This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Extreme Slowness

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was recommended to come here by a friend. Any assistance would be greatly appreciated:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:39:37 AM, on 5/9/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE
C:\WINDOWS\system32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Safari\Safari.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo 825] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P22 "EPSON Stylus Photo 825" /O6 "USB001" /M "Stylus Photo 825"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f audio -m logitech -d 10.5.1.2023 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f audio -m logitech -d 10.5.1.2023 (User 'Default user')
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Java Mainframe Display (MFDFTX) - http://web3270.extra.daimlerchrysler.com/w…va/wdmfdftx.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt4_x.cab
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - https://sodddm07.extra.daimlerchrysler.com/iNotes.cab
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://sodddm07.extra.daimlerchrysler.com/iNotes6W.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130572231171
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CBD8B1CB-2F5F-415F-93E8-A297B33DCBB2} (CentrinoCheck Control) - http://entriq.vo.llnwd.net/o1/NBCUniversal…eck_1_0_0_4.cab
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} (MediaControl Class) - http://entriq.vo.llnwd.net/o1/NBCUniversal…0_15_Silent.cab
O16 - DPF: {DE0FB644-C59B-46D1-B650-88BA945BC98F} - http://entriq.vo.llnwd.net/o1/NBCUniversal…sal_1_0_0_3.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

–
End of file - 12451 bytes


Thank you!
Hi Saint Marcos, welcome to the forum.



To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.



Open hijackthis, do a system scan only and checkmark these lines, if present

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.



Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Download OTListIt2 to your desktop.
  • Double click on OTList2.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

No need for a Hijackthis log this time.

Please post back with
  • MBAM log
  • both OTLISIT2 logs
Please describe the symptoms you are experiencing.

Thanks
Yes, thanks – Just needed time to be able to run the scans.

MBAM Log:

Malwarebytes' Anti-Malware 1.36
Database version: 2141
Windows 5.1.2600 Service Pack 3

5/16/2009 11:10:06 AM
mbam-log-2009-05-16 (11-10-06).txt

Scan type: Quick Scan
Objects scanned: 108082
Time elapsed: 14 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 10

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\mysearchtoolbar.settingsplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mysearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{014da6cb-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\My Search Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MySearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\m.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\p.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\q.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\x.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\y.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\a.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Karla\Favorites\adult sites\Hardcore\yvon's training.lnk (Adware.SurfAssistant) -> Quarantined and deleted successfully.
C:\WINDOWS\system.exe (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM\system.exe (Trojan.Banker) -> Quarantined and deleted successfully.
C:\WINDOWS\smdat32a.sys (Rootkit.Agent) -> Quarantined and deleted successfully.


OT Logs:

OTListIt Extras logfile created on: 5/16/2009 12:09:01 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Darrin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.98 Mb Total Physical Memory | 222.53 Mb Available Physical Memory | 43.55% Memory free
1.22 Gb Paging File | 0.92 Gb Available in Paging File | 75.39% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.83 Gb Total Space | 15.01 Gb Free Space | 26.88% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HARRIS
Current User Name: Darrin
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = YBrowser.HTML] – C:\Program Files\Yahoo!\browser\YBrowser.exe (Yahoo!, Inc.)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1723:TCP" = 1723:TCP:*:Enabled:@xpsp2res.dll,-22015
"1701:UDP" = 1701:UDP:*:Enabled:@xpsp2res.dll,-22016
"500:UDP" = 500:UDP:*:Enabled:@xpsp2res.dll,-22017

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1723:TCP" = 1723:TCP:*:Enabled:@xpsp2res.dll,-22015
"1701:UDP" = 1701:UDP:*:Enabled:@xpsp2res.dll,-22016
"500:UDP" = 500:UDP:*:Enabled:@xpsp2res.dll,-22017

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 6.2 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 6.2 (Microsoft Corporation)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{00718491-55BF-46C6-83EF-4B3B95AC807A}" = SplitCam
"{015E4B8A-29B5-4AE3-BD08-38220FADFF4C}" = aspi
"{01A4AEDE-F219-49A2-B855-16A016EAF9A4}" = Intel® PROSet II
"{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
"{06E76F86-A913-4FCE-9B0E-1D4AD820368F}" = Disney Mix Stick
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{10E98E14-832C-4AF7-A4D1-6A9EF83B282E}" = VCAMCEN
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert
"{154508C0-07C5-4659-A7A0-E49968750D21}" = HLPPDOCK
"{184EB198-1DBA-46DB-B728-7A5FC13D5C2B}_is1" = Yahoo! Photos Print-at-Home Tool
"{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2604C0F9-BFD3-4BA0-9EB5-22537C648F03}" = MobileMe Control Panel
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{29D88826-2AB9-11D5-8854-00902761A46D}" = WordPerfect Office 2002
"{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}" = EXEtender Player
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{3347CE04-1F9A-4DD9-BF65-0C6766DD9313}" = DynaComm i:scan
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{44A537A5-859C-43A6-8285-C0668142A090}" = iPod for Windows 2005-03-23
"{45893FEB-30FD-4034-8661-3BA4238FE67A}" = Britannica Ready Reference
"{469730CC-78DF-4CD3-B286-562D459EA619}" = ESSCAM
"{48C82F7A-F100-4DAB-A310-8E18BF2159E1}" = ESSvpot
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{55BC7EFA-D832-4EE3-9DEA-49B0C07539D9}" =
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = MouseWare 9.41 .3
"{5E835305-63BB-4E55-BBB7-EEBBE67774DB}" = MyDVD
"{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
"{64116298-93C5-401D-B06C-39D8E3338508}" = DAO
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{669571CD-CED0-4F86-B769-F3980F167FA5}" = OnWeb Web-to-Host Java MS Crypto Native Support
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69BD6399-3D8F-45B7-81D9-819361F5101D}" = PCDLNCH
"{78F79C84-BFD5-4D79-A07D-F39A3CF428DC}" = HLPIndex
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}" = ESSCT
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}" = Musicmatch® Jukebox
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}" = Logitech QuickCam
"{96850EA1-87F2-4C21-A341-A32C3FD8C936}" = DCX: AT&T Dialer 5.08.1
"{96E16100-A77F-4B31-B9AD-FFBA040EE1BD}" = Sound Blaster Live!
"{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}" = Apple Mobile Device Support
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9D1CF8B6-17B3-4832-B062-2C2DD0B57B04}" = CCHelp
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{9D98F245-3010-43C6-B3B0-67A464DA298E}" = ELNKInst
"{A0AF08BA-3630-4505-BFB2-A41F3837B0D0}" = SFR2
"{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}" = ESSvpaht
"{A6F18A67-B771-4191-8A33-36D2E742D6D9}" = ESSANUP
"{ABEB838C-A1A7-4C5D-B7E1-8B4314600137}" = MSN Messenger 6.2
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{C354C9B6-A4E0-4BB0-A368-6DC6BCA0E314}" = SFR
"{C9D96682-5A4D-45FA-BA3E-DDCB2B0CB868}" = Safari
"{CA60320D-6A16-49C8-A34F-84EEF4799567}" = ESSTUTOR
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D15E9DB5-6BEB-4534-901E-80C0A29BAB97}" = ESSAdpt
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D4936AAF-FFD0-44A1-A7EA-A2DB41CEB5BC}" = iPod for Windows 2005-09-23
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{DCDC8E79-4600-4C02-9824-CD3BB8971D4E}" =
"{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}" = iTunes
"{E09A3F86-62CA-4B23-8F73-4521F0349F36}" = MovieScheduler
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
"{F2D0C1B1-80FF-46F9-BA61-33B01A07FAFC}" = HLPCCTR
"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"7-Zip" = 7-Zip 4.57
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"AT&T Global Network Client {C:,PROGRA~1,AT&TGL~1,}" = AT&T Global Network Client
"ATI Display Driver" = ATI Display Driver
"Audacity_is1" = Audacity 1.2.6
"AVG7Uninstall" = AVG Free Edition
"AVGAntiSpyware75" = AVG Anti-Spyware 7.5
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"BroadJump Client Foundation" = BroadJump Client Foundation
"BroadJump CorrectConnect Engine" = BroadJump CorrectConnect Engine
"Canon PhotoStitch 3.1" = Canon Utilities PhotoStitch 3.1
"CCleaner" = CCleaner (remove only)
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Entriq MediaSphere_is1" = Entriq MediaSphere [removed]
"EPSON Printer and Utilities" = EPSON Printer Software
"exPressit S.E. 2.1" = exPressit S.E. 2.1
"GMAT POWERPREP" = GMAT POWERPREP
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"InstallShield_{44A537A5-859C-43A6-8285-C0668142A090}" = iPod for Windows 2005-03-23
"InstallShield_{9D98F245-3010-43C6-B3B0-67A464DA298E}" = Earthlink Installer - uninstall 'Earthlink 5.0' entry first if present
"InstallShield_{D4936AAF-FFD0-44A1-A7EA-A2DB41CEB5BC}" = iPod for Windows 2005-09-23
"legacyqcam_10.51" = Logitech Legacy USB Camera Driver Package
"LimeWire" = LimeWire 4.16.6
"lvdrivers_11.50" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Missing" = Missing
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Orb" = Orb
"PalTalk8.2" = PaltalkScene
"Panda ActiveScan" = Panda ActiveScan
"PhotoRecord" = Canon PhotoRecord
"PROSet" = Intel® PRO Ethernet Adapter and Software
"Quicken 2002 Deluxe" = Quicken 2002 Deluxe
"RealPlayer 6.0" = RealPlayer
"SBC Connection Manager" = SBC Connection Manager
"SBC Yahoo! DSL Activation" = SBC Yahoo! DSL Activation
"Scrabble" = Scrabble
"Shockwave" = Shockwave
"Silent Package Run-Time Sample" = EPSON Online Reference Guide
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.2
"Sqwire" = Web Helper
"Starcraft" = Starcraft
"StreetPlugin" = Learn2 Player (Uninstall Only)
"System Tweaker_is1" = Uniblue System Tweaker
"The Omega Stone" = The Omega Stone (remove only)
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"Washington State University Alumni Directory" = Washington State University Alumni Directory
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WordPerfect Office 2002" = WordPerfect Office 2002
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Applications" = AT&T Yahoo! Applications
"Yahoo! Photos Easy Upload Tool" = Yahoo! Photos Easy Upload Tool
"Yahoo! SiteBuilder" = Yahoo! SiteBuilder
"Yahoo! Toolbar" = Yahoo! Toolbar
"Zarinmedia's Quick JPG2SWF_is1" = Quick JPG2SWF v 0.2
"ZoomBrowserEXDeInstall" = Canon Utilities ZoomBrowser EX

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Yahoo! SiteBuilder" = Yahoo! SiteBuilder

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/24/2008 8:36:43 AM | Computer Name = HARRIS | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 7.0.8.218, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/7/2009 8:15:29 PM | Computer Name = HARRIS | Source = Application Hang | ID = 1002
Description = Hanging application Safari.exe, version 3.525.21.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/2/2009 12:02:24 AM | Computer Name = HARRIS | Source = Application Error | ID = 1000
Description = Faulting application itouch.exe, version 1.82.0.0, faulting module
itouch.exe, version 1.82.0.0, fault address 0x00011720.

Error - 4/20/2009 11:06:51 PM | Computer Name = HARRIS | Source = Application Hang | ID = 1002
Description = Hanging application yum.exe, version 2003.11.10.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 4/20/2009 11:07:10 PM | Computer Name = HARRIS | Source = Application Hang | ID = 1002
Description = Hanging application YBrowser.exe, version 2006.8.11.1, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/21/2009 7:20:13 AM | Computer Name = HARRIS | Source = Application Error | ID = 1000
Description = Faulting application itouch.exe, version 1.82.0.0, faulting module
itouch.exe, version 1.82.0.0, fault address 0x00011720.

Error - 5/2/2009 5:59:24 PM | Computer Name = HARRIS | Source = Application Hang | ID = 1002
Description = Hanging application YBrowser.exe, version 2006.8.11.1, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/9/2009 9:46:12 AM | Computer Name = HARRIS | Source = Application Hang | ID = 1002
Description = Hanging application r1puninst.exe, version 7.0.0.3996, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/9/2009 9:46:19 AM | Computer Name = HARRIS | Source = Application Hang | ID = 1002
Description = Hanging application setup.exe, version 7.5.0.510, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 5/10/2009 6:41:46 PM | Computer Name = HARRIS | Source = Application Error | ID = 1000
Description = Faulting application safari.exe, version 3.525.21.0, faulting module
webkit.dll, version 3.525.19.0, fault address 0x000e7167.

[ System Events ]
Error - 5/10/2009 5:21:05 PM | Computer Name = HARRIS | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{BB922996-EE6B-478E-B4CD-67D19F2565C8}
because another computer on the network has the same name. The server could not
start.

Error - 5/10/2009 5:21:05 PM | Computer Name = HARRIS | Source = Service Control Manager | ID = 7000
Description = The Ati HotKey Poller service failed to start due to the following
error: %%2

Error - 5/16/2009 10:23:47 AM | Computer Name = HARRIS | Source = NetBT | ID = 4321
Description = The name "HARRIS :0" could not be registered on the Interface
with IP address 192.168.0.106. The machine with the IP address 192.168.0.100 did
not allow the name to be claimed by this machine.

Error - 5/16/2009 10:23:50 AM | Computer Name = HARRIS | Source = NetBT | ID = 4321
Description = The name "HARRIS :20" could not be registered on the Interface
with IP address 192.168.0.106. The machine with the IP address 192.168.0.100 did
not allow the name to be claimed by this machine.

Error - 5/16/2009 10:23:50 AM | Computer Name = HARRIS | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{BB922996-EE6B-478E-B4CD-67D19F2565C8}
because another computer on the network has the same name. The server could not
start.

Error - 5/16/2009 10:23:50 AM | Computer Name = HARRIS | Source = Service Control Manager | ID = 7000
Description = The Ati HotKey Poller service failed to start due to the following
error: %%2

Error - 5/16/2009 11:12:27 AM | Computer Name = HARRIS | Source = NetBT | ID = 4321
Description = The name "HARRIS :0" could not be registered on the Interface
with IP address 192.168.0.106. The machine with the IP address 192.168.0.100 did
not allow the name to be claimed by this machine.

Error - 5/16/2009 11:12:30 AM | Computer Name = HARRIS | Source = Service Control Manager | ID = 7000
Description = The Ati HotKey Poller service failed to start due to the following
error: %%2

Error - 5/16/2009 11:12:30 AM | Computer Name = HARRIS | Source = NetBT | ID = 4321
Description = The name "HARRIS :20" could not be registered on the Interface
with IP address 192.168.0.106. The machine with the IP address 192.168.0.100 did
not allow the name to be claimed by this machine.

Error - 5/16/2009 11:12:30 AM | Computer Name = HARRIS | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{BB922996-EE6B-478E-B4CD-67D19F2565C8}
because another computer on the network has the same name. The server could not
start.


< End of report >

OTListIt logfile created on: 5/16/2009 12:09:01 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Darrin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.98 Mb Total Physical Memory | 222.53 Mb Available Physical Memory | 43.55% Memory free
1.22 Gb Paging File | 0.92 Gb Available in Paging File | 75.39% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.83 Gb Total Space | 15.01 Gb Free Space | 26.88% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HARRIS
Current User Name: Darrin
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Grisoft\AVG Free\avgamsvr.exe (GRISOFT, s.r.o.)
PRC - C:\Program Files\Grisoft\AVG Free\avgupsvc.exe (GRISOFT, s.r.o.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\System32\CTsvcCDA.exe (Creative Technology Ltd)
PRC - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\system32\drivers\KodakCCS.exe (Eastman Kodak Company)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\AT&T Global Network Client\NetCfgSv.EXE (AT&T)
PRC - C:\WINDOWS\system32\ScsiAccess.EXE ()
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\System32\MsPMSPSv.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\BCMSMMSG.exe (Broadcom Corporation)
PRC - C:\Program Files\MouseWare\system\EM_EXEC.EXE (Logitech Inc. )
PRC - C:\WINDOWS\System32\DSentry.exe (Dell - Advanced Desktop Engineering)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Grisoft\AVG Free\avgcc.exe (GRISOFT, s.r.o.)
PRC - C:\Program Files\Grisoft\AVG Free\avgemc.exe (GRISOFT, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\cidaemon.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\browser\ycommon.exe (Yahoo!, Inc.)
PRC - C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
PRC - C:\Documents and Settings\Darrin\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Ati HotKey Poller [Auto | Stopped]) – File not found
SRV - (AVG Anti-Spyware Guard [On_Demand | Stopped]) – C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (Anti-Malware Development a.s.)
SRV - (Avg7Alrt [Auto | Running]) – C:\Program Files\Grisoft\AVG Free\avgamsvr.exe (GRISOFT, s.r.o.)
SRV - (Avg7UpdSvc [Auto | Running]) – C:\Program Files\Grisoft\AVG Free\avgupsvc.exe (GRISOFT, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (Creative Service for CDROM Access [Auto | Running]) – C:\WINDOWS\System32\CTsvcCDA.exe (Creative Technology Ltd)
SRV - (DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (EPSONStatusAgent2 [Auto | Running]) – C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KodakCCS [Auto | Running]) – C:\WINDOWS\system32\drivers\KodakCCS.exe (Eastman Kodak Company)
SRV - (LVCOMSer [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (LVPrcSrv [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVSrvLauncher [Auto | Stopped]) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (NetCfgSvr [Auto | Running]) – C:\Program Files\AT&T Global Network Client\NetCfgSv.EXE (AT&T)
SRV - (NMSSvc [On_Demand | Stopped]) – C:\WINDOWS\System32\NMSSvc.exe (Intel Corporation)
SRV - (ScsiAccess [Auto | Running]) – C:\WINDOWS\system32\ScsiAccess.EXE ()
SRV - (Viewpoint Manager Service [Auto | Running]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WMDM PMSP Service [Auto | Running]) – C:\WINDOWS\System32\MsPMSPSv.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (YPCService [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\YPcservice.exe (Yahoo! Inc.)

========== Driver Services (SafeList) ==========

DRV - (ABVPN2K [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\abvpn2k.sys (AT&T)
DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AVG Anti-Spyware Driver [System | Running]) – C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ()
DRV - (Avg7Core [System | Running]) – C:\WINDOWS\System32\Drivers\avg7core.sys (GRISOFT, s.r.o.)
DRV - (Avg7RsW [System | Running]) – C:\WINDOWS\System32\Drivers\avg7rsw.sys (GRISOFT, s.r.o.)
DRV - (Avg7RsXP [System | Running]) – C:\WINDOWS\System32\Drivers\avg7rsxp.sys (GRISOFT, s.r.o.)
DRV - (AvgAsCln [System | Running]) – C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys (GRISOFT, s.r.o.)
DRV - (AvgClean [System | Running]) – C:\WINDOWS\system32\drivers\avgclean.sys (GRISOFT, s.r.o.)
DRV - (AvgTdi [Auto | Running]) – C:\WINDOWS\System32\Drivers\avgtdi.sys (GRISOFT, s.r.o.)
DRV - (avpnnic [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\avpnnic.sys (AT&T)
DRV - (BCMModem [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (Cdr4_xp [System | Running]) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Roxio)
DRV - (Cdralw2k [System | Running]) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Roxio)
DRV - (cdudf_xp [System | Running]) – C:\WINDOWS\System32\drivers\cdudf_xp.sys (Roxio)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (ctsfm2k [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DcCam [System | Running]) – C:\WINDOWS\system32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (DcFpoint [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (DCFS2K [Auto | Running]) – C:\WINDOWS\system32\drivers\dcfs2k.sys (Eastman Kodak Company)
DRV - (DcLps [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DcPTP [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\DcPTP.sys (Eastman Kodak Company)
DRV - (DSproct [On_Demand | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (dvd_2K [On_Demand | Running]) – C:\WINDOWS\System32\drivers\Dvd_2k.sys (Roxio)
DRV - (E100B [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (EL90XBC [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\el90xbc5.sys (3Com Corporation)
DRV - (Exportit [System | Stopped]) – C:\WINDOWS\system32\DRIVERS\exportit.sys (Eastman Kodak Company)
DRV - (FilterService [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys (Logitech Inc.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (i81x [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV01nt.sys (Intel® Corporation)
DRV - (iAimFP1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV02NT.sys (Intel® Corporation)
DRV - (iAimFP2 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV05NT.sys (Intel® Corporation)
DRV - (iAimFP3 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys (Intel® Corporation)
DRV - (iAimFP4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys (Intel® Corporation)
DRV - (iAimTV0 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV01nt.sys (Intel® Corporation)
DRV - (iAimTV1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV02NT.sys (Intel® Corporation)
DRV - (iAimTV3 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV04nt.sys (Intel® Corporation)
DRV - (iAimTV4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys (Intel® Corporation)
DRV - (itchfltr [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\itchfltr.sys (Logitech Inc. )
DRV - (l8042pr2 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\L8042Pr2.sys (Logitech)
DRV - (LCcFltr [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\LCcFltr.Sys (Logitech)
DRV - (LHidFlt2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\LHidFlt2.sys (Logitech)
DRV - (LHidUsb [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\LHidUsb.Sys (Logitech)
DRV - (LKbdFlt2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\LKbdFlt2.sys (Logitech)
DRV - (LMouFlt2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\LMouFlt2.sys (Logitech)
DRV - (Lvckap [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LVcKap.sys (Logitech Inc.)
DRV - (lvmvdrv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys (Logitech Inc.)
DRV - (lvpopflt [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\lvpopflt.sys (Logitech Inc.)
DRV - (LVPr2Mon [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVPrcMon [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\LVPrcMon.sys ()
DRV - (LVUSBSta [On_Demand | Running]) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVUVC [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\lvuvc.sys (Logitech Inc.)
DRV - (MCSTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\mcstrm.sys (RealNetworks, Inc.)
DRV - (mmc_2K [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\Mmc_2k.sys (Roxio)
DRV - (MODEMCSA [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (NMSCFG [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\NMSCFG.SYS (Intel Corporation)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\System32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (ossrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (P16X [On_Demand | Running]) – C:\WINDOWS\system32\drivers\P16X.sys (Creative Technology Ltd.)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (PfModNT [Auto | Running]) – C:\WINDOWS\System32\PfModNT.sys (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (pwd_2k [System | Running]) – C:\WINDOWS\System32\drivers\pwd_2K.sys (Roxio)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ROOTMODEM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (SASDIFSV [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Running]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (SuperAdBlocker, Inc.)
DRV - (SASKUTIL [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (SPLITCAM [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\splitcam.sys (LoteSoft Co.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (UdfReadr_xp [System | Running]) – C:\WINDOWS\System32\drivers\udfreadr_xp.sys (Roxio)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (usbaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (X4HS16 [Auto | Running]) – C:\Program Files\games\EXEtender\X4HS16.Sys (Exent Technologies Ltd.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…/search/ie.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page_bak = http://rd.yahoo.com/customize/sbcydsl/defa…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_bak = http://yahoo.sbc.com/dsl
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant_bak = http://www.couldnotfind.com/search_page.ht…count_id=132986
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = http://localhost;*.local

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/02/02 21:43:59 | 00,000,000 | —D | M]


O1 HOSTS File: (21 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SidebarAutoLaunch Class) - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [ATIModeChange] Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP (GRISOFT, s.r.o.)
O4 - HKLM..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe (GRISOFT, s.r.o.)
O4 - HKLM..\Run: [BCMSMMSG] BCMSMMSG.exe (Broadcom Corporation)
O4 - HKLM..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe (Dell - Advanced Desktop Engineering)
O4 - HKLM..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE (Logitech Inc. )
O4 - HKLM..\Run: [EPSON Stylus Photo 825] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P22 "EPSON Stylus Photo 825" /O6 "USB001" /M "Stylus Photo 825" (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc. )
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKLM..\RunOnceEx: [] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html File not found
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html File not found
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html File not found
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html File not found
O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (AVM Software Inc.)
O9 - Extra Button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} https://sodddm07.extra.daimlerchrysler.com/iNotes.cab (iNotes Class)
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} C:\Program Files\Yahoo!\common\yucconfig.dll (yucsetreg Class)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll (Installation Support)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} https://sodddm07.extra.daimlerchrysler.com/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} http://aolcc.aol.com/computercheckup/qdiagcc.cab (QDiagAOLCCUpdateObj Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1130572231171 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoftware.com/activescan/as5free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {9CF28A69-7659-4C51-BFD5-9ADE19E19EC3} http://download.yahoo.com/dl/installs/bkm/prod/yregcfg.cab (RegConfig Class)
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} http://download.yahoo.com/dl/installs/ymail/ymmapi.dll (YahooYMailTo Class)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://download.yahoo.com/dl/mail/ac4sbc.cab (YAddBook Class)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CBD8B1CB-2F5F-415F-93E8-A297B33DCBB2} http://entriq.vo.llnwd.net/o1/NBCUniversal…eck_1_0_0_4.cab (CentrinoCheck Control)
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} http://entriq.vo.llnwd.net/o1/NBCUniversal…0_15_Silent.cab (MediaControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DE0FB644-C59B-46D1-B650-88BA945BC98F} http://entriq.vo.llnwd.net/o1/NBCUniversal…sal_1_0_0_3.cab (Reg Error: Key error.)
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} http://officeupdate.microsoft.com/Template…nloads/outc.cab (Microsoft Office Tools on the Web Control)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://download.games.yahoo.com/games/web_…aploader_v6.cab (PopCapLoader Object)
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} https://sodddm07.extra.chrysler.com/dwa7W.cab (Domino Web Access 7 Control)
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab (Quantum Streaming IE Player Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Java Mainframe Display (MFDFTX) http://web3270.extra.daimlerchrysler.com/w…va/wdmfdftx.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java (Reg Error: Key error.)
O16 - DPF: Yahoo! Literati http://download.games.yahoo.com/games/clients/y/tt4_x.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {57B86673-276A-48B2-BAE7-C6DBB3020EB8} - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll (Anti-Malware Development a.s.)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{b25e89e2-e0fa-11d9-bcb0-00038a000015}\Shell\AutoRun\command - "" = G:\setupSNK.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/05/16 12:07:37 | 00,000,000 | R–D | M]

========== Files/Folders - Created Within 30 Days ==========

[9 C:\WINDOWS\System32\*.tmp files]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files]
[2009/05/16 12:07:35 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Darrin\Desktop\OTListIt2.exe
[2009/05/16 10:53:02 | 00,000,000 | —D | C] – C:\Documents and Settings\Darrin\Application Data\Malwarebytes
[2009/05/16 10:52:58 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/16 10:52:58 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/16 10:52:56 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/16 10:52:54 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/16 10:52:54 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/05/16 10:52:07 | 02,967,800 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Darrin\Desktop\mbam-setup.exe
[2009/05/10 19:04:12 | 00,058,368 | —- | C] () – C:\Documents and Settings\Darrin\Desktop\Resumebm.doc
[2009/05/09 09:39:19 | 00,001,734 | —- | C] () – C:\Documents and Settings\Darrin\Desktop\HijackThis.lnk
[2009/05/09 09:39:19 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/29 03:02:09 | 00,000,260 | —- | C] () – C:\WINDOWS\tasks\WGASetup.job
[2009/04/29 03:02:08 | 00,000,000 | —D | C] – C:\WINDOWS\System32\KB905474
[2009/04/20 23:13:16 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/20 23:13:16 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp4res.dll
[2009/04/20 23:13:15 | 01,203,922 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2008/04/07 20:15:49 | 00,039,936 | —- | C] () – C:\WINDOWS\System32\P16X.dll
[2008/04/07 20:15:47 | 00,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[2008/04/07 20:15:44 | 00,005,917 | —- | C] () – C:\WINDOWS\SBMIXDEF.INI
[2008/04/07 20:15:43 | 00,006,175 | —- | C] () – C:\WINDOWS\MIXDEF.INI
[2007/10/11 18:59:24 | 00,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/04/08 08:28:37 | 00,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2006/06/13 03:39:33 | 00,000,719 | R— | C] () – C:\WINDOWS\System32\InstExec.ini
[2006/06/13 03:39:16 | 00,050,127 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2006/05/22 17:19:51 | 00,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2006/05/22 17:19:51 | 00,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2006/05/22 17:19:51 | 00,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2005/12/09 18:37:42 | 00,016,768 | —- | C] () – C:\WINDOWS\System32\drivers\LVPrcMon.sys
[2005/08/06 14:19:51 | 00,010,009 | —- | C] () – C:\WINDOWS\agnslang.ini
[2004/12/27 02:30:34 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2004/11/07 18:58:03 | 00,000,055 | —- | C] () – C:\WINDOWS\OSA.INI
[2004/07/31 01:52:51 | 00,000,000 | —- | C] () – C:\WINDOWS\LHK04.INI
[2004/05/23 01:40:21 | 00,000,000 | RHS- | C] () – C:\WINDOWS\System32\system32.dll
[2004/05/21 23:06:48 | 00,000,000 | RHS- | C] () – C:\WINDOWS\System32\d2kpax.dll
[2004/05/21 23:06:47 | 00,000,000 | RHS- | C] () – C:\WINDOWS\System32\msxslab.dll
[2004/05/21 23:06:47 | 00,000,000 | RHS- | C] () – C:\WINDOWS\System32\jac.dll
[2004/05/21 23:06:47 | 00,000,000 | RHS- | C] () – C:\WINDOWS\System32\bridge.dll
[2004/03/18 03:04:18 | 00,100,352 | —- | C] () – C:\WINDOWS\System32\pg32conv.dll
[2004/03/06 14:47:01 | 00,000,060 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/02/18 10:06:33 | 00,000,399 | —- | C] () – C:\WINDOWS\Belt.ini
[2003/12/18 01:43:05 | 00,229,793 | —- | C] () – C:\WINDOWS\bi.ini
[2003/12/04 02:26:45 | 00,000,004 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/11/27 23:50:30 | 00,007,836 | —- | C] () – C:\WINDOWS\wsme.ini
[2003/11/22 00:50:20 | 00,008,189 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/09/13 01:02:22 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2003/09/06 23:37:14 | 00,000,043 | —- | C] () – C:\WINDOWS\INTUIT.INI
[2003/08/31 01:22:59 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/08/24 20:32:47 | 00,000,026 | —- | C] () – C:\WINDOWS\UP9ASP.INI
[2003/07/14 15:30:28 | 00,197,120 | —- | C] () – C:\WINDOWS\patchw32.dll
[2003/06/26 07:00:38 | 00,006,510 | —- | C] () – C:\WINDOWS\System32\DAntivirus.ini
[2003/06/02 22:12:04 | 00,000,506 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/05/20 23:21:16 | 00,000,000 | —- | C] () – C:\WINDOWS\OPPRIN~1.INI
[2003/05/11 14:25:14 | 00,000,028 | —- | C] () – C:\WINDOWS\ICOA.INI
[2003/05/11 14:25:06 | 00,000,000 | —- | C] () – C:\WINDOWS\QFN.ini
[2003/05/11 14:25:06 | 00,000,000 | —- | C] () – C:\WINDOWS\QDQICK.ini
[2003/05/10 18:16:31 | 00,000,045 | —- | C] () – C:\WINDOWS\EPSP825.ini
[2003/04/29 13:59:35 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/04/29 13:47:43 | 00,001,234 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/04/29 13:47:43 | 00,001,105 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/04/29 13:44:50 | 00,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2003/04/29 13:44:38 | 00,002,092 | —- | C] () – C:\WINDOWS\System32\P16X.ini
[2003/04/29 13:44:38 | 00,000,026 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2003/04/29 13:44:37 | 00,000,064 | —- | C] () – C:\WINDOWS\P16x.ini
[2003/04/29 13:44:13 | 00,000,245 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2003/04/29 13:42:13 | 00,109,056 | —- | C] () – C:\WINDOWS\System32\LGUICOM.DLL
[2003/04/29 13:42:13 | 00,000,443 | —- | C] () – C:\WINDOWS\Cmousecc.ini
[2003/04/29 13:40:28 | 00,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/04/29 13:17:34 | 00,000,547 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/03/27 10:28:44 | 00,004,955 | —- | C] () – C:\WINDOWS\System32\DProg.ini
[2002/09/03 14:36:02 | 00,000,715 | —- | C] () – C:\WINDOWS\WIN.INI
[2002/09/03 14:26:32 | 00,000,231 | —- | C] () – C:\WINDOWS\SYSTEM.INI
[2002/08/29 06:00:00 | 00,056,880 | —- | C] () – C:\WINDOWS\System32\scvideo.dll
[2002/02/06 10:04:14 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\NMSInst.dll
[2002/01/21 15:17:18 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PROInst.dll
[2001/07/20 08:09:58 | 00,196,608 | —- | C] () – C:\WINDOWS\System32\swfobjs.dll
[2000/09/08 19:53:50 | 00,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll

========== Files - Modified Within 30 Days ==========

[9 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files]
[2009/05/16 12:07:37 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Darrin\Desktop\OTListIt2.exe
[2009/05/16 12:04:50 | 00,000,260 | —- | M] () – C:\WINDOWS\tasks\WGASetup.job
[2009/05/16 11:13:56 | 00,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2009/05/16 11:13:54 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Darrin\Local Settings\DESKTOP.INI
[2009/05/16 11:12:26 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/16 11:12:23 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/05/16 11:12:19 | 53,587,1488 | -HS- | M] () – C:\hiberfil.sys
[2009/05/16 11:12:14 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2009/05/16 10:52:58 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/16 10:52:07 | 02,967,800 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Darrin\Desktop\mbam-setup.exe
[2009/05/12 23:21:19 | 00,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/05/10 19:46:39 | 00,058,368 | —- | M] () – C:\Documents and Settings\Darrin\Desktop\Resumebm.doc
[2009/05/10 18:34:03 | 00,002,187 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2009/05/09 09:39:20 | 00,001,734 | —- | M] () – C:\Documents and Settings\Darrin\Desktop\HijackThis.lnk
[2009/05/07 03:16:29 | 24,699,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/05/06 21:16:58 | 00,001,234 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009/05/02 12:53:04 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/21 07:20:59 | 00,363,734 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2009/04/21 07:20:58 | 00,045,408 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2009/04/21 07:20:57 | 00,414,482 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/20 23:36:13 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK

========== LOP Check ==========

[1 C:\Documents and Settings\All Users\Application Data\*.tmp files]
[2009/05/16 10:52:54 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/10/19 10:22:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/06/15 11:53:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/05/23 12:13:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2003/08/24 20:35:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2007/09/09 22:50:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/10/15 13:17:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/05/09 09:43:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG7
[2008/10/14 22:22:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Blizzard
[2003/04/29 13:44:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Creative
[2005/05/22 11:16:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2004/12/04 02:02:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2005/05/21 23:11:54 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2004/11/03 12:46:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kodak
[2008/04/07 07:49:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logishrd
[2007/04/08 09:18:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logitech
[2009/05/16 10:52:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/04/04 20:46:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/01/07 20:52:44 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/10/15 14:44:34 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Move Networks
[2004/08/20 22:14:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.2.0137
[2003/05/09 17:13:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2007/08/13 07:54:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2008/02/25 00:13:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OrbNetworks
[2006/11/27 00:31:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2005/02/12 01:02:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2003/04/29 13:48:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2003/04/29 13:41:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2004/03/30 03:20:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2007/04/08 00:16:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2003/09/13 01:04:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Support.com
[2006/11/27 00:30:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2006/10/14 17:43:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/06/11 21:08:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/08/12 01:19:57 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2006/12/25 01:17:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/05/16 10:53:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data
[2008/09/06 23:16:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Adobe
[2008/06/15 11:50:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\AdobeUM
[2008/03/30 12:08:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Apple Computer
[2008/03/23 00:41:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\AVG7
[2004/08/16 14:37:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\btur
[2003/05/09 16:06:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Corel
[2004/04/14 23:57:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\CyberLink
[2008/05/27 00:55:17 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Darrin\Application Data\GTek
[2003/05/11 14:11:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Help
[2003/04/29 13:15:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Identities
[2003/11/02 18:17:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Leadertech
[2004/03/24 21:00:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Lycos
[2003/09/14 02:40:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Macromedia
[2009/05/16 10:53:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Malwarebytes
[2008/04/03 00:04:00 | 00,000,000 | –SD | M] – C:\Documents and Settings\Darrin\Application Data\Microsoft
[2004/09/12 19:50:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\MSN6
[2005/07/06 23:10:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Musicmatch
[2003/08/31 08:11:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\NetManage
[2007/06/19 21:34:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Paltalk
[2006/11/27 00:31:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\PlayFirst
[2005/06/20 23:51:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Real
[2005/06/19 16:40:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Roxio
[2008/03/19 00:45:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\SBC Yahoo! Messenger
[2006/01/05 01:47:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Sun
[2007/04/08 00:16:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\SUPERAntiSpyware.com
[2008/04/02 23:52:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\System Tweaker
[2008/04/02 23:44:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Uniblue
[2007/03/28 01:05:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Darrin\Application Data\Yahoo!
[2009/05/02 12:53:04 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 06:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\DESKTOP.INI
[2009/05/16 11:12:26 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/05/16 12:04:50 | 00,000,260 | —- | M] () – C:\WINDOWS\Tasks\WGASetup.job

========== Purity Check ==========

< End of report >


Its currently running browser applications faster, but for various other software (MS Office applications, iTunes etc.) it seems to still be a little slow (though still noticeably faster).

Thanks again!
–SM
Hi Saint Marcos,

One or more infections have been identified as being a password stealer and having bakdoor capabilities.

I strongly suggest you do the following immediately:
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

Next, Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:OTLI
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/.../search/ie.html
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html File not found
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html File not found
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html File not found
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html File not found
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html File not found

:Services
lvuvc

:Reg

:Files
C:\WINDOWS\System32\drivers\lvuvc.hs
C:\WINDOWS\imsins.BAK

:Commands
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.

We go deeper

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • OTLISTIT2 log
  • combofix log
  • new HJT log taken after all other steps

How's the computer?

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI