Jump to content


Photo

Installed Adobe Flash Player not recognized in IE9 only Firefox


  • This topic is locked This topic is locked
17 replies to this topic

#1 MoJo Risin&039;

MoJo Risin&039;

    Member

  • Full Member
  • Pip
  • 66 posts

Posted 01 December 2012 - 01:24 PM

Installed Adobe Flash Player not recognized in IE9 only Firefox

Greetings again good people at SWI. A PC novice friend who has had several issues in the past has once again dropped off a laptop which all of a sudden can no longer play Adobe Flash files in IE 9. However, the same Flash files play OK in Firefox 17. (ex: A YouTube vid in IE 9 gets a constant prompt that Adobe Flash Player is not installed along with a download Hyperlink to the Adobe website. After download and install of Flash Player 11.5.502.110 I am led back to the Adobe website and notified that the install was successful.) I have uninstalled and reinstalled Flash Player (alternately, for a 32 bit, then a 64 bit OS) several times to no avail. The lappy is an Acer Intel Core I3, 64 bit CPU, OS is W7SP1, running ESET Smart Security 4.0, Malwarebytes Pro, SpywareBalster (free version) and HOSTS Secure for manual HOST file updates. All are up to date as of this posting. IE9 is set as their default browser. I also cannot run a complete scan with ESET. There are approx. 60 Gigs of data on a 320 Gig HDD and ESET locks up after scanning only around 25,000 files. However, the CPU activity appears that ESET is running and using about 25 – 35% of CPU resources although no progress is happening even after 9 hours of scanning. I ran the scan several times and each time it stalled anywhere between 35 – 55% complete. I do know that recently somehow they accidentally downloaded and installed Norton Internet Security which caused a conflict with ESET. So, I got the latest Norton removal tool from their website and ran it to remove it. Coincidentally, it appears that is when these issues started happening. (Although I don’t understand what that would have to do with it, unless Norton wasn’t completely removed properly by the tool.)

All related IE 9 Internet Options, Task Manager & MSCONFIG Services settings are identical to mine and I have no problem with my IE 9 playing Flash files. (For the record, I use Firefox and only IE when necessary.) After several hours and days of unsuccessfully trying to resolve this issue, I decided to run and post the Malwarebytes, DDS, & Security Check results logs for you kind folks to analyze. Let me know should you require anything further.

Thank you all for what you unselfishly do.

Best Regards,
Mojo

Logs are posted below:

Malwarebytes Full Scan Log:
Malwarebytes Anti-Malware (PRO) 1.65.1.1000
www.malwarebytes.org

Database version: v2012.12.01.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
John :: JOHN-ACER [administrator]

Protection: Enabled

12/1/2012 10:04:21 AM
mbam-log-2012-12-01 (10-04-21).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 488168
Time elapsed: 2 hour(s), 2 minute(s), 53 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
*************************************
*************************************

DDS.txt Results:

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16455 BrowserJavaVersion: 10.9.2
Run by John at 12:33:39 on 2012-12-01
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3764.1903 [GMT -5:00]
.
AV: ESET Smart Security 4.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET Smart Security 4.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\LSI SoftModem\agr64svc.exe
C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\StudioLine Photo Basic\NMSAccess32.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Program Files (x86)\Common Files\Motive\pcCMService.exe
C:\Program Files\Common Files\Motive\pcCMService.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Acer\Acer Updater\UpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\igfxext.exe
C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files (x86)\D-Link\D-Link RangeBooster N DWA-140\AirNCFG.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\notepad.exe
C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
C:\Windows\splwow64.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/?ilc=21
mStart Page = hxxp://www.mytotalusa.net
uURLSearchHooks: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - <orphaned>
BHO: KeyScramblerBHO Class: {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} -
BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - <orphaned>
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} -
TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} -
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [ANIWZCS2Service] C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe
mRun: [D-Link D-Link RangeBooster N DWA-140] C:\Program Files (x86)\D-Link\D-Link RangeBooster N DWA-140\AirNCFG.exe
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://floridakeysmedia.tv/axiscam/Codebase/AxisCamControl.ocx
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} - hxxp://zone.msn.com/bingame/zpagames/ZPA_Backgammon.cab64162.cab
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{6E450910-314D-4311-8099-EB494996A50E}\2456C6B696E6F5E4F575962756C6563737F5542364030333 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{6E450910-314D-4311-8099-EB494996A50E}\A696E676C65637D27657563747 : DHCPNameServer = 209.18.47.61 209.18.47.62 192.168.33.1
TCP: Interfaces\{84A88CC5-A21A-470B-A64E-B0377BD41669} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{84A88CC5-A21A-470B-A64E-B0377BD41669}\2375942554131373 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{84A88CC5-A21A-470B-A64E-B0377BD41669}\2456C6B696E6F5E4F575962756C6563737F5542364030333 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{84A88CC5-A21A-470B-A64E-B0377BD41669}\A696E676C65637D27657563747 : DHCPNameServer = 209.18.47.61 209.18.47.62 192.168.33.1
TCP: Interfaces\{8F423660-B973-4BA7-B1E9-34FAABD6A777} : DHCPNameServer = 192.168.2.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
x64-BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - <orphaned>
x64-BHO: KeyScramblerBHO Class: {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\x64\KeyScramblerIE.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} -
x64-BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - <orphaned>
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
x64-Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - C:\Program Files (x86)\KeyScrambler\x64\KeyScramblerIE.dll
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
Hosts: 127.0.0.1 ads.mcafee.com
Hosts: 127.0.0.1 analytics.microsoft.com
Hosts: 127.0.0.1 metrics.bitdefender.com
Hosts: 127.0.0.1 metrics.mcafee.com
Hosts: 127.0.0.1 om.symantec.com
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=SO3TDF&PC=SUN3&q=
FF - prefs.js: browser.search.selectedEngine - Ixquick
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=SO3TDF&PC=SUN3&q=
FF - prefs.js: network.proxy.type - 0
FF - component: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\extensions\keyscrambler@qfx.software.corporation\components\KeyScramblerIE.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Common Files\Motive\npMotiveRequest.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}\plugins\npietab2.dll
FF - plugin: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: !HIDDEN! 2010-06-30 19:17; smartwebprinting@hp.com; C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
============= SERVICES / DRIVERS ===============
.
R0 pavboot;pavboot;C:\Windows\System32\drivers\pavboot64.sys [2011-4-18 33800]
R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\System32\drivers\mwlPSDFilter.sys [2009-6-2 22576]
R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\System32\drivers\mwlPSDNserv.sys [2009-6-2 20016]
R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\System32\drivers\mwlPSDVDisk.sys [2009-6-2 60464]
R2 eamonm;eamonm;C:\Windows\System32\drivers\eamonm.sys [2010-12-21 170640]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2011-1-12 810144]
R2 epfwwfp;epfwwfp;C:\Windows\System32\drivers\epfwwfp.sys [2010-12-21 50624]
R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2010-2-7 844320]
R2 Greg_Service;GRegService;C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-8-28 1150496]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-11-7 399432]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2010-4-24 676936]
R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-9-24 62720]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-6-17 144640]
R2 pcCMService;pcCMService;C:\Program Files (x86)\Common Files\Motive\pcCMService.exe [2012-8-13 361472]
R2 pcCMService64;pcCMService64;C:\Program Files\Common Files\Motive\pcCMService.exe [2012-8-13 441344]
R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-11-4 2320920]
R2 Updater Service;Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-11-4 240160]
R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2009-11-4 56344]
R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-2-7 151936]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-2-7 244736]
R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2009-8-6 320040]
R3 KeyScrambler;KeyScrambler;C:\Windows\System32\drivers\keyscrambler.sys [2010-4-24 222904]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2010-4-24 25928]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AmUStor;AM USB Stroage Driver;C:\Windows\System32\drivers\AmUStor.sys [2009-7-22 40448]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-2-28 183560]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2010-10-20 48488]
S3 MWLService;MyWinLocker Service;C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe [2009-9-11 305448]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-6-17 50432]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-30 19456]
S3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;C:\Windows\System32\drivers\RTL8187.sys [2010-1-7 448512]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-30 57856]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-4-23 1255736]
S4 PuranDefrag;PuranDefrag;C:\Windows\System32\PuranDefragS.exe [2011-6-21 290816]
.
=============== Created Last 30 ================
.
2012-12-01 00:25:30 73696 ----a-w- C:\Program Files (x86)\Mozilla Firefox\breakpadinjector.dll
2012-12-01 00:25:28 770384 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcr100.dll
2012-12-01 00:25:28 421200 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcp100.dll
2012-12-01 00:25:25 96224 ----a-w- C:\Program Files (x86)\Mozilla Firefox\webapprt-stub.exe
2012-12-01 00:25:25 157272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\webapp-uninstaller.exe
2012-12-01 00:10:33 73656 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-01 00:10:33 697272 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-11-30 21:42:17 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-11-30 21:42:17 247808 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-11-30 21:42:16 458712 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-11-30 21:42:16 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-11-30 21:42:16 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-11-30 21:42:16 154480 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-11-30 21:42:16 1448448 ----a-w- C:\Windows\System32\lsasrv.dll
2012-11-30 21:42:15 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-11-30 21:42:15 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-11-30 21:41:21 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2012-11-30 21:41:21 366592 ----a-w- C:\Windows\System32\qdvd.dll
2012-11-15 23:07:27 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2012-11-15 23:07:26 9728 ----a-w- C:\Windows\System32\Wdfres.dll
2012-11-15 23:07:26 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys
2012-11-15 23:07:26 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys
2012-11-15 22:49:00 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2012-11-15 22:48:59 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2012-11-15 22:48:56 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2012-11-15 22:48:56 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2012-11-15 22:48:54 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2012-11-15 22:48:54 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2012-11-15 22:48:54 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2012-11-14 19:52:22 -------- d-----w- C:\Windows\System32\drivers\NISx64\1309000.009
2012-11-14 17:56:41 95744 ----a-w- C:\Windows\System32\synceng.dll
2012-11-14 17:56:40 78336 ----a-w- C:\Windows\SysWow64\synceng.dll
2012-11-13 17:58:59 -------- d-----w- C:\Program Files\Common Files\Symantec Shared
2012-11-13 17:58:09 -------- d-----w- C:\Windows\System32\drivers\NISx64
2012-11-13 17:57:59 -------- d-----w- C:\ProgramData\Norton
2012-11-13 17:57:15 -------- d-----w- C:\ProgramData\NortonInstaller
2012-11-07 15:51:34 95208 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-07 15:34:11 -------- d-----w- C:\Program Files (x86)\Magical Jelly Bean
.
==================== Find3M ====================
.
2012-11-07 15:51:25 821736 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-11-07 15:51:25 746984 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-10-25 08:12:26 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2012-10-25 08:12:26 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
2012-10-18 18:25:58 3149824 ----a-w- C:\Windows\System32\win32k.sys
2012-10-16 08:38:37 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38:34 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39:52 561664 ----a-w- C:\Windows\apppatch\AcLayers.dll
2012-10-09 18:17:13 55296 ----a-w- C:\Windows\System32\dhcpcsvc6.dll
2012-10-09 18:17:13 226816 ----a-w- C:\Windows\System32\dhcpcore6.dll
2012-10-09 17:40:31 44032 ----a-w- C:\Windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40:31 193536 ----a-w- C:\Windows\SysWow64\dhcpcore6.dll
2012-10-08 11:31:03 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2012-10-08 11:23:52 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-10-08 11:22:55 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-10-08 11:18:22 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-10-08 11:17:35 599040 ----a-w- C:\Windows\System32\vbscript.dll
2012-10-08 11:13:33 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-10-08 07:56:24 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-10-08 07:48:03 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-10-08 07:47:44 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-10-08 07:44:05 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-10-08 07:43:21 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2012-10-08 07:40:56 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-10-03 17:56:54 1914248 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-10-03 17:44:21 70656 ----a-w- C:\Windows\System32\nlaapi.dll
2012-10-03 17:44:21 303104 ----a-w- C:\Windows\System32\nlasvc.dll
2012-10-03 17:44:17 246272 ----a-w- C:\Windows\System32\netcorehc.dll
2012-10-03 17:44:17 18944 ----a-w- C:\Windows\System32\netevent.dll
2012-10-03 17:44:16 216576 ----a-w- C:\Windows\System32\ncsi.dll
2012-10-03 17:42:16 569344 ----a-w- C:\Windows\System32\iphlpsvc.dll
2012-10-03 16:42:24 18944 ----a-w- C:\Windows\SysWow64\netevent.dll
2012-10-03 16:42:24 175104 ----a-w- C:\Windows\SysWow64\netcorehc.dll
2012-10-03 16:42:23 156672 ----a-w- C:\Windows\SysWow64\ncsi.dll
2012-10-03 16:07:26 45568 ----a-w- C:\Windows\System32\drivers\tcpipreg.sys
2012-09-30 00:54:26 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-09-14 19:19:29 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-09-14 18:28:53 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2007-01-25 07:52:26 65536 ----a-w- C:\Program Files (x86)\Common Files\NMSAccessU.exe
.
============= FINISH: 12:34:22.63 ===============

Results of screen317's Security Check version 0.99.56
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
ESET Smart Security 4.2
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
MVPS Hosts File
SpywareBlaster 4.6
HOSTS Secure 1.0
Malwarebytes Anti-Malware version 1.65.1.1000
JavaFX 2.1.0
Java 7 Update 9
Adobe Reader 10.1.4 Adobe Reader out of Date!
Mozilla Firefox (17.0.1)
````````Process Check: objlist.exe by Laurent````````
ESET NOD32 Antivirus egui.exe
ESET NOD32 Antivirus ekrn.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````
Regards,
MoJo

They said the baby looked like me. Then they turned her rightside up.

#2 cnm

cnm

    Mother Lion of SWI

  • Administrators
  • PipPipPipPipPip
  • 25,254 posts

Posted 02 December 2012 - 03:49 PM

Hello MoJo Risin'.

Please make sure that IE has Flash Player installed and enabled.
Please open IE, then do Tools > Manage Add-ons.
You should see the Shockwave Flash Object from Adobe and its status should be Enabled.

Since Norton remnants could be involved,
Please download SystemLook_x64 from one of the links below and save it to your Desktop on the affected PC.
http://jpshortstuff....temLook_x64.exe
http://images.malwar...temLook_x64.exe
Double-click SystemLook_x64.exe to run it.
Copy the content of the following codebox into the main textfield:
:filefind
*Norton*
:regfind
Norton
Symantec
Click the 'Look' button to start the scan and wait for a few minutes until the "Look" button reappears.
When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Microsoft MVP Windows Security 2005-2006
How camest thou in this pickle? -- William Shakespeare:(1564-1616)
The various helper groups here
UNITE


#3 MoJo Risin&039;

MoJo Risin&039;

    Member

  • Full Member
  • Pip
  • 66 posts

Posted 03 December 2012 - 07:27 AM

Greetings Mother Lion. Thank you for your quick and helpful reply.
Both IE 32 bit & 64 bit had the Shockwave Flash Object Add-on enabled. I executed the SystemLook_x64 tool as instructed. The results of its search are posted below.
Many thanks again.
Regards – Mojo

SystemLook 30.07.11 by jpshortstuff
Log created at 07:04 on 03/12/2012 by John
Administrator - Elevation successful

========== filefind ==========

Searching for "*Norton*"
C:\Al's Use Only\John's Acer\Run First\Norton_Removal_Tool_ 2003+Later .exe --a---- 854064 bytes [19:05 24/04/2010] [13:56 24/04/2010] A84BD7E74994C3DBE698440C9E417918
C:\oem\Preload\Autorun\APP\NortonBK\NortonBK_12036v2.cfg --a---- 3503 bytes [05:18 12/11/2009] [05:18 12/11/2009] 46E5FED1753DBFCD84D890C1ECC0777D
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_BrazPortuguese_128x128.png --a---- 15045 bytes [07:04 11/08/2009] [07:04 11/08/2009] 36AB31B4E2A1C2AB2452054A2B3675E1
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_Czech_128x128.png --a---- 14958 bytes [07:04 11/08/2009] [07:04 11/08/2009] C1B8B37A47D769E390FABA6B8F1CAD07
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_Danish_128x128.png --a---- 15167 bytes [07:04 11/08/2009] [07:04 11/08/2009] 573736A08AFEAD01A2516B212E66D802
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_Dutch_128x128.png --a---- 15566 bytes [07:04 11/08/2009] [07:04 11/08/2009] 0F3E86073B31F7BA9098CCD5C541A7F0
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_Engl_128x128.png --a---- 15167 bytes [07:04 11/08/2009] [07:04 11/08/2009] 573736A08AFEAD01A2516B212E66D802
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_Finn_128x128.png --a---- 15167 bytes [07:04 11/08/2009] [07:04 11/08/2009] 573736A08AFEAD01A2516B212E66D802
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_French_128x128.png --a---- 15338 bytes [07:04 11/08/2009] [07:04 11/08/2009] 35F621B94737C27787933189443EFD4F
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_German_128x128.png --a---- 15376 bytes [07:04 11/08/2009] [07:04 11/08/2009] FC53285C8DE66BA3A7CE949D97019647
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_Hungarian_128x128.png --a---- 15195 bytes [07:04 11/08/2009] [07:04 11/08/2009] FDAD2BF6DAA7F4FCC34EAB3C30568E9D
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_IberianPort_128x128.png --a---- 15688 bytes [07:04 11/08/2009] [07:04 11/08/2009] 45A658B21580CF44A03763360A365D49
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_Italian_128x128.png --a---- 14771 bytes [07:04 11/08/2009] [07:04 11/08/2009] EB997D71B562AB20850B6F7EDF777FE1
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_Japanese_128x128.png --a---- 15167 bytes [07:04 11/08/2009] [07:04 11/08/2009] 573736A08AFEAD01A2516B212E66D802
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_Korean_128x128.png --a---- 15352 bytes [07:04 11/08/2009] [07:04 11/08/2009] 3A7E8DF09CF9AF53A9454EE180D716FF
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_Norw_128x128.png --a---- 15167 bytes [07:04 11/08/2009] [07:04 11/08/2009] 573736A08AFEAD01A2516B212E66D802
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_Polish_128x128.png --a---- 14589 bytes [07:04 11/08/2009] [07:04 11/08/2009] 2022236EA67FA6AD5E7049357DAA92A8
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_Russian_128x128.png --a---- 16338 bytes [07:04 11/08/2009] [07:04 11/08/2009] A19C34E462D662CAB0F8A9FC07A84C7F
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_SimpChi_128x128.png --a---- 15368 bytes [07:04 11/08/2009] [07:04 11/08/2009] 2B3C4434D030746B8E2359CF19564516
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_SpaLatin_128x128.png --a---- 15860 bytes [07:04 11/08/2009] [07:04 11/08/2009] C4109797279187702B8DA2F1D1EEF607
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_Swedish_128x128.png --a---- 15167 bytes [07:04 11/08/2009] [07:04 11/08/2009] 573736A08AFEAD01A2516B212E66D802
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_TraChi_128x128.png --a---- 15397 bytes [07:04 11/08/2009] [07:04 11/08/2009] D15BEE4F8A63B632426DFF76A147EC12
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\Norton_Turkish_128x128.png --a---- 14858 bytes [07:04 11/08/2009] [07:04 11/08/2009] B2DFB7D43577C2D42142DB1BEC0A17DB
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_BrazPortuguese_128x128.png --a---- 24321 bytes [07:18 11/08/2009] [07:18 11/08/2009] C3E32C2CA03E3BACF161BD9A7C95E74F
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_Czech_128x128.png --a---- 23599 bytes [07:18 11/08/2009] [07:18 11/08/2009] 381A0DAB1913B0CA1E066A9296AA56D4
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_Danish_128x128.png --a---- 24270 bytes [07:18 11/08/2009] [07:18 11/08/2009] 25C11D2F0F756C3659D49416A00577F6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_Dutch_128x128.png --a---- 24885 bytes [07:18 11/08/2009] [07:18 11/08/2009] 3209D93A7EBB191743BF7670FCD1833A
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_Engl_128x128.png --a---- 24270 bytes [07:18 11/08/2009] [07:18 11/08/2009] 25C11D2F0F756C3659D49416A00577F6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_Finn_128x128.png --a---- 24270 bytes [07:18 11/08/2009] [07:18 11/08/2009] 25C11D2F0F756C3659D49416A00577F6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_French_128x128.png --a---- 24380 bytes [07:18 11/08/2009] [07:18 11/08/2009] 12DC7390E44EF35E7D8438E2486F4946
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_German_128x128.png --a---- 24547 bytes [07:18 11/08/2009] [07:18 11/08/2009] 6DEA0B013CC62BAE1796F35250D80828
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_Hungarian_128x128.png --a---- 23931 bytes [07:18 11/08/2009] [07:18 11/08/2009] 080AC8BC9C4CA6F35426A012C83F3CF8
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_IberianPort_128x128.png --a---- 24731 bytes [07:18 11/08/2009] [07:18 11/08/2009] AE4201DABF0CF72028DA245F9A068247
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_Italian_128x128.png --a---- 23788 bytes [07:18 11/08/2009] [07:18 11/08/2009] AE5A4E9A875E6E63DB154F71F799BD63
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_Japanese_128x128.png --a---- 24270 bytes [07:18 11/08/2009] [07:18 11/08/2009] 25C11D2F0F756C3659D49416A00577F6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_Korean_128x128.png --a---- 24842 bytes [07:18 11/08/2009] [07:18 11/08/2009] 85949198C395220077AA57A0E54DFC0A
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_Norw_128x128.png --a---- 24270 bytes [07:18 11/08/2009] [07:18 11/08/2009] 25C11D2F0F756C3659D49416A00577F6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_Polish_128x128.png --a---- 23495 bytes [07:18 11/08/2009] [07:18 11/08/2009] 7EB229D6780855D0BDAA9C58F07BF17F
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_Russian_128x128.png --a---- 26178 bytes [07:18 11/08/2009] [07:18 11/08/2009] F276A181D2718B3FC5EE77F34E7086CC
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_SimpChi_128x128.png --a---- 23876 bytes [07:18 11/08/2009] [07:18 11/08/2009] 87117D524BC6E3A1AA27495D8F8C776F
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_SpaLatin_128x128.png --a---- 25336 bytes [07:18 11/08/2009] [07:18 11/08/2009] 12D4B7489EB977D6ED524BC8BFBC5D60
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_Swedish_128x128.png --a---- 24270 bytes [07:18 11/08/2009] [07:18 11/08/2009] 25C11D2F0F756C3659D49416A00577F6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_TraChi_128x128.png --a---- 23958 bytes [07:18 11/08/2009] [07:18 11/08/2009] 6FAB6F9B5A4DD8AEFFC564D3E1F37C85
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120\Norton_Turkish_128x128.png --a---- 23918 bytes [07:18 11/08/2009] [07:18 11/08/2009] B928B68A5B6284A66E4DB1670A2421ED
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_BrazPortuguese_128x128.png --a---- 32271 bytes [07:18 11/08/2009] [07:18 11/08/2009] 452B911996703998063640BC2016DE17
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_Czech_128x128.png --a---- 31243 bytes [07:18 11/08/2009] [07:18 11/08/2009] 374883442A98D13C77073358E686EA83
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_Danish_128x128.png --a---- 32351 bytes [07:18 11/08/2009] [07:18 11/08/2009] 82D3F8E5B8C2F48B69A0774D97020F00
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_Dutch_128x128.png --a---- 33178 bytes [07:18 11/08/2009] [07:18 11/08/2009] 1637E2D1E5517B661F684C5A4251F6A1
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_Engl_128x128.png --a---- 32351 bytes [07:18 11/08/2009] [07:18 11/08/2009] 82D3F8E5B8C2F48B69A0774D97020F00
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_Finn_128x128.png --a---- 32351 bytes [07:18 11/08/2009] [07:18 11/08/2009] 82D3F8E5B8C2F48B69A0774D97020F00
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_French_128x128.png --a---- 32527 bytes [07:18 11/08/2009] [07:18 11/08/2009] 27700CE0F533128125347E187609D156
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_German_128x128.png --a---- 32556 bytes [07:18 11/08/2009] [07:18 11/08/2009] F2B60DEBE489EA486F4C6E0CD1013048
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_Hungarian_128x128.png --a---- 31699 bytes [07:18 11/08/2009] [07:18 11/08/2009] C3E7EEA3EBDB3B85E0BAE1098F943237
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_IberianPort_128x128.png --a---- 32949 bytes [07:18 11/08/2009] [07:18 11/08/2009] 8B5B647EE519EFA1EA2B3589D48E3A9A
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_Italian_128x128.png --a---- 31816 bytes [07:18 11/08/2009] [07:18 11/08/2009] F6ED784C9C94CCE05D4BCA01A005F53A
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_Japanese_128x128.png --a---- 32351 bytes [07:18 11/08/2009] [07:18 11/08/2009] 82D3F8E5B8C2F48B69A0774D97020F00
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_Korean_128x128.png --a---- 32851 bytes [07:18 11/08/2009] [07:18 11/08/2009] 957A2F7371F7EC1752D7C8827CFA8DE1
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_Norw_128x128.png --a---- 32351 bytes [07:18 11/08/2009] [07:18 11/08/2009] 82D3F8E5B8C2F48B69A0774D97020F00
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_Polish_128x128.png --a---- 31016 bytes [07:18 11/08/2009] [07:18 11/08/2009] 9AE2F886A2FBCE001E28300AE5BA8CA5
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_Russian_128x128.png --a---- 35093 bytes [07:18 11/08/2009] [07:18 11/08/2009] B5CDF48F351BCE4CA35F8C51EF42DEDB
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_SimpChi_128x128.png --a---- 31699 bytes [07:18 11/08/2009] [07:18 11/08/2009] DE64F13D92613BCA0BB92794E03F677C
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_SpaLatin_128x128.png --a---- 33509 bytes [07:18 11/08/2009] [07:18 11/08/2009] 95290079C09B4C246239491BD7A70E33
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_Swedish_128x128.png --a---- 34101 bytes [04:05 02/10/2009] [04:05 02/10/2009] E6BDDB47EE8FD290DC6D58FC933CB088
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_TraChi_128x128.png --a---- 31795 bytes [07:18 11/08/2009] [07:18 11/08/2009] FC75337FDCEC007C84A8A4A02DEE4673
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144\Norton_Turkish_128x128.png --a---- 31710 bytes [07:18 11/08/2009] [07:18 11/08/2009] C1AA834A652660198D2B37BD62FF336E
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_BrazPortuguese_128x128.png --a---- 14556 bytes [07:18 11/08/2009] [07:18 11/08/2009] 099CBD895DDCD9FB5718F13411A2393C
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_Czech_128x128.png --a---- 14454 bytes [07:18 11/08/2009] [07:18 11/08/2009] 75D9AA89C69465112D3C0C686CDF35B6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_Danish_128x128.png --a---- 14604 bytes [07:18 11/08/2009] [07:18 11/08/2009] C6634FA085C262FB90AD28CF8716F8B3
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_Dutch_128x128.png --a---- 14974 bytes [07:18 11/08/2009] [07:18 11/08/2009] 672E2ACE255AA2D2A1C9A79C27E531E8
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_Engl_128x128.png --a---- 14604 bytes [07:18 11/08/2009] [07:18 11/08/2009] C6634FA085C262FB90AD28CF8716F8B3
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_Finn_128x128.png --a---- 14604 bytes [07:18 11/08/2009] [07:18 11/08/2009] C6634FA085C262FB90AD28CF8716F8B3
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_French_128x128.png --a---- 14753 bytes [07:18 11/08/2009] [07:18 11/08/2009] F01BF004A343796772EE162AC1A0E230
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_German_128x128.png --a---- 14928 bytes [07:18 11/08/2009] [07:18 11/08/2009] 444C9BE64075F1D2AD19B280091F823D
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_Hungarian_128x128.png --a---- 14547 bytes [07:18 11/08/2009] [07:18 11/08/2009] ABAE0A1244A67C4F3031584CC02627EE
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_IberianPort_128x128.png --a---- 14957 bytes [07:18 11/08/2009] [07:18 11/08/2009] 202C38B132D33CEFD135661E03307F9D
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_Italian_128x128.png --a---- 14244 bytes [07:18 11/08/2009] [07:18 11/08/2009] E8C36EF7A6B41F0F167EF1C28986B6E7
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_Japanese_128x128.png --a---- 14604 bytes [07:18 11/08/2009] [07:18 11/08/2009] C6634FA085C262FB90AD28CF8716F8B3
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_Korean_128x128.png --a---- 14978 bytes [07:18 11/08/2009] [07:18 11/08/2009] 4B168509DB5B5AFF08F75F5C89B63941
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_Norw_128x128.png --a---- 14604 bytes [07:18 11/08/2009] [07:18 11/08/2009] C6634FA085C262FB90AD28CF8716F8B3
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_Polish_128x128.png --a---- 14196 bytes [07:18 11/08/2009] [07:18 11/08/2009] 2C02B6B72228251F484137FA340394D1
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_Russian_128x128.png --a---- 15732 bytes [07:18 11/08/2009] [07:18 11/08/2009] BD8ABDA6B8D597C8DB036C2FA8972A30
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_SimpChi_128x128.png --a---- 14651 bytes [07:18 11/08/2009] [07:18 11/08/2009] 5B938FEABCE062758088F90505C95D3F
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_SpaLatin_128x128.png --a---- 15131 bytes [07:18 11/08/2009] [07:18 11/08/2009] BB8861B15F1ACFBC4F9EF353C72D42D6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_Swedish_128x128.png --a---- 14604 bytes [07:18 11/08/2009] [07:18 11/08/2009] C6634FA085C262FB90AD28CF8716F8B3
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_TraChi_128x128.png --a---- 14894 bytes [07:18 11/08/2009] [07:18 11/08/2009] 4E28A030031928C8653E28C4B7243D9B
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96\Norton_Turkish_128x128.png --a---- 14487 bytes [07:18 11/08/2009] [07:18 11/08/2009] A4325D514B1A6E887776D4E13E7802E9
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_BrazPortuguese_128x128.png --a---- 24321 bytes [07:18 11/08/2009] [07:18 11/08/2009] C3E32C2CA03E3BACF161BD9A7C95E74F
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_Czech_128x128.png --a---- 23599 bytes [07:18 11/08/2009] [07:18 11/08/2009] 381A0DAB1913B0CA1E066A9296AA56D4
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_Danish_128x128.png --a---- 24270 bytes [07:18 11/08/2009] [07:18 11/08/2009] 25C11D2F0F756C3659D49416A00577F6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_Dutch_128x128.png --a---- 24885 bytes [07:18 11/08/2009] [07:18 11/08/2009] 3209D93A7EBB191743BF7670FCD1833A
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_Engl_128x128.png --a---- 24270 bytes [07:18 11/08/2009] [07:18 11/08/2009] 25C11D2F0F756C3659D49416A00577F6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_Finn_128x128.png --a---- 24270 bytes [07:18 11/08/2009] [07:18 11/08/2009] 25C11D2F0F756C3659D49416A00577F6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_French_128x128.png --a---- 24380 bytes [07:18 11/08/2009] [07:18 11/08/2009] 12DC7390E44EF35E7D8438E2486F4946
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_German_128x128.png --a---- 24547 bytes [07:18 11/08/2009] [07:18 11/08/2009] 6DEA0B013CC62BAE1796F35250D80828
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_Hungarian_128x128.png --a---- 23931 bytes [07:18 11/08/2009] [07:18 11/08/2009] 080AC8BC9C4CA6F35426A012C83F3CF8
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_IberianPort_128x128.png --a---- 24731 bytes [07:18 11/08/2009] [07:18 11/08/2009] AE4201DABF0CF72028DA245F9A068247
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_Italian_128x128.png --a---- 23788 bytes [07:18 11/08/2009] [07:18 11/08/2009] AE5A4E9A875E6E63DB154F71F799BD63
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_Japanese_128x128.png --a---- 24270 bytes [07:18 11/08/2009] [07:18 11/08/2009] 25C11D2F0F756C3659D49416A00577F6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_Korean_128x128.png --a---- 24842 bytes [07:18 11/08/2009] [07:18 11/08/2009] 85949198C395220077AA57A0E54DFC0A
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_Norw_128x128.png --a---- 24270 bytes [07:18 11/08/2009] [07:18 11/08/2009] 25C11D2F0F756C3659D49416A00577F6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_Polish_128x128.png --a---- 23495 bytes [07:18 11/08/2009] [07:18 11/08/2009] 7EB229D6780855D0BDAA9C58F07BF17F
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_Russian_128x128.png --a---- 26178 bytes [07:18 11/08/2009] [07:18 11/08/2009] F276A181D2718B3FC5EE77F34E7086CC
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_SimpChi_128x128.png --a---- 23876 bytes [07:18 11/08/2009] [07:18 11/08/2009] 87117D524BC6E3A1AA27495D8F8C776F
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_SpaLatin_128x128.png --a---- 25336 bytes [07:18 11/08/2009] [07:18 11/08/2009] 12D4B7489EB977D6ED524BC8BFBC5D60
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_Swedish_128x128.png --a---- 24270 bytes [07:18 11/08/2009] [07:18 11/08/2009] 25C11D2F0F756C3659D49416A00577F6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_TraChi_128x128.png --a---- 23958 bytes [07:18 11/08/2009] [07:18 11/08/2009] 6FAB6F9B5A4DD8AEFFC564D3E1F37C85
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120\Norton_Turkish_128x128.png --a---- 23918 bytes [07:18 11/08/2009] [07:18 11/08/2009] B928B68A5B6284A66E4DB1670A2421ED
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_BrazPortuguese_128x128.png --a---- 32271 bytes [07:18 11/08/2009] [07:18 11/08/2009] 452B911996703998063640BC2016DE17
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_Czech_128x128.png --a---- 31243 bytes [07:18 11/08/2009] [07:18 11/08/2009] 374883442A98D13C77073358E686EA83
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_Danish_128x128.png --a---- 32351 bytes [07:18 11/08/2009] [07:18 11/08/2009] 82D3F8E5B8C2F48B69A0774D97020F00
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_Dutch_128x128.png --a---- 33178 bytes [07:18 11/08/2009] [07:18 11/08/2009] 1637E2D1E5517B661F684C5A4251F6A1
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_Engl_128x128.png --a---- 32351 bytes [07:18 11/08/2009] [07:18 11/08/2009] 82D3F8E5B8C2F48B69A0774D97020F00
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_Finn_128x128.png --a---- 32351 bytes [07:18 11/08/2009] [07:18 11/08/2009] 82D3F8E5B8C2F48B69A0774D97020F00
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_French_128x128.png --a---- 32527 bytes [07:18 11/08/2009] [07:18 11/08/2009] 27700CE0F533128125347E187609D156
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_German_128x128.png --a---- 32556 bytes [07:18 11/08/2009] [07:18 11/08/2009] F2B60DEBE489EA486F4C6E0CD1013048
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_Hungarian_128x128.png --a---- 31699 bytes [07:18 11/08/2009] [07:18 11/08/2009] C3E7EEA3EBDB3B85E0BAE1098F943237
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_IberianPort_128x128.png --a---- 32949 bytes [07:18 11/08/2009] [07:18 11/08/2009] 8B5B647EE519EFA1EA2B3589D48E3A9A
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_Italian_128x128.png --a---- 31816 bytes [07:18 11/08/2009] [07:18 11/08/2009] F6ED784C9C94CCE05D4BCA01A005F53A
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_Japanese_128x128.png --a---- 32351 bytes [07:18 11/08/2009] [07:18 11/08/2009] 82D3F8E5B8C2F48B69A0774D97020F00
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_Korean_128x128.png --a---- 32851 bytes [07:18 11/08/2009] [07:18 11/08/2009] 957A2F7371F7EC1752D7C8827CFA8DE1
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_Norw_128x128.png --a---- 32351 bytes [07:18 11/08/2009] [07:18 11/08/2009] 82D3F8E5B8C2F48B69A0774D97020F00
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_Polish_128x128.png --a---- 31016 bytes [07:18 11/08/2009] [07:18 11/08/2009] 9AE2F886A2FBCE001E28300AE5BA8CA5
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_Russian_128x128.png --a---- 35093 bytes [07:18 11/08/2009] [07:18 11/08/2009] B5CDF48F351BCE4CA35F8C51EF42DEDB
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_SimpChi_128x128.png --a---- 31699 bytes [07:18 11/08/2009] [07:18 11/08/2009] DE64F13D92613BCA0BB92794E03F677C
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_SpaLatin_128x128.png --a---- 33509 bytes [07:18 11/08/2009] [07:18 11/08/2009] 95290079C09B4C246239491BD7A70E33
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_Swedish_128x128.png --a---- 34101 bytes [04:04 02/10/2009] [04:04 02/10/2009] E6BDDB47EE8FD290DC6D58FC933CB088
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_TraChi_128x128.png --a---- 31795 bytes [07:18 11/08/2009] [07:18 11/08/2009] FC75337FDCEC007C84A8A4A02DEE4673
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144\Norton_Turkish_128x128.png --a---- 31710 bytes [07:18 11/08/2009] [07:18 11/08/2009] C1AA834A652660198D2B37BD62FF336E
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_BrazPortuguese_128x128.png --a---- 14556 bytes [07:18 11/08/2009] [07:18 11/08/2009] 099CBD895DDCD9FB5718F13411A2393C
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_Czech_128x128.png --a---- 14454 bytes [07:18 11/08/2009] [07:18 11/08/2009] 75D9AA89C69465112D3C0C686CDF35B6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_Danish_128x128.png --a---- 14604 bytes [07:18 11/08/2009] [07:18 11/08/2009] C6634FA085C262FB90AD28CF8716F8B3
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_Dutch_128x128.png --a---- 14974 bytes [07:18 11/08/2009] [07:18 11/08/2009] 672E2ACE255AA2D2A1C9A79C27E531E8
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_Engl_128x128.png --a---- 14604 bytes [07:18 11/08/2009] [07:18 11/08/2009] C6634FA085C262FB90AD28CF8716F8B3
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_Finn_128x128.png --a---- 14604 bytes [07:18 11/08/2009] [07:18 11/08/2009] C6634FA085C262FB90AD28CF8716F8B3
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_French_128x128.png --a---- 14753 bytes [07:18 11/08/2009] [07:18 11/08/2009] F01BF004A343796772EE162AC1A0E230
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_German_128x128.png --a---- 14928 bytes [07:18 11/08/2009] [07:18 11/08/2009] 444C9BE64075F1D2AD19B280091F823D
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_Hungarian_128x128.png --a---- 14547 bytes [07:18 11/08/2009] [07:18 11/08/2009] ABAE0A1244A67C4F3031584CC02627EE
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_IberianPort_128x128.png --a---- 14957 bytes [07:18 11/08/2009] [07:18 11/08/2009] 202C38B132D33CEFD135661E03307F9D
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_Italian_128x128.png --a---- 14244 bytes [07:18 11/08/2009] [07:18 11/08/2009] E8C36EF7A6B41F0F167EF1C28986B6E7
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_Japanese_128x128.png --a---- 14604 bytes [07:18 11/08/2009] [07:18 11/08/2009] C6634FA085C262FB90AD28CF8716F8B3
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_Korean_128x128.png --a---- 14978 bytes [07:18 11/08/2009] [07:18 11/08/2009] 4B168509DB5B5AFF08F75F5C89B63941
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_Norw_128x128.png --a---- 14604 bytes [07:18 11/08/2009] [07:18 11/08/2009] C6634FA085C262FB90AD28CF8716F8B3
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_Polish_128x128.png --a---- 14196 bytes [07:18 11/08/2009] [07:18 11/08/2009] 2C02B6B72228251F484137FA340394D1
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_Russian_128x128.png --a---- 15732 bytes [07:18 11/08/2009] [07:18 11/08/2009] BD8ABDA6B8D597C8DB036C2FA8972A30
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_SimpChi_128x128.png --a---- 14651 bytes [07:18 11/08/2009] [07:18 11/08/2009] 5B938FEABCE062758088F90505C95D3F
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_SpaLatin_128x128.png --a---- 15131 bytes [07:18 11/08/2009] [07:18 11/08/2009] BB8861B15F1ACFBC4F9EF353C72D42D6
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_Swedish_128x128.png --a---- 14604 bytes [07:18 11/08/2009] [07:18 11/08/2009] C6634FA085C262FB90AD28CF8716F8B3
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_TraChi_128x128.png --a---- 14894 bytes [07:18 11/08/2009] [07:18 11/08/2009] 4E28A030031928C8653E28C4B7243D9B
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96\Norton_Turkish_128x128.png --a---- 14487 bytes [07:18 11/08/2009] [07:18 11/08/2009] A4325D514B1A6E887776D4E13E7802E9
C:\Users\John\Desktop\Norton_Removal_Tool.exe --a---- 866592 bytes [16:58 26/11/2012] [17:08 26/11/2012] 2908AF0DABE8D664A0F006B092EF993D
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Norton Removal Tool\Norton Removal Tool (SymNRT) 2008.0.3.16.exe --a---- 667648 bytes [17:55 24/06/2010] [19:04 30/04/2008] 689D88F884497683F52E1D31F7F6422D
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\AppData\Roaming\Microsoft\Office\Recent\Norton Removal Tool.LNK --a---- 429 bytes [17:40 24/06/2010] [18:47 30/04/2008] C0425864F7965111C3BC1B77190C18A6
C:\Users\John\Downloads\Norton_Removal_Tool.exe --a---- 866592 bytes [17:08 26/11/2012] [17:08 26/11/2012] 2908AF0DABE8D664A0F006B092EF993D
C:\Windows\System32\Tasks\Norton WSC Integration --a---- 3232 bytes [17:58 13/11/2012] [23:35 15/11/2012] 5EB6EC365A7E9B2F27B9CED0251DE415
C:\Windows\System32\Tasks\Norton Internet Security\Norton Error Analyzer --a---- 2998 bytes [23:40 15/11/2012] [23:40 15/11/2012] 211D287218A60B51375EDC0E1D36960C
C:\Windows\System32\Tasks\Norton Internet Security\Norton Error Processor --a---- 3712 bytes [23:40 15/11/2012] [23:40 15/11/2012] 373B0B0CD8F0F35A654E40A2D730863C

========== regfind ==========

Searching for "Norton"
[HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\AddIns\MsouPlug.OutlookPlug]
"FriendlyName"="Norton AntiSpam Outlook Plugin"
[HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\AddIns\MsouPlug.OutlookPlug]
"Description"="Norton AntiSpam Outlook Plugin"
[HKEY_CURRENT_USER\Software\Norton]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C038C017-8A01-4929-8639-52EBECB5F6B8}\InprocServer32]
@="C:\Program Files (x86)\Norton Internet Security\Engine64\19.9.0.9\NPCGadgt.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C038C017-8A01-4929-8639-52EBECB5F6B8}\ProgID]
@="Symantec.Norton.SystemStatus.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C038C017-8A01-4929-8639-52EBECB5F6B8}\VersionIndependentProgID]
@="Symantec.Norton.SystemStatus"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NortonAntiVirus.MediaStatusSink.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B04EE549-EDE9-497A-9B61-CA9B15EE9699}\1.0\0\win64]
@="C:\Program Files (x86)\Norton Internet Security\Engine64\19.9.0.9\NPCGadgt.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{B04EE549-EDE9-497A-9B61-CA9B15EE9699}\1.0\0\win64]
@="C:\Program Files (x86)\Norton Internet Security\Engine64\19.9.0.9\NPCGadgt.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\Compatibility\NortonSystemInfo]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08FF730A-494F-4cba-AA0B-E4F1D44715F9}]
"AppPath"="C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NortonOnlineBackupReminder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NortonOnlineBackupReminder]
"item"="NortonOnlineBackupReminder"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NortonOnlineBackupReminder]
"command"=""C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SMDEn]
"OEM4"="%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Norton Online Backup\Norton Online Backup.lnk"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant]
"ExecutablesToExclude"="c:\program files (x86)\nortoninstaller\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis\a5e82d02\19.9.0.9\inststub.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0DA5EF35-3961-4AA3-BAFF-71F431438340}]
"Path"="\Norton WSC Integration"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2BE4E5A8-290C-49D4-B97A-B5BE584B6EE4}]
"Path"="\Norton Internet Security\Norton Error Processor"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F6F0A3C0-BBEE-42B5-9D83-2472F312DC6E}]
"Path"="\Norton Internet Security\Norton Error Analyzer"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Internet Security]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Internet Security\Norton Error Analyzer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Internet Security\Norton Error Processor]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton WSC Integration]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DirectDraw\Compatibility\NortonSystemInfo]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08FF730A-494F-4cba-AA0B-E4F1D44715F9}]
"AppPath"="C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{B04EE549-EDE9-497A-9B61-CA9B15EE9699}\1.0\0\win64]
@="C:\Program Files (x86)\Norton Internet Security\Engine64\19.9.0.9\NPCGadgt.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CCSET_NIS\0000]
"DeviceDesc"="Norton Internet Security Settings Manager"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\NIS]
"EventMessageFile"="C:\Program Files (x86)\Norton Internet Security\MUI\19.9.0.9\09\01\rcSvcHst.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{6D739258-15AE-42C6-865E-F5F143C6C94E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Users\John\AppData\Local\Temp\7zSB61.tmp\SymNRT.exe|Name=Norton Removal Tool|"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{CF1D6759-CE7D-4452-9AB0-9237EFAD668E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Users\John\AppData\Local\Temp\7zSB61.tmp\SymNRT.exe|Name=Norton Removal Tool|"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CCSET_NIS\0000]
"DeviceDesc"="Norton Internet Security Settings Manager"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\eventlog\Application\NIS]
"EventMessageFile"="C:\Program Files (x86)\Norton Internet Security\MUI\19.9.0.9\09\01\rcSvcHst.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{6D739258-15AE-42C6-865E-F5F143C6C94E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Users\John\AppData\Local\Temp\7zSB61.tmp\SymNRT.exe|Name=Norton Removal Tool|"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{CF1D6759-CE7D-4452-9AB0-9237EFAD668E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Users\John\AppData\Local\Temp\7zSB61.tmp\SymNRT.exe|Name=Norton Removal Tool|"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CCSET_NIS\0000]
"DeviceDesc"="Norton Internet Security Settings Manager"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\NIS]
"EventMessageFile"="C:\Program Files (x86)\Norton Internet Security\MUI\19.9.0.9\09\01\rcSvcHst.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{6D739258-15AE-42C6-865E-F5F143C6C94E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Users\John\AppData\Local\Temp\7zSB61.tmp\SymNRT.exe|Name=Norton Removal Tool|"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{CF1D6759-CE7D-4452-9AB0-9237EFAD668E}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Users\John\AppData\Local\Temp\7zSB61.tmp\SymNRT.exe|Name=Norton Removal Tool|"
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\ShellNoRoam\MuiCache]
"C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe"="Norton Internet Security"
[HKEY_USERS\.DEFAULT\Software\Norton]
[HKEY_USERS\S-1-5-21-2497620218-1680459894-400693757-1001\Software\Microsoft\Office\Outlook\AddIns\MsouPlug.OutlookPlug]
"FriendlyName"="Norton AntiSpam Outlook Plugin"
[HKEY_USERS\S-1-5-21-2497620218-1680459894-400693757-1001\Software\Microsoft\Office\Outlook\AddIns\MsouPlug.OutlookPlug]
"Description"="Norton AntiSpam Outlook Plugin"
[HKEY_USERS\S-1-5-21-2497620218-1680459894-400693757-1001\Software\Norton]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\ShellNoRoam\MuiCache]
"C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe"="Norton Internet Security"
[HKEY_USERS\S-1-5-18\Software\Norton]

Searching for "Symantec"
[HKEY_CURRENT_USER\Software\Symantec]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C038C017-8A01-4929-8639-52EBECB5F6B8}\ProgID]
@="Symantec.Norton.SystemStatus.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C038C017-8A01-4929-8639-52EBECB5F6B8}\VersionIndependentProgID]
@="Symantec.Norton.SystemStatus"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NortonOnlineBackupReminder]
"command"=""C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED"
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Symantec]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_EECTRL\0000]
"DeviceDesc"="Symantec Eraser Control driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SRTSP\0000]
"DeviceDesc"="Symantec Real Time Storage Protection x64"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SRTSPX\0000]
"DeviceDesc"="Symantec Real Time Storage Protection (PEL) x64"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SYMDS\0000]
"DeviceDesc"="Symantec Data Store"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SYMEFA\0000]
"DeviceDesc"="Symantec Extended File Attributes"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SYMIRON\0000]
"DeviceDesc"="Symantec Iron Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SYMNETS\0000]
"DeviceDesc"="Symantec Network Security WFP Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_EECTRL\0000]
"DeviceDesc"="Symantec Eraser Control driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SRTSP\0000]
"DeviceDesc"="Symantec Real Time Storage Protection x64"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SRTSPX\0000]
"DeviceDesc"="Symantec Real Time Storage Protection (PEL) x64"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SYMDS\0000]
"DeviceDesc"="Symantec Data Store"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SYMEFA\0000]
"DeviceDesc"="Symantec Extended File Attributes"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SYMIRON\0000]
"DeviceDesc"="Symantec Iron Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SYMNETS\0000]
"DeviceDesc"="Symantec Network Security WFP Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_EECTRL\0000]
"DeviceDesc"="Symantec Eraser Control driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SRTSP\0000]
"DeviceDesc"="Symantec Real Time Storage Protection x64"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SRTSPX\0000]
"DeviceDesc"="Symantec Real Time Storage Protection (PEL) x64"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMDS\0000]
"DeviceDesc"="Symantec Data Store"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMEFA\0000]
"DeviceDesc"="Symantec Extended File Attributes"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMIRON\0000]
"DeviceDesc"="Symantec Iron Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMNETS\0000]
"DeviceDesc"="Symantec Network Security WFP Driver"
[HKEY_USERS\S-1-5-21-2497620218-1680459894-400693757-1001\Software\Symantec]

-= EOF =-
Regards,
MoJo

They said the baby looked like me. Then they turned her rightside up.

#4 cnm

cnm

    Mother Lion of SWI

  • Administrators
  • PipPipPipPipPip
  • 25,254 posts

Posted 03 December 2012 - 05:44 PM

It seems Norton's removal tool wasn't very thorough.

I hope OTL will see most of that.
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy the contents of these files, one at a time, and post with your next two replies.

Microsoft MVP Windows Security 2005-2006
How camest thou in this pickle? -- William Shakespeare:(1564-1616)
The various helper groups here
UNITE


#5 MoJo Risin&039;

MoJo Risin&039;

    Member

  • Full Member
  • Pip
  • 66 posts

Posted 03 December 2012 - 06:57 PM

It seems Norton's removal tool wasn't very thorough.

I hope OTL will see most of that.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy the contents of these files, one at a time, and post with your next two replies.


Hello again cnm.
To say Norton's Removal Tool wasn't very thorough is an understatement. It was pathetic and practically useless. For the record, I am taking note of all your advice and direction and filing it away for future reference. I'm sure I'll encounter a similar situation sometime in the future.

I ran the OLT Log Analyzer as directed. This first reply post contains the contents of OLT.txt, which I copied below:
OTL logfile created on: 12/3/2012 6:03:56 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\John\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.68 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 53.04% Memory free
7.35 Gb Paging File | 5.72 Gb Available in Paging File | 77.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.30 Gb Total Space | 223.55 Gb Free Space | 78.36% Space Free | Partition Type: NTFS
Drive E: | 14.91 Gb Total Space | 7.35 Gb Free Space | 49.28% Space Free | Partition Type: FAT32

Computer Name: JOHN-ACER | User Name: John | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\John\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\Motive\pcCMService.exe (Alcatel-Lucent)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (ESET)
PRC - C:\Program Files (x86)\SpeedFan\speedfan.exe (Almico Software (www.almico.com))
PRC - C:\Program Files (x86)\StudioLine Photo Basic\NMSAccess32.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\D-Link\D-Link RangeBooster N DWA-140\AirNCFG.exe (D-Link)
PRC - C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Wireless Service)


========== Modules (No Company Name) ==========

MOD - C:\Users\John\AppData\Local\Temp\sfamcc00001.dll ()
MOD - C:\Users\John\AppData\Local\Temp\sfareca00001.dll ()
MOD - C:\Windows\SysWOW64\WlanApp.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (pcCMService64) -- C:\Program Files\Common Files\Motive\pcCMService.exe (Alcatel-Lucent)
SRV:64bit: - (PuranDefrag) -- C:\Windows\SysNative\PuranDefragS.exe (Puran Software)
SRV:64bit: - (EhttpSrv) -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe (ESET)
SRV:64bit: - (ekrn) -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (ESET)
SRV:64bit: - (ePowerSvc) -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Updater Service) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
SRV:64bit: - (AgereModemAudio) -- C:\Program Files\LSI SoftModem\agr64svc.exe (LSI Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (pcCMService) -- C:\Program Files (x86)\Common Files\Motive\pcCMService.exe (Alcatel-Lucent)
SRV - (BBSvc) -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (HPSLPSVC) -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (NMSAccess) -- C:\Program Files (x86)\StudioLine Photo Basic\NMSAccess32.exe ()
SRV - (GameConsoleService) -- C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (NTI IScheduleSvc) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (MWLService) -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe ()
SRV - (Greg_Service) -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (NMSAccessU) -- C:\Program Files (x86)\Common Files\NMSAccessU.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (KeyScrambler) -- C:\Windows\SysNative\drivers\keyscrambler.sys (QFX Software Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (eamonm) -- C:\Windows\SysNative\drivers\eamonm.sys (ESET)
DRV:64bit: - (ehdrv) -- C:\Windows\SysNative\drivers\ehdrv.sys (ESET)
DRV:64bit: - (epfw) -- C:\Windows\SysNative\drivers\epfw.sys (ESET)
DRV:64bit: - (epfwwfp) -- C:\Windows\SysNative\drivers\epfwwfp.sys (ESET)
DRV:64bit: - (Epfwndis) -- C:\Windows\SysNative\drivers\epfwndis.sys (ESET)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (MREMP50a64) -- C:\Program Files\Common Files\Motive\MREMP50a64.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV:64bit: - (MRESP50a64) -- C:\Program Files\Common Files\Motive\MRESP50a64.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV:64bit: - (RTL8187) -- C:\Windows\SysNative\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (Impcd) -- C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (HECIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corporation)
DRV:64bit: - (k57nd60a) -- C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (AmUStor) -- C:\Windows\SysNative\drivers\AmUStor.sys (Alcor Micro, Corp.)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (pavboot) -- C:\Windows\SysNative\drivers\pavboot64.sys (Panda Security, S.L.)
DRV:64bit: - (L1E) -- C:\Windows\SysNative\drivers\L1E62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (netr28ux) -- C:\Windows\SysNative\drivers\netr28ux.sys (Ralink Technology Corp.)
DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (mwlPSDVDisk) -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (NTIDrvr) -- C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) -- C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV - (MREMP50) -- C:\Program Files (x86)\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) -- C:\Program Files (x86)\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...B_PVER}&ar=home
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mytotalusa.net
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.co...ng}&rlz=1I7ACAW
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=21
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {C4E5BA1D-6A57-4B2A-8A5F-DD5350714000}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{1BF9CDB4-073A-433C-A08A-429C18EB7CD3}: "URL" = http://search.lycos....y={searchTerms}
IE - HKCU\..\SearchScopes\{59F16E9D-BEED-44E2-8394-7D57FE489C07}: "URL" = http://search.yahoo....rtPage?}&fr=ie8
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.co...1I7ACAW_enUS376
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKCU\..\SearchScopes\{A56A863C-8B94-4E51-B020-AEF0A39AF674}: "URL" = http://www.ask.com/w...src=0&o=0&l=dir
IE - HKCU\..\SearchScopes\{C4E5BA1D-6A57-4B2A-8A5F-DD5350714000}: "URL" = http://ixquick.com/d...anguage=english
IE - HKCU\..\SearchScopes\{C8383368-C5CA-40B6-8370-F215E77D668B}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/...TDF&PC=SUN3&q="
FF - prefs.js..browser.search.selectedEngine: "Ixquick"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:blank"
FF - prefs.js..extensions.enabledAddons: keyscrambler%40qfx.software.corporation:2.9.3.0
FF - prefs.js..extensions.enabledAddons: %7B0545b830-f0aa-4d7e-8820-50a4629a56fe%7D:17.0
FF - prefs.js..extensions.enabledAddons: %7B1018e4d6-728f-4b20-ad56-37578a4de76b%7D:4.2.3
FF - prefs.js..extensions.enabledAddons: %7B1BC9BA34-1EED-42ca-A505-6D2F1A935BBB%7D:4.1.3.1
FF - prefs.js..extensions.enabledAddons: %7B3d7eb24f-2740-49df-8937-200b1cc08f8a%7D:1.5.15.1
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20120910
FF - prefs.js..extensions.enabledAddons: %7Bd40f5e7b-d2cf-4856-b441-cc613eeffbe3%7D:1.68
FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems: keyscrambler@qfx.software.corporation:2.8.1.0
FF - prefs.js..extensions.enabledItems: {1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}:3.5.9.1
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6.5
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.1.4
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110323
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.51
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.8
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.14.2
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.93
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.18
FF - prefs.js..keyword.URL: "http://www.bing.com/...TDF&PC=SUN3&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/npMotiveRequest,version=1.0: C:\Program Files (x86)\Common Files\Motive\npMotiveRequest.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files (x86)\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security, S.L.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\PROGRAM FILES\ESET\ESET SMART SECURITY\MOZILLA THUNDERBIRD [2012/06/04 14:35:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/06/30 18:17:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/11/30 19:25:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/11/29 13:24:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2012/06/04 14:35:54 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/06/30 18:17:34 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/11/30 19:25:31 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/11/29 13:24:20 | 000,000,000 | ---D | M]

[2010/04/24 14:13:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\John\AppData\Roaming\Mozilla\Extensions
[2010/04/24 14:13:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\John\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2012/11/29 13:02:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\extensions
[2012/11/12 10:25:35 | 000,000,000 | ---D | M] ("ColorfulTabs") -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2012/11/10 15:08:47 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2012/03/16 10:02:27 | 000,000,000 | ---D | M] (IE Tab 2 (FF 3.6+)) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}
[2012/09/26 12:42:54 | 000,000,000 | ---D | M] (WOT) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2012/07/10 15:05:43 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012/11/29 13:02:29 | 000,000,000 | ---D | M] (KeyScrambler) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\extensions\keyscrambler@qfx.software.corporation
[2011/07/21 09:44:27 | 000,097,169 | ---- | M] () (No name found) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}.xpi
[2012/11/26 12:09:34 | 000,804,627 | ---- | M] () (No name found) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/03/16 10:02:27 | 000,138,614 | ---- | M] () (No name found) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
[2010/04/24 21:22:41 | 000,002,207 | ---- | M] () -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\searchplugins\askcom.xml
[2010/04/24 21:21:51 | 000,002,484 | ---- | M] () -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\searchplugins\ixquick.xml
[2010/04/24 21:50:27 | 000,000,705 | ---- | M] () -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\0llyexhq.default\searchplugins\webster.xml
[2012/10/16 07:20:40 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/11/30 19:25:31 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2012/11/30 19:25:30 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2006/10/26 19:12:16 | 000,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL
[2012/07/27 15:51:30 | 000,184,248 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll
[2012/11/29 13:24:20 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll
[2012/11/29 13:24:20 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll
[2012/11/29 13:24:20 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll
[2012/11/29 13:24:20 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll
[2012/11/29 13:24:20 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll
[2012/11/29 13:24:20 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll
[2012/11/29 13:24:20 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll
[2012/11/30 19:25:26 | 000,001,607 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
[2012/11/30 19:25:26 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/11/30 19:25:26 | 000,001,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
[2012/11/30 19:25:26 | 000,003,581 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2012/11/30 19:25:26 | 000,002,058 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
[2012/11/30 19:25:26 | 000,001,391 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
[2012/11/30 19:25:26 | 000,001,309 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com/

O1 HOSTS File: ([2012/11/07 10:47:53 | 000,599,925 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost #[IPv6]
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 abcstats.com
O1 - Hosts: 127.0.0.1 a.abv.bg
O1 - Hosts: 127.0.0.1 adserver.abv.bg
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 ca.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 achmedia.com
O1 - Hosts: 127.0.0.1 aconti.net
O1 - Hosts: 127.0.0.1 secure.aconti.net
O1 - Hosts: 127.0.0.1 www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1 csh.actiondesk.com
O1 - Hosts: 127.0.0.1 www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ads.activepower.net
O1 - Hosts: 127.0.0.1 stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 cms.ad2click.nl
O1 - Hosts: 16132 more lines...
O2:64bit: - BHO: (no name) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No CLSID value found.
O2:64bit: - BHO: (KeyScramblerBHO Class) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\x64\KeyScramblerIE.dll (QFX Software Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll File not found
O2:64bit: - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No CLSID value found.
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No CLSID value found.
O2 - BHO: (KeyScramblerBHO Class) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O2 - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No CLSID value found.
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll File not found
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ANIWZCS2Service] C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Wireless Service)
O4 - HKLM..\Run: [D-Link D-Link RangeBooster N DWA-140] C:\Program Files (x86)\D-Link\D-Link RangeBooster N DWA-140\AirNCFG.exe (D-Link)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O9:64bit: - Extra 'Tools' menuitem : &KeyScrambler Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files (x86)\KeyScrambler\x64\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &KeyScrambler Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: adobe.com ([get] http in Trusted sites)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitd...can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.9.2)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://floridakeysme...sCamControl.ocx (CamImage Class)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn...k.cab102118.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_09)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_09)
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} http://zone.msn.com/...on.cab64162.cab (MSN Games – Backgammon)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{84A88CC5-A21A-470B-A64E-B0377BD41669}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8F423660-B973-4BA7-B1E9-34FAABD6A777}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\sacore - No CLSID value found
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore - No CLSID value found
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application
Regards,
MoJo

They said the baby looked like me. Then they turned her rightside up.

#6 MoJo Risin&039;

MoJo Risin&039;

    Member

  • Full Member
  • Pip
  • 66 posts

Posted 03 December 2012 - 07:17 PM

It seems Norton's removal tool wasn't very thorough.

I hope OTL will see most of that.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy the contents of these files, one at a time, and post with your next two replies.



This second reply post contains the contents of Extras.txt, which I copied below:

Regards - Mojo

OTL Extras logfile created on: 12/3/2012 6:03:56 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\John\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.68 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 53.04% Memory free
7.35 Gb Paging File | 5.72 Gb Available in Paging File | 77.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.30 Gb Total Space | 223.55 Gb Free Space | 78.36% Space Free | Partition Type: NTFS
Drive E: | 14.91 Gb Total Space | 7.35 Gb Free Space | 49.28% Space Free | Partition Type: FAT32

Computer Name: JOHN-ACER | User Name: John | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B3BD1F6-911F-45FA-B68C-0E26FE57FCA9}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0D2599E0-6E2F-4AD3-9F47-A4F842FA9F33}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2898B238-C30E-4025-AC7B-44D505B583C6}" = lport=139 | protocol=6 | dir=in | app=system |
"{41F31AA2-68C5-4C44-9D29-16ABBDEECF9D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{47C55220-1257-4F89-A219-8C6ABB03D513}" = lport=10243 | protocol=6 | dir=in | app=system |
"{4FCDE43B-8A6A-4577-BCB7-382A7FCE2FE5}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{55925E36-D152-43EE-9885-37B0441CE1A4}" = lport=137 | protocol=17 | dir=in | app=system |
"{5C7B3F12-1F39-4AA2-B53D-9B4EDC713E99}" = lport=138 | protocol=17 | dir=in | app=system |
"{66765D49-B6B4-4708-A2F9-F6F2609249FF}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{67E83172-E312-40E8-87B5-E6B8DBDEE3BA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7D237920-9801-4281-9B56-408131C95A63}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{8048F010-0998-483F-9227-47F5AEBC4887}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{92519F0F-34F4-4752-8C95-168152CE8C95}" = rport=138 | protocol=17 | dir=out | app=system |
"{A0484EA5-FFEC-4928-94CA-7F7355D815C1}" = lport=445 | protocol=6 | dir=in | app=system |
"{A11EF3D3-C339-4FAF-808C-7CC8C307EC26}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A8E8D45D-42B1-4039-98C9-635BECACFDC5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{AACAE5A1-155D-46EA-9249-FE09DA437653}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B1C9A216-496A-4D63-837E-0A0CE9EDCC3E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BCAD693B-A57A-4C7A-85D9-C20C3CF033A7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D08CA0D4-505A-4675-A08D-9ECC847D9129}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D8A6BE5E-A5C1-4D81-817F-3BF6877D77F1}" = rport=10243 | protocol=6 | dir=out | app=system |
"{D9FAC1CB-6CB8-4A26-B130-2108F9DF7238}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E46064A7-255B-44CB-A328-05DC06341A56}" = rport=445 | protocol=6 | dir=out | app=system |
"{EE6E9DC8-36DF-43C7-BC95-0907B1541106}" = rport=139 | protocol=6 | dir=out | app=system |
"{F54AE3F5-25CF-424B-9B63-E70B92255055}" = rport=137 | protocol=17 | dir=out | app=system |
"{FFB3E733-4F52-4225-891B-0C636A01C741}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0504C01C-F763-4603-B99F-2A5A66A96F77}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0635FD8D-272F-4CF8-B7B5-C72CE99FD1EC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0F3B64B2-EEF3-4F8A-9C8F-10F472CED6CA}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |
"{1121DC6B-6156-4BF6-BBBA-5AE07DE20082}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{11E7CF78-0D76-4267-9A7E-93CC8D2FAC19}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{152452E9-3C71-4072-A825-5F8E0DAFA32D}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqfxt08.exe |
"{1ABA5C6B-9016-45E9-8B68-4A55256B6AAC}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{1E05AC01-7835-4A87-9C88-E32386E8D1A3}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |
"{24094169-6ACA-4265-9EAE-65ABB99023E4}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{26D30364-5F10-44C1-930F-84C14BFA8F8D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{2842AF8A-C10B-41CB-9278-E854EABF1C81}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpsapp.exe |
"{2892A68C-F237-4591-8441-F7F1FF009CB6}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqnrs08.exe |
"{2D62F1CC-5EAF-4D45-A1DD-8C572BAFCF2E}" = dir=in | app=c:\program files (x86)\acer arcade deluxe\playmovie\playmovie.exe |
"{2E2297A9-0758-4FB2-BFE5-B2E4E56FDE13}" = protocol=6 | dir=out | app=system |
"{2EAB53CA-FB16-4ED4-889A-E2FEC0B1EE90}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3323F53B-7AF0-4333-9225-D4D3A77CBE54}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{43CC7C3F-ED8C-41FF-A61B-05AFBD9740FC}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqsudi.exe |
"{4CA19BE6-7B6A-464B-9997-14E923CEE952}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe |
"{5563C7F5-52DD-4BEF-AEF7-8A83B156D4B5}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{55A3610D-0757-4583-8394-D6575CD94D99}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{598DFA71-0669-48C4-A0E7-D51C53E042C5}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{63FC8A43-E14C-4711-A3A5-0A0DB425D2BC}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxm08.exe |
"{652B6C5E-70FC-452B-9A0C-A5D9FB1F0A4C}" = dir=in | app=c:\program files (x86)\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe |
"{6AD57B92-C0D4-4C99-9621-CE26FBB0CAB9}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{6BC0FAAC-1BF8-4420-BE3C-FC7449DE2DDB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpzwiz01.exe |
"{6D739258-15AE-42C6-865E-F5F143C6C94E}" = protocol=6 | dir=in | app=c:\users\john\appdata\local\temp\7zsb61.tmp\symnrt.exe |
"{6F838A18-9E16-4A31-910C-8BE634251064}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{7BF9D2D7-9224-4AD5-9BAA-658F15862DA5}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{80D17EED-C1B0-4716-A253-560115589AC0}" = dir=in | app=c:\program files (x86)\common files\mcafee\mna\mcnasvc.exe |
"{8244A8BD-6EA5-4569-83E2-A560B5E00782}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe |
"{851F1EA6-DBAF-4098-B08B-FFE89314AC67}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpse.exe |
"{8823BFE8-B527-4287-A0BD-A104CB277456}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{8C329BE8-66B2-410A-AB2A-15A79E801C64}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8E08DDC6-E369-4403-A41B-31121F41CE08}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe |
"{92609C6D-EC0C-4F88-8F2F-306FFCB697B4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9CC8B17A-242E-46BD-A815-3CDD08C9D3F8}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A5F0F4C2-123B-4FF7-990F-6BF3381F5335}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{AAB50490-8C3C-4FB0-A5DA-CEA8A925D9F9}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposfx08.exe |
"{ABA42F5D-CE99-4D79-9C6A-570668A9D204}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{AC20C583-660B-4706-BD38-CACBB97B3F71}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{B6379504-84B4-4606-907D-4BE304560502}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe |
"{B72AFC5D-D1B1-4EAE-B1B5-5AE1A0811324}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe |
"{BE5427BE-2561-4703-A483-20D1601E86FC}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |
"{C04C707A-C5A9-4473-A128-A883E8320E64}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe |
"{C8FE00B1-504C-4F0F-AE46-D82A6B66C5E9}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{CCF9D081-B247-4DE8-A006-11749994A20C}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe |
"{CCFBADFD-D9A8-4853-917F-276ECE959C04}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{CD48E4D2-21DC-4B1C-92F3-BF399FEDA924}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{CF1D6759-CE7D-4452-9AB0-9237EFAD668E}" = protocol=17 | dir=in | app=c:\users\john\appdata\local\temp\7zsb61.tmp\symnrt.exe |
"{D02D2369-B19E-440D-9D5A-78DF0E578397}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D88ABBEE-533B-40A2-8D06-47A14780DDE6}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{DA471BDC-C3D9-4692-9697-EB24CD1E1B77}" = dir=in | app=c:\program files (x86)\acer arcade deluxe\playmovie\pmvservice.exe |
"{E34D51B0-146A-43CC-9055-68AE87D5BD0F}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe |
"{E67140B2-D35F-4ECC-8E2A-DC4B860A5E02}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E7DF3791-80E2-4055-B174-8D1077A0BE01}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxs08.exe |
"{E998F3CE-6909-4BEA-9279-0CBBDC9AA771}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{EB20C05A-006F-400B-BAAA-5F203DEDCEFE}" = dir=in | app=c:\program files (x86)\acer arcade deluxe\homemedia\homemedia.exe |
"{ECB09EEC-A219-4363-81D8-23B5C2069D4B}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{EE6E6800-D9C7-4200-912B-4C727CDA7343}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F4C4E0E8-69D7-43F7-8AB9-1F20B5EDBBD7}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F7D0D778-FF6E-4D97-B2E4-517485CDB6C1}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |
"{F9266E94-607E-40D6-AAB8-6ED6058CC5B8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CBBBC4D-B0B6-49DB-A421-98C65080D8EE}" = Eraser 6.0.7.1893
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A325B368-A9EC-40EF-A95C-9DEAD3683AE3}" = Broadcom Gigabit NetLink Controller
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{B61ED343-0B14-4241-999C-490CB1A20DA4}" = HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B
"{C0D93E4E-0866-43C8-A104-BF41A803EA84}" = ESET Smart Security
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"LSI Soft Modem" = LSI HDA Modem
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Puran Defrag Free Edition_is1" = Puran Defrag Free Edition 7.3
"Shop for HP Supplies" = Shop for HP Supplies
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{060A46F8-6E0B-455C-B37B-EDE99762E770}" = Eudora
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{0AA5429F-66E4-4E2C-8BDC-A7D9D9F6A0A4}" = StudioLine Photo Basic 3
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{104066F4-5897-4067-85D3-4C88B67CCF75}" = AIO_Scan
"{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{22DD005D-0EF1-4E3E-92F8-49D89E31479A}" = 1400
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"{2656D0AB-9EA4-4C58-A117-635F3CED8B93}" = Microsoft UI Engine
"{26A24AE4-039D-4CA4-87B4-2F83217009FF}" = Java 7 Update 9
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4C590030-7469-453E-8589-D15DA9D03F52}" = ANIWZCS2 Service
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{68301905-2DEA-41CE-A4D4-E8B443B099BA}" = MyWinLocker
"{6A3C2391-BCE2-4D28-A336-73B953B4502F}" = 1400Trb
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6FBE200D-1F00-40B7-BF48-FEB265AADE94}" = 1400_Help
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISER_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{94056AE8-EF0F-45E4-A1B4-D754115F8A28}" = Numedia CD-DVD writing as non-admin user
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F6B13E2-B93F-4203-9BD4-5DC18C9F9DEB}" = AIO_CDB_Software
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}" = Acer Crystal Eye webcam Ver:1.1.124.1120
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D7D2F494-89E3-42ED-8A2B-75BDD9B464CB}" = D-Link RangeBooster N DWA-140
"{DBCE1208-433D-4D3E-A26A-CB1B5E71A8F5}" = Alcor Micro USB Card Reader
"{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}" = eBay Worldwide
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{EC3B598C-1151-4191-B5B4-A9072ADE6259}_is1" = ZipGenius 6 (6.3.1.2552)
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F26615EF-AF0A-486C-99C9-B65C8C401EBC}" = EuroTalk Talk Now!
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"Acer Assist" = Acer Assist
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"ATT-Management Agent" = ATT-Management Agent
"ENTERPRISER" = Microsoft Office Enterprise 2007
"Google Chrome" = Google Chrome
"GridVista" = Acer GridVista
"HOSTS Secure_is1" = HOSTS Secure 1.0
"Identity Card" = Identity Card
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Acer Backup Manager
"InstallShield_{DBCE1208-433D-4D3E-A26A-CB1B5E71A8F5}" = Alcor Micro USB Card Reader
"IrfanView" = IrfanView (remove only)
"KeyFinder_is1" = Magical Jelly Bean KeyFinder
"KeyScrambler" = KeyScrambler
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"Mozilla Firefox 17.0.1 (x86 en-US)" = Mozilla Firefox 17.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"SpeedFan" = SpeedFan (remove only)
"SpywareBlaster_is1" = SpywareBlaster 4.6
"StudioLine Photo Basic" = StudioLine Photo Basic
"WildTangent acer Master Uninstall" = Acer Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"World Poker Championship" = World Poker Championship (remove only)
"Yahoo! Companion" = Yahoo! Toolbar

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 11/26/2011 9:39:56 PM | Computer Name = John-Acer | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 11/27/2011 3:41:48 AM | Computer Name = John-Acer | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 11/27/2011 9:43:39 AM | Computer Name = John-Acer | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 11/27/2011 1:32:13 PM | Computer Name = John-Acer | Source = NMSAccessU | ID = 0
Description =

Error - 11/27/2011 1:32:44 PM | Computer Name = John-Acer | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 11/28/2011 1:31:42 AM | Computer Name = John-Acer | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "c:\program files (x86)\windows
live\photo gallery\MovieMaker.Exe".Error in manifest or policy file "c:\program
files (x86)\windows live\photo gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 11/28/2011 1:01:37 PM | Computer Name = John-Acer | Source = MsiInstaller | ID = 11706
Description =

Error - 11/28/2011 1:03:07 PM | Computer Name = John-Acer | Source = MsiInstaller | ID = 11706
Description =

Error - 11/28/2011 1:04:59 PM | Computer Name = John-Acer | Source = NMSAccessU | ID = 0
Description =

Error - 11/28/2011 1:05:30 PM | Computer Name = John-Acer | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

[ OSession Events ]
Error - 7/28/2011 9:00:29 AM | Computer Name = John-Acer | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.

Error - 4/24/2012 7:31:16 PM | Computer Name = John-Acer | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 31133
seconds with 540 seconds of active time. This session ended with a crash.

Error - 8/6/2012 4:26:06 PM | Computer Name = John-Acer | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6661.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 725
seconds with 120 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 12/2/2012 6:18:58 PM | Computer Name = John-Acer | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
the following error: %%2

Error - 12/3/2012 3:59:15 AM | Computer Name = John-Acer | Source = bowser | ID = 8003
Description =

Error - 12/3/2012 7:55:30 AM | Computer Name = John-Acer | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 12/3/2012 7:55:31 AM | Computer Name = John-Acer | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 12/3/2012 7:55:31 AM | Computer Name = John-Acer | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 12/3/2012 7:55:32 AM | Computer Name = John-Acer | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 12/3/2012 7:55:33 AM | Computer Name = John-Acer | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 12/3/2012 5:54:37 PM | Computer Name = John-Acer | Source = bowser | ID = 8003
Description =

Error - 12/3/2012 6:30:39 PM | Computer Name = John-Acer | Source = bowser | ID = 8003
Description =

Error - 12/3/2012 6:54:39 PM | Computer Name = John-Acer | Source = bowser | ID = 8003
Description =


< End of report >
Regards,
MoJo

They said the baby looked like me. Then they turned her rightside up.

#7 cnm

cnm

    Mother Lion of SWI

  • Administrators
  • PipPipPipPipPip
  • 25,254 posts

Posted 03 December 2012 - 08:54 PM

Please create a Restore Point. Give it a description like "Before OTL Fix". How to create Restore Point.

Most of the Norton remnants don't actually matter - just language support - but you don't want all that clutter.

Bring up OTL (don't run it just yet).

In the Custom Scans/Fixes box at the bottom, paste in the following:

:OTL
[2012/11/13 12:57:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2012/11/13 12:57:15 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2012/11/26 12:08:14 | 000,866,592 | ---- | M] () -- C:\Users\John\Desktop\Norton_Removal_Tool.exe
[2012/11/13 12:58:59 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared

:Files
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\AppData\Roaming\Microsoft\Office\Recent\Norton Removal Tool.LNK
C:\Users\John\Downloads\Norton_Removal_Tool.exe
C:\Windows\System32\Tasks\Norton*

:Reg
[-HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\AddIns\MsouPlug.OutlookPlug]
[-HKEY_CURRENT_USER\Software\Norton]
[-HKEY_USERS\S-1-5-21-2497620218-1680459894-400693757-1001\Software\Microsoft\Office\Outlook\AddIns\MsouPlug.OutlookPlug]
[-HKEY_USERS\S-1-5-21-2497620218-1680459894-400693757-1001\Software\Norton]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08FF730A-494F-4cba-AA0B-E4F1D44715F9}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08FF730A-494F-4cba-AA0B-E4F1D44715F9}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NortonOnlineBackupReminder]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\NIS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{CF1D6759-CE7D-4452-9AB0-9237EFAD668E}"=-
[-HKEY_CURRENT_USER\Software\Symantec]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Symantec]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Symantec]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"

:Commands
[EMPTYTEMP]
[CREATERESTOREPOINT]

Close other windows.
Then click the red 'Run Fix' button (not the Run Scan).
There will be a reboot.

Post the log OTL.TXT in your reply.

Microsoft MVP Windows Security 2005-2006
How camest thou in this pickle? -- William Shakespeare:(1564-1616)
The various helper groups here
UNITE


#8 MoJo Risin&039;

MoJo Risin&039;

    Member

  • Full Member
  • Pip
  • 66 posts

Posted 03 December 2012 - 11:22 PM

Thanks again for your help cnm. I created a restore point, pasted the remnant unnecessaries as you instructed, then ran the "Run Fix" command in OTL, rebooted, and have posted the resultant OTL log.

All processes killed
========== OTL ==========
C:\ProgramData\Norton\{086A63F0-6B13-4F29-9695-134E7A01E963} folder moved successfully.
C:\ProgramData\Norton\00000082\0000011a\00000582 folder moved successfully.
C:\ProgramData\Norton\00000082\0000011a folder moved successfully.
C:\ProgramData\Norton\00000082 folder moved successfully.
C:\ProgramData\Norton folder moved successfully.
C:\ProgramData\NortonInstaller\Settings folder moved successfully.
C:\ProgramData\NortonInstaller\Logs folder moved successfully.
C:\ProgramData\NortonInstaller folder moved successfully.
C:\Users\John\Desktop\Norton_Removal_Tool.exe moved successfully.
C:\Program Files\Common Files\Symantec Shared folder moved successfully.
========== FILES ==========
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\96 folder moved successfully.
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\144 folder moved successfully.
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009\120 folder moved successfully.
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2009 folder moved successfully.
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\96 folder moved successfully.
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\144 folder moved successfully.
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010\120 folder moved successfully.
C:\Program Files (x86)\Acer\Welcome Center\Content\NIS2010 folder moved successfully.
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\AppData\Roaming\Microsoft\Office\Recent\Norton Removal Tool.LNK moved successfully.
C:\Users\John\Downloads\Norton_Removal_Tool.exe moved successfully.
File\Folder C:\Windows\System32\Tasks\Norton* not found.
========== REGISTRY ==========
Registry key HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\AddIns\MsouPlug.OutlookPlug\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Norton\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-2497620218-1680459894-400693757-1001\Software\Microsoft\Office\Outlook\AddIns\MsouPlug.OutlookPlug\ not found.
Registry key HKEY_USERS\S-1-5-21-2497620218-1680459894-400693757-1001\Software\Norton\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08FF730A-494F-4cba-AA0B-E4F1D44715F9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08FF730A-494F-4cba-AA0B-E4F1D44715F9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08FF730A-494F-4cba-AA0B-E4F1D44715F9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08FF730A-494F-4cba-AA0B-E4F1D44715F9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NortonOnlineBackupReminder\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\NIS\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CF1D6759-CE7D-4452-9AB0-9237EFAD668E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF1D6759-CE7D-4452-9AB0-9237EFAD668E}\ not found.
Registry key HKEY_CURRENT_USER\Software\Symantec\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Symantec\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\\""|""%1" %*" /E : value set successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: John
->Temp folder emptied: 419933 bytes
->Temporary Internet Files folder emptied: 3614469 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 50151038 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 291 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1108250 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 53.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.69.0 log created on 12032012_214534

Files\Folders moved on Reboot...
C:\Users\John\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
Regards,
MoJo

They said the baby looked like me. Then they turned her rightside up.

#9 cnm

cnm

    Mother Lion of SWI

  • Administrators
  • PipPipPipPipPip
  • 25,254 posts

Posted 03 December 2012 - 11:52 PM

I don't like the look of this error that turned up in Exras.txt:
Error - 12/3/2012 7:55:33 AM | Computer Name = John-Acer | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

That would be drive E:.

Open an elevated command prompt. To do this, click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator. If you are prompted for an administrator password or for a confirmation, type the password, or click Allow.
Type the following command, and then press ENTER:
sfc /scannow
The sfc /scannow command scans all protected system files and replaces incorrect versions with correct Microsoft versions.

After that, see if you can run ESET now.

Please scan your machine with ESET OnlineScan

  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image
      icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.

Please post the ESET log, if any, and let me know how things are now. Can you get Flash Player to work in IE?

Microsoft MVP Windows Security 2005-2006
How camest thou in this pickle? -- William Shakespeare:(1564-1616)
The various helper groups here
UNITE


#10 MoJo Risin&039;

MoJo Risin&039;

    Member

  • Full Member
  • Pip
  • 66 posts

Posted 04 December 2012 - 06:24 PM

First off I apologize for the late reply. My youngest turned 21 today, so I was dispatched to run several errands in preparation for tonight.

I don't like the look of this error that turned up in Exras.txt:
Error - 12/3/2012 7:55:33 AM | Computer Name = John-Acer | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

That would be drive E:.


I noticed that when I first ran and perused the results in Extras.txt. However, I neglected to let you know that Drive E: is a 16GB portable USB Flash Drive (my bad). I am communicating on my personal laptop and copying certain things to a flash drive and taking it to the affected laptop, which I have running at another workstation in my "Fortress of Solitude".

Open an elevated command prompt. To do this, click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator. If you are prompted for an administrator password or for a confirmation, type the password, or click Allow.
Type the following command, and then press ENTER:
sfc /scannow
The sfc /scannow command scans all protected system files and replaces incorrect versions with correct Microsoft versions.


Please post the ESET log, if any, and let me know how things are now. Can you get Flash Player to work in IE?

I successfully ran the sfc / scannow command as an administrator.

After that, see if you can run ESET now.
Please scan your machine with ESET OnlineScan


I successfully ran the ESET Online Scan per your recommended settings. When it finished, to my knowledge, it only listed the scan results. A "List Threats" option or command button was not given. The only options I saw were a "Uninstall application on close" check box, along with a "Finish" command button. I assume that is because no threats were detected?

The Scan Results read as follows:
No threats found
Scanned files: 219703
Infected files: 0
Cleaned files: 0
Total scan time: 02:22:27
Scan status: Finished

However, the Flash Player is still not being recognized in IE. In Firefox 17, I imported the IE favorites bookmarks into Firefox, (which is functioning properly with all add-ons), in the event I have to uninstall and reinstall IE.

As an aside:
One thing I noticed during the course of things is that the lappy's temp felt somewhat warm, so I ran an app that monitors the CPU core temps and noticed that it would continuously reach upwards of 145o F. So, I elevated the laptop an inch on a stand, and set up a portable fan to blow on its underside by the intake vent before doing the above scans. The temps during the scan typically dropped to between 110o F – 120o F. This could possibly explain why the resident ESET scans were locking up and stalling.

To prove this, I ran an ESET Smart Scan as an administrator using the laptop's resident Smart Security (as I had done unsuccessfully multiple times earlier) and it successfully completed in less than an hour and a half. The results are posted below:

Scan Log
Version of virus signature database: 7763 (20121204)
Date: 12/4/2012 Time: 10:26:13 AM
Scanned disks, folders and files: C:\Boot sector;C:\
C:\hiberfil.sys - error opening [4]
C:\pagefile.sys - error opening [4]
C:\Al's Use Only\Blonde Teen - xHamster_com.mht » MIME - is OK (internal scanning not performed)
C:\Al's Use Only\Google(Bad)\Update\1.3.21.57\GoogleUpdateHelper.msi » MSI » required.cab » CAB - error reading archive
C:\Al's Use Only\John's Acer\Acer Drivers\3G_Huawei_2.0.3.827_W7x86W7x64_A.zip » ZIP » 3G_Huawei_2.0.3.827_Win7x86x64_Aspire 5740/Acer/Setup.exe » NSIS - archive damaged
C:\MSOCache\All Users\{91120000-0030-0000-0000-0000000FF1CE}-C\EnterrWW.cab » CAB » PROCESS_LIBRARY.FDT » MIME - is OK (internal scanning not performed)
C:\MSOCache\All Users\{91120000-0030-0000-0000-0000000FF1CE}-C\EnterrWW.cab » CAB » HIRING_REQUISITION_CUSTOMIZED.FDT » MIME - is OK (internal scanning not performed)
C:\MSOCache\All Users\{91120000-0030-0000-0000-0000000FF1CE}-C\EnterrWW.cab » CAB » HIRING_REQUISITION.FDT » MIME - is OK (internal scanning not performed)
C:\MSOCache\All Users\{91120000-0030-0000-0000-0000000FF1CE}-C\EnterrWW.cab » CAB » TRACK_ISSUES.FDT » MIME - is OK (internal scanning not performed)
C:\MSOCache\All Users\{91120000-0030-0000-0000-0000000FF1CE}-C\EnterrWW.cab » CAB » POLICIES.FDT » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.A1FFBB52_4F2E_44F1_8614_5D66C2EF43F0 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.03A77D79_488A_445D_B528_0E0089E3FCB3 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.D495C848_F235_46BF_A9A0_77D7C2120E3B » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.445237FC_7259_4EAD_ACEF_7ED7A95D32D7 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.79A89863_540B_470E_9C71_D57F22BFA44D » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.5ACB9F6A_C06C_4121_B854_7133C2ED29A8 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.15989D71_6BEB_424A_88DF_78A882081F91 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.1C571119_9D2B_4542_84BD_0CD3AA24E739 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.C4EB4D09_95BA_4DC2_9551_B6E637DA2230 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.C39C5B26_ED03_4B04_9CFD_166FDC7523D1 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.C05C46CB_E961_4BBA_86BE_4FE1A4426A32 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.87E45AFF_C0E7_4B6E_8E37_52EEB71BF5B7 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.E34CAC5A_4546_4E3A_BFFA_CE28E0CED140 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.14AFC4D4_5454_4AD5_B7FC_10D4FAB85CF3 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.B4924446_617C_4229_8C33_089CD780544D » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.F02247A4_BA3B_4A1D_B7EA_2CB2F17490B7 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.0F75E4D6_4C58_47F6_B626_BA408BA6F03B » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.B3E4ACDE_961E_474B_87CC_22A67A5E77CB » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.D8256176_51D5_41D4_B965_C7B0BC9E4A27 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht.D073AD43_9C5B_4759_A404_ED1717BEEAD7 » MIME - is OK (internal scanning not performed)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab » CAB » ls_hsi.msi » MSI » Data1.cab » CAB » Getting_Started.mht » MIME - is OK (internal scanning not performed)
C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2\License\license.mht » MIME - is OK (internal scanning not performed)
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log - error opening [4]
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb - error opening [4]
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb - error opening [4]
C:\System Volume Information\Syscache.hve - error opening [4]
C:\System Volume Information\Syscache.hve.LOG1 - error opening [4]
C:\System Volume Information\Syscache.hve.LOG2 - error opening [4]
C:\System Volume Information\{30407c91-3a4f-11e2-ac94-00262d88cf1e}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{366c4cfe-397b-11e2-9615-00262d88cf1e}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{6198b094-3b49-11e2-8671-00262d88cf1e}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{d1cbedbf-3b08-11e2-af23-00262d88cf1e}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{e3a5fb2c-3ccd-11e2-8eac-00262d88cf1e}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{e3a5fb31-3ccd-11e2-8eac-00262d88cf1e}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\MSS.log - error opening [4]
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\tmp.edb - error opening [4]
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Windows.edb - error opening [4]
C:\Users\John\ntuser.dat - error opening [4]
C:\Users\John\ntuser.dat.LOG1 - error opening [4]
C:\Users\John\ntuser.dat.LOG2 - error opening [4]
C:\Users\John\AppData\Local\Microsoft\Windows\UsrClass.dat - error opening [4]
C:\Users\John\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 - error opening [4]
C:\Users\John\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 - error opening [4]
C:\Users\John\AppData\Local\VirtualStore\Program Files (x86)\Qualcomm\Eudora\In.mbx.001 » MBOX - is OK (internal scanning not performed)
C:\Users\John\AppData\Local\VirtualStore\Program Files (x86)\Qualcomm\Eudora\In.mbx.002 » MBOX - is OK (internal scanning not performed)
C:\Users\John\AppData\Local\VirtualStore\Program Files (x86)\Qualcomm\Eudora\Junk.mbx » MBOX - is OK (internal scanning not performed)
C:\Users\John\AppData\Local\VirtualStore\Program Files (x86)\Qualcomm\Eudora\Out.mbx » MBOX - is OK (internal scanning not performed)
C:\Users\John\AppData\Local\VirtualStore\Program Files (x86)\Qualcomm\Eudora\Trash.mbx » MBOX - is OK (internal scanning not performed)
C:\Users\John\AppData\Local\VirtualStore\Program Files (x86)\Qualcomm\Eudora\Microsoft Outlook-Personal Folders.fol\Deleted Items.mbx » MBOX - is OK (internal scanning not performed)
C:\Users\John\AppData\Local\VirtualStore\Program Files (x86)\Qualcomm\Eudora\Microsoft Outlook-Personal Folders.fol\Inbox.mbx » MBOX - is OK (internal scanning not performed)
C:\Users\John\AppData\Local\VirtualStore\Program Files (x86)\Qualcomm\Eudora\Microsoft Outlook-Personal Folders.fol\Junk E-mail.mbx » MBOX - is OK (internal scanning not performed)
C:\Users\John\AppData\Local\VirtualStore\Program Files (x86)\Qualcomm\Eudora\Microsoft Outlook-Personal Folders.fol\John.fol\Computer.mbx » MBOX - is OK (internal scanning not performed)
C:\Users\John\AppData\Local\VirtualStore\Program Files (x86)\Qualcomm\Eudora\Microsoft Outlook.fol\Deleted Items.mbx » MBOX - is OK (internal scanning not performed)
C:\Users\John\AppData\Local\VirtualStore\Program Files (x86)\Qualcomm\Eudora\Microsoft Outlook.fol\Drafts.mbx » MBOX - is OK (internal scanning not performed)
C:\Users\John\AppData\Local\VirtualStore\Program Files (x86)\Qualcomm\Eudora\Microsoft Outlook.fol\John.mbx » MBOX - is OK (internal scanning not performed)
C:\Users\John\AppData\Local\VirtualStore\Program Files (x86)\Qualcomm\Eudora\Microsoft Outlook.fol\Sent Items.mbx » MBOX - is OK (internal scanning not performed)
C:\Users\John\Documents\An update is available that improves the compatibility and the reliability of Microsoft XML Core Services 4_0 Service Pack 2 on a Windows Vista-based computer.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\boats_com - Photo Gallery.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\boats_com BEST- Photo Gallery.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\Download details Update for Microsoft XML Core Services 4_0 Service Pack 2 (KB941833).mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\FW Aetna Requests Additional Information Chart # 4677516.txt » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\Inbox (1, 1) - WEBMAIL (John Germovsek).mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\Key Largo Rentals - Vacation Townhouse rental in Key Largo Florida Gorgeous Key Largo Townhouse.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\m00nbay key largo florida - Google Maps.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\MarineMax Ohio 38' (Port Clinton, OH).mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\Yahoo! Maps - 529 E Water St, Sandusky, Oh 44870, United States 44870, US.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\Yellowjackets, Yellow Jackets, Stinging Insects, Wasps.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » arrow1.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » arrow2.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bck1.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bck2.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt11.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt12.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt13.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt21.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt22.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt23.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt31.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt32.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt33.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt41.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt42.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt43.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt51.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt52.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt53.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt61.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » bt62.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » checkbox1.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » checkbox2.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » checkbox3.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » checkbox4.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » default.skn - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » defbtn1.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » defbtn2.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » defbtn3.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » glyph1.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » glyph2.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » glyph3.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » glyph4.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » glyph5.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » glyph6.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » glyph7.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » main.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » preview.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » sprite1.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » tab1.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask » ZIP » tab2.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Additional Downloads\Eraser (Recycle Clear)\Eraser57Setup.zip » ZIP » EraserSetup.exe » INNO » - archive damaged
C:\Users\John\Documents\IBM ThinkPad Files\John\Desktop\Al's Use Only\Downloads to install\Additional Downloads\Eraser (Recycle Clear)\EraserSetup.exe » INNO » - archive damaged
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Application Data\Identities\{57C99B89-9EE1-413F-8582-650593E01B40}\Microsoft\Outlook Express\Deleted Items.dbx » DBX - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Application Data\Identities\{57C99B89-9EE1-413F-8582-650593E01B40}\Microsoft\Outlook Express\Inbox.dbx » DBX - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Application Data\Identities\{57C99B89-9EE1-413F-8582-650593E01B40}\Microsoft\Outlook Express\Sent Items.dbx » DBX - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temp\wecerr.txt » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temporary Internet Files\Content.IE5\0X2Z0563\DIPOver[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temporary Internet Files\Content.IE5\2543YHQ5\hp_anim_outlook[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temporary Internet Files\Content.IE5\4DC9ERSL\CarSpin_outlook[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temporary Internet Files\Content.IE5\4V3NECDD\banner_personalCare_fixed[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temporary Internet Files\Content.IE5\5GFGALA2\s1[1].js » GZIP » s1[1].js - archive damaged
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temporary Internet Files\Content.IE5\5GFGALA2\s2[1].js » GZIP » s2[1].js - archive damaged
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temporary Internet Files\Content.IE5\5GFGALA2\TSIntro2006[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temporary Internet Files\Content.IE5\EPCJY9I5\f_20070325_homefeat_1[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temporary Internet Files\Content.IE5\KP096FCT\00014503-15844[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temporary Internet Files\Content.IE5\MHCRMFS3\mh_bg[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temporary Internet Files\Content.IE5\STYV0DIR\navigationOver[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temporary Internet Files\Content.IE5\T9LAFDB5\zlsSetup_70_337_000_en[1].exe » WISE » 50comupd.exe - archive damaged
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temporary Internet Files\Content.IE5\UBUF2HUJ\homeflash_1[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John\Local Settings\Temporary Internet Files\Content.IE5\WLYF4HYR\CarSpin_Relay[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John\My Documents\Discover Card Year-End Summary Statement 06.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John\My Documents\Sharon Nyman, Premier Island Properties - The Florida Keys TH5.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Auto Converter\Uconeer\uconeer.zip » ZIP » uconeer_setup.exe » INNO - error - unknown compression method
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Auto Converter\Uconeer\uconeer_setup.exe » INNO - error - unknown compression method
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Eraser (Recycle Clear)\Older Versions\Eraser57Setup.zip » ZIP » EraserSetup.exe » INNO » - archive damaged
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » Ad-Aware SE Default.skn - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » arrow1.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » arrow2.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bck1.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt11.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt12.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt13.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt21.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt22.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt23.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt31.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt32.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt33.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt41.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt42.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt43.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt51.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt52.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt53.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt61.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » bt62.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » checkbox1.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » checkbox2.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » checkbox3.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » checkbox4.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » defbtn1.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » defbtn2.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » defbtn3.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » glyph1.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » glyph2.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » glyph3.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » glyph4.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » glyph5.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » glyph6.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » glyph7.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » main.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » preview.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Security and Encryption\Ad-Aware\Ad Awarew SE Personal 1.06.exe » WISE » Ad-Aware SE default.ask » ZIP » sprite1.bmp - error - password-protected file
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\SpywareGuard\spywareguard2.2setup.exe » INNO » {app}\sgliveupdate.exe - is OK
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Zone Alarm\ZA Spy Blocker Toolbar\1999 38' Sea Ray 38 SUNDANCER 7 photo.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Al's Use\John's New Laptop\Dowloads\Zone Alarm\ZA Spy Blocker Toolbar\Sharon Nyman, Premier Island Properties - The Florida Keys Real Estate, Marathon Home.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\08ILCE1Z\videoPlayer[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\54AW2ARJ\megaHomePage[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D51E0TB2\Reader[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D51E0TB2\Skin_VP[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\AppData\Local\Temp\wecerr.txt » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Documents\An update is available that improves the compatibility and the reliability of Microsoft XML Core Services 4_0 Service Pack 2 on a Windows Vista-based computer.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Documents\BUICK ENCLAVE Official Buick Web Site - Luxury Crossover.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Documents\Download details Update for Microsoft XML Core Services 4_0 Service Pack 2 (KB941833).mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Documents\Inbox (1, 1) - WEBMAIL (John Germovsek).mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Documents\Key Largo Rentals - Vacation Townhouse rental in Key Largo Florida Gorgeous Key Largo Townhouse.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Documents\Looking for a photo of the Chagrin River Entrance.txt » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Documents\m00nbay key largo florida - Google Maps.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Documents\MarineMax Ohio 38' (Port Clinton, OH).mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Documents\Yahoo! Maps - 529 E Water St, Sandusky, Oh 44870, United States 44870, US.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Documents\Yellowjackets, Yellow Jackets, Stinging Insects, Wasps.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\John 2009\Pictures\TV Converter Box Coupon Program Website - Online Coupon Application Submission.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G3TBTMA6\zaSetup_80_065_000_en[1].exe » WISE » Windows6.0-KB929547-v2-x64.msu » CAB » WSUSSCAN.cab - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G3TBTMA6\zaSetup_80_065_000_en[1].exe » WISE » Windows6.0-KB929547-v2-x64.msu » CAB » Windows6.0-KB929547-v2-x64.cab - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G3TBTMA6\zaSetup_80_065_000_en[1].exe » WISE » Windows6.0-KB929547-v2-x64.msu » CAB » Windows6.0-KB929547-v2-x64-pkgProperties.txt - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G3TBTMA6\zaSetup_80_065_000_en[1].exe » WISE » Windows6.0-KB929547-v2-x64.msu » CAB » Windows6.0-KB929547-v2-x64.xml - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\08ILCE1Z\videoPlayer[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WA65KUJS\des.player.small[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WKTPC5N2\dynamic_lead[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\Documents\An update is available that improves the compatibility and the reliability of Microsoft XML Core Services 4_0 Service Pack 2 on a Windows Vista-based computer.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\Documents\BUICK ENCLAVE Official Buick Web Site - Luxury Crossover.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\Documents\Download details Update for Microsoft XML Core Services 4_0 Service Pack 2 (KB941833).mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\Documents\Inbox (1, 1) - WEBMAIL (John Germovsek).mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\Documents\Key Largo Rentals - Vacation Townhouse rental in Key Largo Florida Gorgeous Key Largo Townhouse.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\Documents\Looking for a photo of the Chagrin River Entrance.txt » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\Documents\m00nbay key largo florida - Google Maps.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\Documents\MarineMax Ohio 38' (Port Clinton, OH).mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\Documents\Yahoo! Maps - 529 E Water St, Sandusky, Oh 44870, United States 44870, US.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\Documents\Yellowjackets, Yellow Jackets, Stinging Insects, Wasps.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Documents\IBM ThinkPad Files\Users\john\Pictures\TV Converter Box Coupon Program Website - Online Coupon Application Submission.mht » MIME - is OK (internal scanning not performed)
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/bgButton.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/bgButtonFinished.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/bgCloseProgram.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/bgDownloadBarEmpty.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/bgDownloadBarError.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/bgDownloadBarFull.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/bgHeaderError.gif - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/bgListBullet.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/buttonCenter.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/buttonCenterHighlight.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/buttonLeft.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/buttonLeftHighlight.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/buttonRight.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/buttonRightHighlight.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/iconBlank.gif - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/iconComplete.gif - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/iconError.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/iconHeader.png - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/jspArrowDown.gif - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/jspArrowUp.gif - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/logoAdobe.gif - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _css/default.css - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _css/openx.css - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _host/app.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _host/bundleloader.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _host/host.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _host/httpdownload.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _host/interop.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _host/jshelper.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _host/json2.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _host/oserror.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _host/skinwindow.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _host/skinwindowprompt.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _host/textfilereader.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _host/textfilewriter.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actionairappexists.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actionairappinstall.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actionairruntimeexists.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actioncheckreaderversion.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actioncheckuninstall.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actiondiskspace.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actiondownload.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actiondownloadadobe.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actiongccheck.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actiongtbcheck.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actionitem.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actionlaunch.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actionlaunchadobe.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actionlaunchchrome.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actionlaunchflashplayer.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actionlaunchreader.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actionlist.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actionregistrykeypathcheck.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/actionregistryvaluecheck.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/adobe.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/authenticate.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/index.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/jquery.hasevent.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/jquery.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/jquery.jscrollpane.min.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/jquery.mousewheel.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/language-cs.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/language-da.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » _js/language-de.js - error - password-protected file
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).ex
Regards,
MoJo

They said the baby looked like me. Then they turned her rightside up.

#11 cnm

cnm

    Mother Lion of SWI

  • Administrators
  • PipPipPipPipPip
  • 25,254 posts

Posted 04 December 2012 - 06:50 PM

I don't know what to make of that log. Overheating could easily cause the slowness and perhaps the errors. 145F (63C) is a little hot for CPU core. Keeping it below 140F would be best. Can you open the case and check that the fans are all running and unobstructed?

What is the make and model of the PC?

There isn't really any way to uninstall IE. It is part of Windows. All you can do is uninstall its update(s) and revert to earlier version. http://windows.micro...rnet-explorer-9
It might be worthwhile to reinstall it (you can just install it over the existing one).

Microsoft MVP Windows Security 2005-2006
How camest thou in this pickle? -- William Shakespeare:(1564-1616)
The various helper groups here
UNITE


#12 cnm

cnm

    Mother Lion of SWI

  • Administrators
  • PipPipPipPipPip
  • 25,254 posts

Posted 06 December 2012 - 12:10 AM

You need to un-password-protect those files if you want them scanned.

Microsoft MVP Windows Security 2005-2006
How camest thou in this pickle? -- William Shakespeare:(1564-1616)
The various helper groups here
UNITE


#13 MoJo Risin&039;

MoJo Risin&039;

    Member

  • Full Member
  • Pip
  • 66 posts

Posted 07 December 2012 - 04:23 PM

Greetings again cnm. Much obliged for your expertise. I've been busy working this lappy's issues. So here's an update to its status.

"Overheating could easily cause the slowness and perhaps the errors. 145F (63C) is a little hot for CPU core. Keeping it below 140F would be best.
What is the make and model of the PC?"

The unit is an Acer Aspire 15.6" Laptop
Model: AS5740-5513 Notebook (circa, Jan. 2010) purchased in April 2010

It's a budget friendly, bottom end mid level laptop with enough features to satisfy most average household, office productivity, and non-high end gamer users.

The CPU is an Intel Core i3-330M 64 Bit Processor (Basically, a Hyperthreading Dual Core / 4 Thread (threads can be processed simultaneously), 2.13 GHz, 1066 MHz FSB, 3 MB L3 cache, interlaced with a GMA HD 3150, DDR3 1066 MHz memory controller for integrated HD graphics.

According to the Intel specs: The i3 330M has Thermal Monitoring Technologies to protect the processor package and the system from thermal failure through several thermal management features. An on-die Digital Thermal Sensor (DTS) detects the core's temperature, and the thermal management features reduce package power consumption and thereby temperature when required in order to remain within normal operating limits.
i3 330M specs: http://ark.intel.com/products/47663

Note: I have a somewhat similar feature Acer Aspire, model 5741-5763 with a slightly higher clocked i3 350M 2.26 GHz processor in my laptop. When I first got it, the temps were somewhat higher than I was comfortable with, so I bought a laptop cooling pad powered by an AC adapter to keep the temps in check.

I'm speculating that as the CPU was sustaining the continuous workload of the scan, (plus any burdens from Windows, ESET, Malwarebytes, Java, Mozilla and IE add-on live updates, etc because I neglected to disconnect the WLAN.), and resultant rise in core temperature, the Thermal Monitoring kept decreasing the power consumption, and thus, the performance in order to offset the high temps incurred. It could also be controlling the fan speed, which appears to be dictated by temperature. When the resource intensive scan exceeded the CPU's threshold for whatever temp level and length of time it can tolerate, the Thermal Monitor gradually shut the CPU's outside activity level down until it decreased it to 0% and stalled it. When I said temps were upwards of 145F (62C) there were also periods where it pushed 160F (71C).

"Can you open the case and check that the fans are all running and unobstructed?"

The fan is what initially caught my attention. It was abnormally kicking into an accelerated rpm speed. When I placed my hand by the fan's exhaust vent, it was hotter than normal, so I started monitoring the temps and saw that they seemed rather high compared to mine.

Opening the case and checking the fan for obstruction is not a readily do-able check. There is only one fan, and the fan is located at the very base of the inner workings of the lappy's bottom half chassis and is an integrated part of the CPU's heat sink module on the underside of the Main Board, with a 1" x 2" ventilation slot on the bottom below the fan and a ducted rear exhaust vent. The Heat Sink Module is shaped such that it encompasses two other chipsets besides the CPU, (probably the North Bridge and South Bridge). This requires quite a bit of disassembling to check. Without an available product / model specific service manual detailing the orderly step by step procedure, I would never consider and do not advise attempting it on a laptop without one. There are just too many make / model specific disassembly quirks to mess up on. Acer did not have one online, however, I did manage to locate a service manual online, so I decided to have at it. Took me some time, however, I'm not on the clock and I prefer to err on the side of caution when charting into unknown waters. As I'm sure you know by what you do and knowledgeably advise to others; an ounce of prevention is worth a pound of cure. Bottomline, the fan moves freely and appears to be fine and unobstructed. Dust appeared to be minimal by my standards. However, I still air dusted everything in the system anyway. (System could have hidden or static particles, who knows?) Anyhow, when I slapped it back together and fired it back up, the temps were surprisingly much cooler. I ran another ESET scan without the external fan I previously had to use for it, and it completed in under one hour and 15 minutes with no threats, and the max temp reached was 133F (56C) a couple of times and only for a split second. Mostly, it was in the mid teens and lower. (Well within the tolerance limits.)

I also upped the memory from 4 GB to 8 GB Dual Channel DDR3 1066MHz. I am currently running an extended memory test on it. Although I believe that should not be an issue, it should prove the integrity of the new memory and the overheating issue since an extended test requires a long-term burden.

"There isn't really any way to uninstall IE. It is part of Windows. All you can do is uninstall its update(s) and revert to earlier version. http://windows.micro...rnet-explorer-9
It might be worthwhile to reinstall it (you can just install it over the existing one)."

I haven't reached this point yet. When I do, I'll post the results. I'll probably just reinstall the earlier IE 9 over the existing one as you suggested and see what happens.

"You need to un-password-protect those files if you want them scanned."

I'll try if you feel the benefit of doing so outweighs the effort. However, I'm not sure that I can undo it if Adobe set the password.

Take care, and thanks as always for all your help and great advice.
Regards,
MoJo

They said the baby looked like me. Then they turned her rightside up.

#14 cnm

cnm

    Mother Lion of SWI

  • Administrators
  • PipPipPipPipPip
  • 25,254 posts

Posted 07 December 2012 - 04:39 PM

It sounds as though you are making good progress. Your speculations are probably right on.

I'm surprised there is only one fan, but then I'm not familiar with laptop internals. I would have thought there would be a case fan in addition to the CPU fan.

Whether those password protected files need to be scanned is up to you.. But it is not usual for them to be encrypted.
For instance why would this be encrypted?
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/buttonRightHighlight.png - error - password-protected file

And if you need the space you could delete the damaged archives like this one:
Files\Content.IE5\G3TBTMA6\zaSetup_80_065_000_en[1].exe » WISE » Windows6.0-KB929547-v2-x64.msu » CAB » Windows6.0-KB929547-v2-x64.cab - archive damaged - the file could not be extracted.

Truthfully, though, I'm not sure from the log exactly what files ESET is looking at. With all those >>

Microsoft MVP Windows Security 2005-2006
How camest thou in this pickle? -- William Shakespeare:(1564-1616)
The various helper groups here
UNITE


#15 MoJo Risin&039;

MoJo Risin&039;

    Member

  • Full Member
  • Pip
  • 66 posts

Posted 08 December 2012 - 07:16 PM

Hello again cnm.

This should be my final post for this thread. I apologize for the story-like content, but as some can attest to, I tend to get diarrhea of the mouth sometimes.

"It might be worthwhile to reinstall it (you can just install it over the existing one)."

This sounded like a solid plan. I went to the Microsoft's IE 9 download site, however, neither IE 32 or 64, or Firefox could connect to the download after I selected the Win7 version for download, whether I was on the affected system or mine. My Wireless Network showed I had a 5 bar Internet Access connection. Therefore, that could not be an issue. After a couple unsuccessful attempts, I decided to go to plan B.

As I mentioned before, I avoid IE like the plague whenever possible. Out of desperation, among other things, which I won't mention, I decided to bring the affected laptop over to my main station and once again do a side-by-side comparison of the files and settings since I know my IE 9 works fine.

First, I opened Windows Explorer and opened "C:\Windows\System32\Macromed\Flash" on both systems and compared the files within. They checked out identical.

Then, I opened "C:\Windows\SysWOW64\Macromed\Flash" on both and compared the files. They also checked out identical.

I then opened IE9 on both and did a comparison of the "Tools>Internet options>Advanced" settings. They once again checked out identical. Now I'm really getting flustered.

So, I'm now figurin' that I just keep batting a thousand on the old "IE Gotcha Meter". I scratch my head, go to the coffee pot I have in my "Fortress of Solitude", and pour another cup. I now decide to compare all the IE menu bar drop downs, as I once did before. This time I notice that on the affected laptop's IE menu bar "Tools" drop down menu, the "ActiveX Filtering" command had a check next to it (thus enabling it), whereas, it was disabled on my laptop's IE. I toggled off the ActiveX Filtering on the affected laptop, OK'd the setting, closed IE, and decided to do a system Restart for the heck of it. (I realize a restart is not actually required, or I would have been prompted to do so. But, what the Hey.) When the system came back up, I opened IE, said a quick prayer, and went to YouTube to once again, for the umpteenth time, try to play a Flash video. "Lo and Behold", no "Flash Player not installed" error messages are displayed, and it now plays Flash vids. Boy, do I feel stupid, yet relieved. OK, moving on:

"But it is not usual for them to be encrypted.
For instance why would this be encrypted?
C:\Users\John\Downloads\install_flashplayer11x32_mssd_aih(1).exe » ZIP » images/buttonRightHighlight.png - error - password-protected file
"

I agree. I can see no reason or need for a Flash Player portable network graphic image file to have that strict level of security imposed on it, unless its parent .exe requires it for proprietary purpose at the top level and thus subsequently imposes all installed sub files with the same security limitations. But then again, what do I know? Anyway, since I see no need for them now, because it resides in the "Downloads" folder and was already apparently properly installed, I'll simply say, "See ya!" "Sayonara!" and "Say good night Gracie!" to the downloaded add on .exe files there. They can say hello to the Recycle Bin.

"And if you need the space you could delete the damaged archives like this one:
Files\Content.IE5\G3TBTMA6\zaSetup_80_065_000_en[1].exe » WISE » Windows6.0-KB929547-v2-x64.msu » CAB » Windows6.0-KB929547-v2-x64.cab - archive damaged - the file could not be extracted.

Truthfully, though, I'm not sure from the log exactly what files ESET is looking at. With all those"


I believe that particular one is from a temporary Zone Alarm Freeware firewall I installed in lieu of Windows Firewall until I could install a permanent AV/Internet app security solution for them. Apparently, similar to Norton, it left certain garbage remnants. Although this unit only has used around 20% of its actual total 285 GB HDD space, if it's junk, it's "Outta Here!" I'll also clean out any other similar junk things I know about. (As an aside, these Acer lappy's also come preloaded with a bunch of needless trial "Bloatware", which I initially trashed back then.)

Epilogue:
Thanks for all you've done. With all your help I was finally able wrap things up and send this puppy back home to its master. You helped me clean up this lappy's needless garbage files, so it now runs faster. You steered me towards the system's internals and it now runs much cooler. I learned a heck of a lot from this entire episode. Your selfless efforts are greatly appreciated. PC's and the Internet can sometimes be a blessing or a curse. You good folks at SWI and your superb, professional forum are certainly a blessing. I can't say enough about all the great things you considerately do and provide for us less knowledgeable folks. I wish you and all your associates nothing but the best and many continued successes. It was an honor and a pleasure to have you help me, and once again, SWI saved my bacon. I'm much obliged to you all.

Similar to you kind, dedicated folks, all my efforts for others are on a gratis basis, and since this is the Season of Giving, the memory update and laptop cooling pad I just purchased for them will also be on my dime. Happy Holidays to all and Seasons Greetings!

You may now close this thread and consider it successfully completed.

Best regards,
Al (aka Mojo Risin')

Edited by MoJo Risin', 08 December 2012 - 07:21 PM.

Regards,
MoJo

They said the baby looked like me. Then they turned her rightside up.

#16 cnm

cnm

    Mother Lion of SWI

  • Administrators
  • PipPipPipPipPip
  • 25,254 posts

Posted 08 December 2012 - 07:31 PM

Before you sent it home it would have been good to run OTL and click the CleanUp button. Also delete the DDS files and Security Check from the Desktop.

Not worth worrying about if inconvenient, though.

Your adventures with IE are highly entertaining. Good work beating it into submission.

Microsoft MVP Windows Security 2005-2006
How camest thou in this pickle? -- William Shakespeare:(1564-1616)
The various helper groups here
UNITE


#17 MoJo Risin&039;

MoJo Risin&039;

    Member

  • Full Member
  • Pip
  • 66 posts

Posted 08 December 2012 - 08:32 PM

OK, story of my life, I was wrong again. Here's my actual last post, (maybe). Yet, I love it, cause I can always count on SWI to steer me in the right direction and advise how to get me to the next level.

"Before you sent it home it would have been good to run OTL and click the CleanUp button. Also delete the DDS files and Security Check from the Desktop.

Not worth worrying about if inconvenient, though."


Great point. I'll definitely file that info away for future reference. That's a great tool. Similar to SWI, Old Timers is my hero.

However, we live on the south shore of Lake Erie and the laptop's owner is a snowbird who spends their winters in FL and dropped it in my lap the day before they left. It's now on its way to warmer climates via Fedex because the owner does a lot of online stuff and uses it daily down there, and is probably experiencing a void without it.

"Your adventures with IE are highly entertaining. Good work beating it into submission."

When it comes to PC issues, you can't win 'em all on your own, However, with your expert advice, we'll slay the dragon.

Thanks again.
Regards,
MoJo

They said the baby looked like me. Then they turned her rightside up.

#18 cnm

cnm

    Mother Lion of SWI

  • Administrators
  • PipPipPipPipPip
  • 25,254 posts

Posted 08 December 2012 - 08:41 PM

Glad we could help. :)

If you need this topic reopened, please tell the moderating team by replying here with the address of the thread. This applies only to the original topic starter. Everyone else please begin a New Topic.

Microsoft MVP Windows Security 2005-2006
How camest thou in this pickle? -- William Shakespeare:(1564-1616)
The various helper groups here
UNITE





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button