Jump to content

Malwarebytes

Firefox Shuts Down When Options are Clicked


79 replies to this topic

#1
sandi149

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 102 posts
I have a ? about Firefox. I just noticed that when I click on Tools, and then Options, Firefox closes on me. Totally shuts down.

do you have any idea why?

Thanks,
Sandi

#2
Jintan

    Advanced Member

  • Experts
  • PipPipPip
  • 103 posts
Good you noticed that while we had the thread open. The malware may have been operating perhaps as an add-on, and would definitely not want you to access anywhere changes might be made to it. Not sure right off where the blocks were set for that though.

Navigate to the following hilighted file:

C:\Documents and Settings\[User Name]\Application Data\Mozilla\Firefox\Profiles\xxxxxxxx.default\prefs.js

Replace User Name with your current user name, and then the "xxxxxxxx" on your computer will instead show as random characters, such as 8Xaugl7a.

Once you have located that file, zip a copy of it and upload it here like you did the last time please.

#3
sandi149

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 102 posts
Jintan, I don't understand what you mean. Which username should I navigate to? Mine which is Sandi or my husband's which is Temp. He originally had his username as Jay but something happened to his profile a couple months ago, I think it got corrupted, and I tried to fix it, but it ended up with his "username" as being Temp for some reason.

Also, I don't understand what you mean when you say,

C:\Documents and Settings\[User Name]\Application Data\Mozilla\Firefox\Profiles\xxxxxxxx.default\prefs.js
Replace User Name with your current user name, and then the "xxxxxxxx" on your computer will instead show as random characters, such as 8Xaugl7a.

Could you please explain that to me.

thanks.
Sandi

#4
Jintan

    Advanced Member

  • Experts
  • PipPipPip
  • 103 posts
Right click My Computer, left click Explore, then use the plus (+) symbols to expand the folder list. Go to both of these locations:

C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\xxxxxxxx.default\prefs.js

And zip and upload that prefs.js file. I can't help with what there will show where the x's are - they will be random characters like in my example. If you go to that "Profiles" folder you will see what I mean.

#5
sandi149

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 102 posts
Ok, I understand what you mean. I zipped the file and uploaded to that site.

#6
Jintan

    Advanced Member

  • Experts
  • PipPipPip
  • 103 posts
File received, thanks. The changes aren't showing in that though. Firefox uses a master list of settings, but then used different folders to create and store changes for that. New to me, so a bit of fishing to locate the changes that were made. Let's check in two areas now.

Navigate again to your Firefox user Profiles folder, and this time zip a copy of the Chrome folder, and upload that please. If it proves to be easier you can also just send it to jintan @ cfl.rr.com as an attachment. Please place "Submitted Files - sandi149" as the email Subject. So the folder to locate will be:

C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\xxxxxxxx.default\Chrome


Also, in the address bar at the top of Firefox, type about:config (and press Enter). A long list of Firefox settings will be disaplyed. In the box next to "Filter" type the word tools

If any items are now displayed in the area below, right click each entry and select "Copy Name". Then in an open Notepad textbox select Paste to copy that Firefox Config entry. For the same item also right click, select "Copy Value" and again Paste that in the open Notepad textbox. This way you are building a list of any "tools" items displayed there. Then copy and paste your list back here please.

#7
sandi149

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 102 posts
Hi Jintan,

Ok, I zipped that file and emailed it to you. My email is sandi149 at ix.netcom dot com so you will know that it's from me.

I will do the other stuff in the morning.

Thanks,
Sandi

#8
sandi149

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 102 posts
When I type in Tools and press enter, the list clears and there is nothing there.

#9
Jintan

    Advanced Member

  • Experts
  • PipPipPip
  • 103 posts
No "tools" in that then. The Chrome folder only contained the standard .css examples it normally does. When the user "Temp" is logged on and opens Firefox, when they access the Tools option, that causes problems as well? I reread what you said, and realize it is an actual shutdown. Leads me to wonder if the file removal left a missing item some other function needs.

Still making sure dss.exe is directly on your desktop, go to Start - Run, and copy/paste the following (then press OK):

"%userprofile%\desktop\dss.exe" /config

When the DSS Configuration display opens, under the Main Log, uncheck all items. Then under the Extra Log, place a check next to these two only:

Add/Remove Programs
Event Logs


Don't make any other changes at this time. Then click the "Scan!" button to start the scan.

Once the scan has completed a textbox will appear - copy/paste those contents back here please (extra.txt). (The logs can also be found in the C:\Deckard\System Scanner folder)

#10
sandi149

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 102 posts
When I went into the Temp user which is actually my husband's acct and I opened up Firefox, clicked on Tools, Options, it worked fine. It seems that it only isn't working for me.

Here's the log from Deckards.



Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- Add/Remove Programs ---------------------------------------------------------

--> "C:\Program Files\AOL\AOL Toolbar 5.0\uninstall.exe"
--> C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0B095086-7205-4D48-90DF-DCD16613C6D4}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0B095086-7205-4D48-90DF-DCD16613C6D4}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{103BCDA0-E063-46AC-8028-64E78722ABA7}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{103BCDA0-E063-46AC-8028-64E78722ABA7}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2616B36E-38CE-4357-8AB5-8B3EE9B1C117}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2616B36E-38CE-4357-8AB5-8B3EE9B1C117}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4095E277-3005-42E9-8D84-DE6EB8704CEC}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4095E277-3005-42E9-8D84-DE6EB8704CEC}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4F2F3E0C-2025-4F5E-9583-AB8CD5AA88A6}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4F2F3E0C-2025-4F5E-9583-AB8CD5AA88A6}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{66BCC50C-22D9-4927-9251-27FA88A32214}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{66BCC50C-22D9-4927-9251-27FA88A32214}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7550D6AA-CCF3-4FDA-87D6-C2C1B2E5358D}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7550D6AA-CCF3-4FDA-87D6-C2C1B2E5358D}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{836612F0-1571-4C65-A4B7-58A39AA578EE}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{836612F0-1571-4C65-A4B7-58A39AA578EE}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98181885-5B28-4280-9B56-452FF877D5B9}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98181885-5B28-4280-9B56-452FF877D5B9}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9AB14DF5-3B04-4E3B-9969-695DBA7F2008}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9AB14DF5-3B04-4E3B-9969-695DBA7F2008}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D42EFA6C-0553-45F7-AD03-6D36207CA6D4}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D42EFA6C-0553-45F7-AD03-6D36207CA6D4}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D524239C-FD5C-4183-A49C-7930915A9C0A}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D524239C-FD5C-4183-A49C-7930915A9C0A}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DAAC5938-8026-4D0C-A476-D1954917B7F5}\SETUP.EXE" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DAAC5938-8026-4D0C-A476-D1954917B7F5}\SETUP.EXE" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DD2D9012-E5A1-4717-8EE9-8DB3F36E2F8C}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DD2D9012-E5A1-4717-8EE9-8DB3F36E2F8C}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{22EB2FA7-1BA0-4FFB-972F-353EC6ABA9D5}\setup.exe" -l0x9 -removeonly
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{28B97CAB-828F-49D8-A30A-675476F9BA92}\setup.exe" -l0x9 /cont -removeonly
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4E7DC12A-3597-4A94-9429-F6C6987361B1}\setup.exe" -l0x9 -removeonly
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6813C983-427E-4511-8456-E98FCAA1A125}\setup.exe" -l0x9 -removeonly
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7DADB304-AF20-48C3-A780-4B4133A08817}\setup.exe" -l0x9 -removeonly
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9C423CF6-2DAA-4A37-94B8-59D7ECC7DB13}\setup.exe" -l0x9 -removeonly
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ACE66099-E18E-4037-83C8-9D182E5B9FA8}\setup.exe" -l0x9 -removeonly
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B34B6E67-FCDD-4E03-8742-B5701427FAFB}\setup.exe" -l0x9 -removeonly
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FA6CC4B4-7741-4F8D-8E81-15C4BAB9869B}\setup.exe" -l0x9 -removeonly
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-00BA-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0114-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
Ad-Aware --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Adobe® Photoshop® Album Starter Edition 3.2 --> MsiExec.exe /I{A654A805-41D9-40C7-AA46-4AF04F044D61}
AIM 6 --> C:\Program Files\AIM6\uninst.exe
AOL Toolbar 5.0 --> "C:\Program Files\AOL\AOL Toolbar 5.0\uninstall.exe"
AOL Uninstaller (Choose which Products to Remove) --> C:\Program Files\Common Files\AOL\uninstaller.exe
Apple Mobile Device Support --> MsiExec.exe /I{D8AB8F0C-CEEB-4A29-8EF5-219B064813F4}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
ArcSoft PhotoImpression 5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D433ABC3-0CD8-4BB0-B6A9-84501B4B47B7}\Setup.exe" -l0x9
ATI - Software Uninstall Utility --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Control Panel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
BigOven --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E0267007-A6FD-4304-8131-346D1CEA6F82}\Setup.exe" -l0x9
BOClean --> C:\WINDOWS\UNBOC.EXE
CA Yahoo! Anti-Spy (remove only) --> "C:\Program Files\CA Yahoo! Anti-Spy\uninstall.exe"
CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
Celestia 1.4.1 --> "C:\Program Files\Celestia\unins000.exe"
Creative MediaSource --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}\SETUP.EXE" -l0x9 /remove
Creative Removable Disk Manager --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x9 /remove
Creative System Information --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9 /remove
Creative Zen Vision M --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DC3065BF-95B4-42C5-B47D-0B713CDA75D0}\SETUP.EXE" -l0x9 /remove
Dell Resource CD --> MsiExec.exe /X{FCD9CD52-7222-4672-94A0-A722BA702FD0}
DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Content Uploader --> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Converter --> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
EarthLink Smart Installer --> C:\Program Files\EarthLink\Smart Installer\UnSMI.exe
EPSON CX 4200 4800 Guide --> C:\Program Files\epson\guide\cx4200_4800_e\uninstall.exe
EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EPSON Scan --> C:\Program Files\epson\escndv\setup\setup.exe /r
ESET Online Scanner --> C:\WINDOWS\system32\OnlineScannerUninstaller.exe
EULAlyzer v1.2 --> "C:\Program Files\EULAlyzer\unins000.exe"
Google Earth --> MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
GoToAssist 8.0.0.480 --> C:\Program Files\Citrix\GoToAssist\480\G2AUninstaller.exe /uninstall
Graboid Video --> rundll32.exe dfshim.dll,ShArpMaintain GraboidClient.application, Culture=neutral, PublicKeyToken=a80ba8b73604aca7, processorArchitecture=msil
Harry Potter ™ Demo --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{86FD72CF-FC88-43D3-8F0C-B9316F6344B4}\setup.exe" -l0x9 Uninstall
Harry Potter and the Prisoner of Azkaban™ --> C:\Program Files\EA GAMES\Harry Potter and the Prisoner of Azkaban™\EAUninstall.exe
High Definition Audio Driver Package - KB835221 --> C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
InspiredCooking --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9C67E1B9-3CBB-42C5-AAF8-2E571111171B}\setup.exe" -l0x9
Intel® PRO Network Connections Drivers --> Prounstl.exe
InterActual Player --> C:\Program Files\InterActual\InterActual Player\inuninst.exe
iPIX MovieViewer --> C:\WINDOWS\ipUninst.exe C:\WINDOWS\Unwise.exe /a C:\PROGRA~1\IPIX\IPIXMO~1\V360Vwr.log,iPIX movieViewer
iTunes --> MsiExec.exe /I{B85C4D19-6CEB-48CF-BD98-C887AC8C6F94}
Java™ 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
Kaspersky Online Scanner --> C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
Legacy 6.0 --> C:\Legacy\UNWISE.EXE /U C:\Legacy\Install.log
LimeWire 4.16.7 --> "C:\Program Files\LimeWire\uninstall.exe"
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee SecurityCenter --> C:\Program Files\McAfee\MSC\mcuninst.exe
McAfee Uninstaller --> C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /uninstall=1 /interact=1 /script_proactive=0 /start=c:\PROGRA~1\mcafee.com\agent\uninst\comrem.dll::uninstall.htm
MetaFrame Presentation Server Web Client for Win32 --> RunDll32 ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\wficat.inf,DefaultUninstall
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Flight Simulator 2002 --> "C:\Program Files\Microsoft Games\FS2002\FSUNINSTALL.EXE" /runtemp /addremove
Microsoft Office Access MUI (English) 2007 --> MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007 --> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISER /dll OSETUP.DLL
Microsoft Office Enterprise 2007 --> MsiExec.exe /X{91120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel 2007 Get Started Tab --> MsiExec.exe /I{AB706D91-2242-4E1D-B4D0-1ED35387F5A7}
Microsoft Office Excel MUI (English) 2007 --> MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007 --> MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007 --> MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007 --> MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007 --> MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007 --> MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007 --> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007 --> MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word 2007 Get Started Tab --> MsiExec.exe /I{68B52EFD-86CC-486E-A8D0-A3A1554CB5BC}
Microsoft Office Word MUI (English) 2007 --> MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs --> MsiExec.exe /X{90120000-00B2-0409-0000-0000000FF1CE}
Microsoft Silverlight --> MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
mIRC --> "C:\Program Files\mIRC\mirc.exe" -uninstall
Monopoly (remove only) --> "C:\Program Files\Yahoo! Games\Monopoly\Uninstall.exe"
Mozilla ActiveX Control v1.7.12 --> C:\Program Files\Mozilla ActiveX Control v1.7.12\uninst.exe
Mozilla Firefox (2.0.0.14) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mozilla Thunderbird (2.0.0.14) --> C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
Netflix Movie Viewer --> MsiExec.exe /X{BCE72AED-3332-4863-9567-C5DCB9052CA2}
Netscape Navigator (9.0.0.6) --> C:\Program Files\Netscape\Navigator 9\uninstall\helper.exe
OverDrive Media Console --> MsiExec.exe /I{16D9439B-DF3D-43D1-A727-4B335300D07A}
Panda ActiveScan 2.0 --> C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
Personal Ancestral File 5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D94A8E22-DF2B-4107-9E51-608A60A7671D}\Setup.exe"
Personal Ancestral File Companion 5.2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{91AFACB3-CA46-4C1E-AF2D-F72EE0B112E4}\setup.exe" -l0x9 -uninst -removeonly
Photo Story 3 for Windows --> MsiExec.exe /I{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}
PICVideo Codecs --> C:\WINDOWS\system32\UNPICVID2.EXE "PICVideo Codecs Uninstall"
Putt Putt Saves the Zoo --> C:\PROGRA~1\INFOGR~1\PUTTPU~1\UNWISE.EXE C:\PROGRA~1\INFOGR~1\PUTTPU~1\INSTALL.LOG
QuickTime --> MsiExec.exe /I{6EC874C2-F950-4B7E-A5B7-B1066D6B74AA}
QuickTime 3.0 --> C:\WINDOWS\uninst.exe -f"C:\Program Files\QuickTime\DeIsL1.isu" -c"C:\WINDOWS\system32\QTUninst.dll
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Rhapsody Player Engine --> MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}
Scrapbook Factory Deluxe 3.0 --> MsiExec.exe /X{08F9879C-0AA3-4B0A-AACE-3498BBCAE175}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Excel 2007 (KB946974) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {85E83E2E-AF9B-439B-B4F9-EB9B7EF6A00E}
Security Update for Microsoft Office Publisher 2007 (KB950114) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
Security Update for Microsoft Office system 2007 (KB951808) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00}
Security Update for Microsoft Office Word 2007 (KB950113) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9}
Security Update for Office 2007 (KB947801) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E}
Security Update for Outlook 2007 (KB946983) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {66B9496E-C0C3-4065-9868-85CCA92126C3}
Security Update for Visio 2007 (KB947590) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
Sibelius Scorch (ActiveX Only) --> MsiExec.exe /I{C8E4455F-0F70-4DA2-A9F9-2D56C80E10AD}
SigmaTel Audio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x9 -remove -removeonly
Sony Picture Utility --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5068583-D569-468B-9755-5FBF5848F46F}\setup.exe" -l0x9 /removeonly uninstall -removeonly
Sony USB Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}\setup.exe" -l0x9 UNINSTALL -removeonly
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Spybot - Search & Destroy 1.5.2.20 --> "C:\WINDOWS\unins000.exe"
SpywareBlaster 4.0 --> "C:\Program Files\SpywareBlaster\unins000.exe"
SpywareGuard v2.2 --> "C:\Program Files\SpywareGuard\unins000.exe"
SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
The Game Of Life --> C:\WINDOWS\uninst.exe -f"C:\Program Files\Hasbro Interactive\The Game Of Life\DeIsL1.isu" -c"C:\Program Files\Hasbro Interactive\The Game Of Life\_ISREG32.DLL"
Uninstall AOL Emergency Connect Utility 1.0 --> C:\Program Files\Common Files\AOL\ECU\uninst.exe
Update for Office 2007 (KB946691) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Outlook 2007 Junk Email Filter (kb950378) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {F6296086-AED5-4EC0-938B-08EA0254F20E}
VideoLAN VLC media player 0.8.6d --> C:\Program Files\VideoLAN\VLC\uninstall.exe
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Virtual Earth 3D (Beta) --> MsiExec.exe /I{D76D1828-BBA0-4BD9-8181-5ACC617DC5F2}
Visual IRC 2.0 --> "C:\Program Files\ViRC\unins000.exe"
Webshots Desktop --> "C:\Program Files\Webshots\unins000.exe"
Webshots Toolbar --> C:\Program Files\Webshots\ToolbarUninstall.exe
Windows Defender --> MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401}
Windows Desktop Search 3.01 --> "C:\WINDOWS\$NtUninstallKB917013$\spuninst\spuninst.exe"
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows XP Service Pack 3 --> "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinPatrol 2008 --> C:\PROGRA~1\BILLPS~1\WINPAT~1\Setup.exe /remove /q0
World of Warcraft --> C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exe
Yahoo! Browser Services --> C:\PROGRA~1\Yahoo!\Common\UNIN_Y~1.EXE /S
Yahoo! Install Manager --> C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Internet Mail --> C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll
Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Search Protection --> C:\PROGRA~1\Yahoo!\SEARCH~1\UNINST~1.EXE
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE


-- Application Event Log -------------------------------------------------------

Event Record #/Type18453 / Warning
Event Submitted/Written: 06/24/2008 08:37:30 PM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Event Record #/Type18444 / Error
Event Submitted/Written: 06/23/2008 07:04:12 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application iexplore.exe, version 7.0.6000.16674, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Event Record #/Type18443 / Error
Event Submitted/Written: 06/23/2008 07:00:19 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application iexplore.exe, version 7.0.6000.16674, faulting module unknown, version 0.0.0.0, fault address 0x00000002.
Processing media-specific event for [iexplore.exe!ws!]

Event Record #/Type18438 / Warning
Event Submitted/Written: 06/23/2008 06:06:24 AM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Event Record #/Type18433 / Error
Event Submitted/Written: 06/22/2008 10:03:08 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application CTCMS.exe, version 3.0.41.0, faulting module comctl32.dll, version 6.0.2900.5512, fault address 0x00063d38.
Processing media-specific event for [CTCMS.exe!ws!]



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type22164 / Error
Event Submitted/Written: 06/24/2008 08:35:03 PM
Event ID/Source: 10001 / DCOM
Event Description:
Unable to start a DCOM Server: {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} as /.
The error:
"%%233"
Happened while starting this command:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe -Embedding

Event Record #/Type22163 / Error
Event Submitted/Written: 06/24/2008 08:35:03 PM
Event ID/Source: 10001 / DCOM
Event Description:
Unable to start a DCOM Server: {6A972E27-93E2-4F98-8367-4101B2073814} as /.
The error:
"%%233"
Happened while starting this command:
"c:\PROGRA~1\mcafee\msc\mcuimgr.exe" -Embedding

Event Record #/Type22149 / Warning
Event Submitted/Written: 06/22/2008 09:01:47 PM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Event Record #/Type22144 / Warning
Event Submitted/Written: 06/22/2008 10:01:37 AM
Event ID/Source: 15208 / WPDMTPDriver
Event Description:
MTP Protocol Driver has detected that the device 'Creative Technology Ltd, Creative Zen Vision:M, 1.30.02_0.00.16' cannot accept read-only properties when creating new objects ((27)).

Event Record #/Type22140 / Error
Event Submitted/Written: 06/22/2008 09:43:48 AM
Event ID/Source: 10001 / DCOM
Event Description:
Unable to start a DCOM Server: {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} as /.
The error:
"%%233"
Happened while starting this command:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe -Embedding



-- End of Deckard's System Scanner: finished at 2008-06-24 20:40:09 ------------

#11
Jintan

    Advanced Member

  • Experts
  • PipPipPip
  • 103 posts
No significant info in those views, but did want to check your Firefox version. As there does not seem to be any bad modifications in the profiles parts I checked, I would like you to download and install Firefox 3. It will install and basically overwrite the existing copy, and might correct changes in your existing copy as well. Be sure to close Firefox before installing, re-open and check it for changes and improvements after installing, but also reboot at some point to complete any changes made. Then post back an update please.

#12
sandi149

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 102 posts
Actually, a day after Firefox 3 was released last week I d/l it. When I tried to launch the program it crashed immediately. I tried several times and it still crashed. Never would open and would give me some sort crash report. So I uninstalled everything, tried again and the same thing happened. Then I went on the Mozilla forums to ask what to do about it. Never really got much help from them, but I see that many many others are experiencing the same thing.

So I uninstalled version 3 and reinstalled version 2 again.

In my opinion, I think there are still lots of bugs in Version 3 that Mozilla needs to work out because so many people are having problems with it.

#13
sandi149

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 102 posts
Nope, Temp user hasn't been using Firefox since I had those popups. I still have the Version 2 exe file if that's what you mean by installer.

Now I seem to have another problem. When I click on a link in Outlook, I get an error msg saying "this operation has been cancelled due to restrictions in effect on this computer. Please contact your system administrator". I never had that happen to me before. I was always able to click on a link in Outlook and the browser would open up right to the page.

This computer is doing some very strange things lately. :P

Thanks for your help.

#14
Jintan

    Advanced Member

  • Experts
  • PipPipPip
  • 103 posts
Strange likely more related to changes like those with Firefox. That sounds more like those recent changes changed your defaults there. Right click the IE desktop shortcut and select Properties. Under the Programs tab click the "Reset Web Settings" button. Then Apply/OK to close the display.

Yes, go ahead and click the Firefox installer and allow Firefox to install "over" the existing install. Actually, after that be prepared to repeat the steps to reset web settings.

#15
sandi149

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 102 posts
Jintan, there is no button for "Reset Web settings" when I go into the Programs tab. But what I did do was click on "Make Internet Explorer the default browser" and then retried to click on a link in an Outlook email and now IE opens, which is fine with me. I'm actually starting to like IE better than Firefox since I've had so many problems with it.

Ok....clicked on the firefox exe file to install it and when it finished, I opened the browser and the same thing happens when I click on Tools, Options.

#16
Jintan

    Advanced Member

  • Experts
  • PipPipPip
  • 103 posts
Sorry - I haven't looked back through the logs but betting you have IE7 against my IE6 steps provided. I rethought the issue with Tools, which took me to issues with plugins, which took me back to that Mozilla ActiveX Control. It is a cause of the type of crashes you are describing. I would suggest you close all open browsers (important) then go to Add/Remove Programs and uninstall Mozilla ActiveX Control v1.7.12.

#17
sandi149

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 102 posts
Yes, I do have IE 7.

Ok. I uninstalled that Active X but Firefox still shuts down after I click on Tools, Options.

Do you think there is a corrupt file or something?

#18
Jintan

    Advanced Member

  • Experts
  • PipPipPip
  • 103 posts
It is definitely your user Firefox settings there. I checked to see where Firefox goes when you click the Tools option, and we already know malware placed itself in your folders there, so let's look at those two areas now.


@ECHO OFF
if exist Check.txt del /q Check.txt
regedit /e Regsearch1.txt "HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\MenuPopup"
regedit /e Regsearch2.txt "HKEY_CLASSES_ROOT\Applications\FIREFOX.EXE"
Type Regsearch*.txt > Check.txt
del /q Regsearch*.txt 
Notepad Check.txt
Open Notepad (Start - Run, type notepad and press Enter).

Copy/paste the above text into the open text box, then save this to your desktop as "foxcheck.bat"

Be sure to include the "" quotes in the name. Then click on foxcheck.bat. When the scan completes a textbox will open - copy/paste those contents back here please.

------------------------------

@ECHO OFF
if exist showfox.txt del /q showfox.txt
cd %userprofile%\Application Data\Mozilla\Firefox\Profiles
dir /s > c:\showfox.txt & start notepad c:\showfox.txt
Again open Notepad (Start - Run, type notepad and press Enter).

Copy/paste the above text into the open text box, then save this to your desktop as "foxlook.bat"

Be sure to include the "" quotes in the name. Then click on foxlook.bat. When the scan completes a textbox will open - copy/paste those contents back here please. This one will be a bit longish.

#19
Jintan

    Advanced Member

  • Experts
  • PipPipPip
  • 103 posts
Sandi, the larger second log leads me to a change to make it a bit easier to see some target info. Instead of the earlier "foxlook.bat" step do this instead please:


@ECHO OFF
if exist showfox.txt del /q showfox.txt
cd %userprofile%\Application Data\Mozilla\Firefox\Profiles
dir /s /o:d > c:\showfox.txt & start notepad c:\showfox.txt
Again open Notepad (Start - Run, type notepad and press Enter).

Copy/paste the above text into the open text box, then save this to your desktop as "foxlook.bat"

Be sure to include the "" quotes in the name. Then click on foxlook.bat. When the scan completes a textbox will open - copy/paste those contents back here please.

#20
sandi149

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 102 posts
Ok, here you go.


Volume in drive C has no label.
Volume Serial Number is 50CE-3C98

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles

06/22/2008 03:56 PM <DIR> ..
06/22/2008 03:56 PM <DIR> .
06/23/2008 08:49 PM <DIR> gh4p514o.default
06/25/2008 05:25 PM <DIR> kkq2lwzk.Sandi New Profile
0 File(s) 0 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default

04/04/2008 06:04 PM 3,287 search.rdf
04/04/2008 06:04 PM 356 mimeTypes.rdf
06/18/2008 06:06 PM <DIR> chrome
06/18/2008 06:06 PM 146 compatibility.ini
06/18/2008 06:06 PM 16,384 secmod.db
06/18/2008 06:06 PM 2,048 search.sqlite
06/18/2008 06:06 PM 165,516 temp.js
06/18/2008 06:06 PM 165,516 search.dat
06/18/2008 06:07 PM 92 hostperm.1
06/19/2008 09:05 PM <DIR> searchplugins
06/19/2008 09:40 PM 7,288 extensions.rdf
06/19/2008 09:40 PM 831 extensions.cache
06/19/2008 09:40 PM 576 extensions.ini
06/19/2008 09:40 PM 98,403 xpti.dat
06/19/2008 09:40 PM 163,402 compreg.dat
06/22/2008 06:43 AM <DIR> GoogleToolbarData
06/22/2008 06:43 AM <DIR> bookmarkbackups
06/22/2008 06:53 AM <DIR> extensions
06/22/2008 06:53 AM 865 blocklist.xml
06/22/2008 09:42 AM 124,082 bookmarks.bak
06/22/2008 09:42 AM 65,536 cert8.db
06/22/2008 09:42 AM 16,384 key3.db
06/22/2008 09:42 AM 124,082 bookmarks.html
06/22/2008 11:49 AM 166 signons2.txt
06/22/2008 03:07 PM 4,106,240 urlclassifier2.sqlite
06/22/2008 03:12 PM 17,423 sessionstore.bak
06/22/2008 03:12 PM 233 formhistory.dat
06/22/2008 03:47 PM 9,460 prefs.js
06/22/2008 03:47 PM 25,942 cookies.txt
06/22/2008 03:47 PM 490 sessionstore.js
06/22/2008 03:47 PM 1,728 localstore.rdf
06/22/2008 03:47 PM 268,620 history.dat
06/23/2008 07:17 PM 2,683 prefs.zip
06/23/2008 08:49 PM <DIR> ..
06/23/2008 08:49 PM <DIR> .
06/23/2008 08:49 PM 1,209 chrome.zip
29 File(s) 5,388,988 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\bookmarkbackups

04/04/2008 06:04 PM 7,138 bookmarks-2008-06-18.html
06/18/2008 06:07 PM 38,253 bookmarks-2008-06-19.html
06/19/2008 09:56 PM 120,164 bookmarks-2008-06-20.html
06/20/2008 11:32 PM 124,082 bookmarks-2008-06-21.html
06/21/2008 09:02 AM 124,082 bookmarks-2008-06-22.html
06/22/2008 06:43 AM <DIR> ..
06/22/2008 06:43 AM <DIR> .
5 File(s) 413,719 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\chrome

04/04/2008 06:04 PM 1,078 userChrome-example.css
04/04/2008 06:04 PM 663 userContent-example.css
06/18/2008 06:06 PM <DIR> ..
06/18/2008 06:06 PM <DIR> .
2 File(s) 1,741 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\extensions

06/19/2008 09:05 PM <DIR> {3112ca9c-de6d-4884-a869-9855de68056c}
06/22/2008 06:53 AM <DIR> ..
06/22/2008 06:53 AM <DIR> .
0 File(s) 0 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

05/25/2007 04:52 PM 2,443 install.rdf
05/25/2007 04:52 PM 7,789 LICENSE.txt
05/25/2007 04:52 PM 2,599 chrome.manifest
06/19/2008 09:05 PM <DIR> lib
06/19/2008 09:05 PM <DIR> chrome
06/19/2008 09:05 PM <DIR> META-INF
06/19/2008 09:05 PM <DIR> ..
06/19/2008 09:05 PM <DIR> .
06/19/2008 09:05 PM <DIR> defaults
06/19/2008 09:05 PM <DIR> components
3 File(s) 12,831 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\chrome

05/25/2007 04:52 PM 574,273 google-toolbar.jar
06/19/2008 09:05 PM <DIR> ..
06/19/2008 09:05 PM <DIR> .
1 File(s) 574,273 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components

05/25/2007 04:52 PM 139,264 metrics.dll
05/25/2007 04:52 PM 7,824 bootstrap.js
05/25/2007 04:52 PM 351,232 googletoolbar.dll
05/25/2007 04:52 PM 4,578 googletoolbar.xpt
05/25/2007 04:52 PM 1,126 metrics.xpt
06/19/2008 09:05 PM <DIR> ..
06/19/2008 09:05 PM <DIR> .
5 File(s) 504,024 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults

06/19/2008 09:05 PM <DIR> preferences
06/19/2008 09:05 PM <DIR> custombuttons
06/19/2008 09:05 PM <DIR> ..
06/19/2008 09:05 PM <DIR> .
06/19/2008 09:05 PM <DIR> contenthandling
0 File(s) 0 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults\contenthandling

05/25/2007 04:52 PM 22,486 doc.ico
06/19/2008 09:05 PM <DIR> ..
06/19/2008 09:05 PM <DIR> .
1 File(s) 22,486 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults\custombuttons

05/25/2007 04:52 PM 6,697 toolbar.google.com_J66T77NJDBMW4FEUU7FA.xml
05/25/2007 04:52 PM 2,005 toolbar.google.com_CTK0Y7F4MTG6NKYH03WT.xml
05/25/2007 04:52 PM 7,667 toolbar.google.com_O8Y91YHB24Z6SR0SGYSK.xml
06/19/2008 09:05 PM <DIR> ..
06/19/2008 09:05 PM <DIR> .
3 File(s) 16,369 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults\preferences

05/25/2007 04:52 PM 4,341 options.js
06/19/2008 09:05 PM <DIR> ..
06/19/2008 09:05 PM <DIR> .
1 File(s) 4,341 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\lib

05/25/2007 04:52 PM 550,145 toolbar.js
06/19/2008 09:05 PM <DIR> ..
06/19/2008 09:05 PM <DIR> .
1 File(s) 550,145 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\META-INF

05/25/2007 11:19 AM 3,247 zigbert.rsa
05/25/2007 11:19 AM 2,303 manifest.mf
05/25/2007 11:19 AM 2,411 zigbert.sf
06/19/2008 09:05 PM <DIR> ..
06/19/2008 09:05 PM <DIR> .
3 File(s) 7,961 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\GoogleToolbarData

06/19/2008 09:05 PM <DIR> feeds
06/19/2008 09:05 PM 141,312 googlesafebrowsing.db
06/22/2008 06:43 AM 35 features.properties
06/22/2008 06:43 AM <DIR> ..
06/22/2008 06:43 AM <DIR> .
06/22/2008 09:43 AM 51 textreuse.dat
06/22/2008 09:43 AM 295 searchhistory.xml
06/22/2008 03:47 PM 77 kf.txt
5 File(s) 141,770 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\GoogleToolbarData\feeds

06/19/2008 09:05 PM <DIR> ..
06/19/2008 09:05 PM <DIR> .
06/22/2008 03:47 PM 9,545 toolbar.google.com_O8Y91YHB24Z6SR0SGYSK.xml
1 File(s) 9,545 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\searchplugins

06/19/2008 09:05 PM <DIR> searchplugins-backup
06/19/2008 09:05 PM <DIR> ..
06/19/2008 09:05 PM 2,386 siteadvisor.xml
06/19/2008 09:05 PM <DIR> .
1 File(s) 2,386 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\gh4p514o.default\searchplugins\searchplugins-backup

06/18/2008 06:07 PM 276 siteadvisor.src
06/19/2008 09:05 PM <DIR> ..
06/19/2008 09:05 PM <DIR> .
1 File(s) 276 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile

04/04/2008 06:04 PM 3,287 search.rdf
04/04/2008 06:04 PM 356 mimeTypes.rdf
06/22/2008 03:56 PM <DIR> chrome
06/22/2008 03:57 PM 146 compatibility.ini
06/22/2008 03:57 PM 16,384 secmod.db
06/22/2008 03:57 PM 2,048 search.sqlite
06/23/2008 09:04 AM 165,516 temp.js
06/23/2008 09:04 AM 165,516 search.dat
06/23/2008 09:04 AM <DIR> searchplugins
06/23/2008 09:04 AM 92 hostperm.1
06/23/2008 09:09 AM 233 formhistory.dat
06/24/2008 09:26 AM 2,048 webappsstore.sqlite
06/25/2008 06:22 AM <DIR> bookmarkbackups
06/25/2008 03:08 PM <DIR> GoogleToolbarData
06/25/2008 03:13 PM 5,053,440 urlclassifier2.sqlite
06/25/2008 03:18 PM <DIR> extensions
06/25/2008 03:18 PM 865 blocklist.xml
06/25/2008 03:21 PM 134 signons2.txt
06/25/2008 03:36 PM 70,392 bookmarks.bak
06/25/2008 03:36 PM 65,536 cert8.db
06/25/2008 03:36 PM 16,384 key3.db
06/25/2008 03:36 PM 70,392 bookmarks.html
06/25/2008 03:56 PM 7,296 extensions.rdf
06/25/2008 03:56 PM 831 extensions.cache
06/25/2008 03:56 PM 586 extensions.ini
06/25/2008 03:56 PM 98,413 xpti.dat
06/25/2008 03:56 PM 163,862 compreg.dat
06/25/2008 03:57 PM 18,786 history.dat
06/25/2008 05:25 PM 5,533 prefs.js
06/25/2008 05:25 PM 2,383 localstore.rdf
06/25/2008 05:25 PM 3,742 cookies.txt
06/25/2008 05:25 PM <DIR> .
06/25/2008 05:25 PM <DIR> ..
26 File(s) 5,934,201 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\bookmarkbackups

04/04/2008 06:04 PM 7,138 bookmarks-2008-06-22.html
04/04/2008 06:04 PM 7,138 bookmarks-2008-06-23.html
06/23/2008 10:17 PM 56,797 bookmarks-2008-06-24.html
06/24/2008 08:43 PM 56,797 bookmarks-2008-06-25.html
06/25/2008 06:22 AM <DIR> ..
06/25/2008 06:22 AM <DIR> .
4 File(s) 127,870 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\chrome

04/04/2008 06:04 PM 1,078 userChrome-example.css
04/04/2008 06:04 PM 663 userContent-example.css
06/22/2008 03:56 PM <DIR> ..
06/22/2008 03:56 PM <DIR> .
2 File(s) 1,741 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\extensions

06/23/2008 09:03 AM <DIR> {3112ca9c-de6d-4884-a869-9855de68056c}
06/25/2008 03:18 PM <DIR> ..
06/25/2008 03:18 PM <DIR> .
0 File(s) 0 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

05/25/2007 04:52 PM 2,599 chrome.manifest
05/25/2007 04:52 PM 7,789 LICENSE.txt
05/25/2007 04:52 PM 2,443 install.rdf
06/23/2008 09:03 AM <DIR> lib
06/23/2008 09:03 AM <DIR> chrome
06/23/2008 09:03 AM <DIR> META-INF
06/23/2008 09:03 AM <DIR> .
06/23/2008 09:03 AM <DIR> ..
06/23/2008 09:03 AM <DIR> defaults
06/23/2008 09:03 AM <DIR> components
3 File(s) 12,831 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\chrome

05/25/2007 04:52 PM 574,273 google-toolbar.jar
06/23/2008 09:03 AM <DIR> ..
06/23/2008 09:03 AM <DIR> .
1 File(s) 574,273 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components

05/25/2007 04:52 PM 139,264 metrics.dll
05/25/2007 04:52 PM 7,824 bootstrap.js
05/25/2007 04:52 PM 351,232 googletoolbar.dll
05/25/2007 04:52 PM 4,578 googletoolbar.xpt
05/25/2007 04:52 PM 1,126 metrics.xpt
06/23/2008 09:03 AM <DIR> ..
06/23/2008 09:03 AM <DIR> .
5 File(s) 504,024 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults

06/23/2008 09:03 AM <DIR> preferences
06/23/2008 09:03 AM <DIR> custombuttons
06/23/2008 09:03 AM <DIR> ..
06/23/2008 09:03 AM <DIR> .
06/23/2008 09:03 AM <DIR> contenthandling
0 File(s) 0 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults\contenthandling

05/25/2007 04:52 PM 22,486 doc.ico
06/23/2008 09:03 AM <DIR> ..
06/23/2008 09:03 AM <DIR> .
1 File(s) 22,486 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults\custombuttons

05/25/2007 04:52 PM 6,697 toolbar.google.com_J66T77NJDBMW4FEUU7FA.xml
05/25/2007 04:52 PM 2,005 toolbar.google.com_CTK0Y7F4MTG6NKYH03WT.xml
05/25/2007 04:52 PM 7,667 toolbar.google.com_O8Y91YHB24Z6SR0SGYSK.xml
06/23/2008 09:03 AM <DIR> ..
06/23/2008 09:03 AM <DIR> .
3 File(s) 16,369 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults\preferences

05/25/2007 04:52 PM 4,341 options.js
06/23/2008 09:03 AM <DIR> ..
06/23/2008 09:03 AM <DIR> .
1 File(s) 4,341 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\lib

05/25/2007 04:52 PM 550,145 toolbar.js
06/23/2008 09:03 AM <DIR> ..
06/23/2008 09:03 AM <DIR> .
1 File(s) 550,145 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\META-INF

05/25/2007 11:19 AM 3,247 zigbert.rsa
05/25/2007 11:19 AM 2,303 manifest.mf
05/25/2007 11:19 AM 2,411 zigbert.sf
06/23/2008 09:03 AM <DIR> ..
06/23/2008 09:03 AM <DIR> .
3 File(s) 7,961 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\GoogleToolbarData

06/23/2008 09:03 AM <DIR> feeds
06/23/2008 09:03 AM 141,312 googlesafebrowsing.db
06/25/2008 03:08 PM 35 features.properties
06/25/2008 03:08 PM <DIR> ..
06/25/2008 03:08 PM <DIR> .
06/25/2008 03:36 PM 49 textreuse.dat
06/25/2008 03:36 PM 139 searchhistory.xml
06/25/2008 05:25 PM 77 kf.txt
5 File(s) 141,612 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\GoogleToolbarData\feeds

06/23/2008 09:03 AM <DIR> ..
06/23/2008 09:03 AM <DIR> .
06/25/2008 05:25 PM 9,545 toolbar.google.com_O8Y91YHB24Z6SR0SGYSK.xml
1 File(s) 9,545 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\searchplugins

06/23/2008 09:04 AM <DIR> searchplugins-backup
06/23/2008 09:04 AM 2,386 siteadvisor.xml
06/23/2008 09:04 AM <DIR> ..
06/23/2008 09:04 AM <DIR> .
1 File(s) 2,386 bytes

Directory of C:\Documents and Settings\Sandi\Application Data\Mozilla\Firefox\Profiles\kkq2lwzk.Sandi New Profile\searchplugins\searchplugins-backup

06/22/2008 03:57 PM 276 siteadvisor.src
06/23/2008 09:04 AM <DIR> ..
06/23/2008 09:04 AM <DIR> .
1 File(s) 276 bytes

Total Files Listed:
120 File(s) 15,560,916 bytes
104 Dir(s) 114,786,000,896 bytes free





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us