SysWow64\regapi.dll
[2012/03/25 00:16:10 | 000,052,224 | ---- | C] () -- C:\Windows\SysWow64\rdpd3d.dll
[2012/03/25 00:16:10 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\tsgqec.dll
[2012/03/25 00:16:10 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\rdpencom.dll
[2012/03/25 00:16:09 | 000,209,920 | ---- | C] () -- C:\Windows\SysWow64\mstask.dll
[2012/03/25 00:16:09 | 000,069,632 | ---- | C] () -- C:\Windows\SysWow64\tlscsp.dll
[2012/03/25 00:16:09 | 000,031,744 | ---- | C] () -- C:\Windows\SysWow64\utildll.dll
[2012/03/25 00:16:05 | 000,069,632 | ---- | C] () -- C:\Windows\SysWow64\rastapi.dll
[2012/03/25 00:16:05 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\secproc_ssp_isv.dll
[2012/03/25 00:16:02 | 000,082,944 | ---- | C] () -- C:\Windows\SysWow64\logman.exe
[2012/03/25 00:15:58 | 001,644,032 | ---- | C] () -- C:\Windows\SysWow64\netcenter.dll
[2012/03/25 00:15:58 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\pnidui.dll
[2012/03/25 00:15:57 | 000,078,848 | ---- | C] () -- C:\Windows\SysWow64\nci.dll
[2012/03/25 00:15:57 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\netplwiz.dll
[2012/03/25 00:15:57 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\netjoin.dll
[2012/03/25 00:15:57 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\netcfgx.dll
[2012/03/25 00:15:57 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\net1.exe
[2012/03/25 00:15:57 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\ncryptui.dll
[2012/03/25 00:15:57 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\NaturalLanguage6.dll
[2012/03/25 00:15:56 | 000,301,568 | ---- | C] () -- C:\Windows\SysWow64\msieftp.dll
[2012/03/25 00:15:56 | 000,225,792 | ---- | C] () -- C:\Windows\SysWow64\netdiagfx.dll
[2012/03/25 00:15:56 | 000,068,096 | ---- | C] () -- C:\Windows\SysWow64\napdsnap.dll
[2012/03/25 00:15:56 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\QUTIL.DLL
[2012/03/25 00:15:56 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\QSVRMGMT.DLL
[2012/03/25 00:15:56 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\QSHVHOST.DLL
[2012/03/25 00:15:56 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\nshipsec.dll
[2012/03/25 00:15:56 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\MSMPEG2ENC.DLL
[2012/03/25 00:15:56 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\mcbuilder.exe
[2012/03/25 00:15:56 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\ipsmsnap.dll
[2012/03/25 00:15:56 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\iasrad.dll
[2012/03/25 00:15:56 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\iasacct.dll
[2012/03/25 00:15:55 | 000,226,304 | ---- | C] () -- C:\Windows\SysWow64\MSAC3ENC.DLL
[2012/03/25 00:15:55 | 000,101,376 | ---- | C] () -- C:\Windows\SysWow64\mobsync.exe
[2012/03/25 00:15:54 | 000,954,752 | ---- | C] () -- C:\Windows\SysWow64\mfc40.dll
[2012/03/25 00:15:54 | 000,954,288 | ---- | C] () -- C:\Windows\SysWow64\mfc40u.dll
[2012/03/25 00:15:54 | 000,076,800 | ---- | C] () -- C:\Windows\SysWow64\mapistub.dll
[2012/03/25 00:15:54 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\logagent.exe
[2012/03/25 00:15:52 | 000,778,240 | ---- | C] () -- C:\Windows\SysWow64\sqlsrv32.dll
[2012/03/25 00:15:49 | 000,176,128 | ---- | C] () -- C:\Windows\SysWow64\msorcl32.dll
[2012/03/25 00:15:48 | 000,041,984 | ---- | C] () -- C:\Windows\SysWow64\luainstall.dll
[2012/03/25 00:15:38 | 000,337,408 | ---- | C] () -- C:\Windows\SysWow64\msihnd.dll
[2012/03/25 00:15:38 | 000,070,656 | ---- | C] () -- C:\Windows\SysWow64\MuiUnattend.exe
[2012/03/25 00:15:38 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\nlsbres.dll
[2012/03/25 00:15:38 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\isoburn.exe
[2012/03/25 00:15:29 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drvstore.dll
[2012/03/25 00:15:28 | 000,113,152 | ---- | C] () -- C:\Windows\SysWow64\setupugc.exe
[2012/03/25 00:15:17 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\dsuiext.dll
[2012/03/25 00:15:14 | 000,066,560 | ---- | C] () -- C:\Windows\SysWow64\cca.dll
[2012/03/25 00:15:06 | 000,616,960 | ---- | C] () -- C:\Windows\SysWow64\wmdrmsdk.dll
[2012/03/25 00:15:02 | 000,220,672 | ---- | C] () -- C:\Windows\SysWow64\defaultlocationcpl.dll
[2012/03/25 00:15:02 | 000,219,648 | ---- | C] () -- C:\Windows\SysWow64\iTVData.dll
[2012/03/25 00:15:01 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\imapi2.dll
[2012/03/25 00:14:54 | 000,732,160 | ---- | C] () -- C:\Windows\SysWow64\imapi2fs.dll
[2012/03/25 00:14:51 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\fontext.dll
[2012/03/25 00:14:48 | 001,400,320 | ---- | C] () -- C:\Windows\SysWow64\DxpTaskSync.dll
[2012/03/25 00:14:48 | 000,242,176 | ---- | C] () -- C:\Windows\SysWow64\eapp3hst.dll
[2012/03/25 00:14:48 | 000,222,208 | ---- | C] () -- C:\Windows\SysWow64\eapphost.dll
[2012/03/25 00:14:48 | 000,115,200 | ---- | C] () -- C:\Windows\SysWow64\dot3msm.dll
[2012/03/25 00:14:45 | 000,206,848 | ---- | C] () -- C:\Windows\SysWow64\qasf.dll
[2012/03/25 00:14:44 | 000,302,592 | ---- | C] () -- C:\Windows\SysWow64\cmd.exe
[2012/03/25 00:14:43 | 000,036,352 | ---- | C] () -- C:\Windows\SysWow64\wshbth.dll
[2012/03/20 19:15:33 | 000,465,408 | ---- | C] () -- C:\Windows\SysWow64\psisdecd.dll
[2012/03/20 19:14:45 | 000,319,488 | ---- | C] () -- C:\Windows\SysWow64\odbcjt32.dll
[2012/03/20 19:14:33 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\CPFilters.dll
[2012/03/20 19:07:12 | 000,014,336 | ---- | C] () -- C:\Windows\SysWow64\ntvdm64.dll

========== LOP Check ==========

[2012/03/18 22:15:42 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\ID Vault
[2012/05/11 16:10:22 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Nikon
[2012/03/18 23:22:06 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\WildTangent
[2012/03/20 23:34:03 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\WindSolutions
[2012/05/14 16:04:19 | 000,025,844 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
  • 0

Advertisements


#2
godawgs

godawgs

    Teacher

  • Retired Staff
  • 8,228 posts
Hello Gauze, :wave:
:welcome:. My name is godawgs and I will be assisting you with your Virus / Malware issues.

I am currently still in training and my posts have to be approved by an expert so please expect a delay between my posts.

We apologize for the delay in responding to your request for help. Here at GeeksToGo we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

I will start working on your Malware issues. This may, or may not, solve other issues you have with your machine. The fixes are specific to your problem and should only be used for this issue on this machine!

If you have since resolved the issues you were originally experiencing, or have received help elsewhere, please inform me so that this topic can be closed.
If you have not, please adhere to the guidelines below and then carefully follow all future instructions:

I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same.
Because of this, you must reply within four days. If you haven't replied within that time, the topic will be closed! If you need additional time to complete things, just let me know.
  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forums.
  • Please let me know if you are using a computer with multiple accounts, as this can affect the instructions given.
  • Please make sure to carefully read any instruction that I give you. Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.
    I would recommend printing them out, if you can, so you can check off each step as you complete it.
    Also, part of the fix may require you to be in Safe Mode, which will not allow you to access the internet, or my instructions!
  • If you're not sure, or if something unexpected happens, Do NOT continue! Stop and ask!
  • All tools must be run from an account with Administrator privileges.
  • Do not do things I do not ask for, such as running a spyware scan on your computer, installing/uninstall programs, deleting files, modifying the registry or running any tools, unless instructed to do so. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date (if possible)!
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post unless directed otherwise.
  • Lastly, Please be aware that removing Malware is a hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. Some infections are so severe that we might encounter situations where the only recourse is to re-format and re-install your operating system. Don't worry, this only happens in severe cases, but, sadly, it does happen.
    In light of this be prepared to back up your data. Have means of backing up your data available.
In order to be notified when your topic has been replied to:

Click My Settings at the top of the page. An Option page will open. In the left hand column click Notification Options. On the new page that opens under the Notification Preferences section click Watch every topic I reply to and set the notification type to Immediate Notification.


I am currently reviewing your OTL log. When OTL was run it should have generated a Extras.txt file and placed it the same folder as the OTL.txt file. So it should be in the C:\Users\Shannon\Downloads folder. I need you to copy/paste it in your next reply.

I want you to run a tool that will let me have a look at your MBR.


Step-1.

Run aswMBR
  • Download aswMBR.exe to your desktop.
  • Double click the aswMBR.exe file to run it. (Windows /7 users: Right click the file and click Run as Administrator. If you get a UAC window, allow the file to run.
  • If it asks you if you want to download the latest virus definitions, click Yes
  • Click the "Scan" button to start the scan
    Posted Image
  • On completion of the scan click save log. Save it to your desktop and post in your next reply.
    Posted Image
NOTE: When you run aswMBR, if it is shutdown automatically, then it is most likely the infection detecting that aswMBR is running and terminating it. In this situation you should rename executable to iexplore.exe and try it again.


Step-2.

Run Farbar Service Scanner

Please download Farbar Service Scanner to the desktop.
Doubleclick the FSS.exe file to run it. (Vista and 7 users may need to right click the file and click Run as Administrator)
  • Posted Image
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


Step-3.

Things For Your Next Post:
1. The Extras.txt log
2. The aswMBR log
3. The FSS.txt log

I will be back to you as soon as I get these new logs and get them all analyzed.

Edited by godawgs, 03 July 2012 - 07:39 AM.

  • 0

#3
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP