Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: browser redirects  (Read 141524 times)

0 Members and 1 Guest are viewing this topic.

glathem40

    Topic Starter


    Intermediate
  • Bytor_Snowdog
  • Thanked: 2
    • Experience: Familiar
    • OS: Windows 10
    browser redirects
    « on: March 11, 2011, 02:08:18 AM »
    Greetings all !
             I have an HP p6320f desktop.   AMD phenom 2.8 GHz, 64bit, Windows 7 Home Premium, Service Pack 1.  I am getting redirects in both I.E. and firefox.  I have had avast installed since I bought it last year.  Have run  S.A.S and malwarebytes scans - They keep finding infected files, but after removing selected files and reboot the redirects persist.  I have tried running highjack this and posting it per your self-help guidelines.  I removed the files it suggested - still no luck.  I am going to attempt to post my latest highjack this log to this post.   If anybody can offer a suggestion on what to do, I will buy them a new house in the Hamptons.  thx

    [recovering disk space - old attachment deleted by admin]
    If you choose not to decide, you still have made a choice.

    Allan

    • Moderator

    • Mastermind
    • Thanked: 1260
    • Experience: Guru
    • OS: Windows 10
    Re: browser redirects
    « Reply #1 on: March 11, 2011, 05:41:28 AM »
    Please follow the instructions in the following link and post your logs:
    http://www.computerhope.com/forum/index.php/topic,46313.0.html

    glathem40

      Topic Starter


      Intermediate
    • Bytor_Snowdog
    • Thanked: 2
      • Experience: Familiar
      • OS: Windows 10
      Re: browser redirects
      « Reply #2 on: March 11, 2011, 07:33:12 PM »
      per your  request

      [recovering disk space - old attachment deleted by admin]
      If you choose not to decide, you still have made a choice.

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: browser redirects
      « Reply #3 on: March 12, 2011, 12:00:43 PM »
      Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

      1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
      2. The fixes are specific to your problem and should only be used for this issue on this machine.
      3. If you don't know or understand something, please don't hesitate to ask.
      4. Please DO NOT run any other tools or scans while I am helping you.
      5. It is important that you reply to this thread. Do not start a new topic.
      6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
      7. Absence of symptoms does not mean that everything is clear.

      If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
      ***********************************************
      Please do not attach the logs unless absolutely necessary. Copy and paste them in your reply.

      I strongly recommend that you remove Ask from your computer because it;

      •Promotes its toolbars on sites targeted to kids.

      •Promotes its toolbars through ads that appear to be part of other companies' sites.

      •Promotes its toolbars through other companies' spyware.

      •Installs without any disclosure whatsoever and without any consent whatsoever.

      •Solicits installations via "deceptive door openers" that do not accurately describe the offer; failing to affirmatively show a license agreement; linking to a EULA via an off-screen link.

      •Makes confusing changes to users' browsers -- increasing Ask's revenues while taking users to pages they didn't intend to visit.

      See Here for more info.

      If you choose to follow my recommendation then please go to Start > Control Panel > Add/Remove Programs and remove the following programs if present.

      AskBarDis or anything related to Ask

      Then please find and delete this folder in bold (if present):
      C:\Program Files\AskBarDis. or anything related to Ask.
      ***************************************************

      Open HijackThis and select Do a system scan only

      Place a check mark next to the following entries: (if there)

      O2 - BHO: WhiteSmoke Toolbar - {52794457-af6c-4c50-9def-f2e24f4c8889} - C:\Program Files (x86)\whitesmoketoolbar\whitesmoketoolbarX.dll (file missing)
      O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
      O3 - Toolbar: LimeWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
      O3 - Toolbar: WhiteSmoke Toolbar - {52794457-af6c-4c50-9def-f2e24f4c8889} - C:\Program Files (x86)\whitesmoketoolbar\whitesmoketoolbarX.dll (file missing)
      O4 - HKCU\..\Run: [ihzbjgg] rundll32 "C:\Users\computer 1\AppData\Roaming\vaultclie.dll",upjkmp


      Important: Close all open windows except for HijackThis and then click Fix checked.

      Once completed, exit HijackThis.
      *************************************************
      Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

      link # 1
      Link # 2
      If you are using Firefox, make sure that your download settings are as follows:

      * Tools->Options->Main tab
      * Set to "Always ask me where to Save the files".

      Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

      Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

      Right-click combofix.exe and select Run as Administrator and follow the prompts.
      When finished, ComboFix will produce a log for you.
      Post the ComboFix log and a new HijackThis log in your next reply.

      NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

      Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.
      Windows 8 and Windows 10 dual boot with two SSD's

      glathem40

        Topic Starter


        Intermediate
      • Bytor_Snowdog
      • Thanked: 2
        • Experience: Familiar
        • OS: Windows 10
        Re: browser redirects
        « Reply #4 on: March 17, 2011, 12:31:49 PM »
        Hello Dave,
               Please  excuse the delay in my response.  I have tried 3 times to respond and for some reason they would not post.  If this short message posts, I will try again.
        If you choose not to decide, you still have made a choice.

        glathem40

          Topic Starter


          Intermediate
        • Bytor_Snowdog
        • Thanked: 2
          • Experience: Familiar
          • OS: Windows 10
          Re: browser redirects
          « Reply #5 on: March 18, 2011, 03:03:04 AM »
          Dave - It seems as though my post times out if I include too much information.   Browser redirects are fixed folllowing your steps.  attatching hijack this log - thanks for your help !

          [recovering disk space - old attachment deleted by admin]
          If you choose not to decide, you still have made a choice.

          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: browser redirects
          « Reply #6 on: March 18, 2011, 01:22:46 PM »
          I don't need the HJT log but I do need you to run ComboFix as instructed.
          Windows 8 and Windows 10 dual boot with two SSD's

          glathem40

            Topic Starter


            Intermediate
          • Bytor_Snowdog
          • Thanked: 2
            • Experience: Familiar
            • OS: Windows 10
            Re: browser redirects
            « Reply #7 on: March 18, 2011, 08:27:51 PM »
            Dave -
                As instructed downloaded combofix to desktop.  disabled avast realtime shield.  Right clicked combofix and ran as administrator.  After 20min this is what I ended up (screenshot).
            Surely this is not what you are looking for, but I cannot figure out how to produce a log from combfix.  Once again this novice is so appreciative of your patience.

            [recovering disk space - old attachment deleted by admin]
            If you choose not to decide, you still have made a choice.

            SuperDave

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: browser redirects
            « Reply #8 on: March 19, 2011, 12:33:23 PM »
            Ok. Please try this:

            Delete your copy of ComboFix; download a fresh copy, except before you download it, rename it to blackpudding.bat

            Navigate to Start --> Run, and enter the following command exactly as shown:

            "%userprofile%\desktop\blackpudding.bat" /killall

            See if ComboFix will run now
            Windows 8 and Windows 10 dual boot with two SSD's

            richardpreston



              Starter

              • Experience: Beginner
              • OS: Unknown
              Re: browser redirects
              « Reply #9 on: March 19, 2011, 01:51:43 PM »
              Your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help.
              « Last Edit: March 19, 2011, 05:22:56 PM by SuperDave »

              glathem40

                Topic Starter


                Intermediate
              • Bytor_Snowdog
              • Thanked: 2
                • Experience: Familiar
                • OS: Windows 10
                Re: browser redirects
                « Reply #10 on: March 19, 2011, 03:48:25 PM »
                Dave
                      It seems to have worked per your last instructions.  Hope this is what your looking for.  As always thx.

                [recovering disk space - old attachment deleted by admin]
                If you choose not to decide, you still have made a choice.

                SuperDave

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: browser redirects
                « Reply #11 on: March 19, 2011, 05:40:58 PM »
                Download DDS from HERE or HERE and save it to your desktop.

                Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

                * XP users Double click on dds to run it.
                * If your antivirus or firewall try to block DDS then please allow it to run.
                * When finished DDS will open two (2) logs.

                1) DDS.txt
                2) Attach.txt

                * Save both logs to your desktop.
                * Please copy and paste the entire contents of both logs in your next reply.

                Note: DDS will instruct you to post the Attach.txt log as an attachment.
                Please just post it as you would any other log by copy and pasting it into the reply.
                *****************************************************
                Please download Rooter and Save it to your desktop.
                • Double click it to start the tool.Vista and Windows7 run as administrator.
                • Click Scan.
                • Eventually, a Notepad file containing the report will open, also found at C:\Rooter.txt. Post that log in your next reply.
                Windows 8 and Windows 10 dual boot with two SSD's

                glathem40

                  Topic Starter


                  Intermediate
                • Bytor_Snowdog
                • Thanked: 2
                  • Experience: Familiar
                  • OS: Windows 10
                  Re: browser redirects
                  « Reply #12 on: March 19, 2011, 08:21:15 PM »
                  Dave - logs

                  [recovering disk space - old attachment deleted by admin]
                  If you choose not to decide, you still have made a choice.

                  SuperDave

                  • Malware Removal Specialist
                  • Moderator


                  • Genius
                  • Thanked: 1020
                  • Certifications: List
                  • Experience: Expert
                  • OS: Windows 10
                  Re: browser redirects
                  « Reply #13 on: March 20, 2011, 01:18:53 PM »
                  Conduit Engine doesn't have a good reputation in the malware world. If you don't need it I would recommend removing it.

                  Please download Rooter and Save it to your desktop.
                  • Double click it to start the tool.Vista and Windows7 run as administrator.
                  • Click Scan.
                  • Eventually, a Notepad file containing the report will open, also found at C:\Rooter.txt. Post that log in your next reply.
                  Windows 8 and Windows 10 dual boot with two SSD's

                  glathem40

                    Topic Starter


                    Intermediate
                  • Bytor_Snowdog
                  • Thanked: 2
                    • Experience: Familiar
                    • OS: Windows 10
                    Re: browser redirects
                    « Reply #14 on: March 20, 2011, 09:11:29 PM »
                    Dave - logs

                    [recovering disk space - old attachment deleted by admin]
                    If you choose not to decide, you still have made a choice.

                    SuperDave

                    • Malware Removal Specialist
                    • Moderator


                    • Genius
                    • Thanked: 1020
                    • Certifications: List
                    • Experience: Expert
                    • OS: Windows 10
                    Re: browser redirects
                    « Reply #15 on: March 21, 2011, 01:18:30 PM »
                    I'd like to scan your machine with ESET OnlineScan

                    •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
                    ESET OnlineScan
                    •Click the button.
                    •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
                    • Click on to download the ESET Smart Installer. Save it to your desktop.
                    • Double click on the icon on your desktop.
                    •Check
                    •Click the button.
                    •Accept any security warnings from your browser.
                    •Check
                    •Push the Start button.
                    •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
                    •When the scan completes, push
                    •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
                    •Push the button.
                    •Push
                    A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
                    Windows 8 and Windows 10 dual boot with two SSD's

                    glathem40

                      Topic Starter


                      Intermediate
                    • Bytor_Snowdog
                    • Thanked: 2
                      • Experience: Familiar
                      • OS: Windows 10
                      Re: browser redirects
                      « Reply #16 on: March 24, 2011, 06:29:17 PM »
                      Dave- Just wondering, from what you see is everything ok ?  Computer seems to be working fine.  browser redirects seem to be gone.
                      If you choose not to decide, you still have made a choice.

                      SuperDave

                      • Malware Removal Specialist
                      • Moderator


                      • Genius
                      • Thanked: 1020
                      • Certifications: List
                      • Experience: Expert
                      • OS: Windows 10
                      Re: browser redirects
                      « Reply #17 on: March 25, 2011, 12:25:30 PM »
                      I need to see the ESET scan log.
                      Windows 8 and Windows 10 dual boot with two SSD's

                      glathem40

                        Topic Starter


                        Intermediate
                      • Bytor_Snowdog
                      • Thanked: 2
                        • Experience: Familiar
                        • OS: Windows 10
                        Re: browser redirects
                        « Reply #18 on: March 25, 2011, 10:22:20 PM »
                        Dave -
                                 Per my last posts, does everything look ok ?  I still seem to bbe getting intermittent redirects.  Concerned.  thx
                        If you choose not to decide, you still have made a choice.

                        SuperDave

                        • Malware Removal Specialist
                        • Moderator


                        • Genius
                        • Thanked: 1020
                        • Certifications: List
                        • Experience: Expert
                        • OS: Windows 10
                        Re: browser redirects
                        « Reply #19 on: March 26, 2011, 12:10:37 PM »
                        Please go to Jotti's malware scan
                        (If more than one file needs scanned they must be done separately and links posted for each one)

                        * Copy the file path in the below Code box:

                        Code: [Select]
                        c:\ijji\ENGLISH\AVA\Binaries\GameGuard\dump_wmimmc.sys
                        * At the upload site, click once inside the window next to Browse.
                        * Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
                        * Next click Submit file
                        * Your file will possibly be entered into a queue which normally takes less than a minute to clear.
                        * This will perform a scan across multiple different virus scanning engines.
                        * Important: Wait for all of the scanning engines to complete.
                        * Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.
                        *************************************************
                        Download OTL to your desktop.

                        * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
                        * When the window appears, underneath Output at the top change it to Minimal Output.
                        * Check the boxes beside LOP Check and Purity Check.
                        * Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.

                        When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

                        Please copy and pate the contents of these files, one at a time, into your next reply.

                        Note: You may need two or more posts to fit them all in.
                        Windows 8 and Windows 10 dual boot with two SSD's

                        glathem40

                          Topic Starter


                          Intermediate
                        • Bytor_Snowdog
                        • Thanked: 2
                          • Experience: Familiar
                          • OS: Windows 10
                          Re: browser redirects
                          « Reply #20 on: March 26, 2011, 05:05:46 PM »
                          Dave -
                                 Please excuse me for being SUCH an idiot.  I kept scrolling to the bottom of pg1 wondering why you had not responded.  I just today realized I needed to click pg 2.  Per your steps listed I am posting the ESET log. 

                          [recovering disk space - old attachment deleted by admin]
                          If you choose not to decide, you still have made a choice.

                          glathem40

                            Topic Starter


                            Intermediate
                          • Bytor_Snowdog
                          • Thanked: 2
                            • Experience: Familiar
                            • OS: Windows 10
                            Re: browser redirects
                            « Reply #21 on: March 26, 2011, 05:26:02 PM »
                            Dave -
                                 Jotti link

                            [recovering disk space - old attachment deleted by admin]
                            If you choose not to decide, you still have made a choice.

                            glathem40

                              Topic Starter


                              Intermediate
                            • Bytor_Snowdog
                            • Thanked: 2
                              • Experience: Familiar
                              • OS: Windows 10
                              Re: browser redirects
                              « Reply #22 on: March 26, 2011, 05:44:38 PM »
                              Dave  -otl

                              [recovering disk space - old attachment deleted by admin]
                              If you choose not to decide, you still have made a choice.

                              SuperDave

                              • Malware Removal Specialist
                              • Moderator


                              • Genius
                              • Thanked: 1020
                              • Certifications: List
                              • Experience: Expert
                              • OS: Windows 10
                              Re: browser redirects
                              « Reply #23 on: March 26, 2011, 07:03:35 PM »
                              You are missing one log from OTL. It's called Extras.Txt and should be on your desktop. Please send it to me. Please do not attach it. Copy and paste it in your reply.
                              How's your computer working now?
                              Windows 8 and Windows 10 dual boot with two SSD's

                              glathem40

                                Topic Starter


                                Intermediate
                              • Bytor_Snowdog
                              • Thanked: 2
                                • Experience: Familiar
                                • OS: Windows 10
                                Re: browser redirects
                                « Reply #24 on: March 26, 2011, 09:08:11 PM »
                                Still getting intermittent re-directs.OTL Extras logfile created on: 3/26/2011 6:36:36 PM - Run 1
                                OTL by OldTimer - Version 3.2.22.3     Folder = C:\Users\computer 1\Desktop
                                64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
                                Internet Explorer (Version = 8.0.7601.17514)
                                Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
                                 
                                8.00 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 75.00% Memory free
                                15.00 Gb Paging File | 13.00 Gb Available in Paging File | 86.00% Paging File free
                                Paging file location(s): ?:\pagefile.sys [binary data]
                                 
                                %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
                                Drive C: | 920.64 Gb Total Space | 776.92 Gb Free Space | 84.39% Space Free | Partition Type: NTFS
                                Drive D: | 10.77 Gb Total Space | 1.56 Gb Free Space | 14.48% Space Free | Partition Type: NTFS
                                Unable to calculate disk information.
                                 
                                Computer Name: COMPUTER1-PC | User Name: computer 1 | Logged in as Administrator.
                                Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
                                Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
                                 
                                ========== Extra Registry (SafeList) ==========
                                 
                                 
                                ========== File Associations ==========
                                 
                                64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
                                .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
                                 
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
                                .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
                                 
                                ========== Shell Spawning ==========
                                 
                                64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
                                batfile [open] -- "%1" %* File not found
                                cmdfile [open] -- "%1" %* File not found
                                comfile [open] -- "%1" %* File not found
                                exefile [open] -- "%1" %* File not found
                                helpfile [open] -- Reg Error: Key error.
                                htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
                                inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
                                InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
                                InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
                                piffile [open] -- "%1" %* File not found
                                regfile [merge] -- Reg Error: Key error.
                                scrfile [config] -- "%1" File not found
                                scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
                                scrfile [open] -- "%1" /S File not found
                                txtfile [edit] -- Reg Error: Key error.
                                Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
                                Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
                                Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
                                Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
                                Folder [explore] -- Reg Error: Value error.
                                Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
                                 
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
                                batfile [open] -- "%1" %*
                                cmdfile [open] -- "%1" %*
                                comfile [open] -- "%1" %*
                                cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
                                exefile [open] -- "%1" %*
                                helpfile [open] -- Reg Error: Key error.
                                piffile [open] -- "%1" %*
                                regfile [merge] -- Reg Error: Key error.
                                scrfile [config] -- "%1"
                                scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
                                scrfile [open] -- "%1" /S
                                txtfile [edit] -- Reg Error: Key error.
                                Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
                                Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
                                Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
                                Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
                                Folder [explore] -- Reg Error: Value error.
                                Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
                                 
                                ========== Security Center Settings ==========
                                 
                                64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                                "cval" = 1
                                "FirewallDisableNotify" = 0
                                "AntiVirusDisableNotify" = 0
                                "UpdatesDisableNotify" = 0
                                 
                                64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
                                 
                                64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
                                "VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
                                "AntiVirusOverride" = 0
                                "AntiSpywareOverride" = 0
                                "FirewallOverride" = 0
                                 
                                64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
                                 
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                                "FirewallDisableNotify" = 0
                                "AntiVirusDisableNotify" = 0
                                "UpdatesDisableNotify" = 0
                                 
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
                                 
                                ========== System Restore Settings ==========
                                 
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
                                "DisableSR" = 0
                                 
                                ========== Firewall Settings ==========
                                 
                                64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
                                 
                                64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
                                 
                                64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
                                 
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
                                 
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
                                 
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
                                 
                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
                                "DisableNotifications" = 0
                                "EnableFirewall" = 1
                                 
                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
                                "DisableNotifications" = 0
                                "EnableFirewall" = 1
                                 
                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
                                 
                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
                                "DisableNotifications" = 0
                                "EnableFirewall" = 1
                                 
                                ========== Authorized Applications List ==========
                                 
                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
                                 
                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
                                 
                                 
                                ========== HKEY_LOCAL_MACHINE Uninstall List ==========
                                 
                                64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
                                "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
                                "{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
                                "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
                                "{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
                                "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
                                "{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
                                "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
                                "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
                                "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
                                "{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Client 1.10.01
                                "{88E60521-1E4E-4785-B9F1-1798A4BD0C30}" = HP MediaSmart SmartMenu
                                "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
                                "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
                                "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
                                "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
                                "{9EFC40E3-5F31-4F75-8445-286273F74D8E}" = Apple Mobile Device Support
                                "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
                                "{B812FCC0-6192-4BFA-A9C6-1E8578F255DA}" = iTunes
                                "{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
                                "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
                                "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
                                "{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
                                "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
                                "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
                                "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
                                "CCleaner" = CCleaner
                                "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
                                "NVIDIA Drivers" = NVIDIA Drivers
                                "PC-Doctor for Windows" = Hardware Diagnostic Tools
                                 
                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
                                "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
                                "{08DB3902-2CE0-474D-BCE3-0177766CE9F1}" = HP Support Assistant
                                "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
                                "{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
                                "{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
                                "{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup
                                "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
                                "{1896E712-2B3D-45eb-BCE9-542742A51032}" = PictureMover
                                "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
                                "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
                                "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
                                "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
                                "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
                                "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
                                "{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
                                "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 24
                                "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
                                "{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
                                "{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java(TM) SE Runtime Environment 6 Update 1
                                "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
                                "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
                                "{35021DFB-F9CA-402A-89A2-47F91E506465}" = HP MediaSmart/TouchSmart Netflix
                                "{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
                                "{40719211-D09A-11DF-BA30-0013D3D69929}" = MSVCRT Redists
                                "{40AE01BE-A290-4FFB-8DAB-C624C17DC87E}" = Vegas Movie Studio HD Platinum 10.0
                                "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
                                "{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
                                "{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
                                "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
                                "{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
                                "{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
                                "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
                                "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
                                "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
                                "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
                                "{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
                                "{6D592E30-11EC-11E0-859C-0013D3D69929}" = Vegas Pro 10.0
                                "{7032B400-11EC-11E0-A9BF-0013D3D69929}" = MSVCRT Redists
                                "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
                                "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
                                "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
                                "{7FC8C210-A319-4835-A87D-B935EFB4C148}" = Microsoft Live Search Toolbar
                                "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
                                "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
                                "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
                                "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
                                "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
                                "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
                                "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
                                "{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
                                "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
                                "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
                                "{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
                                "{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
                                "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
                                "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
                                "{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
                                "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
                                "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
                                "{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
                                "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
                                "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
                                "{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
                                "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
                                "{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-002A-0000-1000-0000000FF1CE}_PROR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-002A-0409-1000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
                                "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
                                "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
                                "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
                                "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-0116-0409-1000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
                                "{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
                                "{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
                                "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
                                "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
                                "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
                                "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
                                "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
                                "{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
                                "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
                                "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
                                "{9DEF9686-CCB2-47B7-BF83-B49EA21FA016}" = HP MediaSmart Demo
                                "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
                                "{A54F806B-A2E1-4794-A7FE-365167EC67CB}" = Masque IGT Slots Little Green Men
                                "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
                                "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
                                "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
                                "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
                                "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
                                "{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.2
                                "{B1924580-0C5D-11E0-B655-0013D3D69929}" = MSVCRT Redists
                                "{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
                                "{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
                                "{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
                                "{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
                                "{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Norton Online Backup
                                "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
                                "{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution
                                "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
                                "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
                                "{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software
                                "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
                                "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
                                "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
                                "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
                                "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
                                "{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
                                "{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
                                "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
                                "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
                                "{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
                                "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
                                "{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
                                "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
                                "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
                                "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
                                "{F59205C8-E5FB-43F5-AAB2-16C1760D4F59}" = FaceFilter Studio 2 Trial Edition
                                "{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
                                "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
                                "24MusicBar Toolbar" = 24MusicBar Toolbar
                                "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
                                "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
                                "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
                                "Adobe Shockwave Player" = Adobe Shockwave Player 11.5
                                "avast" = avast! Internet Security
                                "Bally Slots - HotShot" = Bally Slots - HotShot
                                "Barbie(TM) Beauty Boutique(TM) CD-ROM" = Barbie(TM) Beauty Boutique(TM) CD-ROM
                                "Bejeweled Twist" = Bejeweled Twist
                                "conduitEngine" = Conduit Engine
                                "DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
                                "ESET Online Scanner" = ESET Online Scanner v3
                                "Free 3GP Video Converter_is1" = Free 3GP Video Converter version 3.4
                                "Free YouTube Download_is1" = Free YouTube Download 2.10
                                "HijackThis" = HijackThis 2.0.2
                                "HOMESTUDENTR" = Microsoft Office Home and Student 2007
                                "HP Remote Solution" = HP Remote Solution
                                "HyperCam 2" = HyperCam 2
                                "HyperCam Toolbar" = HyperCam Toolbar
                                "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
                                "InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
                                "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
                                "InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
                                "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
                                "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
                                "InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
                                "InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
                                "LEGO Friends" = LEGO Friends
                                "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
                                "Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
                                "MP3 Rocket" = MP3 Rocket
                                "Production Assistant" = Production Assistant 1.0
                                "PROR" = Microsoft Office Professional 2007 Trial
                                "SpeedingUpMyPC_is1" = SpeedingUpMyPC v2.2
                                "TuneUpMedia" = TuneUp Companion 1.6.4
                                "Uninstall_is1" = Uninstall 1.0.0.1
                                "WildTangent hp Master Uninstall" = HP Games
                                "WinLiveSuite" = Windows Live Essentials
                                "Xfire" = Xfire (remove only)
                                "Xvid_is1" = Xvid 1.2.1 final uninstall
                                "ZD Soft Screen Recorder" = ZD Soft Screen Recorder 4.1.3.0
                                "Zynga Toolbar" = Zynga Toolbar
                                 
                                ========== HKEY_CURRENT_USER Uninstall List ==========
                                 
                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
                                "HuluDesktop" = Hulu Desktop
                                 
                                ========== Last 10 Event Log Errors ==========
                                 
                                Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
                                 
                                < End of report >
                                If you choose not to decide, you still have made a choice.

                                SuperDave

                                • Malware Removal Specialist
                                • Moderator


                                • Genius
                                • Thanked: 1020
                                • Certifications: List
                                • Experience: Expert
                                • OS: Windows 10
                                Re: browser redirects
                                « Reply #25 on: March 27, 2011, 12:33:32 PM »
                                Quote
                                Still getting intermittent re-directs.
                                If you look carefully in the ASK warning there is this line:
                                (Makes confusing changes to users' browsers -- increasing Ask's revenues while taking users to pages they didn't intend to visit.)

                                Windows 8 and Windows 10 dual boot with two SSD's

                                glathem40

                                  Topic Starter


                                  Intermediate
                                • Bytor_Snowdog
                                • Thanked: 2
                                  • Experience: Familiar
                                  • OS: Windows 10
                                  Re: browser redirects
                                  « Reply #26 on: March 28, 2011, 06:17:22 PM »
                                  Dave - Do you see something that indicates Ask is still installed on this computer?  Went back over your steps on looking for ask or anything related to it, and I don't see it anywhere. thx
                                  If you choose not to decide, you still have made a choice.

                                  SuperDave

                                  • Malware Removal Specialist
                                  • Moderator


                                  • Genius
                                  • Thanked: 1020
                                  • Certifications: List
                                  • Experience: Expert
                                  • OS: Windows 10
                                  Re: browser redirects
                                  « Reply #27 on: March 29, 2011, 12:32:50 PM »
                                  * Open OTL
                                  * Copy and Paste the following text in the codebox into the Custom Scans/Fixes window.

                                  Code: [Select]
                                  :OTL
                                  FF - prefs.js..browser.search.defaultengine: "Ask.com"
                                  FF - prefs.js..browser.search.defaultenginename: "Ask.com"
                                  FF - prefs.js..browser.search.order.1: "Ask.com"
                                  O18:[b]64bit:[/b] - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
                                  O18:[b]64bit:[/b] - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
                                  O18:[b]64bit:[/b] - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
                                  O18:[b]64bit:[/b] - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
                                  O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
                                  O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
                                  O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
                                  O28:[b]64bit:[/b] - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found

                                  :files
                                  C:\Users\computer 1\AppData\Roaming\ijjigame
                                  C:\Users\computer 1\AppData\Roaming\iWin

                                  :COMMANDS
                                  [resethosts]
                                  [purity]
                                  [emptytemp]
                                  [start explorer]

                                  * Click Run Fix
                                  * OTLI2 may ask to reboot the machine. Please do so if asked.
                                  * Click OK
                                  * A report will open. Copy and Paste that report in your next reply.
                                  Windows 8 and Windows 10 dual boot with two SSD's

                                  glathem40

                                    Topic Starter


                                    Intermediate
                                  • Bytor_Snowdog
                                  • Thanked: 2
                                    • Experience: Familiar
                                    • OS: Windows 10
                                    Re: browser redirects
                                    « Reply #28 on: March 29, 2011, 07:04:31 PM »
                                    Dave - All processes killed
                                    ========== OTL ==========
                                    Prefs.js: "Ask.com" removed from browser.search.defaultengine
                                    Prefs.js: "Ask.com" removed from browser.search.defaultenginename
                                    Prefs.js: "Ask.com" removed from browser.search.order.1
                                    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
                                    ========== FILES ==========
                                    C:\Users\computer 1\AppData\Roaming\ijjigame folder moved successfully.
                                    C:\Users\computer 1\AppData\Roaming\iWin\FamilyFeud3 folder moved successfully.
                                    C:\Users\computer 1\AppData\Roaming\iWin folder moved successfully.
                                    ========== COMMANDS ==========
                                    C:\Windows\System32\drivers\etc\Hosts moved successfully.
                                    HOSTS file reset successfully
                                     
                                    [EMPTYTEMP]
                                     
                                    User: All Users
                                     
                                    User: AppData
                                    ->Temp folder emptied: 0 bytes
                                     
                                    User: computer 1
                                    ->Temp folder emptied: 7740789 bytes
                                    ->Temporary Internet Files folder emptied: 92324218 bytes
                                    ->Java cache emptied: 1184748 bytes
                                    ->FireFox cache emptied: 64463235 bytes
                                    ->Flash cache emptied: 12683037 bytes
                                     
                                    User: Default
                                    ->Temp folder emptied: 0 bytes
                                    ->Temporary Internet Files folder emptied: 67 bytes
                                     
                                    User: Default User
                                    ->Temp folder emptied: 0 bytes
                                    ->Temporary Internet Files folder emptied: 0 bytes
                                     
                                    User: Public
                                    ->Temp folder emptied: 0 bytes
                                     
                                    %systemdrive% .tmp files removed: 0 bytes
                                    %systemroot% .tmp files removed: 0 bytes
                                    %systemroot%\System32 .tmp files removed: 0 bytes
                                    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
                                    %systemroot%\System32\drivers .tmp files removed: 0 bytes
                                    Windows Temp folder emptied: 3426540 bytes
                                    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67764 bytes
                                    RecycleBin emptied: 68302363 bytes
                                     
                                    Total Files Cleaned = 239.00 mb
                                     
                                     
                                    OTL by OldTimer - Version 3.2.22.3 log created on 03292011_195815

                                    Files\Folders moved on Reboot...
                                    C:\Users\computer 1\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
                                    File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

                                    Registry entries deleted on Reboot...
                                    If you choose not to decide, you still have made a choice.

                                    SuperDave

                                    • Malware Removal Specialist
                                    • Moderator


                                    • Genius
                                    • Thanked: 1020
                                    • Certifications: List
                                    • Experience: Expert
                                    • OS: Windows 10
                                    Re: browser redirects
                                    « Reply #29 on: March 30, 2011, 11:45:28 AM »
                                    Any change with the redirects?
                                    Windows 8 and Windows 10 dual boot with two SSD's

                                    glathem40

                                      Topic Starter


                                      Intermediate
                                    • Bytor_Snowdog
                                    • Thanked: 2
                                      • Experience: Familiar
                                      • OS: Windows 10
                                      Re: browser redirects
                                      « Reply #30 on: March 31, 2011, 06:15:48 PM »
                                      Dave - You really super.  No redirects and computer seems to be operating properly.  Is there anything a lay person can do (besides just saying thank you) to insure that the INVALUABLE help that you and this website will carry on ?  Thank you very much !
                                      If you choose not to decide, you still have made a choice.

                                      SuperDave

                                      • Malware Removal Specialist
                                      • Moderator


                                      • Genius
                                      • Thanked: 1020
                                      • Certifications: List
                                      • Experience: Expert
                                      • OS: Windows 10
                                      Re: browser redirects
                                      « Reply #31 on: April 01, 2011, 11:24:39 AM »
                                      Quote
                                      Is there anything a lay person can do (besides just saying thank you) to insure that the INVALUABLE help that you and this website will carry on ?  Thank you very much !
                                      Thank you. The only thing you need to do is to spread the word about us and to help someone else in whatever way you can.
                                      If there are no other issues, we can do some cleanup.


                                      To remove all of the tools we used and the files and folders they created do the following:
                                      Double click OTL.exe.
                                      • Click the CleanUp button.
                                      • Select Yes when the "Begin cleanup Process?" prompt appears.
                                      • If you are prompted to Reboot during the cleanup, select Yes.
                                      • The tool will delete itself once it finishes.
                                      Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
                                      ****************************************************
                                      To set a new Restore Point.

                                      Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode.
                                      Click the Start button , click Control Panel, click System and Maintenance, and then click System.
                                      In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
                                      To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.
                                      This will give you a new, clean Restore Point.
                                      *******************************************************
                                      Clean out your temporary internet files and temp files.

                                      Download TFC by OldTimer to your desktop.

                                      Double-click TFC.exe to run it.

                                      Note: If you are running on Vista, right-click on the file and choose Run As Administrator

                                      TFC will close all programs when run, so make sure you have saved all your work before you begin.

                                      * Click the Start button to begin the cleaning process.
                                      * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
                                      * Please let TFC run uninterrupted until it is finished.

                                      Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
                                      *****************************************************
                                      Looking over your log it seems you don't have any evidence of a third party firewall.

                                      Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

                                      Remember only install ONE firewall

                                      1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
                                      2) Online Armor
                                      3) Agnitum Outpost
                                      4) PC Tools Firewall Plus

                                      If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
                                      *****************************************************
                                      Use the Secunia Software Inspector to check for out of date software.

                                      •Click Start Now

                                      •Check the box next to Enable thorough system inspection.

                                      •Click Start

                                      •Allow the scan to finish and scroll down to see if any updates are needed.
                                      •Update anything listed.
                                      .
                                      ----------

                                      Go to Microsoft Windows Update and get all critical updates.

                                      ----------

                                      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

                                      SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
                                      * Using SpywareBlaster to protect your computer from Spyware and Malware
                                      * If you don't know what ActiveX controls are, see here

                                      Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

                                      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

                                      Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
                                      Safe Surfing!
                                      Windows 8 and Windows 10 dual boot with two SSD's