Member
Spyware Fighter
Please uninstall Firefox, delete every firefox-related folder manually and reboot. Install firefox without addons and post back with a fresh OTL logfile.
Still problems?
regards
schrauber
Tom, Any idea how to get sound back on for youtube videos. Google search came up with several suggestions. Not sure what really is best. I assume it is a flash problem with drivers. BTW, sound works fine with iTunes.
Larry
Tom, I deleted Google search from the FireFox Search Bar. The redirect is only when using Google search in the Firefox search bar. Google search works fine from the Navigation Bar. I replaced Google Search with Google SSL which works fine in the FF Search Bar.. I normally use Chrome, anyway. The big problem is lack of sound in things like youtube which occurred when the Rootkit was removed.
I did run OTL but since all I did was delete Google Search from the Firefox Search Bar, I did not attach it.
Thanks,
Larry
Tom, Ran Superantispyware again. Log follows. Another Trojan deleted. Not sure where it came from as I have been careful not to visit any "ify" sites. Still no sound from Flash.
SUPERAntiSpyware Scan Log SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!
Generated 06/24/2010 at 04:07 PM
Application Version : 4.39.1002
Core Rules Database Version : 5115
Trace Rules Database Version: 2927
Scan type : Quick Scan
Total Scan Time : 00:32:58
Memory items scanned : 587
Memory threats detected : 0
Registry items scanned : 1799
Registry threats detected : 0
File items scanned : 10337
File threats detected : 2
Adware.Flash Tracking Cookie
C:\Documents and Settings\Larry\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\5P8T9F5R\MSNBCMEDIA.MSN.COM
Trojan.Agent/Gen-Dropper[Wrk]
C:\DOCUMENTS AND SETTINGS\LARRY\LOCAL SETTINGS\TEMP\INS13E.TMP
Member
Spyware Fighter
Please uninstall everything from Plash Player and reboot, then download it again and install it. Post back with a fresh OTL logfile regards
schrauber
Tom, Uninstalled and reinstalled flash. Still no sound from youtube. (Sound is fine in iTunes). Lots of suggestions after Googling, but I did not want to risk trying them. How about this one? Fixed the Adobe Flash no sound problem - Tech Support Guy Forums
Attached is the latest logfile:
OTL logfile created on: 6/25/2010 9:05:46 AM - Run 5
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\Larry\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 53.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.33 Gb Total Space | 5.36 Gb Free Space | 7.21% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HP_LAPTOP
Current User Name: Larry
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal ========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Larry\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - C:\Program Files\NOS\bin\getPlusPlus_Adobe.exe (NOS Microsystems Ltd.)
PRC - C:\Documents and Settings\Larry\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\support.com\bin\tgcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe ()
PRC - C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe ()
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe ()
PRC - C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\HPQ\Quick Launch Buttons\eabservr.exe (Hewlett-Packard )
PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.) ========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Larry\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\ScanSoft\OmniPageSE4\OpHookSE4.dll (Nuance Communications, Inc.)
MOD - C:\Program Files\support.com\bin\sdchook.dll (SupportSoft, Inc.) ========== Win32 Services (SafeList) ==========
SRV - (PEVSystemStart) -- File not found
SRV - (MSSQLServerADHelper) -- File not found
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (mcmscsvc) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (getPlusHelper) getPlus(R) -- C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (McODS) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (FlipShare Service) -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (IntuitUpdateService) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (GoogleDesktopManager-060409-093314) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (McProxy) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McNASvc) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (AdobeActiveFileMonitor5.0) -- C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe ()
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (AcrSch2Svc) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (AdobeActiveFileMonitor) -- C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe ()
SRV - (SoundMAX Agent Service (default)) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.) ========== Driver Services (SafeList) ==========
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (mfehidk) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) -- C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) -- C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (MPFP) -- C:\WINDOWS\system32\drivers\Mpfp.sys (McAfee, Inc.)
DRV - (tmcomm) -- C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (AVG Anti-Rootkit) -- C:\WINDOWS\System32\DRIVERS\avgarkt.sys (GRISOFT, s.r.o.)
DRV - (AvgArCln) -- C:\WINDOWS\system32\drivers\AvgArCln.sys (GRISOFT, s.r.o.)
DRV - (BVRPMPR5) -- C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (BVRP Software)
DRV - (timounter) -- C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (snapman) -- C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (tifsfilter) -- C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (tifm21) -- C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (w29n51) Intel(R) -- C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BCM43XX) -- C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (RTL8023xp) -- C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (ApfiltrService) -- C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (senfilt) -- C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (eabfiltr) -- C:\WINDOWS\system32\drivers\eabfiltr.sys (Hewlett-Packard Company)
DRV - (eabusb) -- C:\WINDOWS\system32\drivers\EabUsb.sys (Hewlett-Packard Company)
DRV - (MidiSyn) -- C:\WINDOWS\system32\drivers\MidiSyn.sys (Analog Devices Inc)
DRV - (SMCIRDA) -- C:\WINDOWS\system32\drivers\smcirda.sys (SMC)
DRV - (AliIde) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Google Toolbar
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = SEARCH - WEB SEARCH - Comcast.net
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = Google Toolbar
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Comcast.net: News, Sports, Video, TV listings, Email and more!
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Google Toolbar
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Google Toolbar
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ==========
FF - prefs.js ..browser.search.order.1: "Google"
FF - prefs.js ..browser.search.useDBForOrder: true
FF - prefs.js ..browser.startup.homepage: "http://www.eternalsunset.net/more.php|http://www.headlinespot.com/|http://www.nytimes.com/|http://www.washingtonpost.com/?reload=true|http://news.bbc.co.uk/|http://www.huffingtonpost.com/|http://online.wsj.com/public/us|http://www.cnn.com/?refresh=1|http://finance.yahoo.com/|http://www.wunderground.com/cgi-bin/findweather/getForecast?query=60558&MR=1|http://www.msnbc.msn.com/|http://www.aldaily.com/|http://www.webbkameror.se/webbkameror/gondolen/webkamera_eriks_640_2.php|http://www.techmeme.com/"
FF - prefs.js ..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js ..extensions.enabledItems: support@ancestry.com :1.0.0.1
FF - prefs.js ..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6
FF - prefs.js ..extensions.enabledItems: {103B2EA2-F063-4273-958D-6B46E5B6F98C}:1.3.1.1
FF - prefs.js ..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.3
FF - prefs.js ..extensions.enabledItems: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.5
FF - prefs.js ..extensions.enabledItems: {6e84150a-d526-41f1-a480-a67d3fed910d}:1.4.5.1
FF - prefs.js ..extensions.enabledItems: {E4091D66-127C-11DB-903A-DE80D2EFDFE8}:1.6.4
FF - prefs.js ..extensions.enabledItems: jqs@sun.com :1.0
FF - prefs.js ..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8
FF - prefs.js ..extensions.enabledItems: {1ced4832-f06e-413f-aa14-9eb63ad40ace}:1.0.2
FF - prefs.js ..extensions.enabledItems: {53A03D43-5363-4669-8190-99061B2DEBA5}:1.3.7
FF - prefs.js ..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.6.7.4
FF - prefs.js ..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.2
FF - prefs.js ..extensions.enabledItems: {89736E8E-4B14-4042-8C75-AD00B6BD3900}:1.0.5
FF - prefs.js ..extensions.enabledItems: foxmarks@kei.com :3.6.14
FF - prefs.js ..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js ..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js ..extensions.enabledItems: {a45e6b3a-725d-4b20-afde-e7486bfe317c}:3.5.4
FF - prefs.js ..extensions.enabledItems: {c9c58820-7bd4-11da-a72b-0800200c9a66}:3.20100306
FF - prefs.js ..extensions.enabledItems: {36C13C8F-54F1-412e-8177-2E411719162D}:4.1.1
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.4\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/22 17:11:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.4\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/23 07:42:05 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/04/07 07:39:24 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010/04/16 17:59:56 | 000,000,000 | ---D | M]
[2008/08/28 19:33:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\Mozilla\Extensions
[2010/06/23 08:27:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions
[2010/05/09 11:49:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2007/10/19 10:33:18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{07d43a66-4e08-4028-b473-ae9f7f991984}
[2006/01/14 18:29:14 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{07D70F98-08D3-432e-8BD6-496AD6481A68}
[2010/02/24 06:50:45 | 000,000,000 | ---D | M] (Copy Link Name) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{103B2EA2-F063-4273-958D-6B46E5B6F98C}
[2009/12/11 07:35:13 | 000,000,000 | ---D | M] (Session Manager) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}
[2009/09/15 20:45:46 | 000,000,000 | ---D | M] (Nuke Anything Enhanced) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{1ced4832-f06e-413f-aa14-9eb63ad40ace}
[2010/04/28 17:39:02 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2007/10/19 10:33:18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{2564ae73-58ac-4aab-9a32-b531c778b549}
[2006/01/14 13:33:58 | 000,000,000 | ---D | M] (Silver Skin) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{2A10B180-05EF-11D9-8C50-444553540001}
[2006/01/14 13:33:13 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{3143B27B-F7DE-49d8-BF08-C2E4DEA71DBB}
[2010/02/24 06:50:49 | 000,000,000 | ---D | M] (Linkification) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2010/03/29 21:23:49 | 000,000,000 | ---D | M] (Qute) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{36C13C8F-54F1-412e-8177-2E411719162D}
[2007/10/19 10:33:17 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{3a7c7029-261d-4349-a53c-dff12ed8c4f4}
[2010/03/29 21:24:20 | 000,000,000 | ---D | M] (ScrapBook) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2010/01/27 19:58:01 | 000,000,000 | ---D | M] (IE View) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2007/10/19 10:33:20 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{74FD056A-18A2-41d8-B9A8-2025C3FFBA94}
[2009/06/04 08:44:29 | 000,000,000 | ---D | M] (IE Tab) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2008/06/02 22:10:39 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}
[2008/06/04 08:01:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}-trash
[2010/01/27 19:58:00 | 000,000,000 | ---D | M] (Firefox Showcase) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
[2008/07/24 10:52:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{89736E8E-4B14-4042-8C75-AD00B6BD3900}
[2010/03/29 21:23:48 | 000,000,000 | ---D | M] (Aluminium Kai 2) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{a45e6b3a-725d-4b20-afde-e7486bfe317c}
[2010/04/21 13:44:30 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/06/30 19:36:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
[2010/03/13 19:27:40 | 000,000,000 | ---D | M] (iPox) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{c9c58820-7bd4-11da-a72b-0800200c9a66}
[2010/05/09 11:49:04 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/10/21 10:55:43 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/06/22 17:14:59 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/05/15 21:02:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{E4091D66-127C-11DB-903A-DE80D2EFDFE8}
[2010/04/21 13:45:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\foxmarks@kei.com
[2008/09/11 16:32:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\notebook@google.com
[2010/04/28 17:39:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\personas@christopher.beard
[2009/08/25 17:37:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\redshift_V2@shift-themes.com
[2009/11/11 14:07:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\support@ancestry.com
[2010/03/13 19:27:40 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{c9c58820-7bd4-11da-a72b-0800200c9a66}\chrome\mozapps\extensions
[2010/03/13 19:27:39 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\extensions\{c9c58820-7bd4-11da-a72b-0800200c9a66}\chrome\mozapps\extensions\CVS
[2010/06/18 08:38:21 | 000,001,820 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\searchplugins\bing.xml
[2010/06/18 08:41:18 | 000,005,719 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\searchplugins\google-ssl.xml
[2010/06/18 08:47:56 | 000,002,027 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\searchplugins\google-translate-any--en.xml
[2008/06/19 00:58:26 | 000,000,681 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\searchplugins\webster.xml
[2008/06/19 00:58:26 | 000,001,108 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\searchplugins\wikipedia.xml
[2010/06/18 08:39:56 | 000,004,140 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Profiles\xhk64krx.default\searchplugins\youtube.xml
[2010/06/23 08:27:11 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/06/23 07:42:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/06/23 07:41:44 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2006/01/18 13:50:00 | 000,319,488 | ---- | M] ( ) -- C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll
[2010/06/11 19:57:04 | 000,002,076 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google_search.xml
O1 HOSTS File: ([2010/06/16 06:13:58 | 000,000,020 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 84.16.244.58 us.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [Acronis*True*Image Monitor] C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe File not found
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe (Hewlett-Packard )
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\Larry\Start Menu\Programs\Startup\YPOPs!.lnk = C:\Program Files\YPOPs\ypops.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {594ECDD4-A991-4208-A7B7-00DDAD9BE328} http://media.labs.live.com/all/ps/_code_/Photosynth.cab (Photosynth Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/res...scbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsof...?1135014702306 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.72.134 68.87.77.134
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\Hp\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Larry\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{40dade5c-e923-11de-be5d-0015001dc5f9}\Shell\AutoRun\command - "" = E:\Setup_FlipShare.exe -- File not found
O33 - MountPoints2\{40dade5c-e923-11de-be5d-0015001dc5f9}\Shell\Setup FlipShare\command - "" = E:\Setup_FlipShare.exe -- File not found
O33 - MountPoints2\{d5296494-dc82-11de-be54-0015001dc5f9}\Shell\AutoRun\command - "" = E:\setup.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ==========
[2010/06/25 08:49:13 | 000,231,888 | ---- | C] (Adobe Systems, Inc.) -- C:\Documents and Settings\Larry\Desktop\uninstall_flash_player.exe
[2010/06/23 08:41:20 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/06/23 08:25:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/06/23 07:42:05 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010/06/23 07:42:04 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010/06/23 07:42:04 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/06/23 07:42:04 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/06/23 07:42:04 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/06/23 07:17:54 | 016,295,712 | ---- | C] (Sun Microsystems, Inc.) -- C:\Documents and Settings\Larry\Desktop\jre-6u20-windows-i586.exe
[2010/06/22 20:28:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Larry\Application Data\McAfee
[2010/06/22 17:15:04 | 000,000,000 | ---D | C] -- C:\Program Files\NOS
[2010/06/22 17:15:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NOS
[2010/06/21 12:02:27 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/06/21 12:01:56 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/06/21 11:53:25 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/06/20 12:24:46 | 000,998,736 | ---- | C] (Kaspersky Lab) -- C:\Documents and Settings\Larry\Desktop\TDSSKiller.exe
[2010/06/20 10:58:26 | 000,000,000 | --SD | C] -- C:\schrauber
[2010/06/20 10:43:27 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/06/20 10:37:45 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/06/20 10:37:45 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/06/20 10:37:45 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/06/20 10:37:45 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/06/20 10:37:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/06/20 10:35:15 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/06/19 07:39:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Larry\Application Data\Template
[2010/06/18 12:21:17 | 000,572,416 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Larry\Desktop\OTL.exe
[2010/06/18 12:07:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Larry\My Documents\hp problem
[2010/06/16 21:04:53 | 010,341,832 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Larry\Desktop\windows-kb890830-v3.8.exe
[2010/06/16 20:46:06 | 000,532,480 | ---- | C] (Trend Micro Incorporated) -- C:\Documents and Settings\Larry\Desktop\cwshredder.exe
[2010/06/16 06:45:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Larry\Desktop\backups
[2010/06/16 06:37:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Larry\My Documents\hijackthis
[2010/06/16 06:12:42 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Larry\Desktop\HijackThis.exe
[2010/06/15 21:54:12 | 000,034,248 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mferkdk.sys
[2010/06/15 21:54:09 | 000,040,552 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfesmfk.sys
[2010/06/15 21:54:08 | 000,214,664 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfehidk.sys
[2010/06/15 21:54:08 | 000,079,816 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeavfk.sys
[2010/06/15 21:54:08 | 000,035,272 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfebopk.sys
[2010/06/15 21:54:00 | 000,120,136 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\Mpfp.sys
[2010/06/15 21:53:20 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee.com
[2010/06/15 21:53:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\McAfee
[2010/06/15 21:53:03 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee
[2010/06/15 17:20:17 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/06/15 17:20:16 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/06/15 17:20:16 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/15 16:59:27 | 000,000,000 | ---D | C] -- C:\4075c12769b82126e2
[2010/06/15 16:38:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/06/15 16:38:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/15 14:56:47 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2010/06/15 08:16:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Larry\Local Settings\Application Data\{B2501F85-D055-477B-97D7-B0158EF5C0D5}
[2010/06/15 08:14:09 | 000,000,000 | ---D | C] -- C:\spoolerlogs
[2010/06/15 08:12:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Larry\Application Data\0162AF75ABADEC679B7FA90BE0F70F5D
[2010/06/10 03:14:10 | 000,000,000 | ---D | C] -- C:\a01d82a5f56a1f02b6
[2010/06/09 23:42:37 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/06/02 21:41:44 | 003,600,384 | ---- | C] (Google Inc.) -- C:\WINDOWS\System32\GPhotos.scr
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\Documents and Settings\Larry\My Documents\*.tmp files -> C:\Documents and Settings\Larry\My Documents\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files - Modified Within 30 Days ==========
[2010/06/25 09:05:01 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2189691198-1194379149-427336440-1007UA.job
[2010/06/25 08:49:15 | 000,231,888 | ---- | M] (Adobe Systems, Inc.) -- C:\Documents and Settings\Larry\Desktop\uninstall_flash_player.exe
[2010/06/25 08:15:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/25 03:05:01 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2189691198-1194379149-427336440-1007Core.job
[2010/06/25 00:29:22 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2010/06/24 23:06:06 | 000,002,321 | ---- | M] () -- C:\Documents and Settings\Larry\Desktop\Google Chrome.lnk
[2010/06/24 21:15:01 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/24 18:13:51 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/06/24 18:10:14 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/06/24 18:10:09 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/06/24 18:10:05 | 1600,638,976 | -HS- | M] () -- C:\hiberfil.sys
[2010/06/24 18:08:47 | 007,077,888 | ---- | M] () -- C:\Documents and Settings\Larry\ntuser.dat
[2010/06/24 18:08:47 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Larry\ntuser.ini
[2010/06/24 03:09:06 | 000,571,778 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/24 03:09:06 | 000,490,020 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/06/24 03:09:06 | 000,091,840 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/06/23 07:41:42 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/06/23 07:41:42 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/06/23 07:41:42 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/06/23 07:41:42 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010/06/23 07:41:41 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010/06/23 07:18:06 | 016,295,712 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\Larry\Desktop\jre-6u20-windows-i586.exe
[2010/06/22 22:49:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/06/21 12:04:45 | 000,001,804 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/06/20 10:43:37 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/06/20 10:25:55 | 003,716,715 | R--- | M] () -- C:\Documents and Settings\Larry\Desktop\schrauber.exe
[2010/06/19 07:45:52 | 000,000,795 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/06/19 07:39:26 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\wklnhst.dat
[2010/06/18 12:56:24 | 000,293,376 | ---- | M] () -- C:\r5xidd2y.exe
[2010/06/18 12:20:33 | 000,572,416 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Larry\Desktop\OTL.exe
[2010/06/16 20:58:45 | 010,341,832 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Larry\Desktop\windows-kb890830-v3.8.exe
[2010/06/16 20:40:12 | 000,532,480 | ---- | M] (Trend Micro Incorporated) -- C:\Documents and Settings\Larry\Desktop\cwshredder.exe
[2010/06/16 16:04:11 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/06/16 16:04:11 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010/06/16 06:13:58 | 000,000,020 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/06/16 06:10:02 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Larry\Desktop\HijackThis.exe
[2010/06/16 03:21:35 | 000,347,400 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/16 03:13:46 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/06/15 21:55:30 | 000,000,708 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2010/06/15 21:53:39 | 000,000,340 | ---- | M] () -- C:\WINDOWS\tasks\McDefragTask.job
[2010/06/15 21:16:52 | 000,070,656 | ---- | M] () -- C:\Documents and Settings\Larry\My Documents\Copy of 2009MurderViolentCrimeRankings.xls
[2010/06/15 17:20:20 | 000,000,733 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/15 17:16:04 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Larry\Desktop\mbam-setup.exe
[2010/06/15 15:28:39 | 000,002,463 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/06/15 08:16:26 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Szokoqoyeja.dat
[2010/06/15 08:16:26 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Sbiba.bin
[2010/06/02 21:41:44 | 003,600,384 | ---- | M] (Google Inc.) -- C:\WINDOWS\System32\GPhotos.scr
[2010/05/31 10:41:00 | 000,998,736 | ---- | M] (Kaspersky Lab) -- C:\Documents and Settings\Larry\Desktop\TDSSKiller.exe
[2010/05/27 19:20:16 | 000,006,211 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\PrimoPDFSet.xml
[2010/05/26 12:11:52 | 000,015,360 | ---- | M] () -- C:\Documents and Settings\Larry\My Documents\retiree health costs (version 1).xls
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\Documents and Settings\Larry\My Documents\*.tmp files -> C:\Documents and Settings\Larry\My Documents\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files Created - No Company Name ==========
[2010/06/21 12:04:45 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/06/20 10:43:36 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/06/20 10:43:30 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/06/20 10:37:45 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/06/20 10:37:45 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/06/20 10:37:45 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/06/20 10:37:45 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/06/20 10:37:45 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/06/20 10:28:06 | 003,716,715 | R--- | C] () -- C:\Documents and Settings\Larry\Desktop\schrauber.exe
[2010/06/19 07:39:26 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Larry\Application Data\wklnhst.dat
[2010/06/18 12:58:05 | 000,293,376 | ---- | C] () -- C:\r5xidd2y.exe
[2010/06/16 16:05:51 | 1600,638,976 | -HS- | C] () -- C:\hiberfil.sys
[2010/06/15 21:55:30 | 000,000,708 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2010/06/15 21:53:39 | 000,000,340 | ---- | C] () -- C:\WINDOWS\tasks\McDefragTask.job
[2010/06/15 21:16:52 | 000,070,656 | ---- | C] () -- C:\Documents and Settings\Larry\My Documents\Copy of 2009MurderViolentCrimeRankings.xls
[2010/06/15 21:05:38 | 000,001,571 | ---- | C] () -- C:\Documents and Settings\Larry\Start Menu\Programs\Startup\YPOPs!.lnk
[2010/06/15 17:20:20 | 000,000,733 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/15 15:28:39 | 000,002,463 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/06/15 08:16:26 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Szokoqoyeja.dat
[2010/06/15 08:16:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Sbiba.bin
[2010/06/01 00:41:22 | 007,077,888 | ---- | C] () -- C:\Documents and Settings\Larry\ntuser.dat
[2010/05/26 12:11:51 | 000,015,360 | ---- | C] () -- C:\Documents and Settings\Larry\My Documents\retiree health costs (version 1).xls
[2008/05/14 14:05:49 | 000,176,235 | ---- | C] () -- C:\WINDOWS\System32\Primomonnt.dll
[2008/02/19 01:33:34 | 000,446,352 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2007/10/14 19:34:13 | 000,010,236 | ---- | C] () -- C:\WINDOWS\hpdj3840.ini
[2007/10/09 17:00:01 | 000,011,776 | ---- | C] () -- C:\WINDOWS\System32\pmsbfn32.dll
[2007/10/09 16:55:23 | 000,000,412 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2007/02/15 07:06:49 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2006/11/06 17:49:36 | 000,000,310 | ---- | C] () -- C:\WINDOWS\primopdf.ini
[2006/04/16 07:04:37 | 000,000,206 | ---- | C] () -- C:\WINDOWS\HPGdiPlus.ini
[2006/04/12 20:25:03 | 000,010,511 | ---- | C] () -- C:\WINDOWS\hpdj3600.ini
[2006/01/02 12:43:13 | 000,037,888 | ---- | C] () -- C:\WINDOWS\System32\setupnt.dll
[2005/12/30 17:55:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2005/12/19 16:50:14 | 000,000,078 | ---- | C] () -- C:\WINDOWS\qwimp.ini
[2005/12/19 15:48:50 | 000,000,165 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2005/12/19 14:23:33 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/08/02 01:44:13 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2005/08/02 01:44:13 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2005/08/02 01:44:13 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2005/08/02 01:44:13 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2005/08/02 01:44:13 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2005/08/02 01:44:13 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2005/08/02 01:27:22 | 000,015,669 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005/07/01 06:47:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/07 08:16:44 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/08/07 08:10:08 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/01/13 14:46:34 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\tifmicon.dll
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
< End of report >
Member
Spyware Fighter
You can try this. In which browser do you have no sound with flash? IF in firefox, did you install firefox without any addons like I said above?
regards
schrauber
No sound using Flash in Chrome and Firefox.
Member
Spyware Fighter
After you have tried the above? What about my question? Are there any addons installed?
Please follow the guide here Codec Guide: 10 fixes for sound problems in Flash videos regards
schrauber
I tried the 10 flash video sound fixes (except for the quicktime, could not find control panel). I did not try the fix I found, http://forums.techguy.org/multimedia....html.......it was not clear to me how one was to edict the registry......I was nervous to try it). Could you provide more details, if you feel this would be a useful attempt.
No sound in Chrome and FireFox. Sound in iTunes.
I am not clear what your suggestion to delete Firefox and all related folders will accomplish? Do you feel that deleting Firefox could possibly solve the problem with no sound in flash when using Chrome.
Thanks
Larry