This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer Freezing Up

43 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

free_spirit_etc,

I did notice when I was looking for the Tea Timer on the Spybot startup - that there was something disabled on start up.
The box is unchecked and it says start up disabled.


HPDigitalImagi C:\PROGRA~1|HP|DIGTA~1\bin\hpqtra08.exe

HP Digital Imaging Monitor - Relates to your All in One Printer - Required if you prefer to use the all-in-one buttons to manually scan documents or transfer photos from a camera, for example

This item is not essential at start up. That being said, please try and re-enable it to begin at start up to see if helps alleviate the problem.

  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the System Start up in the list.
  • Locate HPDigitalImagi C:\PROGRA~1|HP|DIGTA~1\bin\hpqtra08.exe and place a check mark in the box to it's left.
  • Exit Spybot S&D when done.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • New HijackThis log
  • Tell me how your computer is running.

I tried to check the box in Spybot, but it wouldn't let me select it. I tried checking the box, and I tried highlighting it and checking the box. It will let me uncheck boxes, but it won't let me check that one.

My computer seems to be running much better. It didn't freeze on me at random. It did give me the error a couple times when I printed coupons - Microsoft Visual C+ Run TIme Error C:\Program Files \ Internet Explorer \iexplore.exe

And of course, the PhotoGallery still wants me to install a disk when I start the computer.

Here is my new Hijack this log:



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:45:55 AM, on 5/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: IE to Lightning Helper - {F1FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\Lightning Download\LD_Catch.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1238528926738
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{91D2EC90-5FB7-478F-96C5-1A8C5263C28E}: NameServer = 146.163.252.6 146.163.252.7
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 6626 bytes

free_spirit_etc,

Let's reset your Internet Explorer settings to their default values to see if that clears up your runtime error.

  • Open Internet Explorer 7.
  • Click Tools, and then click Internet Options.
  • Click the Advanced tab.
  • Under Reset Internet Explorer Settings, click Reset.
- - - - - Next - - - - -

Reboot

- - - - - Next - - - - -

Your log is clean of malware. I would like for you to do an online scan to verify this.

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • ESET log.txt
  • New HijackThis log
  • Please tell me how your computer is running.

Yes. Thanks. My computer has been running much better. And I have been super busy. I re-set the Internet Explorer settings. And I tried to run the scanner last night. The first time it said that I had stopped the scan (though I didn't think I had). So I ran it again - and it went over 30 minutes and then my computer froze up before it was finished. (I am on dial-up). It hasn't really been freezing up on me lately - but it did this time. I rebooted - and it froze up again immediately. So I gave up on it for the night and figured I would try to do the scan again tonight. Free

free_spirit_etc,

Since you seem to be encountering difficulty each time you try and do the online scan we are going to omit that step
All recent logs you have provided show no signs of malware.

You haven't stated if you are still being prompted for the Photo Gallery disk at start up.

Your computer is clean of malware. But there are still some issues we weren't able to resolve.

Please be advised that this forum is for malware removal only. To assist in resolving your remaining issues you can post in our Windows Help Section.
http://forums.whatthetech.com/Microsoft_Windows_f119.html

If you chose to post at the Windows Help Section please post a link back to this thread so the tech helper can review what we have covered.
http://forums.whatthetech.com/CMF_free_spi…tc_t102502.html

- - - - - Next - - - - -

First we have to take care of this before we get to the All Clean Speech

Enable SpyBot's Tea Timer

  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Check the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Check the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done.
- - - - - Next - - - - -

Your Adobe Reader is out of date.
Please go to http://get.adobe.com/reader/ and download Adobe Reader 9
follow the instructions to install Adobe Reader.

- - - - - Next - - - - -

Here comes the "All Clean Speech":

Now that your log is clean, you need to set a new clean System Restore Point

Create a new Restore Point
  • Click on the Start button to open your Start Menu.
  • Click on the Control Panel menu option.
  • Click on the System and Maintenance menu option.
  • Click on the System menu option.
  • Click on System Protection in the left-hand task list.
  • Create the manual restore point you should click on the Create button. When you press this button a prompt will appear asking you to provide a title for this manual restore point.
  • Type in a title for the manual restore point and press the Create button.
  • Close the System window after you have been advised that the procedure has been successfully completed.
- - - - - Next - - - - -

Clear your existing system restore points except for the new clean restore point you just created:
  • Go to Start > Run and type in cleanmgr
  • Select the More options tab
  • Next to System Restore click Clean up
  • This will remove all restore points except the new one you just created.
- - - - - Next - - - - -

Delete the Contents of the Temporary Internet Files Folder:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, click to select the Delete all offline content check box , and then click OK.
  • Click OK
- - - - - Next - - - - -

Automatic Updates:

The easiest way to ensure you don't miss any of the critical Windows Updates is to set your computer up to receive Automatic Updates.
To set your computer up for Automatic Updates please do the following:
  • Click Start, and then click Control Panel.
  • Depending on which Control Panel view you use, Classic or Category, do one of the following:
  • Click System, and then click the Automatic Updates tab.
  • Click Performance and Maintenance, click System, and then click the Automatic Updates tab.
  • Select Automatic and choose a frequency and time that's convenient for you to get the updates.
  • Click Apply, then OK
  • Close the Control Panel.
- - - - - Next - - - - -

Here are some tips to reduce the potential for spyware infection in the future:

Make your Internet Explorer more secure - This can be done by following these simple instructions:

  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Simple and easy ways to keep your computer safe and secure on the Internet

Alternate Browsers - If you are currently using Internet Explorer you might want to consider changing over to Firefox.
Firefox is one of the most popular alternate browsers. - Mozilla Firefox

Update your AntiVirus Software - You are using Avast Anti - Virus as your anti virus software. It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - You are using Window's Firewall. I cannot stress how important it is that you keep the Firewall on your computer active at all times. Without a firewall your computer is susceptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly. For a tutorial on Firewalls and a listing of some available ones see the link below:
Understanding and Using Firewalls

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs. A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that
aren't actually innocent at all. Using IE-SPYAD to help block unwanted sites and activities

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
This will ensure your computer always has the latest security updates available installed on your computer.
If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Update all security programs regularly - Make sure you update all the programs regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.

Remember to have only one (1) Firewall and one (1) Anti-Virus program running at any one time.

I would also suggest you read "So how did I get infected in the first place"?: by Tony Klein

Thanks do much. Yes. The Photo Gallery still prompts me for the disk at restart. I actually got prompted for a disk at the beginning of starting to download the Adobe Reader too. I am not quite sure why. But after I clicked cancel on it - it started the download. I re-checked the Tea Timer in Spybot Resident Protection. I still do not have it in system startup. I am downloading Adobe - and it looks like it will take awhile.

free_spirit_etc,

I am glad I was able to help you clean up your computer.

If you would like to try to resolve both the Photo Gallery and the SpyBot issue you will be better served by posting in the Windows Help Section.

http://forums.whatthetech.com/Microsoft_Windows_f119.html

If you chose to post at the Windows Help Section please post a link back to this thread so the tech helper can review what we have covered.
http://forums.whatthetech.com/CMF_free_spi…tc_t102502.html

Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.
Hi,

I am back.

I was getting help in the Microsoft Windows forum
http://forums.whatthetech.com/Computer_Freezing_t103277.html

But not having much luck with getting my computer to stop freezing.

I am thinking the system was not clean.
I did QUICK scans Malwarebytes before.
I updated and did another one today.
The Quick Scan came up clean
Then I did a FULL scan.

Malwarebytes' Anti-Malware 1.36
Database version: 2173
Windows 5.1.2600 Service Pack 3

5/24/2009 1:04:46 AM
mbam-log-2009-05-24 (01-04-46).txt

Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\|)
Objects scanned: 138438
Time elapsed: 14 minute(s), 28 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

From what I am reading, the backdoor bot is not a good thing.

Also, I checked the Ignore list on Malwarebytes. For some reason I hadn't checked that before.
It showed two things to ignore, though I had never set it to ignore anything.

They were HKEY_CLASSES_ROOT\Interface\{a138be8b-f051-4802-9a3f-a75096d862d43}
and HKEY_CLASSES_ROOT\Interface\{6e780fob-bcd6-40cb-b2db-7af47-9b4d494}

Not sure why those were on the ignore list.

I did another Hijackthislog:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:13:10 AM, on 5/24/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: IE to Lightning Helper - {F1FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\Lightning Download\LD_Catch.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-CEC4-75A487FD6484} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1238528926738
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} -
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) -
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

–
End of file - 4505 bytes

Then I ran another Qucik scan and FULL scan with Malwarebytes - and both of those came up clean. But the first time I tried to do the Full scan, my computer froze up (In Safe Mode). It worked okay the second time.

I have unplugged my computer from the internet. (Dang! and I JUST got highspeed). I am posting from my son's computer.

I also read about changing passwords - I wasn't sure if that was advised in this case - but to be on the safe side, I already changed some.

Any help would be appreciated.

Free

Welcome back free_spirit_etc,

I wish you were returning under different circumstances.

You have been infected with a Backdoor Trojan.

I would highly recommend you disconnect the infected computer from the internet immediately!

Please review the information I have outlined below:

  • It can allow an attacker to gain control of the system, log keystrokes, steal passwords, access personal
    data, send malevolent outgoing traffic, and close the security warning messages displayed by some anti-virus and security programs.
  • I would advise for you to disconnect this PC from the Internet, and then go to a known clean computer and change any passwords or security
    information
    held on the infected computer. In particular, check whatever relates to online banking financial transactions, shopping, credit
    cards
    , or sensitive personal information. It is also wise to contact your financial institutions to apprise them of your situation.
  • We will do our best to clean the computer of any infections seen on the log. However, because of the nature of this Trojan, we cannot offer a total
    guarantee
    that there are no remnants left in the system, or that the computer will be trustworthy.
  • Many security experts believe that once infected with this type of Trojan, the best course of action is to reformat and reinstall the Operating System.
    Making this decision is based on what the computer is used for, and what information can be accessed from it.
  • Trojans are programs that can appear to serve a legitimate purpose but actually have an unwanted or harmful effect.
  • A large segment of trojan programs download other harmful software components to a user's PC without his/her knowledge.
  • This application is most likely downloaded and installed by another application that is considered to be adware or spyware.
Knowing the above, let me know how you would like to proceed.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

- - - - - Next - - - - -

Your Java is outdated.
Please follow these steps to remove older version Java components.
  • Close any programmes you may have running, ESPECIALLY your web browser
  • Click Start > Control Panel.
  • Click Add/Remove Programs.
  • Check any Java item.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove all versions of Java.
  • Reboot your computer once all Java components are removed.
Then download the latest version of Java , which is Version 6 Update 13, and click Yes at the page warning. Under "Platform" select Windows, then check the box to accept the Licence Agreement. Click Yes at the second page warning before downloading the Offline file.
There is no need to download the Sun Dowload manager but it is optional.

- - - - - Next - - - - -

Please download OTListIt2 by OldTimer from http://oldtimer.geekstogo.com/OTListIt2.exe. Save it your desktop.

  • Double click on OTListIt2.exe to run it.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click on Run Scan at the top left hand corner.
  • When done, two (2) Notepad files will open. Please post the contents of these two (2) Notepad files in your next reply. One log per reply please.
- - - - - Next - - - - -

Your HijackThis log appears to have been run in Safe Mode.

Could you please run a new HijackThis scan in Normal Mode.

- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • OTListIt2 logs (both please)
  • New HijackThis log
  • Tell me how your computer is running at the moment.

Thanks!

I am thinking I may have to reformat. I am willing to if that is what it takes. I am not so much concerned about losing data, as I am about doing it correctly, or my computer not working again.

Also, the guy who set my computer up did it to where there is a C drive and a D drive.

My computer is freezing up quite a bit now. It froze once yesterday in safe mode while working on a word document. But it only did that once. I have just been using safe mode and stayed unplugged from the internet.

I updated Java again. I think. I am not sure what is going in with that because you had me update it earlier in this thread and I did so. Actually my add and remove programs was already showing I had Java Version 6 Update 13. But I deleted that. And reinstalled it. I am not sure why it was showing as outdated.

Here are the logs you requested:

OTListIt logfile created on: 5/25/2009 5:41:24 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Semproni\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

255.48 Mb Total Physical Memory | 39.12 Mb Available Physical Memory | 15.31% Memory free
1.35 Gb Paging File | 0.96 Gb Available in Paging File | 71.28% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 63.47 Gb Total Space | 52.26 Gb Free Space | 82.33% Space Free | Partition Type: NTFS
Drive D: | 85.57 Gb Total Space | 74.23 Gb Free Space | 86.75% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 488.00 Mb Total Space | 260.55 Mb Free Space | 53.39% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SEPRONI-D392BF7
Current User Name: Semproni
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Semproni\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Pml Driver HPZ12 [Disabled | Stopped]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (WMPNetworkSvc [Disabled | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (AegisP [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (ES1370 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ES1370MP.sys (Creative Technology Ltd.)
DRV - (FET5X86V [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys (VIA Technologies, Inc. )
DRV - (FETNDIS [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. )
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (HPZid412 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (HSFHWBS2 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (ndiscm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\NetMotCM.sys (Motorola Inc.)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (Point32 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\point32.sys (Microsoft Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RT73 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\rt73.sys (Ralink Technology, Corp.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/04/28 18:13:03 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/06 13:00:40 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/21 14:46:39 | 00,000,000 | —D | M]

[2008/12/17 22:27:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Semproni\Application Data\mozilla\Extensions
[2008/12/17 22:27:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Semproni\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008/12/17 22:27:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Semproni\Application Data\mozilla\Firefox\Profiles\on0wtzl9.default\extensions
[2009/05/25 17:25:03 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/29 10:04:54 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/05/25 17:25:04 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/29 10:04:46 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/29 10:04:46 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/11 23:36:51 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/11 23:36:51 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/11 23:36:51 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/11 23:36:51 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/11 23:36:51 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/11 23:36:51 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/11 23:36:51 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (307853 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 10597 more lines…
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (IE to Lightning Helper) - {F1FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\Lightning Download\LD_Catch.dll (Headlight Software, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {A057A204-BACC-4D26-CEC4-75A487FD6484} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto (Microsoft Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoComputersNearMe = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoComputersNearMe = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 55 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1238528926738 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/21 01:21:26 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{64d7c457-c083-11dd-ac15-000fea17c644}\Shell - "" = AutoRun
O33 - MountPoints2\{64d7c457-c083-11dd-ac15-000fea17c644}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{6a67ac33-101d-11de-ac3c-000fea17c644}\Shell - "" = AutoRun
O33 - MountPoints2\{6a67ac33-101d-11de-ac3c-000fea17c644}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{e12d0375-f38f-11dc-ab98-000fea17c644}\Shell - "" = AutoRun
O33 - MountPoints2\{e12d0375-f38f-11dc-ab98-000fea17c644}\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/05/25 17:40:33 | 00,000,000 | —D | M]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[154 C:\Documents and Settings\Semproni\My Documents\*.tmp files]
[109 C:\Documents and Settings\Semproni\Desktop\*.tmp files]
[2009/05/25 17:40:31 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Semproni\Desktop\OTListIt2.exe
[2009/05/25 16:59:19 | 26,796,4416 | -HS- | C] () – C:\hiberfil.sys
[2009/05/25 16:58:07 | 00,122,368 | —- | C] () – C:\Documents and Settings\Semproni\Desktop\more scope of application.doc
[2009/05/24 13:59:42 | 00,084,691 | —- | C] () – C:\Documents and Settings\Semproni\Desktop\WinKeyFinder173_RC2.zip
[2009/05/24 13:53:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Semproni\Desktop\keyfinder.2.0.1
[2009/05/23 20:44:44 | 00,275,080 | —- | C] () – C:\Documents and Settings\Semproni\Desktop\system event log 5232009_844pm.evt
[2009/05/23 19:03:09 | 00,000,000 | —D | C] – C:\Documents and Settings\Semproni\Desktop\OIG
[2009/05/23 17:29:51 | 00,019,968 | —- | C] () – C:\Documents and Settings\Semproni\My Documents\Plan for junk.doc
[2009/05/22 10:34:43 | 00,022,528 | —- | C] () – C:\Documents and Settings\Semproni\Desktop\I have been working on that.doc
[2009/05/22 02:57:45 | 00,000,000 | —D | C] – C:\Program Files\mypoints
[2009/05/22 02:00:54 | 00,051,376 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/05/22 02:00:54 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/05/22 02:00:54 | 00,001,715 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/05/22 02:00:53 | 00,026,944 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/05/22 02:00:52 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/05/22 02:00:51 | 00,114,768 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/05/22 02:00:51 | 00,094,032 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/05/22 02:00:51 | 00,093,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/05/22 02:00:51 | 00,020,560 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/05/22 02:00:32 | 01,256,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/05/22 02:00:32 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/05/22 01:45:43 | 00,308,160 | —- | C] (ALWIL Software) – C:\Documents and Settings\Semproni\Desktop\avast_home_setup.exe
[2009/05/21 16:13:38 | 00,014,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2009/05/21 14:46:39 | 00,430,080 | —- | C] (Invenda Corporation) – C:\WINDOWS\System32\BSTIEPrintCtl1.dll
[2009/05/21 14:46:39 | 00,417,792 | —- | C] (Invenda Corporation) – C:\NPcol305.dll
[2009/05/21 14:45:44 | 00,988,712 | —- | C] () – C:\Documents and Settings\Semproni\Desktop\CouponActivator.exe
[2009/05/21 13:38:13 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Semproni\My Documents\~$ack Spending.doc
[2009/05/20 23:22:46 | 00,000,000 | —D | C] – C:\Documents and Settings\Semproni\My Documents\spring 05 docs
[2009/05/20 03:00:11 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Semproni\Desktop\~$cial Security Cover Letter March 18, 2008.doc
[2009/05/19 00:53:40 | 13,085,823 | —- | C] () – C:\Documents and Settings\Semproni\My Documents\Belkin Manual_ P74559-B_F5D7230-4v7_man.pdf
[2009/05/17 23:23:51 | 00,015,360 | —- | C] (Motorola Inc.) – C:\WINDOWS\System32\drivers\NetMotCM.sys
[2009/05/17 22:33:20 | 00,532,480 | —- | C] () – C:\Documents and Settings\Semproni\My Documents\Charter set up.doc
[2009/05/17 16:56:48 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Semproni\My Documents\~$eren Deals.doc
[2009/05/17 10:49:06 | 00,000,428 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{8EB98E4C-8F55-435E-9667-18FC8FE9E34B}.job
[2009/05/16 19:49:32 | 00,035,840 | —- | C] () – C:\Documents and Settings\Semproni\Desktop\target.doc
[2009/05/16 16:50:48 | 00,040,448 | —- | C] () – C:\Documents and Settings\Semproni\My Documents\Ameren Deals.doc
[2009/05/16 15:53:08 | 00,099,840 | —- | C] () – C:\Documents and Settings\Semproni\My Documents\Passwords.doc
[2009/05/16 15:37:54 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
[2009/05/16 11:56:27 | 00,000,000 | —D | C] – C:\Documents and Settings\Semproni\Desktop\Charter
[2009/05/16 11:10:00 | 00,000,000 | —D | C] – C:\Documents and Settings\Semproni\My Documents\Banks
[2009/05/15 17:12:42 | 00,029,184 | —- | C] () – C:\Documents and Settings\Semproni\My Documents\OIG.doc
[2009/05/15 11:38:49 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Semproni\My Documents\~$mu code used.doc
[2009/05/15 04:52:23 | 00,000,000 | —D | C] – C:\Documents and Settings\Semproni\Application Data\OfficeUpdate12
[2009/05/15 04:35:47 | 00,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2009/05/15 04:35:05 | 00,102,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/05/15 04:32:46 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/05/15 04:03:44 | 00,020,480 | —- | C] () – C:\Documents and Settings\Semproni\Desktop\internet freezing.doc
[2009/05/15 01:00:07 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Semproni\My Documents\~$eping computer clean.doc
[2009/05/14 13:10:25 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Semproni\My Documents\~$edit Cards.doc
[2009/05/14 02:57:42 | 00,059,904 | —- | C] () – C:\Documents and Settings\Semproni\My Documents\HOUSING.doc
[2009/05/12 16:28:51 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Semproni\My Documents\~$m address.doc
[2009/05/12 14:47:26 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Semproni\My Documents\~$hens ohio.doc
[2009/05/12 04:36:44 | 00,023,552 | —- | C] () – C:\Documents and Settings\Semproni\My Documents\athens ohio.doc
[2009/05/12 04:33:59 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2009/05/12 04:32:13 | 00,000,000 | —D | C] – C:\Program Files\Adobe
[2009/05/12 04:31:57 | 00,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2009/05/12 02:04:50 | 00,451,968 | —- | C] (Ralink Technology, Corp.) – C:\WINDOWS\System32\drivers\rt73.sys
[2009/05/12 02:04:50 | 00,000,000 | —D | C] – C:\WINDOWS\System32\DRVSTORE
[2009/05/12 02:04:49 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\UpdateDriver.exe
[2009/05/12 02:04:49 | 00,001,690 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Belkin Wireless Networking Utility.lnk
[2009/05/12 02:04:48 | 00,005,224 | —- | C] () – C:\WINDOWS\System32\ucuiinfo.ini
[2009/05/12 02:04:45 | 00,000,000 | -H-D | C] – C:\Program Files\InstallShield Installation Information
[2009/05/12 02:04:37 | 00,000,000 | —D | C] – C:\Program Files\Belkin
[2009/05/12 02:04:34 | 00,000,000 | —D | C] – C:\Documents and Settings\Semproni\Application Data\InstallShield
[2009/05/11 23:52:17 | 00,020,444 | —- | C] () – C:\Documents and Settings\Semproni\My Documents\USAA electronicdeliveryconsent.pdf
[2009/05/11 22:15:05 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2009/05/11 22:15:03 | 00,000,000 | —D | C] – C:\Program Files\NOS
[2009/05/06 16:28:41 | 00,023,552 | —- | C] () – C:\Documents and Settings\Semproni\My Documents\2009 Coupon Inserts Schedule.doc
[2009/05/05 13:58:08 | 00,000,000 | —D | C] – C:\Documents and Settings\Semproni\Desktop\Internet
[2009/05/03 01:36:25 | 00,233,035 | —- | C] () – C:\Documents and Settings\Semproni\My Documents\Janet Credit Report April 3_ 2009.pdf
[2009/05/02 13:12:42 | 00,035,328 | —- | C] () – C:\Documents and Settings\Semproni\Desktop\May Deals.doc
[2009/05/02 01:44:17 | 00,019,456 | —- | C] () – C:\Documents and Settings\Semproni\My Documents\CONTACT CATALINA.doc
[2009/05/02 00:21:14 | 00,299,688 | —- | C] () – C:\Documents and Settings\Semproni\Desktop\Movie Cash 8032009Your_TPG_Free_Movie_10132625.pdf
[2009/05/01 13:49:39 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/04/30 11:55:30 | 00,020,992 | —- | C] () – C:\Documents and Settings\Semproni\My Documents\THINGS CHOSEN AND THINGS NOT.doc
[2009/04/29 12:17:10 | 00,000,000 | —D | C] – C:\Documents and Settings\Semproni\Desktop\Print today
[2009/04/28 18:12:54 | 00,000,000 | —D | C] – C:\Program Files\Java
[2009/04/28 18:04:25 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Semproni\Desktop\~$ additional argument for date of entitlement.doc
[2009/04/28 16:49:34 | 00,028,160 | —- | C] () – C:\Documents and Settings\Semproni\Desktop\an additional argument for date of entitlement.doc
[2009/04/28 16:06:32 | 00,000,000 | —D | C] – C:\Program Files\EsetOnlineScanner
[2009/04/28 12:19:58 | 00,058,368 | —- | C] () – C:\Documents and Settings\Semproni\Desktop\What the tech.doc
[2009/04/28 12:18:51 | 00,000,000 | —D | C] – C:\Program Files\E1704C
[2009/04/28 12:17:28 | 00,131,829 | —- | C] () – C:\Program Files\E1704C.zip
[2009/04/26 18:27:59 | 00,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2009/04/26 01:19:45 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Semproni\My Documents\~$timating survivor benefits.doc
[2009/04/26 00:33:21 | 00,000,000 | —D | C] – C:\Documents and Settings\Semproni\Desktop\Fall 2009
[2009/04/26 00:33:07 | 00,000,000 | —D | C] – C:\Documents and Settings\Semproni\Desktop\Summer 2009
[2009/04/25 23:15:28 | 00,000,000 | —D | C] – C:\Documents and Settings\Semproni\My Documents\Radiohead - In Rainbows
[2009/04/25 19:30:15 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/25 12:05:48 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\virport.dll
[2009/03/08 06:37:58 | 00,000,097 | —- | C] () – C:\WINDOWS\TaxACT05.ini
[2009/02/10 15:32:45 | 00,000,057 | —- | C] () – C:\WINDOWS\TaxACT08.ini
[2008/10/12 17:46:18 | 00,663,552 | —- | C] () – C:\WINDOWS\System32\tx12.dll
[2008/10/12 17:46:18 | 00,000,530 | —- | C] () – C:\WINDOWS\System32\tx12_ic.ini
[2008/04/15 22:21:02 | 00,000,056 | —- | C] () – C:\WINDOWS\TaxACT07.ini
[2008/04/05 00:37:05 | 00,000,085 | —- | C] () – C:\WINDOWS\TaxACT02.ini
[2008/04/04 23:47:39 | 00,000,073 | —- | C] () – C:\WINDOWS\Taxact00.ini
[2008/04/04 17:54:16 | 00,000,097 | —- | C] () – C:\WINDOWS\TaxACT04.ini
[2008/04/04 15:33:54 | 00,000,098 | —- | C] () – C:\WINDOWS\TaxACT03.ini
[2008/04/04 10:58:36 | 00,000,123 | —- | C] () – C:\WINDOWS\TaxACT06.ini
[2008/02/26 19:11:29 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/02/26 07:25:15 | 00,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/02/26 07:25:15 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/02/22 05:51:58 | 00,000,092 | —- | C] () – C:\WINDOWS\CMISETUP.INI
[2008/02/22 05:51:58 | 00,000,026 | —- | C] () – C:\WINDOWS\CMCDPLAY.INI
[2008/02/22 03:11:35 | 00,000,136 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/02/11 09:39:26 | 00,253,952 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2008/02/11 09:39:18 | 00,237,568 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2008/02/08 13:53:46 | 00,110,592 | —- | C] () – C:\WINDOWS\System32\OnlineScannerLang.dll
[2007/07/27 14:49:02 | 00,225,355 | —- | C] () – C:\WINDOWS\System32\lnod32apiW.dll
[2007/07/27 14:49:02 | 00,196,683 | —- | C] () – C:\WINDOWS\System32\lnod32apiA.dll
[2007/01/03 12:24:36 | 00,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 12:22:46 | 00,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 12:22:14 | 00,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/10/27 09:26:56 | 00,069,632 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2005/12/05 19:25:22 | 00,139,264 | —- | C] () – C:\WINDOWS\System32\lnod32umc.dll
[2005/12/05 12:37:10 | 00,106,496 | —- | C] () – C:\WINDOWS\System32\lnod32upd.dll
[2004/08/16 19:49:43 | 00,000,658 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/16 19:49:34 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2003/02/18 19:26:28 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\cmirmdrv.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[154 C:\Documents and Settings\Semproni\My Documents\*.tmp files]
[109 C:\Documents and Settings\Semproni\Desktop\*.tmp files]
[2009/05/25 17:40:33 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Semproni\Desktop\OTListIt2.exe
[2009/05/25 17:35:36 | 00,000,658 | —- | M] () – C:\WINDOWS\win.ini
[2009/05/25 17:35:36 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/05/25 17:35:36 | 00,000,211 | -HS- | M] () – C:\boot.ini
[2009/05/25 17:35:31 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/25 17:34:53 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Semproni\Local Settings\desktop.ini
[2009/05/25 17:34:48 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/25 17:34:44 | 26,796,4416 | -HS- | M] () – C:\hiberfil.sys
[2009/05/25 17:28:08 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/05/25 17:06:01 | 00,000,428 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{8EB98E4C-8F55-435E-9667-18FC8FE9E34B}.job
[2009/05/25 16:58:07 | 00,122,368 | —- | M] () – C:\Documents and Settings\Semproni\Desktop\more scope of application.doc
[2009/05/25 02:57:07 | 00,061,440 | —- | M] () – C:\Documents and Settings\Semproni\Desktop\TO DO.doc
[2009/05/24 13:59:42 | 00,084,691 | —- | M] () – C:\Documents and Settings\Semproni\Desktop\WinKeyFinder173_RC2.zip
[2009/05/23 20:44:45 | 00,275,080 | —- | M] () – C:\Documents and Settings\Semproni\Desktop\system event log 5232009_844pm.evt
[2009/05/23 20:30:05 | 00,000,136 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/05/23 19:16:44 | 00,035,328 | —- | M] () – C:\Documents and Settings\Semproni\Desktop\May Deals.doc
[2009/05/23 18:46:14 | 00,307,853 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/05/23 17:32:10 | 00,019,968 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\Plan for junk.doc
[2009/05/22 11:55:35 | 00,000,231 | —- | M] () – C:\Documents and Settings\Semproni\Desktop\Craigslist.url
[2009/05/22 11:05:57 | 00,022,528 | —- | M] () – C:\Documents and Settings\Semproni\Desktop\I have been working on that.doc
[2009/05/22 10:19:29 | 00,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2009/05/22 02:00:54 | 00,001,715 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/05/22 02:00:51 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/05/22 01:45:44 | 00,308,160 | —- | M] (ALWIL Software) – C:\Documents and Settings\Semproni\Desktop\avast_home_setup.exe
[2009/05/21 16:13:10 | 00,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2009/05/21 16:13:10 | 00,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2009/05/21 14:46:39 | 00,430,080 | —- | M] (Invenda Corporation) – C:\WINDOWS\System32\BSTIEPrintCtl1.dll
[2009/05/21 14:46:39 | 00,417,792 | —- | M] (Invenda Corporation) – C:\NPcol305.dll
[2009/05/21 14:45:49 | 00,988,712 | —- | M] () – C:\Documents and Settings\Semproni\Desktop\CouponActivator.exe
[2009/05/21 14:16:20 | 00,029,696 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\Credit Cards.doc
[2009/05/21 14:15:15 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Semproni\My Documents\~$edit Cards.doc
[2009/05/21 14:14:47 | 00,045,568 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\Track Spending.doc
[2009/05/21 13:38:13 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Semproni\My Documents\~$ack Spending.doc
[2009/05/20 21:51:22 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Semproni\My Documents\~$m address.doc
[2009/05/20 03:00:11 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Semproni\Desktop\~$cial Security Cover Letter March 18, 2008.doc
[2009/05/19 15:29:30 | 00,099,840 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\Passwords.doc
[2009/05/19 00:53:41 | 13,085,823 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\Belkin Manual_ P74559-B_F5D7230-4v7_man.pdf
[2009/05/18 17:57:49 | 00,532,480 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\Charter set up.doc
[2009/05/18 17:57:46 | 00,029,184 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\OIG.doc
[2009/05/18 12:07:05 | 00,000,516 | —- | M] () – C:\WINDOWS\tasks\WinASORegistryOptimizerForSemproni.job
[2009/05/17 17:00:34 | 00,040,448 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\Ameren Deals.doc
[2009/05/17 16:56:48 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Semproni\My Documents\~$eren Deals.doc
[2009/05/16 19:52:24 | 00,035,840 | —- | M] () – C:\Documents and Settings\Semproni\Desktop\target.doc
[2009/05/15 13:00:14 | 00,000,073 | —- | M] () – C:\WINDOWS\Taxact00.ini
[2009/05/15 12:56:55 | 00,000,097 | —- | M] () – C:\WINDOWS\TaxACT05.ini
[2009/05/15 11:38:49 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Semproni\My Documents\~$mu code used.doc
[2009/05/15 05:09:19 | 00,000,057 | —- | M] () – C:\WINDOWS\TaxACT08.ini
[2009/05/15 04:38:11 | 00,000,079 | -HS- | M] () – C:\Documents and Settings\Semproni\My Documents\desktop.ini
[2009/05/15 04:36:41 | 00,020,480 | —- | M] () – C:\Documents and Settings\Semproni\Desktop\internet freezing.doc
[2009/05/15 04:35:50 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/05/15 03:06:55 | 00,293,536 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090523-184614.backup
[2009/05/15 01:00:07 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Semproni\My Documents\~$eping computer clean.doc
[2009/05/14 03:01:47 | 00,090,624 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\SUPPORT.doc
[2009/05/14 02:57:42 | 00,059,904 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\HOUSING.doc
[2009/05/12 23:48:33 | 00,000,374 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2009/05/12 14:47:26 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Semproni\My Documents\~$hens ohio.doc
[2009/05/12 04:36:45 | 00,023,552 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\athens ohio.doc
[2009/05/12 02:06:59 | 00,468,774 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/05/12 02:06:59 | 00,401,394 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/05/12 02:06:59 | 00,059,818 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/05/12 02:04:49 | 00,001,690 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Belkin Wireless Networking Utility.lnk
[2009/05/11 23:52:17 | 00,020,444 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\USAA electronicdeliveryconsent.pdf
[2009/05/11 18:09:27 | 00,000,056 | —- | M] () – C:\WINDOWS\TaxACT07.ini
[2009/05/11 18:08:54 | 00,000,123 | —- | M] () – C:\WINDOWS\TaxACT06.ini
[2009/05/11 18:07:40 | 00,000,098 | —- | M] () – C:\WINDOWS\TaxACT03.ini
[2009/05/09 13:00:20 | 00,110,592 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\Free Shipping . com claims.doc
[2009/05/09 00:14:46 | 00,025,600 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\Pizza Hut Coupon codes.doc
[2009/05/07 02:16:29 | 24,699,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/05/06 16:28:41 | 00,023,552 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\2009 Coupon Inserts Schedule.doc
[2009/05/03 02:17:39 | 00,048,640 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\To Cancel.doc
[2009/05/03 01:36:25 | 00,233,035 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\Janet Credit Report April 3_ 2009.pdf
[2009/05/03 01:21:45 | 00,288,768 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\Start CheckoutFree.doc
[2009/05/02 03:43:37 | 00,019,456 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\CONTACT CATALINA.doc
[2009/05/02 00:21:14 | 00,299,688 | —- | M] () – C:\Documents and Settings\Semproni\Desktop\Movie Cash 8032009Your_TPG_Free_Movie_10132625.pdf
[2009/05/01 17:09:49 | 00,058,368 | —- | M] () – C:\Documents and Settings\Semproni\Desktop\What the tech.doc
[2009/04/30 11:55:42 | 00,020,992 | —- | M] () – C:\Documents and Settings\Semproni\My Documents\THINGS CHOSEN AND THINGS NOT.doc
[2009/04/29 22:49:00 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Semproni\Desktop\~$one Cable Internet.doc
[2009/04/28 23:33:56 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Semproni\Desktop\~$ additional argument for date of entitlement.doc
[2009/04/28 16:49:34 | 00,028,160 | —- | M] () – C:\Documents and Settings\Semproni\Desktop\an additional argument for date of entitlement.doc
[2009/04/26 01:19:45 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Semproni\My Documents\~$timating survivor benefits.doc
[2009/04/25 20:44:15 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Semproni\Desktop\~$ee Shipping . com claims.doc
[2009/04/25 19:35:15 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Semproni\Desktop\~$ril Deals.doc

========== Alternate Data Streams ==========

@Alternate Data Stream - 1406 bytes -> C:\Documents and Settings\Semproni\Desktop\iGoogle.url:favicon
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 1150 bytes -> C:\Documents and Settings\Semproni\Desktop\Craigslist.url:favicon
< End of report >

OTListIt Extras logfile created on: 5/25/2009 5:41:24 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Semproni\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

255.48 Mb Total Physical Memory | 39.12 Mb Available Physical Memory | 15.31% Memory free
1.35 Gb Paging File | 0.96 Gb Available in Paging File | 71.28% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 63.47 Gb Total Space | 52.26 Gb Free Space | 82.33% Space Free | Partition Type: NTFS
Drive D: | 85.57 Gb Total Space | 74.23 Gb Free Space | 86.75% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 488.00 Mb Total Space | 260.55 Mb Free Space | 53.39% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SEPRONI-D392BF7
Current User Name: Semproni
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Lightning Download\Lightning.exe:*:Enabled:Lightning Download® see: www.LightningDownload.com (Headlight Software, Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00020409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Standard
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{2405665A-16C9-4D3A-B70E-F006220E1472}" = Overland
"{267868CE-6DFF-40F7-9C58-C01119B7B117}" = Fax
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{2F71F2BA-B513-4113-969C-18A84D238E27}" = 1310
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AE681E0-4E8D-453F-950A-48534D3C0724}" = Copy
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{41254D7B-EADF-4078-AE4A-BD73B300EE86}" = Unload
"{457791C5-D702-4143-A7B2-2744BE9573F2}" = HP Software Update
"{595D0DE8-C38A-4432-B851-47DECC1A99BD}" = HP Unload DLL Patch
"{597D73A8-5FDB-4bc1-9893-40B54459F1BC}" = ProductContext
"{5B39603F-2A77-40E6-950D-ED7B8307933D}" = Microsoft IntelliPoint 5.3
"{80413011-029C-4D6B-B3AD-725DDE60B81C}" = 1310Trb
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{B32C75F2-7495-4D01-9431-C11E97D66F8C}" = DocProc
"{B3D5D4E0-E965-41C4-ABFD-A7B1AD0663C2}" = Director
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2D}" = DocumentViewer
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BF018D2F-C788-4AB1-AB95-1280EAB8F13E}" = TrayApp
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{E21658D0-8C83-4ADD-937B-6ED07F335ABA}" = 1310Tour
"{E90BEB5B-CFA0-418E-9ABB-4C4A7B0D9483}" = 1310_Help
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{F3759A9F-7AFA-4FB4-8DF1-53F26B979DEE}" = Belkin 54Mbps Wireless Network Adapter
"{F4F47155-5B4D-42AA-97F8-490BC52EA7F3}" = Destinations
"{F65787F3-B356-45EC-8DD0-0E6758EDBCEE}" = WebReg
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"avast!" = avast! Antivirus
"CNXT_MODEM_PCI" = SoftV92 Data Fax Modem
"Consumer Input Software" = Consumer Input Software (remove only)
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"ERUNT_is1" = ERUNT 1.1j
"EsetOnlineScanner" = ESET Online Scanner
"getPlus®_ocx" = getPlus®_ocx
"HijackThis" = HijackThis 2.0.2
"HP Photo & Imaging" = HP Image Zone 4.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Lightning Download" = Lightning Download
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"mypoints" = MyPoints Toolbar
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Respondus 3.5 Campus-Wide" = Respondus 3.5 Campus-Wide
"RSEE4" = Respondus Equation Editor 4
"SpywareBlaster_is1" = SpywareBlaster 4.2
"TaxACT 2000" = TaxACT 2000
"TaxACT 2002" = TaxACT 2002
"TaxACT 2003" = TaxACT 2003
"TaxACT 2004" = TaxACT 2004
"TaxACT 2005" = TaxACT 2005
"TaxACT 2006" = TaxACT 2006
"TaxACT 2007" = TaxACT 2007
"TaxACT 2008" = TaxACT 2008
"TaxACT 2008 Illinois" = TaxACT 2008 Illinois
"TaxACT Illinois 2006" = TaxACT Illinois 2006
"TaxACT Illinois 2007" = TaxACT Illinois 2007
"TaxACT Missouri 2006" = TaxACT Missouri 2006
"TZ Connection Booster_is1" = TZ Connection Booster 2.6
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"WinASO Registry Optimizer 3.0.5_is1" = WinASO Registry Optimizer 3.0.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.1.3 final uninstall
"YInstHelper" = Yahoo! Install Manager

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 5/20/2009 11:41:15 PM | Computer Name = SEPRONI-D392BF7 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\SEMPRONI\MY DOCUMENTS\SCHOOL STUFF\SPRING 2008\SWIC IP
SCHEDULE UPDATE - UPDATED FEB 27, 2008.DOC failed, 00000005.

Error - 5/20/2009 11:41:15 PM | Computer Name = SEPRONI-D392BF7 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\SEMPRONI\MY DOCUMENTS\SCHOOL STUFF\SPRING 2008\SWIC IP
SCHEDULE UPDATE - UPDATED MARCH 18 2008.DOC failed, 00000005.

Error - 5/20/2009 11:41:15 PM | Computer Name = SEPRONI-D392BF7 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\SEMPRONI\MY DOCUMENTS\SCHOOL STUFF\SPRING 2008\SWIC PUBLIC
SPEAKING MIDTERM STUDY GUIDE.DOC failed, 00000005.

Error - 5/20/2009 11:41:15 PM | Computer Name = SEPRONI-D392BF7 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\SEMPRONI\MY DOCUMENTS\SCHOOL STUFF\SPRING 2008\TENTATIVE
SCHEDULE SIU IP SPRING 08 IDEAS.DOC failed, 00000005.

Error - 5/20/2009 11:41:15 PM | Computer Name = SEPRONI-D392BF7 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\SEMPRONI\MY DOCUMENTS\SCHOOL STUFF\SPRING 2008\TENTATIVE
SCHEDULE SIU IP SPRING 08.DOC failed, 00000005.

Error - 5/20/2009 11:41:15 PM | Computer Name = SEPRONI-D392BF7 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\SEMPRONI\MY DOCUMENTS\SCHOOL STUFF\SPRING 2008\TEST QUESTIONS.DOC
failed, 00000005.

Error - 5/20/2009 11:41:15 PM | Computer Name = SEPRONI-D392BF7 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\SEMPRONI\MY DOCUMENTS\SCHOOL STUFF\SPRING 2008\TYPES
OF INFORMATIVE SPEECHES.DOC failed, 00000005.

Error - 5/20/2009 11:41:15 PM | Computer Name = SEPRONI-D392BF7 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\SEMPRONI\MY DOCUMENTS\SCHOOL STUFF\SPRING 2008\YAHOO
GROUP INSTRUCTIONS.DOC failed, 00000005.

Error - 5/20/2009 11:41:15 PM | Computer Name = SEPRONI-D392BF7 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\SEMPRONI\MY DOCUMENTS\SCHOOL STUFF\SUMMER 2008\1215 CLASS
SUMMER 2008 ROSTER.DOC failed, 00000005.

Error - 5/25/2009 6:22:35 PM | Computer Name = SEPRONI-D392BF7 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\SEMPRONI\DESKTOP\SOCIAL SECURITY 2008_2\2009\OIG\RESPONSE
BY CLAIMANT TO REPORT OF CONTACT DATED AUGUST 12, 2008_EDIT1.DOC failed, 00000005.


[ Application Events ]
Error - 5/19/2009 10:39:54 AM | Computer Name = SEPRONI-D392BF7 | Source = Windows Search Service | ID = 3038
Description = The gatherer is unable to read the registry DocIdMapFile. Context:
Application, SystemIndex Catalog Details: The system cannot find the file specified.
(0x80070002)

Error - 5/19/2009 10:40:04 AM | Computer Name = SEPRONI-D392BF7 | Source = Windows Search Service | ID = 3028
Description = The gatherer object cannot be initialized. Context: Windows Application,
SystemIndex Catalog Details: The registry value cannot be read because the configuration
is invalid. Recreate the content index configuration by removing the content index.
(0x80040d03)

Error - 5/19/2009 10:40:04 AM | Computer Name = SEPRONI-D392BF7 | Source = Windows Search Service | ID = 3058
Description = The application cannot be initialized. Context: Windows Application

Details:
The
registry value cannot be read because the configuration is invalid. Recreate the
content index configuration by removing the content index. (0x80040d03)

Error - 5/19/2009 12:15:38 PM | Computer Name = SEPRONI-D392BF7 | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog

Error - 5/20/2009 11:28:54 PM | Computer Name = SEPRONI-D392BF7 | Source = Windows Search Service | ID = 3038
Description = The gatherer is unable to read the registry DocIdMapFile. Context:
Application, SystemIndex Catalog Details: The system cannot find the file specified.
(0x80070002)

Error - 5/20/2009 11:28:59 PM | Computer Name = SEPRONI-D392BF7 | Source = Windows Search Service | ID = 3028
Description = The gatherer object cannot be initialized. Context: Windows Application,
SystemIndex Catalog Details: The registry value cannot be read because the configuration
is invalid. Recreate the content index configuration by removing the content index.
(0x80040d03)

Error - 5/20/2009 11:28:59 PM | Computer Name = SEPRONI-D392BF7 | Source = Windows Search Service | ID = 3058
Description = The application cannot be initialized. Context: Windows Application

Details:
The
registry value cannot be read because the configuration is invalid. Recreate the
content index configuration by removing the content index. (0x80040d03)

Error - 5/20/2009 11:37:19 PM | Computer Name = SEPRONI-D392BF7 | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog

Error - 5/21/2009 12:49:46 AM | Computer Name = SEPRONI-D392BF7 | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog

Error - 5/21/2009 6:52:59 AM | Computer Name = SEPRONI-D392BF7 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft Office 2000 Standard - Update '{C7FF6B17-77F5-49FF-AD5F-3B22254BB053}'
could not be installed. Error code 1642. Additional information is available in
the log file C:\DOCUME~1\Semproni\LOCALS~1\Temp\OHotfix\OHotfix(00002)_Msi.log.

[ System Events ]
Error - 5/25/2009 6:14:07 PM | Computer Name = SEPRONI-D392BF7 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 5/25/2009 6:14:07 PM | Computer Name = SEPRONI-D392BF7 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 5/25/2009 6:14:07 PM | Computer Name = SEPRONI-D392BF7 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 5/25/2009 6:14:07 PM | Computer Name = SEPRONI-D392BF7 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 5/25/2009 6:14:07 PM | Computer Name = SEPRONI-D392BF7 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 5/25/2009 6:14:07 PM | Computer Name = SEPRONI-D392BF7 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 5/25/2009 6:14:07 PM | Computer Name = SEPRONI-D392BF7 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%2

Error - 5/25/2009 6:18:54 PM | Computer Name = SEPRONI-D392BF7 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 5/25/2009 6:29:19 PM | Computer Name = SEPRONI-D392BF7 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 5/25/2009 6:36:04 PM | Computer Name = SEPRONI-D392BF7 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058


< End of report >

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:59:37 PM, on 5/25/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: IE to Lightning Helper - {F1FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\Lightning Download\LD_Catch.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-CEC4-75A487FD6484} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1238528926738
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} -
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) -
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 5331 bytes

Thanks!

Free

free_spirit_etc,

I am thinking I may have to reformat. I am willing to if that is what it takes. I am not so much concerned about losing data, as I am about doing it correctly, or my computer not working again.

Could you please clarify which direction you would like to take.
  • Re-format your computer
    or
  • Try and clean your computer

free_spirit_etc,

I am thinking I may have to reformat. I am willing to if that is what it takes. I am not so much concerned about losing data, as I am about doing it correctly, or my computer not working again.

Could you please clarify which direction you would like to take.
  • Re-format your computer
    or
  • Try and clean your computer


At this point I think I would like to try cleaning my computer.

I am willing to try to reformat it if neccessary.

Thanks!

Janet

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI