Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

LAN PROXY HiJacked on Every Reboot. (3rd RePosting) Pls HLP!

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

LAN PROXY HiJacked on Every Reboot. (3rd RePosting) Pls HLP!

Unread postby Confounded » December 23rd, 2011, 7:40 am

Hello really need some help here. This is the 3rd time this has been reposted. Twice closed out do to my errors attaching file, and then adding a DDS post after topic was opened.

Here is the deal.

Recently a file was scanned as safe but on running it all the bells went off in the ISP provided McAfee software. Removing of course resulted in more of the same. Scans and fixes were tempory until the next boot. SpyBot found nothing. McAfee Stinger did a bit more. But it wsa not until running Malware bytes that the PUP FUN malware was spotted and removed. Since then nothing shows up on any scans and I tried loads.

My LAN Proxy is hijacked on every reboot.

ProxyServer = http://79.160.222.20:8080
ProxyOverride = *.local

That is the only symptom I have. I have gone through hIJackthis and removed anything remotely suspicious. I have also gone through the registry and checked entries suggested from googles results.

Here is my lastest HiJackthis log.
DDS.TXT and ATTACH.TXT follow below that!
_____________________________________________

Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\WINDOWS\system32\mfevtps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Belkin Office Keyboard\kbdap32a.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\VoipCheapCom\VoipCheapCom.exe
C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee Security Scan\3.0.229\SSScheduler.exe
C:\Documents and Settings\Karin_2\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\SearchProtocolHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk/ig/dell?hl=en&c ... channel=uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://79.160.222.20:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local


O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Audio Web Cam 31
O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Belkin Office Keyboard\kbdap32a.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Trend Micro RUBotted V2.0 Beta] C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [VoipCheapCom] "C:\Program Files\VoipCheapCom\VoipCheapCom.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Advanced SystemCare 5] "C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - Startup: Dropbox.lnk = C:\Documents and Settings\Karin_2\Application Data\Dropbox\bin\Dropbox.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.229\SSScheduler.exe
O8 - Extra context menu item: Open Picture in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~3\Office\1033\PHDINTL.DLL/phdContext.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.euro.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scan ... ProExe.cab
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} (DellSystemLite.Scanner) - http://support.euro.dell.com/systemprof ... emLite.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{29FBD7C5-6175-4E2C-ACCD-C794B5C99DA5}: NameServer = 192.168.1.254
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\mcsniepl.dll
O23 - Service: McAfee Application Installer Cleanup (0181001324360532) (0181001324360532mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\018100~1.EXE (file missing)
O23 - Service: Advanced SystemCare Service 5 (AdvancedSystemCareService5) - IObit - C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - Unknown owner - C:\WINDOWS\system32\brsvc01a.exe (file missing)
O23 - Service: Googles oppdateringstjeneste (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.229\McCHSvc.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: Trend Micro RUBotted Service (RUBotSrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe

==== End Of HiJACKthis File ===========================

DDS.TXT
(after LAN R1 enteries shown above in red were removed. These reapper on reboot!)

(Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
Run by Karin_2 at 0:56:22 on 2011-12-22
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1304 [GMT 0:00]
.
AV: Doctor Web Anti-Virus *Enabled/Outdated* {3454C8F1-ECBC-4180-A6F4-04632FBA762B}
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled*
.
============== Running Processes ===============
.
C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\svchost.exe -k HPService
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\mfevtps.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Belkin Office Keyboard\kbdap32a.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\VoipCheapCom\VoipCheapCom.exe
C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee Security Scan\3.0.229\SSScheduler.exe
C:\Documents and Settings\Karin_2\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\NOTEPAD.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Page_URL = www.google.co.uk/ig/dell?hl=en&client=d ... channel=uk
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [VoipCheapCom] "c:\program files\voipcheapcom\VoipCheapCom.exe" -nosplash -minimized
uRun: [Advanced SystemCare 5] "c:\program files\iobit\advanced systemcare 5\ASCTray.exe" /AutoStart
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [BigDogPath] c:\windows\VM_STI.EXE Audio Web Cam 31
mRun: [OFFICEKB] c:\program files\belkin office keyboard\kbdap32a.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [Trend Micro RUBotted V2.0 Beta] c:\program files\trend micro\rubotted\RUBottedGUI.exe
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\docume~1\karin_2\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\karin_2\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.0.229\SSScheduler.exe
uPolicies-explorer: NoInstrumentation = 1 (0x1)
IE: Open Picture in &Microsoft PhotoDraw - c:\progra~1\micros~3\office\1033\PHDINTL.DLL/phdContext.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
LSP: mswsock.dll
Trusted Zone: bt.com\www.businessdirect
Trusted Zone: ebay.co.uk\signin
Trusted Zone: firstdirect.com\www*
Trusted Zone: firstdirect.com\www.banking
Trusted Zone: firstdirect.com\www.banking*
Trusted Zone: hmrc.gov.uk\online
Trusted Zone: internet
Trusted Zone: ispro.net\cp
Trusted Zone: mcafee.com
Trusted Zone: modem-help.co.uk
Trusted Zone: mybusinessbank.co.uk\www
Trusted Zone: northernrock.co.uk\www
Trusted Zone: paypal.com\www
Trusted Zone: plus.net\portal
Trusted Zone: plus.net\www
Trusted Zone: santander.co.uk\applyonline
Trusted Zone: shareview.co.uk\www
Trusted Zone: xe.com\fx2
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.euro.dell.com/systemprofiler/SysPro.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/ ... ontrol.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://i.dell.com/images/global/js/scan ... ProExe.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.euro.dell.com/systemprof ... emLite.CAB
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/aut ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/s ... wflash.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{29FBD7C5-6175-4E2C-ACCD-C794B5C99DA5} : DhcpNameServer = 192.168.1.254
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\McSnIePl.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {56F9679E-7826-4C84-81F3-532071A8BCC5} - No File
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\karin_2\application data\mozilla\firefox\profiles\efdrcit6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://radiobar.toolbarhome.com/?hp=df
FF - prefs.js: keyword.URL - hxxp://radiobar.toolbarhome.com/search.aspx?srch=ku&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\progra~1\mcafee\msc\npMcSnFFPl.dll
FF - plugin: c:\program files\common files\motive\npMotive.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mcafee\siteadvisor\NPMcFFPlg32.dll
FF - plugin: c:\program files\mcafee\supportability\mvt\NPMVTPlugin.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
.
---- FIREFOX POLICIES ----
# Mozilla User Preferences/* Do not edit this file. * * If you make changes to this file while the application is running, * the changes will be overwritten when the application exits. * * To make a manual change to preferences, you can visit the URL about:config * For more information, see hxxp://www.mozilla.org/unix/customizing.html#prefs */FF - user.js: app.update.lastUpdateTime.addon-background-update-timer - 1300737946
base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA7PT7/3zF6/9Ptu//RbHx/0227/+Tzvb/9vv5/97h0f9JeBz/NHoA/z98Av9AfAD/PHsA/0F6AP8AAAAA/vz7/1+33/8Mp+z/FrHw/xWy8f8bs/T/Hqrx/3zE7v////7/t8qp/zF2A/87gwH/P4ID/z59AP8+egD/Q3kA/97s8v8botj/ELn3/wy58f8PtfL/D7Lw/xuz9P8vq+f/8/n///779v9KhR3/OYYA/0GFAv88hgD/QIAC/z17AP/0+/j/N6bM/wC07/8Cxf7/CsP7/wm+9v8Aqur/SrDb//7+/v///P7/VZEl/zSJAP87jQD/PYYA/0OBBf8+fQH///3//9Dp8/84sM7/CrDf/wC14/8CruL/KqnW/9ns8f/8/v//4OjX/z+GDf85kAD/PIwD/z2JAv8+hQD/PoEA/9C7pv/97uv////+/9Xw+v+w3ej/ls/e/+rz9///////+/z6/22mSf8qjQH/OJMA/zuQAP85iwL/PIgA/zyFAP+OSSL/nV44/7J+Vv/AkG7/7trP//7//f/9//7/6/Lr/2uoRv8tjQH/PJYA/zuTAP87kwD/PY8A/z2KAP89hAD/olkn/6RVHP+eSgj/mEgR//Ho3//+/v7/5Ozh/1GaJv8tlAD/OZcC/zuXAv84lAD/O5IC/z2PAf89iwL/OIkA/6hWFf+cTxD/pm9C/76ihP/8/v//+////8nav/8fdwL/NZsA/zeZAP83mgD/PJQB/zyUAf84jwD/PYsB/z6HAf+fXif/1r6s//79///58u//3r+g/+3i2v/+//3/mbiF/yyCAP87mgP/OpgD/zeWAP85lgD/OpEB/z+TAP9ChwH/7eHb/////v/28ej/tWwo/7tUAP+5XQ7/5M+5/////v+bsZn/IHAd/zeVAP89lgP/O5MA/zaJCf8tZTr/DyuK//3////9////0qmC/7lTAP/KZAT/vVgC/8iQWf/+//3///j//ygpx/8GGcL/ESax/xEgtv8FEMz/AALh/wAB1f///f7///z//758O//GXQL/yGYC/8RaAv/Ojlf/+/////////9QU93/BAD0/wAB//8DAP3/AAHz/wAA5f8DAtr///////v7+/+2bCT/yGMA/89mAP/BWQD/0q+D///+/////P7/Rkbg/wEA+f8AA/z/AQH5/wMA8P8AAev/AADf///7/P////7/uINQ/7lXAP/MYwL/vGIO//Lm3P/8/v//1dT2/woM5/8AAP3/AwH+/wAB/f8AAfb/BADs/wAC4P8AAAAA//z7/+LbzP+mXyD/oUwE/9Gshv/8//3/7/H5/zo/w/8AAdX/AgL6/wAA/f8CAP3/AAH2/wAA7v8AAAAAgAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgAEAAA==);
base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAQAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/Pz/PV1dX/z8/P98/Pz+PPz8/QAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/Pz9AXl5e/9zc3P+NjY7/gYGB/1NTU/8/Pz/vPz8/rz8/P2A/Pz8QAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPz8/v6Wlpv/R0dH/vMLR/7i6wP+SkpL/tbW2/46Ojv9jY2P/R0dH/z8/P88/Pz+APz8/IAAAAAAAAAAAPz8/QFRUVP/Nzc7/yM7d/7/P9//B0fr/wMvm/+Tk5P/T09T/nJyc/7u7vP+dnZ7/YWFh/0VFRf8/Pz8wAAAAAD8/P5+Xl5f/y8vM/8zY9/+/zvf/wdD5/6u1zv/+/v7//v7+//j4+P/v7+//3Nzc/6SkpP+BgYL/Pz8/zz8/PyBJSUr/xcXF/83Q2P+svOT/jZ3F/5Ggyf+wtsX/wsLC/3p6ev+SkpL/+Pj4/+7u7//MzM3/39/g/0tLS/8/Pz+fL014/8nJyf/P2fL/vs73/8HR+f+ls9n/19fX/2BgYP9zfYX/QWZ8/3l5ef+9vb7/2NjZ/7u7vP8/Pz/vSkpK71qAuv+hscv/sL/o/4ubw/+Tosv/nqe+//39/f8/Pz//PsDx/wGIx/8vU2n/g4OD/7Kysv94eHn/Pz8/70hMUv93mc//fJ7Y/7fG7/+8y/T/n6/X/8XHzP/ExMT/YGBg/xWiwv8CmNr/CH+//1VVVf/c3N3/Wlpa/z8/P1A/Pz/vjKnY/3u28f8jb9H/XIbT/4SYv//5+fn/+vr7/7q6uv83Ulf/Abv1/wKLyv8gZpL/V1dX/z8/P+8AAAAAPz8/n2yCkv8EmPP/AJ7//wKP9P8HdNv/GWvI/1eGxv9iga//UmaC/yCKn/8Bn+P/BIPB/ztESv8/Pz+AAAAAAD8/PxA/Pz+fPz8//ytie/8YgLf/CI/n/wCP//8Ahv//AX76/wdy4/8zUGP/CbPh/wGOzf8Ybp//Pz8/vwAAAAAAAAAAAAAAAD8/PxA/Pz9gPz8/nz8/P983SVf/K1Z7/yBgn/8YZ7f/I1uT/ytue/8Cre7/AYfG/y9Tav8/Pz9gAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPz8/ID8/P0A/Pz+APz8/gD8/P78/Pz/vEKjM/xyMvv9kgI//Pz8/7wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPz8/QERERP96gZz/dYGy/z8/P/8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/Pz+fTVFi/z8/P+8/Pz9Q4P8AAMAPAADAAQAAgAAAAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAEAAAABAAAAAQAAwAAAAPwAAAD/4AAA//AAAA==\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>);
base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAQAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADg42v84ONr/p6f5/6en+f+np/n/p6f5/6en+f+np/n/p6f5/6en+f+np/n/p6f5/6en+f+np/n/ODja/zg42v84ONr/ODja/+Li////////////////////////////////////////////////////////4uL//zg42v84ONr/ODja/zg42v+np/n/4uL/////////////////////////////////////////////4uL//6en+f84ONr/ODja/zg42v84ONr/4uL//6en+f/i4v////////////+BgfL/gYHy////////////4uL//6en+f/i4v//ODja/zg42v84ONr/ODja///////i4v//p6f5/7a2//+BgfL/Wlrp/1pa6f+BgfL/trb//6en+f/i4v///////zg42v84ONr/ODja/zg42v///////////7a2//+BgfL/Wlrp/zg42v84ONr/Wlrp/4GB8v+2tv////////////84ONr/ODja/zg42v84ONr///////////+BgfL/Wlrp/zg42v+2tv//trb//zg42v9aWun/gYHy////////////ODja/zg42v84ONr/ODja//////+BgfL/Wlrp/zg42v+2tv////////////+2tv//ODja/1pa6f+BgfL//////zg42v84ONr/ODja/zg42v+BgfL/Wlrp/zg42v+2tv///////////////////////7a2//84ONr/Wlrp/4GB8v84ONr/ODja/zg42v84ONr/ODja/zg42v+2tv//////////////////////////////////trb//zg42v84ONr/ODja/zg42v84ONr/ODja/zg42v+BgfL/p6f5/6en+f+np/n/p6f5/6en+f+np/n/p6f5/6en+f+BgfL/ODja/zg42v84ONr/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAP//AAD//wAA//8AAA==\ hassearch=\true\ type=\menu-button\ class=\gtb-custombutton gtbHelperIcon gtbButtonWithSeparateMenu\><menupopup class=\gtbButtonFeedMenupopup\/></toolbarbutton>);
base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAQAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAF5+kBBefpCAaoiZ73KOnv9efpBAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAXn6QIF5+kI91kaDvscLK//b5+f/e5en/Xn6QvwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABefpAgXn6Qn3mVo//F0tj/+/z8/////////////////4mirv9efpBAAAAAAAAAAAAAAAAAAAAAAAAAAABefpCviaKu/9Td4v/7/Pz/////////////////39Hb/7qhs//T2t//Xn6QvwAAAAAAAAAAAAAAAAAAAAAAAAAAeZWj///////////////////////YzNX/royk/6p8nP+qfJz/zbvI/4mirv9efpAgAAAAAAAAAABefpCvXn6Qv15+kP/O2N7/+fb4/9O/zf+rhJ//rH2d/7B+of+wfqH/sH6h/6uJof/T3eH/Xn6QnwAAAAAAAAAAhp6s///////19/j/kKaz/8+9yv+qfJz/sH6h/7B+of+wfqH/tYKm/8mQuP/kptL/7drn/3mVo/9efpAgAAAAAIaerP///////////6+/yP/Q1tz/p4Kc/7B+of+wfqH/sH6h/86TvP//t+n//7fp/+Gw0//E0df/Xn6QnwAAAACGnqz/2O7U/7Hdqf+n1KL/cpKa/8mxwv+xf6L/sH6h/7B+of/wrNz/+bTk/+iq1f/kw9r/+fv7/3OQn/8AAAAAhp6s/7Hdqf9j4Er/Y+BK/2Gvbf+8ws3/46bR/+al0//Xm8X/5K3U/+fN3//69/n/9Pf4/7DByv9kg5TvAAAAAIaerP+v1aH/Yt1H/2PgSv9j2k7/cpSZ/+TD2v/ksdX/6dPj//r3+f/m7O7/nLG8/2SEld9efpBgXn6QEAAAAACGnqz/q8mU/1zIMv9j4Er/WcEr/1+sav+/yNH/6u7w/6S2wP+HoK3/ZYSVz15+kGAAAAAAAAAAAAAAAAAAAAAAhp6s/6vJlP9Vsx3/X9I8/1OsFv9Tphr/XYGI/12BiP+Fopj/fJal/15+kBAAAAAAAAAAAAAAAAAAAAAAAAAAAIaerP+ryZT/VZ8e/1WfHv9Vnx7/VZ8e/1WfHv9Vnx7/qsmU/4aerP8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACGnqz//v7+//39/f/9/f3//f39//39/f/9/f3//f39//7+/v+Gnqz/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAaYeX74aerP+Gnqv/hp6r/4aeq/+Gnqv/hp6r/4aeq/+Gnqv/aYeX7wAAAAAAAAAAAAAAAAAAAAAAAAAA/wcAAPwHAADwAwAA4AMAAOABAACAAQAAgAAAAIAAAACAAAAAgAAAAIAAAACABwAAgA8AAIAfAACAHwAAgB8AAA==\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>);
base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAQAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAE3LlP8roW7/K6Fu/yuhbv8roW7/K6Fu/yuhbv8roW7/K6Fu/yuhbv8AAAAAAAAAAAAAAAAAAAAAAAAAACuhbv9Ny5T/P8GJ/z/HjP8/xYz/PsWL/z7Fi/8+xYv/PsWL/z7Fi//S3dz/K6Fu/wAAAADMnV3/oXA3/29NJv8roW7/TcuU/z/AiP9M0pj/StGX/0nPlf9FzZL/Q8qQ/0HIjv8/x4z/093d/yuhbv+hcDf/zJ1d/8d5TP+IYTX/K6Fu/03LlP8/vYf/Uded/0/Vm/9N05n/StCW/0fOk/9Ey5D/QcmO/9Xf3v8roW7/oXA3/8ydXf/LklL/imM3/yuhbv9Ny5T/QLqE/1bco/9U2qD/Uded/07Umv9K0Zb/R86T/0PLkP/Y4eH/K6Fu/6FwN//MnV3/2KBh/5NmQf8roW7/TcuU/0C3hP9c4af/Wd+l/1bbov9S2J7/TtSa/0rRlv9GzZL/2+Tj/yuhbv+hcDf/zJ1d/92lZv+XXET/K6Fu/03LlP8/tYL/Yuas/1/jqf9a36X/Vtyh/1HXnv9Q1Zr/Sc+V/+Dn5v8roW7/oXA3/8ydXf/ioWv/mnRJ/yuhbv9Ny5T/QLOB/2fqsf9n67L/Zeiv/13iqP9V2qD/T9Wb/0rRl//k6+r/K6Fu/6FwN//MnV3/57By/55/Tf8roW7/TcuU/0Cyf/9r7bX/bfC3/2frsf9f46n/Vtyh/1HXnf9M05j/6e7u/yuhbv+hcDf/zJ1d/+y1d/+he1D/K6Fu/yuhbv9AsH//bfC3/2nss/9j567/XuKp/1jdpP9S2J7/TdOZ/+7y8f8roW7/oXA3/8ydXf/wuXv/o3dT/yuhbv9Ny5T/QLB//27xuf9q7bT/ZOiv/1/jqv9Y3qT/U9ie/03Tmf/y9fX/K6Fu/6FwN/+hcDf/oXA3/6V/Vf8roW7/TcuU/yuhbv8roW7/K6Fu/yuhbv8roW7/K6Fu/yuhbv8roW7/9vj4/yuhbv+hcDf/zJ1d//S0f/+lc1X/TcuU/yuhbv////////////////////////////////////////////r7+/8roW7/oXA3/8ydXf+hcDf/oXA3/6FwN/8roW7/K6Fu/yuhbv8roW7/K6Fu/yuhbv8roW7/K6Fu/yuhbv8roW7/AAAAAMydXf+hcDf/////////////////////////////////////////////////oXA3/wAAAAAAAAAAAAAAAAAAAAAAAAAAoXA3/6FwN/+hcDf/oXA3/6FwN/+hcDf/oXA3/6FwN/+hcDf/oXA3/wAAAAAAAAAAAAAAAAAAAAAAAAAA+AEAAPAAAACAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAADwAAgB8AAA==\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>);
base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAQAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAF5+kBBefpC/Xn6Q/15+kP9efpC/Xn6QEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABefpDPX32N/zxGTP8sNjz/XXuM/15+kM8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABefpBAXn6Q/4WPlf9mZmb/YmJi/3yGi/9efpD/Xn6QQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAXn6QQF5+kP+Cio7/b29v/2BgYP9+hor/Xn6Q/15+kEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAF5+kFBefpD/eK7D/3OgsP9nlqf/cae8/15+kP9efpBQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABefpCAXn6Q/0jD8v9mwOD/ZsDg/4vZ9/9efpD/Xn6QgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAXn6Qn0+Iov89wPH/DpvN/xCbzf9szvT/VISc/15+kJ8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAXn6QEF5+kO9XnL7/mN73/0u/5f9Cstb/ddb2/3Knwf9efpDvXn6QEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAF5+kJ9ag5f/oN/0/6Pr//9zzer/bcbi/5vo//+C3/f/WYOX/15+kJ8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABefpD/YarB/8Tw//920/X/Z8Dg/3LG5f9vyuv/qen//1mmwf9efpDvAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAXn6Q/1zE4/+b5P//gM3r/6DZ8P/F7f//W7bW/8nw//+Cy+P/Xn6Q/wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAF5+kP94w9z/qOb//5rX8P/C3Oj/x93o/7Xd6///////ksjc/15+kP8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABefpDflq26/8Pu//++6///2vP///r9////////zvD//3Okuv9efpDfAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAXn6QgF5+kP/a5er/0/L///H6////////+f3//53U6v9efpD/Xn6QgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABefpDPaIaX/6S2wf/U3uP/19/j/4Wtwf9efpD/Xn6QzwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAF5+kIBefpDvXn6Q/15+kP9efpDvXn6QgAAAAAAAAAAAAAAAAAAAAAAAAAAA+B8AAPgfAADwDwAA8A8AAPAPAADwDwAA8A8AAOAHAADgBwAA4AcAAOAHAADgBwAA4AcAAOAHAADwDwAA+B8AAA==\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>);
base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAQAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJJmQZaSZkH/kmZB/5JmQf+SZkH/kmZBlgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACSZkH/x7GP/7mZbf+2lGn/vqeF/5JmQf8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAkmZB/7+hdf+wgUn/rHxE/7aUaf+SZkH/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJJmQf/Dp3r/s4dP/7CBSf+5mW3/kmZB/wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACSZkH/x6t//7eOVf+zh0//vZxx/5JmQf8AAAAAAAAAAAAAAAAAAAAAAAAAAJJmQZaSZkH/kmZB/5JmQf+SZkH/kmZB/8iqe/+7lFv/t45V/7ybbP+SZkH/kmZB/5JmQf+SZkH/kmZB/5JmQZaSZkH/49iy/9vImf/Yw5X/1b+R/9C0hP/HpW7/v5ph/7uUW/+6lF7/vJts/72ccf+5mW3/tpRp/76nhf+SZkH/kmZB/+XWqf/awon/1ruD/9K2fv/PsHf/yqdu/8SgZv+/mmH/u5Rb/7eOVf+zh0//sIFJ/6x8RP+2lGn/kmZB/5JmQf/r4bz/5dWn/+PRpP/fy5//28SX/9a7i//Pr3v/xaJq/7+aYf+7lFv/t45V/7OHT/+wgUn/uZlt/5JmQf+SZkH/8u3X//DozP/v5sr/7OLH/+jcvP/gz6j/2L+S/9CygP/Kqnb/yKt8/8esgP/EqHz/v6F1/8exj/+SZkH/kmZBlpJmQf+SZkH/kmZB/5JmQf+SZkH/6d2+/9/Mo//YvpD/1buQ/5JmQf+SZkH/kmZB/5JmQf+SZkH/kmZBlgAAAAAAAAAAAAAAAAAAAAAAAAAAkmZB/+3jyf/k063/28WZ/9nFm/+SZkH/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJJmQf/v5sz/59iz/9/Lnv/byZ7/kmZB/wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACSZkH/8OnO/+rduP/j0aX/386j/5JmQf8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAkmZB//Pv2v/v58v/6+C+/+fevv+SZkH/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJJmQZaSZkH/kmZB/5JmQf+SZkH/kmZBlgAAAAAAAAAAAAAAAAAAAAAAAAAA+B8AAPgfAAD4HwAA+B8AAPgfAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD4HwAA+B8AAPgfAAD4HwAA+B8AAA==\ type=\menu\ class=\gtb-custombutton gtbHelperIcon gtbWholeMenuGadgetButton\/>);
base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAQAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAlZKKRpWSio2VkorHlZKK8JWSivCVkorHlZKKjZWSikYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACVkooglZKKjJWSivO9vLf/1NHN/9fQzf/Wz8r/2NTQ/8jFwf+Wk4vzlZKKjJWSiiAAAAAAAAAAAAAAAACVkooglZKKo5qfnP+YhHn/c11M/3VdTP+QfG3/o5KG/6mZjf+djYD/pZWJ/6Odlf+VkoqjlZKKIAAAAAAAAAAAlZKKjHmeov9SZV7/YUEu/4pxZP/Vz83/////////////////+vr7/413aP9yWUj/qKSd/5WSiowAAAAAlZKKRpWSi/NSeHf/P1FI/2WJif/U3d7/3tzd/8vLzP/Iycn/6Orq//////+UgHP/bVVD/8C/vP+VkorzlZKKRpWSio1ij6D/T2hp/0qDi/9M4f//lbvE/7y0sv/l5+j/5eXn/7W4uP/Ew8T/hG5g/2FLO/+yran/tLCn/5WSio2VkorHZouf/154gv8tp+X/Nr/7/726tf/e2tf/eHFf/3hxX//b29n/sbK0/46Bd/+KdGH/pYxo/8euf/+VkorHlZKK8F95r/9TbKf/DWX//0l+0///9+X/eHFf/wAAAAAAAAAAeHFf/+vw9/+/tKP/48eX/9y6gv/Xtnz/lZKK8JWSivBsbrn/Ulm8/w8m/v9UX8T///ro/3hxX/8AAAAAAAAAAHlxYP/u8P7/u5p0/+GpaP/gsXz/37uN/5WSivCVkorHvLS1/7ixs//GxM7/zMvH/7e3tP/a2NX/eHFf/3hxX//e2tr/uLe9/1yhXv9dkzT/i4co/6mGOP+VkorHlZKKjbayqv/SzcL/2djP/+fn5P/ExMT/srKz/+Tl5v/m5ej/urS4/4m1o/9QzIz/PLpy/y6wX/9immX/lZKKjZWSikaVkorz3NvZ/+Hg3//u7u7/+/r6/+Tl5f/Hx8f/yMfI/9jW1v+u1Mb/fs6t/2PUoP9VwYT/lJKK85WSikYAAAAAlZKKjLOyrP/u7uv/9/X1//f4+P/6+vr//v7+///////39Pf/19bX/5eajP9/v6D/hKuV/5WSiowAAAAAAAAAAJWSiiCVkoqjuLax//Dw7//39/j/9fX3//X19f/5+fn/8O3t/8i+uv+rm5P/lZWL/5WSiqOVkoogAAAAAAAAAAAAAAAAlZKKIJWSioyWk4vzyMbC/+Xi4P/u7e3/6OXi/87Kxf+xq6T/lZKK85WSioyVkoogAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAlZKKRpWSio2VkorHlZKK8JWSivCVkorHlZKKjZWSikYAAAAAAAAAAAAAAAAAAAAA8A8AAMADAACAAQAAgAEAAAAAAAAAAAAAAAAAAAGAAAABgAAAAAAAAAAAAAAAAAAAgAEAAIABAADAAwAA8A8AAA==\ hassearch=\true\ type=\menu-button\ class=\gtb-custombutton gtbHelperIcon gtbButtonWithSeparateMenu\><menupopup class=\gtbButtonFeedMenupopup\/></toolbarbutton>);
base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAQAQAAAAAAAAAAAAAAAAAAAAAAAD//////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////4yMjP9OV1r/PktM/7W1tf////////////////////////////////////////////////////////////////8hJCj/ZL72/1Oezf9ra2v/////////////////////////////////////////////////////////////////SkpK/1Oi1f9Dhqz/lJSU/////////////////97e3v/39/f//////////////////////////////////////4yMjP9Lkrz/MmqM/+fn5////////////56Zl/+QQTD/bktF/8bHxv////////////////////////////////+cnJz/Q4a0/ylVa//Nzc3/kIyM/3dHPv/eXDn//2xC//9sQv+tTDH/hGRb/5eXl/+1tbX/3t7e////////////ra2t/0OGrP9LboT/lC8h/95UMf/3XDn//2xC//9sQv//bEL//2xC//dgOf/GRDH/czAh/5SUlP///////////97e3v9Afpj/X3mH/3ssGP/nUDH/91g5/7VMMf+cQCn/nDsp/61IKf/3WDH/71Ax/0oYEP/n5+f////////////39/f/GDhS/21vcv8wHxf/nDMh/5wzIf/eTDH//1Q5//9UOf/nTDH/pTch/4wrGP9EJh//////////////////jIyM/zFJWv9SLCn/zkQx//9UOf//VDn//1Q5//9UOf//VDn//1Q5//9UOf//VDn/pTMh/0w3Mf+xsLH//v7+/z4fF//GQCn/xkxC/71QSv+cREL/pURC/3swMf9rJBj/vUAp//9UOf//VDn//1Q5//9UOf//UDn/ShgQ/zAzMP/v7+//jIyM/2ZBN/+MKyH/70wx//9UOf//VDn/xkAp/85EMf//VDn//1Q5/95IMf97KBj/Nh8Y/4SGhP/n5+f/////////////////xsbG/1dVUv9wJx//xkAp//9QOf/GOyn/cyQY/1IzMP9zc3P/xsbG////////////////////////////////////////////5+fn/4SEhP82LCn/e3t7/97e3v//////////////////////////////////////////////////////////////////////////////////////////////////////////////////////AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>);
base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAQAQAAAAAAAAAAAAAAAAAAAAAAAD///////////////////////////////////////////////////////////////////////////////////////////////////////////r1/P/Ql+T/rkzQ/58qx/+eKMf/pz7M/8R93f/x4ff//////////////////////////////////////+7a9f+nPcz/nijG/8F32//ar+r/3rjs/8uM4f+lOcv/nSfG/9uv6v////////////////////////////Lk9/+jM8j/s1jT//To+f///////////////////////P/9/8iG3/+ZIcT/3bTr//////////////////////+/c9r/q0fN//v2/P//////////////////////////////////////xoHe/6Atx//27Pr//////+3t7f9eXl7/QEBA/7Krs/+SkZH/uLi4//Dv7/9XV1f/VVVV/8bFxf+bmpr/PDw8/4eAiP+2YtP/amNt/8XFxf9paWn/enp6/8PDw/8fHx//ZWVl/6SkpP/q6ur/AAAA/4GBgf/j4+P/JSUl/8vLy/8yMjL/enl6/05OTv/z8/P/TU1N/8C/v//+/v7/Ly8v/1hYWP+ampr/6ejo/wEBAf/R0dH/z87O/0lJSf//////Xl5e/0xMTP+Hh4f//////7a1tf8fHx//ODg4/1JSUv/Ix8f/Hx8f/35+fv8NDQ3/KSkp/7Oysv9JSUn//////15eXv9MTEz/Kioq/39/f///////0brX/6Bts//9/P3//////+Tk5P/FxMT/Ly8v/9PS0v/Y19f/1NTU///////a2dn/gYGB/2ZmZv/T0tL//////+zW9P+aIMX/5cXw////////////6+vr/zIyMv//////////////////////+vX8/7Vo0P/dwub/////////////////tVzU/6xIz//7+P3////////////9/Pz//////////////////////8aB3v+gLcf/9+36//////////////////Lk+P+jM8n/s1jT//To+f///////////////////////P/9/8mH4P+bIcT/3bTr////////////////////////////7tr1/6c9zP+eKMb/wXbb/9uw6v/fuu3/yozg/6Y6zP+dJ8b/2q3p///////////////////////////////////////69fz/z5bj/65M0P+fKsf/nSfG/6g+zP/DfNz/8eH3////////////////////////////////////////////////////////////////////////////////////////////////////////////AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>);
base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAQAQAAAAAAAAAAAAAAAAAAAAAAAD/////////////////////////////////////////////////////////////////////////////////////ZGhp/2Roaf9kaGn/ZGhp/2Roaf9kaGn/ZGhp/2Roaf9kaGn/ZGhp/2Roaf9kaGn/ZGhp/2Roaf9kaGn//////2dsa//97+X//e/k//3v5f/97+X//e/l//3v5f/97+X//e/l//3v5f/97+X//e/l//3v5f/97+X/Z2xr//////9scG///fDn/83EuP/NxLj/zcS4/83EuP/NxLj/zcS4/83EuP/NxLj/zcS4//3w5//98Of//fDn/2xwbv//////cXZz//3z6v/NxLj///7+/83EuP///v7/zcS4///+/v/NxLj///7+/83EuP/98+r//fPq//3z6v9ydXP//////3d7d//+9O//zcS4/83EuP/NxLj/zcS4/83EuP/NxLj/iYLP/zQy7v80Mu7/iYLP/83EuP/+9O//d3t2//////9/gnr//vfz/83EuP///v7/zcS4///+/v/NxLj///7+/zQy7v/Av/7/mpPJ/0BA///NxLj//vfz/3+Cev//////hoiA///59//NxLj/zcS4/83EuP/NxLj/zcS4/83EuP80Mu7/mpPJ/5qTyf80Mu7/zcS4///59/+FiID//////42Phf///Pv///37///8+////Pv///z7/83EuP///v7/iYLP/0BA//80Mu7/qqn+/83EuP///Pv/jI+F//////+Ulor///39///+/v///f3///39///9/f/NxLj/zcS4/83EuP/NxLj/zcS4/83EuP/NxLj///39/5SWif//////mp2P///9/f///f3///39///9/f///f3///39///9/f///f3///39///9/f///f3///39///9/f+bnY///////6Kkk//5ewj/+XsI//l7CP/5ewj/+XsI//l7CP/5ewj/+XsI//l7CP/5ewj/+XsI//l7CP/5ewj/oqOT//////+oqZf/5H4L//TLbv/0zG3//6QL//TNbf/ygQf/8oEH//KBB//ygQf/8oEH//KBB//ygQf/63sK/6iql///////rbCc//TAa//0wGv/9MBr//TAa//0wGv/9MBr//TAa//0wGv/9MBr//TAa//0wGv/9MBr//TAa/+tr5z///////////+ys5//srSf/7K0nv+ys57/sbSe/7Kznv+xtJ//srOf/7Kznv+xs57/sbOf/7G0n/+xtJ//////////////////////////////////////////////////////////////////////////////////////////////////AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==\ hassend=\true\ hassearch=\true\ type=\menu-button\ class=\gtb-custombutton gtbHelperIcon gtbButtonWithSeparateMenu\><menupopup class=\gtbButtonFeedMenupopup\/></toolbarbutton>);
base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAQAQAAAAAAAAAAAAAAAAAAAAAAAD8/Pz//Pz8//z8/P/8/Pz//Pz8//z8/P/8/Pz//Pz8//z8/P/8/Pz//Pz8//z8/P/8/Pz//Pz8//z8/P/8/Pz/iHRk/4h0ZP+IdGT/h3Ji/4dyYv+CbVz/gm1c/4JtXP9/alj/f2pY/35oV/9+aFf/fmhX/3liT/95Yk//eWJP/4t4af87shf/e9he/4DbZP+b44X/gNtk/5vjhf+b44X/m+OF/5vjhf+b44X/m+OF/5vjhf+b44X/m+OF/3liT/+Oe2z/oMt9/zuyF/+A22T/gNtk/4DbZP+A22T/gNtk/4DbZP+A22T/gNtk/4DbZP+A22T/gNtk/5vjhf95Yk//kX5w/+3p1f+AxWD/S7wp/4DbZP+A22T/gNtk/4DbZP+A22T/gNtk/4DbZP+A22T/gNtk/3vYXv+b44X/eWJP/5SBdP/x7d7/8e3e/3fFW/87shf/UL8v/2XLRv972F7/gNtk/4DbZP+A22T/gNtk/4DbZP+A22T/m+OF/35oV/+WhHj//Pz8//Ty5v/49+//8vrv/73ksf97yWP/VsI1/4DbZP+A22T/gNtk/4DbZP+A22T/gNtk/5vjhf9+aFf/mYd7//z8/P/08ub/+vnz//z8/P/8/Pz/5fTg/0C2Hf+A22T/gNtk/4DbZP+A22T/gNtk/4DbZP+b44X/fmhX/5yKfv/8/Pz/9PLm//r58//8/Pz//Pz8//z8/P9IsyP/gNtk/4DbZP+A22T/gNtk/4DbZP+A22T/m+OF/35oV/+ejIH//Pz8//Lv4P/39ez//Pz8//z8/P/8/Pz/e8lj/1C/L/911Vj/gNtk/4DbZP+A22T/gNtk/5vjhf9+aFf/oI6E//r58//x7d7/9PLm//r58//8/Pz//Pz8//L67/+i2ZL/U7k0/0izI/9w0lL/gNtk/4DbZP+A22T/fmhX/6GQhv/6+fP/7enV//Ht3v/39ez/+vnz//r58//8/Pz//Pz8//r58/+43qX/QLYd/4DbZP+A22T/uuur/35oV/+kk4n/+vnz/+nkzf/t6dX/8e3e//Ty5v/39ez/9/Xs//f17P/39ez/8O3d/1y6Ov9rz0z/gNtk/6Lljf+CbVz/pJOJ//z8/P/08ub/9/Xs//Ty5v/39ez/9/Xs//f17P/39ez/9PLm//Dt3f/J37L/SLMj/0u8Kf9ly0b/f2pY/6STif+kk4n/oI6E/6COhP+ejIH/nIp+/5mHe/+WhHj/lIF0/5F+cP+Oe2z/jnts/4dyYv+HcmL/gm1c/4JtXP/8/Pz//Pz8//z8/P/8/Pz//Pz8//z8/P/8/Pz//Pz8//z8/P/8/Pz//Pz8//z8/P/8/Pz//Pz8//z8/P/8/Pz/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>);
base64,iVBORw0KGgoAAAANSUhEUgAAABAAAAAQCAMAAAAoLQ9TAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAHVQTFRF/7cA7MOk/+BS19fXqnY5qXY57lQe86SNw5h+u62k7Ojkw5h//38AqKio4HdT0c/E/+HB/+BT/+LC7cOlQTUseHh44ODg29bG7lQd/99S9Idl7lMdx8fH4+Pj5OTk/7gAj4+PwMDAKysrYWFhoaGh/////////RSm8QAAACd0Uk5T//////////////////////////////////////////////////8Ag1aX2QAAAHNJREFUeNpcze0SQzAQheFNIkGpUrT1EVukuf9LxMjINs/Pd87MgYWy1sLy9VxYL2dog2B+l5cJgnZh3jVZ4sOBlYz9LeonR0kXglWAkizmO3YIEX0RyOEo/lYAx3e0Bz2d9Ii3hyrAEOmQK7BU/Ok3AQYARI0fFHay6AYAAAAASUVORK5CYII=\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>);
FF - user.js: app.update.lastUpdateTime.background-update-timer - 1300738115
FF - user.js: app.update.lastUpdateTime.blocklist-background-update-timer - 1300737984
FF - user.js: app.update.lastUpdateTime.microsummary-generator-update-timer - 1300738004
FF - user.js: app.update.lastUpdateTime.places-maintenance-timer - 1300738012
FF - user.js: app.update.lastUpdateTime.restart-nag-timer - 1227538734
FF - user.js: app.update.lastUpdateTime.search-engine-update-timer - 1300737802
FF - user.js: app.update.never.2.0.0.6 - false
FF - user.js: app.update.never.3.0.1 - false
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.download.lastDir - j:\\my pictures\\EBAY Photos
FF - user.js: browser.download.manager.alertOnEXEOpen - false
FF - user.js: browser.download.save_converter_index - 0
FF - user.js: browser.fixup.alternate.enabled - false
FF - user.js: browser.migration.version - 1
FF - user.js: browser.places.importBookmarksHTML - false
FF - user.js: browser.places.importDefaults - false
FF - user.js: browser.places.leftPaneFolderId - -1
FF - user.js: browser.places.migratePostDataAnnotations - false
FF - user.js: browser.places.smartBookmarksVersion - 2
FF - user.js: browser.places.updateRecentTagsUri - false
FF - user.js: browser.preferences.advanced.selectedTabIndex - 1
FF - user.js: browser.rights.3.shown - true
FF - user.js: browser.search.defaultenginename - Web Search...
FF - user.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - user.js: browser.search.selectedEngine - Google
FF - user.js: browser.search.useDBForOrder - true
FF - user.js: browser.shell.checkDefaultBrowser - false
FF - user.js: browser.startup.homepage - hxxp://radiobar.toolbarhome.com/?hp=df
FF - user.js: browser.startup.homepage_override.mstone - rv:1.9.2.13
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: extensions.enabledItems - {6614d11d-d21d-b211-ae23-815234e1ebb5}:1.0.21,{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,jqs@sun.com:1.0,radiobar@toolbar:1.0.0,{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21,{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.13
FF - user.js: extensions.lastAppVersion - 3.6.13
FF - user.js: extensions.mozilla.metrics.event-count - 0
FF - user.js: extensions.update.notifyUser - true
FF - user.js: general.useragent.extra.microsoftdotnet - (.NET CLR 3.5.30729)
FF - user.js: google.toolbar.auto_page_translate - true
FF - user.js: google.toolbar.auto_page_translate.rules.blacklist - chrome://global/locale/intl.propertiesundefined
FF - user.js: google.toolbar.auto_page_translate.rules.whitelist -
FF - user.js: google.toolbar.auto_translate - false
FF - user.js: google.toolbar.bookmarks_used - true
FF - user.js: google.toolbar.button_option.cached.gtbCountrySearch - <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbCountrySearch\ tooltip=\gtbMultilineTooltip\ label=\USA\ fullText=\USA\ image=\chrome://google-toolbar/skin/country-search.png\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>
FF - user.js: google.toolbar.button_option.cached.gtbFeelingLucky - <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbFeelingLucky\ tooltip=\gtbMultilineTooltip\ label=\I'm Feeling Lucky\ fullText=\I'm Feeling Lucky\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>
user_pref(google.toolbar.button_option.cached.gtbSearchBlogs, <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchBlogs\ tooltip=\gtbMultilineTooltip\ label=\Google Blog Search\ fullText=\Google Blog Search\ image=\data:image/x-icon;
user_pref(google.toolbar.button_option.cached.gtbSearchBooks, <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchBooks\ tooltip=\gtbMultilineTooltip\ label=\Google Books\ fullText=\Google Books\ image=\data:image/x-icon;
user_pref(google.toolbar.button_option.cached.gtbSearchCalendar, <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchCalendar\ tooltip=\gtbMultilineTooltip\ label=\Google Calendar\ fullText=\Google Calendar\ image=\data:image/x-icon;
user_pref(google.toolbar.button_option.cached.gtbSearchDocs, <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchDocs\ tooltip=\gtbMultilineTooltip\ label=\Google Documents\ fullText=\Google Documents\ image=\data:image/x-icon;
user_pref(google.toolbar.button_option.cached.gtbSearchFinance, <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchFinance\ tooltip=\gtbMultilineTooltip\ label=\Google Finance\ fullText=\Google Finance\ image=\data:image/x-icon;
FF - user.js: google.toolbar.button_option.cached.gtbSearchFroogle - <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchFroogle\ tooltip=\gtbMultilineTooltip\ label=\Google Product Search\ fullText=\Google Product Search\ image=\chrome://google-toolbar/skin/froogle.png\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>
FF - user.js: google.toolbar.button_option.cached.gtbSearchGroups - <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchGroups\ tooltip=\gtbMultilineTooltip\ label=\Google Groups\ fullText=\Google Groups\ image=\chrome://google-toolbar/skin/groups.png\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>
FF - user.js: google.toolbar.button_option.cached.gtbSearchImages - <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchImages\ tooltip=\gtbMultilineTooltip\ label=\Google Images\ fullText=\Google Images\ image=\chrome://google-toolbar/skin/images.png\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>
FF - user.js: google.toolbar.button_option.cached.gtbSearchLocal - <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchLocal\ tooltip=\gtbMultilineTooltip\ label=\Google Maps\ fullText=\Google Maps\ image=\chrome://google-toolbar/skin/local.png\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>
FF - user.js: google.toolbar.button_option.cached.gtbSearchNews - <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchNews\ tooltip=\gtbMultilineTooltip\ label=\Google News\ fullText=\Google News\ image=\chrome://google-toolbar/skin/news.png\ hassearch=\true\ type=\menu-button\ class=\gtb-custombutton gtbHelperIcon gtbGadgetButtonWithSeparateMenu\/>
user_pref(google.toolbar.button_option.cached.gtbSearchPatents, <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchPatents\ tooltip=\gtbMultilineTooltip\ label=\Google Patents\ fullText=\Google Patents\ image=\data:image/x-icon;
user_pref(google.toolbar.button_option.cached.gtbSearchPhotos, <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchPhotos\ tooltip=\gtbMultilineTooltip\ label=\Picasa Web Albums\ fullText=\Picasa Web Albums\ image=\data:image/x-icon;
user_pref(google.toolbar.button_option.cached.gtbSearchScholar, <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchScholar\ tooltip=\gtbMultilineTooltip\ label=\Google Scholar\ fullText=\Google Scholar\ image=\data:image/x-icon;
FF - user.js: google.toolbar.button_option.cached.gtbSearchSite - <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchSite\ tooltip=\gtbMultilineTooltip\ label=\Search Site\ fullText=\Search Site\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>
user_pref(google.toolbar.button_option.cached.gtbSearchVideo, <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchVideo\ tooltip=\gtbMultilineTooltip\ label=\Google Video\ fullText=\Google Video\ image=\data:image/x-icon;
FF - user.js: google.toolbar.button_option.cached.gtbSearchWebhistory - <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbSearchWebhistory\ tooltip=\gtbMultilineTooltip\ label=\Web History\ fullText=\Web History\ image=\chrome://google-toolbar/skin/webhistory.png\ hassearch=\true\ class=\gtb-custombutton gtbHelperIcon gtbSimpleCustomButton\/>
user_pref(google.toolbar.button_option.cached.gtbstoolbar-google-com_CTK0Y7F4MTG6NKYH03WT-xml, <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbstoolbar-google-com_CTK0Y7F4MTG6NKYH03WT-xml\ tooltip=\gtbMultilineTooltip\ label=\orkut\ fullText=\orkut\ image=\data:image/x-icon;
user_pref(google.toolbar.button_option.cached.gtbstoolbar-google-com_J66T77NJDBMW4FEUU7FA-xml, <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbstoolbar-google-com_J66T77NJDBMW4FEUU7FA-xml\ tooltip=\gtbMultilineTooltip\ label=\Gmail\ fullText=\Gmail\ image=\data:image/x-icon;
user_pref(google.toolbar.button_option.cached.gtbstoolbar-google-com_O8Y91YHB24Z6SR0SGYSK-xml, <toolbarbutton xmlns=\hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\ id=\gtbstoolbar-google-com_O8Y91YHB24Z6SR0SGYSK-xml\ tooltip=\gtbMultilineTooltip\ label=\Button Gallery\ fullText=\Button Gallery\ image=\data:image/x-icon;
FF - user.js: google.toolbar.button_option.gtbAutoFill - true
FF - user.js: google.toolbar.button_option.gtbAutoLink - true
FF - user.js: google.toolbar.button_option.gtbBookmarks - true
FF - user.js: google.toolbar.button_option.gtbPageRank - false
FF - user.js: google.toolbar.button_option.gtbSearchBookmarks - true
FF - user.js: google.toolbar.button_option.gtbSearchGoogle - true
FF - user.js: google.toolbar.button_option.gtbSpellCheck - true
FF - user.js: google.toolbar.button_option.gtbstoolbar-google-com_J66T77NJDBMW4FEUU7FA-xml - false
FF - user.js: google.toolbar.button_option.gtbstoolbar-google-com_O8Y91YHB24Z6SR0SGYSK-xml - true
FF - user.js: google.toolbar.button_option.gtbsTOOLBAR-GOOGLE-COM_O8Y91YHB24Z6SR0SGYSK-XML - true
FF - user.js: google.toolbar.button_option.gtbsTOOLBAR-GOOGLE-COM_O8Y91YHB24Z6SR0SGYSK-XML.feedUpdate - 1261556362
FF - user.js: google.toolbar.button_option.gtbstoolbar-google-com_O8Y91YHB24Z6SR0SGYSK-xml.feedUpdate - 1300823574
FF - user.js: google.toolbar.button_option.gtbstoolbar-google-com_O8Y91YHB24Z6SR0SGYSK-xml.feedWasRead - true
FF - user.js: google.toolbar.button_option.gtbTranslate - true
FF - user.js: google.toolbar.button_option.gtbTranslateMenu - false
FF - user.js: google.toolbar.button_option.gtbuHKCU_Google Desktop Search - false
FF - user.js: google.toolbar.button_option.safebrowsing.advancedprotection - false
FF - user.js: google.toolbar.button_option.safebrowsing.advancedprotection.default - false
FF - user.js: google.toolbar.button_option.safebrowsing.hasrun - true
FF - user.js: google.toolbar.button_option.safebrowsing.tableversion.goog-black-enchash - 1.34382
FF - user.js: google.toolbar.button_option.safebrowsing.tableversion.goog-black-url - 1.14668
FF - user.js: google.toolbar.button_option.safebrowsing.tableversion.goog-sandbox-text - 1.5
FF - user.js: google.toolbar.button_option.safebrowsing.tableversion.goog-white-domain - 1.23
FF - user.js: google.toolbar.button_option.safebrowsing.tableversion.goog-white-url - 1.371
FF - user.js: google.toolbar.component.bundled.share_providers.json - 7.0.20100326
FF - user.js: google.toolbar.component.bundled.suggest_window.html - 7.0.20100326
FF - user.js: google.toolbar.custombuttons.list - gtbSearchImages,gtbCountrySearch,gtbSearchLocal,gtbSearchSite,gtbSearchNews,gtbSearchVideo,gtbSearchWebhistory,gtbFeelingLucky,gtbSearchGroups,gtbSearchFroogle,gtbstoolbar-google-com_CTK0Y7F4MTG6NKYH03WT-xml,gtbSearchBlogs,gtbSearchBooks,gtbSearchCalendar,gtbSearchDocs,gtbSearchFinance,gtbSearchPatents,gtbSearchPhotos,gtbSearchScholar,gtbstoolbar-google-com_O8Y91YHB24Z6SR0SGYSK-xml,gtbstoolbar-google-com_J66T77NJDBMW4FEUU7FA-xml
FF - user.js: google.toolbar.custombuttons.migrated - true
FF - user.js: google.toolbar.custombuttons.order.migrated.to.v6 - false
FF - user.js: google.toolbar.custombuttons.version - 1
FF - user.js: google.toolbar.done_page_shown - AU_7.0.20100326
FF - user.js: google.toolbar.enhanced_features.week - -1
FF - user.js: google.toolbar.first_search - false
FF - user.js: google.toolbar.first_search_ping_retires - 1
FF - user.js: google.toolbar.firstrun.done - true
FF - user.js: google.toolbar.google_home - www.google.com
FF - user.js: google.toolbar.install_id - 7C12B9403B957D114455A8766471904B2B648yCYBC
FF - user.js: google.toolbar.install_ping_acked - true
FF - user.js: google.toolbar.install_ping_retires - 2
FF - user.js: google.toolbar.last_ping_attempt - 1300737183873
FF - user.js: google.toolbar.linkdoctor.backup.browser.fixup.alternate.enabled - false
FF - user.js: google.toolbar.never_show_done_page - false
FF - user.js: google.toolbar.opted_into_advanced_features_1 - false
FF - user.js: google.toolbar.rlz - 1B3DVFA_en___GB242
FF - user.js: google.toolbar.safebrowsing.keyupdatetime - 1300823571
FF - user.js: google.toolbar.search_box_history -
FF - user.js: google.toolbar.searchdomaincheck.done - true
user_pref(google.toolbar.search-icon, data:image/x-icon;
FF - user.js: google.toolbar.seenInstaller - true
FF - user.js: google.toolbar.sharing.button-promotion-shown - 2
FF - user.js: google.toolbar.sharing.usage.Facebook - 1
FF - user.js: google.toolbar.sidewiki.enabled - false
FF - user.js: google.toolbar.sidewiki.first.run - false
FF - user.js: google.toolbar.spell_check.dictionary.words2 -
FF - user.js: google.toolbar.spell_check.lang - en
FF - user.js: google.toolbar.spell_check.last_lang - en
FF - user.js: google.toolbar.subscribe.aggregators.bloglines.desc - Personal page loaded with the freshest news about the things you love
FF - user.js: google.toolbar.subscribe.aggregators.bloglines.id - bloglines
FF - user.js: google.toolbar.subscribe.aggregators.bloglines.order - 2
FF - user.js: google.toolbar.subscribe.aggregators.bloglines.title - Bloglines
FF - user.js: google.toolbar.subscribe.aggregators.bloglines.url - hxxp://www.bloglines.com/sub?url=%feed%
FF - user.js: google.toolbar.subscribe.aggregators.googlereader.desc - Use Google Reader for all your favorite feeds
FF - user.js: google.toolbar.subscribe.aggregators.googlereader.id - googlereader
FF - user.js: google.toolbar.subscribe.aggregators.googlereader.order - 1
FF - user.js: google.toolbar.subscribe.aggregators.googlereader.title - Google Reader
FF - user.js: google.toolbar.subscribe.aggregators.googlereader.url - hxxp://www.google.com/reader/view/feed/%feed%?q=*
FF - user.js: google.toolbar.subscribe.aggregators.iGoogle.desc - Personalized Home
FF - user.js: google.toolbar.subscribe.aggregators.iGoogle.id - iGoogle
FF - user.js: google.toolbar.subscribe.aggregators.iGoogle.order - 0
FF - user.js: google.toolbar.subscribe.aggregators.iGoogle.title - Google personalized home
FF - user.js: google.toolbar.subscribe.aggregators.iGoogle.url - hxxp://fusion.google.com/add?feedurl=%feed%&client=firetools&hl=en
FF - user.js: google.toolbar.subscribe.aggregators.LiveBookmarks.desc - Read subscriptions with Firefox Live Bookmarks
FF - user.js: google.toolbar.subscribe.aggregators.LiveBookmarks.id - LiveBookmarks
FF - user.js: google.toolbar.subscribe.aggregators.LiveBookmarks.order - 3
FF - user.js: google.toolbar.subscribe.aggregators.LiveBookmarks.title - Firefox Live Bookmarks
FF - user.js: google.toolbar.subscribe.aggregators.LiveBookmarks.url - LiveBookmarksUrl
FF - user.js: google.toolbar.subscribe.aggregators.myyahoo.desc - My Yahoo!
FF - user.js: google.toolbar.subscribe.aggregators.myyahoo.id - myyahoo
FF - user.js: google.toolbar.subscribe.aggregators.myyahoo.order - 4
FF - user.js: google.toolbar.subscribe.aggregators.myyahoo.title - My Yahoo
FF - user.js: google.toolbar.subscribe.aggregators.myyahoo.url - hxxp://add.my.yahoo.com/rss?url=%feed%
FF - user.js: google.toolbar.subscribe.aggregators.newsgator.desc - NewsGator Online
FF - user.js: google.toolbar.subscribe.aggregators.newsgator.id - newsgator
FF - user.js: google.toolbar.subscribe.aggregators.newsgator.order - 5
FF - user.js: google.toolbar.subscribe.aggregators.newsgator.title - NewsGator
FF - user.js: google.toolbar.subscribe.aggregators.newsgator.url - hxxp://www.newsgator.com/ngs/subscriber ... ?url=%feed%
FF - user.js: google.toolbar.subscribe.aggregators.pluck.desc - Pluck personal web information center
FF - user.js: google.toolbar.subscribe.aggregators.pluck.id - pluck
FF - user.js: google.toolbar.subscribe.aggregators.pluck.order - 6
FF - user.js: google.toolbar.subscribe.aggregators.pluck.title - Pluck
FF - user.js: google.toolbar.subscribe.aggregators.pluck.url - hxxp://client.pluck.com/pluckit/prompt. ... 53&a=%feed%
FF - user.js: google.toolbar.subscribe.defaultid - iGoogle
FF - user.js: google.toolbar.subscribe.lastrefreshed - Mon Sep 24 2007 09:05:23 GMT+0100 (GMT Standard Time)
FF - user.js: google.toolbar.thumbnail.clearing - 268
FF - user.js: idle.lastDailyNotification - 1292849420
FF - user.js: intl.charsetmenu.browser.cache - windows-1252, us-ascii, UTF-8, EUC-KR, ISO-8859-1
FF - user.js: keyword.URL - hxxp://radiobar.toolbarhome.com/search.aspx?srch=ku&q=
FF - user.js: metrics.event-count - 0
FF - user.js: microsoft.CLR.auto_install - false
FF - user.js: network.cookie.prefsMigrated - true
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.protocol-handler.warn-external.itmss - false
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: places.last_vacuum - 1291482111
FF - user.js: plugin.expose_full_path - true
FF - user.js: plugin.expose_full_path - true
FF - user.js: print.print_printer - Brother MFC-465CN Printer
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_bgcolor - false
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_bgimages - false
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_command -
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_downloadfonts - false
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_edge_bottom - 0
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_edge_left - 0
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_edge_right - 0
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_edge_top - 0
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_evenpages - true
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_footercenter -
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_footerleft - &PT
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_footerright - &D
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_headercenter -
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_headerleft - &T
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_headerright - &U
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_in_color - true
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_margin_bottom - 0.5
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_margin_left - 0.5
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_margin_right - 0.5
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_margin_top - 0.5
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_oddpages - true
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_orientation - 0
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_pagedelay - 500
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_paper_data - 9
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_paper_height - 11,00
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_paper_size_type - 0
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_paper_size_unit - 1
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_paper_width - 8,50
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_reversed - false
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_scaling - 1,00
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_shrink_to_fit - true
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_to_file - false
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_to_filename -
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_unwriteable_margin_bottom - 0
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_unwriteable_margin_left - 0
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_unwriteable_margin_right - 0
FF - user.js: print.printer_Brother_MFC-465CN_Printer.print_unwriteable_margin_top - 0
FF - user.js: print.printer_NETWORK_Printer.print_bgcolor - false
FF - user.js: print.printer_NETWORK_Printer.print_bgimages - false
FF - user.js: print.printer_NETWORK_Printer.print_command -
FF - user.js: print.printer_NETWORK_Printer.print_downloadfonts - true
FF - user.js: print.printer_NETWORK_Printer.print_evenpages - true
FF - user.js: print.printer_NETWORK_Printer.print_footercenter -
FF - user.js: print.printer_NETWORK_Printer.print_footerleft - &PT
FF - user.js: print.printer_NETWORK_Printer.print_footerright - &D
FF - user.js: print.printer_NETWORK_Printer.print_headercenter -
FF - user.js: print.printer_NETWORK_Printer.print_headerleft - &T
FF - user.js: print.printer_NETWORK_Printer.print_headerright - &U
FF - user.js: print.printer_NETWORK_Printer.print_in_color - true
FF - user.js: print.printer_NETWORK_Printer.print_margin_bottom - 0.5
FF - user.js: print.printer_NETWORK_Printer.print_margin_left - 0.5
FF - user.js: print.printer_NETWORK_Printer.print_margin_right - 0.5
FF - user.js: print.printer_NETWORK_Printer.print_margin_top - 0.5
FF - user.js: print.printer_NETWORK_Printer.print_oddpages - true
FF - user.js: print.printer_NETWORK_Printer.print_orientation - 1
FF - user.js: print.printer_NETWORK_Printer.print_pagedelay - 500
FF - user.js: print.printer_NETWORK_Printer.print_paper_data - 9
FF - user.js: print.printer_NETWORK_Printer.print_paper_height - 11,00
FF - user.js: print.printer_NETWORK_Printer.print_paper_size - 4653104
FF - user.js: print.printer_NETWORK_Printer.print_paper_size_type - 0
FF - user.js: print.printer_NETWORK_Printer.print_paper_size_unit - 1
FF - user.js: print.printer_NETWORK_Printer.print_paper_width - 8,50
FF - user.js: print.printer_NETWORK_Printer.print_printer - NETWORK Printer
FF - user.js: print.printer_NETWORK_Printer.print_reversed - false
FF - user.js: print.printer_NETWORK_Printer.print_scaling - 1,00
FF - user.js: print.printer_NETWORK_Printer.print_shrink_to_fit - true
FF - user.js: print.printer_NETWORK_Printer.print_to_file - false
FF - user.js: print.printer_NETWORK_Printer.print_to_filename -
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: privacy.clearOnShutdown.downloads - false
FF - user.js: privacy.clearOnShutdown.formdata - false
FF - user.js: privacy.clearOnShutdown.history - false
FF - user.js: privacy.sanitize.didShutdownSanitize - true
FF - user.js: privacy.sanitize.migrateFx3Prefs - true
FF - user.js: privacy.sanitize.promptOnSanitize - false
FF - user.js: privacy.sanitize.sanitizeOnShutdown - true
FF - user.js: radiobar.install.date - 1275955200000
FF - user.js: radiobar.install.finished - 1.0.0
FF - user.js: radiobar.install.guid - {ca41f2d5-b784-435b-a8d1-6696dcfbc9a6}
FF - user.js: radiobar.install.isHidden - true
FF - user.js: radiobar.install.istoolbarhp - true
FF - user.js: radiobar.install.istoolbarsearch - true
FF - user.js: radiobar.install.laststatreq - 1300665600000
FF - user.js: radiobar.install.newtab - true
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: spellchecker.dictionary - en-US
FF - user.js: symantec.browser.sessionstore.resume_from_crash.toggle - false
FF - user.js: ui.submenuDelay - 0
FF - user.js: ui.submenuDelay - 0
FF - user.js: urlclassifier.keyupdatetime.hxxps://sb-ssl.google.com/safebrowsing/newkey - 1303329168
FF - user.js: urlclassifier.tableversion.goog-black-enchash - 1.58159
FF - user.js: urlclassifier.tableversion.goog-black-url - 1.24294
FF - user.js: urlclassifier.tableversion.goog-white-domain - 1.481
FF - user.js: urlclassifier.tableversion.goog-white-url - 1.371
FF - user.js: xpinstall.whitelist.add -
FF - user.js: xpinstall.whitelist.add.103 -
FF - user.js: yahoo.installer.nd - 1
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-10-13 464176]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2011-2-12 89792]
R1 UnHooker;UnHooker;c:\windows\system32\drivers\UnHooker.sys [2010-1-20 25400]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\iobit\advanced systemcare 5\ASCService.exe [2011-11-26 494424]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-10-24 54752]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-11-30 366152]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-12-2 214904]
R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-12-2 214904]
R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-12-2 214904]
R2 McProxy;McAfee Proxy Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-12-2 214904]
R2 McShield;McAfee McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2011-12-2 166288]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2011-2-12 160608]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-11-30 150856]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-2-12 57600]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-11-30 22216]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2011-2-12 180816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2011-2-12 59456]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-2-12 338176]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2011-2-12 83856]
R3 mv2;mv2;c:\windows\system32\drivers\mv2.sys [2011-1-26 10688]
R3 ZSMC302;Audio Web Cam 31;c:\windows\system32\drivers\usbvm302.sys [2006-12-9 90559]
S2 0181001324360532mcinstcleanup;McAfee Application Installer Cleanup (0181001324360532);c:\windows\temp\018100~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service --> c:\windows\temp\018100~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Googles oppdateringstjeneste (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-3 135664]
S2 RUBotSrv;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\RUBotSrv.exe [2011-12-6 439632]
S3 androidusb;ADB Interface Driver;c:\windows\system32\drivers\fxxandroidusb.sys [2011-9-6 25728]
S3 cpudrv;cpudrv;c:\program files\systemrequirementslab\cpudrv.sys [2009-12-18 11336]
S3 EraserUtilDrv10621;EraserUtilDrv10621;\??\c:\program files\common files\symantec shared\eengine\eraserutildrv10621.sys --> c:\program files\common files\symantec shared\eengine\EraserUtilDrv10621.sys [?]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-3 135664]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\microsoft fix it center\Matsvc.exe [2011-6-13 267568]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\3.0.229\McCHSvc.exe [2011-9-20 237008]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2011-2-12 83856]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-2-12 87656]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2011-8-3 18432]
S3 palmusb;USB Comm driver (WDM);c:\windows\system32\drivers\palmusb.sys [2010-7-6 72800]
S3 qcusbser;Qualcomm USB Device for Legacy Serial Communication;c:\windows\system32\drivers\fxx\qcusbser.sys [2011-9-6 103424]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-10 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2010-8-24 92008]
.
=============== Created Last 30 ================
.
2011-12-20 10:07:01 -------- d-----w- c:\documents and settings\all users\application data\SecTaskMan
2011-12-20 10:06:54 -------- d-----w- c:\program files\Security Task Manager
2011-12-20 05:58:07 28760 ----a-w- c:\program files\mozilla firefox\ScriptFF.dll
2011-12-15 23:01:12 388096 ----a-r- c:\documents and settings\karin_2\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-12-06 14:35:59 81920 ------w- c:\windows\system32\ieencode.dll
2011-12-06 14:35:58 884712 ------w- c:\program files\msn\msncorefiles\install\msn9components\digcore.exe
2011-12-06 14:35:58 1327320 ------w- c:\program files\msn\msncorefiles\install\msnsusii.exe
2011-12-06 14:35:57 966656 ------w- c:\program files\msn\msncorefiles\oobe\obemetal.dll
2011-12-06 14:35:57 86016 ------w- c:\program files\msn\msncorefiles\oobe\obepopc.dll
2011-12-06 14:35:57 77824 ------w- c:\program files\msn\msncorefiles\oobe\obemtllc.dll
2011-12-06 14:35:57 229376 ------w- c:\program files\msn\msncorefiles\oobe\obelog.dll
2011-12-06 14:35:57 11053008 ------w- c:\program files\msn\msncorefiles\install\msn9components\msncli.exe
2011-12-06 14:34:37 19569 ----a-w- c:\windows\000001_.tmp
2011-12-06 13:55:41 -------- d-----w- c:\documents and settings\all users\application data\Trend Micro
2011-12-06 13:48:32 -------- d-----w- c:\program files\Windows Resource Kits
2011-12-06 13:14:26 -------- d-----w- c:\windows\Performance
2011-12-06 13:14:08 -------- d-----w- c:\documents and settings\karin_2\local settings\application data\Microsoft Corporation
2011-12-06 13:12:47 -------- d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2011-12-04 14:40:45 42112 ----a-w- c:\windows\system32\drivers\imapi.sys
2011-12-04 14:40:45 42112 ----a-w- c:\windows\system32\dllcache\imapi.sys
2011-12-02 20:20:59 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
2011-12-02 20:20:58 9608 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-11-30 14:42:52 -------- d-----w- c:\documents and settings\karin_2\application data\Malwarebytes
2011-11-30 14:42:44 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-11-30 14:42:35 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-30 14:42:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-30 14:40:42 22032 ----a-w- c:\windows\DCEBoot.exe
2011-11-30 14:40:42 102400 ----a-w- c:\windows\RegBootClean.suspect
2011-11-30 11:37:15 -------- d-----w- c:\program files\common files\Motive
2011-11-30 11:36:14 -------- d-----w- c:\program files\Plusnet Assist
2011-11-30 11:26:09 14664 ----a-w- c:\windows\stinger.sys
2011-11-30 10:55:48 150856 ----a-w- c:\windows\system32\mfevtps.exe
2011-11-30 10:54:55 -------- d-----w- c:\program files\stinger
2011-11-30 10:49:26 -------- d-----w- c:\documents and settings\karin_2\application data\McAfee
2011-11-30 10:42:45 -------- d-----w- c:\documents and settings\all users\application data\McAfee Security Scan
2011-11-30 10:42:38 -------- d-----w- c:\program files\McAfee Security Scan
2011-11-29 10:24:38 -------- d-sh--w- c:\documents and settings\karin_2\local settings\application data\bf18a5a5
2011-11-26 13:21:13 20312 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2011-11-26 13:20:45 -------- d-----w- c:\documents and settings\karin_2\local settings\application data\AuctionSentry
2011-11-26 13:20:45 -------- d-----w- c:\documents and settings\karin_2\application data\AuctionSentry
2011-11-26 13:20:44 -------- d-----w- c:\documents and settings\karin_2\local settings\application data\Auction_Sentry_Software
2011-11-26 13:19:38 -------- d-----w- c:\program files\Auction Sentry 4
.
==================== Find3M ====================
.
2011-11-30 10:55:36 464176 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2011-11-29 17:30:17 186880 ----a-w- c:\windows\system32\searchprotocolhost.exe
2011-11-29 13:15:17 441856 ----a-w- c:\windows\system32\searchindexer.exe
2011-11-29 10:30:17 45056 ----a-w- c:\windows\system32\brss01a.old
2011-11-26 10:50:23 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-23 13:25:32 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20:51 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20:51 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20:51 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23:59 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07:10 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37:08 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:02 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13:22 186880 ----a-w- c:\windows\system32\encdec.dll
2011-10-15 12:16:16 89792 ----a-w- c:\windows\system32\drivers\mfetdi2k.sys
2011-10-15 12:16:16 87656 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2011-10-15 12:16:16 83856 ----a-w- c:\windows\system32\drivers\mfendisk.sys
2011-10-15 12:16:16 59456 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2011-10-15 12:16:16 57600 ----a-w- c:\windows\system32\drivers\cfwids.sys
2011-10-15 12:16:16 338176 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2011-10-15 12:16:16 180816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-10-15 12:16:16 121256 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 10:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 10:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll

==== End Of File ===========================
ATTACH.TXT----------------------------------------------------

DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 25/11/2006 17:30:33
System Uptime: 20/12/2011 12:25:47 (36 hours ago)
.
Motherboard: Dell Inc. | | 0DD332
Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | Microprocessor | 2992/800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 51 GiB total, 15.921 GiB free.
D: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (NTFS) - 20 GiB total, 1.504 GiB free.
K: is FIXED (FAT32) - 4 GiB total, 2.063 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP1487: 02/12/2011 15:51:14 - System Checkpoint
RP1488: 03/12/2011 00:19:23 - Restore Operation
RP1489: 04/12/2011 11:16:31 - System Checkpoint
RP1490: 05/12/2011 12:22:46 - System Checkpoint
RP1491: 06/12/2011 13:12:46 - Installed Windows 7 Upgrade Advisor
RP1492: 06/12/2011 13:48:30 - Installed Windows Resource Kit Tools - SubInAcl.exe
RP1493: 06/12/2011 14:34:55 - Installed Windows XP Service Pack 3.
RP1494: 07/12/2011 15:14:28 - System Checkpoint
RP1495: 07/12/2011 23:13:34 - Software Distribution Service 3.0
RP1496: 08/12/2011 23:58:04 - System Checkpoint
RP1497: 10/12/2011 00:20:58 - System Checkpoint
RP1498: 11/12/2011 02:26:39 - System Checkpoint
RP1499: 12/12/2011 02:44:58 - System Checkpoint
RP1500: 13/12/2011 02:57:00 - System Checkpoint
RP1501: 14/12/2011 03:44:57 - System Checkpoint
RP1502: 14/12/2011 14:05:34 - Software Distribution Service 3.0
RP1503: 15/12/2011 14:18:58 - System Checkpoint
RP1504: 16/12/2011 14:20:50 - System Checkpoint
RP1505: 17/12/2011 15:48:48 - System Checkpoint
RP1506: 18/12/2011 16:22:44 - System Checkpoint
RP1507: 19/12/2011 16:34:44 - System Checkpoint
RP1508: 20/12/2011 17:22:35 - System Checkpoint
RP1509: 21/12/2011 18:14:36 - System Checkpoint
.
==== Installed Programs ======================
.
32 Bit HP CIO Components Installer
32 bit Windows Card Reader Driver
4500_G510nz_Help
4500G510nz
4500G510nz_Software_Min
Adobe Flash Player 10 Plugin
Adobe Flash Player 11 ActiveX
Adobe Reader 7.1.0
Adobe Shockwave Player 11.5
Advanced SystemCare 5
AirTouch Deluxe keyboard
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft Software Suite
ARTEuro
ATI - Software Uninstall Utility
ATI Parental Control
Auction Sentry
Belkin Keyboard Mouse
Bonjour
Brother Driver Deployment Wizard
Brother Peer to Peer Print (NetBIOS) 1.16
BufferChm
Bullzip PDF Printer 7.1.0.1218
CCleaner
Children's Encyclopedia
CiD Help
Compatibility Pack for the 2007 Office system
Conexant D850 56K V.9x DFVc Modem
Dell CinePlayer
Dell Driver Reset Tool
Dell Support 3.2
Dell System Restore
Digital Line Detect
DivX Codec
Dropbox
DYMO Label Software
EasyWeather
Firmware Develop Kits 1.51
Google Toolbar for Firefox
Google Toolbar for Internet Explorer
Google Update Helper
gormiti Screensaver
GPL Ghostscript Lite 8.70
HiJackThis
HijackThis 2.0.0
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB2570791)
Hotfix for Windows XP (KB2633952)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB922120-v6)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
HP Officejet 4500 G510n-z
Intel(R) Graphics Media Accelerator Driver
Intel(R) Network Connections 14.0.40.0
Internet Explorer (Enable DEP)
iTunes
J2SE Runtime Environment 5.0 Update 10
Java Auto Updater
Java(TM) 6 Update 26
Jessops Photo
Junk Mail filter update
Malwarebytes' Anti-Malware version 1.51.2.1300
Mavis Beacon Teaches Typing Platinum 20
McAfee Security Scan Plus
McAfee SecurityCenter
McAfee Virtual Technician
MCU
Media Player Product Tool 5.29
MediaLooks QuickTime Source 1.7.0.30 (DirectShow Filter)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2572067)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Choice Guard
Microsoft Fix it Center
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Office 97, Professional Edition
Microsoft Office File Validation Add-In
Microsoft Office Live Add-in 1.3
Microsoft Office Outlook Connector
Microsoft Office Professional Edition 2003
Microsoft PhotoDraw 2000 V2
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft User-Mode Driver Framework Feature Pack 1.7
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Windows XP Video Decoder Checkup Utility
Microsoft WinUsb 1.0
MobileMe Control Panel
Modem Helper
Mozilla Firefox 8.0.1 (x86 en-US)
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero Suite
Network
Norton PartitionMagic
Norton PartitionMagic 8.0
Palm Desktop
PHOTOfunSTUDIO -viewer-
PhotoPad Image Editor
Plusnet Assist
PMP Transcoding Tool 0.5.1.0 For Windows NT/2000/XP
Prism Video File Converter
Quicken 2004
QuickTime
RealPlayer Basic
Samsung Mobile phone USB driver Software
Scan
SDFormatter
Search Assist
Security Task Manager 1.8d
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft Windows (KB2564958)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2530548)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2559049)
Security Update for Windows Internet Explorer 8 (KB2586448)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2503665)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2536276)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2544893)
Security Update for Windows XP (KB2555917)
Security Update for Windows XP (KB2562937)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567053)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2619339)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2633171)
Security Update for Windows XP (KB2639417)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Segoe UI
Series 1 - Noctis Screensaver
Series 1 - Poivrons Screensaver
SigmaTel Audio
Sonic Activation Module
Spybot - Search & Destroy
System Requirements Lab for Intel
TomTom HOME 2.7.6.2056
TomTom HOME Visual Studio Merge Modules
Toolbox
TouchCopy 11
Trend Micro RUBotted 2.0 Beta
Undelete Plus 2.94
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB2447568)
Update for Windows Internet Explorer 8 (KB2598845)
Update for Windows Internet Explorer 8 (KB971180)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2492386)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2607712)
Update for Windows XP (KB2616676)
Update for Windows XP (KB2641690)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB971029)
Viewpoint Media Player
Visual C++ 2008 Runtime (x86)
VoipCheapCom
WebFldrs XP
WebReg
WiFi Engine
Windows 7 Upgrade Advisor
Windows Essentials Media Codec Pack 2.3d
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Installer Clean Up
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Management Framework Core
Windows Media Format 11 runtime
Windows Media Player 11
Windows PowerShell(TM) 1.0
Windows Resource Kit Tools - SubInAcl.exe
WinFF 1.3.2
WinRAR archiver
WLAN 802.11G USB
X-Mouse Button Control 1.52
Yahoo! Toolbar
.
==== Event Viewer Messages From Past Week ========
.
21/12/2011 15:00:39, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 1 time(s).
21/12/2011 15:00:39, error: Service Control Manager [7031] - The McAfee VirusScan Announcer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
21/12/2011 15:00:39, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
21/12/2011 15:00:39, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
21/12/2011 15:00:39, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
21/12/2011 15:00:39, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
20/12/2011 10:23:35, error: Service Control Manager [7034] - The McciCMService service terminated unexpectedly. It has done this 1 time(s).
16/12/2011 12:31:14, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The system cannot find the file specified.
16/12/2011 12:31:14, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Trend Micro RUBotted Service service to connect.
16/12/2011 12:31:14, error: Service Control Manager [7000] - The Trend Micro RUBotted Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
16/12/2011 12:31:13, error: Service Control Manager [7000] - The BrSplService service failed to start due to the following error: The system cannot find the file specified.
15/12/2011 17:59:52, error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23).
15/12/2011 09:18:33, error: Service Control Manager [7031] - The McShield service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
15/12/2011 09:15:35, error: Service Control Manager [7000] - The Advanced SystemCare Service 5 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
15/12/2011 09:15:34, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Advanced SystemCare Service 5 service to connect.
15/12/2011 09:15:21, error: Print [19] - Sharing printer failed + 1722, Printer Bullzip PDF Printer share name Printer4.
.
==== End Of File ===========================
Confounded
Active Member
 
Posts: 12
Joined: December 20th, 2011, 7:16 pm
Advertisement
Register to Remove

Re: LAN PROXY HiJacked on Every Reboot. (3rd RePosting) Pls

Unread postby deltalima » December 24th, 2011, 5:05 pm

Checking your log - back soon.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: LAN PROXY HiJacked on Every Reboot. (3rd RePosting) Pls

Unread postby deltalima » December 24th, 2011, 5:09 pm

Hi Confounded,

Welcome to the forum.

Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Please note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please do not run any scans or make any changes to the system unless I ask you too.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • If after 3 days you have not responded to this topic, it will be closed, and you will need to start a new one.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Rootkit Warning
Your computer has multiple infections, including a rootkit.
A rootkit is a set of software tools intended for concealing running processes, files or system data from the operating system.

You are strongly advised to do the following:
  1. Disconnect the computer from the Internet and from any networked computers until it is cleaned.
  2. Call all your banks, financial institutions, credit card companies and inform them that you may be a victim of identity theft and put a watch on your accounts.
    If you don't mind the hassle, change all your account numbers.
  3. From a clean computer, change all your passwords
    (Internet login, your email address(es), financial accounts, PayPal, eBay, Amazon...any online activities you carry out which require a username and password).
    Do NOT change your passwords from this computer, the attacker can still get all the new passwords and transaction records.
  4. Back up all your important data except programs. The programs can be reinstalled back from the original disc or from the Net.

Due to its rootkit functionality, your computer is very likely to have been compromised and there is no way that it can be trusted again.
Many experts in the security community believe that once infected with this type of Trojan,
the best course of action would be to do a reformat and re-installation of the operating system (OS).
This decision will have to be made by you...


We can attempt to clean this machine but we will not guarantee that it won't still be compromised, afterwards.
Please let me know how you wish to proceed.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: LAN PROXY HiJacked on Every Reboot. (3rd RePosting) Pls

Unread postby deltalima » December 27th, 2011, 2:24 pm

Due to a lack of response, this topic is now closed.

If you still require help, please open a new thread in the Infected? Virus, malware, adware, ransomware, oh my! forum, include a fresh FRST log, and wait for a new helper.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK
Advertisement
Register to Remove


  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 297 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware