Jump to content

Recommended Posts

Posted

Hi, firstly apologies if this isn't posted in the correct forum and it's something that's been asked a million times before.

I have an old Advent laptop using XP.

It started off with 40GBB HDD but for the past year or so the Local Disk C has been showing total size 32GB with about 8 free. I assumed it was all the photos and documents I had stored that was clogging it up so I bought an external hard drive and have stored all my docs and photos on there. By using Wise disk cleaner regularly we've got along OK. I only use the laptop to play, go shopping and send e-mails.

Over the last couple of weeks the free space has slowly gone and is now down to 2.66GB. The disk cleaner has made no difference. I can't do a defragmentation as there isn't enough free space to do it.

Can anyone explain in very very simple language if there is anything I can do? I realise the laptop is very old and out of date but I cannot afford a new one.

Many thanks

Jane

  • Replies 29
  • Created
  • Last Reply

Top Posters In This Topic

Posted

Hi, thanks for the quick response and the welcome.

I ran the scan and it produced the following:

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 142

Registry Values Infected: 12

Registry Data Items Infected: 2

Folders Infected: 22

Files Infected: 156

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{1093995A-BA37-41D2-836E-091067C4AD17} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.DataControl.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.DataControl (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{2EFF3CF7-99C1-4c29-BC2B-68E057E22340} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\TypeLib\{621FEACD-8857-43A6-AE26-451D670D5370} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{2763E333-B168-41A0-A112-D35F96F410C0} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.ShellViewControl.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.ShellViewControl (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.2 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.1 (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{A9571378-68A1-443d-B082-284F960C6D17} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{B813095C-81C0-4E40-AA14-67520372B987} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA} (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton.1 (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{819FFE22-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\TypeLib\{819FFE20-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{799391D3-EB86-4bac-9BD3-CBFEA58A0E15} (Adware.MyWebSearch) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{D858DAFC-9573-4811-B323-7011A3AA7E61} (Adware.MyWebSearch) -> No action taken.

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\My Web Search Bar Search Scope Monitor (Adware.MyWebSearch) -> Value: My Web Search Bar Search Scope Monitor -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44CF-8957-5838F569A31D} -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44cf-8957-5838F569A31D} -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Value: (default) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Value: f3PopularScreensavers -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Value: FunWebProducts -> No action taken.

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:

c:\program files\funwebproducts (Adware.MyWebSearch) -> No action taken.

c:\program files\funwebproducts\screensaver (Adware.MyWebSearch) -> No action taken.

c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> No action taken.

c:\program files\funwebproducts\Shared (Adware.MyWebSearch) -> No action taken.

c:\program files\funwebproducts\Shared\Cache (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\chrome (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Avatar (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Game (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\icons (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Notifier (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Overlay (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\SrchAstt (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\SrchAstt\1.bin (Adware.MyWebSearch) -> No action taken.

Files Infected:

c:\Program Files\MyWebSearch\bar\2.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> No action taken.

c:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\MWSSVC.EXE (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\MWSBAR.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\1.bin\F3SHLLVW.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\M3HTML.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\M3SKIN.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\M3MSG.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3REPROX.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> No action taken.

c:\WINDOWS\system32\f3PSSavr.scr (PUP.FunWebProducts) -> No action taken.

c:\program files\funwebproducts\screensaver\Images\3E83D10D.urr (Adware.MyWebSearch) -> No action taken.

c:\program files\funwebproducts\Shared\Cache\cursormaniabtn.html (Adware.MyWebSearch) -> No action taken.

c:\program files\funwebproducts\Shared\Cache\funbuddyiconbtn.html (Adware.MyWebSearch) -> No action taken.

c:\program files\funwebproducts\Shared\Cache\mailstampbtn.html (Adware.MyWebSearch) -> No action taken.

c:\program files\funwebproducts\Shared\Cache\myfuncardsimbtn.html (Adware.MyWebSearch) -> No action taken.

c:\program files\funwebproducts\Shared\Cache\mysignatureinsertbtn.html (Adware.MyWebSearch) -> No action taken.

c:\program files\funwebproducts\Shared\Cache\mysignaturepreviewbtn.html (Adware.MyWebSearch) -> No action taken.

c:\program files\funwebproducts\Shared\Cache\mystationerybtn.html (Adware.MyWebSearch) -> No action taken.

c:\program files\funwebproducts\Shared\Cache\smileycentralbtn.html (Adware.MyWebSearch) -> No action taken.

c:\program files\funwebproducts\Shared\Cache\webfettibtn.html (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\1.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\1.bin\m3ffxtbr.manifest (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\1.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3SPACER.WMV (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\chrome.manifest (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3IMSTUB.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3REGHK.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\INSTALL.RDF (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\M3AUXSTB.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\M3DLGHK.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\M3IDLE.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\MWSMLBTN.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\MWSUABTN.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\2.bin\chrome\M3FFXTBR.JAR (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\00097A93 (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\0022484E.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\00224A42.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\00224BA9.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\00224CE2.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\003312B5.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\00331499.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\00372ADD.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\00373925.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\00373AAC (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\00A54572.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\00A54728.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\00A548DD.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\00A54A06.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\0390B4A6 (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\3E6D7CEC.bmp (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\5BE24BD3.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\921ABCC4 (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\B961E08D.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\B961E1C6.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\B961E243.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\B961E2B0.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\DD308D02.bmp (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\DD308DFC.bin (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\DD308E79 (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Cache\files.ini (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\History\search2 (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\History\search3 (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\8_step1.gif (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\autoup.gif (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\autoup.htm (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bkez.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bkgr.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bkgs.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bklf.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bkrg.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bkwebfet.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bkzc.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bkzl.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bkzn.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bkzq.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bkzr.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bkzu.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bkzv.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bkzw.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\bkzwinky.jpg (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\blubtn2d.png (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\blubtn2r.png (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\blubtn3d.png (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\blubtn3r.png (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\center.htm (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\index.htm (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\mid_dots.gif (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\protect.htm (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\rebut4.htm (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\rebut4b.htm (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\rebut4c.htm (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\shield.png (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\shocked.gif (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\stop.gif (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\systray.htm (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\systrayp.htm (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\tp_grad.gif (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Message\COMMON\warn.gif (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Overlay\COMMON.F3S (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Settings\setting2.htm (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Settings\settings.dat (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Settings\settings.dat.bak (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> No action taken.

c:\program files\mywebsearch\SrchAstt\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> No action taken.

 

Many thanks & regards

Jane

 

(Sorry, I had to save it as a text file, it wouldn't let me copy from the scan).

Posted

Hello, janec.

 

My name is etavares and I will be helping you with this log.

 

 

Here are some guidelines to ensure we are able to get your machine back under your control.

 

  • Please do not run any unsupervised scans, fixes, etc. We can work against each other and end up in a worse place.
  • Please subscribe to this topic if you have not already done so. Please check back just in case, as the email system can fail at times.
  • Just because your machine is running better does not mean it is completely cleaned. Please wait for the 'all clear' from me to say when we are done.
  • Please reply within 3 days to be fair to other people asking for help.
  • When in doubt, please stop and ask first. There's no harm in asking questions!

 

 

 

 

 

Step 1

 

 

We need to create an OTL report,

  • Please download OTL from this link.
  • (If that link doesn't work, try this alternate link
  • Save it to your desktop.
  • Double click on the http://billy-oneal.com/Canned%20Speeches/speechimages/OTL/otlDesktopIcon.png icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Select "Use Safelist" under "Extra Registry"
  • Under the Custom Scan box paste this in:

    netsvcs
    msconfig
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.sys /90
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\system32\*.exe /lockedfiles
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\*
    %USERPROFILE%\..|smtmp;true;true;true /FP
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    hklm\software\clients\startmenuinternet|command /rs
    hklm\software\clients\startmenuinternet|command /64 /rs
    CREATERESTOREPOINT
  • Click the Quick Scan button.
  • The scan should take a few minutes.
  • Please copy and paste both logs in your reply. If they are too big to paste in one reply, please split them into separate posts.

 

 

 

 

 

Step 2

 

 

Please download aswMBR ( 511KB ) to your desktop.

  • Double click the aswMBR.exe icon to run it
  • It gives you the option to add the latest Avast definitions and recommends you do so. Ignore it and click No as it may crash your system or hang up and we don't need that info.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

 

Note: aswMBR will save MBR.dat to your desktop. Do NOT delete it until I tell you your computer is clean. It is a backup of your MBR that we may need later.

 

 

 

 

 

 

Step 3

 

Please run MBAM again.

 

 

MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.

  • Click the Update tab, then click Check for Updates and install any it finds.
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.

Back at the main Scanner screen:

  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.

Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

 

 

etavares

Posted

Hello etavares,

OTL log no. 1:

OTL logfile created on: 28/10/2011 13:20:34 - Run 1

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Jane Cureton\Desktop

Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

 

895.36 Mb Total Physical Memory | 164.87 Mb Available Physical Memory | 18.41% Memory free

2.12 Gb Paging File | 1.53 Gb Available in Paging File | 72.14% Paging File free

Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 32.50 Gb Total Space | 2.34 Gb Free Space | 7.19% Space Free | Partition Type: NTFS

 

Computer Name: JCMOSAICS | User Name: Jane Cureton | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2011/10/28 13:16:07 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jane Cureton\Desktop\OTL.exe

PRC - [2010/11/01 18:13:35 | 000,032,849 | ---- | M] (MyWebSearch.com) -- C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE

PRC - [2009/02/09 22:26:23 | 000,386,480 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jucheck.exe

PRC - [2008/10/17 16:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE

PRC - [2008/08/26 23:34:08 | 001,245,064 | ---- | M] () -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

PRC - [2008/08/04 11:20:16 | 003,220,856 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE

PRC - [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2008/02/18 19:37:42 | 000,214,888 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

PRC - [2008/02/10 01:06:33 | 000,238,968 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe

PRC - [2008/02/10 01:06:27 | 000,062,840 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe

PRC - [2008/02/10 01:06:15 | 000,308,600 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE

PRC - [2006/06/07 13:46:31 | 000,180,269 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe

PRC - [2005/08/17 11:39:58 | 000,090,112 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE

PRC - [2004/12/28 15:10:54 | 000,532,480 | ---- | M] (Ralink Technology, Corp.) -- C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe

PRC - [2004/03/01 00:27:40 | 000,184,320 | ---- | M] (InterVideo Inc.) -- C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe

PRC - [2003/07/11 20:45:02 | 000,241,664 | ---- | M] (Nikon Corporation) -- C:\Program Files\Nikon\NkView6\NkvMon.exe

PRC - [1998/12/17 06:09:20 | 000,057,393 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/02/04 18:48:30 | 000,291,840 | ---- | M] () -- C:\WINDOWS\system32\sbe.dll

MOD - [2010/02/05 19:27:45 | 001,291,776 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll

MOD - [2008/08/26 23:34:08 | 001,245,064 | ---- | M] () -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

MOD - [2008/08/26 23:34:08 | 000,357,768 | ---- | M] () -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcnet.dll

MOD - [2008/04/14 01:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll

MOD - [2008/04/14 01:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll

MOD - [2008/03/25 05:50:40 | 000,355,112 | ---- | M] () -- C:\WINDOWS\system32\msjetoledb40.dll

MOD - [2008/02/10 00:51:58 | 000,169,304 | ---- | M] () -- C:\Program Files\Symantec\LiveUpdate\UNRAR.DLL

 

 

========== Win32 Services (SafeList) ==========

 

SRV - File not found [Disabled | Stopped] -- -- (HidServ)

SRV - [2010/11/01 18:13:36 | 000,028,762 | ---- | M] (MyWebSearch.com) [Auto | Stopped] -- C:\Program Files\MyWebSearch\bar\2.bin\MWSSVC.EXE -- (MyWebSearchService)

SRV - [2008/10/17 16:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (LiveUpdate Notice)

SRV - [2008/10/17 16:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (CLTNetCnService)

SRV - [2008/10/17 16:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)

SRV - [2008/10/17 16:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)

SRV - [2008/08/26 23:34:08 | 001,245,064 | ---- | M] () [On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC)

SRV - [2008/08/04 11:20:16 | 003,220,856 | ---- | M] (Symantec Corporation) [On_Demand | Running] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE -- (LiveUpdate)

SRV - [2008/02/18 19:37:42 | 000,214,888 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccProxy.exe -- (ccProxy)

SRV - [2008/02/10 01:06:33 | 000,238,968 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler)

SRV - [2007/08/22 09:21:30 | 000,055,640 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe -- (comHost)

 

 

========== Driver Services (SafeList) ==========

 

DRV - [2011/10/18 07:09:40 | 001,576,312 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111026.025\NAVEX15.SYS -- (NAVEX15)

DRV - [2011/10/18 07:09:40 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111026.025\NAVENG.SYS -- (NAVENG)

DRV - [2011/10/17 23:22:25 | 000,268,728 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20111017.001\SymIDSCo.sys -- (SYMIDSCO)

DRV - [2011/07/28 09:00:00 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\eengine\eeCtrl.sys -- (eeCtrl)

DRV - [2011/07/28 09:00:00 | 000,105,592 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)

DRV - [2009/02/19 12:31:42 | 000,031,280 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SymIM.sys -- (SymIMMP)

DRV - [2009/02/19 12:31:42 | 000,031,280 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SymIM.sys -- (SymIM)

DRV - [2009/02/19 12:31:16 | 000,184,496 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)

DRV - [2009/02/19 12:31:16 | 000,096,560 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMFW.SYS -- (SYMFW)

DRV - [2009/02/19 12:31:16 | 000,038,576 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMIDS.SYS -- (SYMIDS)

DRV - [2009/02/19 12:31:16 | 000,037,424 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMNDIS.SYS -- (SYMNDIS)

DRV - [2009/02/19 12:31:16 | 000,022,320 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)

DRV - [2009/02/19 12:31:16 | 000,013,616 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMDNS.SYS -- (SYMDNS)

DRV - [2009/01/26 07:03:42 | 000,124,464 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)

DRV - [2008/09/05 15:31:42 | 000,447,024 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)

DRV - [2008/07/30 17:42:12 | 000,023,888 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\COH_Mon.sys -- (COH_Mon)

DRV - [2008/02/01 02:51:16 | 000,317,616 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL)

DRV - [2008/02/01 02:51:16 | 000,279,088 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP)

DRV - [2008/02/01 02:51:16 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX)

DRV - [2007/08/09 01:39:56 | 000,036,056 | ---- | M] (Symantec Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CO_Mon.sys -- (CO_Mon)

DRV - [2005/08/19 10:31:52 | 003,644,800 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)

DRV - [2005/07/13 15:37:16 | 001,269,760 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)

DRV - [2005/07/01 08:58:58 | 001,094,814 | R--- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)

DRV - [2005/04/27 10:40:00 | 000,070,144 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtlnicxp.sys -- (RTL8023xp)

DRV - [2005/03/09 16:53:00 | 000,036,352 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)

DRV - [2004/12/15 20:12:04 | 000,218,368 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RT2500.sys -- (RT2500)

DRV - [2004/08/04 07:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)

DRV - [2004/04/03 06:35:08 | 000,043,392 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdr4_xp.sys -- (Cdr4_xp)

DRV - [2004/04/03 06:32:20 | 000,024,576 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdralw2k.sys -- (Cdralw2k)

DRV - [2003/09/19 02:47:00 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (Pfc)

DRV - [2001/08/17 15:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)

DRV - [1995/11/07 10:57:00 | 000,006,144 | ---- | M] (Corel Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\crlscsi.sys -- (crlscsi)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com)

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

========== FireFox ==========

 

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"

 

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\2.bin\NPMyWebS.dll (MyWebSearch.com)

FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2321: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2379: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

 

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\2.bin [2010/11/01 18:13:46 | 000,000,000 | ---D | M]

 

[2011/07/30 00:14:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jane Cureton\Application Data\Mozilla\Firefox\Profiles\077fyhc8.default\extensions

[2011/10/14 22:15:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2007/02/20 16:15:00 | 002,115,816 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\NPSWF32.dll

 

========== Chrome ==========

 

 

O1 HOSTS File: ([2004/08/10 20:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com)

O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)

O2 - BHO: (Reg Error: Value error.) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)

O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)

O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)

O3 - HKLM\..\Toolbar: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)

O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)

O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)

O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)

O3 - HKCU\..\Toolbar\WebBrowser: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)

O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)

O4 - HKLM..\Run: [] File not found

O4 - HKLM..\Run: [\\HARE-GORP3PSMHP\EPSON Stylus C86 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE /P41 "\\HARE-GORP3PSMHP\EPSON Stylus C86 Series" /O5 "LPT1:" /M "Stylus C86" File not found

O4 - HKLM..\Run: [CardReaderReset] C:\Program Files\Realtek Semiconductor Corp\Card Reader Software\Reset.exe ()

O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)

O4 - HKLM..\Run: [EPSON Stylus C86 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE /P23 "EPSON Stylus C86 Series" /O5 "LPT1:" /M "Stylus C86" File not found

O4 - HKLM..\Run: [My Web Search Bar Search Scope Monitor] C:\Program Files\MyWebSearch\bar\2.bin\M3SRCHMN.EXE (MyWebSearch.com)

O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE (MyWebSearch.com)

O4 - HKLM..\Run: [osCheck] C:\Program Files\Norton Internet Security\osCheck.exe (Symantec Corporation)

O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()

O4 - HKLM..\Run: [soundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

O4 - HKLM..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u File not found

O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background File not found

O4 - HKCU..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE (MyWebSearch.com)

O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)

O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10x_ActiveX.exe (Adobe Systems, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe (Nikon Corporation)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk = C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe (Ralink Technology, Corp.)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?s=100000349&p=ZNxmk999YYGB&si=&a=hjmFQK9KcDy93s.Diy5Wiw&n=2006051618 File not found

O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)

O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/SmileyCentralInitialSetup1.0.1.1.cab (Reg Error: Key error.)

O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)

O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} http://tools.ebayimg.com/pm/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab (EPUImageControl Class)

O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} http://msnuk.oberon-media.com/online2/MSN_INTL_UK/chainz_2/mjolauncher.cab (MJLauncherCtrl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl.sun.com/webapps/download/AutoDL?BundleId=27986 (Java Plug-in 1.6.0_12)

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab53083.cab (ZoneIntro Class)

O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} http://game.zylom.com/activex/zylomgamesplayer.cab (Zylom Games Player)

O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab (EPUImageControl Class)

O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)

O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab (Java Plug-in 1.6.0_12)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab (Java Plug-in 1.6.0_12)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://sympatico.zone.msn.com/bingame/popcaploader_v10.cab (PopCapLoader Object)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C36A7A38-96C7-4290-A25B-E6073651D588}: DhcpNameServer = 192.168.1.254

O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)

O24 - Desktop WallPaper: C:\Documents and Settings\Jane Cureton\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jane Cureton\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2005/09/16 20:44:20 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O33 - MountPoints2\{692bd095-bd9e-11da-957a-806d6172696f}\Shell - "" = AutoRun

O33 - MountPoints2\{692bd095-bd9e-11da-957a-806d6172696f}\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\{692bd095-bd9e-11da-957a-806d6172696f}\Shell\AutoRun\command - "" = D:\winshell110.exe

O33 - MountPoints2\Z\Shell - "" = AutoRun

O33 - MountPoints2\Z\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\Z\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

NetSvcs: 6to4 - File not found

NetSvcs: HidServ - File not found

NetSvcs: Ias - File not found

NetSvcs: Iprip - File not found

NetSvcs: Irmon - File not found

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: WmdmPmSp - File not found

 

 

CREATERESTOREPOINT

Restore point Set: OTL Restore Point

 

========== Files/Folders - Created Within 30 Days ==========

 

[2011/10/28 13:15:51 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jane Cureton\Desktop\OTL.exe

[2011/10/27 22:50:00 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2011/10/27 22:47:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jane Cureton\Application Data\Malwarebytes

[2011/10/27 22:46:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware

[2011/10/27 22:46:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2011/10/27 22:46:51 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2011/10/27 22:46:51 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2011/10/14 22:47:12 | 000,000,000 | -HSD | C] -- C:\Config.Msi

[2005/09/16 22:54:14 | 000,036,963 | R--- | C] (Cypress Semiconductor) -- C:\Program Files\Common Files\SM1updtr.dll

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2011/10/28 13:16:07 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jane Cureton\Desktop\OTL.exe

[2011/10/28 13:13:10 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2011/10/27 22:50:15 | 000,041,272 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2011/10/27 22:47:01 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/10/27 22:13:05 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2011/10/15 12:31:23 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2011/10/15 12:31:17 | 938,921,984 | -HS- | M] () -- C:\hiberfil.sys

[2011/10/14 23:05:39 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2011/10/14 23:01:03 | 000,313,656 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2011/10/14 22:51:41 | 000,443,248 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2011/10/14 22:51:41 | 000,072,514 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2011/10/14 22:48:00 | 000,001,943 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2011/10/02 18:57:16 | 000,002,491 | ---- | M] () -- C:\Documents and Settings\Jane Cureton\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Word (2).lnk

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2011/10/27 22:47:01 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010/11/13 18:40:41 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat

[2008/08/26 22:52:14 | 000,022,403 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LUUnInstall.LiveUpdate

[2008/03/11 18:26:46 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini

[2008/03/11 18:26:45 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat

[2008/03/11 18:26:45 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat

[2008/03/11 18:26:45 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat

[2008/03/11 18:26:45 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat

[2008/03/11 18:26:45 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat

[2008/03/11 18:26:45 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat

[2008/03/11 18:26:45 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat

[2008/03/11 18:26:45 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat

[2008/03/11 18:26:45 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat

[2008/03/11 18:26:45 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat

[2008/03/11 18:26:45 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat

[2008/03/11 18:26:45 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat

[2008/03/11 18:26:45 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat

[2008/03/11 18:26:45 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat

[2008/03/11 18:26:45 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat

[2008/03/11 18:26:45 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat

[2008/03/11 18:26:45 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat

[2008/03/11 18:26:45 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat

[2008/03/11 18:19:06 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDED92Euro.ini

[2007/06/08 23:30:22 | 000,001,156 | ---- | C] () -- C:\WINDOWS\mozver.dat

[2007/06/08 23:27:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat

[2007/01/01 14:54:24 | 000,000,182 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT4.DAT

[2007/01/01 14:29:34 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDESC86PEEuro.ini

[2006/12/27 15:30:52 | 000,002,887 | ---- | C] () -- C:\WINDOWS\cdplayer.ini

[2006/09/03 16:41:53 | 000,005,120 | ---- | C] () -- C:\Documents and Settings\Jane Cureton\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2006/07/18 20:02:41 | 000,000,340 | ---- | C] () -- C:\WINDOWS\QTW.INI

[2006/07/18 20:02:37 | 000,000,144 | ---- | C] () -- C:\WINDOWS\INDEO.INI

[2006/07/01 11:04:31 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Jcmkr32.INI

[2006/06/05 17:26:35 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini

[2006/05/20 15:02:20 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\qttask.exe

[2006/05/20 15:01:31 | 000,000,021 | ---- | C] () -- C:\WINDOWS\PMK_setup.ini

[2006/05/17 11:47:50 | 000,000,135 | ---- | C] () -- C:\Documents and Settings\Jane Cureton\Local Settings\Application Data\fusioncache.dat

[2006/05/15 16:47:47 | 000,000,797 | ---- | C] () -- C:\WINDOWS\SGREP32.INI

[2006/05/15 16:42:53 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\sg50Ps32.dll

[2006/05/15 16:42:51 | 000,256,512 | ---- | C] () -- C:\WINDOWS\System32\SGOPopDg.dll

[2006/05/15 15:43:44 | 000,000,083 | ---- | C] () -- C:\WINDOWS\REPENG.INI

[2006/05/15 15:14:48 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\BurnData.bin

[2006/05/15 14:41:45 | 000,019,932 | ---- | C] () -- C:\WINDOWS\SAGE.INI

[2006/05/14 22:33:06 | 000,001,006 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2006/05/14 20:41:47 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Jane Cureton\Application Data\wklnhst.dat

[2006/03/27 15:39:39 | 000,000,516 | ---- | C] () -- C:\WINDOWS\dialer.ini

[2006/02/28 06:07:15 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\ntiembed.dll

[2006/02/28 06:05:53 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIMPEG2.dll

[2006/02/28 06:05:53 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTICDMK32.dll

[2006/02/28 05:41:50 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll

[2006/02/28 05:41:50 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll

[2006/02/28 05:41:50 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll

[2006/02/28 05:41:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll

[2006/02/28 05:41:49 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll

[2006/02/28 05:41:49 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll

[2006/02/27 22:13:19 | 000,000,060 | ---- | C] () -- C:\WINDOWS\System32\SYSDRV.DAT

[2006/02/27 21:35:38 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat

[2006/02/27 21:35:06 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat

[2006/02/27 21:35:05 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat

[2006/02/27 21:34:57 | 000,004,518 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat

[2006/02/27 21:34:45 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin

[2006/02/27 21:34:29 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

[2006/02/27 21:33:28 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat

[2006/02/27 21:33:26 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin

[2006/02/27 21:32:28 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat

[2006/02/27 21:30:47 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin

[2006/02/27 14:16:47 | 000,151,552 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe

[2006/02/27 14:16:47 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\installrt2500qa.dll

[2006/02/27 14:16:47 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\WRLSetup.exe

[2006/02/27 14:05:44 | 000,000,164 | R--- | C] () -- C:\WINDOWS\avrack.ini

[2006/02/27 13:41:44 | 000,156,672 | R--- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll

[2006/02/27 13:41:44 | 000,040,960 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe

[2006/02/27 13:39:05 | 000,095,617 | R--- | C] () -- C:\WINDOWS\System32\atiicdxx.dat

[2006/01/24 13:37:36 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\SageEventHandler.exe

[2006/01/24 13:36:20 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\SGCtrlEx.dll

[2006/01/24 13:36:12 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SageFolderBrowser.dll

[2006/01/24 13:36:10 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\SGTBAR32.DLL

[2006/01/24 13:36:04 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\SGSTAT32.DLL

[2006/01/24 13:36:04 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\SGLOGO32.DLL

[2006/01/24 13:36:02 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\SGJPEG32.dll

[2006/01/24 13:35:58 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\SGCDLG32.DLL

[2006/01/24 13:35:48 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\SGLIST32.DLL

[2006/01/24 13:35:38 | 000,278,528 | ---- | C] () -- C:\WINDOWS\System32\SGTOOL32.DLL

[2006/01/24 13:35:34 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\SGINTL32.DLL

[2006/01/24 13:35:32 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\SGDT32.DLL

[2006/01/24 13:35:30 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\SGHELP32.DLL

[2006/01/24 13:35:28 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SGAPPBAR.DLL

[2006/01/24 13:35:24 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SG3D32.DLL

[2006/01/24 13:35:10 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeXP.dll

[2006/01/24 13:35:06 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeDefault.dll

[2006/01/24 13:34:58 | 000,221,184 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeManager.dll

[2006/01/24 13:34:48 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\SGCOM32.DLL

[2006/01/24 13:33:42 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\SGWebBrowser.dll

[2006/01/13 11:43:50 | 000,245,760 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeXml.dll

[2005/11/30 13:49:32 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\REPDES32.EXE

[2005/11/30 13:49:30 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\SGLCH32.DLL

[2005/11/30 13:49:20 | 001,712,128 | ---- | C] () -- C:\WINDOWS\System32\SGREP32.DLL

[2005/09/19 17:54:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini

[2005/09/16 20:47:13 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2005/09/16 20:40:30 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

[2005/09/16 20:28:26 | 000,001,452 | R--- | C] () -- C:\WINDOWS\System32\oeminfo.ini

[2005/09/16 20:27:13 | 000,443,248 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat

[2005/09/16 20:27:13 | 000,072,514 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat

[2005/09/16 13:35:23 | 000,005,997 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2005/09/16 13:34:32 | 000,313,656 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2005/09/02 00:39:24 | 000,831,488 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll

[2005/09/02 00:39:24 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll

[2005/09/02 00:39:00 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll

[2005/08/05 22:01:54 | 000,239,104 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll

[2005/07/11 14:33:12 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\SDOApp.dll

[2004/06/09 11:57:12 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\Install.exe

[2002/04/16 12:27:54 | 000,000,005 | -HS- | C] () -- C:\WINDOWS\System32\CdI5T.drv

[2001/12/26 17:12:30 | 000,065,536 | R--- | C] () -- C:\WINDOWS\System32\multiplex_vcd.dll

[2001/09/04 00:46:38 | 000,110,592 | R--- | C] () -- C:\WINDOWS\System32\Hmpg12.dll

[2001/07/30 17:33:56 | 000,118,784 | R--- | C] () -- C:\WINDOWS\System32\HMPV2_ENC.dll

[2001/07/23 23:04:36 | 000,118,784 | R--- | C] () -- C:\WINDOWS\System32\HMPV2_ENC_MMX.dll

[1999/01/23 03:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL

[1998/03/26 02:12:00 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\SgHmZLib.dll

[1997/06/14 01:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll

 

========== LOP Check ==========

 

[2010/09/27 21:56:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON

[2008/07/11 15:06:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo

[2010/09/05 23:47:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster

[2006/09/04 13:37:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap

[2006/05/14 22:30:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBT

[2007/12/08 19:41:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP

[2008/03/11 18:35:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL

[2009/09/01 22:40:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zylom

[2008/03/24 18:56:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jane Cureton\Application Data\EPSON

[2007/06/24 13:37:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jane Cureton\Application Data\InterVideo

[2006/05/22 19:04:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jane Cureton\Application Data\Nikon

[2005/09/16 23:18:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jane Cureton\Application Data\SampleView

[2006/05/14 22:22:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jane Cureton\Application Data\Template

 

========== Purity Check ==========

 

 

 

========== Custom Scans ==========

 

 

< %SYSTEMDRIVE%\*.* >

[2006/07/30 23:30:19 | 000,000,000 | ---- | M] () -- C:\AILog.txt

[2005/09/16 20:44:20 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT

[2006/02/28 07:20:58 | 000,000,032 | ---- | M] () -- C:\BIOSINFO.INI

[2006/02/28 07:20:58 | 000,000,091 | ---- | M] () -- C:\BIOSVIEW.INI

[2006/05/14 20:06:17 | 000,000,209 | RHS- | M] () -- C:\boot.ini

[2005/09/16 20:44:20 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS

[2011/10/15 12:31:17 | 938,921,984 | -HS- | M] () -- C:\hiberfil.sys

[2010/09/27 22:22:37 | 000,002,096 | ---- | M] () -- C:\InstallHelper.log

[2005/09/16 20:44:20 | 000,000,000 | RHS- | M] () -- C:\IO.SYS

[2005/09/19 17:39:15 | 000,000,021 | ---- | M] () -- C:\LOCAL

[2005/09/19 17:39:15 | 000,000,021 | ---- | M] () -- C:\MINI

[2005/09/16 20:44:20 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS

[2004/08/10 20:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM

[2011/02/01 21:28:38 | 000,250,048 | RHS- | M] () -- C:\ntldr

[2011/10/15 12:31:15 | 1409,286,144 | -HS- | M] () -- C:\pagefile.sys

 

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

[2008/07/06 13:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll

 

< %systemroot%\*. /mp /s >

 

< %systemroot%\system32\*.sys /90 >

[2011/09/06 14:20:51 | 001,858,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys

[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

 

< %systemroot%\system32\*.dll /lockedfiles >

[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

 

< %systemroot%\Tasks\*.job /lockedfiles >

 

< %systemroot%\system32\drivers\*.sys /lockedfiles >

 

< %systemroot%\system32\*.exe /lockedfiles >

[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

 

< %systemroot%\System32\config\*.sav >

[2005/09/16 13:33:51 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav

[2005/09/16 13:33:51 | 000,659,456 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav

[2005/09/16 13:33:50 | 000,876,544 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav

 

< %PROGRAMFILES%\* >

 

< %USERPROFILE%\..|smtmp;true;true;true /FP >

 

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU >

 

< hklm\software\clients\startmenuinternet|command /rs >

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/08/22 12:56:56 | 000,174,080 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/08/22 12:56:56 | 000,174,080 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/08/22 12:56:56 | 000,174,080 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 15:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2009/03/08 15:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)

 

< hklm\software\clients\startmenuinternet|command /64 /rs >

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/08/22 12:56:56 | 000,174,080 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/08/22 12:56:56 | 000,174,080 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/08/22 12:56:56 | 000,174,080 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 15:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2009/03/08 15:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:02C1CB6D

@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:69E17801

@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:10B7A752

@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:57B4E612

@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7A266313

@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5711EF65

< End of report >

Posted

OTL Log no 2:

OTL Extras logfile created on: 28/10/2011 13:20:34 - Run 1

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Jane Cureton\Desktop

Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

 

895.36 Mb Total Physical Memory | 164.87 Mb Available Physical Memory | 18.41% Memory free

2.12 Gb Paging File | 1.53 Gb Available in Paging File | 72.14% Paging File free

Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 32.50 Gb Total Space | 2.34 Gb Free Space | 7.19% Space Free | Partition Type: NTFS

 

Computer Name: JCMOSAICS | User Name: Jane Cureton | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

 

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]

.html [@ = htmlfile] -- Reg Error: Key error. File not found

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [print] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)

http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"

https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusDisableNotify" = 1

"FirewallDisableNotify" = 1

"UpdatesDisableNotify" = 0

"AntiVirusOverride" = 0

"FirewallOverride" = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

"DisableMonitoring" = 1

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

"DisableMonitoring" = 1

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

"DisableMonitoring" = 1

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

 

========== System Restore Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

"Start" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

"Start" = 2

 

========== Firewall Settings ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0

"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0

"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)

"C:\WINDOWS\system32\spool\drivers\w32x86\3\SAGENT4.EXE" = C:\WINDOWS\system32\spool\drivers\w32x86\3\SAGENT4.EXE:*:Disabled:SAgent4

"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium

"{00040409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Disc 2

"{0A7124DF-F8A4-405B-904F-CFD3D3DFB5AE}" = PIF DESIGNER2.1

"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel

"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer

"{1CABB679-3958-44AA-BFFF-4E68A2684255}" = ArcSoft Panorama Maker 3.0

"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer

"{23B59ED4-C360-11D7-875B-0090CC005647}" = EPSON PRINT Image Framer Tool2.1

"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java 6 Update 12

"{2E0695EE-ED29-4D96-BD77-2A9A17EDF0D6}" = Cypress USB Mass Storage Driver Installation

"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator 2

"{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}" = Component Framework

"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java 6 Update 2

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{3672B097-EA69-4BFE-B92F-29AE6D9D2B34}" = Norton Internet Security

"{3DB6BE63-3919-4B74-9EAF-884ED7BE901A}" = SymNet

"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works

"{420F8FCF-8F5E-4518-A5B3-FBBD56B98FEC}" = Bonus

"{4E68EAA3-775A-4542-A08A-47DB8E8E74A6}" = NTI Backup NOW! 3

"{55A6283C-638A-4EE0-B491-51118554BDA2}" = Norton Confidential Core

"{5677563D-0CB1-485F-9E18-C5025306BB3F}" = Norton AntiSpam

"{62120008-8E1E-4807-860D-A8B48F8552DB}" = Norton Protection Center

"{65F5B7AF-3363-11D7-BB6B-00018021113F}" = EPSON PhotoQuicker3.5

"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable

"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC 32bit

"{779F426C-A8F3-414B-B7AF-B6BDC9B8E040}" = CC_ccProxyExt

"{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}" = Norton AntiVirus

"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page

"{8927E07C-97F7-4A54-88FB-D976F50DD46E}" = Turbo Lister 2

"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Roxio Burn Engine

"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD

"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver

"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{AAA66A0D-E610-40B8-9D51-C1854285773A}" = RT2500 Wireless LAN Card

"{AAB84E83-C8DF-4752-9DFC-2E2A48EE5E9F}" = Nikon View 6

"{AB70ABEC-771B-47CB-9E41-DF77DE4FFC5C}" = ccPxyCore

"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2

"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}" = ccCommon

"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth

"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2

"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver

"{C1C185CA-C531-49F5-A6FA-B838405A049D}" = Norton Internet Security

"{C438B7C4-B4F8-49C5-A4DF-FF6F1F242778}" = NTI CD & DVD-Maker

"{C45B1500-7B63-47C2-AB25-C28CB46AFDEE}" = MSN Music Mediabar

"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{D32D4182-DE6C-457E-838C-8D7B9CE332BA}" = InterVideo WinRip

"{D4BB907A-623E-4F07-8787-041ABAE088E4}" = Norton AntiVirus Help

"{D6E6FA4A-5445-4850-8365-CF216C1CBB7A}" = Symantec Real Time Storage Protection Component

"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)

"{DC24971E-1946-445D-8A82-CE685433FA7D}" =

"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}" = Norton AntiVirus Help

"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)

"{E8176C35-0C2D-4142-9ED4-81861ECAB403}" = CIB

"{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}" = ScanToWeb

"{ECA2B21B-A180-4775-B93F-6E404E36A8CC}" = MSRuntime Libraries

"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore

"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Photoshop Elements 2.0" = Adobe Photoshop Elements 2.0

"Adobe Shockwave Player" = Adobe Shockwave Player 11.5

"Agere Systems Soft Modem" = Agere Systems AC'97 Modem v2157D

"All ATI Software" = ATI - Software Uninstall Utility

"ATI Display Driver" = ATI Display Driver

"Corel Applications" = Corel Applications

"ESC86 Reference Guide" = ESC86 Reference Guide

"ESC86 Software Guide" = ESC86 Software Guide

"ie8" = Windows Internet Explorer 8

"InstallShield_{4E68EAA3-775A-4542-A08A-47DB8E8E74A6}" = NTI Backup NOW! 3

"InstallShield_{C438B7C4-B4F8-49C5-A4DF-FF6F1F242778}" = NTI CD & DVD-Maker Gold

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300

"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"MyWebSearch bar Uninstall" = My Web Search (Smiley Central)

"OcaHistoryUpd" = OCA Client history tool install

"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)

"QuickTime" = QuickTime

"RealPlayer 6.0" = RealPlayer

"Sage Instant Accounting 6.0" = Sage Instant Accounting 6.0

"SM1FX_AT" = USB Storage Adapter FX (SM1)

"SymSetup.{420F8FCF-8F5E-4518-A5B3-FBBD56B98FEC}" = Norton Add-on Pack (Symantec Corporation)

"SymSetup.{C1C185CA-C531-49F5-A6FA-B838405A049D}" = Norton Internet Security (Symantec Corporation)

"SynTPDeinstKey" = Synaptics Pointing Device Driver

"WIC" = Windows Imaging Component

"Windows Media Format Runtime" = Windows Media Format Runtime

"Windows XP Service Pack" = Windows XP Service Pack 3

"Wise Disk Cleaner_is1" = Wise Disk Cleaner 5.93

 

========== Last 10 Event Log Errors ==========

 

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

 

< End of report >

Posted

aswMBR log

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software

Run date: 2011-10-28 14:04:22

-----------------------------

14:04:22.984 OS Version: Windows 5.1.2600 Service Pack 3

14:04:22.984 Number of processors: 1 586 0x2C02

14:04:22.984 ComputerName: JCMOSAICS UserName:

14:04:27.593 Initialize success

14:04:54.203 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3

14:04:54.203 Disk 0 Vendor: ST9402112A 3.06 Size: 38154MB BusType: 3

14:04:56.265 Disk 0 MBR read successfully

14:04:56.265 Disk 0 MBR scan

14:04:56.265 Disk 0 unknown MBR code

14:04:56.296 Disk 0 scanning sectors +78124095

14:04:56.453 Disk 0 scanning C:\WINDOWS\system32\drivers

14:05:40.734 Service scanning

14:05:44.187 Modules scanning

14:06:58.593 Disk 0 trace - called modules:

14:06:58.625 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS

14:06:58.625 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8553dab8]

14:06:58.625 3 CLASSPNP.SYS[f761cfd7] -> nt!IofCallDriver -> \Device\00000098[0x855759e8]

14:06:58.625 5 ACPI.sys[f7433620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x85575d98]

14:06:59.156 Scan finished successfully

14:07:27.875 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Jane Cureton\Desktop\MBR.dat"

14:07:27.890 The log file has been saved successfully to "C:\Documents and Settings\Jane Cureton\Desktop\aswMBR.txt"

Posted

and finally the MBAM log:

Malwarebytes' Anti-Malware 1.51.2.1300

www.malwarebytes.org

Database version: 8034

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

28/10/2011 14:56:29

mbam-log-2011-10-28 (14-56-29).txt

Scan type: Quick scan

Objects scanned: 195660

Time elapsed: 40 minute(s), 37 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 142

Registry Values Infected: 12

Registry Data Items Infected: 2

Folders Infected: 22

Files Infected: 156

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_CLASSES_ROOT\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{819FFE22-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{819FFE20-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{1093995A-BA37-41D2-836E-091067C4AD17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.DataControl.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.DataControl (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{2EFF3CF7-99C1-4c29-BC2B-68E057E22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{621FEACD-8857-43A6-AE26-451D670D5370} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{2763E333-B168-41A0-A112-D35F96F410C0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.ShellViewControl.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.ShellViewControl (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{A9571378-68A1-443d-B082-284F960C6D17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{B813095C-81C0-4E40-AA14-67520372B987} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{799391D3-EB86-4bac-9BD3-CBFEA58A0E15} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{D858DAFC-9573-4811-B323-7011A3AA7E61} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\My Web Search Bar Search Scope Monitor (Adware.MyWebSearch) -> Value: My Web Search Bar Search Scope Monitor -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44CF-8957-5838F569A31D} -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44cf-8957-5838F569A31D} -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Value: (default) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Value: f3PopularScreensavers -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Value: FunWebProducts -> Quarantined and deleted successfully.

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:

c:\program files\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\funwebproducts\screensaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\funwebproducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\funwebproducts\Shared\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch (Adware.MyWebSearch) -> Delete on reboot.

c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Delete on reboot.

c:\program files\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin (Adware.MyWebSearch) -> Delete on reboot.

c:\program files\mywebsearch\bar\2.bin\chrome (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\icons (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Overlay (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\SrchAstt (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\SrchAstt\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:

c:\Program Files\MyWebSearch\bar\2.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Delete on reboot.

c:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Delete on reboot.

c:\Program Files\MyWebSearch\bar\2.bin\M3AUXSTB.DLL (Adware.MyWebSearch) -> Delete on reboot.

c:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Delete on reboot.

c:\Program Files\MyWebSearch\bar\2.bin\M3DLGHK.DLL (Adware.MyWebSearch) -> Delete on reboot.

c:\program files\mywebsearch\bar\2.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\MWSSVC.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\1.bin\F3SHLLVW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\M3HTML.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\M3SKIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\M3MSG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\WINDOWS\system32\f3PSSavr.scr (PUP.FunWebProducts) -> Not selected for removal.

c:\program files\funwebproducts\screensaver\Images\3E83D10D.urr (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\funwebproducts\Shared\Cache\cursormaniabtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\funwebproducts\Shared\Cache\funbuddyiconbtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\funwebproducts\Shared\Cache\mailstampbtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\funwebproducts\Shared\Cache\myfuncardsimbtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\funwebproducts\Shared\Cache\mysignatureinsertbtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\funwebproducts\Shared\Cache\mysignaturepreviewbtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\funwebproducts\Shared\Cache\mystationerybtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\funwebproducts\Shared\Cache\smileycentralbtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\funwebproducts\Shared\Cache\webfettibtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\1.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\1.bin\m3ffxtbr.manifest (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\1.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\chrome.manifest (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3IMSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3REGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\INSTALL.RDF (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\M3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\MWSMLBTN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\MWSUABTN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\2.bin\chrome\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\00097A93 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\0022484E.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\00224A42.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\00224BA9.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\00224CE2.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\003312B5.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\00331499.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\00372ADD.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\00373925.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\00373AAC (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\00A54572.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\00A54728.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\00A548DD.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\00A54A06.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\0390B4A6 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\3E6D7CEC.bmp (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\5BE24BD3.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\921ABCC4 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\B961E08D.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\B961E1C6.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\B961E243.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\B961E2B0.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\DD308D02.bmp (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\DD308DFC.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\DD308E79 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Cache\files.ini (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\History\search2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\History\search3 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\8_step1.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\autoup.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\autoup.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bkez.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bkgr.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bkgs.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bklf.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bkrg.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bkwebfet.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bkzc.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bkzl.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bkzn.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bkzq.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bkzr.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bkzu.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bkzv.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bkzw.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\bkzwinky.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\blubtn2d.png (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\blubtn2r.png (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\blubtn3d.png (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\blubtn3r.png (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\center.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\index.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\mid_dots.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\protect.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\rebut4.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\rebut4b.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\rebut4c.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\shield.png (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\shocked.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\stop.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\systray.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\systrayp.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\tp_grad.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Message\COMMON\warn.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Overlay\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Settings\setting2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Settings\settings.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Settings\settings.dat.bak (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.

c:\program files\mywebsearch\SrchAstt\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

 

As you predicted MBAM did reboot the computer.

Kind regards

Jane

Posted

Hello, janec.

 

 

Besides the disappearing hard drive space, have you noticed any other odd behavior?

 

 

Install ERUNT

This tool will create a complete backup of your registry. After every reboot, a new backup is created to ensure we have a safety net after each step. Do not delete these backups until we are finished.


  •  
  • Please download erunt-setup.exe to your desktop.
     
  • Double click erunt-setup.exe. Follow the prompts and allow ERUNT to be installed with the settings at default. If you do not want a Desktop icon, feel free to uncheck that. When asked if you want to create an ERUNT entry in the startup folder, answer Yes. You can delete the installation file after use.
     
  • Erunt will open when the installation is finished. Check all items to be backed up in the default location and click OK.

 

 

You can find a complete guide to using the program here:

http://www.larshederer.homepage.t-online.de/erunt/erunt.txt

 

 

When we are finished with fixing your computer (I will make it clear when we are), you can uninstall ERUNT through Add/Remove Programs. The backups will be stored at C:\WINDOWS\erdnt, and will not be deleted when ERUNT is uninstalled.

 

 

 

 

 

 

Step 1

 

 

Please pull anything out of the recycle bin that you want to save. Part of this fix will empty temp files, and that does include the recycle bin.

 

 

We need run an OTL Script

  1. Please download OTL from one of the following mirrors if you do not still have it.

[*]Save it to your desktop.

[*]Double click on the http://billy-oneal.com/Canned%20Speeches/speechimages/OTL/otlDesktopIcon.png icon on your desktop.

[*]Paste the following code under the Custom Scans/Fixes box at the bottom.

:OTL
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [\\HARE-GORP3PSMHP\EPSON Stylus C86 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0R 2.EXE /P41 "\\HARE-GORP3PSMHP\EPSON Stylus C86 Series" /O5 "LPT1:" /M "Stylus C86" File not found
O4 - HKLM..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u File not found
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background File not found
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...w&n=2006051618 File not found
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/noc...tup1.0.1.1.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O33 - MountPoints2\Z\Shell - "" = AutoRun
O33 - MountPoints2\Z\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\Z\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=0
"AntiVirusDisableNotify"=0
"FirewallDisableNotify"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring"=-
:Commands
[EmptyTemp]

[*]Click the Run Fix button at the top.

[*]let the program run unhindered and reboot when it is done.

[*]You will get a log when it is done, please post that in your reply.

[*]Please then create a new OTL report....

[*]Click the "Scan All Users" checkbox.

[*]Push the http://billy-oneal.com/Canned%20Speeches/speechimages/OTL/runscanbutton.png button.

[*]A report will open, copy and paste it in a reply here.

 

 

 

 

 

 

Step 2

 

 

I'd like us to scan your machine with ESET OnlineScan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetOnline.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstallDesktopIcon.png icon on your desktop.

    [*]Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetAcceptTerms.png

    [*]Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetStart.png button.

    [*]Accept any security warnings from your browser.

    [*]Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetScanArchives.png

    [*]Push the Start button.

    [*]ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.

    [*]When the scan completes, push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png

    [*]Push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

    [*]Push the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetBack.png button.

    [*]Push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetFinish.png

 

 

etavares

Posted

Hello etavares,

I have not noticed anything strange on my PC apart from it slowing down and if I have too many things happening at once, in particular three or more internet tabs open it sometimes freezes up and has a sulk for a minute or two.

I installed ERUNT.

OTL after run/fix:

 

All processes killed

========== OTL ==========

Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\\\HARE-GORP3PSMHP\EPSON Stylus C86 Series deleted successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\UserFaultCheck deleted successfully.

Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MsnMsgr deleted successfully.

Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Search\ deleted successfully.

Starting removal of ActiveX control {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ not found.

Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}

C:\WINDOWS\Downloaded Program Files\gp.inf not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\Z\ deleted successfully.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\Z\ not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\Z\ not found.

File C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480 not found.

========== REGISTRY ==========

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"FirstRunDisabled"|0 /E : value set successfully!

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"AntiVirusDisableNotify"|0 /E : value set successfully!

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"FirewallDisableNotify"|0 /E : value set successfully!

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\\DisableMonitoring deleted successfully.

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\\DisableMonitoring deleted successfully.

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\\DisableMonitoring deleted successfully.

========== COMMANDS ==========

 

[EMPTYTEMP]

 

User: Administrator

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 32768 bytes

 

User: All Users

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 32902 bytes

->Flash cache emptied: 41 bytes

 

User: Jane Cureton

->Temp folder emptied: 7820431 bytes

->Temporary Internet Files folder emptied: 252600376 bytes

->Java cache emptied: 122496049 bytes

->FireFox cache emptied: 10569577 bytes

->Google Chrome cache emptied: 34472366 bytes

->Flash cache emptied: 1892 bytes

 

User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 710221 bytes

 

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 19569 bytes

%systemroot%\System32 .tmp files removed: 2577 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 525 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 237710553 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34318 bytes

RecycleBin emptied: 0 bytes

 

Total Files Cleaned = 636.00 mb

 

 

OTL by OldTimer - Version 3.2.31.0 log created on 10302011_180718

Files\Folders moved on Reboot...

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\VF133H80\myebaysummary;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;sz=728x90;ord=1251491826009;dcopt=i[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\UYN3DS7B\keywords;kw=display+shelves;cat=12576;cat=11890;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;t[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\UYN3DS7B\keywords;kw=melamine+tray;cat=11700;cat=20625;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tca[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\UYN3DS7B\keywords;kw=melamine+tray;cat=11700;cat=20625;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tca[2].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\UYN3DS7B\keywords;kw=shelving+unit;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=608;sz[2].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\UYN3DS7B\myebaymymessages;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;sz=728x90;ord=1251495662707;dcop[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\UYN3DS7B\myebaysummary;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;sz=728x90;ord=1251493273932;dcopt=i[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\UYN3DS7B\storage;cat=11700;cat=43502;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=122954;items=128[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\TTSI3RXL\myebaysummary;seg=GL_Google100Mod0to99;seg=GL_GenderMale30to49;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;sz=728x90;or[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\TTSI3RXL\storage;cat=11700;cat=43502;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=122954;items=128[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\RVDZZTG4\251621884&ga_sid=1251621884&ga_hid=1359242306&ga_fc=0&u_tz=60&u_his=6&u_java=1&u_h=800&u_w=1280&u_ah=770&u_aw=1280&u_cd=32&u_nplug=0&u_nmime=0&biw=1250&bih=567&fu=0&ifi=2&dtd=63 not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\RVDZZTG4\keywords;kw=melamine+tray;cat=11700;cat=20625;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tca[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\QX1U3AD8\keywords;kw=bath+bombs;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=26395;items=2250;sz=7[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\QX1U3AD8\keywords;kw=display+shelves;cat=12576;cat=11890;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;t[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\QX1U3AD8\keywords;kw=pepper+mill;seg=GL_Google100Mod0to99;seg=GL_GenderMale30to49;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;tc[3].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\QX1U3AD8\keywords;kw=shelving+unit;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=608;sz[2].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\QX1U3AD8\keywords;kw=shelving+unit;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=608;sz[3].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\QX1U3AD8\storage;cat=11700;cat=43502;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=122954;items=138[2].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\QX1U3AD8\storage;cat=11700;cat=43502;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=122954;items=138[4].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q9FKL872\251659453&ga_sid=1251659453&ga_hid=1884593084&ga_fc=0&u_tz=60&u_his=0&u_java=1&u_h=800&u_w=1280&u_ah=770&u_aw=1280&u_cd=32&u_nplug=0&u_nmime=0&biw=1259&bih=613&fu=0&ifi=1&dtd=78 not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q9FKL872\checkout_521_RTM;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;sz=300x250;ord=1251495390588;dco[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q9FKL872\keywords;kw=display+stand;cat=12576;cat=11890;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tca[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q9FKL872\keywords;kw=hooks;seg=GL_Google100Mod0to99;seg=GL_GenderMale30to49;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;tcat=382[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q9FKL872\keywords;kw=shelving+unit;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=608;sz[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONLJYYBL\51621884&ga_sid=1251621884&ga_hid=1359242306&ga_fc=0&u_tz=60&u_his=6&u_java=1&u_h=800&u_w=1280&u_ah=770&u_aw=1280&u_cd=32&u_nplug=0&u_nmime=0&biw=1250&bih=567&fu=0&ifi=3&dtd=172 not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONLJYYBL\keywords;kw=lap+trays;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=400;sz=160[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONLJYYBL\keywords;kw=melamine+tray;cat=11700;cat=20625;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tca[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONLJYYBL\keywords;kw=new+cute+baby+farm+animals;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=220;i[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONLJYYBL\keywords;kw=pot+pourri;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=1775;sz=1[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONLJYYBL\keywords;kw=shelving+unit;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=608;sz[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONLJYYBL\storage;cat=11700;cat=43502;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=122954;items=128[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\NRODR4QB\keywords;kw=shelving+unit;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=608;sz[3].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\NRODR4QB\keywords;kw=shelving+unit;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=608;sz[4].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\NRODR4QB\keywords;kw=small+gift+box;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=485;s[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\NRODR4QB\myebayallfavorites;seg=GL_Google100Mod0to99;seg=GL_GenderMale30to49;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;sz=728x[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\LNAOOKX9\checkout_521_RTM;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;sz=300x250;ord=1251586434845;dco[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\LNAOOKX9\keywords;kw=melamine+tray;cat=11700;cat=20625;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tca[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\LNAOOKX9\keywords;kw=metal+display+shelves;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11890;item[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\LNAOOKX9\keywords;kw=new+cute+baby+farm+animals;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=220;i[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\LNAOOKX9\keywords;kw=pot+pourri;cat=40005;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=31605;items[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\LNAOOKX9\myebayallfavorites;seg=GL_Google100Mod0to99;seg=GL_GenderMale30to49;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;sz=728x[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\LLXQ7N1Y\aHR0cDovL3d3dy5jMnNob3AuY28udWsvYXNzZXRzL3NjcmlwdHMvaW1nc2l6ZS5waHA@aD0yNTAmdz0yNTAmY29uc3RyYWluPTEmaW1nPS4uLy4uL2Fzc2V0cy9wcm9kdWN0aW1hZ2VzL3dvbWVuX3Nob3J0cy5naWY===[1].jpg not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\LLXQ7N1Y\keywords;kw=display+shelves;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=327;[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\LLXQ7N1Y\keywords;kw=lap+trays;cat=11700;cat=20625;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=20[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\L4W7XPKT\;sz=300x60;tile=6;sect=Product;server=prod;status=internal;toplevelcategory=home_and_garden;stor[1].com;cat=home;subcat=home_improvement_design;site=kaboodle;ord=1246918501283; not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\L4W7XPKT\keywords;kw=lap+trays;cat=11700;cat=20625;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=20[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\L4W7XPKT\keywords;kw=lap+trays;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=400;sz=728[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\L4W7XPKT\keywords;kw=melamine+tray;cat=11700;cat=20625;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tca[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\L4W7XPKT\keywords;kw=shelving+unit;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=608;sz[2].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\L4W7XPKT\myebaysummary;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;sz=160x600;ord=1251493237490;tile=2[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\L0S3D5KX\;mv=1;ms=b;mc=3;mc=4;mc=5;mc=6;mc=7;mc=8;mc=9;ma=g2;ma=g3;ma=g4;ma=g5;ma=g6;ma=h2;ma=h3;ma=h4;ma=h5;ma=h6;ma=h7;ma=a4;ma=c;ma=d;pt=1;px=180000;hb=3;lx=GB;ai=15022;oc=IP3[1] not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\L0S3D5KX\;sz=336x280;tile=2;sect=Product;server=prod;status=internal;toplevelcategory=home_and_garden;sto[1].com;cat=home;subcat=home_improvement_design;site=kaboodle;ord=1246918501283; not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\L0S3D5KX\keywords;kw=display+stand;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=281;items=2243;sz=[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\L0S3D5KX\keywords;kw=lap+trays;cat=11700;cat=20625;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=20[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\L0S3D5KX\keywords;kw=shelving+unit;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=608;sz[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\L0S3D5KX\myebayallfavorites;seg=GL_Google100Mod0to99;seg=GL_GenderMale30to49;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;sz=160x[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\L0S3D5KX\myebayallfavorites;seg=GL_Google100Mod0to99;seg=GL_GenderMale30to49;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;sz=728x[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\L0S3D5KX\myebaysummary;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;sz=728x90;ord=1251492959295;dcopt=i[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\HO43X1OP\keywords;kw=melamine+tray;cat=11700;cat=20625;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tca[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\HO43X1OP\keywords;kw=new+cute+baby+farm+animals+lrg+melamine+tray+sturd;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRe[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\H7JJ9T0Y\;sz=728x90;tile=1;sect=Product;dcopt=ist;server=prod;status=internal;toplevelcategory=home_and_g[1].com;cat=home;subcat=home_improvement_design;site=kaboodle;ord=1246918501283; not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\H7JJ9T0Y\keywords;kw=hooks;seg=GL_Google100Mod0to99;seg=GL_GenderMale30to49;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;tcat=382[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\H7JJ9T0Y\keywords;kw=lap+trays;cat=11700;cat=20625;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=20[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\H7JJ9T0Y\keywords;kw=lap+trays;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=400;sz=160[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\H7JJ9T0Y\keywords;kw=new+cute+baby+farm+animals+lrg+melamine+tray+sturd;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRe[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\H7JJ9T0Y\keywords;kw=tray+new+cute+baby+farm+animals;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\F9XNUA61\keywords;kw=lap+trays;cat=11700;cat=20625;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=20[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\F9XNUA61\keywords;kw=pamper+cafe;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=26395;items=116;sz=1[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\F9XNUA61\keywords;kw=shelving+unit;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=608;sz[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\F9XNUA61\myebaymymessages;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;sz=728x90;ord=1251495641820;dcop[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\F9XNUA61\myebaysummary;seg=GL_Google100Mod0to99;seg=GL_GenderMale30to49;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;sz=160x600;o[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\F9XNUA61\myebaysummary;seg=GL_Google100Mod0to99;seg=GL_GenderMale30to49;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;sz=728x90;or[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\F9XNUA61\myebaysummary;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;sz=160x600;ord=1251492412263;tile=2[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\F9XNUA61\myebaysummary;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;sz=160x600;ord=1251493532420;tile=2[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\F9XNUA61\myebaysummary;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;sz=728x90;ord=1251492412263;dcopt=i[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\F9XNUA61\myebaysummary;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;sz=728x90;ord=1251493112884;dcopt=i[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\CXTP9L3Z\51621884&ga_sid=1251621884&ga_hid=1359242306&ga_fc=0&u_tz=60&u_his=6&u_java=1&u_h=800&u_w=1280&u_ah=770&u_aw=1280&u_cd=32&u_nplug=0&u_nmime=0&biw=1250&bih=567&fu=0&ifi=1&dtd=125 not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\CXTP9L3Z\keywords;kw=cake+boxes+small;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=5;s[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\CXTP9L3Z\keywords;kw=pot+pourri;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=1775;sz=7[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\CRJNE011\keywords;kw=lap+trays;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=400;sz=728[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\CBR7MC55\;mv=1;ms=b;mc=3;mc=4;mc=5;mc=6;mc=7;mc=8;mc=9;ma=g2;ma=g3;ma=g4;ma=g5;ma=g6;ma=h2;ma=h3;ma=h4;ma=h5;ma=h6;ma=h7;ma=a4;ma=c;ma=d;pt=1;px=190000;hb=2;lx=GB;ai=13886;oc=IP2[1] not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\CBR7MC55\keywords;kw=lap+trays;cat=11700;cat=20625;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=20[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\CBR7MC55\keywords;kw=pamper+cafe;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=26395;items=116;sz=1[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\AHF8PWJA\;mv=1;ms=b;mc=3;mc=4;mc=5;mc=6;mc=7;mc=8;mc=9;ma=g2;ma=g3;ma=g4;ma=g5;ma=g6;ma=h2;ma=h3;ma=h4;ma=h5;ma=h6;ma=h7;ma=a4;ma=c;ma=d;pt=1;px=190000;hb=2;lx=GB;ai=13886;oc=IP2[1] not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\AHF8PWJA\sid=1251659453&ga_hid=1701606863&ga_fc=1&u_tz=60&u_his=0&u_java=1&u_h=800&u_w=1280&u_ah=770&u_aw=1280&u_cd=32&u_nplug=0&u_nmime=0&biw=1259&bih=613&eid=36815003&fu=0&ifi=1&dtd=47 not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\5NIQJVGU\dcp;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;sz=300x250;ord=1251480363237;dcopt=ist;tile=1[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\5NIQJVGU\keywords;kw=bath+bombs;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=26395;items=2250;sz=1[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\5NIQJVGU\keywords;kw=cake+boxes+small;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=5;s[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\5NIQJVGU\keywords;kw=melamine+tray;cat=11700;cat=20625;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tca[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\5NIQJVGU\keywords;kw=small+gift+box;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=11700;items=485;s[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\5NIQJVGU\myebaysummary;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;sz=160x600;ord=1251493273932;tile=2[1].htm not found!

File\Folder C:\Documents and Settings\Jane Cureton\Local Settings\Temp\Temporary Internet Files\Content.IE5\5NIQJVGU\storage;cat=11700;cat=43502;seg=GL_Sellers_Listed_within12mont;seg=GL_Buyers_GMB_0to50_last90days;seg=GL_AllSucSell_Mar05;seg=GL_AllRegisteredUsers;tcat=122954;items=138[3].htm not found!

C:\Documents and Settings\Jane Cureton\Local Settings\Temporary Internet Files\Content.IE5\RLZVBA1O\sed[1].htm moved successfully.

C:\Documents and Settings\Jane Cureton\Local Settings\Temporary Internet Files\Content.IE5\M2QH11HN\si[1].htm moved successfully.

C:\Documents and Settings\Jane Cureton\Local Settings\Temporary Internet Files\Content.IE5\KY34WYIH\ads[2].htm moved successfully.

C:\Documents and Settings\Jane Cureton\Local Settings\Temporary Internet Files\Content.IE5\HJOXS2C0\12546-Where-have-my-missing-GBs-gone[1].txt moved successfully.

C:\Documents and Settings\Jane Cureton\Local Settings\Temporary Internet Files\Content.IE5\FDOEUAHR\ads[2].htm moved successfully.

File\Folder C:\WINDOWS\temp\JETC92C.tmp not found!

Registry entries deleted on Reboot...

Posted

OTL after RUN SCAN

OTL logfile created on: 30/10/2011 18:36:24 - Run 2

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Jane Cureton\Desktop

Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

 

895.36 Mb Total Physical Memory | 327.88 Mb Available Physical Memory | 36.62% Memory free

2.12 Gb Paging File | 1.69 Gb Available in Paging File | 79.64% Paging File free

Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 32.50 Gb Total Space | 3.56 Gb Free Space | 10.95% Space Free | Partition Type: NTFS

 

Computer Name: JCMOSAICS | User Name: Jane Cureton | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2011/10/28 12:16:07 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jane Cureton\Desktop\OTL.exe

PRC - [2009/02/09 21:26:23 | 000,386,480 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jucheck.exe

PRC - [2008/10/17 15:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE

PRC - [2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2008/02/18 18:37:42 | 000,214,888 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

PRC - [2008/02/10 00:06:33 | 000,238,968 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe

PRC - [2006/06/07 12:46:31 | 000,180,269 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe

PRC - [2005/08/17 10:39:58 | 000,090,112 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE

PRC - [2004/12/28 14:10:54 | 000,532,480 | ---- | M] (Ralink Technology, Corp.) -- C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe

PRC - [2004/02/29 23:27:40 | 000,184,320 | ---- | M] (InterVideo Inc.) -- C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe

PRC - [2003/07/11 19:45:02 | 000,241,664 | ---- | M] (Nikon Corporation) -- C:\Program Files\Nikon\NkView6\NkvMon.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/02/04 17:48:30 | 000,291,840 | ---- | M] () -- C:\WINDOWS\system32\sbe.dll

MOD - [2010/02/05 18:27:45 | 001,291,776 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll

MOD - [2008/04/14 00:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll

MOD - [2008/04/14 00:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll

MOD - [2008/03/25 04:50:40 | 000,355,112 | ---- | M] () -- C:\WINDOWS\system32\msjetoledb40.dll

 

 

========== Win32 Services (SafeList) ==========

 

SRV - File not found [Disabled | Stopped] -- -- (HidServ)

SRV - [2008/10/17 15:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (LiveUpdate Notice)

SRV - [2008/10/17 15:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (CLTNetCnService)

SRV - [2008/10/17 15:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)

SRV - [2008/10/17 15:52:10 | 000,149,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)

SRV - [2008/08/26 22:34:08 | 001,245,064 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC)

SRV - [2008/08/04 10:20:16 | 003,220,856 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE -- (LiveUpdate)

SRV - [2008/02/18 18:37:42 | 000,214,888 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccProxy.exe -- (ccProxy)

SRV - [2008/02/10 00:06:33 | 000,238,968 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler)

SRV - [2007/08/22 08:21:30 | 000,055,640 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe -- (comHost)

 

 

========== Driver Services (SafeList) ==========

 

DRV - [2011/10/18 06:09:40 | 001,576,312 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111027.022\NAVEX15.SYS -- (NAVEX15)

DRV - [2011/10/18 06:09:40 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111027.022\NAVENG.SYS -- (NAVENG)

DRV - [2011/10/17 22:22:25 | 000,268,728 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20111017.001\SymIDSCo.sys -- (SYMIDSCO)

DRV - [2011/07/28 08:00:00 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\eengine\eeCtrl.sys -- (eeCtrl)

DRV - [2011/07/28 08:00:00 | 000,105,592 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)

DRV - [2009/02/19 11:31:42 | 000,031,280 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SymIM.sys -- (SymIMMP)

DRV - [2009/02/19 11:31:42 | 000,031,280 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SymIM.sys -- (SymIM)

DRV - [2009/02/19 11:31:16 | 000,184,496 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)

DRV - [2009/02/19 11:31:16 | 000,096,560 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMFW.SYS -- (SYMFW)

DRV - [2009/02/19 11:31:16 | 000,038,576 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMIDS.SYS -- (SYMIDS)

DRV - [2009/02/19 11:31:16 | 000,037,424 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMNDIS.SYS -- (SYMNDIS)

DRV - [2009/02/19 11:31:16 | 000,022,320 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)

DRV - [2009/02/19 11:31:16 | 000,013,616 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMDNS.SYS -- (SYMDNS)

DRV - [2009/01/26 06:03:42 | 000,124,464 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)

DRV - [2008/09/05 14:31:42 | 000,447,024 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)

DRV - [2008/07/30 16:42:12 | 000,023,888 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\COH_Mon.sys -- (COH_Mon)

DRV - [2008/02/01 01:51:16 | 000,317,616 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL)

DRV - [2008/02/01 01:51:16 | 000,279,088 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP)

DRV - [2008/02/01 01:51:16 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX)

DRV - [2007/08/09 00:39:56 | 000,036,056 | ---- | M] (Symantec Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CO_Mon.sys -- (CO_Mon)

DRV - [2005/08/19 09:31:52 | 003,644,800 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)

DRV - [2005/07/13 14:37:16 | 001,269,760 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)

DRV - [2005/07/01 07:58:58 | 001,094,814 | R--- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)

DRV - [2005/04/27 09:40:00 | 000,070,144 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtlnicxp.sys -- (RTL8023xp)

DRV - [2005/03/09 15:53:00 | 000,036,352 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)

DRV - [2004/12/15 19:12:04 | 000,218,368 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RT2500.sys -- (RT2500)

DRV - [2004/08/04 06:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)

DRV - [2004/04/03 05:35:08 | 000,043,392 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdr4_xp.sys -- (Cdr4_xp)

DRV - [2004/04/03 05:32:20 | 000,024,576 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdralw2k.sys -- (Cdralw2k)

DRV - [2003/09/19 01:47:00 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (Pfc)

DRV - [2001/08/17 14:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)

DRV - [1995/11/07 09:57:00 | 000,006,144 | ---- | M] (Corel Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\crlscsi.sys -- (crlscsi)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

 

 

IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.pcservicecall.co.uk

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.pcservicecall.co.uk

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.pcservicecall.co.uk

 

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.pcservicecall.co.uk

 

IE - HKU\S-1-5-21-1750105772-1827593217-929180627-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie

IE - HKU\S-1-5-21-1750105772-1827593217-929180627-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKU\S-1-5-21-1750105772-1827593217-929180627-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/

IE - HKU\S-1-5-21-1750105772-1827593217-929180627-1006\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKU\S-1-5-21-1750105772-1827593217-929180627-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

========== FireFox ==========

 

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"

 

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\2.bin\NPMyWebS.dll File not found

FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2321: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2379: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

 

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\2.bin

 

[2011/07/29 23:14:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jane Cureton\Application Data\Mozilla\Firefox\Profiles\077fyhc8.default\extensions

[2011/10/14 21:15:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2007/02/20 15:15:00 | 002,115,816 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\NPSWF32.dll

 

========== Chrome ==========

 

 

O1 HOSTS File: ([2004/08/10 19:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

O2 - BHO: (Reg Error: Value error.) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)

O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)

O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)

O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)

O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)

O3 - HKU\S-1-5-21-1750105772-1827593217-929180627-1006\..\Toolbar\WebBrowser: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)

O3 - HKU\S-1-5-21-1750105772-1827593217-929180627-1006\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)

O4 - HKLM..\Run: [CardReaderReset] C:\Program Files\Realtek Semiconductor Corp\Card Reader Software\Reset.exe ()

O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)

O4 - HKLM..\Run: [EPSON Stylus C86 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE /P23 "EPSON Stylus C86 Series" /O5 "LPT1:" /M "Stylus C86" File not found

O4 - HKLM..\Run: [osCheck] C:\Program Files\Norton Internet Security\osCheck.exe (Symantec Corporation)

O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()

O4 - HKLM..\Run: [soundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe (Nikon Corporation)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk = C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe (Ralink Technology, Corp.)

O4 - Startup: C:\Documents and Settings\Jane Cureton\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-1750105772-1827593217-929180627-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)

O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)

O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)

O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} http://tools.ebayimg.com/pm/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab (EPUImageControl Class)

O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} http://msnuk.oberon-media.com/online2/MSN_INTL_UK/chainz_2/mjolauncher.cab (MJLauncherCtrl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl.sun.com/webapps/download/AutoDL?BundleId=27986 (Java Plug-in 1.6.0_12)

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab53083.cab (ZoneIntro Class)

O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} http://game.zylom.com/activex/zylomgamesplayer.cab (Zylom Games Player)

O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab (EPUImageControl Class)

O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)

O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab (Java Plug-in 1.6.0_12)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab (Java Plug-in 1.6.0_12)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://sympatico.zone.msn.com/bingame/popcaploader_v10.cab (PopCapLoader Object)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C36A7A38-96C7-4290-A25B-E6073651D588}: DhcpNameServer = 192.168.1.254

O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)

O24 - Desktop WallPaper: C:\Documents and Settings\Jane Cureton\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jane Cureton\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2005/09/16 19:44:20 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O33 - MountPoints2\{692bd095-bd9e-11da-957a-806d6172696f}\Shell - "" = AutoRun

O33 - MountPoints2\{692bd095-bd9e-11da-957a-806d6172696f}\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\{692bd095-bd9e-11da-957a-806d6172696f}\Shell\AutoRun\command - "" = D:\winshell110.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[2011/10/30 18:07:18 | 000,000,000 | ---D | C] -- C:\_OTL

[2011/10/30 18:02:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT

[2011/10/30 18:01:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT

[2011/10/30 18:01:28 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT

[2011/10/30 18:00:27 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Jane Cureton\Desktop\erunt-setup.exe

[2011/10/28 13:04:00 | 001,916,416 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Jane Cureton\Desktop\aswMBR.exe

[2011/10/28 12:15:51 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jane Cureton\Desktop\OTL.exe

[2011/10/27 21:47:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jane Cureton\Application Data\Malwarebytes

[2011/10/27 21:46:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware

[2011/10/27 21:46:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2011/10/27 21:46:51 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2011/10/27 21:46:51 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2011/10/14 21:47:12 | 000,000,000 | -HSD | C] -- C:\Config.Msi

[2011/10/02 18:09:05 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl

[2011/10/02 17:59:14 | 000,750,424 | ---- | C] (Adobe Systems Incorporated) -- C:\Documents and Settings\Jane Cureton\Desktop\install_flashplayer10ax_gtbp_chrd_aih.exe

[2005/09/16 21:54:14 | 000,036,963 | R--- | C] (Cypress Semiconductor) -- C:\Program Files\Common Files\SM1updtr.dll

 

========== Files - Modified Within 30 Days ==========

 

[2011/10/30 18:33:14 | 000,444,150 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2011/10/30 18:33:14 | 000,073,058 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2011/10/30 18:27:55 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2011/10/30 18:26:50 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2011/10/30 18:26:43 | 938,921,984 | -HS- | M] () -- C:\hiberfil.sys

[2011/10/30 18:13:05 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2011/10/30 18:02:01 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\Jane Cureton\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk

[2011/10/30 18:01:30 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\Jane Cureton\Desktop\NTREGOPT.lnk

[2011/10/30 18:01:30 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\Jane Cureton\Desktop\ERUNT.lnk

[2011/10/30 18:00:27 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Jane Cureton\Desktop\erunt-setup.exe

[2011/10/28 16:29:30 | 000,002,491 | ---- | M] () -- C:\Documents and Settings\Jane Cureton\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Word (2).lnk

[2011/10/28 13:07:27 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Jane Cureton\Desktop\MBR.dat

[2011/10/28 13:04:01 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Jane Cureton\Desktop\aswMBR.exe

[2011/10/28 12:16:07 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jane Cureton\Desktop\OTL.exe

[2011/10/27 21:47:01 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/10/14 22:05:39 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2011/10/14 22:01:03 | 000,313,656 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2011/10/14 21:48:00 | 000,001,943 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2011/10/03 08:35:11 | 005,971,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll

[2011/10/02 18:09:05 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl

[2011/10/02 17:59:19 | 000,750,424 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\Jane Cureton\Desktop\install_flashplayer10ax_gtbp_chrd_aih.exe

 

========== Files Created - No Company Name ==========

 

[2011/10/30 18:02:01 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\Jane Cureton\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk

[2011/10/30 18:01:30 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\Jane Cureton\Desktop\NTREGOPT.lnk

[2011/10/30 18:01:30 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\Jane Cureton\Desktop\ERUNT.lnk

[2011/10/28 13:07:27 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Jane Cureton\Desktop\MBR.dat

[2011/10/27 21:47:01 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010/11/13 17:40:41 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat

[2008/08/26 21:52:14 | 000,022,403 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LUUnInstall.LiveUpdate

[2008/03/11 17:26:46 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini

[2008/03/11 17:26:45 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat

[2008/03/11 17:26:45 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat

[2008/03/11 17:26:45 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat

[2008/03/11 17:26:45 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat

[2008/03/11 17:26:45 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat

[2008/03/11 17:26:45 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat

[2008/03/11 17:26:45 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat

[2008/03/11 17:26:45 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat

[2008/03/11 17:26:45 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat

[2008/03/11 17:26:45 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat

[2008/03/11 17:26:45 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat

[2008/03/11 17:26:45 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat

[2008/03/11 17:26:45 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat

[2008/03/11 17:26:45 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat

[2008/03/11 17:26:45 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat

[2008/03/11 17:26:45 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat

[2008/03/11 17:26:45 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat

[2008/03/11 17:26:45 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat

[2008/03/11 17:19:06 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDED92Euro.ini

[2007/06/08 22:30:22 | 000,001,156 | ---- | C] () -- C:\WINDOWS\mozver.dat

[2007/06/08 22:27:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat

[2007/01/01 13:54:24 | 000,000,182 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT4.DAT

[2007/01/01 13:29:34 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDESC86PEEuro.ini

[2006/12/27 14:30:52 | 000,002,887 | ---- | C] () -- C:\WINDOWS\cdplayer.ini

[2006/09/03 15:41:53 | 000,005,120 | ---- | C] () -- C:\Documents and Settings\Jane Cureton\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2006/07/18 19:02:41 | 000,000,340 | ---- | C] () -- C:\WINDOWS\QTW.INI

[2006/07/18 19:02:37 | 000,000,144 | ---- | C] () -- C:\WINDOWS\INDEO.INI

[2006/07/01 10:04:31 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Jcmkr32.INI

[2006/06/05 16:26:35 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini

[2006/05/20 14:02:20 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\qttask.exe

[2006/05/20 14:01:31 | 000,000,021 | ---- | C] () -- C:\WINDOWS\PMK_setup.ini

[2006/05/17 10:47:50 | 000,000,135 | ---- | C] () -- C:\Documents and Settings\Jane Cureton\Local Settings\Application Data\fusioncache.dat

[2006/05/15 15:47:47 | 000,000,797 | ---- | C] () -- C:\WINDOWS\SGREP32.INI

[2006/05/15 15:42:53 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\sg50Ps32.dll

[2006/05/15 15:42:51 | 000,256,512 | ---- | C] () -- C:\WINDOWS\System32\SGOPopDg.dll

[2006/05/15 14:43:44 | 000,000,083 | ---- | C] () -- C:\WINDOWS\REPENG.INI

[2006/05/15 14:14:48 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\BurnData.bin

[2006/05/15 13:41:45 | 000,019,932 | ---- | C] () -- C:\WINDOWS\SAGE.INI

[2006/05/14 21:33:06 | 000,001,006 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2006/05/14 19:41:47 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Jane Cureton\Application Data\wklnhst.dat

[2006/03/27 14:39:39 | 000,000,516 | ---- | C] () -- C:\WINDOWS\dialer.ini

[2006/02/28 05:07:15 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\ntiembed.dll

[2006/02/28 05:05:53 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIMPEG2.dll

[2006/02/28 05:05:53 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTICDMK32.dll

[2006/02/28 04:41:50 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll

[2006/02/28 04:41:50 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll

[2006/02/28 04:41:50 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll

[2006/02/28 04:41:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll

[2006/02/28 04:41:49 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll

[2006/02/28 04:41:49 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll

[2006/02/27 21:13:19 | 000,000,060 | ---- | C] () -- C:\WINDOWS\System32\SYSDRV.DAT

[2006/02/27 20:35:38 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat

[2006/02/27 20:35:06 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat

[2006/02/27 20:35:05 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat

[2006/02/27 20:34:57 | 000,004,518 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat

[2006/02/27 20:34:45 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin

[2006/02/27 20:34:29 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

[2006/02/27 20:33:28 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat

[2006/02/27 20:33:26 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin

[2006/02/27 20:32:28 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat

[2006/02/27 20:30:47 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin

[2006/02/27 13:16:47 | 000,151,552 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe

[2006/02/27 13:16:47 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\installrt2500qa.dll

[2006/02/27 13:16:47 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\WRLSetup.exe

[2006/02/27 13:05:44 | 000,000,164 | R--- | C] () -- C:\WINDOWS\avrack.ini

[2006/02/27 12:41:44 | 000,156,672 | R--- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll

[2006/02/27 12:41:44 | 000,040,960 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe

[2006/02/27 12:39:05 | 000,095,617 | R--- | C] () -- C:\WINDOWS\System32\atiicdxx.dat

[2006/01/24 12:37:36 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\SageEventHandler.exe

[2006/01/24 12:36:20 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\SGCtrlEx.dll

[2006/01/24 12:36:12 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SageFolderBrowser.dll

[2006/01/24 12:36:10 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\SGTBAR32.DLL

[2006/01/24 12:36:04 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\SGSTAT32.DLL

[2006/01/24 12:36:04 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\SGLOGO32.DLL

[2006/01/24 12:36:02 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\SGJPEG32.dll

[2006/01/24 12:35:58 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\SGCDLG32.DLL

[2006/01/24 12:35:48 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\SGLIST32.DLL

[2006/01/24 12:35:38 | 000,278,528 | ---- | C] () -- C:\WINDOWS\System32\SGTOOL32.DLL

[2006/01/24 12:35:34 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\SGINTL32.DLL

[2006/01/24 12:35:32 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\SGDT32.DLL

[2006/01/24 12:35:30 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\SGHELP32.DLL

[2006/01/24 12:35:28 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SGAPPBAR.DLL

[2006/01/24 12:35:24 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\SG3D32.DLL

[2006/01/24 12:35:10 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeXP.dll

[2006/01/24 12:35:06 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeDefault.dll

[2006/01/24 12:34:58 | 000,221,184 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeManager.dll

[2006/01/24 12:34:48 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\SGCOM32.DLL

[2006/01/24 12:33:42 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\SGWebBrowser.dll

[2006/01/13 10:43:50 | 000,245,760 | ---- | C] () -- C:\WINDOWS\System32\SGSchemeXml.dll

[2005/11/30 12:49:32 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\REPDES32.EXE

[2005/11/30 12:49:30 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\SGLCH32.DLL

[2005/11/30 12:49:20 | 001,712,128 | ---- | C] () -- C:\WINDOWS\System32\SGREP32.DLL

[2005/09/19 16:54:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini

[2005/09/16 19:47:13 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2005/09/16 19:40:30 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

[2005/09/16 19:28:26 | 000,001,452 | R--- | C] () -- C:\WINDOWS\System32\oeminfo.ini

[2005/09/16 19:27:13 | 000,444,150 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat

[2005/09/16 19:27:13 | 000,073,058 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat

[2005/09/16 12:35:23 | 000,005,997 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2005/09/16 12:34:32 | 000,313,656 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2005/09/01 23:39:24 | 000,831,488 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll

[2005/09/01 23:39:24 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll

[2005/09/01 23:39:00 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll

[2005/08/05 21:01:54 | 000,239,104 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll

[2005/07/11 13:33:12 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\SDOApp.dll

[2004/06/09 10:57:12 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\Install.exe

[2002/04/16 11:27:54 | 000,000,005 | -HS- | C] () -- C:\WINDOWS\System32\CdI5T.drv

[2001/12/26 16:12:30 | 000,065,536 | R--- | C] () -- C:\WINDOWS\System32\multiplex_vcd.dll

[2001/09/03 23:46:38 | 000,110,592 | R--- | C] () -- C:\WINDOWS\System32\Hmpg12.dll

[2001/07/30 16:33:56 | 000,118,784 | R--- | C] () -- C:\WINDOWS\System32\HMPV2_ENC.dll

[2001/07/23 22:04:36 | 000,118,784 | R--- | C] () -- C:\WINDOWS\System32\HMPV2_ENC_MMX.dll

[1999/01/23 02:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL

[1998/03/26 01:12:00 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\SgHmZLib.dll

[1997/06/14 00:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:02C1CB6D

@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:69E17801

@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:10B7A752

@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:57B4E612

@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7A266313

@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5711EF65

< End of report >

Posted

ESETscan:

C:\WINDOWS\system32\f3PSSavr.scr Win32/Toolbar.MyWebSearch application cleaned by deleting - quarantined

 

I have a little bit of space returned - free space now 3.39GB.

 

Thanks for the time you're spending on this.

Kind regards

Jane

Posted

Hello, janec.

 

 

 

 

Step 1

 

 

You are using and outdated version of Adobe Reader. Adobe has since been updated and the update closes many security holes and provides new features.

 

 

First, uninstall earlier versions of Adobe Reader.

  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all versions of Adobe Reader.
  • Check (highlight) any item with Adobe Reader in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Adobe Reader version.

 

 

Please download the latest version from:

http://get.adobe.com/reader/download/

 

 

And install it. Once installed, launch it, select Help --> Check for Updates and install any updates.

 

 

 

 

You may also try the free Foxit PDF reader if you prefer:

http://www.foxitsoftware.com/pdf/reader/

 

 

 

 

 

 

Step 2

 

 

Next, we need to update Java.

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:

  • Download the latest version of Java Runtime Environment (JRE) Version 26 32-bit version. Note that if you have 64-bit windows, the default is to use a 32-bit browser. If you modified your IE to use the 64-bit version, make sure to also download the 64-bit version.
  • Save it to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) or Java in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version(s) shown below:
    Java 6 Update 2
    Java 6 Update 12
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u26-windows-i586-s.exe to install the newest version. If you downloaded the 64-bit version, make sure to install that as well.

 

 

 

 

 

 

 

 

Step 3

 

 

 

 

Do you know where those GBs are on your hard drive? Let's use JDiskReport.

 

 

Download JDiskReport Here

 

 

Double click to run it.

Click Next. Uncheck everything except Desktop Icon and click Next.

Click Install.

Uncheck show readme and click Finish.

 

 

Find the icon and double-click it on your desktop (JDiskReport)

 

 

It will scan your hard drive, this usually takes a couple of minutes. Then, you'll see a report. On the left pane, click on your C:\ drive. Then, on the right, click on the Top 100 tab...it will show the 100 largest files. See what is there and let me know...you can take a screenshot and attach it if you like. ALso, look at the Types tab for C:\....what file types are taking the biggest space?

 

 

 

 

 

 

 

 

 

 

etavares

Posted

Hello etavares,

I now have the up to date versions of Adobe and Java.

I ran Jdiskreport but for some reason the results only show the top 50 files not top 100.

 

50 largest files in C:\

No. Name File Size Modified Path

1 C:\pagefile.sys 1.3 GB 01-Jan-1970 01:00 C:\

2 C:\Documents and Settings\Jane Cureton\Local Settings\Application Data\Google\GoogleEarth\dbCache.dat 1.3 GB 23-Sep-2011 16:59 C:\Documents and Settings\Jane Cureton\Local Settings\Application Data\Google\GoogleEarth

3 C:\hiberfil.sys 895.4 MB 01-Jan-1970 01:00 C:\

4 C:\Documents and Settings\Jane Cureton\Local Settings\Application Data\Microsoft\Outlook\outlook.pst 204.3 MB 31-Oct-2011 12:17 C:\Documents and Settings\Jane Cureton\Local Settings\Application Data\Microsoft\Outlook

5 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp7b5c.tmp\VIRSCAN7.DAT 189.0 MB 30-Oct-2011 08:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp7b5c.tmp

6 C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111030.005\VIRSCAN7.DAT 189.0 MB 30-Oct-2011 08:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111030.005

7 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp3393.tmp\VIRSCAN7.DAT 0 KB 01-Jan-1970 01:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp3393.tmp

8 C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111029.006\VIRSCAN7.DAT 188.7 MB 29-Oct-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111029.006

9 C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111027.022\VIRSCAN7.DAT 188.2 MB 27-Oct-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111027.022

10 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp4a97.tmp\virscan7.dat 187.8 MB 26-Oct-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp4a97.tmp

11 C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111026.002\VIRSCAN7.DAT 187.8 MB 26-Oct-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111026.002

12 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp2ddd.tmp\virscan7.dat 185.3 MB 18-Oct-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp2ddd.tmp

13 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp1485.tmp\VIRSCAN7.DAT 185.3 MB 18-Oct-2011 07:09 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp1485.tmp

14 C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan7.dat 185.3 MB 18-Oct-2011 07:09 C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub

15 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp6444.tmp\VIRSCAN7.DAT 182.3 MB 09-Oct-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp6444.tmp

16 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp5d5a.tmp\VIRSCAN7.DAT 181.3 MB 04-Oct-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp5d5a.tmp

17 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp3710.tmp\VIRSCAN7.DAT 181.2 MB 03-Oct-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp3710.tmp

18 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp7244.tmp\VIRSCAN7.DAT 180.3 MB 30-Sep-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp7244.tmp

19 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp4c32.tmp\VIRSCAN7.DAT 177.6 MB 22-Sep-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp4c32.tmp

20 C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110922.002\VIRSCAN7.DAT 177.6 MB 22-Sep-2011 22:23 C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110922.002

21 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp4e67.tmp\VIRSCAN7.DAT 170.2 MB 28-Aug-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp4e67.tmp

22 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp4c82.tmp\VIRSCAN7.DAT 168.0 MB 23-Aug-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp4c82.tmp

23 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp26e4.tmp\VIRSCAN7.020 167.2 MB 18-Oct-2011 07:06 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp26e4.tmp

24 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp752.tmp\virscan7.dat 165.7 MB 31-Aug-2011 12:19 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp752.tmp

25 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp5570.tmp\virscan7.dat 165.7 MB 18-Aug-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp5570.tmp

26 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp4626.tmp\VIRSCAN7.DAT 160.7 MB 07-Aug-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp4626.tmp

27 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp909.tmp\VIRSCAN7.DAT 158.8 MB 01-Aug-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp909.tmp

28 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp4ad5.tmp\VIRSCAN7.DAT 156.6 MB 28-Jul-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp4ad5.tmp

29 C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110728.002\VIRSCAN7.DAT 156.6 MB 28-Jul-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110728.002

30 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmpb85.tmp\VIRSCAN7.DAT 151.1 MB 19-Jul-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmpb85.tmp

31 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp1175.tmp\VIRSCAN7.DAT 150.6 MB 26-Sep-2011 19:19 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp1175.tmp

32 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp6ddb.tmp\VIRSCAN7.DAT 148.8 MB 12-Jul-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp6ddb.tmp

33 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp6a88.tmp\VIRSCAN7.DAT 145.9 MB 06-Jul-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp6a88.tmp

34 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp230e.tmp\VIRSCAN7.DAT 145.5 MB 05-Jul-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp230e.tmp

35 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp506.tmp\VIRSCAN7.DAT 145.0 MB 01-Jul-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp506.tmp

36 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp309c.tmp\VIRSCAN7.DAT 144.6 MB 30-Jun-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp309c.tmp

37 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp2ba5.tmp\VIRSCAN7.DAT 143.5 MB 28-Jun-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp2ba5.tmp

38 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp612f.tmp\VIRSCAN7.DAT 143.1 MB 26-Jun-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp612f.tmp

39 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp6113.tmp\VIRSCAN7.DAT 143.1 MB 26-Jun-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp6113.tmp

40 C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\1318972338jtun_nav2k8ennful25.m25 142.6 MB 26-Oct-2011 22:24 C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads

41 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp5522.tmp\VIRSCAN7.DAT 139.6 MB 16-Jun-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp5522.tmp

42 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp7441.tmp\VIRSCAN7.DAT 138.0 MB 14-Jun-2011 18:20 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp7441.tmp

43 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp14a3.tmp\VIRSCAN7.DAT 134.8 MB 05-Jun-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp14a3.tmp

44 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp1c81.tmp\VIRSCAN7.DAT 129.0 MB 08-Apr-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp1c81.tmp

45 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp3587.tmp\VIRSCAN7.DAT 128.5 MB 18-Apr-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp3587.tmp

46 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp7caa.tmp\VIRSCAN7.DAT 128.3 MB 04-May-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp7caa.tmp

47 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp792c.tmp\VIRSCAN7.DAT 128.2 MB 03-Apr-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp792c.tmp

48 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp2ff3.tmp\VIRSCAN7.DAT 127.6 MB 29-Apr-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp2ff3.tmp

49 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp7dbd.tmp\VIRSCAN7.035 123.3 MB 18-Aug-2011 13:21 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp7dbd.tmp

50 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp7765.tmp\VIRSCAN7.DAT 119.1 MB 15-Feb-2011 09:00 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp7765.tmp

Posted

Types of files as follows:

File types in C:\

Extension File Sizes (KB) % of Total Files % of Files

dat 13,493,208 45.2% 2,189 2.7%

dll 4,018,267 13.5% 10,566 13.1%

sys 2,600,246 8.7% 1,236 1.5%

exe 1,624,010 5.4% 2,632 3.3%

cab 717,943 2.4% 110 0.1%

bin 663,806 2.2% 335 0.4%

jpg 636,173 2.1% 2,277 2.8%

m25 457,823 1.5% 24 0.0%

zip 373,901 1.3% 380 0.5%

<None> 335,155 1.1% 3,131 3.9%

msp 326,904 1.1% 52 0.1%

pst 212,012 0.7% 3 0.0%

000 189,713 0.6% 494 0.6%

da2 181,757 0.6% 25 0.0%

020 171,185 0.6% 2 0.0%

dl_ 168,183 0.6% 1,740 2.2%

xml 157,533 0.5% 480 0.6%

msi 156,049 0.5% 96 0.1%

035 126,231 0.4% 1 0.0%

hlp 116,717 0.4% 253 0.3%

cpl 114,973 0.4% 90 0.1%

wmv 89,498 0.3% 18 0.0%

log 83,516 0.3% 615 0.8%

chm 77,183 0.3% 516 0.6%

vxd 76,246 0.3% 234 0.3%

979 75,180 0.3% 48 0.1%

bmp 73,337 0.2% 1,100 1.4%

tdb 72,920 0.2% 8 0.0%

dn2 72,114 0.2% 25 0.0%

999 70,112 0.2% 557 0.7%

ocx 69,371 0.2% 132 0.2%

inf 67,799 0.2% 2,596 3.2%

jar 60,809 0.2% 20 0.0%

exp 58,830 0.2% 146 0.2%

api 55,643 0.2% 34 0.0%

sbs 48,301 0.2% 1 0.0%

img 46,743 0.2% 4 0.0%

nup 39,787 0.1% 17 0.0%

bak 39,766 0.1% 21 0.0%

tt_ 39,736 0.1% 139 0.2%

ex_ 38,087 0.1% 467 0.6%

ttf 37,764 0.1% 361 0.4%

mst 35,986 0.1% 20 0.0%

qbd 35,870 0.1% 2,947 3.7%

otf 32,261 0.1% 18 0.0%

pnf 29,963 0.1% 751 0.9%

wav 29,847 0.1% 523 0.7%

edb 29,720 0.1% 3 0.0%

gif 29,529 0.1% 5,246 6.5%

ch_ 29,230 0.1% 272 0.3%

cat 28,251 0.1% 922 1.1%

mmc 27,497 0.1% 7 0.0%

scr 27,202 0.1% 1,072 1.3%

eit 26,660 0.1% 2 0.0%

ax 26,169 0.1% 117 0.1%

db 24,819 0.1% 47 0.1%

lex 23,385 0.1% 13 0.0%

mof 22,259 0.1% 133 0.2%

wwp 21,236 0.1% 169 0.2%

800 20,915 0.1% 31 0.0%

swf 20,766 0.1% 33 0.0%

ird 20,712 0.1% 2 0.0%

x02 20,428 0.1% 262 0.3%

data 19,800 0.1% 1 0.0%

ini 19,151 0.1% 971 1.2%

996 18,694 0.1% 557 0.7%

di_ 18,480 0.1% 11 0.0%

qbs 17,645 0.1% 1 0.0%

sdb 17,167 0.1% 22 0.0%

png 17,133 0.1% 2,490 3.1%

003 17,113 0.1% 483 0.6%

wmz 17,067 0.1% 17 0.0%

x86 16,652 0.1% 23 0.0%

loc 15,980 0.1% 140 0.2%

980 15,834 0.1% 61 0.1%

nls 15,817 0.1% 197 0.2%

acs 15,678 0.1% 10 0.0%

981 14,695 0.0% 62 0.1%

txt 14,561 0.0% 1,251 1.6%

imd 14,441 0.0% 8 0.0%

qm 13,939 0.0% 84 0.1%

wlt 13,444 0.0% 1 0.0%

sw_ 13,322 0.0% 7 0.0%

im_ 13,083 0.0% 38 0.0%

jsa 13,056 0.0% 1 0.0%

bi_ 12,818 0.0% 3 0.0%

mdb 12,137 0.0% 10 0.0%

api__non_opt 12,105 0.0% 1 0.0%

tlb 11,517 0.0% 100 0.1%

pdf 11,516 0.0% 16 0.0%

rtf 11,485 0.0% 32 0.0%

liveupdate 11,255 0.0% 48 0.1%

psd 11,133 0.0% 52 0.1%

htm 10,899 0.0% 1,951 2.4%

018 10,752 0.0% 2 0.0%

wm_ 10,736 0.0% 30 0.0%

icc 10,449 0.0% 34 0.0%

sbt 10,348 0.0% 1 0.0%

ttc 10,266 0.0% 1 0.0%

sy_ 10,209 0.0% 229 0.3%

iec 9,942 0.0% 27 0.0%

x3d 9,891 0.0% 12 0.0%

adm 9,816 0.0% 24 0.0%

qtx 9,797 0.0% 16 0.0%

aw 9,710 0.0% 23 0.0%

982 9,039 0.0% 62 0.1%

8bf 8,552 0.0% 81 0.1%

wmf 8,483 0.0% 778 1.0%

ref 8,464 0.0% 8 0.0%

pf 7,860 0.0% 135 0.2%

998 7,731 0.0% 557 0.7%

ilg 7,588 0.0% 20 0.0%

mdt 7,532 0.0% 2 0.0%

997 7,351 0.0% 557 0.7%

flt 7,322 0.0% 23 0.0%

ms_ 7,018 0.0% 25 0.0%

js 7,017 0.0% 277 0.3%

sbc 6,928 0.0% 3 0.0%

dls 6,721 0.0% 2 0.0%

inx 6,680 0.0% 34 0.0%

poc 6,611 0.0% 73 0.1%

hlx 6,567 0.0% 72 0.1%

ctg 6,378 0.0% 2 0.0%

ac_ 6,171 0.0% 15 0.0%

cch 6,145 0.0% 109 0.1%

ton 6,058 0.0% 2 0.0%

abr 5,993 0.0% 13 0.0%

avi 5,972 0.0% 3 0.0%

pat 5,657 0.0% 73 0.1%

api_non_opt 5,579 0.0% 7 0.0%

msstyles 5,409 0.0% 2 0.0%

mui 5,273 0.0% 82 0.1%

983 5,181 0.0% 63 0.1%

eff 5,052 0.0% 17 0.0%

wa_ 5,002 0.0% 134 0.2%

mde 4,976 0.0% 2 0.0%

mfl 4,942 0.0% 34 0.0%

html 4,854 0.0% 777 1.0%

x32 4,832 0.0% 21 0.0%

ca_ 4,807 0.0% 39 0.0%

978 4,603 0.0% 38 0.0%

sqlite 4,408 0.0% 2 0.0%

wmdb 4,355 0.0% 6 0.0%

8be 4,332 0.0% 2 0.0%

ic_ 4,316 0.0% 33 0.0%

dot 4,204 0.0% 64 0.1%

index 4,177 0.0% 1 0.0%

icm 4,164 0.0% 39 0.0%

qts 4,108 0.0% 1 0.0%

swz 4,064 0.0% 14 0.0%

asl 3,995 0.0% 14 0.0%

apl 3,856 0.0% 5 0.0%

nlp 3,819 0.0% 56 0.1%

mbk 3,753 0.0% 3 0.0%

jp_ 3,734 0.0% 153 0.2%

wpc 3,718 0.0% 19 0.0%

rcc 3,717 0.0% 34 0.0%

fon 3,538 0.0% 146 0.2%

cnv 3,524 0.0% 19 0.0%

m21 3,468 0.0% 1 0.0%

hhk 3,358 0.0% 9 0.0%

spd 3,293 0.0% 2 0.0%

3643236f_fc70_11d3_a536_0090278a1bb8 3,256 0.0% 10 0.0%

le_ 3,017 0.0% 5 0.0%

ime 2,981 0.0% 20 0.0%

sql 2,944 0.0% 46 0.1%

drv 2,912 0.0% 56 0.1%

chq 2,893 0.0% 4 0.0%

ogg 2,878 0.0% 279 0.3%

001 2,854 0.0% 483 0.6%

nl_ 2,703 0.0% 137 0.2%

dll_non_opt 2,632 0.0% 1 0.0%

in_ 2,602 0.0% 820 1.0%

hl_ 2,590 0.0% 161 0.2%

wma 2,564 0.0% 1 0.0%

mo3 2,550 0.0% 1 0.0%

lxa 2,439 0.0% 4 0.0%

xlt 2,409 0.0% 35 0.0%

8li 2,388 0.0% 11 0.0%

acm 2,383 0.0% 18 0.0%

igb 2,376 0.0% 58 0.1%

olb 2,369 0.0% 14 0.0%

972 2,250 0.0% 2 0.0%

pot 2,244 0.0% 34 0.0%

spi 2,213 0.0% 2 0.0%

csf 2,189 0.0% 4 0.0%

wsb 2,136 0.0% 4 0.0%

pn_ 2,135 0.0% 151 0.2%

wws 2,092 0.0% 130 0.2%

984 2,064 0.0% 65 0.1%

992 1,958 0.0% 65 0.1%

985 1,831 0.0% 65 0.1%

008 1,826 0.0% 482 0.6%

che 1,820 0.0% 6 0.0%

ths 1,816 0.0% 3 0.0%

btr 1,750 0.0% 3 0.0%

ico 1,744 0.0% 123 0.2%

vch 1,743 0.0% 2 0.0%

kml 1,682 0.0% 289 0.4%

8bi 1,668 0.0% 16 0.0%

wiz 1,663 0.0% 7 0.0%

deu 1,645 0.0% 4 0.0%

hdr 1,619 0.0% 32 0.0%

995 1,601 0.0% 393 0.5%

sav 1,593 0.0% 5 0.0%

oc_ 1,586 0.0% 20 0.0%

cpa 1,538 0.0% 3 0.0%

fae 1,488 0.0% 12 0.0%

enu 1,487 0.0% 10 0.0%

cp_ 1,483 0.0% 27 0.0%

bdb 1,477 0.0% 4 0.0%

tsp 1,416 0.0% 15 0.0%

sp_ 1,413 0.0% 1 0.0%

cfg 1,404 0.0% 97 0.1%

mpp 1,389 0.0% 8 0.0%

1 1,387 0.0% 3 0.0%

pmp 1,385 0.0% 6 0.0%

fo_ 1,371 0.0% 202 0.3%

cdr 1,336 0.0% 20 0.0%

md3 1,324 0.0% 2 0.0%

nld 1,299 0.0% 4 0.0%

mar 1,276 0.0% 4 0.0%

old 1,256 0.0% 12 0.0%

wrs 1,245 0.0% 7 0.0%

977 1,217 0.0% 22 0.0%

evt 1,216 0.0% 5 0.0%

022 1,194 0.0% 2 0.0%

ax_ 1,194 0.0% 18 0.0%

pfb 1,192 0.0% 28 0.0%

sif 1,174 0.0% 4 0.0%

dvr-ms 1,158 0.0% 2 0.0%

qkt 1,158 0.0% 1 0.0%

sve 1,142 0.0% 4 0.0%

sig 1,094 0.0% 469 0.6%

ita 1,087 0.0% 4 0.0%

query 1,073 0.0% 540 0.7%

sc_ 1,068 0.0% 17 0.0%

psp 1,066 0.0% 8 0.0%

fil 1,057 0.0% 2 0.0%

004 1,049 0.0% 483 0.6%

bdr 1,046 0.0% 30 0.0%

tbl 1,038 0.0% 4 0.0%

fra 1,037 0.0% 4 0.0%

ntf 1,036 0.0% 1 0.0%

crmlog 1,024 0.0% 1 0.0%

fti 1,019 0.0% 1 0.0%

idx 1,014 0.0% 7 0.0%

vbs 987 0.0% 23 0.0%

csh 965 0.0% 17 0.0%

mb_ 947 0.0% 3 0.0%

lst 939 0.0% 34 0.0%

acg 917 0.0% 8 0.0%

vs 916 0.0% 7 0.0%

isu 913 0.0% 2 0.0%

cmp 901 0.0% 1 0.0%

qbi 898 0.0% 3,885 4.8%

msc 885 0.0% 22 0.0%

007 878 0.0% 482 0.6%

96868 877 0.0% 2 0.0%

nor 842 0.0% 3 0.0%

wfn 837 0.0% 39 0.0%

qtc 822 0.0% 8 0.0%

esn 816 0.0% 3 0.0%

987 806 0.0% 65 0.1%

spm 787 0.0% 309 0.4%

ai 779 0.0% 41 0.1%

002 778 0.0% 483 0.6%

config 773 0.0% 84 0.1%

lx_ 767 0.0% 2 0.0%

38449 758 0.0% 2 0.0%

dic 755 0.0% 4 0.0%

abm 720 0.0% 10 0.0%

sdf 706 0.0% 4 0.0%

cache 703 0.0% 54 0.1%

lnk 685 0.0% 660 0.8%

de_ 679 0.0% 3 0.0%

pub 671 0.0% 16 0.0%

w32 672 0.0% 2 0.0%

da_ 653 0.0% 12 0.0%

elm 650 0.0% 13 0.0%

vbx 640 0.0% 14 0.0%

hsp 630 0.0% 3 0.0%

chw 627 0.0% 6 0.0%

doc 626 0.0% 13 0.0%

037 624 0.0% 1 0.0%

45900 611 0.0% 2 0.0%

wwd 595 0.0% 14 0.0%

xls 585 0.0% 14 0.0%

ibd 580 0.0% 1 0.0%

fmt 560 0.0% 27 0.0%

grd 555 0.0% 429 0.5%

isn 552 0.0% 3 0.0%

rob 545 0.0% 3 0.0%

994 531 0.0% 69 0.1%

targets 524 0.0% 14 0.0%

mid 518 0.0% 46 0.1%

browser 515 0.0% 25 0.0%

sv_ 507 0.0% 3 0.0%

gi_ 500 0.0% 116 0.1%

dbx 499 0.0% 5 0.0%

en_ 496 0.0% 2 0.0%

com 494 0.0% 20 0.0%

css 488 0.0% 91 0.1%

ani 487 0.0% 43 0.1%

gm 483 0.0% 1 0.0%

033 482 0.0% 1 0.0%

005 478 0.0% 483 0.6%

mdz 476 0.0% 10 0.0%

ppa 472 0.0% 1 0.0%

sll 472 0.0% 1 0.0%

usf 471 0.0% 17 0.0%

aspx 469 0.0% 37 0.0%

970 452 0.0% 2 0.0%

sam 450 0.0% 9 0.0%

ibt 446 0.0% 5 0.0%

019 441 0.0% 2 0.0%

key 439 0.0% 2 0.0%

chi 437 0.0% 8 0.0%

sd_ 436 0.0% 5 0.0%

lng 435 0.0% 51 0.1%

fr_ 432 0.0% 3 0.0%

as_ 426 0.0% 31 0.0%

dib 425 0.0% 30 0.0%

it_ 423 0.0% 3 0.0%

986 419 0.0% 65 0.1%

tb_ 415 0.0% 13 0.0%

clx 414 0.0% 4 0.0%

xsd 414 0.0% 77 0.1%

mda 412 0.0% 1 0.0%

mo_ 406 0.0% 46 0.1%

rll 400 0.0% 8 0.0%

wp_ 393 0.0% 32 0.0%

ipf 390 0.0% 64 0.1%

sds 388 0.0% 1 0.0%

13808 385 0.0% 2 0.0%

sk 381 0.0% 17 0.0%

bm_ 380 0.0% 48 0.1%

sob 377 0.0% 1 0.0%

es_ 375 0.0% 3 0.0%

988 374 0.0% 65 0.1%

jp2 367 0.0% 22 0.0%

tga 354 0.0% 65 0.1%

8bx 352 0.0% 3 0.0%

kc 353 0.0% 3 0.0%

pcx 352 0.0% 35 0.0%

dft 342 0.0% 5 0.0%

prf 337 0.0% 4 0.0%

tl_ 326 0.0% 19 0.0%

mdw 324 0.0% 3 0.0%

59422 324 0.0% 2 0.0%

php 320 0.0% 14 0.0%

prx 310 0.0% 1 0.0%

ht_ 307 0.0% 174 0.2%

ldo 305 0.0% 29 0.0%

gpd 298 0.0% 19 0.0%

95755 297 0.0% 2 0.0%

ver 297 0.0% 327 0.4%

22293 295 0.0% 2 0.0%

hds 292 0.0% 1 0.0%

btn 290 0.0% 3 0.0%

dr_ 289 0.0% 16 0.0%

hyp 288 0.0% 4 0.0%

976 282 0.0% 6 0.0%

993 279 0.0% 65 0.1%

71681 273 0.0% 2 0.0%

ntd 272 0.0% 1 0.0%

ts_ 269 0.0% 8 0.0%

29212 267 0.0% 2 0.0%

xsl 264 0.0% 31 0.0%

atr 261 0.0% 38 0.0%

989 260 0.0% 65 0.1%

psys 258 0.0% 97 0.1%

hiv 256 0.0% 1 0.0%

lo_ 257 0.0% 4 0.0%

gdl 256 0.0% 10 0.0%

oca 254 0.0% 2 0.0%

cty 253 0.0% 2 0.0%

fpt 253 0.0% 2 0.0%

ma_ 248 0.0% 3 0.0%

atn 242 0.0% 155 0.2%

uce 241 0.0% 8 0.0%

cnt 240 0.0% 58 0.1%

90007 238 0.0% 2 0.0%

cdt 238 0.0% 7 0.0%

vp 238 0.0% 9 0.0%

006 235 0.0% 482 0.6%

cn_ 235 0.0% 19 0.0%

ps 231 0.0% 6 0.0%

acl 229 0.0% 6 0.0%

dbf 228 0.0% 8 0.0%

shb 226 0.0% 1 0.0%

mf_ 222 0.0% 29 0.0%

cur 218 0.0% 192 0.2%

013 216 0.0% 2 0.0%

cmv 213 0.0% 1 0.0%

manifest 213 0.0% 67 0.1%

uc_ 210 0.0% 8 0.0%

bpt 206 0.0% 2 0.0%

rpv 203 0.0% 5 0.0%

ad_ 202 0.0% 7 0.0%

wcd 200 0.0% 1 0.0%

991 200 0.0% 65 0.1%

shw 190 0.0% 5 0.0%

msg 184 0.0% 3 0.0%

gra 183 0.0% 1 0.0%

68153 181 0.0% 2 0.0%

gdp 181 0.0% 7 0.0%

dll_apollo 180 0.0% 1 0.0%

tmd 176 0.0% 55 0.1%

wab 173 0.0% 1 0.0%

wab~ 173 0.0% 1 0.0%

asp 171 0.0% 25 0.0%

co_ 170 0.0% 19 0.0%

012 168 0.0% 2 0.0%

xtr 162 0.0% 20 0.0%

msk 161 0.0% 1 0.0%

e_e 160 0.0% 1 0.0%

scn 160 0.0% 11 0.0%

91288 157 0.0% 2 0.0%

default 157 0.0% 13 0.0%

ell 156 0.0% 1 0.0%

esp 156 0.0% 1 0.0%

ie_ 156 0.0% 1 0.0%

75470 153 0.0% 2 0.0%

hun 152 0.0% 1 0.0%

plk 152 0.0% 1 0.0%

ptb 152 0.0% 1 0.0%

rus 152 0.0% 1 0.0%

84165 152 0.0% 2 0.0%

csy 148 0.0% 1 0.0%

dan 148 0.0% 1 0.0%

fin 148 0.0% 1 0.0%

tha 149 0.0% 2 0.0%

trk 148 0.0% 1 0.0%

64379 147 0.0% 2 0.0%

974 146 0.0% 2 0.0%

resx 146 0.0% 45 0.1%

ara 144 0.0% 1 0.0%

uninstall 145 0.0% 7 0.0%

wri 144 0.0% 4 0.0%

ccs 143 0.0% 1 0.0%

76104 141 0.0% 2 0.0%

qpx 141 0.0% 1 0.0%

url 140 0.0% 674 0.8%

cc 139 0.0% 9 0.0%

83415 138 0.0% 2 0.0%

tpl 138 0.0% 39 0.0%

44587 137 0.0% 2 0.0%

heb 136 0.0% 1 0.0%

80238 136 0.0% 2 0.0%

ezlog 136 0.0% 1 0.0%

mlb 135 0.0% 1 0.0%

inc 134 0.0% 18 0.0%

nt_ 132 0.0% 3 0.0%

11308 130 0.0% 2 0.0%

75021 129 0.0% 2 0.0%

lns 129 0.0% 1 0.0%

84104 127 0.0% 2 0.0%

cod 126 0.0% 2 0.0%

65889 125 0.0% 2 0.0%

cdl 125 0.0% 80 0.1%

cpi 125 0.0% 1 0.0%

mi_ 124 0.0% 25 0.0%

12675 120 0.0% 2 0.0%

rm 120 0.0% 2 0.0%

dtd 119 0.0% 31 0.0%

im 118 0.0% 13 0.0%

jpn 116 0.0% 1 0.0%

map 116 0.0% 17 0.0%

8by 112 0.0% 2 0.0%

cpt 113 0.0% 1 0.0%

kor 112 0.0% 1 0.0%

64313 111 0.0% 2 0.0%

compositefont 111 0.0% 4 0.0%

reg 111 0.0% 28 0.0%

990 109 0.0% 65 0.1%

jsp 108 0.0% 2 0.0%

chs 108 0.0% 3 0.0%

cht 108 0.0% 3 0.0%

63573 105 0.0% 2 0.0%

ta_ 105 0.0% 2 0.0%

xdr 105 0.0% 36 0.0%

asd 104 0.0% 26 0.0%

arbvp1 101 0.0% 26 0.0%

comments 99 0.0% 2 0.0%

mch 97 0.0% 2 0.0%

wpj 96 0.0% 11 0.0%

vboxlm 95 0.0% 1 0.0%

vs_2_0 94 0.0% 26 0.0%

dmp 92 0.0% 1 0.0%

txr 93 0.0% 1 0.0%

xla 93 0.0% 3 0.0%

ink 92 0.0% 3 0.0%

xdc 90 0.0% 2 0.0%

81907 88 0.0% 2 0.0%

fli 88 0.0% 4 0.0%

pfm 88 0.0% 27 0.0%

properties 88 0.0% 23 0.0%

rul 86 0.0% 3 0.0%

13622 85 0.0% 2 0.0%

90204 85 0.0% 2 0.0%

98317 85 0.0% 2 0.0%

mlsxml 84 0.0% 45 0.1%

450 83 0.0% 1 0.0%

mov 81 0.0% 1 0.0%

tif 79 0.0% 3 0.0%

445 78 0.0% 1 0.0%

19599 77 0.0% 2 0.0%

des 77 0.0% 48 0.1%

gr_ 77 0.0% 1 0.0%

hkf 76 0.0% 2 0.0%

vb_ 76 0.0% 10 0.0%

46637 73 0.0% 2 0.0%

71778 71 0.0% 2 0.0%

co[1] 70 0.0% 73 0.1%

h 70 0.0% 34 0.0%

clb 68 0.0% 2 0.0%

448 67 0.0% 2 0.0%

htx 67 0.0% 31 0.0%

js_ 67 0.0% 18 0.0%

oft 67 0.0% 1 0.0%

44788 66 0.0% 2 0.0%

rpd 65 0.0% 9 0.0%

w 65 0.0% 5 0.0%

xrs 65 0.0% 1 0.0%

tmp 64 0.0% 8 0.0%

ascx 63 0.0% 11 0.0%

md_ 62 0.0% 2 0.0%

cdv 60 0.0% 1 0.0%

ac3 59 0.0% 1 0.0%

cs 59 0.0% 7 0.0%

81689 58 0.0% 2 0.0%

soc 58 0.0% 7 0.0%

64858 57 0.0% 2 0.0%

73316 57 0.0% 2 0.0%

73982 57 0.0% 2 0.0%

82891 57 0.0% 2 0.0%

bud 57 0.0% 1 0.0%

feed-ms 56 0.0% 2 0.0%

iso 56 0.0% 1 0.0%

58005 56 0.0% 2 0.0%

83498 56 0.0% 2 0.0%

rom 55 0.0% 3 0.0%

84140 54 0.0% 2 0.0%

cdx 52 0.0% 7 0.0%

qfn 53 0.0% 1 0.0%

rnx 53 0.0% 2 0.0%

theme 53 0.0% 11 0.0%

84806 52 0.0% 2 0.0%

rhn 52 0.0% 22 0.0%

iem 51 0.0% 2 0.0%

dbt 49 0.0% 1 0.0%

ppt 48 0.0% 4 0.0%

37340 48 0.0% 2 0.0%

ppd 48 0.0% 9 0.0%

qtr 47 0.0% 2 0.0%

sq_ 47 0.0% 2 0.0%

021 46 0.0% 2 0.0%

cov 46 0.0% 4 0.0%

14264 45 0.0% 2 0.0%

conf 44 0.0% 6 0.0%

22587 43 0.0% 2 0.0%

cu_ 43 0.0% 150 0.2%

jwt 42 0.0% 4 0.0%

18555 41 0.0% 2 0.0%

41249 41 0.0% 2 0.0%

skin 41 0.0% 1 0.0%

sog 41 0.0% 3 0.0%

ui 41 0.0% 17 0.0%

htt 40 0.0% 9 0.0%

wsc 40 0.0% 1 0.0%

xm_ 40 0.0% 41 0.1%

dvd 39 0.0% 2 0.0%

mod 39 0.0% 3 0.0%

rl_ 39 0.0% 4 0.0%

452 38 0.0% 1 0.0%

33986 37 0.0% 2 0.0%

56079 37 0.0% 2 0.0%

8ba 36 0.0% 1 0.0%

crl 37 0.0% 2 0.0%

arbfp1 35 0.0% 26 0.0%

cct 35 0.0% 16 0.0%

451 33 0.0% 1 0.0%

50639 33 0.0% 2 0.0%

68802 33 0.0% 2 0.0%

76164 33 0.0% 2 0.0%

89990 33 0.0% 2 0.0%

fav 33 0.0% 1 0.0%

lgg 33 0.0% 3 0.0%

nqf 32 0.0% 1 0.0%

ps_2_0 33 0.0% 26 0.0%

pl_ 32 0.0% 1 0.0%

449 31 0.0% 1 0.0%

50550 31 0.0% 2 0.0%

70845 31 0.0% 2 0.0%

irs 31 0.0% 13 0.0%

ent 30 0.0% 3 0.0%

xcu 30 0.0% 10 0.0%

017 29 0.0% 2 0.0%

52012 29 0.0% 2 0.0%

60207 29 0.0% 2 0.0%

65896 29 0.0% 2 0.0%

77596 29 0.0% 2 0.0%

92726 29 0.0% 2 0.0%

bat 29 0.0% 7 0.0%

qtif 29 0.0% 1 0.0%

032 28 0.0% 1 0.0%

bst 28 0.0% 17 0.0%

obe 28 0.0% 4 0.0%

vrg 28 0.0% 6 0.0%

98426 26 0.0% 2 0.0%

rgs 26 0.0% 1 0.0%

21676 25 0.0% 2 0.0%

58446 25 0.0% 2 0.0%

61767 25 0.0% 2 0.0%

70096 25 0.0% 2 0.0%

91192 25 0.0% 2 0.0%

aco 25 0.0% 8 0.0%

an_ 25 0.0% 34 0.0%

xs_ 25 0.0% 16 0.0%

ecf 24 0.0% 23 0.0%

38003 23 0.0% 2 0.0%

policy 23 0.0% 33 0.0%

dcr 22 0.0% 2 0.0%

pdi 22 0.0% 2 0.0%

wbk 22 0.0% 1 0.0%

25152 21 0.0% 2 0.0%

446 21 0.0% 1 0.0%

bla 21 0.0% 2 0.0%

pro 21 0.0% 1 0.0%

49435 20 0.0% 2 0.0%

91193 20 0.0% 2 0.0%

son 20 0.0% 1 0.0%

web 20 0.0% 1 0.0%

0%7c817%7c2017952%20%7c0%7c225%20%7cadtech;cookie=info;loc=100%20;target=_blank;key=$keywordstring;grp=310;misc=1320002497062 19 0.0% 1 0.0%

0%7c817%7c2017952%20%7c0%7c225%20%7cadtech;cookie=info;loc=100%20;target=_blank;key=$keywordstring;grp=79;misc=1320002479703 19 0.0% 1 0.0%

0%7c817%7c2017952%20%7c0%7c225%20%7cadtech;cookie=info;loc=100%20;target=_blank;key=$keywordstring;grp=903;misc=1320002450093 19 0.0% 1 0.0%

0%7c817%7c2017952%20%7c0%7c225%20%7cadtech;cookie=info;loc=100%20;target=_blank;key=crime;grp=434;misc=1320002396265 19 0.0% 1 0.0%

0%7c817%7c2017954%20%7c0%7c168%20%7cadtech;cookie=info;loc=100%20;target=_blank;key=$keywordstring;grp=310;misc=1320002494453 19 0.0% 1 0.0%

55642 19 0.0% 2 0.0%

end 19 0.0% 2 0.0%

xpi 19 0.0% 1 0.0%

30116 18 0.0% 2 0.0%

cls 18 0.0% 4 0.0%

man 18 0.0% 19 0.0%

pip 18 0.0% 17 0.0%

src 18 0.0% 2 0.0%

tasks 18 0.0% 2 0.0%

tpf 18 0.0% 1 0.0%

21677 17 0.0% 2 0.0%

22302 17 0.0% 2 0.0%

59893 17 0.0% 2 0.0%

68642 17 0.0% 2 0.0%

98014 17 0.0% 2 0.0%

acf 17 0.0% 4 0.0%

chk 16 0.0% 2 0.0%

rsp 17 0.0% 10 0.0%

18779 16 0.0% 2 0.0%

63110 16 0.0% 2 0.0%

av_ 16 0.0% 1 0.0%

wb2 16 0.0% 4 0.0%

26150 15 0.0% 2 0.0%

60477 15 0.0% 2 0.0%

63336 15 0.0% 2 0.0%

81426 15 0.0% 2 0.0%

93010 15 0.0% 2 0.0%

cfn 15 0.0% 2 0.0%

eps 15 0.0% 1 0.0%

ffp 15 0.0% 1 0.0%

mmm 15 0.0% 2 0.0%

stg 14 0.0% 2 0.0%

81889 14 0.0% 2 0.0%

fca 14 0.0% 3 0.0%

libraries 14 0.0% 1 0.0%

rat 14 0.0% 3 0.0%

spp 14 0.0% 1 0.0%

windowslivegroup 14 0.0% 6 0.0%

wpt 14 0.0% 1 0.0%

29484 13 0.0% 2 0.0%

55207 13 0.0% 2 0.0%

78562 13 0.0% 2 0.0%

frm 13 0.0% 2 0.0%

master 13 0.0% 6 0.0%

swp 12 0.0% 1 0.0%

25757 12 0.0% 2 0.0%

49266 12 0.0% 2 0.0%

dis 12 0.0% 122 0.2%

lds 12 0.0% 1 0.0%

opg 12 0.0% 1 0.0%

sm 12 0.0% 6 0.0%

spr 12 0.0% 104 0.1%

template 12 0.0% 3 0.0%

xd_ 12 0.0% 18 0.0%

hta 11 0.0% 1 0.0%

rdf 11 0.0% 8 0.0%

security 11 0.0% 1 0.0%

010 10 0.0% 2 0.0%

14695 10 0.0% 2 0.0%

ct_ 10 0.0% 1 0.0%

dun 10 0.0% 18 0.0%

ll 10 0.0% 2 0.0%

nib 10 0.0% 1 0.0%

rjt 10 0.0% 1 0.0%

swb 10 0.0% 1 0.0%

wk4 10 0.0% 4 0.0%

xlb 10 0.0% 3 0.0%

009 9 0.0% 2 0.0%

bld 9 0.0% 3 0.0%

cpx 9 0.0% 4 0.0%

iss 9 0.0% 11 0.0%

mtz 9 0.0% 1 0.0%

n1_ 9 0.0% 1 0.0%

prc 9 0.0% 1 0.0%

pwl 9 0.0% 1 0.0%

qtp 9 0.0% 2 0.0%

s 9 0.0% 3 0.0%

scp 9 0.0% 4 0.0%

shp 9 0.0% 23 0.0%

tx_ 9 0.0% 10 0.0%

windowslivecontact 9 0.0% 2 0.0%

xpt 9 0.0% 4 0.0%

014 8 0.0% 2 0.0%

14300 8 0.0% 2 0.0%

54607 8 0.0% 2 0.0%

63972 8 0.0% 2 0.0%

88484 8 0.0% 2 0.0%

cds 8 0.0% 1 0.0%

dlg 8 0.0% 1 0.0%

feedsdb-ms 7 0.0% 1 0.0%

font 8 0.0% 14 0.0%

h_ 8 0.0% 11 0.0%

icw 8 0.0% 6 0.0%

mmf 8 0.0% 3 0.0%

soh 8 0.0% 2 0.0%

usd 8 0.0% 17 0.0%

ws_ 8 0.0% 1 0.0%

zi_ 8 0.0% 2 0.0%

43805 7 0.0% 2 0.0%

48887 7 0.0% 2 0.0%

bfc 7 0.0% 2 0.0%

env 7 0.0% 2 0.0%

hxx 7 0.0% 1 0.0%

json 7 0.0% 3 0.0%

lrm 7 0.0% 20 0.0%

ro_ 7 0.0% 3 0.0%

sep 7 0.0% 4 0.0%

soe 7 0.0% 2 0.0%

spc 7 0.0% 1 0.0%

sqm 7 0.0% 20 0.0%

tpa 7 0.0% 2 0.0%

023 6 0.0% 2 0.0%

029 6 0.0% 1 0.0%

18374 6 0.0% 2 0.0%

acrodata 6 0.0% 2 0.0%

class 6 0.0% 2 0.0%

cor 6 0.0% 5 0.0%

cs_ 6 0.0% 7 0.0%

eif 6 0.0% 2 0.0%

mecontact 6 0.0% 2 0.0%

sca 6 0.0% 13 0.0%

si_ 6 0.0% 3 0.0%

015 5 0.0% 2 0.0%

030 5 0.0% 1 0.0%

038 5 0.0% 1 0.0%

30642 5 0.0% 2 0.0%

50822 5 0.0% 2 0.0%

_ 5 0.0% 5 0.0%

ba_ 5 0.0% 1 0.0%

bjf 5 0.0% 1 0.0%

content 5 0.0% 3 0.0%

db-journal 5 0.0% 1 0.0%

def 5 0.0% 11 0.0%

dt_ 5 0.0% 2 0.0%

du_ 5 0.0% 9 0.0%

enc 5 0.0% 1 0.0%

gry 5 0.0% 9 0.0%

h2_ 5 0.0% 4 0.0%

lic 5 0.0% 1 0.0%

nt 5 0.0% 2 0.0%

prg 5 0.0% 1 0.0%

registeredservices 5 0.0% 2 0.0%

sdv 4 0.0% 2 0.0%

sod 5 0.0% 2 0.0%

tmpl 5 0.0% 2 0.0%

trm 4 0.0% 1 0.0%

025 4 0.0% 1 0.0%

16812 4 0.0% 2 0.0%

33319 4 0.0% 2 0.0%

33814 4 0.0% 2 0.0%

69283 4 0.0% 2 0.0%

92723 4 0.0% 2 0.0%

95203 4 0.0% 2 0.0%

969 4 0.0% 2 0.0%

97619 4 0.0% 2 0.0%

access 4 0.0% 1 0.0%

ctr 4 0.0% 4 0.0%

det 4 0.0% 1 0.0%

ds 4 0.0% 1 0.0%

id 4 0.0% 1 0.0%

obj 4 0.0% 2 0.0%

pbk 4 0.0% 1 0.0%

shc 4 0.0% 2 0.0%

sol 4 0.0% 10 0.0%

tp_ 4 0.0% 1 0.0%

tsk 4 0.0% 3 0.0%

036 3 0.0% 1 0.0%

34924 3 0.0% 2 0.0%

39071 3 0.0% 2 0.0%

66878 3 0.0% 2 0.0%

71084 3 0.0% 2 0.0%

78510 3 0.0% 2 0.0%

88865 3 0.0% 2 0.0%

971 3 0.0% 2 0.0%

975 3 0.0% 3 0.0%

98465 3 0.0% 2 0.0%

addressbook 3 0.0% 1 0.0%

btl 3 0.0% 2 0.0%

cer 3 0.0% 3 0.0%

cmd 3 0.0% 5 0.0%

db_ 3 0.0% 1 0.0%

heu 3 0.0% 14 0.0%

htc 3 0.0% 7 0.0%

ja 3 0.0% 1 0.0%

job 3 0.0% 3 0.0%

l2736%2526_nkw%253dgarrett+ace+150 3 0.0% 2 0.0%

lib 3 0.0% 1 0.0%

ob_ 3 0.0% 2 0.0%

opt 3 0.0% 1 0.0%

pr_ 3 0.0% 1 0.0%

propdesc 3 0.0% 1 0.0%

sa_ 3 0.0% 2 0.0%

se_ 3 0.0% 4 0.0%

sl3 3 0.0% 1 0.0%

th_ 3 0.0% 3 0.0%

011 2 0.0% 2 0.0%

016 2 0.0% 2 0.0%

034 2 0.0% 1 0.0%

14681 2 0.0% 2 0.0%

17138 2 0.0% 2 0.0%

17978 2 0.0% 2 0.0%

18731 2 0.0% 2 0.0%

19567 2 0.0% 2 0.0%

20298 2 0.0% 2 0.0%

24167 2 0.0% 2 0.0%

24903 2 0.0% 2 0.0%

26388 2 0.0% 2 0.0%

29611 2 0.0% 2 0.0%

32788 2 0.0% 2 0.0%

33332 2 0.0% 2 0.0%

34206 2 0.0% 2 0.0%

386 2 0.0% 1 0.0%

40803 2 0.0% 2 0.0%

41039 2 0.0% 2 0.0%

44819 2 0.0% 2 0.0%

48017 2 0.0% 2 0.0%

49388 2 0.0% 2 0.0%

51968 2 0.0% 2 0.0%

58118 2 0.0% 2 0.0%

60274 2 0.0% 2 0.0%

61986 2 0.0% 2 0.0%

62171 2 0.0% 2 0.0%

63804 2 0.0% 2 0.0%

66213 2 0.0% 2 0.0%

70709 2 0.0% 2 0.0%

71847 2 0.0% 2 0.0%

79617 2 0.0% 2 0.0%

87324 2 0.0% 2 0.0%

94949 2 0.0% 2 0.0%

973 2 0.0% 2 0.0%

98496 2 0.0% 2 0.0%

bas 2 0.0% 1 0.0%

bpz 2 0.0% 10 0.0%

cm_ 2 0.0% 3 0.0%

cnf 2 0.0% 5 0.0%

col 2 0.0% 1 0.0%

con 2 0.0% 3 0.0%

dbl 2 0.0% 1 0.0%

der 2 0.0% 1 0.0%

do_ 2 0.0% 2 0.0%

ds_ 2 0.0% 1 0.0%

dsg 2 0.0% 1 0.0%

eng 2 0.0% 2 0.0%

for 2 0.0% 1 0.0%

gp_ 2 0.0% 4 0.0%

hx_ 2 0.0% 1 0.0%

ins 2 0.0% 2 0.0%

is_ 2 0.0% 5 0.0%

isp 2 0.0% 10 0.0%

mcl 2 0.0% 4 0.0%

odb 2 0.0% 1 0.0%

os_ 2 0.0% 2 0.0%

pp_ 2 0.0% 1 0.0%

ra_ 2 0.0% 2 0.0%

scd 2 0.0% 2 0.0%

thm 2 0.0% 2 0.0%

usr 2 0.0% 1 0.0%

wb_ 2 0.0% 1 0.0%

wfc 2 0.0% 1 0.0%

xl_ 2 0.0% 2 0.0%

xlc 2 0.0% 2 0.0%

xul 2 0.0% 3 0.0%

0%7c817%7c2017954%20%7c0%7c168%20%7cadtech;cfp=1;rndc=132000238;cookie=info;loc=100%20;target=_blank;key=crime;grp=434;misc=1320002381156 1 0.0% 1 0.0%

0%7c817%7c2017954%20%7c0%7c168%20%7cadtech;cookie=info;loc=100%20;target=_blank;key=$keywordstring;grp=79;misc=1320002474015 1 0.0% 1 0.0%

0%7c817%7c2017954%20%7c0%7c168%20%7cadtech;cookie=info;loc=100%20;target=_blank;key=$keywordstring;grp=903;misc=1320002446671 1 0.0% 1 0.0%

0%7c817%7c2338152%20%7c0%7c170%20%7cadtech;cookie=info;loc=100%20;target=_blank;key=crime;grp=434;misc=1320002388375 1 0.0% 1 0.0%

0%7c817%7c2377458%7c0%7c1025%7cadtech;cookie=info;loc=100;target=_blank;key=key1+key2+key3+key4;grp=310;misc=1320002495765 1 0.0% 1 0.0%

0%7c817%7c2377458%7c0%7c1025%7cadtech;cookie=info;loc=100;target=_blank;key=key1+key2+key3+key4;grp=434;misc=1320002395437 1 0.0% 1 0.0%

0%7c817%7c2377458%7c0%7c1025%7cadtech;cookie=info;loc=100;target=_blank;key=key1+key2+key3+key4;grp=79;misc=1320002476484 1 0.0% 1 0.0%

0%7c817%7c2377458%7c0%7c1025%7cadtech;cookie=info;loc=100;target=_blank;key=key1+key2+key3+key4;grp=903;misc=1320002449515 1 0.0% 1 0.0%

024 1 0.0% 1 0.0%

026 1 0.0% 1 0.0%

027 1 0.0% 1 0.0%

028 1 0.0% 1 0.0%

031 1 0.0% 1 0.0%

11473 1 0.0% 2 0.0%

12000 1 0.0% 2 0.0%

12115 1 0.0% 1 0.0%

12826 1 0.0% 1 0.0%

13003 1 0.0% 2 0.0%

13541 1 0.0% 2 0.0%

13657 1 0.0% 2 0.0%

13981 1 0.0% 1 0.0%

14349 1 0.0% 2 0.0%

14399 1 0.0% 2 0.0%

14448 1 0.0% 2 0.0%

15008 1 0.0% 2 0.0%

15244 1 0.0% 2 0.0%

15965 1 0.0% 2 0.0%

16192 1 0.0% 2 0.0%

16460 1 0.0% 2 0.0%

17821 1 0.0% 2 0.0%

18248 1 0.0% 2 0.0%

19446 1 0.0% 2 0.0%

19484 1 0.0% 1 0.0%

19780 1 0.0% 2 0.0%

20479 1 0.0% 2 0.0%

21926 1 0.0% 2 0.0%

22325 1 0.0% 2 0.0%

23430 1 0.0% 2 0.0%

23700 1 0.0% 1 0.0%

24224 1 0.0% 2 0.0%

25293 1 0.0% 2 0.0%

25601 1 0.0% 2 0.0%

25722 1 0.0% 2 0.0%

26788 1 0.0% 2 0.0%

27500 1 0.0% 2 0.0%

27526 1 0.0% 2 0.0%

27605 1 0.0% 1 0.0%

27678 1 0.0% 1 0.0%

27719 1 0.0% 2 0.0%

28044 1 0.0% 2 0.0%

28349 1 0.0% 2 0.0%

29416 1 0.0% 2 0.0%

29473 1 0.0% 2 0.0%

29775 1 0.0% 2 0.0%

30439 1 0.0% 2 0.0%

30836 1 0.0% 2 0.0%

31106 1 0.0% 2 0.0%

31974 1 0.0% 2 0.0%

32535 1 0.0% 2 0.0%

33237 1 0.0% 1 0.0%

36002 1 0.0% 2 0.0%

36021 1 0.0% 2 0.0%

36568 1 0.0% 1 0.0%

37757 1 0.0% 2 0.0%

38068 1 0.0% 2 0.0%

38745 1 0.0% 2 0.0%

38839 1 0.0% 1 0.0%

39530 1 0.0% 2 0.0%

40072 1 0.0% 2 0.0%

40097 1 0.0% 2 0.0%

40433 1 0.0% 2 0.0%

41117 1 0.0% 2 0.0%

41138 1 0.0% 2 0.0%

41411 1 0.0% 2 0.0%

41531 1 0.0% 2 0.0%

42361 1 0.0% 2 0.0%

43168 1 0.0% 2 0.0%

43223 1 0.0% 1 0.0%

43984 1 0.0% 2 0.0%

44747 1 0.0% 2 0.0%

45021 1 0.0% 1 0.0%

45223 1 0.0% 2 0.0%

45708 1 0.0% 2 0.0%

45929 1 0.0% 2 0.0%

46663 1 0.0% 2 0.0%

47671 1 0.0% 2 0.0%

47790 1 0.0% 1 0.0%

48234 1 0.0% 2 0.0%

48806 1 0.0% 2 0.0%

48940 1 0.0% 1 0.0%

49511 1 0.0% 2 0.0%

49811 1 0.0% 1 0.0%

50665 1 0.0% 2 0.0%

51177 1 0.0% 2 0.0%

51568 1 0.0% 1 0.0%

51670 1 0.0% 2 0.0%

52020 1 0.0% 2 0.0%

52762 1 0.0% 2 0.0%

53249 1 0.0% 1 0.0%

53913 1 0.0% 1 0.0%

54342 1 0.0% 1 0.0%

54508 1 0.0% 2 0.0%

55012 1 0.0% 2 0.0%

55243 1 0.0% 2 0.0%

55318 1 0.0% 2 0.0%

55515 1 0.0% 2 0.0%

56232 1 0.0% 2 0.0%

56722 1 0.0% 2 0.0%

56927 1 0.0% 2 0.0%

57539 1 0.0% 2 0.0%

58291 1 0.0% 2 0.0%

58613 1 0.0% 1 0.0%

58983 1 0.0% 2 0.0%

59144 1 0.0% 1 0.0%

59187 1 0.0% 2 0.0%

59927 1 0.0% 1 0.0%

60434 1 0.0% 2 0.0%

60507 1 0.0% 2 0.0%

61492 1 0.0% 2 0.0%

61903 1 0.0% 1 0.0%

61911 1 0.0% 2 0.0%

61946 1 0.0% 2 0.0%

62084 1 0.0% 2 0.0%

62384 1 0.0% 2 0.0%

62791 1 0.0% 2 0.0%

62970 1 0.0% 2 0.0%

64078 1 0.0% 2 0.0%

64859 1 0.0% 2 0.0%

65407 1 0.0% 2 0.0%

65693 1 0.0% 1 0.0%

65825 1 0.0% 2 0.0%

66047 1 0.0% 2 0.0%

66578 1 0.0% 1 0.0%

67275 1 0.0% 2 0.0%

67316 1 0.0% 2 0.0%

67483 1 0.0% 2 0.0%

67816 1 0.0% 2 0.0%

68516 1 0.0% 2 0.0%

68599 1 0.0% 2 0.0%

69744 1 0.0% 2 0.0%

69808 1 0.0% 2 0.0%

70028 1 0.0% 1 0.0%

70100 1 0.0% 2 0.0%

70591 1 0.0% 2 0.0%

71051 1 0.0% 2 0.0%

71654 1 0.0% 2 0.0%

71722 1 0.0% 2 0.0%

72762 1 0.0% 1 0.0%

73099 1 0.0% 2 0.0%

73288 1 0.0% 2 0.0%

73595 1 0.0% 2 0.0%

73726 1 0.0% 2 0.0%

73840 1 0.0% 2 0.0%

74559 1 0.0% 2 0.0%

74827 1 0.0% 2 0.0%

75485 1 0.0% 1 0.0%

75793 1 0.0% 1 0.0%

76243 1 0.0% 2 0.0%

76477 1 0.0% 2 0.0%

76503 1 0.0% 2 0.0%

77161 1 0.0% 1 0.0%

77639 1 0.0% 2 0.0%

77876 1 0.0% 2 0.0%

78193 1 0.0% 2 0.0%

78382 1 0.0% 2 0.0%

79061 1 0.0% 2 0.0%

79329 1 0.0% 2 0.0%

79386 1 0.0% 2 0.0%

79626 1 0.0% 2 0.0%

81061 1 0.0% 2 0.0%

81249 1 0.0% 2 0.0%

81349 1 0.0% 2 0.0%

81560 1 0.0% 2 0.0%

82174 1 0.0% 2 0.0%

82359 1 0.0% 2 0.0%

83444 1 0.0% 2 0.0%

83659 1 0.0% 2 0.0%

84569 1 0.0% 2 0.0%

86224 1 0.0% 2 0.0%

87688 1 0.0% 2 0.0%

87696 1 0.0% 2 0.0%

88063 1 0.0% 1 0.0%

89194 1 0.0% 2 0.0%

89967 1 0.0% 2 0.0%

90942 1 0.0% 2 0.0%

91348 1 0.0% 2 0.0%

91832 1 0.0% 1 0.0%

92090 1 0.0% 2 0.0%

92380 1 0.0% 1 0.0%

92600 1 0.0% 2 0.0%

92974 1 0.0% 1 0.0%

93428 1 0.0% 2 0.0%

93479 1 0.0% 2 0.0%

95016 1 0.0% 2 0.0%

95266 1 0.0% 2 0.0%

97164 1 0.0% 1 0.0%

97744 1 0.0% 2 0.0%

99047 1 0.0% 2 0.0%

99316 1 0.0% 1 0.0%

99798 1 0.0% 2 0.0%

aud 1 0.0% 1 0.0%

awe 1 0.0% 2 0.0%

ba1 0 0.0% 1 0.0%

ba2 0 0.0% 1 0.0%

bau 1 0.0% 1 0.0%

cf_ 1 0.0% 2 0.0%

cvm 1 0.0% 2 0.0%

dcf 1 0.0% 1 0.0%

dep 1 0.0% 1 0.0%

desklink 0 0.0% 4 0.0%

dicproof 0 0.0% 1 0.0%

disco 1 0.0% 1 0.0%

ec_ 1 0.0% 1 0.0%

eid 1 0.0% 1 0.0%

esi 1 0.0% 2 0.0%

exe&ce_name=download 1 0.0% 1 0.0%

exv 1 0.0% 1 0.0%

flg 1 0.0% 2 0.0%

fnd 0 0.0% 1 0.0%

helpcfg 1 0.0% 1 0.0%

inuse 0 0.0% 1 0.0%

iqy 1 0.0% 4 0.0%

itr 1 0.0% 2 0.0%

jc_ 1 0.0% 1 0.0%

ko_ 1 0.0% 1 0.0%

l1313%2526_nkw%253dmetal+detector%2526_sacat%253dsee-all-categories 1 0.0% 1 0.0%

lck 0 0.0% 4 0.0%

ldb 1 0.0% 1 0.0%

loadfeaturemap_15_0 1 0.0% 1 0.0%

loadfeaturemap_716_0 1 0.0% 1 0.0%

local 1 0.0% 5 0.0%

lock 0 0.0% 2 0.0%

mak 1 0.0% 1 0.0%

mapimail 0 0.0% 4 0.0%

mm_ 1 0.0% 1 0.0%

mtx 1 0.0% 1 0.0%

mydocs 0 0.0% 4 0.0%

ndf 1 0.0% 1 0.0%

nick 0 0.0% 1 0.0%

nqi 1 0.0% 1 0.0%

nsi 1 0.0% 4 0.0%

pal 1 0.0% 4 0.0%

pd 1 0.0% 2 0.0%

ph 0 0.0% 1 0.0%

pi_ 1 0.0% 1 0.0%

pif 1 0.0% 1 0.0%

pm_ 1 0.0% 1 0.0%

ram 1 0.0% 1 0.0%

re_ 1 0.0% 2 0.0%

registeredapplications 1 0.0% 1 0.0%

rmi 0 0.0% 1 0.0%

rs_ 1 0.0% 1 0.0%

rst 0 0.0% 1 0.0%

rwz 1 0.0% 1 0.0%

scc 1 0.0% 3 0.0%

scf 1 0.0% 6 0.0%

sec 1 0.0% 1 0.0%

set 1 0.0% 1 0.0%

settings 1 0.0% 1 0.0%

sh_ 1 0.0% 1 0.0%

smi 1 0.0% 1 0.0%

smil 1 0.0% 1 0.0%

sr_ 1 0.0% 1 0.0%

ssf 1 0.0% 2 0.0%

sta 1 0.0% 1 0.0%

stat 1 0.0% 2 0.0%

state 1 0.0% 3 0.0%

ste 0 0.0% 1 0.0%

tag 1 0.0% 2 0.0%

tme 0 0.0% 1 0.0%

tr_ 1 0.0% 1 0.0%

uk%252fnews%252flatest-news 1 0.0% 1 0.0%

utf8 0 0.0% 1 0.0%

ve_ 1 0.0% 1 0.0%

vx_ 1 0.0% 1 0.0%

we_ 1 0.0% 1 0.0%

win32manifest 1 0.0% 1 0.0%

wk_ 1 0.0% 1 0.0%

wpd 1 0.0% 5 0.0%

wpg 1 0.0% 5 0.0%

wpl 1 0.0% 2 0.0%

xba 1 0.0% 1 0.0%

xml~ 1 0.0% 1 0.0%

zfsendtotarget 0 0.0% 4 0.0%

 

 

Looking at the top 50, they are virtually all Norton files. Is it Norton that is causing the problem?

Kind regards

Jane

Posted

Yes, it does appear to be Norton...there are Gigs being taken up by it. We can rebuild the definitions. Try following this article from Norton on how to clear out corrupted definitions and start fresh.

 

http://service1.symantec.com/SUPPORT/ent-security.nsf/2326c6a13572aeb788257363002b62aa/691fb01f62f2a700882573c2006d6de7?OpenDocument

 

If you're not comfortable with those instructions, let me know and I can write a batch file to do it for you. It does involve editing the registry. We do have a safety net with ERUNT, so that's good.

 

Alternatively, you may want to use another antivirus. I recommend Avast! or Avira AntiVir...both of which are free for home use.

Posted

Hello etavares,

Thank you so much for your help. I had a look at the article from Norton and have hit a snag straight away.

It instructs you to:

Stop the SymantecEndpoint Protection Services:

  1. Click the Start button and then click Run
  2. Type services.msc and click OK
  3. Right-click Symantec Management Client and click Stop.
  4. Right-click Symantec Endpoint Protection and click Stop.

I was OK until steps c and d. Neither of these appear in the list.

Unfortunately I have to admit I'm fairly clueless with all this. I'm not even 100% sure what XP I'm using. I'm assuming it's a 32-bit Operating System but don't know how to check. I'm sorry to cause you more work but if you could write a batch file and tell me what to do with it I'd really appreciate it.

Sorry to be so dopey.

Kind regards

Jane

Posted

Hello etavares,

I was looking at my Norton to determine which version I am using and it's come up with a message stating that with the subscription I have I can download the most up to date version for free.

Would it be a good idea if I did this and might it solve the problems?

Kind regards

Jane

Posted

Maybe this link will help with determing your version of Norton.

https://www-secure.symantec.com/norton-support/jsp/help-solutions.jsp?lg=english&ct=united+states&docid=20080417101717EN&product=home&version=1&pvid=f-home

 

As etavares has said there used to be an issue with Norton eating up drive space but that was some time ago.

 

As Norton can be a real pain to remove and a mention was made I would use the uninstall tool if you choose to go that route.

 

Please wait for etavares to reply before doing anything.

We are all members helping other members. Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs.

Get help with computer problems. Join Free PC Help here

 

Donations are welcome. Read Here

Posted (edited)

OK, I think the best approach is to remove Norton and reinstall it at this point since the definitions appear corrupted. It used to happen a lot more years ago, but it still happens from time to time.

 

Please follow these instructions to save your account key and uninstall Norton.

https://www-secure.symantec.com/norton-support/jsp/help-solutions.jsp?docid=20080828154508EN&lg=english&ct=united+states&product=home&version=1&pvid=f-home

 

Then, immediately reinstall Norton and update it, or install Avast or AntiVir, both free for home use. Only install one..having more than 1 antivirus will cause many issues.

 

Once that's done, please let me know and we'll get your space back.

Edited by etavares

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...