This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Slow computer, possibly virus melt

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Just a few days ago I noticed my internet connection slowing down quite a bit. I then started getting pop ups wanting me to download a program called Virus Melt. Using Malwarebytes anti malware i was able to remove it. The popups stopped but the computer still remains slow. I am running a network and another computer on the network is experiencing similar symptoms. It didnt have the virusmelt problem but it has slowed down around the same time. I will post the log of the main computer. Im not sure if you want to look at them one at a time so just let me know if u need to see the other log.

*Edit* Today 3/08 I started getting popups saying I was infected and wanting me to download Virus Doctor, this is different than the popups I was experiencing before.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:17:50 PM, on 3/6/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Portrait Displays\Plugins\AM\dtsslsrv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Kodak\printer\center\KodakSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\WINDOWS\SM1BG.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
C:\Program Files\twc\medicsp2\bin\sprtsvc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Samsung\EmoDio\SMSTray.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Kodak\Printer\Center\EKDiscovery.exe
C:\Program Files\Lexmark X125\LEX125SU.exe
C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Speeditup Free\SpeedItUp.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.rr.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [LMPDPSRV] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE"
O4 - HKLM\..\Run: [BCMSMMSG] "C:\WINDOWS\BCMSMMSG.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SM1BG] "C:\WINDOWS\SM1BG.EXE"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [PC-Checkup] "C:\Program Files\Speeditup Free\PCCheckUp\PCCheckUp.exe" -mini
O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SMSTray] "C:\Program Files\Samsung\EmoDio\SMSTray.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpeedItUpEX] C:\Program Files\Speeditup Free\SpeedItUp.exe -MINI
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Lexmark X125 Settings Utility.lnk = C:\Program Files\Lexmark X125\LEX125SU.exe
O4 - Global Startup: SnapDetect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n024p/EN/install/gtdownlr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} - http://entimg.msn.com/client/msnediag4227.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) - http://webcamnow.com/fs5/ax/ActiveXWebCam.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…rk.cab56649.cab
O16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/36/install/gtdownde.cab
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} (MSN Games – Backgammon) - http://zone.msn.com/bingame/zpagames/ZPA_B…on.cab64162.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Asset Management Daemon - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Plugins\AM\dtsslsrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Acer Display\eDisplay Management\dtsrvc.exe (file missing)
O23 - Service: Google Update Service (gupdate1c98f7fef094cf4) (gupdate1c98f7fef094cf4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak AiO Network Discovery Service - Eastman Kodak Company - C:\Program Files\Kodak\Printer\Center\EKDiscovery.exe
O23 - Service: Kodak AiO Device Service (KodakSvc) - Eastman Kodak Company - C:\Program Files\Kodak\printer\center\KodakSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: SupportSoft Sprocket Service (medicsp2) (sprtsvc_medicsp2) - SupportSoft, Inc. - C:\Program Files\twc\medicsp2\bin\sprtsvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe

–
End of file - 12941 bytes
Hi,

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Thanks.
Hi, thank you for taking the time to help me. :) Here are the logs. DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 7:14:39.42 on Tue 03/10/2009 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.383 [GMT -4:00] AV: CA Anti-Virus *On-access scanning enabled* (Updated) AV: avast! antivirus 4.8.1335 [VPS 090309-0] *On-access scanning disabled* (Updated) ============== Running Processes =============== C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\BCMSMMSG.exe C:\WINDOWS\SM1BG.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Samsung\EmoDio\SMSTray.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\Portrait Displays\Plugins\AM\dtsslsrv.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Program Files\Lexmark X125\LEX125SU.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe C:\Program Files\Kodak\printer\center\KodakSvc.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\AIM6\aolsoftware.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe C:\Program Files\twc\medicsp2\bin\sprtsvc.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Program Files\Kodak\Printer\Center\EKDiscovery.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\internet explorer\iexplore.exe C:\Documents and Settings\Nick\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.rr.com/ uDefault_Search_URL = hxxp://www.rr.com uSearchMigratedDefaultURL = mSearchMigratedDefaultURL = uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet mRun: [BCMSMMSG] "c:\windows\BCMSMMSG.exe" mRun: [SM1BG] "c:\windows\SM1BG.EXE" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [NvCplDaemon] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] "c:\windows\system32\nwiz.exe" /install mRun: [NvMediaCenter] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [EKIJ5000StatusMonitor] "c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe" mRun: [AppleSyncNotifier] "c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SMSTray] "c:\program files\samsung\emodio\SMSTray.exe" mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [PC-Checkup] "c:\program files\speeditup free\pccheckup\PCCheckUp.exe" -mini StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\lexmar~1.lnk - c:\program files\lexmark x125\LEX125SU.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\snapde~1.lnk - c:\windows\twain_32\ca561a\SnapDetect.exe IE: E&xport; to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL Trusted Zone: aol.com\free DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {25365FF3-2746-4230-9DA7-163CCA318309} - hxxp://inst.c-wss.com/n024p/EN/install/gtdownlr.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} - hxxp://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} - hxxp://www.acclaim.com/cabs/acclaim_v4.cab DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} - hxxp://entimg.msn.com/client/msnediag4227.cab DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - hxxp://mediaplayer.walmart.com/installer/install.cab DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} - hxxp://chat.yahoo.com/cab/yuplapp.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {9732FB42-C321-11D1-836F-00A0C993F125} - hxxp://www.pcpitstop.com/mhLbl.cab DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} - hxxp://webcamnow.com/fs5/ax/ActiveXWebCam.cab DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab56649.cab DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} - hxxps://ediagnostics.lexmark.com/serval.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab41227.cab DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} - hxxp://chat.yahoo.com/cab/yvwrctl.cab DPF: {E856B973-45FD-4559-8F82-EAB539144667} - hxxp://pccheckup.dellfix.com/rel/36/install/gtdownde.cab DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} - hxxp://zone.msn.com/bingame/zpagames/ZPA_Backgammon.cab64162.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: ShellHook Class: {88485281-8b4b-4f8d-9ede-82e29a064277} - c:\progra~1\markany\conten~1\MACSMA~1.DLL ============= SERVICES / DRIVERS =============== R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2008-8-9 29808] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-3-8 114768] R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2009-3-6 26376] R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2009-3-6 21128] R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\vetefile.sys [2009-3-6 880560] R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2009-3-6 32264] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-3-8 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-3-8 138680] R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\kodak\printer\center\EKDiscovery.exe [2008-10-10 274432] R2 KodakSvc;Kodak AiO Device Service;c:\program files\kodak\printer\center\KodakSvc.exe [2008-10-30 28672] R2 PdiService;Portrait Displays SDK Service;c:\program files\common files\portrait displays\drivers\pdisrvc.exe [2008-11-28 90112] R2 sprtsvc_medicsp2;SupportSoft Sprocket Service (medicsp2);c:\program files\twc\medicsp2\bin\sprtsvc.exe [2008-12-9 202280] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-1-23 24652] R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\spy sweeper\SpySweeper.exe [2008-10-2 3667304] R2 WRConsumerService;Webroot Client Service;c:\program files\webroot\spy sweeper\WRConsumerService.exe [2008-11-1 1066360] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-3-8 352920] R3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter;c:\windows\system32\drivers\lne100v5.sys [2006-12-29 36224] S1 VETFDDNT;VET Floppy Boot Sector Monitor; [x] S2 gupdate1c98f7fef094cf4;Google Update Service (gupdate1c98f7fef094cf4);c:\program files\google\update\GoogleUpdate.exe [2009-2-15 133104] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-3-8 254040] S3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2009-3-6 108368] S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2008-7-10 47128] S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-7-10 242712] S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2008-7-10 369688] =============== Created Last 30 ================ 2009-03-07 18:24 –d—– c:\program files\LimeWire 2009-03-06 21:28 –d—– c:\windows\CAVTemp 2009-03-06 21:19 880,560 a——- c:\windows\system32\drivers\vetefile.sys 2009-03-06 21:19 108,368 a——- c:\windows\system32\drivers\veteboot.sys 2009-03-06 21:17 32,264 a——- c:\windows\system32\drivers\vetmonnt.sys 2009-03-06 21:17 26,376 a——- c:\windows\system32\drivers\vet-filt.sys 2009-03-06 21:17 21,128 a——- c:\windows\system32\drivers\vet-rec.sys 2009-03-06 21:01 66,048 a——- c:\windows\ieResetIcons.exe 2009-03-06 00:03 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-03-06 00:03 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-03-06 00:03 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-03-05 17:41 –d—– c:\program files\AVG 2009-03-05 00:24 –dsh— c:\docume~1\alluse~1\applic~1\e2efe92 2009-03-03 23:43 25,272 a——- c:\windows\system32\drivers\purendis.sys 2009-03-03 20:48 –d—– c:\program files\common files\Pure Networks Shared 2009-02-25 06:57 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat 2009-02-20 23:34 14,592 ac—— c:\windows\system32\dllcache\kbdhid.sys 2009-02-20 23:34 14,592 a——- c:\windows\system32\drivers\kbdhid.sys 2009-02-20 13:24 –d—– c:\program files\Walmart MP3 Music Downloads 2009-02-15 13:30 20,992 ac—— c:\windows\system32\dllcache\dshowext.ax 2009-02-15 13:30 20,992 a——- c:\windows\system32\dshowext.ax ==================== Find3M ==================== 2009-03-05 00:24 73 a——- c:\windows\fonts\kernel32.sys 2009-03-05 00:24 44 a——- c:\windows\fonts\SICKBOY.sys 2009-02-20 20:45 115,200 ac—— c:\windows\snap.dat 2009-01-20 21:58 124,464 a——- c:\windows\system32\drivers\SYMEVENT.SYS 2009-01-20 21:58 60,808 a——- c:\windows\system32\S32EVNT1.DLL 2009-01-20 21:58 10,635 a——- c:\windows\system32\drivers\SYMEVENT.CAT 2009-01-20 21:58 806 a——- c:\windows\system32\drivers\SYMEVENT.INF 2009-01-17 13:55 410,984 a——- c:\windows\system32\deploytk.dll 2009-01-16 22:35 3,594,752 ——– c:\windows\system32\dllcache\mshtml.dll 2009-01-06 18:56 3,932 ac—— c:\docume~1\nick\applic~1\LMLayout.dat 2009-01-06 18:56 268 ac—— c:\docume~1\nick\applic~1\LMCPaper.dat 2008-12-19 05:10 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2008-12-19 01:25 634,024 ——– c:\windows\system32\dllcache\iexplore.exe 2008-12-19 01:23 161,792 ——– c:\windows\system32\dllcache\ieakui.dll 2008-12-12 12:18 87,336 a——- c:\windows\system32\dns-sd.exe 2008-12-12 12:11 61,440 a——- c:\windows\system32\dnssd.dll 2008-10-01 22:03 47,360 ac—— c:\docume~1\nick\applic~1\pcouffin.sys 2008-02-02 17:46 76,920 ac—— c:\docume~1\nick\applic~1\GDIPFONTCACHEV1.DAT 2007-12-31 17:06 87,608 ac—— c:\docume~1\nick\applic~1\ezpinst.exe 2003-08-27 14:19 36,963 ac—r– c:\program files\common files\SM1updtr.dll 2008-09-13 18:16 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091320080914\index.dat ============= FINISH: 7:15:44.76 ===============

Attachments:

Hi,

LimeWire
You have LimeWire, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm
See Clean/Infected P2P Programs here

I would recommend that you uninstall LimeWire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


I notice that you have 2 AntiVirus programs running (Avast! and CA). While this may seem like a good idea, multiple AntiVirus programs running at the same time can conflict with each other as well as slowing your system down unnecessarily. I recommend you pick one of them and remove the other.


Please download OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Files
    c:\windows\fonts\kernel32.sys
    c:\windows\fonts\SICKBOY.sys

    :Commands
    [emptytemp]
    [Reboot]

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Please run this online scan, using Internet Explorer with Administrator priviledges (Vista users right-click and select Run As Administrator…):

Panda Activescan
  • Once you are on the Panda site, click the Scan now button
  • When prompted to install ActiveX control click Install
  • On the update page, click on the security warning at the top of the page and select "Run ActiveX control…"
  • Panda should now start scanning your system.
  • When the scan completes, if anything malicious is detected, click the Export To…(with a little notepad icon) button, then Save the report to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log.Let me know how things are running now.

Thanks.
At the moment the computer seems to be doing fairly well. Alot of the slowness I was experiencing was with pictures loading on webpages, and that is fixed. It is also no longer slow between web page loading. The startup of the browser seems a tad slow but that may just be the homepage im using. As far as having 2 anti virus programs, I had removed CA antivirus so I have no idea why it would still be running. I don't even see it on the program list so that I can remove it. Another thing is that since these problems started Ive been getting a pop up saying something "Revocation information for the security certificate for this site is no available. Do you want to proceed?" I am then given the options to click yes, no. or view certificate. I have been getting this from time to time, the most recent was just now, I tried to update java. Other than that, its looking good. Here are the logs.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:48:16 AM, on 3/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Portrait Displays\Plugins\AM\dtsslsrv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Kodak\printer\center\KodakSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
C:\Program Files\twc\medicsp2\bin\sprtsvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Kodak\Printer\Center\EKDiscovery.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Samsung\EmoDio\SMSTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Lexmark X125\LEX125SU.exe
C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.rr.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rr.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [BCMSMMSG] "C:\WINDOWS\BCMSMMSG.exe"
O4 - HKLM\..\Run: [SM1BG] "C:\WINDOWS\SM1BG.EXE"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SMSTray] "C:\Program Files\Samsung\EmoDio\SMSTray.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PC-Checkup] "C:\Program Files\Speeditup Free\PCCheckUp\PCCheckUp.exe" -mini
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Lexmark X125 Settings Utility.lnk = C:\Program Files\Lexmark X125\LEX125SU.exe
O4 - Global Startup: SnapDetect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n024p/EN/install/gtdownlr.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} - http://entimg.msn.com/client/msnediag4227.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) - http://webcamnow.com/fs5/ax/ActiveXWebCam.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…rk.cab56649.cab
O16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/36/install/gtdownde.cab
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} (MSN Games – Backgammon) - http://zone.msn.com/bingame/zpagames/ZPA_B…on.cab64162.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Asset Management Daemon - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Plugins\AM\dtsslsrv.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Acer Display\eDisplay Management\dtsrvc.exe (file missing)
O23 - Service: Google Update Service (gupdate1c98f7fef094cf4) (gupdate1c98f7fef094cf4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak AiO Network Discovery Service - Eastman Kodak Company - C:\Program Files\Kodak\Printer\Center\EKDiscovery.exe
O23 - Service: Kodak AiO Device Service (KodakSvc) - Eastman Kodak Company - C:\Program Files\Kodak\printer\center\KodakSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: SupportSoft Sprocket Service (medicsp2) (sprtsvc_medicsp2) - SupportSoft, Inc. - C:\Program Files\twc\medicsp2\bin\sprtsvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe

–
End of file - 13375 bytes


========== FILES ==========
c:\windows\fonts\kernel32.sys moved successfully.
c:\windows\fonts\SICKBOY.sys moved successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS02406416-590D-4153-BC65-2B0F9E2EC424.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS032B166B-D600-49D5-8E7B-E970A8DAB971.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS05FE3FAD-F2A0-4BDA-983C-0C2592CA8205.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0701419F-228D-48EE-972D-0485F1A049BB.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0730B50D-10F0-4587-A55D-0F2485FBED86.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0BFA7C67-2871-4A74-932C-292A7ED24C2C.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0C168AE9-E476-4BF0-A4CF-6A35A65CC012.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS10E258C2-B8A9-4C96-8B02-073C89D3C438.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS12A70EE6-B492-410D-9721-8B4E6CFF62FB.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1680ADAA-68FB-4EF4-89E1-4560C712765B.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS175F9DF1-D18E-4499-BDB8-F8BEF895A9A9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS195A70EC-2726-45CF-9E88-9382C08CD056.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1A045660-B65C-4024-901A-2FA45AD4216B.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS24149FB6-C01A-459B-A787-99366C986599.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS252B04D4-F519-42F7-B9B9-5FA353158088.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS27C2FA01-42EA-4703-A400-A858B5874871.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS29E1C594-C894-4788-B5C3-83409BE92E54.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2A5908CA-EB0F-4930-894C-08BBCE277C87.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2EE1BE83-5B50-46B9-855C-EA3AD3F21229.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2F67159C-C07E-48D4-9B98-3603ED0D188D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS33E5B0C6-ACE8-4CD5-9319-DE337B3888F5.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS34294F12-751D-4DC9-92E9-3FA64F6E7246.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS360B4B4A-26E3-4243-980D-228502871B4B.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS378F2F99-7AAF-4160-82CB-6C55F45987F1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS38B5881F-D76E-42BE-AD56-805D0BDFFB88.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS3D577EC8-C612-48D3-AACD-5C43C934CB6D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS3F41FF32-103E-4473-AC40-35B958F06AE1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS447FA878-7D65-47AD-A39D-B4BB89094AE7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4571CCFE-43CD-41EF-AD21-7985F9AE06F5.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4645FC67-BF07-48BB-BCEC-AE7DB305F9D0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS510D6B49-94D8-41F2-BC59-26EBB69B62D5.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5176A18D-26BA-4910-9929-67DE48F15162.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS576CE0D3-6FB5-40C6-8A37-A2FB43BD4065.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5ADECA90-D843-474B-A6C9-1E6F29368B95.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5B2D7FD3-7E3A-4EBD-BB28-9D023811BD95.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5B9DFD6E-6DA2-4BC6-AA01-717CB2EACB1C.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5C4331E6-00B0-4D28-88CD-905EE14D6960.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5ED85434-953E-4B04-B1FC-22621FA37A0A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS65FC5713-13F2-4B83-A6C8-59B2AE35634E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6607B701-4DA3-42F9-9D03-3035ED08D0B0.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS66108EFE-F1AF-4C86-A41B-8875F594A7E7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6A6B33AA-7E9A-4370-9084-AD8204DFA334.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6C3FF941-87AF-4230-A06D-60FBDEE98358.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS702AAF0F-B799-4B9D-B5D7-C0FA8B64555A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7134555D-E7E3-48A9-9585-E3F3BD64B022.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS71C9387A-2484-4B9E-B9E2-C409B2B56285.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS72BB5C70-AA7F-4B64-8EA2-1AE218A143D1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS73C4D4D9-BD98-4074-89AE-9756EBFA0BCD.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS74728287-F4F0-45F4-A52E-D749FF5BD021.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7860B9AF-83EC-49F4-89C0-4060AA972226.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS79220AED-776A-488A-95C1-5EE8BF3566C8.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7F13F8A2-8743-4298-AC70-B43D22EE6268.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS81D43EA4-6B93-4879-B82C-DA59B9ED552F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8407FF9D-E96B-4FDB-AC4A-EB83F8D12E47.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8A02E9C1-5FB0-4B38-8473-DB6B0BD4594A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8A6AC6D5-C3DC-4AD9-B96E-E063EF0D9BC2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8D126C5E-4BCB-48A9-A7DF-70D09EB5986E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8DEA89EC-4AB1-4DF8-9E32-56A137FA8FAC.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9210D7BC-58AA-4D54-85EF-D181B32A52F4.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS926A4160-6B7F-42A2-8779-F94EFB6E8690.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS92FD1355-2526-4813-BC62-66BAAE0655B1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS936CE54E-1E42-46AD-A9F4-D0A0D03D926E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS938E3DFE-A8AF-4B41-80EC-3E462D10E685.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9E1216F2-057E-4ED4-9170-B09DBBBF3C22.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9FEDA26D-E480-4C60-9895-F9F17060EF9C.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA0704E20-51EF-46BE-BE47-EB62C0956A4F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA07CCC7D-2688-462F-85B2-BCFF10754AAB.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA25FAA26-B47F-46AE-8995-FB727707347F.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA6043321-863F-4844-9851-CAFE72622B64.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA8625742-02CA-4DA0-8B33-58C38EB55874.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSAF49FF28-F66A-489B-AE88-E0BC920DB6AD.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB085A901-D392-432F-9469-DF0D8248AD94.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB542FEE9-D515-44C8-99E8-C20E57528DF3.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB5D35FB0-6485-47C7-8ADC-C1A9754D7200.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB722606D-1D13-4985-A842-F6AA283C0AA6.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB78F97C6-628D-4F68-A1A9-B092419BD7C9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBB5CC37D-E088-40AD-8851-857B11162984.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBB79D2EA-094A-42AA-B669-E2200AC16685.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBBCF90DC-04D4-49A3-9DC9-8CE24BC35277.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBD599DB6-4BAF-4A81-B10C-98F96D0B3C2A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBE98BE94-AE90-4C91-8480-A4C96FC72E87.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSBFF6DB4E-CF64-44EB-A423-3A1433C38C80.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSC7FF0C16-8C7A-4CB2-8879-B1EE62C4439D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSC8873D2C-7D58-4F05-8608-F1A13FCD4309.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSCD42F631-61C8-4906-A611-9BA0D4CB74E2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSCEDAD1BC-E1E4-4A5F-90C6-805D06154E71.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD00714D1-C625-40AF-8A35-1E894EB7AEE9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD008F73C-5A01-4A30-997E-AF784BEC9403.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD01D9331-54C5-4CE6-8E34-AA3A83312422.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD0236492-57F9-4A15-9115-1D6FA5C04FDF.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD17D1297-CBF8-4A43-91EB-1559ECEE9FD2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD54BBFD6-DCAA-4BFC-B039-C597CFB791E3.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD94FCFF1-CEBC-4CCB-8C71-68FBCD417C25.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDBE4A006-702D-417A-96D9-3ACB43EFF987.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDFE62F17-BF7E-4CFD-954E-4D6D2538D6FB.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSE2CE4E9E-77DE-4F23-B49B-ED484D0C1733.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEAB8096F-DA73-4427-8CDF-C107855D061D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEB78CD24-99E5-497B-8F1E-A4485B7BD6F1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEBF9737B-7720-4122-A3DE-41517B6CA833.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSECF105A7-BAE4-4C13-873A-B800AF141BBC.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEFE90EE5-09BB-456B-AD3D-2FBD0ECB6501.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSF032399D-3A4B-41DA-A8E0-6A1F5ED3D4FD.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSFB33D1A9-EF0E-457B-A08F-F04F0621B5A3.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrstemp\SSMSFE11F959-21CA-4E49-B33D-D15B8BC35B9E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_78c.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03102009_232611

Files moved on Reboot…
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
File C:\WINDOWS\temp\wrstemp\SSMS02406416-590D-4153-BC65-2B0F9E2EC424.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS032B166B-D600-49D5-8E7B-E970A8DAB971.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS05FE3FAD-F2A0-4BDA-983C-0C2592CA8205.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS0701419F-228D-48EE-972D-0485F1A049BB.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS0730B50D-10F0-4587-A55D-0F2485FBED86.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS0BFA7C67-2871-4A74-932C-292A7ED24C2C.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS0C168AE9-E476-4BF0-A4CF-6A35A65CC012.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS10E258C2-B8A9-4C96-8B02-073C89D3C438.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS12A70EE6-B492-410D-9721-8B4E6CFF62FB.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS1680ADAA-68FB-4EF4-89E1-4560C712765B.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS175F9DF1-D18E-4499-BDB8-F8BEF895A9A9.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS195A70EC-2726-45CF-9E88-9382C08CD056.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS1A045660-B65C-4024-901A-2FA45AD4216B.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS24149FB6-C01A-459B-A787-99366C986599.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS252B04D4-F519-42F7-B9B9-5FA353158088.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS27C2FA01-42EA-4703-A400-A858B5874871.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS29E1C594-C894-4788-B5C3-83409BE92E54.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS2A5908CA-EB0F-4930-894C-08BBCE277C87.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS2EE1BE83-5B50-46B9-855C-EA3AD3F21229.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS2F67159C-C07E-48D4-9B98-3603ED0D188D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS33E5B0C6-ACE8-4CD5-9319-DE337B3888F5.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS34294F12-751D-4DC9-92E9-3FA64F6E7246.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS360B4B4A-26E3-4243-980D-228502871B4B.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS378F2F99-7AAF-4160-82CB-6C55F45987F1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS38B5881F-D76E-42BE-AD56-805D0BDFFB88.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS3D577EC8-C612-48D3-AACD-5C43C934CB6D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS3F41FF32-103E-4473-AC40-35B958F06AE1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS447FA878-7D65-47AD-A39D-B4BB89094AE7.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS4571CCFE-43CD-41EF-AD21-7985F9AE06F5.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS4645FC67-BF07-48BB-BCEC-AE7DB305F9D0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS510D6B49-94D8-41F2-BC59-26EBB69B62D5.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS5176A18D-26BA-4910-9929-67DE48F15162.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS576CE0D3-6FB5-40C6-8A37-A2FB43BD4065.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS5ADECA90-D843-474B-A6C9-1E6F29368B95.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS5B2D7FD3-7E3A-4EBD-BB28-9D023811BD95.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS5B9DFD6E-6DA2-4BC6-AA01-717CB2EACB1C.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS5C4331E6-00B0-4D28-88CD-905EE14D6960.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS5ED85434-953E-4B04-B1FC-22621FA37A0A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS65FC5713-13F2-4B83-A6C8-59B2AE35634E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS6607B701-4DA3-42F9-9D03-3035ED08D0B0.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS66108EFE-F1AF-4C86-A41B-8875F594A7E7.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS6A6B33AA-7E9A-4370-9084-AD8204DFA334.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS6C3FF941-87AF-4230-A06D-60FBDEE98358.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS702AAF0F-B799-4B9D-B5D7-C0FA8B64555A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS7134555D-E7E3-48A9-9585-E3F3BD64B022.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS71C9387A-2484-4B9E-B9E2-C409B2B56285.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS72BB5C70-AA7F-4B64-8EA2-1AE218A143D1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS73C4D4D9-BD98-4074-89AE-9756EBFA0BCD.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS74728287-F4F0-45F4-A52E-D749FF5BD021.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS7860B9AF-83EC-49F4-89C0-4060AA972226.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS79220AED-776A-488A-95C1-5EE8BF3566C8.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS7F13F8A2-8743-4298-AC70-B43D22EE6268.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS81D43EA4-6B93-4879-B82C-DA59B9ED552F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8407FF9D-E96B-4FDB-AC4A-EB83F8D12E47.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8A02E9C1-5FB0-4B38-8473-DB6B0BD4594A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8A6AC6D5-C3DC-4AD9-B96E-E063EF0D9BC2.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8D126C5E-4BCB-48A9-A7DF-70D09EB5986E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS8DEA89EC-4AB1-4DF8-9E32-56A137FA8FAC.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9210D7BC-58AA-4D54-85EF-D181B32A52F4.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS926A4160-6B7F-42A2-8779-F94EFB6E8690.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS92FD1355-2526-4813-BC62-66BAAE0655B1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS936CE54E-1E42-46AD-A9F4-D0A0D03D926E.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS938E3DFE-A8AF-4B41-80EC-3E462D10E685.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9E1216F2-057E-4ED4-9170-B09DBBBF3C22.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMS9FEDA26D-E480-4C60-9895-F9F17060EF9C.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA0704E20-51EF-46BE-BE47-EB62C0956A4F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA07CCC7D-2688-462F-85B2-BCFF10754AAB.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA25FAA26-B47F-46AE-8995-FB727707347F.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA6043321-863F-4844-9851-CAFE72622B64.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSA8625742-02CA-4DA0-8B33-58C38EB55874.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSAF49FF28-F66A-489B-AE88-E0BC920DB6AD.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB085A901-D392-432F-9469-DF0D8248AD94.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB542FEE9-D515-44C8-99E8-C20E57528DF3.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB5D35FB0-6485-47C7-8ADC-C1A9754D7200.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB722606D-1D13-4985-A842-F6AA283C0AA6.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSB78F97C6-628D-4F68-A1A9-B092419BD7C9.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBB5CC37D-E088-40AD-8851-857B11162984.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBB79D2EA-094A-42AA-B669-E2200AC16685.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBBCF90DC-04D4-49A3-9DC9-8CE24BC35277.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBD599DB6-4BAF-4A81-B10C-98F96D0B3C2A.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBE98BE94-AE90-4C91-8480-A4C96FC72E87.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSBFF6DB4E-CF64-44EB-A423-3A1433C38C80.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSC7FF0C16-8C7A-4CB2-8879-B1EE62C4439D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSC8873D2C-7D58-4F05-8608-F1A13FCD4309.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSCD42F631-61C8-4906-A611-9BA0D4CB74E2.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSCEDAD1BC-E1E4-4A5F-90C6-805D06154E71.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD00714D1-C625-40AF-8A35-1E894EB7AEE9.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD008F73C-5A01-4A30-997E-AF784BEC9403.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD01D9331-54C5-4CE6-8E34-AA3A83312422.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD0236492-57F9-4A15-9115-1D6FA5C04FDF.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD17D1297-CBF8-4A43-91EB-1559ECEE9FD2.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD54BBFD6-DCAA-4BFC-B039-C597CFB791E3.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSD94FCFF1-CEBC-4CCB-8C71-68FBCD417C25.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSDBE4A006-702D-417A-96D9-3ACB43EFF987.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSDFE62F17-BF7E-4CFD-954E-4D6D2538D6FB.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSE2CE4E9E-77DE-4F23-B49B-ED484D0C1733.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSEAB8096F-DA73-4427-8CDF-C107855D061D.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSEB78CD24-99E5-497B-8F1E-A4485B7BD6F1.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSEBF9737B-7720-4122-A3DE-41517B6CA833.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSECF105A7-BAE4-4C13-873A-B800AF141BBC.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSEFE90EE5-09BB-456B-AD3D-2FBD0ECB6501.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSF032399D-3A4B-41DA-A8E0-6A1F5ED3D4FD.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSFB33D1A9-EF0E-457B-A08F-F04F0621B5A3.tmp not found!
File C:\WINDOWS\temp\wrstemp\SSMSFE11F959-21CA-4E49-B33D-D15B8BC35B9E.tmp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_78c.dat not found!
;******************************************************************************* ********************************************************************************* ******************* ANALYSIS: 2009-03-11 06:40:05 PROTECTIONS: 2 MALWARE: 3 SUSPECTS: 0 ;******************************************************************************* ********************************************************************************* ******************* PROTECTIONS Description Version Active Updated ;=============================================================================== ================================================================================= =================== CA Anti-Virus 8.4.0.28 Yes Yes avast! antivirus 4.8.1335 [VPS 090310-0] 4.8.1335 Yes Yes ;=============================================================================== ================================================================================= =================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=============================================================================== ================================================================================= =================== 00029036 adware/superspider Adware No 1 Yes No hkey_classes_root\a.a.a 00029036 adware/superspider Adware No 1 Yes No hkey_classes_root\a.a.b 00039204 adware/cws Adware No 0 Yes No c:\documents and settings\nick\favorites\health 00590315 Rootkit/Agent.LNB HackTools No 0 Yes No C:\System Volume Information\_restore{FC0A1C4F-9DEC-4E44-B6C4-A553B2321381}\RP263\A0038530.sys ;=============================================================================== ================================================================================= =================== SUSPECTS Sent Location n ;=============================================================================== ================================================================================= =================== ;=============================================================================== ================================================================================= =================== VULNERABILITIES Id Severity Description n ;=============================================================================== ================================================================================= =================== ;=============================================================================== ================================================================================= ===================
Hi,

Must just be a leftover from CA, nothing to worry about then.

You don't appear to be running any third party Firewall software.

Install a firewall! Without a firewall you are very susceptible to being hacked, and people could gain access to your computer. If you don't have a firewall I strongly recommend you download ONE of the following:
1) Comodo
2) Agnitum
3) Sunbelt/Kerio

The message you are getting isn't bad as such, but it is a bit suspicious if you get it regularly. Run MalwareBytes' again, update it and run a quick scan just to check for anything else.

Thanks.
OK, please run DDS again and post just the first log it gives (DDS.txt). Are you experiencing any other problems other than this IE message? Thanks.
Other than those symptoms there doesnt appear to be anything else. Im pretty sure the slow initial loading of IE is just my homepage because changing it fixed the problem. DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 7:17:49.85 on Thu 03/12/2009 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.402 [GMT -4:00] AV: CA Anti-Virus *On-access scanning enabled* (Updated) AV: avast! antivirus 4.8.1335 [VPS 090311-1] *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\Portrait Displays\Plugins\AM\dtsslsrv.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\BCMSMMSG.exe C:\WINDOWS\SM1BG.EXE C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Kodak\printer\center\KodakSvc.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Samsung\EmoDio\SMSTray.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Speeditup Free\PCCheckUp\PCCheckUp.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\Program Files\Lexmark X125\LEX125SU.exe C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe C:\Program Files\twc\medicsp2\bin\sprtsvc.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Program Files\Kodak\Printer\Center\EKDiscovery.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\wscntfy.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe C:\Documents and Settings\Nick\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://rr.com/ uDefault_Search_URL = hxxp://www.rr.com uSearchMigratedDefaultURL = mSearchMigratedDefaultURL = uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet mRun: [BCMSMMSG] "c:\windows\BCMSMMSG.exe" mRun: [SM1BG] "c:\windows\SM1BG.EXE" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [NvCplDaemon] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] "c:\windows\system32\nwiz.exe" /install mRun: [NvMediaCenter] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [EKIJ5000StatusMonitor] "c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe" mRun: [AppleSyncNotifier] "c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SMSTray] "c:\program files\samsung\emodio\SMSTray.exe" mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [PC-Checkup] "c:\program files\speeditup free\pccheckup\PCCheckUp.exe" -mini mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\lexmar~1.lnk - c:\program files\lexmark x125\LEX125SU.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\snapde~1.lnk - c:\windows\twain_32\ca561a\SnapDetect.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL Trusted Zone: aol.com\free DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {25365FF3-2746-4230-9DA7-163CCA318309} - hxxp://inst.c-wss.com/n024p/EN/install/gtdownlr.cab DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} - hxxp://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} - hxxp://www.acclaim.com/cabs/acclaim_v4.cab DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} - hxxp://entimg.msn.com/client/msnediag4227.cab DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - hxxp://mediaplayer.walmart.com/installer/install.cab DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} - hxxp://chat.yahoo.com/cab/yuplapp.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {9732FB42-C321-11D1-836F-00A0C993F125} - hxxp://www.pcpitstop.com/mhLbl.cab DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} - hxxp://webcamnow.com/fs5/ax/ActiveXWebCam.cab DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab56649.cab DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} - hxxps://ediagnostics.lexmark.com/serval.cab DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab41227.cab DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} - hxxp://chat.yahoo.com/cab/yvwrctl.cab DPF: {E856B973-45FD-4559-8F82-EAB539144667} - hxxp://pccheckup.dellfix.com/rel/36/install/gtdownde.cab DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} - hxxp://zone.msn.com/bingame/zpagames/ZPA_Backgammon.cab64162.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: ShellHook Class: {88485281-8b4b-4f8d-9ede-82e29a064277} - c:\progra~1\markany\conten~1\MACSMA~1.DLL ============= SERVICES / DRIVERS =============== R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-3-10 28544] R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2008-8-9 29808] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-3-8 114768] R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2009-3-6 26376] R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2009-3-6 21128] R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\vetefile.sys [2009-3-6 880560] R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2009-3-6 32264] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-3-8 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-3-8 138680] R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\kodak\printer\center\EKDiscovery.exe [2008-10-10 274432] R2 KodakSvc;Kodak AiO Device Service;c:\program files\kodak\printer\center\KodakSvc.exe [2008-10-30 28672] R2 PdiService;Portrait Displays SDK Service;c:\program files\common files\portrait displays\drivers\pdisrvc.exe [2008-11-28 90112] R2 sprtsvc_medicsp2;SupportSoft Sprocket Service (medicsp2);c:\program files\twc\medicsp2\bin\sprtsvc.exe [2008-12-9 202280] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-1-23 24652] R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\spy sweeper\SpySweeper.exe [2008-10-2 3667304] R2 WRConsumerService;Webroot Client Service;c:\program files\webroot\spy sweeper\WRConsumerService.exe [2008-11-1 1066360] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-3-8 254040] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-3-8 352920] R3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter;c:\windows\system32\drivers\lne100v5.sys [2006-12-29 36224] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-3-6 38496] S1 VETFDDNT;VET Floppy Boot Sector Monitor; [x] S2 gupdate1c98f7fef094cf4;Google Update Service (gupdate1c98f7fef094cf4);c:\program files\google\update\GoogleUpdate.exe [2009-2-15 133104] S3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2009-3-6 108368] S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2008-7-10 47128] S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-7-10 242712] S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2008-7-10 369688] =============== Created Last 30 ================ 2009-03-11 07:16 73,728 a——- c:\windows\system32\javacpl.cpl 2009-03-10 23:39 28,544 a——- c:\windows\system32\drivers\pavboot.sys 2009-03-10 23:38 –d—– c:\program files\Panda Security 2009-03-10 23:26 –d—– C:\_OTMoveIt 2009-03-07 18:24 –d—– c:\program files\LimeWire 2009-03-06 21:28 –d—– c:\windows\CAVTemp 2009-03-06 21:19 880,560 a——- c:\windows\system32\drivers\vetefile.sys 2009-03-06 21:19 108,368 a——- c:\windows\system32\drivers\veteboot.sys 2009-03-06 21:17 32,264 a——- c:\windows\system32\drivers\vetmonnt.sys 2009-03-06 21:17 26,376 a——- c:\windows\system32\drivers\vet-filt.sys 2009-03-06 21:17 21,128 a——- c:\windows\system32\drivers\vet-rec.sys 2009-03-06 21:01 66,048 a——- c:\windows\ieResetIcons.exe 2009-03-06 00:03 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-03-06 00:03 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-03-06 00:03 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-03-05 17:41 –d—– c:\program files\AVG 2009-03-05 00:24 –dsh— c:\docume~1\alluse~1\applic~1\e2efe92 2009-03-03 23:43 25,272 a——- c:\windows\system32\drivers\purendis.sys 2009-03-03 20:48 –d—– c:\program files\common files\Pure Networks Shared 2009-02-25 06:57 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat 2009-02-20 23:34 14,592 ac—— c:\windows\system32\dllcache\kbdhid.sys 2009-02-20 23:34 14,592 a——- c:\windows\system32\drivers\kbdhid.sys 2009-02-20 13:24 –d—– c:\program files\Walmart MP3 Music Downloads 2009-02-15 13:30 20,992 ac—— c:\windows\system32\dllcache\dshowext.ax 2009-02-15 13:30 20,992 a——- c:\windows\system32\dshowext.ax ==================== Find3M ==================== 2009-03-11 07:15 410,984 a——- c:\windows\system32\deploytk.dll 2009-02-20 20:45 115,200 ac—— c:\windows\snap.dat 2009-02-09 07:13 1,846,784 a——- c:\windows\system32\win32k.sys 2009-01-20 21:58 124,464 a——- c:\windows\system32\drivers\SYMEVENT.SYS 2009-01-20 21:58 60,808 a——- c:\windows\system32\S32EVNT1.DLL 2009-01-20 21:58 10,635 a——- c:\windows\system32\drivers\SYMEVENT.CAT 2009-01-20 21:58 806 a——- c:\windows\system32\drivers\SYMEVENT.INF 2009-01-16 22:35 3,594,752 ——– c:\windows\system32\dllcache\mshtml.dll 2009-01-06 18:56 3,932 ac—— c:\docume~1\nick\applic~1\LMLayout.dat 2009-01-06 18:56 268 ac—— c:\docume~1\nick\applic~1\LMCPaper.dat 2008-12-19 05:10 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2008-12-19 01:25 634,024 ——– c:\windows\system32\dllcache\iexplore.exe 2008-12-19 01:23 161,792 ——– c:\windows\system32\dllcache\ieakui.dll 2008-12-12 12:18 87,336 a——- c:\windows\system32\dns-sd.exe 2008-12-12 12:11 61,440 a——- c:\windows\system32\dnssd.dll 2008-10-01 22:03 47,360 ac—— c:\docume~1\nick\applic~1\pcouffin.sys 2008-02-02 17:46 76,920 ac—— c:\docume~1\nick\applic~1\GDIPFONTCACHEV1.DAT 2007-12-31 17:06 87,608 ac—— c:\docume~1\nick\applic~1\ezpinst.exe 2003-08-27 14:19 36,963 ac—r– c:\program files\common files\SM1updtr.dll 2008-09-13 18:16 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091320080914\index.dat ============= FINISH: 7:20:55.31 ===============
None that I can think of, and I havent had them occur since my post about them. Also I had mentioned in my first post that another computer in my network was suffering from similar problems. Would you like me to post the hijack this log or should I just create another topic about it?
Hi Naks

OK. If you get the warnings frequently again and want to find out more feel free to post in our "Browsers, Internet and Email" forum. Please post the logs from the other computer in a new topic, keeps things tidy.

Log looks good :thumbup:

Clean up with OTMoveIt3
  • Double-click OTMoveIt3.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
You can now delete any other tools I had you download and use, unless you wish to keep them.


Set correct settings for files that should be hidden in Windows XP
  • Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
  • Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
  • If unchecked please checkHide protected operating system files (Recommended)
  • If necessary check "Display content of system folders"
  • If necessary Uncheck Hide file extensions for known file types.
  • Click OK

Now that your system appears to be clean, there's just a few steps I'd like you to take to prevent any future infections.
  • System restore:
    We will now clear your existing system restore points and establish a new clean restore point:
    • Go to Start > All Programs > Accessories > System Tools > System Restore
    • Select Create a restore point, and Ok it.
    • Next, go to Start > Run and type in cleanmgr
    • Select the More options tab
    • Choose the option to clean up system restore and OK it.

      This will remove all restore points except the new one you just created.
    Make sure you do this now, as your System Restore currently has infected files in it.

  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:

    Download Spybot Search and Destroy 1.5 from here
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.

    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster

    Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI