This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

hijackthis log file

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

CPU is an Athlon64 3.0+GHz w/ 2GB RAM, 2 EIDE HDD both less than 20% full and do not need to be defragged.
junk files, cookies,temp internet files removed every other day.
caches emptied out daily.
history is kept at zero.

HP lightscribe DVD R/W
board is ASUS.
os is windows xp sp2

the computer is very slow to start up and to turn off.
internet access to comcast home page takes forever, longer than 1 minute and usually have to reload it once or twice before it comes up
ie also takes a long time to close.
once internet is up it works very fast.

i have switched to firefox and that has helped with the initial internet access speed.
have firefox 3.0 installed
downloads seem to be substantially slower than on ie

please find below the hijackthis logfile.

i await your instructions o gurus of silicon and software.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:12:41 PM, on 3/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Tools\Webroot\Spy Sweeper\WRConsumerService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Tools\Lavasoft\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\tools\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\tools\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\kmw_run.exe
C:\tools\AVG\AVG8\avgnsx.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Drivers\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\KMW_SHOW.EXE
C:\tools\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\tools\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Tools\Webroot\Spy Sweeper\SpySweeper.exe
C:\tools\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\tools\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Tools\Mozilla Tri-Pack\Firefox\firefox.exe
C:\Tools\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\tools\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google

Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program

Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google

Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program

Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program

Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google

Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [CTSysVol] "C:\Drivers\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [AVG8_TRAY] "C:\tools\AVG\AVG8\avgtray.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\tools\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Tools\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ATI DeviceDetect] "C:\Program Files\ATI Multimedia\main\ATIDtct.EXE"
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default

user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\dtv\EXPLBAR.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) -

https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} -

http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.3.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\tools\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Tools\Lavasoft\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\tools\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\tools\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure

Networks Shared\Platform\nmsrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD -

C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) -

C:\Tools\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Tools\Webroot\Spy

Sweeper\WRConsumerService.exe

–
End of file - 7326 bytes
Sorry for the delay, If you still need help with your machine, please do the following.

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check
    • .
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt.
      Note: These are saved in the OTListIt2 folder on your C:\ drive if they don't open automatically.
    • Please copy (Select All>Copy) the contents of these files, one at a time, and post them with your next reply.
  • You may need two posts to fit them both in.
hi CatByte,

thank you for the reply.
please find attached the files you requested.

obviously, the OTListit file is first followed by the Extras file

thank you again for your help.

OTListIt logfile created on: 3/16/2009 2:38:21 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.5.2 Folder = C:\Documents and Settings\bob bush\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.84 Gb Available Physical Memory | 56.07% Memory free
2.29 Gb Paging File | 1.76 Gb Available in Paging File | 76.83% Paging File free
Paging file location(s): C:\pagefile.sys 960 1920;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 59.97 Gb Free Space | 80.48% Space Free | Partition Type: NTFS
Drive D: | 28.61 Gb Total Space | 26.00 Gb Free Space | 90.89% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 6.67 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 14.92 Gb Total Space | 8.64 Gb Free Space | 57.91% Space Free | Partition Type: FAT32
Drive I: | 3.73 Gb Total Space | 3.71 Gb Free Space | 99.29% Space Free | Partition Type: FAT32

Computer Name: BOB
Current User Name: bob bush
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Tools\Webroot\Spy Sweeper\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\tools\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\CTsvcCDA.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\snmp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\tools\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Tools\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\tools\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\tools\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
PRC - C:\Drivers\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\tools\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\tools\Pure Networks\Network Magic\nmapp.exe (Cisco Systems, Inc.)
PRC - C:\Tools\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\WINDOWS\system32\kmw_run.exe (Kensington Technology Group)
PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\KMW_SHOW.EXE ()
PRC - C:\Program Files\ATI Multimedia\main\ATIDtct.EXE (ATI Technologies Inc.)
PRC - C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe (Adobe Systems Incorporated)
PRC - C:\tools\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\bob bush\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (6to4 [Auto | Running]) – C:\WINDOWS\System32\6to4svc.dll (Microsoft Corporation)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (avg8emc [Auto | Running]) – C:\tools\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\tools\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Creative Service for CDROM Access [Auto | Running]) – C:\WINDOWS\system32\CTsvcCDA.exe (Creative Technology Ltd)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpdj [Auto | Stopped]) – File not found
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (nmservice [Auto | Running]) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (p2pgasvc [On_Demand | Stopped]) – C:\WINDOWS\system32\p2pgasvc.dll (Microsoft Corporation)
SRV - (SimpTcp [Auto | Running]) – C:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)
SRV - (SNMP [Auto | Running]) – C:\WINDOWS\System32\snmp.exe (Microsoft Corporation)
SRV - (uploadmgr [Auto | Stopped]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (vsmon [Auto | Running]) – C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (WebrootSpySweeperService [Auto | Running]) – C:\Tools\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (WRConsumerService [Auto | Running]) – C:\Tools\Webroot\Spy Sweeper\WRConsumerService.exe (Webroot Software, Inc. )

========== Driver Services (SafeList) ==========

DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ATIAVAIW [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\atinavt2.sys (ATI Technologies Inc.)
DRV - (atinevxx [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\atinevxx.sys (ATI Technologies Inc.)
DRV - (atinrvxx [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\atinrvxx.sys (ATI Technologies Inc.)
DRV - (ATITUNEP [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\atineuxx.sys (ATI Technologies Inc.)
DRV - (ativraxx [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\atinraxx.sys (ATI Technologies Inc.)
DRV - (ATIXSAudio [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\atinesxx.sys (ATI Technologies Inc.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (ctsfm2k [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (CTUSFSYN [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctusfsyn.sys (Creative Technology Ltd.)
DRV - (gameenum [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (KMW_KBD [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\KMW_KBD.sys (Kensington Technology Group)
DRV - (KMW_SYS [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\KMW_SYS.sys (Kensington Technology Group)
DRV - (KMW_USB [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\KMW_USB.sys (Kensington Technology Group)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (LKNUCMP [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\lknucmp.sys (SerComm)
DRV - (lknuhst [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\lknuhst.sys (SerComm)
DRV - (LKNUHUB [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\lknuhub.sys (SerComm)
DRV - (MCSTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\mcstrm.sys (RealNetworks, Inc.)
DRV - (MPE [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\MPE.sys (Microsoft Corporation)
DRV - (MVDCODEC [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\atinmdxx.sys (ATI Technologies Inc.)
DRV - (ossrv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (P17 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (P17xfi [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\P17xfi.sys (Creative Technology Ltd.)
DRV - (p17xfilt [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\p17xfilt.sys (Sensaura)
DRV - (PCDCODEC [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\atinpdxx.sys (ATI Technologies Inc.)
DRV - (pnarp [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\pnarp.sys (Pure Networks, Inc.)
DRV - (PSC60x [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\pscaudio.sys (Philips Components (PSS))
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (purendis [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\purendis.sys (Pure Networks, Inc.)
DRV - (QsndEnum [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\QsndEnum.sys (QSound Labs, Inc.)
DRV - (QSoftAud [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\QSoftAud.sys (QSound Labs, Inc.)
DRV - (rtl8139 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (srescan [Boot | Running]) – C:\WINDOWS\system32\ZoneLabs\srescan.sys (Check Point Software Technologies LTD)
DRV - (ssfs0bbc [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (SSHRMD [Boot | Running]) – C:\WINDOWS\SYSTEM32\Drivers\SSHRMD.SYS (Webroot Software, Inc. (www.webroot.com))
DRV - (SSIDRV [Boot | Running]) – C:\WINDOWS\SYSTEM32\Drivers\SSIDRV.SYS (Webroot Software, Inc. (www.webroot.com))
DRV - (SSKBFD [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\sskbfd.sys (Webroot Software Inc (www.webroot.com))
DRV - (Tcpip6 [System | Running]) – C:\WINDOWS\system32\DRIVERS\tcpip6.sys (Microsoft Corporation)
DRV - (viaagp1 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (VIAudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\viaudio.sys (VIA Technologies, Inc.)
DRV - (videX32 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (vsdatant [System | Running]) – C:\WINDOWS\System32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (WinDriver6 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (X10UIF [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\x10uif.sys (X10 Wireless Technology, Inc.)
DRV - (XUIF [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.comcast.net/"
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.0
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:2.1.0.2
FF - prefs.js..extensions.enabledItems: [removed]:3.0.3
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7

FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\TOOLS\MOZILLA TRI-PACK\FIREFOX\COMPONENTS [2009/03/10 22:19:25 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\TOOLS\MOZILLA TRI-PACK\FIREFOX\PLUGINS [2009/03/10 22:53:35 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\TOOLS\MOZILLA TRI-PACK\FIIREFOX 3.1 BETA 2\COMPONENTS [2009/03/10 22:35:01 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\TOOLS\MOZILLA TRI-PACK\FIIREFOX 3.1 BETA 2\PLUGINS [2009/03/10 23:18:55 | 00,000,000 | —D | M]

[2009/03/10 15:54:52 | 00,000,000 | —D | M] – C:\Documents and Settings\bob bush\Application Data\mozilla\Extensions
[2009/03/10 15:54:52 | 00,000,000 | —D | M] – C:\Documents and Settings\bob bush\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/15 20:54:46 | 00,000,000 | —D | M] – C:\Documents and Settings\bob bush\Application Data\mozilla\Firefox\Profiles\iqf2e92e.default\extensions
[2009/03/15 20:54:46 | 00,000,000 | —D | M] – C:\Documents and Settings\bob bush\Application Data\mozilla\Firefox\Profiles\iqf2e92e.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2009/03/10 22:45:29 | 00,000,000 | —D | M] – C:\Documents and Settings\bob bush\Application Data\mozilla\Firefox\Profiles\iqf2e92e.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/03/10 22:49:31 | 00,000,000 | —D | M] – C:\Documents and Settings\bob bush\Application Data\mozilla\Firefox\Profiles\iqf2e92e.default\extensions\[removed]

O1 HOSTS File: (737 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IEHlprObjClass) - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\tools\Kensington\MouseWorks\IE_KMW.DLL File not found
O3 - HKLM\..\Toolbar: (&Google; Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O4 - HKLM..\Run: [Ad-Watch] "C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe" (Lavasoft)
O4 - HKLM..\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe" (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] "C:\tools\AVG\AVG8\avgtray.exe" (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CTSysVol] "C:\Drivers\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" /r (Creative Technology Ltd)
O4 - HKLM..\Run: [kmw_run.exe] "C:\WINDOWS\system32\kmw_run.exe" (Kensington Technology Group)
O4 - HKLM..\Run: [MSWheel] File not found
O4 - HKLM..\Run: [nmapp] "C:\tools\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash (Cisco Systems, Inc.)
O4 - HKLM..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" (Cisco Systems, Inc.)
O4 - HKLM..\Run: [SpySweeper] "C:\Tools\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray (Webroot Software, Inc.)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] "C:\Tools\Zone Labs\ZoneAlarm\zlclient.exe" (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [ATI DeviceDetect] "C:\Program Files\ATI Multimedia\main\ATIDtct.EXE" (ATI Technologies Inc.)
O4 - HKCU..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe" (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoComputersNearMe = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = C2 FF FF 03 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoComputersNearMe = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [PNRP Cloud Namespace Provider] - C:\WINDOWS\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [PNRP Name Namespace Provider] - C:\WINDOWS\system32\pnrpnsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 8 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.3.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll (PCPitstop Exam)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\tools\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\dimsntfy: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - D:\AUTOEXEC.BAT () - [ FAT32 ]
O32 - Autorun File - D:\AUTOEXEC.BAR () - [ FAT32 ]
O32 - Autorun File - G:\autorun.inf () - [ CDFS ]
O33 - MountPoints2\{acbfdd49-ffa2-11dd-9817-000d8819a54b}\Shell - "" = AutoRun
O33 - MountPoints2\{acbfdd49-ffa2-11dd-9817-000d8819a54b}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{acbfdd49-ffa2-11dd-9817-000d8819a54b}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – [2007/10/23 02:45:39 | 01,336,632 | R— | M] ()
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – [2007/10/23 02:45:39 | 01,336,632 | R— | M] ()

========== Files/Folders - Created Within 30 Days ==========

[2 C:\WINDOWS\*.tmp files]
[2009/03/16 14:33:22 | 00,499,712 | —- | C] (OldTimer Tools) – C:\Documents and Settings\bob bush\Desktop\OTListIt2.exe
[2009/03/13 23:22:42 | 00,176,128 | —- | C] () – C:\WINDOWS\System32\kmw_show.exe
[2009/03/13 23:22:42 | 00,106,496 | —- | C] (Kensington Technology Group) – C:\WINDOWS\System32\kmw_run.exe
[2009/03/13 23:22:42 | 00,010,112 | —- | C] (Kensington Technology Group) – C:\WINDOWS\System32\drivers\KMW_USB.sys
[2009/03/13 23:22:42 | 00,005,376 | —- | C] (Kensington Technology Group) – C:\WINDOWS\System32\drivers\KMW_KBD.sys
[2009/03/13 23:22:42 | 00,004,736 | —- | C] (Kensington Technology Group) – C:\WINDOWS\System32\drivers\KMW_LIB.sys
[2009/03/13 23:22:41 | 00,110,592 | —- | C] (Kensington Technology Group) – C:\WINDOWS\System32\kmw_dll.dll
[2009/03/13 00:11:25 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/03/12 20:40:35 | 00,000,000 | —D | C] – C:\2009-03-12
[2009/03/12 17:49:42 | 00,000,000 | —D | C] – C:\Documents and Settings\bob bush\Local Settings\Application Data\Thunderbird
[2009/03/12 17:49:42 | 00,000,000 | —D | C] – C:\Documents and Settings\bob bush\Application Data\Thunderbird
[2009/03/12 01:12:37 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/03/12 00:44:18 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/03/12 00:44:02 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/03/12 00:39:50 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/03/12 00:39:38 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2009/03/11 22:38:41 | 00,000,000 | —D | C] – C:\Documents and Settings\bob bush\Application Data\Malwarebytes
[2009/03/11 22:38:36 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/11 22:38:34 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/11 22:38:32 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/11 03:00:55 | 00,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2009/03/10 22:35:03 | 00,001,788 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Internet.lnk
[2009/03/09 16:58:15 | 00,000,000 | —D | C] – C:\Documents and Settings\bob bush\Local Settings\Application Data\Mozilla
[2009/03/09 16:58:15 | 00,000,000 | —D | C] – C:\Documents and Settings\bob bush\Application Data\Mozilla
[2009/03/08 21:20:15 | 00,023,552 | —- | C] () – C:\Documents and Settings\All Users\Documents\Ryan Bush.xls
[2009/03/04 17:41:38 | 00,026,112 | —- | C] () – C:\Documents and Settings\bob bush\My Documents\Admiral energy corporation.doc
[2009/03/04 16:36:35 | 00,000,000 | —D | C] – C:\WINDOWS\Intuit
[2009/03/04 16:02:07 | 00,024,064 | —- | C] () – C:\Documents and Settings\bob bush\My Documents\bank ifo.doc
[2009/03/04 15:07:27 | 00,000,000 | —D | C] – C:\Program Files\Common Files\supportsoft
[2009/03/04 15:06:43 | 01,843,200 | —- | C] (Apache Software Foundation) – C:\WINDOWS\System32\acXMLParser.dll
[2009/03/04 15:06:38 | 03,518,464 | —- | C] (Amyuni Technologies
http://www.amyuni.com) – C:\WINDOWS\System32\cdintf300.dll
[2009/03/04 15:00:18 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Intuit
[2009/03/04 14:57:55 | 00,000,091 | —- | C] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2009/03/04 14:57:55 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 10
[2009/03/04 14:57:51 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2009/03/04 14:45:52 | 00,000,000 | —D | C] – C:\Program Files\Akamai
[2009/03/01 15:49:01 | 00,181,170 | —- | C] () – C:\bears1_800[1].jpg
[2009/02/25 18:43:52 | 00,077,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MSBIND.DLL
[2009/02/25 18:43:50 | 00,118,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msadodc.ocx
[2009/02/25 18:43:49 | 00,262,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msdatgrd.ocx
[2009/02/25 18:43:47 | 00,045,056 | —- | C] (Volvo Information Technology) – C:\WINDOWS\System32\vcttools.dll
[2009/02/25 16:12:32 | 00,000,000 | —- | C] () – C:\WINDOWS\MKDEWE.TRN
[2009/02/24 09:15:08 | 00,031,744 | —- | C] () – C:\Documents and Settings\bob bush\My Documents\bank feb24.doc
[2009/02/15 23:16:39 | 00,017,078 | —- | C] () – C:\ladder jacks 2.jpg
[2009/02/15 00:14:33 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ATI MMC
[2009/02/15 00:06:30 | 00,000,000 | —D | C] – C:\Program Files\Common Files\ATI
[2009/02/15 00:06:22 | 00,000,000 | —D | C] – C:\Program Files\ATI Multimedia

========== Files - Modified Within 30 Days ==========

[2 C:\WINDOWS\*.tmp files]
[2009/03/16 14:33:35 | 00,499,712 | —- | M] (OldTimer Tools) – C:\Documents and Settings\bob bush\Desktop\OTListIt2.exe
[2009/03/16 08:04:43 | 34,098,246 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/03/16 02:25:19 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/03/16 00:48:44 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/03/15 17:40:55 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/15 17:40:02 | 00,348,378 | -H– | M] () – C:\WINDOWS\System32\vsconfig.xml
[2009/03/15 17:37:58 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/15 17:37:37 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/15 17:16:02 | 13,389,786 | -H– | M] () – C:\Documents and Settings\bob bush\Local Settings\Application Data\IconCache.db
[2009/03/15 11:58:36 | 00,037,975 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/03/13 23:22:44 | 00,001,046 | —- | M] () – C:\WINDOWS\win.ini
[2009/03/13 23:22:44 | 00,000,258 | —- | M] () – C:\WINDOWS\system.ini
[2009/03/13 02:02:18 | 00,000,737 | R— | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2009/03/13 02:01:48 | 00,001,626 | —- | M] () – C:\WINDOWS\tasks\wrSpySweeper_LB69F284759F046A29970C6304441D369.job
[2009/03/13 02:00:00 | 00,001,476 | —- | M] () – C:\WINDOWS\tasks\wrSpySweeperFullSweep.job
[2009/03/12 00:43:39 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/03/12 00:43:20 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/03/11 09:02:00 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/11 07:10:35 | 00,235,168 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/11 03:01:32 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/03/10 22:35:03 | 00,001,788 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Internet.lnk
[2009/03/10 07:29:27 | 00,230,912 | —- | M] () – C:\Documents and Settings\bob bush\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/10 02:00:00 | 00,001,478 | —- | M] () – C:\WINDOWS\tasks\wrSpySweeperTrialSweep.job
[2009/03/09 01:46:15 | 00,737,280 | —- | M] () – C:\Documents and Settings\bob bush\My Documents\movies.mdb
[2009/03/09 00:42:12 | 00,002,471 | —- | M] () – C:\Documents and Settings\bob bush\Desktop\Access.lnk
[2009/03/08 16:11:23 | 00,023,552 | —- | M] () – C:\Documents and Settings\All Users\Documents\Ryan Bush.xls
[2009/03/08 13:41:37 | 00,442,966 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/08 13:41:36 | 00,524,956 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/08 13:41:36 | 00,071,980 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/08 10:24:35 | 00,002,377 | —- | M] () – C:\Documents and Settings\bob bush\Desktop\WordPerfect.lnk
[2009/03/04 19:04:51 | 00,057,968 | —- | M] () – C:\Documents and Settings\bob bush\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/04 17:41:38 | 00,026,112 | —- | M] () – C:\Documents and Settings\bob bush\My Documents\Admiral energy corporation.doc
[2009/03/04 16:56:53 | 00,002,497 | —- | M] () – C:\Documents and Settings\bob bush\Desktop\Word.lnk
[2009/03/04 16:56:36 | 00,002,495 | —- | M] () – C:\Documents and Settings\bob bush\Desktop\Excel.lnk
[2009/03/04 16:28:34 | 00,000,091 | —- | M] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2009/03/04 16:02:08 | 00,024,064 | —- | M] () – C:\Documents and Settings\bob bush\My Documents\bank ifo.doc
[2009/02/25 16:12:32 | 00,000,000 | —- | M] () – C:\WINDOWS\MKDEWE.TRN
[2009/02/24 09:15:08 | 00,031,744 | —- | M] () – C:\Documents and Settings\bob bush\My Documents\bank feb24.doc
[2009/02/20 18:21:58 | 00,143,360 | —- | M] () – C:\Documents and Settings\bob bush\My Documents\LockerFunction.dll
[2009/02/19 10:09:33 | 00,401,372 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\kb16.com:SummaryInformation
< End of report >




Here is the Extras file



OTListIt Extras logfile created on: 3/16/2009 2:38:21 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.5.2 Folder = C:\Documents and Settings\bob bush\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.84 Gb Available Physical Memory | 56.07% Memory free
2.29 Gb Paging File | 1.76 Gb Available in Paging File | 76.83% Paging File free
Paging file location(s): C:\pagefile.sys 960 1920;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 59.97 Gb Free Space | 80.48% Space Free | Partition Type: NTFS
Drive D: | 28.61 Gb Total Space | 26.00 Gb Free Space | 90.89% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 6.67 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 14.92 Gb Total Space | 8.64 Gb Free Space | 57.91% Space Free | Partition Type: FAT32
Drive I: | 3.73 Gb Total Space | 3.71 Gb Free Space | 99.29% Space Free | Partition Type: FAT32

Computer Name: BOB
Current User Name: bob bush
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Tools\Mozilla Tri-Pack\Fiirefox 3.1 Beta 2\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
"3540:UDP" = 3540:UDP:*:Enabled:Peer Name Resolution Protocol (PNRP)
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"67:UDP" = 67:UDP:*:Enabled:DHCP Discovery Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Tools\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC)
C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer (Microsoft Corporation)
C:\Tools\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.)
C:\Tools\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:LocalSubNet:Enabled:Pure Networks Platform Service (Cisco Systems, Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{02EBDBB9-4600-41D3-B566-40CB861511D2}" = World of Warcraft FREE Trial
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{0B095086-7205-4D48-90DF-DCD16613C6D4}" =
"{0E2DAB2F-5A2F-8F65-1006-30E94506B15D}" = Skins
"{103BCDA0-E063-46AC-8028-64E78722ABA7}" =
"{11051835-560C-9E8F-C9B5-C376F4A46580}" = Catalyst Control Center Graphics Previews Common
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{16D354E4-63D4-B300-AFBC-8D22A94CE6D6}" = ccc-utility
"{1B1DDAD2-C704-49F8-8FC2-18DAAD9A87C5}" = Sound Blaster Audigy
"{1C2CD847-D196-079D-E004-C1D82B57E3A7}" = Catalyst Control Center Graphics Full Existing
"{20AC583C-A6FB-410A-807D-25308225C201}" = Paint.NET v3.35
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2616B36E-38CE-4357-8AB5-8B3EE9B1C117}" =
"{2670895A-4E6C-4450-B868-7B7DB80A3357}" =
"{2BA00471-0328-3743-93BD-FA813353A783}" = Microsoft .NET Framework 3.0 Service Pack 1
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}" = Creative MediaSource
"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
"{3248F0A8-6813-11D6-A77B-00B0D0150030}" = J2SE Runtime Environment 5.0 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{32B4B536-4443-42F0-9676-98373BE9114F}" =
"{34EBD418-B8E6-4E86-89C4-33B72CF5663F}" =
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{37E9E443-FA8E-095F-CF2A-90A18B0B206B}" = CCC Help English
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3CBA0E30-6F54-47EF-910E-1D4D450AFE45}" = ATI Multimedia Center
"{3F5B6210-0903-4DC6-8034-8F488AA3A782}" = Spy Sweeper Core
"{448A1BF6-B110-5C4B-2220-30F5ECE6DD83}" = Catalyst Control Center Core Implementation
"{4669544E-20E4-4E56-8B44-2E6E1200051F}" = Canon MP Toolbox [removed].mp10
"{4C78937F-0C8E-11D9-A3EB-0001025FA304}" = Kensington MouseWorks
"{4F3C8CEE-89D6-891E-D728-80A8CF0DCB32}" = ccc-core-preinstall
"{52338F65-A1C3-4CDC-B733-50051682B297}" =
"{58F8C6D9-5B55-486A-A322-4E8D87670031}" = Canon MP Drivers
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{5CDDF96A-BC34-4D72-9ABA-E1FFF0C39977}" =
"{63A317D0-60A6-43FC-848A-9FE4A53B29CE}" =
"{654870E9-EF38-D3B3-328C-ABA367163D15}" = Catalyst Control Center Graphics Full New
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6DE7A046-E66F-49B8-93C9-21378D9B0F24}" = Cisco Network Magic
"{700932B3-A964-4878-82A2-96054622A1F7}" =
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" =
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73919E2B-725C-4FAA-8473-45E063A3575F}" =
"{76F8CB2B-6516-4E1E-B6F1-AED4ABDB4B0A}_is1" = Webroot AntiVirus with AntiSpyware
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7AFFF09F-386B-4F7A-B3E0-EC24C13893AA}" =
"{822A8730-86A7-4CAA-BDE1-7337169BFF2B}" = Sound Blaster X-Fi Xtreme Audio
"{83073C45-3003-4671-9A86-243AAADD915A}" = Microsoft Calculator Plus
"{8398B542-3CC4-44D9-83DF-696CCE70124B}" = Windows Support Tools
"{84F573D3-0F71-4768-978A-D35310E3FBA6}" =
"{888347B3-AEC5-4BB5-8BAB-781D72A57C73}" =
"{88B1984E-36F0-47B8-B8DC-728966807A9C}" =
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CD8CCC0-3C5C-DF21-DAC3-D5834E803F1E}" = Catalyst Control Center Graphics Light
"{8F6A89F1-F04A-6FD8-1802-D7D5BAE382E1}" = ccc-core-static
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{91490409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Primary Interop Assemblies
"{9194237B-7B58-40B4-A739-184AD59531A2}" =
"{97C72772-7343-4308-B665-D134855D733E}" = Cleanerzoomer 3.0b
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A654A805-41D9-40C7-AA46-4AF04F044D61}" = Adobe® Photoshop® Album Starter Edition 3.2
"{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}" =
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B0625F16-B742-4F75-9FD8-20B47ACC7DE2}" = ACDSee 7.0 PowerPack
"{B3B20D3D-92F9-5EBA-B557-CECA02984F05}" = Catalyst Control Center HydraVision Full
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BD6928A2-9F8F-4AA7-9A3A-FD4A271712EE}" =
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{C61244F9-C335-4EE4-BF7B-5CAB855555E3}" = Linksys Wireless-G Print Server
"{C64409FA-42A7-49C6-837A-D2E5D813BD57}" =
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB99E420-8071-48F9-9567-4A53BE7569C4}" =
"{D3B1C799-CB73-42DE-BA0F-2344793A095C}" = Catalyst Control Center - Branding
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{DAAC5938-8026-4D0C-A476-D1954917B7F5}" =
"{DE114695-AE58-4B66-8E0F-2505188602FB}_is1" = Uninstall Startup Inspector
"{DE4A4C48-2232-4CCB-AD61-490ACD29BA85}" =
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E0828692-FD9D-459F-9312-C645C3CA6650}" = HP Photo and Imaging 2.0 - Deskjet Series
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{ECC3C64B-2A22-48C5-857B-E952D7BE64F5}" =
"{F0601E2E-8FB3-1C63-F72D-54EB2F908767}" = Skins
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FB5CB59C-D4F6-4303-A414-83D533EE773B}" = Pure Networks Platform
"{FBFF2411-D066-4D24-BCE0-893086009E1B}" =
"{FCCDA302-32D9-4AE7-A094-4BE677554F26}" =
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"Ad-Aware" = Ad-Aware
"AddressBook" =
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe® Photoshop® Album Starter Edition 3.2" = Adobe® Photoshop® Album Starter Edition 3.2
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AudioCS" =
"AVG8Uninstall" = AVG Free 8.0
"AVS Audio Converter 5.1_is1" = AVS Audio Converter version 5.1
"AVS Disc Creator_is1" = AVS Disc Creator version 3.4
"Branding" =
"Burn4Free" = Burn4Free CD and DVD
"CADI" =
"Calendar 2000" = Calendar 2000
"CCleaner" = CCleaner (remove only)
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Connection Manager" =
"Console Launcher" =
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 [removed]
"Creative Audio Device Selection" =
"Creative Audio Device Selection Unicode" =
"Creative MediaSource" =
"Creative MediaSource 5" =
"Creative MediaSource CD-ROM Burner Plugin Unicode" =
"Creative MediaSource Detector" =
"Creative MediaSource Go!" =
"Creative MediaSource MiniDisc Plugin" =
"Creative MediaSource MiniDisc Plugin Unicode" =
"Creative MediaSource Net Content Plugin Unicode" =
"Creative MediaSource Online Store Plugin" =
"Creative MediaSource Player Skin Pack" =
"Creative MediaSource Player Skin Pack Unicode" =
"Creative MediaSource Unicode" =
"Creative Music Store Plugin" =
"Creative Restore Defaults" =
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative Volume Panel" =
"Device Control" =
"Diagnostics 4_5" =
"DirectAnimation" =
"DirectDrawEx" =
"DivX 5.0.2 Bundle" = DivX 5.0.2 Bundle
"DXM_Runtime" =
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"EAXSet" =
"Equalizer" =
"Error Messages for Windows" = Error Messages for Windows
"ERUNT_is1" = ERUNT 1.1j
"Fontcore" =
"Free Folder Hider_is1" = Free Folder Hider 10.7
"Get PowerDVD" =
"HijackThis" = HijackThis 2.0.2
"hp print screen utility" = hp print screen utility
"ICW" =
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"IE40" =
"IE4Data" =
"IE5BAKEX" =
"ie7" = Windows Internet Explorer 7
"IEData" =
"InCD!UninstallKey" = Ahead InCD
"InstallShield Uninstall Information" =
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{3CBA0E30-6F54-47EF-910E-1D4D450AFE45}" = ATI Multimedia Center 9.16
"InstallShield_{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"LimeWire" = LimeWire 4.18.8
"MailFrontier Desktop" =
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" =
"Microsoft .NET Framework 3.0" =
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"MobileOptionPack" =
"Mosby's Medical Encyclopedia" = Mosby's Medical Encyclopedia
"Mozilla Firefox (2.0.0.20)" = Mozilla Firefox (2.0.0.20)
"Mozilla Firefox (3.0.7)" = Mozilla Firefox (3.0.7)
"Mozilla Tri-Pack" = Mozilla Tri-Pack
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSI30a-KB884016" =
"MSI30-Beta1" =
"MSI30-Beta2" =
"MSI30-KB884016" =
"MSI30-RC1" =
"MSI30-RC2" =
"MSI31-Beta" =
"MSI31-RC1" =
"NetMeeting" =
"Network MagicUninstall" = Network Magic
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OutlookExpress" =
"PC Doc Pro_is1" = PC Doc Pro
"PC Pitstop Optimize2_is1" = PC Pitstop Optimize2 2.0
"PCHealth" =
"Perfect General Internet Edition & WWII Battle Set" = Perfect General Internet Edition & WWII Battle Set
"RealJukebox 1.0" =
"RealPlayer 6.0" = RealPlayer
"SchedulingAgent" =
"SFBM" =
"Smart Recorder" =
"Sound Blaster Audigy" =
"Sound Blaster Audigy Windows Drivers" =
"Sound Blaster X-Fi Xtreme Audio" =
"Sound Blaster X-Fi Xtreme Audio Windows Drivers" =
"SPEAKER" =
"SURMIXER" =
"SysInfo" = Creative System Information
"Tweak UI 2.10" = Tweak UI
"WaveStudio 7" =
"WIC" = Windows Imaging Component
"WinAce Archiver" = WinAce Archiver
"WinASO Registry Optimizer 4.1_is1" = WinASO Registry Optimizer 4.1
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinZip" = WinZip
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XP Codec Pack" = XP Codec Pack
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"ZoneAlarm" = ZoneAlarm
"ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Sun Download Manager 2.0 (web)" = Sun Download Manager 2.0 (web)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/4/2009 4:40:15 PM | Computer Name = BOB | Source = QuickBooks | ID = 4
Description =

Error - 3/4/2009 4:42:14 PM | Computer Name = BOB | Source = QuickBooks | ID = 4
Description =

Error - 3/4/2009 4:56:26 PM | Computer Name = BOB | Source = Application Error | ID = 1000
Description = Faulting application qbw32.exe, version 19.0.4001.703, faulting module
ole32.dll, version 5.1.2600.2726, fault address 0x0002df2d.

Error - 3/4/2009 6:38:54 PM | Computer Name = BOB | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Failed to compile: C:\drivers\PC Drivers HeadQuarters\Driver Detective\DriversHQ.DriverDetective.Client.exe
. Error code = 0x80131047

Error - 3/6/2009 6:35:42 PM | Computer Name = BOB | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module ieui.dll, version 7.0.5730.13, fault address 0x000061b1.

Error - 3/11/2009 8:10:31 PM | Computer Name = BOB | Source = Application Error | ID = 1000
Description = Faulting application general.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.

Error - 3/11/2009 8:11:02 PM | Computer Name = BOB | Source = Application Error | ID = 1000
Description = Faulting application general.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.

Error - 3/11/2009 8:12:06 PM | Computer Name = BOB | Source = Application Error | ID = 1000
Description = Faulting application general.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.

Error - 3/12/2009 1:40:24 AM | Computer Name = BOB | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 3/13/2009 2:43:36 AM | Computer Name = BOB | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80240016, P2 begininstall, P3 install, P4
1.1.1593.0, P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL,
P10 NIL.

[ System Events ]
Error - 3/14/2009 12:27:58 AM | Computer Name = BOB | Source = Service Control Manager | ID = 7000
Description = The hpdj service failed to start due to the following error: %%3

Error - 3/14/2009 12:27:58 AM | Computer Name = BOB | Source = Service Control Manager | ID = 7000
Description = The Upload Manager service failed to start due to the following error:
%%1079

Error - 3/14/2009 12:27:58 AM | Computer Name = BOB | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Fax service to connect.

Error - 3/14/2009 12:27:58 AM | Computer Name = BOB | Source = Service Control Manager | ID = 7000
Description = The Fax service failed to start due to the following error: %%1053

Error - 3/14/2009 2:44:29 PM | Computer Name = BOB | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{9EAD6A38-8366-4891-BE54-E72D49CB85F9}. The
backup browser is stopping.

Error - 3/15/2009 2:16:24 AM | Computer Name = BOB | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.104 for the Network Card with network
address 000D8819A54B has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 3/15/2009 6:39:27 PM | Computer Name = BOB | Source = Service Control Manager | ID = 7000
Description = The hpdj service failed to start due to the following error: %%3

Error - 3/15/2009 6:39:27 PM | Computer Name = BOB | Source = Service Control Manager | ID = 7000
Description = The Upload Manager service failed to start due to the following error:
%%1079

Error - 3/15/2009 6:39:27 PM | Computer Name = BOB | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Fax service to connect.

Error - 3/15/2009 6:39:27 PM | Computer Name = BOB | Source = Service Control Manager | ID = 7000
Description = The Fax service failed to start due to the following error: %%1053


< End of report >

I am happy to wait for your attention to my situation, I recognize that there are people out there with alot greater problems than mine.

I look at it as sort of a Triage operation.
Treat the most injured first and then the rest like me.

Thank you.

Respectfully,

bob bush
h_bobby**************@comcast.net Edited by paws to try and keep the bad guys from flooding your Inbox
Hi bobb4503,

Please do the following:

NOTE: please disable any realtime protection you may have running before this fix - usually a right click on the icon in the system tray > Exit

Run OTList2.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTLI2

    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - Reg Error: Key error. File not found
    O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
    O33 - MountPoints2\{acbfdd49-ffa2-11dd-9817-000d8819a54b}\Shell - "" = AutoRun
    O33 - MountPoints2\{acbfdd49-ffa2-11dd-9817-000d8819a54b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{acbfdd49-ffa2-11dd-9817-000d8819a54b}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – [2007/10/23 02:45:39 | 01,336,632 | R— | M] ()
    O33 - MountPoints2\G\Shell - "" = AutoRun
    O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – [2007/10/23 02:45:39 | 01,336,632 | R— | M] ()
    [2 C:\WINDOWS\*.tmp files]
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )

Next

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer. (v6 update 12)

Next

Please download ATF Cleaner by Atribune.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
    • If you use Firefox browser
    • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time.

next


Start your MalwareBytes Antimalware program
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Next

Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

In your next reply please include
  • OTLI2 log
  • MBAM log
  • Kaspersky report
  • fresh HJT log

Also please advise how your computer is running now
CatByte, HELP, HELP, HELP I FOLLOWED YOUR INSTRUCTIONS TO THE LETTER. I opened OTListIt2. I copied and pasted the code in the box into the custom box, I clicked the Run Fix box. it went for a few minutes and said process completed and asked if i wanted to reboot. i clicked yes reboot now. the icons disappeared and then nothing, it froze up. after 20 minutes, nothing happened. I hit Ctrl/Alt/Del and hit Restart. Again nothing happened after 20 minutes i force booted. It goes to the Windows splash screen and stops. I tried restarting in Safe Mode with the same result, nothing. I tried restarting from the last system restore point and again nothing past the splash screen.
i am sending from another computer,

please help me

bob bush
email removed, unless you want tons of spam don't post it out in the open.
[removed] in the united states
bobb4503

when you tap F8 on start up

can you get to the screen where you have options of start - up


choose = last known good configuration and hit enter
i tried f8 to start up in safe mode and it did not work either i also tried f8 and command prompt to no avail i tried f8 and last known good configuration and that did not work either i also tried with a recovery cd and that does not work. whatever happened, it is catastrophic i also loaded the winsows cd in and tried to repair windows. all i got in that iteration was a reboot loop. it appears that my only option is a full reinstall unless you have any other ideas bob b
I am just consulting with other experts here to see why this could have happened……. it is most unusual that last know good configuration wont work…. bear with us - we'll try and come up with a solution without having to do a full install…
OK, we need to boot to the recovery console to restore your registry.

Boot into the Recovery Console by following these steps:
  • Insert the Windows CD and restart your computer. Follow your computer's prompts to boot from the CD. (You might need to adjust settings in the computer's BIOS to enable the option to boot from a CD.)
  • Follow the setup prompts to load the basic Windows startup files. At the Welcome To Setup screen press R to start the Recovery Console.
  • Enter the number of the Windows installation you want to access from the Recovery Console.
  • When prompted for the Administrator password, leave this blank, and hit Enter.
  • At the command prompt, type in cd c:\windows\ERDNT then hit Enter
  • Now type in dir and hit Enter
  • You will see a list with one or more entries being like 3-5-2009
  • Make a note of the most recent date
  • Now type in cd 3-5-2009 or what ever is the most recent date that you noted down
  • You should now have a command prompt that shows C:\WINDOWS\ERDNT\3-5-2009> or the date that you entered
  • Type in batch erdnt.con and hit Enter
  • The registry backups will now be copied into place
  • Type in exit and hit Enter.
You will now boot into windows, let me know how things go.
i tried that earlier and i could not get out of c:\windows. i tried using cd and i tried using chdir neither one worked. i just kept getting returned to c:\windows. bob b

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI