<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[MalwareTips.com - All Forums]]></title>
		<link>http://malwaretips.com/</link>
		<description><![CDATA[MalwareTips.com - http://malwaretips.com]]></description>
		<pubDate>Tue, 21 May 2013 00:56:41 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Help with FBI virus aftermath]]></title>
			<link>http://malwaretips.com/Thread-Help-with-FBI-virus-aftermath</link>
			<pubDate>Mon, 20 May 2013 18:45:13 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-Help-with-FBI-virus-aftermath</guid>
			<description><![CDATA[<br /><!-- start: postbit_attachments_attachment -->
<br /><img src="images/attachtypes/txt.gif" border="0" alt=".txt" />&nbsp;&nbsp;<a href="attachment.php?aid=4556" target="_blank">aswMBR.txt</a> (Size: 1.57 KB / Downloads: 0)
<!-- end: postbit_attachments_attachment --><br /><!-- start: postbit_attachments_attachment -->
<br /><img src="images/attachtypes/txt.gif" border="0" alt=".txt" />&nbsp;&nbsp;<a href="attachment.php?aid=4557" target="_blank">OTL.Txt</a> (Size: 149.58 KB / Downloads: 1)
<!-- end: postbit_attachments_attachment -->]]></description>
			<content:encoded><![CDATA[<br /><!-- start: postbit_attachments_attachment -->
<br /><img src="images/attachtypes/txt.gif" border="0" alt=".txt" />&nbsp;&nbsp;<a href="attachment.php?aid=4556" target="_blank">aswMBR.txt</a> (Size: 1.57 KB / Downloads: 0)
<!-- end: postbit_attachments_attachment --><br /><!-- start: postbit_attachments_attachment -->
<br /><img src="images/attachtypes/txt.gif" border="0" alt=".txt" />&nbsp;&nbsp;<a href="attachment.php?aid=4557" target="_blank">OTL.Txt</a> (Size: 149.58 KB / Downloads: 1)
<!-- end: postbit_attachments_attachment -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Trying to Remove PricePeep Ads]]></title>
			<link>http://malwaretips.com/Thread-Trying-to-Remove-PricePeep-Ads</link>
			<pubDate>Mon, 20 May 2013 17:36:16 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-Trying-to-Remove-PricePeep-Ads</guid>
			<description><![CDATA[OTL logfile created on: 5/20/2013 6:41:12 PM - Run 1<br />
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Documents and Settings\Marrier\My Documents\Downloads<br />
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation<br />
Internet Explorer (Version = 8.0.6001.18702)<br />
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br />
 <br />
2.99 Gb Total Physical Memory | 1.87 Gb Available Physical Memory | 62.54% Memory free<br />
5.82 Gb Paging File | 4.90 Gb Available in Paging File | 84.13% Paging File free<br />
Paging file location(s): C:\pagefile.sys 0 0 [binary data]<br />
 <br />
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files<br />
Drive C: | 74.50 Gb Total Space | 18.00 Gb Free Space | 24.16% Space Free | Partition Type: NTFS<br />
Drive E: | 69.50 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS<br />
 <br />
Computer Name: MARRIER-0425E80 | User Name: Marrier | Logged in as Administrator.<br />
Boot Mode: Normal | Scan Mode: Current user<br />
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days<br />
 <br />
<span style="color: #E56717;">========== Processes (SafeList) ==========</span><br />
 <br />
PRC - C:\Documents and Settings\Marrier\My Documents\Downloads\OTL.exe (OldTimer Tools)<br />
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)<br />
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)<br />
PRC - C:\Program Files\Norton Internet Security\Engine\20.3.1.22\ccsvchst.exe (Symantec Corporation)<br />
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe (Safer-Networking Ltd.)<br />
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)<br />
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)<br />
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)<br />
PRC - C:\Program Files\Pando Networks\Media Booster\PMB.exe ()<br />
PRC - C:\Program Files\Norton Safe Web Lite\Engine\2.0.0.16\ccSvcHst.exe (Symantec Corporation)<br />
PRC - C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)<br />
PRC - C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher GUI.exe (r2 studios)<br />
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)<br />
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)<br />
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)<br />
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)<br />
 <br />
 <br />
<span style="color: #E56717;">========== Modules (No Company Name) ==========</span><br />
 <br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll&#8203; ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\Syst&#8203;em.Configuration.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Dra&#8203;wing.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\S&#8203;ystem.Runtime.Remoting.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\S&#8203;ystem.EnterpriseServices.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll&#8203; ()<br />
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.&#8203;Transactions.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\Sys&#8203;tem.ServiceProcess.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\Syst&#8203;em.Windows.Forms.dll ()<br />
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()<br />
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()<br />
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\d7ee03714420&#8203;b252415b952d40ef59e4\System.ServiceProcess.ni.dll ()<br />
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\aeac298c43c77d8860db8e7634&#8203;d9f2eb\System.ni.dll ()<br />
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\eab2340ead8e1a84bdf1a878&#8203;68659979\mscorlib.ni.dll ()<br />
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()<br />
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()<br />
MOD - C:\Program Files\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ()<br />
MOD - C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()<br />
MOD - C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl ()<br />
MOD - C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll ()<br />
MOD - C:\Program Files\Norton Internet Security\Engine\20.3.1.22\wincfi39.dll ()<br />
MOD - C:\Program Files\Pando Networks\Media Booster\PMB.exe ()<br />
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()<br />
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServiceP&#8203;lugin\2.1.72.22__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateSer&#8203;vicePlugin.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateService&#8203;Worker\2.1.72.22__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateS&#8203;erviceWorker.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\2.1.72.22__540d481&#8203;6ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\2.1.72.22__540d&#8203;4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\2.1.72.22__540d481&#8203;6ead86321\Intuit.Spc.Esd.Client.DataAccess.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\2.1.72.22__540d4816ead&#8203;86321\Intuit.Spc.Esd.Client.Common.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\2.0.145.4__540d4816ead86321\Int&#8203;uit.Spc.Esd.Core.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\4.0.114.0__&#8203;7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\4.0.114.0__7ce6deabcb36a8ea&#8203;\Intuit.Spc.Map.Reporter.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_32\System.Data.SQLite\1.0.56.0__28c9bcd4dddc48a1\System.&#8203;Data.SQLite.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Portability\3.1.2.2__540d481&#8203;6ead86321\Intuit.Spc.Foundations.Portability.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Primary.Config\3.1.2.2__540d&#8203;4816ead86321\Intuit.Spc.Foundations.Primary.Config.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Primary.ExceptionHandling\3.&#8203;1.2.2__540d4816ead86321\Intuit.Spc.Foundations.Primary.ExceptionHandling.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Primary.Logging\3.1.2.2__540&#8203;d4816ead86321\Intuit.Spc.Foundations.Primary.Logging.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService\&#8203;1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.dll&#8203; ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService.&#8203;PluginContract\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.Up&#8203;dateService.PluginContract.dll ()<br />
MOD - C:\WINDOWS\system32\msdmo.dll ()<br />
 <br />
 <br />
<span style="color: #E56717;">========== Services (SafeList) ==========</span><br />
 <br />
SRV - (StumbleUponUpdateService) -- C:\Program Files\StumbleUpon\StumbleUponUpdateService.exe File not found<br />
SRV - (Sleepy) -- C:\Program Files\Sleepy\service.exe File not found<br />
SRV - (SDWSCService) -- C:\Program Files\Spybot File not found<br />
SRV - (SDUpdateService) -- C:\Program Files\Spybot File not found<br />
SRV - (SDScannerService) -- C:\Program Files\Spybot File not found<br />
SRV - (AppMgmt) -- %SystemRoot%\System32\appmgmts.dll File not found<br />
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)<br />
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)<br />
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)<br />
SRV - (NIS) -- C:\Program Files\Norton Internet Security\Engine\20.3.1.22\ccSvcHst.exe (Symantec Corporation)<br />
SRV - (NSL) -- C:\Program Files\Norton Safe Web Lite\Engine\2.0.0.16\ccSvcHst.exe (Symantec Corporation)<br />
SRV - (nosGetPlusHelper) -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)<br />
SRV - (MatSvc) -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation)<br />
SRV - (npggsvc) -- C:\WINDOWS\system32\GameMon.des (INCA Internet Co., Ltd.)<br />
SRV - (IntuitUpdateService) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)<br />
SRV - (GoToAssist) -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)<br />
 <br />
 <br />
<span style="color: #E56717;">========== Driver Services (SafeList) ==========</span><br />
 <br />
DRV - (WDICA) --  File not found<br />
DRV - (LVUSBSta) -- system32\drivers\LVUSBSta.sys File not found<br />
DRV - (dump_wmimmc) -- C:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys File not found<br />
DRV - (hitmanpro37) -- C:\WINDOWS\system32\drivers\hitmanpro37.sys ()<br />
DRV - (BHDrvx86) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\BASHDefs\20130515.001\BHDrvx86.sys (Symantec Corporation)<br />
DRV - (SymEvent) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)<br />
DRV - (NAVEX15) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\VirusDefs\20130520.003\NAVEX15.SYS (Symantec Corporation)<br />
DRV - (NAVENG) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\VirusDefs\20130520.003\NAVENG.SYS (Symantec Corporation)<br />
DRV - (IDSxpx86) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\IPSDefs\20130517.001\IDSXpx86.sys (Symantec Corporation)<br />
DRV - (SYMTDI) -- C:\WINDOWS\system32\drivers\NIS\1403010.016\symtdi.sys (Symantec Corporation)<br />
DRV - (SymEFA) -- C:\WINDOWS\system32\drivers\NIS\1403010.016\symefa.sys (Symantec Corporation)<br />
DRV - (SRTSP) -- C:\WINDOWS\system32\drivers\NIS\1403010.016\srtsp.sys (Symantec Corporation)<br />
DRV - (SRTSPX) -- C:\WINDOWS\system32\drivers\NIS\1403010.016\srtspx.sys (Symantec Corporation)<br />
DRV - (SymDS) -- C:\WINDOWS\system32\drivers\NIS\1403010.016\symds.sys (Symantec Corporation)<br />
DRV - (SymIRON) -- C:\WINDOWS\system32\drivers\NIS\1403010.016\ironx86.sys (Symantec Corporation)<br />
DRV - (ccSet_NIS) -- C:\WINDOWS\system32\drivers\NIS\1403010.016\ccsetx86.sys (Symantec Corporation)<br />
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)<br />
DRV - (ccSet_NST) -- C:\WINDOWS\system32\drivers\NST\0200000.010\ccSetx86.sys (Symantec Corporation)<br />
DRV - (PnkBstrK) -- C:\WINDOWS\system32\drivers\PnkBstrK.sys ()<br />
DRV - (LADF_RenderOnly) -- C:\WINDOWS\system32\drivers\ladfGSRi386.sys (Logitech)<br />
DRV - (LADF_CaptureOnly) -- C:\WINDOWS\system32\drivers\ladfGSCi386.sys (Logitech)<br />
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)<br />
DRV - (AtiHDAudioService) -- C:\WINDOWS\system32\drivers\AtihdXP3.sys (ATI Technologies, Inc.)<br />
DRV - (LGVirHid) -- C:\WINDOWS\system32\drivers\LGVirHid.sys (Logitech Inc.)<br />
DRV - (LGBusEnum) -- C:\WINDOWS\system32\drivers\LGBusEnum.sys (Logitech Inc.)<br />
DRV - (AtiHdmiService) -- C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)<br />
DRV - (fssfltr) -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)<br />
DRV - (PID_PEPI) -- C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)<br />
DRV - (epmntdrv) -- C:\WINDOWS\system32\epmntdrv.sys ()<br />
DRV - (EuGdiDrv) -- C:\WINDOWS\system32\EuGdiDrv.sys ()<br />
DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)<br />
DRV - (NPPTNT2) -- C:\WINDOWS\system32\npptNT2.sys (INCA Internet Co., Ltd.)<br />
DRV - (HSFHWBS2) -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)<br />
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)<br />
DRV - (HSF_DP) -- C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)<br />
 <br />
 <br />
<span style="color: #E56717;">========== Standard Registry (SafeList) ==========</span><br />
 <br />
 <br />
<span style="color: #E56717;">========== Internet Explorer ==========</span><br />
 <br />
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = <a href="http://www.google.com/ie" target="_blank">http://www.google.com/ie</a><br />
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = <a href="http://www.google.com/ie" target="_blank">http://www.google.com/ie</a><br />
IE - HKLM\..\SearchScopes,DefaultScope = <br />
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = <a href="http://www.bing.com/search" target="_blank">http://www.bing.com/search</a><br />
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = <a href="http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7" target="_blank">http://www.google.com/search?q={searchTe...urceid=ie7</a><br />
 <br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://www.google.com/ie" target="_blank">http://www.google.com/ie</a><br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = <a href="http://www.google.com" target="_blank">http://www.google.com</a><br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = <a href="http://www.google.com/search?q=%7BsearchTerms%7D&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8" target="_blank">http://www.google.com/search?q={searchTe...f8&oe=utf8</a><br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.google.com" target="_blank">http://www.google.com</a><br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = <a href="http://www.google.com/ie" target="_blank">http://www.google.com/ie</a><br />
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}<br />
IE - HKCU\..\SearchScopes\{04DA659F-89F0-4FDE-B413-86118C8649B8}: "URL" = <a href="http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=382950&p=%7BsearchTerms%7D" target="_blank">http://search.yahoo.com/search?fr=chr-gr...archTerms}</a><br />
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = <a href="http://www.bing.com/search?q=%7BsearchTerms%7D&src=IE-SearchBox&FORM=IE8SRC" target="_blank">http://www.bing.com/search?q={searchTerm...ORM=IE8SRC</a><br />
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = <a href="http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7&rlz=1I7GPCK_en" target="_blank">http://www.google.com/search?q={searchTe...1I7GPCK_en</a><br />
IE - HKCU\..\SearchScopes\{E6AF6939-8D25-4996-AA92-EA85F1BD3B43}: "URL" = <a href="http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7&rlz=1I7GPCK_en" target="_blank">http://www.google.com/search?q={searchTe...1I7GPCK_en</a><br />
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0<br />
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local<br />
 <br />
<span style="color: #E56717;">========== FireFox ==========</span><br />
 <br />
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=382950"<br />
FF - prefs.js..browser.search.selectedEngine: "Google"<br />
FF - prefs.js..browser.search.useDBForOrder: true<br />
FF - prefs.js..browser.startup.homepage: "http://corner.bigblueinteractive.com/index.php"<br />
FF - prefs.js..extensions.enabledAddons: plugin%40vfd.com:1.5<br />
FF - prefs.js..extensions.enabledAddons: %7BAE93811A-5C9A-4d34-8462-F7B864FC4696%7D:4.16<br />
FF - prefs.js..extensions.enabledAddons: smarterwiki%40wikiatic.com:5.1.3<br />
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0033-ABCDEFFEDCBA%7D:6.0.33<br />
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0035-ABCDEFFEDCBA%7D:6.0.35<br />
FF - prefs.js..extensions.enabledAddons: %7BBBDA0591-3099-440a-AA10-41764D9DB4DB%7D:11.3.0.9%20-%205<br />
FF - prefs.js..extensions.enabledAddons: %7B2D3F3651-74B9-4795-BDEC-6DA2F431CB62%7D:2013.3.5.1<br />
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1<br />
FF - prefs.js..extensions.enabledItems: iobit@mybrowserbar.com:4.1<br />
FF - prefs.js..extensions.enabledItems: wtxpcom@mybrowserbar.com:4.1<br />
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.91<br />
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0<br />
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:5.6<br />
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0<br />
FF - prefs.js..extensions.enabledItems: smarterwiki@wikiatic.com:4.3.7<br />
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.5<br />
FF - prefs.js..extensions.enabledItems: yyginstantplay@yoyogames.com:1.1.0.24<br />
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24<br />
FF - prefs.js..extensions.enabledItems: {1DEAE5AA-E19E-458b-9C8C-73CB651B9A58}:3.6<br />
FF - user.js - File not found<br />
 <br />
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()<br />
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)<br />
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found<br />
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()<br />
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)<br />
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)<br />
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)<br />
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)<br />
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)<br />
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)<br />
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+&reg;,version=1.6.2.91: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.)<br />
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)<br />
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)<br />
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)<br />
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)<br />
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)<br />
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)<br />
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)<br />
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Marrier\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)<br />
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Documents and Settings\Marrier\Application Data\Mozilla\plugins\npo1d.dll (Google)<br />
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Marrier\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()<br />
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)<br />
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)<br />
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)<br />
 <br />
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\Documents and Settings\All Users\Application Data\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2.0.0.16\coFFNST\<br />
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\coFFPlgn\ [2013/05/20 18:08:14 | 000,000,000 | ---D | M]<br />
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\IPSFFPlgn\ [2013/03/04 16:23:51 | 000,000,000 | ---D | M]<br />
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/05/19 15:34:17 | 000,000,000 | ---D | M]<br />
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/19 15:49:22 | 000,000,000 | ---D | M]<br />
 <br />
[2012/02/15 21:32:23 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Extensions<br />
[2009/06/13 21:04:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Extensions\mozswing@mozswing.org<br />
[2013/05/16 19:20:47 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Firefox\Profiles\thtksfry.default\extensions<br />
[2012/05/23 16:47:40 | 000,000,000 | ---D | M] (Orange Fox) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Firefox\Profiles\thtksfry.default\extensions\{5b35cb30-16b4-11de-8c30-0800200c9a66}<br />
[2012/08/24 20:03:34 | 000,000,000 | ---D | M] (VideoFileDownload - Download YouTube Videos) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Firefox\Profiles\thtksfry.default\extensions\plugin@vfd.com<br />
[2013/04/05 16:26:23 | 000,361,682 | ---- | M] () (No name found) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Firefox\Profiles\thtksfry.default\extensions\smarterwiki@wikiatic.c&#8203;om.xpi<br />
[2012/08/01 17:50:19 | 001,675,213 | ---- | M] () (No name found) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Firefox\Profiles\thtksfry.default\extensions\{1DEAE5AA-E19E-458b-9C8C-73CB651B9A58}.xpi<br />
[2012/12/30 17:18:43 | 000,377,738 | ---- | M] () (No name found) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Firefox\Profiles\thtksfry.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi<br />
[2013/05/08 15:43:26 | 000,870,680 | ---- | M] () (No name found) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Firefox\Profiles\thtksfry.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi<br />
[2013/04/13 16:51:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions<br />
[2013/04/13 16:51:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}<br />
[2013/04/13 16:51:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}<br />
[2013/04/13 16:51:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}<br />
[2013/05/20 18:08:14 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\COFFPLGN<br />
[2013/03/04 16:23:51 | 000,000,000 | ---D | M] (Norton Vulnerability Protection) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\IPSFFPLGN<br />
[2013/04/13 16:52:07 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll<br />
[2008/06/30 14:44:08 | 000,324,976 | ---- | M] (Symantec Corporation) -- C:\Program Files\mozilla firefox\components\coFFPlgn.dll<br />
[2012/08/29 18:22:50 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml<br />
[2013/03/04 15:47:57 | 000,002,086 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml<br />
 <br />
<span style="color: #E56717;">========== Chrome  ==========</span><br />
 <br />
CHR - default_search_provider: Search Results (Enabled)<br />
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl&#8203;e:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}<br />
CHR - default_search_provider: suggest_url = <br />
CHR - homepage: <a href="http://corner.bigblueinteractive.com/index.php" target="_blank">http://corner.bigblueinteractive.com/index.php</a><br />
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer<br />
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll<br />
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\pdf.dll<br />
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\gcswf32.dll<br />
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll<br />
CHR - plugin: Norton Confidential (Enabled) = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.3.7_0\npcoplgn.d&#8203;ll<br />
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\Marrier\Application Data\Mozilla\plugins\npgoogletalk.dll<br />
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\Marrier\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll<br />
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll<br />
CHR - plugin: Coupons Inc., Coupon Printer Manager  (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll<br />
CHR - plugin: Coupons Inc., Coupon Printer Manager  (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll<br />
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll<br />
CHR - plugin: Java&#153; Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll<br />
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll<br />
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll<br />
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll<br />
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll<br />
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll<br />
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll<br />
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll<br />
CHR - plugin: getPlusPlus for Adobe 16291 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np_gp.dll<br />
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll<br />
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll<br />
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll<br />
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll<br />
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll<br />
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll<br />
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll<br />
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll<br />
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll<br />
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll<br />
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll<br />
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll<br />
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll<br />
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll<br />
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll<br />
CHR - Extension: Angry Birds = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\<br />
CHR - Extension: Solitaire Games = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\eljmkmbmhmgmpmmbkagbobpmpocacdbo\1.0.0.3_0\<br />
CHR - Extension: Bubble Shooter -HD = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hpakbhbnhkbghdcejiiangcefallmaln\2.2.0_0\<br />
CHR - Extension: StumbleUpon = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg\5.3.7.1_0\<br />
CHR - Extension: Norton Identity Protection = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.3.3.19_0\<br />
 <br />
O1 HOSTS File: ([2013/05/06 14:38:38 | 000,445,361 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS<br />
O1 - Hosts: 127.0.0.1	localhost<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.007guard.com" target="_blank">http://www.007guard.com</a><br />
O1 - Hosts: 127.0.0.1	007guard.com<br />
O1 - Hosts: 127.0.0.1	008i.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.008k.com" target="_blank">http://www.008k.com</a><br />
O1 - Hosts: 127.0.0.1	008k.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.00hq.com" target="_blank">http://www.00hq.com</a><br />
O1 - Hosts: 127.0.0.1	00hq.com<br />
O1 - Hosts: 127.0.0.1	010402.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.032439.com" target="_blank">http://www.032439.com</a><br />
O1 - Hosts: 127.0.0.1	032439.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.0scan.com" target="_blank">http://www.0scan.com</a><br />
O1 - Hosts: 127.0.0.1	0scan.com<br />
O1 - Hosts: 127.0.0.1	1000gratisproben.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.1000gratisproben.com" target="_blank">http://www.1000gratisproben.com</a><br />
O1 - Hosts: 127.0.0.1	1001namen.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.1001namen.com" target="_blank">http://www.1001namen.com</a><br />
O1 - Hosts: 127.0.0.1	100888290cs.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.100888290cs.com" target="_blank">http://www.100888290cs.com</a><br />
O1 - Hosts: 127.0.0.1	<a href="http://www.100sexlinks.com" target="_blank">http://www.100sexlinks.com</a><br />
O1 - Hosts: 127.0.0.1	100sexlinks.com<br />
O1 - Hosts: 127.0.0.1	10sek.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.10sek.com" target="_blank">http://www.10sek.com</a><br />
O1 - Hosts: 127.0.0.1	<a href="http://www.1-2005-search.com" target="_blank">http://www.1-2005-search.com</a><br />
O1 - Hosts: 127.0.0.1	1-2005-search.com<br />
O1 - Hosts: 15296 more lines...<br />
O2 - BHO: (StumbleUpon Launcher) - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll File not found<br />
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.<br />
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.3.1.22\coieplg.dll (Symantec Corporation)<br />
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.3.1.22\ips\ipsbho.dll (Symantec Corporation)<br />
O2 - BHO: (Java&#153; Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)<br />
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)<br />
O2 - BHO: (Java&#153; Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)<br />
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.<br />
O3 - HKLM\..\Toolbar: (no name) - !{30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - No CLSID value found.<br />
O3 - HKLM\..\Toolbar: (no name) - !{8dcb7100-df86-4384-8842-8fa844297b3f} - No CLSID value found.<br />
O3 - HKLM\..\Toolbar: (StumbleUpon Toolbar) - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll File not found<br />
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.3.1.22\coieplg.dll (Symantec Corporation)<br />
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.<br />
O4 - HKLM..\Run: [AdmTask] C:\Program Files\AdmTask\admtask.exe (LexoSoft Inc.)<br />
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found<br />
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)<br />
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)<br />
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)<br />
O4 - HKLM..\Run: [StartupDelayer] C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher GUI.exe (r2 studios)<br />
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()<br />
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)<br />
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled [2009/06/14 15:05:45 | 000,000,000 | -H-D | M]<br />
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present<br />
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1<br />
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0<br />
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1<br />
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255<br />
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0<br />
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()<br />
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()<br />
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()<br />
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()<br />
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage File not found<br />
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)<br />
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)<br />
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} <a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/2008...oader5.cab</a> (Facebook Photo Uploader 5 Control)<br />
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} <a href="http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab" target="_blank">http://messenger.zone.msn.com/binary/msg...b56986.cab</a> (Checkers Class)<br />
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} <a href="http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab" target="_blank">http://download.microsoft.com/download/e...vc1dmo.cab</a> (Reg Error: Value error.)<br />
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} <a href="http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab" target="_blank">http://messenger.zone.msn.com/EN-US/a-UN...E_UNO1.cab</a> (UnoCtrl Class)<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} <a href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1219106024718" target="_blank">http://www.update.microsoft.com/windowsu...9106024718</a> (WUWebControl Class)<br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} <a href="http://download.divx.com/player/DivXBrowserPlugin.cab" target="_blank">http://download.divx.com/player/DivXBrowserPlugin.cab</a> (DivXBrowserPlugin Object)<br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" target="_blank">http://upload.facebook.com/controls/2009...ader55.cab</a> (Facebook Photo Uploader 5 Control)<br />
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jinstal...s-i586.cab</a> (Java Plug-in 10.21.2)<br />
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <a href="http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab" target="_blank">http://fpdownload.macromedia.com/get/fla...rashim.cab</a> (Reg Error: Value error.)<br />
O16 - DPF: {994CF098-73ED-4C83-B227-B15F2A8D6177} <a href="https://www.d-life.com/D-Life//DLCUALibrary.cab" target="_blank">https://www.d-life.com/D-Life//DLCUALibrary.cab</a> (CTUADriverWrapperCtrl Object)<br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} <a href="http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab" target="_blank">http://messenger.zone.msn.com/binary/ZIn...b56649.cab</a> (MSN Games - Installer)<br />
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} <a href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab" target="_blank">http://messenger.zone.msn.com/binary/Mes...b56907.cab</a> (MessengerStatsClient Class)<br />
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jinstal...s-i586.cab</a> (Reg Error: Key error.)<br />
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jinstal...s-i586.cab</a> (Java Plug-in 1.6.0_07)<br />
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jinstal...s-i586.cab</a> (Java Plug-in 10.21.2)<br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} <a href="http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/get/fl...wflash.cab</a> (Shockwave Flash Object)<br />
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} <a href="http://messenger.zone.msn.com/binary/WoF.cab57176.cab" target="_blank">http://messenger.zone.msn.com/binary/WoF.cab57176.cab</a> (WheelofFortune Object)<br />
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}  (Reg Error: Value error.)<br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a> (get_atlcom Class)<br />
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} <a href="https://cincinnati.connectge.com/dana-cached/setup/JuniperSetupSP1.cab" target="_blank">https://cincinnati.connectge.com/dana-ca...tupSP1.cab</a> (JuniperSetupControlXP Class)<br />
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} <a href="http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.3.1.0.cab" target="_blank">http://content.systemrequirementslab.com....3.1.0.cab</a> (Reg Error: Value error.)<br />
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} <a href="https://cincinnati.connectge.com/dana-cached/sc/JuniperSetupClient.cab" target="_blank">https://cincinnati.connectge.com/dana-ca...Client.cab</a> (JuniperSetupClientControl Class)<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3AABA5FE-995A-4EBB-9BAB-0AE8F49BE23D}: DhcpNameServer = 75.75.75.75 75.75.76.76<br />
O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found<br />
O18 - Protocol\Handler\AutorunsDisabled\skype4com - No CLSID value found<br />
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)<br />
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)<br />
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)<br />
O20 - Winlogon\Notify\AutorunsDisabled: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found<br />
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) -  File not found<br />
O24 - Desktop Components:0 () - <br />
O24 - Desktop WallPaper: C:\Documents and Settings\Marrier\Local Settings\Application Data\Microsoft\Wallpaper1.bmp<br />
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Marrier\Local Settings\Application Data\Microsoft\Wallpaper1.bmp<br />
O32 - HKLM CDRom: AutoRun - 1<br />
O32 - AutoRun File - [2008/08/18 19:27:57 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]<br />
O32 - AutoRun File - [2013/05/11 16:02:36 | 002,431,246 | ---- | M] () - C:\AutoRuns.arn -- [ NTFS ]<br />
O32 - AutoRun File - [2011/11/05 13:52:32 | 000,049,648 | ---- | M] () - C:\autoruns.chm -- [ NTFS ]<br />
O32 - AutoRun File - [2012/09/10 09:16:28 | 000,649,864 | ---- | M] (Sysinternals - <a href="http://www.sysinternals.com" target="_blank">http://www.sysinternals.com</a>) - C:\autoruns.exe -- [ NTFS ]<br />
O32 - AutoRun File - [2012/09/10 09:16:28 | 000,567,944 | ---- | M] (Sysinternals - <a href="http://www.sysinternals.com" target="_blank">http://www.sysinternals.com</a>) - C:\autorunsc.exe -- [ NTFS ]<br />
O32 - AutoRun File - [2003/11/19 06:16:26 | 000,000,056 | R--- | M] () - E:\Autorun.inf -- [ CDFS ]<br />
O33 - MountPoints2\{20cebf6d-73c4-11dd-8229-0019d1987999}\Shell\AutoRun\command - "" = wscript.exe \SMRTNTKY\script.js<br />
O33 - MountPoints2\{4d87a803-faf1-11dd-833b-0019d1987999}\Shell\AutoRun\command - "" = F:\setupSNK.exe<br />
O33 - MountPoints2\{bcc8dff9-1cd0-11de-836d-0019d1987999}\Shell\AutoRun\command - "" = F:\setupSNK.exe<br />
O33 - MountPoints2\{bde3c206-f2d0-11df-8633-0019d1987999}\Shell\AutoRun\command - "" = F:\DPVSETUP.EXE<br />
O34 - HKLM BootExecute: (autocheck autochk *)<br />
O35 - HKLM\..comfile [open] -- "%1" %*<br />
O35 - HKLM\..exefile [open] -- "%1" %*<br />
O37 - HKLM\...com [@ = comfile] -- "%1" %*<br />
O37 - HKLM\...exe [@ = exefile] -- "%1" %*<br />
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)<br />
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)<br />
 <br />
<span style="color: #E56717;">========== Files/Folders - Created Within 30 Days ==========</span><br />
 <br />
[2013/05/20 17:47:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HitmanPro<br />
[2013/05/19 15:48:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT<br />
[2013/05/19 15:48:26 | 000,000,000 | ---D | C] -- C:\JRT<br />
[2013/05/16 19:27:34 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Marrier\Recent<br />
[2013/05/16 19:21:05 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group<br />
[2013/05/16 19:21:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marrier\Start Menu\Programs\Revo Uninstaller<br />
[2013/05/06 12:13:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy 2<br />
[2013/05/06 12:13:44 | 000,015,224 | ---- | C] (Safer Networking Limited) -- C:\WINDOWS\System32\sdnclean.exe<br />
[2013/05/06 12:13:38 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy 2<br />
[2013/05/06 12:09:47 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe<br />
[2013/05/06 12:09:47 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe<br />
[2013/05/06 12:09:47 | 000,094,112 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll<br />
[2013/05/06 12:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Defraggler<br />
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]<br />
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]<br />
 <br />
<span style="color: #E56717;">========== Files - Modified Within 30 Days ==========</span><br />
 <br />
[2013/05/20 18:30:15 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job<br />
[2013/05/20 18:29:00 | 000,000,888 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job<br />
[2013/05/20 18:07:56 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job<br />
[2013/05/20 18:07:56 | 000,000,620 | ---- | M] () -- C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job<br />
[2013/05/20 18:07:56 | 000,000,616 | -H-- | M] () -- C:\WINDOWS\tasks\ConfigExec.job<br />
[2013/05/20 18:07:53 | 000,030,464 | ---- | M] () -- C:\WINDOWS\System32\drivers\hitmanpro37.sys<br />
[2013/05/20 18:07:49 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat<br />
[2013/05/20 18:00:30 | 000,000,908 | ---- | M] () -- C:\WINDOWS\System32\.crusader<br />
[2013/05/20 17:52:00 | 000,000,986 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1844237615-725345543-1004UA.job<br />
[2013/05/20 17:00:00 | 000,000,580 | -H-- | M] () -- C:\WINDOWS\tasks\DataUpload.job<br />
[2013/05/20 13:52:00 | 000,000,934 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1844237615-725345543-1004Core.job<br />
[2013/05/20 11:34:00 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job<br />
[2013/05/18 11:53:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job<br />
[2013/05/16 19:28:15 | 000,024,776 | ---- | M] () -- C:\Documents and Settings\Marrier\My Documents\cc_20130516_192812.reg<br />
[2013/05/16 19:21:05 | 000,000,917 | ---- | M] () -- C:\Documents and Settings\Marrier\Desktop\Revo Uninstaller.lnk<br />
[2013/05/15 19:09:13 | 000,001,360 | ---- | M] () -- C:\WINDOWS\wininit.ini<br />
[2013/05/15 18:15:08 | 000,131,688 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT<br />
[2013/05/15 18:10:59 | 000,433,574 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat<br />
[2013/05/15 18:10:59 | 000,068,164 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat<br />
[2013/05/15 18:01:50 | 000,000,616 | ---- | M] () -- C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job<br />
[2013/05/14 22:30:11 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe<br />
[2013/05/14 22:30:11 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl<br />
[2013/05/11 22:40:47 | 000,000,751 | ---- | M] () -- C:\Documents and Settings\Marrier\Desktop\Norton Installation Files.lnk<br />
[2013/05/11 16:09:24 | 000,001,870 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\HP Photosmart Essential 3.0.lnk<br />
[2013/05/11 16:02:36 | 002,431,246 | ---- | M] () -- C:\AutoRuns.arn<br />
[2013/05/11 10:44:47 | 000,002,473 | ---- | M] () -- C:\Documents and Settings\Marrier\Desktop\Microsoft Word.lnk<br />
[2013/05/07 00:27:31 | 006,015,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll<br />
[2013/05/06 14:38:38 | 000,445,361 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS<br />
[2013/05/06 12:14:03 | 000,000,446 | ---- | M] () -- C:\WINDOWS\tasks\Scan the system (Spybot - Search & Destroy).job<br />
[2013/05/06 12:13:52 | 000,001,836 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Spybot-S&D Start Center.lnk<br />
[2013/05/06 12:06:21 | 000,001,632 | ---- | M] () -- C:\Documents and Settings\Marrier\Desktop\Update Checker.lnk<br />
[2013/05/06 12:04:22 | 000,001,580 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Defraggler.lnk<br />
[2013/05/06 12:03:36 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk<br />
[2013/05/04 11:39:09 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl<br />
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]<br />
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]<br />
 <br />
<span style="color: #E56717;">========== Files Created - No Company Name ==========</span><br />
 <br />
[2013/05/20 18:07:53 | 000,030,464 | ---- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro37.sys<br />
[2013/05/20 18:00:30 | 000,000,908 | ---- | C] () -- C:\WINDOWS\System32\.crusader<br />
[2013/05/16 19:28:13 | 000,024,776 | ---- | C] () -- C:\Documents and Settings\Marrier\My Documents\cc_20130516_192812.reg<br />
[2013/05/16 19:21:05 | 000,000,917 | ---- | C] () -- C:\Documents and Settings\Marrier\Desktop\Revo Uninstaller.lnk<br />
[2013/05/11 22:40:45 | 000,000,751 | ---- | C] () -- C:\Documents and Settings\Marrier\Desktop\Norton Installation Files.lnk<br />
[2013/05/06 12:14:02 | 000,000,620 | ---- | C] () -- C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job<br />
[2013/05/06 12:14:02 | 000,000,616 | ---- | C] () -- C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job<br />
[2013/05/06 12:14:02 | 000,000,446 | ---- | C] () -- C:\WINDOWS\tasks\Scan the system (Spybot - Search & Destroy).job<br />
[2013/05/06 12:13:53 | 000,001,842 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot-S&D Start Center.lnk<br />
[2013/05/06 12:13:52 | 000,001,836 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Spybot-S&D Start Center.lnk<br />
[2012/02/15 21:32:24 | 000,001,360 | ---- | C] () -- C:\WINDOWS\wininit.ini<br />
[2012/02/14 18:43:15 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll<br />
[2012/02/01 19:35:56 | 000,076,360 | ---- | C] () -- C:\WINDOWS\System32\ladfGSRCoinst_i386.dll<br />
[2011/01/04 17:28:20 | 000,001,940 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini<br />
[2010/01/18 19:26:16 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Marrier\Ÿ9Ÿ9<br />
[2008/12/23 20:00:13 | 000,735,889 | ---- | C] () -- C:\Documents and Settings\Marrier\Application Data\pbsetup.zip<br />
[2008/12/23 19:47:55 | 000,674,600 | ---- | C] () -- C:\Program Files\pbsvc.exe<br />
[2008/12/23 18:22:16 | 000,138,056 | ---- | C] () -- C:\Documents and Settings\Marrier\Application Data\PnkBstrK.sys<br />
[2008/12/23 02:47:15 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\Marrier\__Call Of Duty 4 - Modern Warfare Multiplayer<br />
 <br />
<span style="color: #E56717;">========== ZeroAccess Check ==========</span><br />
 <br />
[2008/12/22 23:14:12 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini<br />
 <br />
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]<br />
 <br />
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]<br />
 <br />
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]<br />
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 20:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)<br />
"ThreadingModel" = Apartment<br />
 <br />
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]<br />
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 08:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)<br />
"ThreadingModel" = Free<br />
 <br />
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]<br />
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/13 20:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)<br />
"ThreadingModel" = Both<br />
 <br />
<span style="color: #E56717;">========== LOP Check ==========</span><br />
 <br />
[2013/03/09 13:05:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1<br />
[2008/08/19 00:26:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore<br />
[2010/12/03 00:03:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo<br />
[2012/05/28 11:21:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BOINC<br />
[2008/08/22 11:00:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ<br />
[2008/08/18 19:41:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Citrix<br />
[2010/12/25 22:00:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreeApp<br />
[2013/05/20 18:00:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HitmanPro<br />
[2009/08/12 21:16:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ijjigame<br />
[2010/11/27 12:34:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Innovative Solutions<br />
[2010/12/25 22:00:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit<br />
[2010/12/06 19:30:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Juniper Networks<br />
[2009/02/14 13:32:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Linksys<br />
[2009/11/16 21:56:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Metacafe<br />
[2011/04/18 20:12:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData<br />
[2009/11/21 20:03:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound<br />
[2010/02/12 21:31:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters<br />
[2008/10/12 12:49:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCSettings<br />
[2012/02/01 20:51:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files<br />
[2010/12/05 15:03:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\r2 Studios<br />
[2009/12/19 22:11:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TelTel<br />
[2009/03/17 21:51:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP<br />
[2008/08/30 17:12:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\utilinkl<br />
[2009/03/18 17:18:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}<br />
[2010/04/08 19:32:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}<br />
[2009/10/29 18:02:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}<br />
[2009/03/18 14:15:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}<br />
[2009/06/09 20:33:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}<br />
[2008/08/19 00:27:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\acccore<br />
[2009/08/27 17:38:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Amazon<br />
[2010/12/03 00:05:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Ashampoo<br />
[2010/12/03 00:34:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\BitTorrent<br />
[2009/10/10 20:11:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Blitware<br />
[2008/11/08 21:11:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1<br />
[2010/11/27 10:52:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\DeviceDoctorSoftware<br />
[2011/09/22 19:13:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\FileZilla<br />
[2009/06/08 18:41:38 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Marrier\Application Data\ijjigame<br />
[2011/09/21 08:37:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Juniper Networks<br />
[2008/11/05 20:08:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Leadertech<br />
[2009/07/23 20:39:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\LimeWire<br />
[2011/08/19 16:16:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\LolClient<br />
[2011/02/13 19:22:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Marine Aquarium 3<br />
[2010/12/05 15:03:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\r2 Studios<br />
[2009/11/23 17:54:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\TeamViewer<br />
[2009/12/19 22:15:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\TelTel<br />
[2010/03/15 19:18:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Tific<br />
[2012/04/05 18:32:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\TS3Client<br />
[2010/02/03 23:35:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Uniblue<br />
[2011/04/09 20:29:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\uTorrent<br />
[2010/10/25 01:47:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\WeGame<br />
[2008/11/08 21:19:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\zweitgeist<br />
 <br />
<span style="color: #E56717;">========== Purity Check ==========</span><br />
 <br />
 <br />
 <br />
<span style="color: #E56717;">========== Alternate Data Streams ==========</span><br />
 <br />
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2<br />
<br />
< End of report ><br />
OTL Extras logfile created on: 5/20/2013 6:41:12 PM - Run 1<br />
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Documents and Settings\Marrier\My Documents\Downloads<br />
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation<br />
Internet Explorer (Version = 8.0.6001.18702)<br />
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br />
 <br />
2.99 Gb Total Physical Memory | 1.87 Gb Available Physical Memory | 62.54% Memory free<br />
5.82 Gb Paging File | 4.90 Gb Available in Paging File | 84.13% Paging File free<br />
Paging file location(s): C:\pagefile.sys 0 0 [binary data]<br />
 <br />
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files<br />
Drive C: | 74.50 Gb Total Space | 18.00 Gb Free Space | 24.16% Space Free | Partition Type: NTFS<br />
Drive E: | 69.50 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS<br />
 <br />
Computer Name: MARRIER-0425E80 | User Name: Marrier | Logged in as Administrator.<br />
Boot Mode: Normal | Scan Mode: Current user<br />
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days<br />
 <br />
<span style="color: #E56717;">========== Extra Registry (SafeList) ==========</span><br />
 <br />
 <br />
<span style="color: #E56717;">========== File Associations ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]<br />
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*<br />
 <br />
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]<br />
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)<br />
 <br />
<span style="color: #E56717;">========== Shell Spawning ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]<br />
batfile [open] -- "%1" %*<br />
cmdfile [open] -- "%1" %*<br />
comfile [open] -- "%1" %*<br />
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*<br />
exefile [open] -- "%1" %*<br />
htmlfile [edit] -- Reg Error: Key error.<br />
piffile [open] -- "%1" %*<br />
regfile [merge] -- Reg Error: Key error.<br />
scrfile [config] -- "%1"<br />
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l<br />
scrfile [open] -- "%1" /S<br />
txtfile [edit] -- Reg Error: Key error.<br />
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1<br />
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br />
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)<br />
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)<br />
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br />
 <br />
<span style="color: #E56717;">========== Security Center Settings ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]<br />
"FirstRunDisabled" = 1<br />
"AntiVirusDisableNotify" = 0<br />
"FirewallDisableNotify" = 0<br />
"UpdatesDisableNotify" = 0<br />
"AntiVirusOverride" = 0<br />
"FirewallOverride" = 0<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]<br />
"DisableMonitoring" = 1<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]<br />
"DisableMonitoring" = 1<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]<br />
"DisableMonitoring" = 1<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]<br />
 <br />
<span style="color: #E56717;">========== System Restore Settings ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]<br />
"DisableSR" = 0<br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]<br />
"Start" = 0<br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]<br />
"Start" = 2<br />
 <br />
<span style="color: #E56717;">========== Firewall Settings ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir&#8203;ewallPolicy\DomainProfile]<br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir&#8203;ewallPolicy\DomainProfile\GloballyOpenPorts\List]<br />
"57915:TCP" = 57915:TCP:*:Enabled:Pando Media Booster<br />
"57915:UDP" = 57915:UDP:*:Enabled:Pando Media Booster<br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir&#8203;ewallPolicy\StandardProfile]<br />
"EnableFirewall" = 0<br />
"DoNotAllowExceptions" = 0<br />
"DisableNotifications" = 0<br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir&#8203;ewallPolicy\StandardProfile\GloballyOpenPorts\List]<br />
"57915:TCP" = 57915:TCP:*:Enabled:Pando Media Booster<br />
"57915:UDP" = 57915:UDP:*:Enabled:Pando Media Booster<br />
 <br />
<span style="color: #E56717;">========== Authorized Applications List ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir&#8203;ewallPolicy\DomainProfile\AuthorizedApplications\List]<br />
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)<br />
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)<br />
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)<br />
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()<br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir&#8203;ewallPolicy\StandardProfile\AuthorizedApplications\List]<br />
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)<br />
"C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin -- (Google)<br />
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent<br />
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)<br />
"H:\Josh\SteamApps\common\alien swarm\srcds.exe" = H:\Josh\SteamApps\common\alien swarm\srcds.exe:*:Enabled:Alien Swarm Dedicated Server<br />
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)<br />
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)<br />
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()<br />
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service -- (Apple Inc.)<br />
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)<br />
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)<br />
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.)<br />
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)<br />
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)<br />
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)<br />
 <br />
 <br />
<span style="color: #E56717;">========== HKEY_LOCAL_MACHINE Uninstall List ==========</span><br />
 <br />
[HKEY_LOCAL_MACHIN<br /><!-- start: postbit_attachments_attachment -->
<br /><img src="images/attachtypes/ppt.gif" border="0" alt=".ppt" />&nbsp;&nbsp;<a href="attachment.php?aid=4549" target="_blank">Screenshot.ppt</a> (Size: 403 KB / Downloads: 2)
<!-- end: postbit_attachments_attachment -->]]></description>
			<content:encoded><![CDATA[OTL logfile created on: 5/20/2013 6:41:12 PM - Run 1<br />
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Documents and Settings\Marrier\My Documents\Downloads<br />
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation<br />
Internet Explorer (Version = 8.0.6001.18702)<br />
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br />
 <br />
2.99 Gb Total Physical Memory | 1.87 Gb Available Physical Memory | 62.54% Memory free<br />
5.82 Gb Paging File | 4.90 Gb Available in Paging File | 84.13% Paging File free<br />
Paging file location(s): C:\pagefile.sys 0 0 [binary data]<br />
 <br />
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files<br />
Drive C: | 74.50 Gb Total Space | 18.00 Gb Free Space | 24.16% Space Free | Partition Type: NTFS<br />
Drive E: | 69.50 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS<br />
 <br />
Computer Name: MARRIER-0425E80 | User Name: Marrier | Logged in as Administrator.<br />
Boot Mode: Normal | Scan Mode: Current user<br />
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days<br />
 <br />
<span style="color: #E56717;">========== Processes (SafeList) ==========</span><br />
 <br />
PRC - C:\Documents and Settings\Marrier\My Documents\Downloads\OTL.exe (OldTimer Tools)<br />
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)<br />
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)<br />
PRC - C:\Program Files\Norton Internet Security\Engine\20.3.1.22\ccsvchst.exe (Symantec Corporation)<br />
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe (Safer-Networking Ltd.)<br />
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)<br />
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)<br />
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)<br />
PRC - C:\Program Files\Pando Networks\Media Booster\PMB.exe ()<br />
PRC - C:\Program Files\Norton Safe Web Lite\Engine\2.0.0.16\ccSvcHst.exe (Symantec Corporation)<br />
PRC - C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)<br />
PRC - C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher GUI.exe (r2 studios)<br />
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)<br />
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)<br />
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)<br />
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)<br />
 <br />
 <br />
<span style="color: #E56717;">========== Modules (No Company Name) ==========</span><br />
 <br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll&#8203; ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\Syst&#8203;em.Configuration.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Dra&#8203;wing.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\S&#8203;ystem.Runtime.Remoting.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\S&#8203;ystem.EnterpriseServices.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll&#8203; ()<br />
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.&#8203;Transactions.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\Sys&#8203;tem.ServiceProcess.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\Syst&#8203;em.Windows.Forms.dll ()<br />
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()<br />
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()<br />
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\d7ee03714420&#8203;b252415b952d40ef59e4\System.ServiceProcess.ni.dll ()<br />
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\aeac298c43c77d8860db8e7634&#8203;d9f2eb\System.ni.dll ()<br />
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\eab2340ead8e1a84bdf1a878&#8203;68659979\mscorlib.ni.dll ()<br />
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()<br />
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()<br />
MOD - C:\Program Files\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ()<br />
MOD - C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()<br />
MOD - C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl ()<br />
MOD - C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll ()<br />
MOD - C:\Program Files\Norton Internet Security\Engine\20.3.1.22\wincfi39.dll ()<br />
MOD - C:\Program Files\Pando Networks\Media Booster\PMB.exe ()<br />
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()<br />
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServiceP&#8203;lugin\2.1.72.22__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateSer&#8203;vicePlugin.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateService&#8203;Worker\2.1.72.22__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateS&#8203;erviceWorker.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\2.1.72.22__540d481&#8203;6ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\2.1.72.22__540d&#8203;4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\2.1.72.22__540d481&#8203;6ead86321\Intuit.Spc.Esd.Client.DataAccess.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\2.1.72.22__540d4816ead&#8203;86321\Intuit.Spc.Esd.Client.Common.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\2.0.145.4__540d4816ead86321\Int&#8203;uit.Spc.Esd.Core.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\4.0.114.0__&#8203;7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\4.0.114.0__7ce6deabcb36a8ea&#8203;\Intuit.Spc.Map.Reporter.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_32\System.Data.SQLite\1.0.56.0__28c9bcd4dddc48a1\System.&#8203;Data.SQLite.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Portability\3.1.2.2__540d481&#8203;6ead86321\Intuit.Spc.Foundations.Portability.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Primary.Config\3.1.2.2__540d&#8203;4816ead86321\Intuit.Spc.Foundations.Primary.Config.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Primary.ExceptionHandling\3.&#8203;1.2.2__540d4816ead86321\Intuit.Spc.Foundations.Primary.ExceptionHandling.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Primary.Logging\3.1.2.2__540&#8203;d4816ead86321\Intuit.Spc.Foundations.Primary.Logging.dll ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService\&#8203;1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.dll&#8203; ()<br />
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService.&#8203;PluginContract\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.Up&#8203;dateService.PluginContract.dll ()<br />
MOD - C:\WINDOWS\system32\msdmo.dll ()<br />
 <br />
 <br />
<span style="color: #E56717;">========== Services (SafeList) ==========</span><br />
 <br />
SRV - (StumbleUponUpdateService) -- C:\Program Files\StumbleUpon\StumbleUponUpdateService.exe File not found<br />
SRV - (Sleepy) -- C:\Program Files\Sleepy\service.exe File not found<br />
SRV - (SDWSCService) -- C:\Program Files\Spybot File not found<br />
SRV - (SDUpdateService) -- C:\Program Files\Spybot File not found<br />
SRV - (SDScannerService) -- C:\Program Files\Spybot File not found<br />
SRV - (AppMgmt) -- %SystemRoot%\System32\appmgmts.dll File not found<br />
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)<br />
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)<br />
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)<br />
SRV - (NIS) -- C:\Program Files\Norton Internet Security\Engine\20.3.1.22\ccSvcHst.exe (Symantec Corporation)<br />
SRV - (NSL) -- C:\Program Files\Norton Safe Web Lite\Engine\2.0.0.16\ccSvcHst.exe (Symantec Corporation)<br />
SRV - (nosGetPlusHelper) -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)<br />
SRV - (MatSvc) -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation)<br />
SRV - (npggsvc) -- C:\WINDOWS\system32\GameMon.des (INCA Internet Co., Ltd.)<br />
SRV - (IntuitUpdateService) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)<br />
SRV - (GoToAssist) -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)<br />
 <br />
 <br />
<span style="color: #E56717;">========== Driver Services (SafeList) ==========</span><br />
 <br />
DRV - (WDICA) --  File not found<br />
DRV - (LVUSBSta) -- system32\drivers\LVUSBSta.sys File not found<br />
DRV - (dump_wmimmc) -- C:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys File not found<br />
DRV - (hitmanpro37) -- C:\WINDOWS\system32\drivers\hitmanpro37.sys ()<br />
DRV - (BHDrvx86) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\BASHDefs\20130515.001\BHDrvx86.sys (Symantec Corporation)<br />
DRV - (SymEvent) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)<br />
DRV - (NAVEX15) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\VirusDefs\20130520.003\NAVEX15.SYS (Symantec Corporation)<br />
DRV - (NAVENG) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\VirusDefs\20130520.003\NAVENG.SYS (Symantec Corporation)<br />
DRV - (IDSxpx86) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\Definitions\IPSDefs\20130517.001\IDSXpx86.sys (Symantec Corporation)<br />
DRV - (SYMTDI) -- C:\WINDOWS\system32\drivers\NIS\1403010.016\symtdi.sys (Symantec Corporation)<br />
DRV - (SymEFA) -- C:\WINDOWS\system32\drivers\NIS\1403010.016\symefa.sys (Symantec Corporation)<br />
DRV - (SRTSP) -- C:\WINDOWS\system32\drivers\NIS\1403010.016\srtsp.sys (Symantec Corporation)<br />
DRV - (SRTSPX) -- C:\WINDOWS\system32\drivers\NIS\1403010.016\srtspx.sys (Symantec Corporation)<br />
DRV - (SymDS) -- C:\WINDOWS\system32\drivers\NIS\1403010.016\symds.sys (Symantec Corporation)<br />
DRV - (SymIRON) -- C:\WINDOWS\system32\drivers\NIS\1403010.016\ironx86.sys (Symantec Corporation)<br />
DRV - (ccSet_NIS) -- C:\WINDOWS\system32\drivers\NIS\1403010.016\ccsetx86.sys (Symantec Corporation)<br />
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)<br />
DRV - (ccSet_NST) -- C:\WINDOWS\system32\drivers\NST\0200000.010\ccSetx86.sys (Symantec Corporation)<br />
DRV - (PnkBstrK) -- C:\WINDOWS\system32\drivers\PnkBstrK.sys ()<br />
DRV - (LADF_RenderOnly) -- C:\WINDOWS\system32\drivers\ladfGSRi386.sys (Logitech)<br />
DRV - (LADF_CaptureOnly) -- C:\WINDOWS\system32\drivers\ladfGSCi386.sys (Logitech)<br />
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)<br />
DRV - (AtiHDAudioService) -- C:\WINDOWS\system32\drivers\AtihdXP3.sys (ATI Technologies, Inc.)<br />
DRV - (LGVirHid) -- C:\WINDOWS\system32\drivers\LGVirHid.sys (Logitech Inc.)<br />
DRV - (LGBusEnum) -- C:\WINDOWS\system32\drivers\LGBusEnum.sys (Logitech Inc.)<br />
DRV - (AtiHdmiService) -- C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)<br />
DRV - (fssfltr) -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)<br />
DRV - (PID_PEPI) -- C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)<br />
DRV - (epmntdrv) -- C:\WINDOWS\system32\epmntdrv.sys ()<br />
DRV - (EuGdiDrv) -- C:\WINDOWS\system32\EuGdiDrv.sys ()<br />
DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)<br />
DRV - (NPPTNT2) -- C:\WINDOWS\system32\npptNT2.sys (INCA Internet Co., Ltd.)<br />
DRV - (HSFHWBS2) -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)<br />
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)<br />
DRV - (HSF_DP) -- C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)<br />
 <br />
 <br />
<span style="color: #E56717;">========== Standard Registry (SafeList) ==========</span><br />
 <br />
 <br />
<span style="color: #E56717;">========== Internet Explorer ==========</span><br />
 <br />
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = <a href="http://www.google.com/ie" target="_blank">http://www.google.com/ie</a><br />
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = <a href="http://www.google.com/ie" target="_blank">http://www.google.com/ie</a><br />
IE - HKLM\..\SearchScopes,DefaultScope = <br />
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = <a href="http://www.bing.com/search" target="_blank">http://www.bing.com/search</a><br />
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = <a href="http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7" target="_blank">http://www.google.com/search?q={searchTe...urceid=ie7</a><br />
 <br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://www.google.com/ie" target="_blank">http://www.google.com/ie</a><br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = <a href="http://www.google.com" target="_blank">http://www.google.com</a><br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google<br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = <a href="http://www.google.com/search?q=%7BsearchTerms%7D&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8" target="_blank">http://www.google.com/search?q={searchTe...f8&oe=utf8</a><br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.google.com" target="_blank">http://www.google.com</a><br />
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = <a href="http://www.google.com/ie" target="_blank">http://www.google.com/ie</a><br />
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}<br />
IE - HKCU\..\SearchScopes\{04DA659F-89F0-4FDE-B413-86118C8649B8}: "URL" = <a href="http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=382950&p=%7BsearchTerms%7D" target="_blank">http://search.yahoo.com/search?fr=chr-gr...archTerms}</a><br />
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = <a href="http://www.bing.com/search?q=%7BsearchTerms%7D&src=IE-SearchBox&FORM=IE8SRC" target="_blank">http://www.bing.com/search?q={searchTerm...ORM=IE8SRC</a><br />
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = <a href="http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7&rlz=1I7GPCK_en" target="_blank">http://www.google.com/search?q={searchTe...1I7GPCK_en</a><br />
IE - HKCU\..\SearchScopes\{E6AF6939-8D25-4996-AA92-EA85F1BD3B43}: "URL" = <a href="http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7&rlz=1I7GPCK_en" target="_blank">http://www.google.com/search?q={searchTe...1I7GPCK_en</a><br />
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0<br />
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local<br />
 <br />
<span style="color: #E56717;">========== FireFox ==========</span><br />
 <br />
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=382950"<br />
FF - prefs.js..browser.search.selectedEngine: "Google"<br />
FF - prefs.js..browser.search.useDBForOrder: true<br />
FF - prefs.js..browser.startup.homepage: "http://corner.bigblueinteractive.com/index.php"<br />
FF - prefs.js..extensions.enabledAddons: plugin%40vfd.com:1.5<br />
FF - prefs.js..extensions.enabledAddons: %7BAE93811A-5C9A-4d34-8462-F7B864FC4696%7D:4.16<br />
FF - prefs.js..extensions.enabledAddons: smarterwiki%40wikiatic.com:5.1.3<br />
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0033-ABCDEFFEDCBA%7D:6.0.33<br />
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0035-ABCDEFFEDCBA%7D:6.0.35<br />
FF - prefs.js..extensions.enabledAddons: %7BBBDA0591-3099-440a-AA10-41764D9DB4DB%7D:11.3.0.9%20-%205<br />
FF - prefs.js..extensions.enabledAddons: %7B2D3F3651-74B9-4795-BDEC-6DA2F431CB62%7D:2013.3.5.1<br />
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1<br />
FF - prefs.js..extensions.enabledItems: iobit@mybrowserbar.com:4.1<br />
FF - prefs.js..extensions.enabledItems: wtxpcom@mybrowserbar.com:4.1<br />
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.91<br />
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0<br />
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:5.6<br />
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0<br />
FF - prefs.js..extensions.enabledItems: smarterwiki@wikiatic.com:4.3.7<br />
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.5<br />
FF - prefs.js..extensions.enabledItems: yyginstantplay@yoyogames.com:1.1.0.24<br />
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24<br />
FF - prefs.js..extensions.enabledItems: {1DEAE5AA-E19E-458b-9C8C-73CB651B9A58}:3.6<br />
FF - user.js - File not found<br />
 <br />
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()<br />
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)<br />
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found<br />
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()<br />
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)<br />
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)<br />
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)<br />
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)<br />
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)<br />
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)<br />
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+&reg;,version=1.6.2.91: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.)<br />
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)<br />
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)<br />
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)<br />
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)<br />
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)<br />
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)<br />
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)<br />
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Marrier\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)<br />
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Documents and Settings\Marrier\Application Data\Mozilla\plugins\npo1d.dll (Google)<br />
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Marrier\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()<br />
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)<br />
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)<br />
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)<br />
 <br />
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\Documents and Settings\All Users\Application Data\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2.0.0.16\coFFNST\<br />
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\coFFPlgn\ [2013/05/20 18:08:14 | 000,000,000 | ---D | M]<br />
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\IPSFFPlgn\ [2013/03/04 16:23:51 | 000,000,000 | ---D | M]<br />
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/05/19 15:34:17 | 000,000,000 | ---D | M]<br />
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/19 15:49:22 | 000,000,000 | ---D | M]<br />
 <br />
[2012/02/15 21:32:23 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Extensions<br />
[2009/06/13 21:04:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Extensions\mozswing@mozswing.org<br />
[2013/05/16 19:20:47 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Firefox\Profiles\thtksfry.default\extensions<br />
[2012/05/23 16:47:40 | 000,000,000 | ---D | M] (Orange Fox) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Firefox\Profiles\thtksfry.default\extensions\{5b35cb30-16b4-11de-8c30-0800200c9a66}<br />
[2012/08/24 20:03:34 | 000,000,000 | ---D | M] (VideoFileDownload - Download YouTube Videos) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Firefox\Profiles\thtksfry.default\extensions\plugin@vfd.com<br />
[2013/04/05 16:26:23 | 000,361,682 | ---- | M] () (No name found) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Firefox\Profiles\thtksfry.default\extensions\smarterwiki@wikiatic.c&#8203;om.xpi<br />
[2012/08/01 17:50:19 | 001,675,213 | ---- | M] () (No name found) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Firefox\Profiles\thtksfry.default\extensions\{1DEAE5AA-E19E-458b-9C8C-73CB651B9A58}.xpi<br />
[2012/12/30 17:18:43 | 000,377,738 | ---- | M] () (No name found) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Firefox\Profiles\thtksfry.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi<br />
[2013/05/08 15:43:26 | 000,870,680 | ---- | M] () (No name found) -- C:\Documents and Settings\Marrier\Application Data\Mozilla\Firefox\Profiles\thtksfry.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi<br />
[2013/04/13 16:51:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions<br />
[2013/04/13 16:51:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}<br />
[2013/04/13 16:51:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}<br />
[2013/04/13 16:51:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}<br />
[2013/05/20 18:08:14 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\COFFPLGN<br />
[2013/03/04 16:23:51 | 000,000,000 | ---D | M] (Norton Vulnerability Protection) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.1.22\IPSFFPLGN<br />
[2013/04/13 16:52:07 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll<br />
[2008/06/30 14:44:08 | 000,324,976 | ---- | M] (Symantec Corporation) -- C:\Program Files\mozilla firefox\components\coFFPlgn.dll<br />
[2012/08/29 18:22:50 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml<br />
[2013/03/04 15:47:57 | 000,002,086 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml<br />
 <br />
<span style="color: #E56717;">========== Chrome  ==========</span><br />
 <br />
CHR - default_search_provider: Search Results (Enabled)<br />
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl&#8203;e:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}<br />
CHR - default_search_provider: suggest_url = <br />
CHR - homepage: <a href="http://corner.bigblueinteractive.com/index.php" target="_blank">http://corner.bigblueinteractive.com/index.php</a><br />
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer<br />
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll<br />
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\pdf.dll<br />
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\gcswf32.dll<br />
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll<br />
CHR - plugin: Norton Confidential (Enabled) = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.3.7_0\npcoplgn.d&#8203;ll<br />
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\Marrier\Application Data\Mozilla\plugins\npgoogletalk.dll<br />
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\Marrier\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll<br />
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll<br />
CHR - plugin: Coupons Inc., Coupon Printer Manager  (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll<br />
CHR - plugin: Coupons Inc., Coupon Printer Manager  (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll<br />
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll<br />
CHR - plugin: Java&#153; Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll<br />
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll<br />
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll<br />
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll<br />
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll<br />
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll<br />
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll<br />
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll<br />
CHR - plugin: getPlusPlus for Adobe 16291 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np_gp.dll<br />
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll<br />
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll<br />
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll<br />
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll<br />
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll<br />
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll<br />
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll<br />
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll<br />
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll<br />
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll<br />
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll<br />
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll<br />
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll<br />
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll<br />
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll<br />
CHR - Extension: Angry Birds = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\<br />
CHR - Extension: Solitaire Games = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\eljmkmbmhmgmpmmbkagbobpmpocacdbo\1.0.0.3_0\<br />
CHR - Extension: Bubble Shooter -HD = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hpakbhbnhkbghdcejiiangcefallmaln\2.2.0_0\<br />
CHR - Extension: StumbleUpon = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg\5.3.7.1_0\<br />
CHR - Extension: Norton Identity Protection = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.3.3.19_0\<br />
 <br />
O1 HOSTS File: ([2013/05/06 14:38:38 | 000,445,361 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS<br />
O1 - Hosts: 127.0.0.1	localhost<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.007guard.com" target="_blank">http://www.007guard.com</a><br />
O1 - Hosts: 127.0.0.1	007guard.com<br />
O1 - Hosts: 127.0.0.1	008i.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.008k.com" target="_blank">http://www.008k.com</a><br />
O1 - Hosts: 127.0.0.1	008k.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.00hq.com" target="_blank">http://www.00hq.com</a><br />
O1 - Hosts: 127.0.0.1	00hq.com<br />
O1 - Hosts: 127.0.0.1	010402.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.032439.com" target="_blank">http://www.032439.com</a><br />
O1 - Hosts: 127.0.0.1	032439.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.0scan.com" target="_blank">http://www.0scan.com</a><br />
O1 - Hosts: 127.0.0.1	0scan.com<br />
O1 - Hosts: 127.0.0.1	1000gratisproben.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.1000gratisproben.com" target="_blank">http://www.1000gratisproben.com</a><br />
O1 - Hosts: 127.0.0.1	1001namen.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.1001namen.com" target="_blank">http://www.1001namen.com</a><br />
O1 - Hosts: 127.0.0.1	100888290cs.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.100888290cs.com" target="_blank">http://www.100888290cs.com</a><br />
O1 - Hosts: 127.0.0.1	<a href="http://www.100sexlinks.com" target="_blank">http://www.100sexlinks.com</a><br />
O1 - Hosts: 127.0.0.1	100sexlinks.com<br />
O1 - Hosts: 127.0.0.1	10sek.com<br />
O1 - Hosts: 127.0.0.1	<a href="http://www.10sek.com" target="_blank">http://www.10sek.com</a><br />
O1 - Hosts: 127.0.0.1	<a href="http://www.1-2005-search.com" target="_blank">http://www.1-2005-search.com</a><br />
O1 - Hosts: 127.0.0.1	1-2005-search.com<br />
O1 - Hosts: 15296 more lines...<br />
O2 - BHO: (StumbleUpon Launcher) - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll File not found<br />
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)<br />
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.<br />
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.3.1.22\coieplg.dll (Symantec Corporation)<br />
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.3.1.22\ips\ipsbho.dll (Symantec Corporation)<br />
O2 - BHO: (Java&#153; Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)<br />
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)<br />
O2 - BHO: (Java&#153; Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)<br />
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.<br />
O3 - HKLM\..\Toolbar: (no name) - !{30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - No CLSID value found.<br />
O3 - HKLM\..\Toolbar: (no name) - !{8dcb7100-df86-4384-8842-8fa844297b3f} - No CLSID value found.<br />
O3 - HKLM\..\Toolbar: (StumbleUpon Toolbar) - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll File not found<br />
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.3.1.22\coieplg.dll (Symantec Corporation)<br />
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.<br />
O4 - HKLM..\Run: [AdmTask] C:\Program Files\AdmTask\admtask.exe (LexoSoft Inc.)<br />
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found<br />
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)<br />
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)<br />
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)<br />
O4 - HKLM..\Run: [StartupDelayer] C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher GUI.exe (r2 studios)<br />
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()<br />
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)<br />
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled [2009/06/14 15:05:45 | 000,000,000 | -H-D | M]<br />
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present<br />
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1<br />
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0<br />
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1<br />
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255<br />
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0<br />
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()<br />
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()<br />
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()<br />
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()<br />
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage File not found<br />
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)<br />
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)<br />
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)<br />
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} <a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" target="_blank">http://upload.facebook.com/controls/2008...oader5.cab</a> (Facebook Photo Uploader 5 Control)<br />
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} <a href="http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab" target="_blank">http://messenger.zone.msn.com/binary/msg...b56986.cab</a> (Checkers Class)<br />
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} <a href="http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab" target="_blank">http://download.microsoft.com/download/e...vc1dmo.cab</a> (Reg Error: Value error.)<br />
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} <a href="http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab" target="_blank">http://messenger.zone.msn.com/EN-US/a-UN...E_UNO1.cab</a> (UnoCtrl Class)<br />
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} <a href="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1219106024718" target="_blank">http://www.update.microsoft.com/windowsu...9106024718</a> (WUWebControl Class)<br />
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} <a href="http://download.divx.com/player/DivXBrowserPlugin.cab" target="_blank">http://download.divx.com/player/DivXBrowserPlugin.cab</a> (DivXBrowserPlugin Object)<br />
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} <a href="http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab" target="_blank">http://upload.facebook.com/controls/2009...ader55.cab</a> (Facebook Photo Uploader 5 Control)<br />
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jinstal...s-i586.cab</a> (Java Plug-in 10.21.2)<br />
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <a href="http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab" target="_blank">http://fpdownload.macromedia.com/get/fla...rashim.cab</a> (Reg Error: Value error.)<br />
O16 - DPF: {994CF098-73ED-4C83-B227-B15F2A8D6177} <a href="https://www.d-life.com/D-Life//DLCUALibrary.cab" target="_blank">https://www.d-life.com/D-Life//DLCUALibrary.cab</a> (CTUADriverWrapperCtrl Object)<br />
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} <a href="http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab" target="_blank">http://messenger.zone.msn.com/binary/ZIn...b56649.cab</a> (MSN Games - Installer)<br />
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} <a href="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab" target="_blank">http://messenger.zone.msn.com/binary/Mes...b56907.cab</a> (MessengerStatsClient Class)<br />
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jinstal...s-i586.cab</a> (Reg Error: Key error.)<br />
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jinstal...s-i586.cab</a> (Java Plug-in 1.6.0_07)<br />
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jinstal...s-i586.cab</a> (Java Plug-in 10.21.2)<br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} <a href="http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/get/fl...wflash.cab</a> (Shockwave Flash Object)<br />
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} <a href="http://messenger.zone.msn.com/binary/WoF.cab57176.cab" target="_blank">http://messenger.zone.msn.com/binary/WoF.cab57176.cab</a> (WheelofFortune Object)<br />
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}  (Reg Error: Value error.)<br />
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a> (get_atlcom Class)<br />
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} <a href="https://cincinnati.connectge.com/dana-cached/setup/JuniperSetupSP1.cab" target="_blank">https://cincinnati.connectge.com/dana-ca...tupSP1.cab</a> (JuniperSetupControlXP Class)<br />
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} <a href="http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.3.1.0.cab" target="_blank">http://content.systemrequirementslab.com....3.1.0.cab</a> (Reg Error: Value error.)<br />
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} <a href="https://cincinnati.connectge.com/dana-cached/sc/JuniperSetupClient.cab" target="_blank">https://cincinnati.connectge.com/dana-ca...Client.cab</a> (JuniperSetupClientControl Class)<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76<br />
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3AABA5FE-995A-4EBB-9BAB-0AE8F49BE23D}: DhcpNameServer = 75.75.75.75 75.75.76.76<br />
O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found<br />
O18 - Protocol\Handler\AutorunsDisabled\skype4com - No CLSID value found<br />
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)<br />
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)<br />
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)<br />
O20 - Winlogon\Notify\AutorunsDisabled: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found<br />
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) -  File not found<br />
O24 - Desktop Components:0 () - <br />
O24 - Desktop WallPaper: C:\Documents and Settings\Marrier\Local Settings\Application Data\Microsoft\Wallpaper1.bmp<br />
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Marrier\Local Settings\Application Data\Microsoft\Wallpaper1.bmp<br />
O32 - HKLM CDRom: AutoRun - 1<br />
O32 - AutoRun File - [2008/08/18 19:27:57 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]<br />
O32 - AutoRun File - [2013/05/11 16:02:36 | 002,431,246 | ---- | M] () - C:\AutoRuns.arn -- [ NTFS ]<br />
O32 - AutoRun File - [2011/11/05 13:52:32 | 000,049,648 | ---- | M] () - C:\autoruns.chm -- [ NTFS ]<br />
O32 - AutoRun File - [2012/09/10 09:16:28 | 000,649,864 | ---- | M] (Sysinternals - <a href="http://www.sysinternals.com" target="_blank">http://www.sysinternals.com</a>) - C:\autoruns.exe -- [ NTFS ]<br />
O32 - AutoRun File - [2012/09/10 09:16:28 | 000,567,944 | ---- | M] (Sysinternals - <a href="http://www.sysinternals.com" target="_blank">http://www.sysinternals.com</a>) - C:\autorunsc.exe -- [ NTFS ]<br />
O32 - AutoRun File - [2003/11/19 06:16:26 | 000,000,056 | R--- | M] () - E:\Autorun.inf -- [ CDFS ]<br />
O33 - MountPoints2\{20cebf6d-73c4-11dd-8229-0019d1987999}\Shell\AutoRun\command - "" = wscript.exe \SMRTNTKY\script.js<br />
O33 - MountPoints2\{4d87a803-faf1-11dd-833b-0019d1987999}\Shell\AutoRun\command - "" = F:\setupSNK.exe<br />
O33 - MountPoints2\{bcc8dff9-1cd0-11de-836d-0019d1987999}\Shell\AutoRun\command - "" = F:\setupSNK.exe<br />
O33 - MountPoints2\{bde3c206-f2d0-11df-8633-0019d1987999}\Shell\AutoRun\command - "" = F:\DPVSETUP.EXE<br />
O34 - HKLM BootExecute: (autocheck autochk *)<br />
O35 - HKLM\..comfile [open] -- "%1" %*<br />
O35 - HKLM\..exefile [open] -- "%1" %*<br />
O37 - HKLM\...com [@ = comfile] -- "%1" %*<br />
O37 - HKLM\...exe [@ = exefile] -- "%1" %*<br />
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)<br />
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)<br />
 <br />
<span style="color: #E56717;">========== Files/Folders - Created Within 30 Days ==========</span><br />
 <br />
[2013/05/20 17:47:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HitmanPro<br />
[2013/05/19 15:48:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT<br />
[2013/05/19 15:48:26 | 000,000,000 | ---D | C] -- C:\JRT<br />
[2013/05/16 19:27:34 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Marrier\Recent<br />
[2013/05/16 19:21:05 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group<br />
[2013/05/16 19:21:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marrier\Start Menu\Programs\Revo Uninstaller<br />
[2013/05/06 12:13:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy 2<br />
[2013/05/06 12:13:44 | 000,015,224 | ---- | C] (Safer Networking Limited) -- C:\WINDOWS\System32\sdnclean.exe<br />
[2013/05/06 12:13:38 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy 2<br />
[2013/05/06 12:09:47 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe<br />
[2013/05/06 12:09:47 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe<br />
[2013/05/06 12:09:47 | 000,094,112 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll<br />
[2013/05/06 12:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Defraggler<br />
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]<br />
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]<br />
 <br />
<span style="color: #E56717;">========== Files - Modified Within 30 Days ==========</span><br />
 <br />
[2013/05/20 18:30:15 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job<br />
[2013/05/20 18:29:00 | 000,000,888 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job<br />
[2013/05/20 18:07:56 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job<br />
[2013/05/20 18:07:56 | 000,000,620 | ---- | M] () -- C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job<br />
[2013/05/20 18:07:56 | 000,000,616 | -H-- | M] () -- C:\WINDOWS\tasks\ConfigExec.job<br />
[2013/05/20 18:07:53 | 000,030,464 | ---- | M] () -- C:\WINDOWS\System32\drivers\hitmanpro37.sys<br />
[2013/05/20 18:07:49 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat<br />
[2013/05/20 18:00:30 | 000,000,908 | ---- | M] () -- C:\WINDOWS\System32\.crusader<br />
[2013/05/20 17:52:00 | 000,000,986 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1844237615-725345543-1004UA.job<br />
[2013/05/20 17:00:00 | 000,000,580 | -H-- | M] () -- C:\WINDOWS\tasks\DataUpload.job<br />
[2013/05/20 13:52:00 | 000,000,934 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1844237615-725345543-1004Core.job<br />
[2013/05/20 11:34:00 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job<br />
[2013/05/18 11:53:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job<br />
[2013/05/16 19:28:15 | 000,024,776 | ---- | M] () -- C:\Documents and Settings\Marrier\My Documents\cc_20130516_192812.reg<br />
[2013/05/16 19:21:05 | 000,000,917 | ---- | M] () -- C:\Documents and Settings\Marrier\Desktop\Revo Uninstaller.lnk<br />
[2013/05/15 19:09:13 | 000,001,360 | ---- | M] () -- C:\WINDOWS\wininit.ini<br />
[2013/05/15 18:15:08 | 000,131,688 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT<br />
[2013/05/15 18:10:59 | 000,433,574 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat<br />
[2013/05/15 18:10:59 | 000,068,164 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat<br />
[2013/05/15 18:01:50 | 000,000,616 | ---- | M] () -- C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job<br />
[2013/05/14 22:30:11 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe<br />
[2013/05/14 22:30:11 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl<br />
[2013/05/11 22:40:47 | 000,000,751 | ---- | M] () -- C:\Documents and Settings\Marrier\Desktop\Norton Installation Files.lnk<br />
[2013/05/11 16:09:24 | 000,001,870 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\HP Photosmart Essential 3.0.lnk<br />
[2013/05/11 16:02:36 | 002,431,246 | ---- | M] () -- C:\AutoRuns.arn<br />
[2013/05/11 10:44:47 | 000,002,473 | ---- | M] () -- C:\Documents and Settings\Marrier\Desktop\Microsoft Word.lnk<br />
[2013/05/07 00:27:31 | 006,015,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll<br />
[2013/05/06 14:38:38 | 000,445,361 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS<br />
[2013/05/06 12:14:03 | 000,000,446 | ---- | M] () -- C:\WINDOWS\tasks\Scan the system (Spybot - Search & Destroy).job<br />
[2013/05/06 12:13:52 | 000,001,836 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Spybot-S&D Start Center.lnk<br />
[2013/05/06 12:06:21 | 000,001,632 | ---- | M] () -- C:\Documents and Settings\Marrier\Desktop\Update Checker.lnk<br />
[2013/05/06 12:04:22 | 000,001,580 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Defraggler.lnk<br />
[2013/05/06 12:03:36 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk<br />
[2013/05/04 11:39:09 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl<br />
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]<br />
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]<br />
 <br />
<span style="color: #E56717;">========== Files Created - No Company Name ==========</span><br />
 <br />
[2013/05/20 18:07:53 | 000,030,464 | ---- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro37.sys<br />
[2013/05/20 18:00:30 | 000,000,908 | ---- | C] () -- C:\WINDOWS\System32\.crusader<br />
[2013/05/16 19:28:13 | 000,024,776 | ---- | C] () -- C:\Documents and Settings\Marrier\My Documents\cc_20130516_192812.reg<br />
[2013/05/16 19:21:05 | 000,000,917 | ---- | C] () -- C:\Documents and Settings\Marrier\Desktop\Revo Uninstaller.lnk<br />
[2013/05/11 22:40:45 | 000,000,751 | ---- | C] () -- C:\Documents and Settings\Marrier\Desktop\Norton Installation Files.lnk<br />
[2013/05/06 12:14:02 | 000,000,620 | ---- | C] () -- C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job<br />
[2013/05/06 12:14:02 | 000,000,616 | ---- | C] () -- C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job<br />
[2013/05/06 12:14:02 | 000,000,446 | ---- | C] () -- C:\WINDOWS\tasks\Scan the system (Spybot - Search & Destroy).job<br />
[2013/05/06 12:13:53 | 000,001,842 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot-S&D Start Center.lnk<br />
[2013/05/06 12:13:52 | 000,001,836 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Spybot-S&D Start Center.lnk<br />
[2012/02/15 21:32:24 | 000,001,360 | ---- | C] () -- C:\WINDOWS\wininit.ini<br />
[2012/02/14 18:43:15 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll<br />
[2012/02/01 19:35:56 | 000,076,360 | ---- | C] () -- C:\WINDOWS\System32\ladfGSRCoinst_i386.dll<br />
[2011/01/04 17:28:20 | 000,001,940 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini<br />
[2010/01/18 19:26:16 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Marrier\Ÿ9Ÿ9<br />
[2008/12/23 20:00:13 | 000,735,889 | ---- | C] () -- C:\Documents and Settings\Marrier\Application Data\pbsetup.zip<br />
[2008/12/23 19:47:55 | 000,674,600 | ---- | C] () -- C:\Program Files\pbsvc.exe<br />
[2008/12/23 18:22:16 | 000,138,056 | ---- | C] () -- C:\Documents and Settings\Marrier\Application Data\PnkBstrK.sys<br />
[2008/12/23 02:47:15 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\Marrier\__Call Of Duty 4 - Modern Warfare Multiplayer<br />
 <br />
<span style="color: #E56717;">========== ZeroAccess Check ==========</span><br />
 <br />
[2008/12/22 23:14:12 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini<br />
 <br />
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]<br />
 <br />
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]<br />
 <br />
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]<br />
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 20:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)<br />
"ThreadingModel" = Apartment<br />
 <br />
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]<br />
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 08:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)<br />
"ThreadingModel" = Free<br />
 <br />
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]<br />
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/13 20:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)<br />
"ThreadingModel" = Both<br />
 <br />
<span style="color: #E56717;">========== LOP Check ==========</span><br />
 <br />
[2013/03/09 13:05:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1<br />
[2008/08/19 00:26:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore<br />
[2010/12/03 00:03:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo<br />
[2012/05/28 11:21:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BOINC<br />
[2008/08/22 11:00:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ<br />
[2008/08/18 19:41:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Citrix<br />
[2010/12/25 22:00:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreeApp<br />
[2013/05/20 18:00:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HitmanPro<br />
[2009/08/12 21:16:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ijjigame<br />
[2010/11/27 12:34:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Innovative Solutions<br />
[2010/12/25 22:00:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit<br />
[2010/12/06 19:30:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Juniper Networks<br />
[2009/02/14 13:32:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Linksys<br />
[2009/11/16 21:56:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Metacafe<br />
[2011/04/18 20:12:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData<br />
[2009/11/21 20:03:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound<br />
[2010/02/12 21:31:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters<br />
[2008/10/12 12:49:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCSettings<br />
[2012/02/01 20:51:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files<br />
[2010/12/05 15:03:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\r2 Studios<br />
[2009/12/19 22:11:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TelTel<br />
[2009/03/17 21:51:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP<br />
[2008/08/30 17:12:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\utilinkl<br />
[2009/03/18 17:18:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}<br />
[2010/04/08 19:32:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}<br />
[2009/10/29 18:02:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}<br />
[2009/03/18 14:15:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}<br />
[2009/06/09 20:33:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}<br />
[2008/08/19 00:27:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\acccore<br />
[2009/08/27 17:38:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Amazon<br />
[2010/12/03 00:05:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Ashampoo<br />
[2010/12/03 00:34:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\BitTorrent<br />
[2009/10/10 20:11:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Blitware<br />
[2008/11/08 21:11:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1<br />
[2010/11/27 10:52:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\DeviceDoctorSoftware<br />
[2011/09/22 19:13:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\FileZilla<br />
[2009/06/08 18:41:38 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Marrier\Application Data\ijjigame<br />
[2011/09/21 08:37:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Juniper Networks<br />
[2008/11/05 20:08:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Leadertech<br />
[2009/07/23 20:39:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\LimeWire<br />
[2011/08/19 16:16:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\LolClient<br />
[2011/02/13 19:22:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Marine Aquarium 3<br />
[2010/12/05 15:03:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\r2 Studios<br />
[2009/11/23 17:54:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\TeamViewer<br />
[2009/12/19 22:15:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\TelTel<br />
[2010/03/15 19:18:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Tific<br />
[2012/04/05 18:32:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\TS3Client<br />
[2010/02/03 23:35:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\Uniblue<br />
[2011/04/09 20:29:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\uTorrent<br />
[2010/10/25 01:47:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\WeGame<br />
[2008/11/08 21:19:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marrier\Application Data\zweitgeist<br />
 <br />
<span style="color: #E56717;">========== Purity Check ==========</span><br />
 <br />
 <br />
 <br />
<span style="color: #E56717;">========== Alternate Data Streams ==========</span><br />
 <br />
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2<br />
<br />
< End of report ><br />
OTL Extras logfile created on: 5/20/2013 6:41:12 PM - Run 1<br />
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Documents and Settings\Marrier\My Documents\Downloads<br />
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation<br />
Internet Explorer (Version = 8.0.6001.18702)<br />
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br />
 <br />
2.99 Gb Total Physical Memory | 1.87 Gb Available Physical Memory | 62.54% Memory free<br />
5.82 Gb Paging File | 4.90 Gb Available in Paging File | 84.13% Paging File free<br />
Paging file location(s): C:\pagefile.sys 0 0 [binary data]<br />
 <br />
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files<br />
Drive C: | 74.50 Gb Total Space | 18.00 Gb Free Space | 24.16% Space Free | Partition Type: NTFS<br />
Drive E: | 69.50 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS<br />
 <br />
Computer Name: MARRIER-0425E80 | User Name: Marrier | Logged in as Administrator.<br />
Boot Mode: Normal | Scan Mode: Current user<br />
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days<br />
 <br />
<span style="color: #E56717;">========== Extra Registry (SafeList) ==========</span><br />
 <br />
 <br />
<span style="color: #E56717;">========== File Associations ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]<br />
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*<br />
 <br />
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]<br />
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)<br />
 <br />
<span style="color: #E56717;">========== Shell Spawning ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]<br />
batfile [open] -- "%1" %*<br />
cmdfile [open] -- "%1" %*<br />
comfile [open] -- "%1" %*<br />
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*<br />
exefile [open] -- "%1" %*<br />
htmlfile [edit] -- Reg Error: Key error.<br />
piffile [open] -- "%1" %*<br />
regfile [merge] -- Reg Error: Key error.<br />
scrfile [config] -- "%1"<br />
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l<br />
scrfile [open] -- "%1" /S<br />
txtfile [edit] -- Reg Error: Key error.<br />
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1<br />
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br />
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)<br />
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)<br />
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)<br />
 <br />
<span style="color: #E56717;">========== Security Center Settings ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]<br />
"FirstRunDisabled" = 1<br />
"AntiVirusDisableNotify" = 0<br />
"FirewallDisableNotify" = 0<br />
"UpdatesDisableNotify" = 0<br />
"AntiVirusOverride" = 0<br />
"FirewallOverride" = 0<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]<br />
"DisableMonitoring" = 1<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]<br />
"DisableMonitoring" = 1<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]<br />
"DisableMonitoring" = 1<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]<br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]<br />
 <br />
<span style="color: #E56717;">========== System Restore Settings ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]<br />
"DisableSR" = 0<br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]<br />
"Start" = 0<br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]<br />
"Start" = 2<br />
 <br />
<span style="color: #E56717;">========== Firewall Settings ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir&#8203;ewallPolicy\DomainProfile]<br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir&#8203;ewallPolicy\DomainProfile\GloballyOpenPorts\List]<br />
"57915:TCP" = 57915:TCP:*:Enabled:Pando Media Booster<br />
"57915:UDP" = 57915:UDP:*:Enabled:Pando Media Booster<br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir&#8203;ewallPolicy\StandardProfile]<br />
"EnableFirewall" = 0<br />
"DoNotAllowExceptions" = 0<br />
"DisableNotifications" = 0<br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir&#8203;ewallPolicy\StandardProfile\GloballyOpenPorts\List]<br />
"57915:TCP" = 57915:TCP:*:Enabled:Pando Media Booster<br />
"57915:UDP" = 57915:UDP:*:Enabled:Pando Media Booster<br />
 <br />
<span style="color: #E56717;">========== Authorized Applications List ==========</span><br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir&#8203;ewallPolicy\DomainProfile\AuthorizedApplications\List]<br />
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)<br />
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)<br />
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)<br />
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()<br />
 <br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir&#8203;ewallPolicy\StandardProfile\AuthorizedApplications\List]<br />
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)<br />
"C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Marrier\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin -- (Google)<br />
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent<br />
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)<br />
"H:\Josh\SteamApps\common\alien swarm\srcds.exe" = H:\Josh\SteamApps\common\alien swarm\srcds.exe:*:Enabled:Alien Swarm Dedicated Server<br />
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)<br />
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)<br />
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()<br />
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service -- (Apple Inc.)<br />
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)<br />
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)<br />
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.)<br />
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)<br />
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)<br />
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)<br />
 <br />
 <br />
<span style="color: #E56717;">========== HKEY_LOCAL_MACHINE Uninstall List ==========</span><br />
 <br />
[HKEY_LOCAL_MACHIN<br /><!-- start: postbit_attachments_attachment -->
<br /><img src="images/attachtypes/ppt.gif" border="0" alt=".ppt" />&nbsp;&nbsp;<a href="attachment.php?aid=4549" target="_blank">Screenshot.ppt</a> (Size: 403 KB / Downloads: 2)
<!-- end: postbit_attachments_attachment -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Hello all]]></title>
			<link>http://malwaretips.com/Thread-Hello-all--15977</link>
			<pubDate>Mon, 20 May 2013 17:22:52 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-Hello-all--15977</guid>
			<description><![CDATA[Hoping to get some useful info from this site.  As someone who is getting on in years (and a bit intimidated by all the Malware out there), it is nice to find truly helpful forums like this.]]></description>
			<content:encoded><![CDATA[Hoping to get some useful info from this site.  As someone who is getting on in years (and a bit intimidated by all the Malware out there), it is nice to find truly helpful forums like this.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[New Config]]></title>
			<link>http://malwaretips.com/Thread-New-Config</link>
			<pubDate>Mon, 20 May 2013 16:55:16 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-New-Config</guid>
			<description><![CDATA[Hi folks,<br />
<br />
As my Avast subscription is up soon,  I have been trying a few alternatives.<br />
<br />
I have just paid for Comodo Internet Security after a short trial so I hope this performs well with no confliction or slow down.<br />
<br />
Antilogger on trial too may may be overkill with the rest I have ?<br />
<br />
Any comments invited.<br />
<br />
Andy]]></description>
			<content:encoded><![CDATA[Hi folks,<br />
<br />
As my Avast subscription is up soon,  I have been trying a few alternatives.<br />
<br />
I have just paid for Comodo Internet Security after a short trial so I hope this performs well with no confliction or slow down.<br />
<br />
Antilogger on trial too may may be overkill with the rest I have ?<br />
<br />
Any comments invited.<br />
<br />
Andy]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[fbi moneypak virus]]></title>
			<link>http://malwaretips.com/Thread-fbi-moneypak-virus--15972</link>
			<pubDate>Mon, 20 May 2013 14:16:44 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-fbi-moneypak-virus--15972</guid>
			<description><![CDATA[need help with next steps.  I have read forum posts and have a log file but don't know what to do now.]]></description>
			<content:encoded><![CDATA[need help with next steps.  I have read forum posts and have a log file but don't know what to do now.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Advanced SystemCare PRO 6 -  6 months free]]></title>
			<link>http://malwaretips.com/Thread-Giveaway-Advanced-SystemCare-PRO-6-6-months-free</link>
			<pubDate>Mon, 20 May 2013 14:04:53 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-Giveaway-Advanced-SystemCare-PRO-6-6-months-free</guid>
			<description><![CDATA[<img src="http://upyourpic.org/images/201303/gj5mv51hck.jpg" border="0" alt="[Image: gj5mv51hck.jpg]" /><br />
<a href="http://ld.iobit.com/2013/softonicgiveaway/es.php#" target="_blank">http://ld.iobit.com/2013/softonicgiveaway/es.php#</a>]]></description>
			<content:encoded><![CDATA[<img src="http://upyourpic.org/images/201303/gj5mv51hck.jpg" border="0" alt="[Image: gj5mv51hck.jpg]" /><br />
<a href="http://ld.iobit.com/2013/softonicgiveaway/es.php#" target="_blank">http://ld.iobit.com/2013/softonicgiveaway/es.php#</a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[fbi money pak still uninstalled]]></title>
			<link>http://malwaretips.com/Thread-fbi-money-pak-still-uninstalled</link>
			<pubDate>Mon, 20 May 2013 13:57:30 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-fbi-money-pak-still-uninstalled</guid>
			<description><![CDATA[]]></description>
			<content:encoded><![CDATA[]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[NEW Stunning Pictures Gallery]]></title>
			<link>http://malwaretips.com/Thread-NEW-Stunning-Pictures-Gallery</link>
			<pubDate>Mon, 20 May 2013 11:48:26 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-NEW-Stunning-Pictures-Gallery</guid>
			<description><![CDATA[<span style="font-size: medium;"><span style="font-weight: bold;">NEW Stunning Pictures Gallery</span></span> here!<br />
<br />
Show all pictures you especially like.<img src="images/smilies/wink.gif" style="vertical-align: middle;" border="0" alt="Wink" title="Wink" /> Amazing web photos, or images taken by ourselves .. share awesome pics here:<br />
<br />
<br />
-----------------------------------------------------<br />
<br />
<br />
Spanish twins holding hands at birth (Des jumeaux se tenant la main à la naissance): on YouTube: <a href="http://www.youtube.com/watch?v=jkSmOFtj7uA" target="_blank">http://www.youtube.com/watch?v=jkSmOFtj7uA</a><br />
<br />
'Pictures of Danel and Maria, fraternal twins born in San Sebastian, Spain, holding hands, unanimous on the Internet. This spontaneous gesture, immortalized by the maternity nurse, made the "a" of the media Gipuzkoa, "El Diario Vasco", Tuesday, May 14, 2013.<br />
<br />
Since then, the euphoria. Video of two newborns has been viewed more than 260,000 times on YouTube in three days. In one day, 20,000 people on Facebook have clicked on "Like" to show their emotion.<br />
<br />
The day Danel and Maria wish to review the pictures of their birth, they will certainly not hard to find them ...'<br />
<br />
Spanish Twins holding hands at birth.jpg <br />
<img src="http://i.imgur.com/ziXZQED.jpg" border="0" alt="[Image: ziXZQED.jpg]" /><br />
<br />
--------------------<br />
<br />
We took in a stray cat that had a nasty eye infection .. Being completely blind, one of our older cats decided to take care and help him around the house. I found them later asleep like this.png<br />
<img src="http://i.imgur.com/2pw3PL3.png" border="0" alt="[Image: 2pw3PL3.png]" /><br />
IMGUR link for this image: <a href="http://imgur.com/gallery/8nBLnkF" target="_blank">http://imgur.com/gallery/8nBLnkF</a><br />
<br />
-------------------<br />
<br />
<img src="http://i.imgur.com/D0oErss.gif" border="0" alt="[Image: D0oErss.gif]" /><br />
gifs-movimiento-gatos-07.gif]]></description>
			<content:encoded><![CDATA[<span style="font-size: medium;"><span style="font-weight: bold;">NEW Stunning Pictures Gallery</span></span> here!<br />
<br />
Show all pictures you especially like.<img src="images/smilies/wink.gif" style="vertical-align: middle;" border="0" alt="Wink" title="Wink" /> Amazing web photos, or images taken by ourselves .. share awesome pics here:<br />
<br />
<br />
-----------------------------------------------------<br />
<br />
<br />
Spanish twins holding hands at birth (Des jumeaux se tenant la main à la naissance): on YouTube: <a href="http://www.youtube.com/watch?v=jkSmOFtj7uA" target="_blank">http://www.youtube.com/watch?v=jkSmOFtj7uA</a><br />
<br />
'Pictures of Danel and Maria, fraternal twins born in San Sebastian, Spain, holding hands, unanimous on the Internet. This spontaneous gesture, immortalized by the maternity nurse, made the "a" of the media Gipuzkoa, "El Diario Vasco", Tuesday, May 14, 2013.<br />
<br />
Since then, the euphoria. Video of two newborns has been viewed more than 260,000 times on YouTube in three days. In one day, 20,000 people on Facebook have clicked on "Like" to show their emotion.<br />
<br />
The day Danel and Maria wish to review the pictures of their birth, they will certainly not hard to find them ...'<br />
<br />
Spanish Twins holding hands at birth.jpg <br />
<img src="http://i.imgur.com/ziXZQED.jpg" border="0" alt="[Image: ziXZQED.jpg]" /><br />
<br />
--------------------<br />
<br />
We took in a stray cat that had a nasty eye infection .. Being completely blind, one of our older cats decided to take care and help him around the house. I found them later asleep like this.png<br />
<img src="http://i.imgur.com/2pw3PL3.png" border="0" alt="[Image: 2pw3PL3.png]" /><br />
IMGUR link for this image: <a href="http://imgur.com/gallery/8nBLnkF" target="_blank">http://imgur.com/gallery/8nBLnkF</a><br />
<br />
-------------------<br />
<br />
<img src="http://i.imgur.com/D0oErss.gif" border="0" alt="[Image: D0oErss.gif]" /><br />
gifs-movimiento-gatos-07.gif]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[FBI Virus - Strange Variant - Still Lingers]]></title>
			<link>http://malwaretips.com/Thread-FBI-Virus-Strange-Variant-Still-Lingers</link>
			<pubDate>Mon, 20 May 2013 09:44:43 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-FBI-Virus-Strange-Variant-Still-Lingers</guid>
			<description><![CDATA[]]></description>
			<content:encoded><![CDATA[]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[FileMedic Anitivirus - Test (TestySecureLab)]]></title>
			<link>http://malwaretips.com/Thread-FileMedic-Anitivirus-Test-TestySecureLab</link>
			<pubDate>Mon, 20 May 2013 09:24:33 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-FileMedic-Anitivirus-Test-TestySecureLab</guid>
			<description><![CDATA[<!-- start: video_youtube_embed --><br />
<iframe title="YouTube video player" width="790" height="550" src="http://www.youtube.com/embed/DwbxhqXVT8o" frameborder="0" allowfullscreen></iframe><br />
<!-- end: video_youtube_embed -->]]></description>
			<content:encoded><![CDATA[<!-- start: video_youtube_embed --><br />
<iframe title="YouTube video player" width="790" height="550" src="http://www.youtube.com/embed/DwbxhqXVT8o" frameborder="0" allowfullscreen></iframe><br />
<!-- end: video_youtube_embed -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[New to the forum]]></title>
			<link>http://malwaretips.com/Thread-New-to-the-forum</link>
			<pubDate>Mon, 20 May 2013 08:24:26 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-New-to-the-forum</guid>
			<description><![CDATA[I happened upon this forum while trying to find out how to remove the FBI virus on a friend's laptop.  Seems like there is a lot of information about this so I am hoping to get it fixed for him.<br />
<br />
Looking forward to being a part of this forum and all the wonderful information that there seems to be. <br />
<br />
Thanks!!!<br />
<br />
Bob]]></description>
			<content:encoded><![CDATA[I happened upon this forum while trying to find out how to remove the FBI virus on a friend's laptop.  Seems like there is a lot of information about this so I am hoping to get it fixed for him.<br />
<br />
Looking forward to being a part of this forum and all the wonderful information that there seems to be. <br />
<br />
Thanks!!!<br />
<br />
Bob]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Winrar 5.00 Beta 3 and 4 Details]]></title>
			<link>http://malwaretips.com/Thread-Winrar-5-00-Beta-3-and-4-Details</link>
			<pubDate>Mon, 20 May 2013 06:41:59 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-Winrar-5-00-Beta-3-and-4-Details</guid>
			<description><![CDATA[<blockquote><cite>Quote:</cite> Version 5.00 beta 3<br />
<br />
   1. Fixed XZ archive support, which did not work in beta 2.<br />
<br />
   2. "Convert" command did not allow to use compression dictionaries<br />
      exceeding 4 MB.<br />
<br />
   3. If both encryption password and archive comment were specified<br />
      when creating RAR archive, archive comment was not added.<br />
<br />
   4. "View as Unicode (UTF-8)" command in internal viewer did not work,<br />
      so UTF-8 files were displayed correctly only if their encoding<br />
      was detected by viewer automatically.<br />
<br />
   5. Maximum compression dictionary size when running in Windows XP x86<br />
      is reduced to 128 MB. WinRAR cannot allocate enough memory to<br />
      create archives with 256 MB dictionary in Windows XP x86.<br />
<br />
   6. Corrections in relative path processing, such as "..\arcname.rar" name<br />
      in archiving dialog or "WinRAR foldername" in the command line.</blockquote>
<br />
<blockquote><cite>Quote:</cite>   Version 5.00 beta 4<br />
<br />
   1. If archiving operation cannot allocate memory required for compression<br />
      dictionary, it automatically reduces the dictionary size.<br />
<br />
   2. Decompression algorithm can store the dictionary in several memory<br />
      blocks. It helps to unpack an archive on systems with high level<br />
      of memory heap fragmentation, when no single memory block<br />
      is large enough to fit the entire compression dictionary.</blockquote>
<br />
<a href="http://www.rarlab.com/rarnew.htm" target="_blank">Source</a>]]></description>
			<content:encoded><![CDATA[<blockquote><cite>Quote:</cite> Version 5.00 beta 3<br />
<br />
   1. Fixed XZ archive support, which did not work in beta 2.<br />
<br />
   2. "Convert" command did not allow to use compression dictionaries<br />
      exceeding 4 MB.<br />
<br />
   3. If both encryption password and archive comment were specified<br />
      when creating RAR archive, archive comment was not added.<br />
<br />
   4. "View as Unicode (UTF-8)" command in internal viewer did not work,<br />
      so UTF-8 files were displayed correctly only if their encoding<br />
      was detected by viewer automatically.<br />
<br />
   5. Maximum compression dictionary size when running in Windows XP x86<br />
      is reduced to 128 MB. WinRAR cannot allocate enough memory to<br />
      create archives with 256 MB dictionary in Windows XP x86.<br />
<br />
   6. Corrections in relative path processing, such as "..\arcname.rar" name<br />
      in archiving dialog or "WinRAR foldername" in the command line.</blockquote>
<br />
<blockquote><cite>Quote:</cite>   Version 5.00 beta 4<br />
<br />
   1. If archiving operation cannot allocate memory required for compression<br />
      dictionary, it automatically reduces the dictionary size.<br />
<br />
   2. Decompression algorithm can store the dictionary in several memory<br />
      blocks. It helps to unpack an archive on systems with high level<br />
      of memory heap fragmentation, when no single memory block<br />
      is large enough to fit the entire compression dictionary.</blockquote>
<br />
<a href="http://www.rarlab.com/rarnew.htm" target="_blank">Source</a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Avast! 8 Premier Test (SafeGroupVideo)]]></title>
			<link>http://malwaretips.com/Thread-Avast-8-Premier-Test-SafeGroupVideo</link>
			<pubDate>Sun, 19 May 2013 22:40:35 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-Avast-8-Premier-Test-SafeGroupVideo</guid>
			<description><![CDATA[<!-- start: video_youtube_embed --><br />
<iframe title="YouTube video player" width="790" height="550" src="http://www.youtube.com/embed/U_OobDYxqmQ" frameborder="0" allowfullscreen></iframe><br />
<!-- end: video_youtube_embed -->]]></description>
			<content:encoded><![CDATA[<!-- start: video_youtube_embed --><br />
<iframe title="YouTube video player" width="790" height="550" src="http://www.youtube.com/embed/U_OobDYxqmQ" frameborder="0" allowfullscreen></iframe><br />
<!-- end: video_youtube_embed -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Kaspersky Antivirus 2013 & Comodo Firewall Free Review  (My IT Tech)]]></title>
			<link>http://malwaretips.com/Thread-Kaspersky-Antivirus-2013-Comodo-Firewall-Free-Review-My-IT-Tech</link>
			<pubDate>Sun, 19 May 2013 21:28:58 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-Kaspersky-Antivirus-2013-Comodo-Firewall-Free-Review-My-IT-Tech</guid>
			<description><![CDATA[<!-- start: video_youtube_embed --><br />
<iframe title="YouTube video player" width="790" height="550" src="http://www.youtube.com/embed/0yqqS8dAWsU" frameborder="0" allowfullscreen></iframe><br />
<!-- end: video_youtube_embed -->]]></description>
			<content:encoded><![CDATA[<!-- start: video_youtube_embed --><br />
<iframe title="YouTube video player" width="790" height="550" src="http://www.youtube.com/embed/0yqqS8dAWsU" frameborder="0" allowfullscreen></iframe><br />
<!-- end: video_youtube_embed -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Ashampoo Win Optimizer 9]]></title>
			<link>http://malwaretips.com/Thread-Giveaway-Ashampoo-Win-Optimizer-9</link>
			<pubDate>Sun, 19 May 2013 19:57:24 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-Giveaway-Ashampoo-Win-Optimizer-9</guid>
			<description><![CDATA[<a href="http://www.ashampoo.com/frontend/registration/php/trial_step1.php?session_langid=2&amp;edition_id=iswygg5gj1diflnqfwuwytvro1tl80zh&amp;ref=linktarget" target="_blank">http://www.ashampoo.com/frontend/registr...linktarget</a>]]></description>
			<content:encoded><![CDATA[<a href="http://www.ashampoo.com/frontend/registration/php/trial_step1.php?session_langid=2&amp;edition_id=iswygg5gj1diflnqfwuwytvro1tl80zh&amp;ref=linktarget" target="_blank">http://www.ashampoo.com/frontend/registr...linktarget</a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Nice forum]]></title>
			<link>http://malwaretips.com/Thread-Nice-forum</link>
			<pubDate>Sun, 19 May 2013 14:54:03 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-Nice-forum</guid>
			<description><![CDATA[I finally joined after finding this forum numerous times with a search engine while looking for answers, I think I will enjoy it here.<br />
<br />
Hello everyone <img src="images/smilies/biggrin.gif" style="vertical-align: middle;" border="0" alt="Big Grin" title="Big Grin" />]]></description>
			<content:encoded><![CDATA[I finally joined after finding this forum numerous times with a search engine while looking for answers, I think I will enjoy it here.<br />
<br />
Hello everyone <img src="images/smilies/biggrin.gif" style="vertical-align: middle;" border="0" alt="Big Grin" title="Big Grin" />]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Glary Utilities Professional Edition 3.3 Free Registration Code]]></title>
			<link>http://malwaretips.com/Thread-Giveaway-Glary-Utilities-Professional-Edition-3-3-Free-Registration-Code</link>
			<pubDate>Sun, 19 May 2013 14:20:35 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-Giveaway-Glary-Utilities-Professional-Edition-3-3-Free-Registration-Code</guid>
			<description><![CDATA[The new Glary Utilities Pro 3.3 comes with a new and innovative design. All Glary Utilities tools can be accessed through an eye-pleasing and totally simplistic interface. Bundle that with the updated scanning engine, you can now scan and analyse your PC issues eight times more fast and thoroughly than before. Glary Utilities Pro normally charges &#36;39.95 (discounted to &#36;27.94 right now), but for unknown reason, you are able to download Glary Utilities Pro 3.3 (latest version) without paying a cent. I am not sure for how long it will be offered as Pro, so if you are interested maybe grab while the grabbing is good.<br />
<br />
<img src="http://3.bp.blogspot.com/-8_Ly2_RfcYw/UXQwz9hmZeI/AAAAAAAAPYo/O-E_1uzjVEs/s1600/Glary+Utilities+Pro+3.1.0.96+Beta+Full+Serial.jpg" border="0" alt="[Image: Glary+Utilities+Pro+3.1.0.96+Beta+Full+Serial.jpg]" /><br />
<br />
 you can download it using this direct link: gu3setup.exe [14.5 MB]<br />
<a href="http://download.glarysoft.com/gu3setup.exe" target="_blank">http://download.glarysoft.com/gu3setup.exe</a><br />
<br />
 - Install it. During installation, you do not need to enter any license. Just install it as freeware edition. After installation, run Glary Utilities 3. It will show you as free version. <br />
- Click on the “Upgrade Now” button<br />
- Registration window will open. The registration code is pre-filled, you only need to enter you name and press OK button.<br />
- Your professional Edition of Glary Utilities 3.3 is now activated for lifetime (Expiration Date: Never).<br />
<br />
Enjoy! <img src="images/smilies/biggrin.gif" style="vertical-align: middle;" border="0" alt="Big Grin" title="Big Grin" />]]></description>
			<content:encoded><![CDATA[The new Glary Utilities Pro 3.3 comes with a new and innovative design. All Glary Utilities tools can be accessed through an eye-pleasing and totally simplistic interface. Bundle that with the updated scanning engine, you can now scan and analyse your PC issues eight times more fast and thoroughly than before. Glary Utilities Pro normally charges &#36;39.95 (discounted to &#36;27.94 right now), but for unknown reason, you are able to download Glary Utilities Pro 3.3 (latest version) without paying a cent. I am not sure for how long it will be offered as Pro, so if you are interested maybe grab while the grabbing is good.<br />
<br />
<img src="http://3.bp.blogspot.com/-8_Ly2_RfcYw/UXQwz9hmZeI/AAAAAAAAPYo/O-E_1uzjVEs/s1600/Glary+Utilities+Pro+3.1.0.96+Beta+Full+Serial.jpg" border="0" alt="[Image: Glary+Utilities+Pro+3.1.0.96+Beta+Full+Serial.jpg]" /><br />
<br />
 you can download it using this direct link: gu3setup.exe [14.5 MB]<br />
<a href="http://download.glarysoft.com/gu3setup.exe" target="_blank">http://download.glarysoft.com/gu3setup.exe</a><br />
<br />
 - Install it. During installation, you do not need to enter any license. Just install it as freeware edition. After installation, run Glary Utilities 3. It will show you as free version. <br />
- Click on the “Upgrade Now” button<br />
- Registration window will open. The registration code is pre-filled, you only need to enter you name and press OK button.<br />
- Your professional Edition of Glary Utilities 3.3 is now activated for lifetime (Expiration Date: Never).<br />
<br />
Enjoy! <img src="images/smilies/biggrin.gif" style="vertical-align: middle;" border="0" alt="Big Grin" title="Big Grin" />]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Inable to download anything. (Suspect ZeroAccess rootkit)]]></title>
			<link>http://malwaretips.com/Thread-Inable-to-download-anything-Suspect-ZeroAccess-rootkit</link>
			<pubDate>Sun, 19 May 2013 10:45:07 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-Inable-to-download-anything-Suspect-ZeroAccess-rootkit</guid>
			<description><![CDATA[As you can see, I've done my homework. I've tried to do this on my own, but I suppose now is a good a time as ever to turn to help.<br />
<br />
I forgot to run the OTL Scan and the aswMBR scan, and will attatch them in a second post as soon as possible. Thank you for reading.]]></description>
			<content:encoded><![CDATA[As you can see, I've done my homework. I've tried to do this on my own, but I suppose now is a good a time as ever to turn to help.<br />
<br />
I forgot to run the OTL Scan and the aswMBR scan, and will attatch them in a second post as soon as possible. Thank you for reading.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Can't Install or Uninstall any programs]]></title>
			<link>http://malwaretips.com/Thread-Can-t-Install-or-Uninstall-any-programs</link>
			<pubDate>Sun, 19 May 2013 10:19:35 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-Can-t-Install-or-Uninstall-any-programs</guid>
			<description><![CDATA[Sorry if I posted in the wrong place.<br />
Here is the problem.<br />
I have a laptop runing Windows XP. If I try to unistall programs, I get an error. <br />
Internal Error 2203. C:\\WINDOWS\Installer\674d42.ipi,<br />
-2147287035<br />
And I also can't install any new programs.<br />
Error<br />
Setup was unable to create the directory "C:\DOCUME~1\*user name*"\LOCALS~1\Temp\is-OAKQB.tmp".<br />
Error 5: Access is denied<br />
Can someone please help me?]]></description>
			<content:encoded><![CDATA[Sorry if I posted in the wrong place.<br />
Here is the problem.<br />
I have a laptop runing Windows XP. If I try to unistall programs, I get an error. <br />
Internal Error 2203. C:\\WINDOWS\Installer\674d42.ipi,<br />
-2147287035<br />
And I also can't install any new programs.<br />
Error<br />
Setup was unable to create the directory "C:\DOCUME~1\*user name*"\LOCALS~1\Temp\is-OAKQB.tmp".<br />
Error 5: Access is denied<br />
Can someone please help me?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Glad to be part of the community!]]></title>
			<link>http://malwaretips.com/Thread-Glad-to-be-part-of-the-community</link>
			<pubDate>Sun, 19 May 2013 09:59:54 -0600</pubDate>
			<guid isPermaLink="false">http://malwaretips.com/Thread-Glad-to-be-part-of-the-community</guid>
			<description><![CDATA[Hi everyone!<br />
<br />
I just registered here at MalwareTips.com. What encouraged me to register is because of the "Giveaways" forum, I want to be updated when a paid product will offer a extended trial or a free license, especially if it is an antivirus or system utility like defragger, system cleaner, etc. =D<br />
<br />
Anyways, I have two questions....<br />
<br />
<span style="font-weight: bold;">1)</span> How can I change me signature? I can't find it in 'edit profile' in the 'user control panel' tab<br />
<br />
<span style="font-weight: bold;">2)</span> Is there anyway to <span style="font-weight: bold;">permanently delete</span> an account here at MalwareTips? I created an account with a misspelled username. I want to delete it since I'm not going to use it anyway. So is there anyway?]]></description>
			<content:encoded><![CDATA[Hi everyone!<br />
<br />
I just registered here at MalwareTips.com. What encouraged me to register is because of the "Giveaways" forum, I want to be updated when a paid product will offer a extended trial or a free license, especially if it is an antivirus or system utility like defragger, system cleaner, etc. =D<br />
<br />
Anyways, I have two questions....<br />
<br />
<span style="font-weight: bold;">1)</span> How can I change me signature? I can't find it in 'edit profile' in the 'user control panel' tab<br />
<br />
<span style="font-weight: bold;">2)</span> Is there anyway to <span style="font-weight: bold;">permanently delete</span> an account here at MalwareTips? I created an account with a misspelled username. I want to delete it since I'm not going to use it anyway. So is there anyway?]]></content:encoded>
		</item>
	</channel>
</rss>