Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

need help removing adware [Closed]


  • This topic is locked This topic is locked

#1
dee55

dee55

    New Member

  • Member
  • Pip
  • 1 posts
My internet explorer keeps crashing ran Mr. fix it and it said I had all these tool bars and search assistants that I cant find (ie.Blubster,DoubleD,Morpheus Bar Search etc). I have Norton security also ran Norton Eraser Malwarebytes and they came up clean. Here is my output from OLT. I hope you can help. Thanks

OTL logfile created on: 8/18/2012 1:58:04 PM - Run 1
OTL by OldTimer - Version 3.2.58.0 Folder = C:\Users\Debra\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 50.25% Memory free
3.99 Gb Paging File | 2.53 Gb Available in Paging File | 63.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 289.34 Gb Total Space | 233.46 Gb Free Space | 80.69% Space Free | Partition Type: NTFS

Computer Name: DEBRA-PC | User Name: Debra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/08/18 13:55:05 | 000,598,016 | ---- | M] (OldTimer Tools) -- C:\Users\Debra\Downloads\OTL.exe
PRC - [2012/08/14 15:57:30 | 001,536,712 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe
PRC - [2012/08/14 14:57:13 | 000,686,792 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_11_3_300_271_ActiveX.exe
PRC - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/19 09:51:31 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/06/15 22:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccsvchst.exe
PRC - [2012/02/14 23:13:20 | 000,405,504 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2012/02/14 23:12:48 | 000,163,328 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2012/02/13 19:18:34 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
PRC - [2011/12/23 11:20:00 | 001,037,672 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe
PRC - [2011/12/23 11:20:00 | 000,406,888 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrvProxy.exe
PRC - [2011/12/23 11:18:38 | 000,406,888 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe
PRC - [2011/12/23 11:18:24 | 001,029,480 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe
PRC - [2011/08/12 23:23:19 | 002,068,480 | ---- | M] (Arachnoid Biometrics Identification Group Corp.) -- C:\Program Files\VitaKey\AC5031\CompPtcVUI.exe
PRC - [2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/11/20 08:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe


========== Modules (No Company Name) ==========

MOD - [2012/08/14 15:57:30 | 009,465,032 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_11_3_300_271.dll
MOD - [2012/07/19 09:51:31 | 002,003,424 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll


========== Win32 Services (SafeList) ==========

SRV - [2012/08/14 15:57:32 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/19 09:51:31 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/06/26 22:15:48 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/06/15 22:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe -- (NIS)
SRV - [2012/02/14 23:12:48 | 000,163,328 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2011/12/23 11:20:00 | 001,037,672 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe -- (SpeedDiskService)
SRV - [2011/12/23 11:18:24 | 001,029,480 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe -- (DiskDoctorService)
SRV - [2011/09/02 23:54:52 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbmodem.sys -- (USBModem)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbdiag.sys -- (UsbDiag)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbbus.sys -- (usbbus)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - [2012/08/17 23:27:52 | 000,094,368 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\SMR310.SYS -- (SMR310)
DRV - [2012/08/10 20:25:14 | 000,995,488 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\Definitions\BASHDefs\20120811.003\BHDrvx86.sys -- (BHDrvx86)
DRV - [2012/08/10 10:46:06 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2012/08/10 10:46:06 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012/07/16 16:09:07 | 001,589,752 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\Definitions\VirusDefs\20120817.034\NAVEX15.SYS -- (NAVEX15)
DRV - [2012/07/16 16:09:07 | 000,087,928 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\Definitions\VirusDefs\20120817.034\NAVENG.SYS -- (NAVENG)
DRV - [2012/07/05 22:17:57 | 000,574,112 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\NIS\1308000.00E\srtsp.sys -- (SRTSP)
DRV - [2012/07/05 22:17:57 | 000,032,928 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1308000.00E\srtspx.sys -- (SRTSPX)
DRV - [2012/07/03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/06/14 14:39:26 | 000,382,624 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\Definitions\IPSDefs\20120817.001\IDSvix86.sys -- (IDSVix86)
DRV - [2012/06/07 00:43:43 | 000,132,768 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1308000.00E\ccsetx86.sys -- (ccSet_NIS)
DRV - [2012/05/21 21:37:12 | 000,924,320 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\NIS\1308000.00E\symefa.sys -- (SymEFA)
DRV - [2012/04/17 22:13:32 | 000,318,584 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1308000.00E\symnets.sys -- (SymNetS)
DRV - [2012/04/17 21:42:14 | 000,149,624 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1308000.00E\ironx86.sys -- (SymIRON)
DRV - [2012/03/23 15:15:14 | 000,141,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2012/03/02 16:02:00 | 000,025,728 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgandadb.sys -- (androidusb)
DRV - [2012/03/02 16:02:00 | 000,025,088 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgandmodem.sys -- (ANDModem)
DRV - [2012/03/02 16:02:00 | 000,020,736 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lganddiag.sys -- (AndDiag)
DRV - [2012/03/02 16:02:00 | 000,020,096 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgandgps.sys -- (AndGps)
DRV - [2012/03/02 16:02:00 | 000,014,336 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgandbus.sys -- (Andbus)
DRV - [2012/02/14 23:47:12 | 009,182,208 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2012/02/14 23:47:12 | 009,182,208 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2012/02/14 22:12:48 | 000,264,704 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2011/12/23 11:20:04 | 000,128,248 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SymDSMon.sys -- (SymDSMon)
DRV - [2011/12/23 11:20:04 | 000,108,800 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SymSpeedDisk.sys -- (SYMSpeedDisk)
DRV - [2011/12/05 15:47:16 | 000,086,032 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdW73.sys -- (AtiHDAudioService)
DRV - [2011/08/16 02:51:40 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\NIS\1308000.00E\symds.sys -- (SymDS)
DRV - [2011/08/12 23:23:10 | 000,042,608 | ---- | M] (Alfa Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\AlfaFF.sys -- (AlfaFF)
DRV - [2010/11/20 08:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 08:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 08:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 06:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 06:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010/11/20 05:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 05:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 05:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/07/14 07:34:15 | 006,680,064 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETwNv32.sys -- (NETwNv32)
DRV - [2009/09/04 13:16:14 | 000,087,536 | ---- | M] (CyberLink Corp.) [2011/08/14 01:47:16] [Kernel | Auto | Running] -- C:\Program Files\CyberLink\PowerDVD\000.fcl -- ({95808DC4-FA4A-4C74-92FE-5B863F82066B})
DRV - [2009/07/13 20:18:07 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2009/07/13 18:02:53 | 000,311,296 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7)
DRV - [2009/06/05 08:14:08 | 001,151,104 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVerBDA716x.sys -- (AVerBDA6x)
DRV - [2008/06/24 15:55:12 | 000,047,104 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2008/04/25 10:31:26 | 000,146,688 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atswpdrv.sys -- (ATSWPDRV)
DRV - [2008/01/25 20:02:04 | 000,140,832 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvstor32.sys -- (nvstor32)
DRV - [2008/01/25 20:02:04 | 000,132,128 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvrd32.sys -- (nvrd32)
DRV - [2007/08/06 20:15:07 | 000,033,052 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2007/07/30 10:42:58 | 000,043,008 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2007/06/15 11:52:18 | 000,143,256 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\mv61xx.sys -- (mv61xx)
DRV - [2007/04/12 00:18:34 | 000,048,000 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\jraid.sys -- (JRAID)
DRV - [2006/12/28 19:51:56 | 000,110,592 | ---- | M] (ATI Technologies Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ahcix86s.sys -- (ahcix86s)
DRV - [2006/02/07 19:52:58 | 000,006,912 | ---- | M] (JMicron ) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\JGOGO.sys -- (JGOGO)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BB 33 E7 B0 D1 7C CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AOL Search"
FF - prefs.js..browser.search.defaulturl: "http://search.aol.co...rud=19-06-2012"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.aol.com/"
FF - prefs.js..keyword.URL: "http://slirsredirect...06-2012&query="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.6.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.6.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\coFFPlgn\ [2012/08/18 13:49:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/06/14 10:31:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\IPSFFPlgn\ [2012/07/16 20:02:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/08/13 15:29:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/19 09:51:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/08/14 17:36:43 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/08/13 15:29:39 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/19 09:51:31 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/08/14 17:36:43 | 000,000,000 | ---D | M]

[2012/06/01 16:58:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Debra\AppData\Roaming\Mozilla\Extensions
[2012/07/20 14:10:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Debra\AppData\Roaming\Mozilla\Firefox\Profiles\ga0zszga.default\extensions
[2012/06/01 18:59:50 | 000,002,470 | ---- | M] () -- C:\Users\Debra\AppData\Roaming\Mozilla\Firefox\Profiles\ga0zszga.default\searchplugins\safesearch.xml
[2012/06/19 15:37:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/06/19 15:37:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\distribution\extensions
[2012/06/19 15:37:24 | 000,000,000 | ---D | M] (AOL Toolbar) -- C:\Program Files\Mozilla Firefox\distribution\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}
[2012/06/14 10:31:51 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2012/08/18 13:49:57 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\COFFPLGN
[2012/07/16 20:02:24 | 000,000,000 | ---D | M] (Norton Vulnerability Protection) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.1.2\IPSFFPLGN
[2012/07/20 11:53:16 | 000,084,548 | ---- | M] () (No name found) -- C:\USERS\DEBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GA0ZSZGA.DEFAULT\EXTENSIONS\{0545B830-F0AA-4D7E-8820-50A4629A56FE}.XPI
[2012/06/01 18:29:51 | 000,042,737 | ---- | M] () (No name found) -- C:\USERS\DEBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GA0ZSZGA.DEFAULT\EXTENSIONS\{AFF87FA2-A58E-4EDD-B852-0A20203C1E17}.XPI
[2012/07/20 13:56:00 | 000,010,480 | ---- | M] () (No name found) -- C:\USERS\DEBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GA0ZSZGA.DEFAULT\EXTENSIONS\[email protected]
[2012/07/19 09:59:36 | 000,146,198 | ---- | M] () (No name found) -- C:\USERS\DEBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GA0ZSZGA.DEFAULT\EXTENSIONS\[email protected]
[2012/07/19 09:55:53 | 000,060,730 | ---- | M] () (No name found) -- C:\USERS\DEBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GA0ZSZGA.DEFAULT\EXTENSIONS\[email protected]
[2012/06/01 18:29:51 | 000,113,603 | ---- | M] () (No name found) -- C:\USERS\DEBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GA0ZSZGA.DEFAULT\EXTENSIONS\[email protected]
[2012/07/19 09:51:31 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/03/18 14:32:12 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/03/18 14:32:14 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/06/01 11:39:16 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/06/01 11:39:16 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.8.0.14\coieplg.dll (Symantec Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Reg Error: Key error.)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.syma...bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.syma...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.syste...yri_4.5.1.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{16DAD830-73FC-4250-941A-C22C8E8AED8C}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\NORTON~3\Tools\SPEEDD~1\aDSBatch.exe /startup)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/08/18 12:45:19 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2012/08/18 00:35:53 | 000,000,000 | ---D | C] -- C:\Users\Debra\AppData\Roaming\SpeedMaxPc
[2012/08/18 00:35:53 | 000,000,000 | ---D | C] -- C:\Users\Debra\AppData\Roaming\DriverCure
[2012/08/18 00:34:33 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedMaxPc
[2012/08/17 23:32:58 | 000,000,000 | ---D | C] -- C:\ProgramData\SMR310
[2012/08/17 23:27:52 | 000,094,368 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\SMR310.SYS
[2012/08/17 22:56:54 | 000,000,000 | ---D | C] -- C:\Program Files\Trojan Remover
[2012/08/17 22:56:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2012/08/15 23:01:03 | 000,000,000 | ---D | C] -- C:\Users\Debra\AppData\Roaming\Lazy Turtle Games
[2012/08/15 17:32:29 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012/08/15 17:32:28 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012/08/15 17:32:27 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012/08/15 17:32:27 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012/08/15 17:32:26 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012/08/15 17:32:25 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012/08/15 17:32:24 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012/08/15 15:14:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/08/15 15:14:35 | 000,246,760 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012/08/15 15:13:53 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012/08/15 15:13:53 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012/08/15 15:13:53 | 000,093,672 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2012/08/15 15:11:30 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2012/08/15 14:12:17 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll
[2012/08/15 14:12:14 | 002,345,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012/08/15 14:12:09 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browcli.dll
[2012/08/13 15:57:27 | 000,000,000 | ---D | C] -- C:\ProgramData\HPSSUPPLY
[2012/08/13 15:28:23 | 000,000,000 | ---D | C] -- C:\ProgramData\HP Product Assistant
[2012/08/13 15:26:07 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\HP
[2012/08/13 15:03:35 | 000,000,000 | ---D | C] -- C:\Users\Debra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pogo Games
[2012/08/13 15:03:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pogo Games
[2012/08/13 15:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Oberon Media
[2012/08/03 22:13:00 | 000,000,000 | ---D | C] -- C:\Users\Debra\AppData\Roaming\Gogii
[2012/07/31 14:21:06 | 000,000,000 | ---D | C] -- C:\Users\Debra\AppData\Local\NPE
[2012/07/22 10:40:31 | 000,000,000 | ---D | C] -- C:\Users\Debra\Documents\Amnesia
[2012/07/21 17:49:51 | 000,000,000 | ---D | C] -- C:\Windows\Severe Incident - Cargo Flight 821
[2012/07/21 15:48:24 | 000,000,000 | ---D | C] -- C:\Program Files\Tiger Games
[2012/02/14 23:01:26 | 000,465,264 | ---- | C] (Corel) -- C:\Program Files\Common Files\AppFramework.dll
[2012/02/14 23:01:26 | 000,332,144 | ---- | C] (Corel) -- C:\Program Files\Common Files\MediaOrganizer.dll
[2012/02/14 23:01:26 | 000,033,136 | ---- | C] (Corel-V1E) -- C:\Program Files\Common Files\FlickrProvider.dll
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/08/18 13:57:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/08/18 13:56:43 | 000,010,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/18 13:56:43 | 000,010,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/18 13:49:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/08/18 13:49:25 | 1606,606,848 | -HS- | M] () -- C:\hiberfil.sys
[2012/08/18 13:07:01 | 000,000,355 | ---- | M] () -- C:\Users\Debra\Desktop\Computer - Shortcut.lnk
[2012/08/18 00:54:02 | 000,001,589 | ---- | M] () -- C:\Users\Debra\Desktop\DivX Movies.lnk
[2012/08/17 23:27:52 | 000,094,368 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\SMR310.SYS
[2012/08/17 19:38:39 | 000,003,280 | ---- | M] () -- C:\bootsqm.dat
[2012/08/17 19:00:32 | 000,000,248 | ---- | M] () -- C:\Windows\tasks\NUSchedule.job
[2012/08/16 12:02:20 | 000,008,942 | ---- | M] () -- C:\Windows\System32\drivers\NIS\1308000.00E\VT20120731.038
[2012/08/15 23:12:07 | 000,624,178 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/08/15 23:12:07 | 000,106,522 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/08/15 18:33:18 | 000,411,344 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/08/15 18:32:41 | 001,424,447 | ---- | M] () -- C:\Windows\System32\drivers\NIS\1308000.00E\Cat.DB
[2012/08/15 15:13:29 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2012/08/15 15:13:29 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2012/08/15 15:13:29 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012/08/15 15:13:29 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012/08/15 15:13:29 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012/08/15 15:13:29 | 000,093,672 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2012/08/14 15:57:30 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/08/14 15:57:30 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/08/13 16:08:47 | 000,002,111 | ---- | M] () -- C:\Users\Debra\Desktop\Jewel Quest Solitaire 2.lnk
[2012/08/13 15:40:22 | 000,207,251 | ---- | M] () -- C:\Windows\hpwins28.dat
[2012/08/13 15:03:35 | 000,002,217 | ---- | M] () -- C:\Users\Debra\Desktop\Tri Peaks 2 Quest For The Ruby Ring.lnk
[2012/08/10 01:28:35 | 000,000,172 | ---- | M] () -- C:\Windows\System32\drivers\NIS\1308000.00E\isolate.ini
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/08/18 13:07:01 | 000,000,355 | ---- | C] () -- C:\Users\Debra\Desktop\Computer - Shortcut.lnk
[2012/08/17 19:38:39 | 000,003,280 | ---- | C] () -- C:\bootsqm.dat
[2012/08/13 16:08:47 | 000,002,111 | ---- | C] () -- C:\Users\Debra\Desktop\Jewel Quest Solitaire 2.lnk
[2012/08/13 15:28:44 | 000,001,028 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR Registration.lnk
[2012/08/13 15:22:20 | 000,207,251 | ---- | C] () -- C:\Windows\hpwins28.dat
[2012/08/13 15:03:34 | 000,002,217 | ---- | C] () -- C:\Users\Debra\Desktop\Tri Peaks 2 Quest For The Ruby Ring.lnk
[2012/06/19 10:56:03 | 000,036,712 | ---- | C] () -- C:\Windows\System32\CleanMFT32.exe
[2012/06/14 10:23:58 | 000,411,344 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/03/21 19:43:30 | 000,207,523 | ---- | C] () -- C:\Windows\hpwins28.dat.temp
[2012/03/21 19:43:30 | 000,000,418 | ---- | C] () -- C:\Windows\hpwmdl28.dat.temp
[2012/03/21 19:25:46 | 000,200,468 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2012/02/25 17:02:37 | 000,053,248 | ---- | C] () -- C:\Windows\System32\CommonDL.dll
[2012/02/25 17:02:37 | 000,002,413 | ---- | C] () -- C:\Windows\System32\lgAxconfig.ini
[2012/02/14 23:01:26 | 000,402,800 | ---- | C] () -- C:\Program Files\Common Files\facebook.dll
[2012/02/14 23:01:26 | 000,130,416 | ---- | C] () -- C:\Program Files\Common Files\PluginCommon.dll
[2012/02/14 22:28:34 | 000,157,144 | ---- | C] () -- C:\Windows\System32\ativvsva.dat
[2012/02/14 22:28:32 | 000,204,952 | ---- | C] () -- C:\Windows\System32\ativvsvl.dat
[2012/02/14 22:05:16 | 000,054,784 | ---- | C] () -- C:\Windows\System32\OVDecode.dll
[2012/01/31 06:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\System32\kdbsdk32.dll
[2012/01/10 17:10:08 | 000,601,728 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2011/12/12 10:32:25 | 000,000,059 | ---- | C] () -- C:\ProgramData\user.ini
[2011/10/05 11:05:32 | 000,001,057 | ---- | C] () -- C:\Users\Debra\AppData\Roaming\vso_ts_preview.xml
[2011/09/14 16:30:31 | 000,148,177 | ---- | C] () -- C:\Program Files\Common Files\BookViewer.xap
[2011/09/14 16:27:05 | 000,003,584 | ---- | C] () -- C:\Users\Debra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/14 16:26:44 | 000,000,952 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2011/09/12 18:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2011/09/03 12:15:01 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011/09/03 12:12:53 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011/09/02 19:44:05 | 000,021,316 | ---- | C] () -- C:\Windows\System32\emptyregdb.dat
[2011/09/02 19:22:03 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/08/17 13:08:43 | 000,116,224 | ---- | C] () -- C:\Windows\System32\redmonnt.dll
[2011/08/17 13:08:43 | 000,045,056 | ---- | C] () -- C:\Windows\System32\unredmon.exe
[2011/08/13 21:55:58 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/08/13 19:57:14 | 000,000,014 | ---- | C] () -- C:\Windows\popcinfo.dat
[2011/08/13 15:36:14 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011/08/12 23:28:17 | 000,003,072 | ---- | C] () -- C:\Windows\System32\716xCoInstaller.dll
[2011/08/12 17:55:01 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:54D5DB8A
@Alternate Data Stream - 246 bytes -> C:\ProgramData\TEMP:B88DC997
@Alternate Data Stream - 246 bytes -> C:\ProgramData\TEMP:B6E58523
@Alternate Data Stream - 246 bytes -> C:\ProgramData\TEMP:48862C37
@Alternate Data Stream - 245 bytes -> C:\ProgramData\TEMP:363E775E
@Alternate Data Stream - 240 bytes -> C:\ProgramData\TEMP:2CB9631F
@Alternate Data Stream - 239 bytes -> C:\ProgramData\TEMP:5164A01F
@Alternate Data Stream - 237 bytes -> C:\ProgramData\TEMP:2A874675
@Alternate Data Stream - 236 bytes -> C:\ProgramData\TEMP:E8B61305
@Alternate Data Stream - 236 bytes -> C:\ProgramData\TEMP:BE0654D6
@Alternate Data Stream - 234 bytes -> C:\ProgramData\TEMP:D7D0B4AF
@Alternate Data Stream - 234 bytes -> C:\ProgramData\TEMP:AAA06E15
@Alternate Data Stream - 234 bytes -> C:\ProgramData\TEMP:661DC753
@Alternate Data Stream - 234 bytes -> C:\ProgramData\TEMP:5E73E1C2
@Alternate Data Stream - 233 bytes -> C:\ProgramData\TEMP:6DD124E2
@Alternate Data Stream - 233 bytes -> C:\ProgramData\TEMP:00D99749
@Alternate Data Stream - 232 bytes -> C:\ProgramData\TEMP:A819A132
@Alternate Data Stream - 232 bytes -> C:\ProgramData\TEMP:88A44CC1
@Alternate Data Stream - 231 bytes -> C:\ProgramData\TEMP:2211E7A0
@Alternate Data Stream - 230 bytes -> C:\ProgramData\TEMP:3969ACF7
@Alternate Data Stream - 229 bytes -> C:\ProgramData\TEMP:B8791731
@Alternate Data Stream - 229 bytes -> C:\ProgramData\TEMP:9D03192E
@Alternate Data Stream - 229 bytes -> C:\ProgramData\TEMP:18B5F839
@Alternate Data Stream - 228 bytes -> C:\ProgramData\TEMP:E0888117
@Alternate Data Stream - 228 bytes -> C:\ProgramData\TEMP:0BBF232A
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:3EC5BC08
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:2727F067
@Alternate Data Stream - 226 bytes -> C:\ProgramData\TEMP:C0BCE04B
@Alternate Data Stream - 226 bytes -> C:\ProgramData\TEMP:4C8FA829
@Alternate Data Stream - 225 bytes -> C:\ProgramData\TEMP:E894A3ED
@Alternate Data Stream - 225 bytes -> C:\ProgramData\TEMP:E6C6EB3B
@Alternate Data Stream - 225 bytes -> C:\ProgramData\TEMP:31C9BA96
@Alternate Data Stream - 223 bytes -> C:\ProgramData\TEMP:B0A727D1
@Alternate Data Stream - 223 bytes -> C:\ProgramData\TEMP:AA0017FD
@Alternate Data Stream - 223 bytes -> C:\ProgramData\TEMP:922DA2DB
@Alternate Data Stream - 223 bytes -> C:\ProgramData\TEMP:884C7316
@Alternate Data Stream - 222 bytes -> C:\ProgramData\TEMP:A9562832
@Alternate Data Stream - 222 bytes -> C:\ProgramData\TEMP:3E200C29
@Alternate Data Stream - 221 bytes -> C:\ProgramData\TEMP:F72306CC
@Alternate Data Stream - 221 bytes -> C:\ProgramData\TEMP:1B389835
@Alternate Data Stream - 221 bytes -> C:\ProgramData\TEMP:1A5822A3
@Alternate Data Stream - 219 bytes -> C:\ProgramData\TEMP:1604D047
@Alternate Data Stream - 218 bytes -> C:\ProgramData\TEMP:E6708F08
@Alternate Data Stream - 215 bytes -> C:\ProgramData\TEMP:A0921B2C
@Alternate Data Stream - 215 bytes -> C:\ProgramData\TEMP:2F8138B7
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:94B46CA2
@Alternate Data Stream - 213 bytes -> C:\ProgramData\TEMP:16A4620C
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:AECF4772
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:59465B40
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:4EE323A4
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:4CA05B44
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:436BE28C
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:E87AB4E3
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:BF2E2F0E
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:8B4B9596
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:8855A119
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:5DABFF83
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:1DB77A89
@Alternate Data Stream - 209 bytes -> C:\ProgramData\TEMP:A6D6E537
@Alternate Data Stream - 209 bytes -> C:\ProgramData\TEMP:8E5EA40F
@Alternate Data Stream - 209 bytes -> C:\ProgramData\TEMP:762408BA
@Alternate Data Stream - 208 bytes -> C:\ProgramData\TEMP:C80AB70B
@Alternate Data Stream - 208 bytes -> C:\ProgramData\TEMP:BE40C8A2
@Alternate Data Stream - 208 bytes -> C:\ProgramData\TEMP:26A148EB
@Alternate Data Stream - 207 bytes -> C:\ProgramData\TEMP:1709732A
@Alternate Data Stream - 206 bytes -> C:\ProgramData\TEMP:EE69D7DF
@Alternate Data Stream - 206 bytes -> C:\ProgramData\TEMP:BD34FFC5
@Alternate Data Stream - 206 bytes -> C:\ProgramData\TEMP:A9223B61
@Alternate Data Stream - 204 bytes -> C:\ProgramData\TEMP:CAC06C34
@Alternate Data Stream - 204 bytes -> C:\ProgramData\TEMP:1416AAA6
@Alternate Data Stream - 204 bytes -> C:\ProgramData\TEMP:041C0562
@Alternate Data Stream - 203 bytes -> C:\ProgramData\TEMP:E5496666
@Alternate Data Stream - 203 bytes -> C:\ProgramData\TEMP:A4241298
@Alternate Data Stream - 203 bytes -> C:\ProgramData\TEMP:8AED9359
@Alternate Data Stream - 188 bytes -> C:\ProgramData\TEMP:E690114B
@Alternate Data Stream - 185 bytes -> C:\ProgramData\TEMP:5CE0D2E5
@Alternate Data Stream - 184 bytes -> C:\ProgramData\TEMP:D3A96964
@Alternate Data Stream - 178 bytes -> C:\ProgramData\TEMP:6CD65498
@Alternate Data Stream - 170 bytes -> C:\ProgramData\TEMP:5EC637CB
@Alternate Data Stream - 169 bytes -> C:\ProgramData\TEMP:A124FC63
@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:9D532E22
@Alternate Data Stream - 162 bytes -> C:\ProgramData\TEMP:24317F39
@Alternate Data Stream - 158 bytes -> C:\ProgramData\TEMP:498C86F6
@Alternate Data Stream - 157 bytes -> C:\ProgramData\TEMP:00F3AA48
@Alternate Data Stream - 154 bytes -> C:\ProgramData\TEMP:80255877
@Alternate Data Stream - 151 bytes -> C:\ProgramData\TEMP:81C88EA7
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:A6E01F67
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:04E8E676
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:EA666F77
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:3FA133CA
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:24C4C2B4
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:53F09A92
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:1E942FB9
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:D287FACF

< End of report >
  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there lets try the simple solution first

Download AdwCleaner from here to your desktop
Run AdwCleaner and select Delete

Posted Image

Once done it will ask to reboot, allow this
On reboot a log will be produced please attach that
  • 0

#3
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP