This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Common Folder Opens with Helper.sig file on startup

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I hope someone can help me. When I startup my laptop a Common Folder opens automatically with a helper.sig file in it. I don't know why this is happening or what caused it. I am running Windows XP and am also using Avast anti-virus and Threatfire for malware detection. Neither program identifies any problems. I also have my Firewall on. Thanks for your help!
Hi tiredofcomputers , welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Please post back with
  • both DDS logs

Thanks
Thanks for your response, I downloaded the DDS, but never got a prompt to click YES for Optimal Scan. It did give me two logs. Here is the DDS.txt log and I attached the other as a zip file as that's what the instructions said to do. DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 17:01:49.17 on Sun 08/02/2009 Internet Explorer: 6.0.2900.5512 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.526 [GMT -4:00] AV: avast! antivirus 4.8.1335 [VPS 090801-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Battery Meter\BTMeter.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Wireless Select Switch\WLSS.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\ThreatFire\TFTray.exe C:\WINDOWS\system32\Grxp4exe.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Dropbox\Dropbox.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\ThreatFire\TFService.exe C:\WINDOWS\system32\wdfmgr.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\alg.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe C:\Documents and Settings\Emily\Desktop\dds.scr C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3081224 mStart Page = hxxp://www.dell.com mSearch Bar = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3081224 uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101804&gct=&gc=1&q=%s uURLSearchHooks: DefaultSearchHook Class: {c94e154b-1459-4a47-966b-4b843befc7db} - c:\program files\asksearch\bin\DefaultSearch.dll BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\smart web printing\hpswp_printenhancer.dll BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [BTMeter] c:\program files\battery meter\BTMeter.exe mRun: [WLSS] c:\program files\wireless select switch\WLSS.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [ThreatFire] c:\program files\threatfire\TFTray.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [Gravis Xperience Driver Support] Grxp4exe.exe /init mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe StartupFolder: c:\docume~1\emily\startm~1\programs\startup\dropbox.lnk - c:\program files\dropbox\Dropbox.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll Trusted Zone: composerarts.com\www Trusted Zone: paypal.com\www DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238781046328 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab Filter: text/html - {0bbe6efb-2da9-435f-a166-4821909c408d} - Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll Notify: igfxcui - igfxdev.dll ============= SERVICES / DRIVERS =============== R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [2008-12-24 14248] R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-2-7 51984] R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-2-7 46864] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-1-20 114768] R1 kid_sys;Kensington Input Devices Class filter driver;c:\windows\system32\drivers\KID_SYS.sys [2009-7-14 11920] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-1-20 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-1-20 138680] R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [2008-4-25 14336] R2 ThreatFire;ThreatFire;c:\program files\threatfire\tfservice.exe service –> c:\program files\threatfire\TFService.exe service [?] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-1-20 254040] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-1-20 352920] R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-12-24 93968] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-2-7 33552] S3 ntxpusb;Gravis USB device driver;c:\windows\system32\drivers\ntxpusb.sys [2009-7-14 266432] =============== Created Last 30 ================ 2009-07-31 23:42 –d—– c:\program files\Nero 2009-07-31 23:42 –d—– c:\docume~1\alluse~1\applic~1\Nero 2009-07-31 23:18 –d—– c:\windows\RegisteredPackages 2009-07-30 13:26 –dsh— C:\found.000 2009-07-20 09:08 –d—– c:\windows\ShellNew 2009-07-20 08:41 –d—– c:\program files\ModPlug 2009-07-20 08:34 –d—– c:\documents and settings\emily\WINDOWS 2009-07-14 15:54 69,632 a——- c:\windows\system32\grxp4dll.dll 2009-07-14 15:54 36,864 a——- c:\windows\system32\grxp4exe.exe 2009-07-14 15:54 35,488 a——- c:\windows\TMPG001.TMP 2009-07-14 15:53 –d—– c:\program files\Gravis 2009-07-14 15:51 –d—– C:\Xp4_5 2009-07-12 00:22 –d—– c:\docume~1\emily\applic~1\Dropbox 2009-07-12 00:21 –d—– c:\program files\Dropbox 2009-07-11 23:47 –d—– c:\windows\system32\wbem\Repository 2009-07-11 11:37 –d—– c:\program files\JRE ==================== Find3M ==================== 2009-06-26 12:50 666,624 a——- c:\windows\system32\wininet.dll 2009-06-26 12:50 81,920 a——- c:\windows\system32\ieencode.dll 2009-06-19 16:37 46,864 a——- c:\windows\system32\drivers\TfSysMon.sys 2009-06-19 16:37 33,552 a——- c:\windows\system32\drivers\TfNetMon.sys 2009-06-19 16:37 51,984 a——- c:\windows\system32\drivers\TfFsMon.sys 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-05-07 11:32 345,600 a——- c:\windows\system32\localspl.dll 2009-03-31 01:47 8 —shr– c:\windows\system32\4F4698B9AB.dll ============= FINISH: 17:04:01.07 ===============📎Attach.zip
Hi tiredofcomputers,

You're welcome.


Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield
  • Do not copy the word CODE , please note the script starts with the :
    :dir
    C:\Program Files\Common
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please post back with
  • MBAM log
  • SystemLook log
  • new DDS log, just the DDS.txt this time

How's the computer now?

Thanks
Ok, here are the logs. When I restarted the Common Folder opened up again by itself but there was no help.sig file in it. The folder was empty. Is there something to do about the Common Folder so it doesn't open on startup? MBAM Log: Malwarebytes' Anti-Malware 1.39 Database version: 2547 Windows 5.1.2600 Service Pack 3 8/2/2009 5:50:37 PM mbam-log-2009-08-02 (17-50-37).txt Scan type: Quick Scan Objects scanned: 101675 Time elapsed: 13 minute(s), 2 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 5 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\main.bho (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\main.bho.1 (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{986a8ac1-ab4d-4f41-9068-4b01c0197867} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{8e3c68cd-f500-4a2a-8cb9-132bb38c3573} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{a0e1054b-01ee-4d57-a059-4d99f339709f} (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Program Files\Common\helper.sig (Trojan.Agent) -> Quarantined and deleted successfully. SystemLook Log: SystemLook v1.0 by jpshortstuff (22.05.09) Log created at 17:56 on 02/08/2009 by Emily (Administrator - Elevation successful) ========== dir ========== C:\Program Files\Common - Parameters: "(none)" —Files— None found. —Folders— None found. -=End Of File=- New DDS Log: DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 17:58:20.67 on Sun 08/02/2009 Internet Explorer: 6.0.2900.5512 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.473 [GMT -4:00] AV: avast! antivirus 4.8.1335 [VPS 090801-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Battery Meter\BTMeter.exe C:\Program Files\Wireless Select Switch\WLSS.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\ThreatFire\TFTray.exe C:\WINDOWS\system32\Grxp4exe.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Dropbox\Dropbox.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\ThreatFire\TFService.exe C:\WINDOWS\system32\wdfmgr.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\alg.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe C:\Program Files\Alwil Software\Avast4\setup\avast.setup C:\Documents and Settings\Emily\Desktop\dds.scr C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3081224 mStart Page = hxxp://www.dell.com mSearch Bar = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3081224 uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101804&gct=&gc=1&q=%s uURLSearchHooks: DefaultSearchHook Class: {c94e154b-1459-4a47-966b-4b843befc7db} - c:\program files\asksearch\bin\DefaultSearch.dll BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\smart web printing\hpswp_printenhancer.dll BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [BTMeter] c:\program files\battery meter\BTMeter.exe mRun: [WLSS] c:\program files\wireless select switch\WLSS.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [ThreatFire] c:\program files\threatfire\TFTray.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [Gravis Xperience Driver Support] Grxp4exe.exe /init mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe StartupFolder: c:\docume~1\emily\startm~1\programs\startup\dropbox.lnk - c:\program files\dropbox\Dropbox.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll Trusted Zone: composerarts.com\www Trusted Zone: paypal.com\www DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238781046328 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab Filter: text/html - {0bbe6efb-2da9-435f-a166-4821909c408d} - Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll Notify: igfxcui - igfxdev.dll ============= SERVICES / DRIVERS =============== R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [2008-12-24 14248] R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-2-7 51984] R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-2-7 46864] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-1-20 114768] R1 kid_sys;Kensington Input Devices Class filter driver;c:\windows\system32\drivers\KID_SYS.sys [2009-7-14 11920] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-1-20 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-1-20 138680] R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [2008-4-25 14336] R2 ThreatFire;ThreatFire;c:\program files\threatfire\tfservice.exe service –> c:\program files\threatfire\TFService.exe service [?] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-1-20 254040] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-1-20 352920] R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-12-24 93968] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-2-7 33552] S3 ntxpusb;Gravis USB device driver;c:\windows\system32\drivers\ntxpusb.sys [2009-7-14 266432] =============== Created Last 30 ================ 2009-08-02 17:35 –d—– c:\docume~1\emily\applic~1\Malwarebytes 2009-08-02 17:35 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-02 17:35 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-02 17:35 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-02 17:35 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-31 23:42 –d—– c:\program files\Nero 2009-07-31 23:42 –d—– c:\docume~1\alluse~1\applic~1\Nero 2009-07-31 23:18 –d—– c:\windows\RegisteredPackages 2009-07-30 13:26 –dsh— C:\found.000 2009-07-20 09:08 –d—– c:\windows\ShellNew 2009-07-20 08:41 –d—– c:\program files\ModPlug 2009-07-20 08:34 –d—– c:\documents and settings\emily\WINDOWS 2009-07-14 15:54 69,632 a——- c:\windows\system32\grxp4dll.dll 2009-07-14 15:54 36,864 a——- c:\windows\system32\grxp4exe.exe 2009-07-14 15:54 35,488 a——- c:\windows\TMPG001.TMP 2009-07-14 15:53 –d—– c:\program files\Gravis 2009-07-14 15:51 –d—– C:\Xp4_5 2009-07-12 00:22 –d—– c:\docume~1\emily\applic~1\Dropbox 2009-07-12 00:21 –d—– c:\program files\Dropbox 2009-07-11 23:47 –d—– c:\windows\system32\wbem\Repository 2009-07-11 11:37 –d—– c:\program files\JRE ==================== Find3M ==================== 2009-06-26 12:50 666,624 a——- c:\windows\system32\wininet.dll 2009-06-26 12:50 81,920 a——- c:\windows\system32\ieencode.dll 2009-06-19 16:37 46,864 a——- c:\windows\system32\drivers\TfSysMon.sys 2009-06-19 16:37 33,552 a——- c:\windows\system32\drivers\TfNetMon.sys 2009-06-19 16:37 51,984 a——- c:\windows\system32\drivers\TfFsMon.sys 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-05-07 11:32 345,600 a——- c:\windows\system32\localspl.dll 2009-03-31 01:47 8 —shr– c:\windows\system32\4F4698B9AB.dll ============= FINISH: 18:00:45.37 ===============
Hi tiredofcomputers,

Yes we can. We will take care of that momentarily, please put up with it until you have updated your java.

Click your Start button > Control Panel > Add/Remove Programs and uninstall these 2 versions of Java

Java™ 6 Update 5
Java™ 6 Update 7



Next, Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

After the java is updated, reboot your computer if not prompted to.


Please download the OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE note the fix starts with the :
    :Services
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html]
    [-HKEY_CLASSES_ROOT\CLSID\{0bbe6efb-2da9-435f-a166-4821909c408d}]
    
    :Files
    C:\Program Files\Common
    
    :Commands
    [Purity]
    [emptytemp]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply along with a new HijackThis log.

Please post back with
  • OTM log
  • Kaspersky log
  • new DDS log.

Let us know of any problems you are having.

Thanks
Hello again! I ran Kaspersky but it didn't find anything so here are the other logs. Are things looking better? :) OTM: All processes killed ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html\ not found. Registry key HKEY_CLASSES_ROOT\CLSID\{0bbe6efb-2da9-435f-a166-4821909c408d}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0bbe6efb-2da9-435f-a166-4821909c408d}\ not found. ========== FILES ========== C:\Program Files\Common moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 49152 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: All Users User: Default User ->Temp folder emptied: 49152 bytes ->Temporary Internet Files folder emptied: 32768 bytes User: Emily File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\YDC5ANG5\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241671797859;eid1=2;ecn1=0;etm1=2;eid2=12;ecn2=0;etm2=2;eid4=3;ec n[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\YDC5ANG5\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679987109;eid1=2;ecn1=1;etm1=2;eid2=12;ecn2=1;etm2=0;eid3=11;e c[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\YDC5ANG5\adtarget;abr=!webtv;page=emusic_creating_realistic_string;subss=;subs=;area=tutorials;site =emusician;spon=primarymag;kw=;sz=300x250;tile=square3001;pos=square3001;o[2].842 40879619 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\YDC5ANG5\BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXADUmVndWxhcgRQYXJ0VHlwZQNZYWh vbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9RdWVyeUlkAzE2MTMyMzQzMDc0OWMz ZGU2YjEzYTQ2BF9TAzE1&r;=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\YDC5ANG5\celebrities;sz=300x250;kl=N;klg=en;kt=K;kga=-1;kr=F;kw=the+patriot+gibson+rides;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=9758725939044026[2] scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\YDC5ANG5\default;sz=300x250;kl=N;klg=en;kt=K;kga=-1;kr=F;kw=jerry+goldsmith+vs+john+williams;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=2321437537249683[2] scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\YDC5ANG5\midarticleflex;dir=news;dir=jurisprudence;dir=midarticleflex;ad=fb;ad=bb;de l=js;ajax=n;dcopt=ist;heavy=n;pageId=slate-id-2077192;poe=yes;undefinedfromrss=n;rss=n;front=n;ms[2] scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\WT6Z4L6J\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241671811359;eid1=2;ecn1=0;etm1=9;eid2=12;ecn2=0;etm2=10;eid6=18; e[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\WT6Z4L6J\BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXADUmVndWxhcgRQYXJ0VHlwZQNZYWh vbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9RdWVyeUlkAzE2MTMyMzQzMDc0OWMz ZGU5MmI0NTQwBF9TAzE1&r;=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\WT6Z4L6J\click,VaUDAHL6BwBvPB0AjWgJAAAAAV4AAP8A.wAGEQIADwKMrgEAznoNAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAM34w0kAAAAA,http%3A%2F%2Fus.ard.yahoo[2].rand%3D1102832347%26da%3D0,;ord=1237579981 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\WT6Z4L6J\movies_moviememorabilia;sz=300x250;kl=N;klg=en;kt=K;kga=-1;kr=F;kw=elfman+terminator;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=2782127890835681[2] scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\T1WWC96Q\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241671795859;eid1=2;ecn1=1;etm1=4;eid2=12;ecn2=1;etm2=0;eid3=11;e c[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\T1WWC96Q\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679684750;eid1=2;ecn1=0;etm1=30;eid5=13;ecn5=1;etm5=0;&_dc_ck=t[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\;_ylc=X1MDOTc1NDYxNjgEX3IDMgRjYXRlZ29yeQNJREVOVElGSUVSBGV4dGZyb20DBGZiAzAEZ nJjb2RlA2NzY195bWFpbG0EaXNleHQDMARpdANzaG9ydGN1dHM6L3VzL2luc3RhbmNlL2[2].adNoOp&fr;=csc_ymailm&modid;=none scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679102640;eid1=2;ecn1=0;etm1=6;eid2=12;ecn2=0;etm2=6;&_dc_ck=tr[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679654750;eid1=2;ecn1=0;etm1=10;eid2=12;ecn2=0;etm2=10;eid4=18 ;[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241686223062;eid4=3;ecn4=1;etm4=1;eid5=4;ecn5=1;etm5=0;&_dc_ck=try[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\jurisprudence;dir=news;dir=jurisprudence;ad=336x90;del=js;ajax=n;heavy=n;pa geId=slate-id-2077192;poe=yes;undefinedfromrss=n;rss=n;front=n;msn_refer=n;dept=58289;articleI d=2[2] scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\leaderboard;dir=news;dir=jurisprudence;dir=leaderboard;ad=lb;del=js;ajax=n; heavy=n;pageId=slate-id-2077192;poe=yes;undefinedfromrss=n;rss=n;front=n;msn_refer=n;dept=58289;a[2] scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\search;_ylc=X3oDMTRhbDBqOWQ5BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXA DUmVndWxhcgRQYXJ0VHlwZQNZYWhvbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9R dWVyeUlkAzE2MTMy[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\search;_ylc=X3oDMTRhdHB1ZGt1BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXA DUmVndWxhcgRQYXJ0VHlwZQNZYWhvbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9R dWVyeUlkAzE2MTMy[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\QRAT3MNO\1KZ4X.present=1&fields;=email,name,nickname,email&sort-fields;=nickname,email&page;=0&pagesize;=5000&appid;=mongo&ts;=1241630288&auth;=edf3adfcfa9ad9b7232dddee6c1724fd&abwssid;=Pfx07rBTelk scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\QRAT3MNO\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241680004562;eid1=2;ecn1=0;etm1=10;eid2=12;ecn2=0;etm2=10;eid4=18 ;[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\QRAT3MNO\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241682506734;eid1=2;ecn1=0;etm1=1;eid4=12;ecn4=1;etm4=0;eid5=11;e c[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\QRAT3MNO\adtarget;abr=!webtv;page=emusic_creating_realistic_string;subss=;subs=;area=tutorials;site =emusician;kw=;spon=primarymag;sz=125x125;tile=smsquare1;pos=smsquare1;ord[2].637 69073518 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\QRAT3MNO\click,VaUDAHL6BwBvPB0AimgJAAAAAV4AAP8A.[2].rand%3D495357937%26fid%3Dinbox%26mid%3D1_2143636_alhu%252fngaaxobscp0uajx2v8l1hg%26noflush%3D%26mcrumb%3D6zuvex1z%252fss,;ord=1237579652 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\QRAT3MNO\rightflex;dir=news;dir=jurisprudence;dir=rightflex;ad=ss;ad=hp;ad=bb;del=js ;ajax=n;heavy=n;pageId=slate-id-2077192;poe=yes;undefinedfromrss=n;rss=n;front=n;msn_refer=n;dept[2] scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\ORYV8LY3\BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXADUmVndWxhcgRQYXJ0VHlwZQNZYWh vbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9RdWVyeUlkAzE2MTMyMzQzMDc0OWMz ZGVhNTFmYWE1BF9TAzE1&r;=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\ORYV8LY3\click,VaUDAHL6BwCHCRkAOGMIAAAAAV4AAP8A.wAGDwIADwKMrgEAh.4LAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAFjew0kAAAAA,http%3A%2F%2Fus.ard.yahoo.com%2FSIG%3D15o4p1j23%2FM%3D715481[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\ORYV8LY3\click,VaUDAHL6BwCHCRkAOGMIAAAAAV4AAP8A.wAGDwIADwKMrgEAh.4LAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAOzew0kAAAAA,http%3A%2F%2Fus.ard.yahoo.com%2FSIG%3D15ocv7066%2FM%3D715481[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\ORYV8LY3\dref=http%253A%252F%252Fdelb.opt.fimserve[1].com%252Fadopt%252F%253Fr%253Dh%2526l%253Dfb5f52b3-7892-4398-bb45-705752ed6df4%2526sz%253D728x90%2526rnd%253D3877520756839897 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\O5ANKPEF\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679096265;eid1=2;ecn1=1;etm1=1;eid2=12;ecn2=1;etm2=0;eid3=11;e c[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN10IE7Y\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679638140;eid1=2;ecn1=1;etm1=3;eid2=12;ecn2=1;etm2=0;eid3=11;e c[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN10IE7Y\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241682513500;eid1=2;ecn1=0;etm1=7;eid4=12;ecn4=0;etm4=7;&_dc_ck=tr[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN10IE7Y\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241686229203;eid1=2;ecn1=0;etm1=6;eid2=12;ecn2=0;etm2=6;eid4=3;ec n[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN10IE7Y\BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXADUmVndWxhcgRQYXJ0VHlwZQNZYWh vbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9RdWVyeUlkAzE2MTMyMzQzMDc0OWMz ZGU5ZDk3OGExBF9TAzE1&r;=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN10IE7Y\click,VaUDAHL6BwBvPB0AjWgJAAAAAV4AAP8A.[1].rand%3D495357937%26fid%3Dinbox%26mid%3D1_2143636_alhu%252fngaaxobscp0uajx2v8l1hg%26noflush%3D%26mcrumb%3D6zuvex1z%252fss,;ord=1237579719 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN10IE7Y\click,VaUDALD7BwAzUhkAl4IIAAAAAVoAAP8A.wAGDgIABgOMrgEAyuoMAM0qDAAAAAAAAAAAA AAAAAAAAAAAAAAAAFLZw0kAAAAA,http%3A%2F%2Fus.ard.yahoo[2].rand%3D851216941%26da%3D0,;ord=1237571922 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\CPEB8HIB\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241671802218;eid1=2;ecn1=0;etm1=5;eid2=12;ecn2=0;etm2=4;eid4=3;ec n[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\CPEB8HIB\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241682490109;eid1=2;ecn1=1;etm1=3;eid2=12;ecn2=1;etm2=0;eid3=11;e c[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\CPEB8HIB\adtarget;abr=!webtv;page=emusic_creating_realistic_string;subss=;subs=;area=tutorials;site =emusician;kw=;spon=primarymag;dcopt=ist;sz=728x90;tile=fullbanner1;pos=fu[2].989 44149972 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\CPEB8HIB\DA4NDQ7NjcyNzkuLjkuZmgudW8uZi40NjVAQHh6eW92QEB3dm96bXdAQC00XzlAQGlsencgaWZt bXZpIHNsb3d4bCBvb3hAQHhsbkBAaGxmZ3N2emhnOzEyNDE2NzY5NzI0Mjc7MTs7OzA7NDszODYzNDE2O zs1MDAwOzs7Ow%3D%3Dd&r;=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\CPEB8HIB\search;_ylc=X3oDMTRhbjMzMDg2BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXA DUmVndWxhcgRQYXJ0VHlwZQNZYWhvbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9R dWVyeUlkAzE2MTMy[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\CP0HMHM7\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241682523468;eid1=2;ecn1=0;etm1=10;eid4=12;ecn4=0;etm4=10;eid6=18 ;[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\4TENGTQN\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679644750;eid1=2;ecn1=0;etm1=7;eid2=12;ecn2=0;etm2=7;&_dc_ck=tr[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\4TENGTQN\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241686222953;eid1=2;ecn1=1;etm1=4;eid2=12;ecn2=1;etm2=0;eid3=11;e c[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\4TENGTQN\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241686239156;eid1=2;ecn1=0;etm1=10;eid2=12;ecn2=0;etm2=10;eid4=3; e[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\4TENGTQN\jurisprudence;dir=news;dir=jurisprudence;ad=336x90;del=js;ajax=n;heavy=n;pa geId=slate-id-2077192;poe=yes;undefinedfromrss=n;rss=n;front=n;msn_refer=n;dept=58289;articleI d=2[1] scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\0PE34TIJ\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679994500;eid1=2;ecn1=0;etm1=8;eid2=12;ecn2=0;etm2=7;&_dc_ck=tr[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\0PE34TIJ\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241682505750;eid1=2;ecn1=1;etm1=2;eid2=3;ecn2=1;etm2=1;eid3=4;ecn 3[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\0PE34TIJ\dref=http%253A%252F%252Fbl132w.blu132[1].aspx%253FFolderID%253D00000000-0000-0000-0000-000000000001%2526InboxSortAscending%253DFalse%2526InboxSortBy%253DDate%2526n%253D921661940 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\0PE34TIJ\search;_ylc=X3oDMTRhbnBvYmh2BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXA DUmVndWxhcgRQYXJ0VHlwZQNZYWhvbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9R dWVyeUlkAzE2MTMy[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\0PE34TIJ\ZUFEP.present=1&fields;=email,name,nickname,email&sort-fields;=nickname,email&page;=0&pagesize;=5000&appid;=mongo&ts;=1241630329&auth;=d37e8e5b8ee0c05b6166775d71be1231&abwssid;=Pfx07rBTelk scheduled to be deleted on reboot. ->Temp folder emptied: 477207134 bytes ->Temporary Internet Files folder emptied: 1824618 bytes ->Java cache emptied: 24679370 bytes User: LocalService ->Temp folder emptied: 65984 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 35488 bytes %systemroot%\System32 .tmp files removed: 2577 bytes File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6bc.dat scheduled to be deleted on reboot. Windows Temp folder emptied: 46654532 bytes RecycleBin emptied: 26379896 bytes Total Files Cleaned = 550.35 mb OTM by OldTimer - Version 3.0.0.5 log created on 08022009_214146 Files moved on Reboot… File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\YDC5ANG5\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241671797859;eid1=2;ecn1=0;etm1=2;eid2=12;ecn2=0;etm2=2;eid4=3;ec n[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\YDC5ANG5\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679987109;eid1=2;ecn1=1;etm1=2;eid2=12;ecn2=1;etm2=0;eid3=11;e c[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\YDC5ANG5\adtarget;abr=!webtv;page=emusic_creating_realistic_string;subss=;subs=;area=tutorials;site =emusician;spon=primarymag;kw=;sz=300x250;tile=square3001;pos=square3001;o[2].842 40879619 not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\YDC5ANG5\BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXADUmVndWxhcgRQYXJ0VHlwZQNZYWh vbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9RdWVyeUlkAzE2MTMyMzQzMDc0OWMz ZGU2YjEzYTQ2BF9TAzE1&r;=0 not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\YDC5ANG5\celebrities;sz=300x250;kl=N;klg=en;kt=K;kga=-1;kr=F;kw=the+patriot+gibson+rides;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=9758725939044026[2] not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\YDC5ANG5\default;sz=300x250;kl=N;klg=en;kt=K;kga=-1;kr=F;kw=jerry+goldsmith+vs+john+williams;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=2321437537249683[2] not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\YDC5ANG5\midarticleflex;dir=news;dir=jurisprudence;dir=midarticleflex;ad=fb;ad=bb;de l=js;ajax=n;dcopt=ist;heavy=n;pageId=slate-id-2077192;poe=yes;undefinedfromrss=n;rss=n;front=n;ms[2] not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\WT6Z4L6J\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241671811359;eid1=2;ecn1=0;etm1=9;eid2=12;ecn2=0;etm2=10;eid6=18; e[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\WT6Z4L6J\BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXADUmVndWxhcgRQYXJ0VHlwZQNZYWh vbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9RdWVyeUlkAzE2MTMyMzQzMDc0OWMz ZGU5MmI0NTQwBF9TAzE1&r;=0 not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\WT6Z4L6J\click,VaUDAHL6BwBvPB0AjWgJAAAAAV4AAP8A.wAGEQIADwKMrgEAznoNAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAM34w0kAAAAA,http%3A%2F%2Fus.ard.yahoo[2].rand%3D1102832347%26da%3D0,;ord=1237579981 not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\WT6Z4L6J\movies_moviememorabilia;sz=300x250;kl=N;klg=en;kt=K;kga=-1;kr=F;kw=elfman+terminator;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=2782127890835681[2] not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\T1WWC96Q\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241671795859;eid1=2;ecn1=1;etm1=4;eid2=12;ecn2=1;etm2=0;eid3=11;e c[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\T1WWC96Q\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679684750;eid1=2;ecn1=0;etm1=30;eid5=13;ecn5=1;etm5=0;&_dc_ck=t[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\;_ylc=X1MDOTc1NDYxNjgEX3IDMgRjYXRlZ29yeQNJREVOVElGSUVSBGV4dGZyb20DBGZiAzAEZ nJjb2RlA2NzY195bWFpbG0EaXNleHQDMARpdANzaG9ydGN1dHM6L3VzL2luc3RhbmNlL2[2].adNoOp&fr;=csc_ymailm&modid;=none not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679102640;eid1=2;ecn1=0;etm1=6;eid2=12;ecn2=0;etm2=6;&_dc_ck=tr[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679654750;eid1=2;ecn1=0;etm1=10;eid2=12;ecn2=0;etm2=10;eid4=18 ;[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241686223062;eid4=3;ecn4=1;etm4=1;eid5=4;ecn5=1;etm5=0;&_dc_ck=try[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\jurisprudence;dir=news;dir=jurisprudence;ad=336x90;del=js;ajax=n;heavy=n;pa geId=slate-id-2077192;poe=yes;undefinedfromrss=n;rss=n;front=n;msn_refer=n;dept=58289;articleI d=2[2] not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\leaderboard;dir=news;dir=jurisprudence;dir=leaderboard;ad=lb;del=js;ajax=n; heavy=n;pageId=slate-id-2077192;poe=yes;undefinedfromrss=n;rss=n;front=n;msn_refer=n;dept=58289;a[2] not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\search;_ylc=X3oDMTRhbDBqOWQ5BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXA DUmVndWxhcgRQYXJ0VHlwZQNZYWhvbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9R dWVyeUlkAzE2MTMy[1].htm not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\R7971QE2\search;_ylc=X3oDMTRhdHB1ZGt1BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXA DUmVndWxhcgRQYXJ0VHlwZQNZYWhvbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9R dWVyeUlkAzE2MTMy[1].htm not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\QRAT3MNO\1KZ4X.present=1&fields;=email,name,nickname,email&sort-fields;=nickname,email&page;=0&pagesize;=5000&appid;=mongo&ts;=1241630288&auth;=edf3adfcfa9ad9b7232dddee6c1724fd&abwssid;=Pfx07rBTelk not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\QRAT3MNO\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241680004562;eid1=2;ecn1=0;etm1=10;eid2=12;ecn2=0;etm2=10;eid4=18 ;[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\QRAT3MNO\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241682506734;eid1=2;ecn1=0;etm1=1;eid4=12;ecn4=1;etm4=0;eid5=11;e c[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\QRAT3MNO\adtarget;abr=!webtv;page=emusic_creating_realistic_string;subss=;subs=;area=tutorials;site =emusician;kw=;spon=primarymag;sz=125x125;tile=smsquare1;pos=smsquare1;ord[2].637 69073518 not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\QRAT3MNO\click,VaUDAHL6BwBvPB0AimgJAAAAAV4AAP8A.[2].rand%3D495357937%26fid%3Dinbox%26mid%3D1_2143636_alhu%252fngaaxobscp0uajx2v8l1hg%26noflush%3D%26mcrumb%3D6zuvex1z%252fss,;ord=1237579652 not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\QRAT3MNO\rightflex;dir=news;dir=jurisprudence;dir=rightflex;ad=ss;ad=hp;ad=bb;del=js ;ajax=n;heavy=n;pageId=slate-id-2077192;poe=yes;undefinedfromrss=n;rss=n;front=n;msn_refer=n;dept[2] not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\ORYV8LY3\BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXADUmVndWxhcgRQYXJ0VHlwZQNZYWh vbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9RdWVyeUlkAzE2MTMyMzQzMDc0OWMz ZGVhNTFmYWE1BF9TAzE1&r;=0 not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\ORYV8LY3\click,VaUDAHL6BwCHCRkAOGMIAAAAAV4AAP8A.wAGDwIADwKMrgEAh.4LAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAFjew0kAAAAA,http%3A%2F%2Fus.ard.yahoo.com%2FSIG%3D15o4p1j23%2FM%3D715481[1].htm not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\ORYV8LY3\click,VaUDAHL6BwCHCRkAOGMIAAAAAV4AAP8A.wAGDwIADwKMrgEAh.4LAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAOzew0kAAAAA,http%3A%2F%2Fus.ard.yahoo.com%2FSIG%3D15ocv7066%2FM%3D715481[1].htm not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\ORYV8LY3\dref=http%253A%252F%252Fdelb.opt.fimserve[1].com%252Fadopt%252F%253Fr%253Dh%2526l%253Dfb5f52b3-7892-4398-bb45-705752ed6df4%2526sz%253D728x90%2526rnd%253D3877520756839897 not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\O5ANKPEF\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679096265;eid1=2;ecn1=1;etm1=1;eid2=12;ecn2=1;etm2=0;eid3=11;e c[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN10IE7Y\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679638140;eid1=2;ecn1=1;etm1=3;eid2=12;ecn2=1;etm2=0;eid3=11;e c[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN10IE7Y\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241682513500;eid1=2;ecn1=0;etm1=7;eid4=12;ecn4=0;etm4=7;&_dc_ck=tr[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN10IE7Y\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241686229203;eid1=2;ecn1=0;etm1=6;eid2=12;ecn2=0;etm2=6;eid4=3;ec n[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN10IE7Y\BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXADUmVndWxhcgRQYXJ0VHlwZQNZYWh vbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9RdWVyeUlkAzE2MTMyMzQzMDc0OWMz ZGU5ZDk3OGExBF9TAzE1&r;=0 not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN10IE7Y\click,VaUDAHL6BwBvPB0AjWgJAAAAAV4AAP8A.[1].rand%3D495357937%26fid%3Dinbox%26mid%3D1_2143636_alhu%252fngaaxobscp0uajx2v8l1hg%26noflush%3D%26mcrumb%3D6zuvex1z%252fss,;ord=1237579719 not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN10IE7Y\click,VaUDALD7BwAzUhkAl4IIAAAAAVoAAP8A.wAGDgIABgOMrgEAyuoMAM0qDAAAAAAAAAAAA AAAAAAAAAAAAAAAAFLZw0kAAAAA,http%3A%2F%2Fus.ard.yahoo[2].rand%3D851216941%26da%3D0,;ord=1237571922 not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\CPEB8HIB\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241671802218;eid1=2;ecn1=0;etm1=5;eid2=12;ecn2=0;etm2=4;eid4=3;ec n[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\CPEB8HIB\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241682490109;eid1=2;ecn1=1;etm1=3;eid2=12;ecn2=1;etm2=0;eid3=11;e c[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\CPEB8HIB\adtarget;abr=!webtv;page=emusic_creating_realistic_string;subss=;subs=;area=tutorials;site =emusician;kw=;spon=primarymag;dcopt=ist;sz=728x90;tile=fullbanner1;pos=fu[2].989 44149972 not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\CPEB8HIB\DA4NDQ7NjcyNzkuLjkuZmgudW8uZi40NjVAQHh6eW92QEB3dm96bXdAQC00XzlAQGlsencgaWZt bXZpIHNsb3d4bCBvb3hAQHhsbkBAaGxmZ3N2emhnOzEyNDE2NzY5NzI0Mjc7MTs7OzA7NDszODYzNDE2O zs1MDAwOzs7Ow%3D%3Dd&r;=0 not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\CPEB8HIB\search;_ylc=X3oDMTRhbjMzMDg2BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXA DUmVndWxhcgRQYXJ0VHlwZQNZYWhvbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9R dWVyeUlkAzE2MTMy[1].htm not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\CP0HMHM7\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241682523468;eid1=2;ecn1=0;etm1=10;eid4=12;ecn4=0;etm4=10;eid6=18 ;[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\4TENGTQN\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679644750;eid1=2;ecn1=0;etm1=7;eid2=12;ecn2=0;etm2=7;&_dc_ck=tr[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\4TENGTQN\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241686222953;eid1=2;ecn1=1;etm1=4;eid2=12;ecn2=1;etm2=0;eid3=11;e c[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\4TENGTQN\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241686239156;eid1=2;ecn1=0;etm1=10;eid2=12;ecn2=0;etm2=10;eid4=3; e[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\4TENGTQN\jurisprudence;dir=news;dir=jurisprudence;ad=336x90;del=js;ajax=n;heavy=n;pa geId=slate-id-2077192;poe=yes;undefinedfromrss=n;rss=n;front=n;msn_refer=n;dept=58289;articleI d=2[1] not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\0PE34TIJ\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241679994500;eid1=2;ecn1=0;etm1=8;eid2=12;ecn2=0;etm2=7;&_dc_ck=tr[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\0PE34TIJ\activity;src=1400366;met=1;v=1;pid=36601406;aid=214747259;ko=0;cid=31370498 ;rid=31388374;rv=2;×tamp=1241682505750;eid1=2;ecn1=1;etm1=2;eid2=3;ecn2=1;etm2=1;eid3=4;ecn 3[1].gif not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\0PE34TIJ\dref=http%253A%252F%252Fbl132w.blu132[1].aspx%253FFolderID%253D00000000-0000-0000-0000-000000000001%2526InboxSortAscending%253DFalse%2526InboxSortBy%253DDate%2526n%253D921661940 not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\0PE34TIJ\search;_ylc=X3oDMTRhbnBvYmh2BEFjdGlvbgNCYXNpYyBzZWFyY2gESW50bAN1cwRMbmtUeXA DUmVndWxhcgRQYXJ0VHlwZQNZYWhvbyEEU3JjaEN1cnIDbWVzc2FnZQRTcmNoRGVzdANtZXNzYWdlBF9R dWVyeUlkAzE2MTMy[1].htm not found! File C:\Documents and Settings\Emily\Local Settings\Temp\Temporary Internet Files\Content.IE5\0PE34TIJ\ZUFEP.present=1&fields;=email,name,nickname,email&sort-fields;=nickname,email&page;=0&pagesize;=5000&appid;=mongo&ts;=1241630329&auth;=d37e8e5b8ee0c05b6166775d71be1231&abwssid;=Pfx07rBTelk not found! File C:\WINDOWS\temp\Perflib_Perfdata_6bc.dat not found! Registry entries deleted on Reboot… DDS: DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 8:08:14.50 on Mon 08/03/2009 Internet Explorer: 6.0.2900.5512 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.357 [GMT -4:00] AV: avast! antivirus 4.8.1335 [VPS 090802-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\ThreatFire\TFService.exe C:\WINDOWS\system32\wdfmgr.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Battery Meter\BTMeter.exe C:\Program Files\Wireless Select Switch\WLSS.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\ThreatFire\TFTray.exe C:\WINDOWS\system32\Grxp4exe.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Dropbox\Dropbox.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe C:\Program Files\Java\jre6\bin\java.exe C:\WINDOWS\Temp\jkos-Emily\binaries\ScanningProcess.exe C:\WINDOWS\Temp\jkos-Emily\binaries\ScanningProcess.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Documents and Settings\Emily\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us uDefault_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=3081224 mStart Page = hxxp://www.dell.com mSearch Bar = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=3081224 uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101804&gct;=&gc;=1&q;=%s uURLSearchHooks: DefaultSearchHook Class: {c94e154b-1459-4a47-966b-4b843befc7db} - c:\program files\asksearch\bin\DefaultSearch.dll BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\smart web printing\hpswp_printenhancer.dll BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [BTMeter] c:\program files\battery meter\BTMeter.exe mRun: [WLSS] c:\program files\wireless select switch\WLSS.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [ThreatFire] c:\program files\threatfire\TFTray.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [Gravis Xperience Driver Support] Grxp4exe.exe /init mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\docume~1\emily\startm~1\programs\startup\dropbox.lnk - c:\program files\dropbox\Dropbox.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll Trusted Zone: composerarts.com\www Trusted Zone: paypal.com\www DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238781046328 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll Notify: igfxcui - igfxdev.dll ============= SERVICES / DRIVERS =============== R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [2008-12-24 14248] R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-2-7 51984] R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-2-7 46864] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-1-20 114768] R1 kid_sys;Kensington Input Devices Class filter driver;c:\windows\system32\drivers\KID_SYS.sys [2009-7-14 11920] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-1-20 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-1-20 138680] R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [2008-4-25 14336] R2 ThreatFire;ThreatFire;c:\program files\threatfire\tfservice.exe service –> c:\program files\threatfire\TFService.exe service [?] R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-12-24 93968] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-2-7 33552] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-1-20 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-1-20 352920] S3 ntxpusb;Gravis USB device driver;c:\windows\system32\drivers\ntxpusb.sys [2009-7-14 266432] =============== Created Last 30 ================ 2009-08-02 21:41 –d—– C:\_OTM 2009-08-02 17:35 –d—– c:\docume~1\emily\applic~1\Malwarebytes 2009-08-02 17:35 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-02 17:35 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-02 17:35 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-02 17:35 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-31 23:42 –d—– c:\program files\Nero 2009-07-31 23:42 –d—– c:\docume~1\alluse~1\applic~1\Nero 2009-07-31 23:18 –d—– c:\windows\RegisteredPackages 2009-07-30 13:26 –dsh— C:\found.000 2009-07-20 09:08 –d—– c:\windows\ShellNew 2009-07-20 08:41 –d—– c:\program files\ModPlug 2009-07-20 08:34 –d—– c:\documents and settings\emily\WINDOWS 2009-07-14 15:54 69,632 a——- c:\windows\system32\grxp4dll.dll 2009-07-14 15:54 36,864 a——- c:\windows\system32\grxp4exe.exe 2009-07-14 15:53 –d—– c:\program files\Gravis 2009-07-14 15:51 –d—– C:\Xp4_5 2009-07-12 00:22 –d—– c:\docume~1\emily\applic~1\Dropbox 2009-07-12 00:21 –d—– c:\program files\Dropbox 2009-07-11 23:47 –d—– c:\windows\system32\wbem\Repository 2009-07-11 11:37 –d—– c:\program files\JRE ==================== Find3M ==================== 2009-06-26 12:50 666,624 a——- c:\windows\system32\wininet.dll 2009-06-26 12:50 81,920 a——- c:\windows\system32\ieencode.dll 2009-06-19 16:37 46,864 a——- c:\windows\system32\drivers\TfSysMon.sys 2009-06-19 16:37 33,552 a——- c:\windows\system32\drivers\TfNetMon.sys 2009-06-19 16:37 51,984 a——- c:\windows\system32\drivers\TfFsMon.sys 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-05-21 11:33 410,984 a——- c:\windows\system32\deploytk.dll 2009-05-07 11:32 345,600 a——- c:\windows\system32\localspl.dll 2009-03-31 01:47 8 —shr– c:\windows\system32\4F4698B9AB.dll ============= FINISH: 8:10:10.54 ===============
Hi tiredofcomputers,

Looks not too bad, just some minor things to clean up.

You have a couple of sites in the Trusted Zone. This zone by default has lower security settings. Is there any reason you have them running there?

Trusted Zone: composerarts.com\www
Trusted Zone: paypal.com\www


A few stray reg entries to clear up.
  • Please double-click OTM.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE note the fix starts with the :
    :Services
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Alcmtr"=-
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM

Please post back with
  • OTM log
  • answer regarding Trusted Zone
Are you having any problems?

Thanks
Hi! I had those sites in the Trusted Zone because I once increased my security settings to high and I kept getting prompts to accept those sites. One of them is my husband's website for composing video game music. I can take them out of there if needed. The Common Folder doesn't come up anymore, thanks for all the help! But when I shutdown I now get an END TASK window for DeviceIO Notification. Any ideas about that? Here is the OTM Log: ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Alcmtr deleted successfully. OTM by OldTimer - Version 3.0.0.5 log created on 08032009_131726
Hi tiredofcomputers, Trusted Zone- Just as long as you are aware the Security settings are lower in this zone. Wen did this error start? Any accompanying error messages? Thanks
I started getting the message yesterday when I shut down after I updated Java and rebooted after the first OTM run. There have been no other error messgaes. Everthing else is running fine.
Hi tiredofcomputers,

Before we accuse the usual suspect in this, HP printers, let's have a look for a few reg keys and files. I'm not sure what we did to upset HP though.

Use SystemLook with this script

:regfind
helper.sig
helper.dll

:filefind
helper.sig
helper.dll

Please post the SystemLook log.

Thanks
So it's the 21st Century and you can't use a laptop and a printer without there being a problem. And some think robots will contol humankind one day! Ha! Ok, so here's the SystemLook log: Thanks! SystemLook v1.0 by jpshortstuff (22.05.09) Log created at 12:58 on 04/08/2009 by Emily (Administrator - Elevation successful) ========== regfind ========== Searching for "helper.sig" No data found. Searching for "helper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\InprocServer32] "@"=="C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\InprocServer32] "@"=="C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5F226421-415D-408D-9A09-0DCD94E25B48}\1.0\0\win32] "@"=="C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\20700791739EEC14F8A70C19A120C3A1] ""801BA6121EA203143B5D022B4C8CF0F8""=="C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\QuickTimeWebHelper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E7EA0B4E57D2DD44691EF1775E71128A] ""68AB67CA7DA73301B7448A0100000030""=="C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\MUILanguages\RCV2\uihelper.dll] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILanguages\RCV2\uihelper.dll] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\uihelper.dll] ========== filefind ========== Searching for "helper.sig" No files found. Searching for "helper.dll" No files found. -=End Of File=-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI