This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Desire help with hijackthis log

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Quite green to be on this forum…a day or so ago, I believe I received a rogue issue (ie virus, malware, etc) of unknown origin. I've since added on Malewarebytes and Super Antispyware which seem to have run successfully with many threats detected. I formerly had AVG 8.5, which I uninstalled. I've been able to to download AVG 9.0, but can't get it activated. The actual error I receive is "Action failed for file avgwdsvc.exe starting service…" I've also attempted to download Avira Antivirus and…that to is unable to be opened. My computer takes several reboots to reach my home screen and after that will randomly freeze. Also worth noting, that when I attempt to research and download sites that may be able to help me…IE explorer and my registry has a mind of its own.

Attaching hijackthis log…gratitude for any one's time and help in advance. Dan

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:54:35 AM, on 12/30/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Common Files\AOL\1237308355\ee\AOLSoftware.exe
F:\WINDOWS\system32\RUNDLL32.EXE
F:\WINDOWS\system32\CTHELPER.EXE
F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
F:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
F:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe
F:\WINDOWS\MXOALDR.EXE
F:\Program Files\ScanSoft\OmniPageSE\opware32.exe
F:\Program Files\HP\HP Software Update\HPWuSchd2.exe
F:\Program Files\Java\jre6\bin\jusched.exe
F:\Program Files\Messenger\msmsgs.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\SUPERAntiSpyware\8a924459-05f3-41e8-848d-af5e0bd2d781.exe
F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
F:\Program Files\Common Files\AOL\1237308355\ee\AOLDesktop.exe
F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
F:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
F:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
F:\Program Files\Bonjour\mDNSResponder.exe
F:\WINDOWS\system32\svchost.exe
F:\Program Files\Java\jre6\bin\jqs.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\nvsvc32.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
F:\PROGRA~1\Dantz\RETROS~1\retrospect.exe
F:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
F:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
F:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
F:\Program Files\AOL 9.5\waol.exe
F:\Program Files\AOL 9.5\shellmon.exe
F:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
f:\program files\aol toolbar\AolTbServer.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: IAOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - F:\Program Files\AOL Toolbar\aoltb.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEToolbarBHO Class - {1A1DAC8C-074D-440F-8707-7009A672D7D1} - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedinIEToolbar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - F:\Program Files\AVG\AVG9\avgssie.dll (file missing)
O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - F:\Program Files\AOL Toolbar\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - F:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - F:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: LinkedIn Toolbar - {BB670D0B-5C46-40C7-B38B-40DD26987723} - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedinIEToolbar.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - F:\Program Files\AOL Toolbar\aoltb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [HostManager] F:\Program Files\Common Files\AOL\1237308355\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] F:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
O4 - HKLM\..\Run: [RetroExpress] F:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h
O4 - HKLM\..\Run: [MXOBG] F:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Omnipage] F:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [HP Software Update] F:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "F:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\Program Files\SUPERAntiSpyware\8a924459-05f3-41e8-848d-af5e0bd2d781.exe
O4 - Startup: Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: AOL Desktop.lnk = F:\Program Files\Common Files\AOL\Launch\aollaunch.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL Toolbar Search - F:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Linked&In Search - res://F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedinIEToolbar.dll/ContextMenu.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - F:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1237306142784
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://intercall.webex.com/client/T26L10NS…bex/ieatgpc.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/da2/PCPitStop2.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - F:\Program Files\AVG\AVG9\avgpp.dll (file missing)
O20 - Winlogon Notify: !SASWinLogon - F:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - F:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - F:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - F:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - F:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - F:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - F:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: TomTomHOMEService - TomTom - F:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

–
End of file - 10543 bytes
Hi Dan Miller, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER log
  • both OTL logs
No need for a Hijackthis log this time.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-30 14:16:16
Windows 5.1.2600 Service Pack 2
Running: q5zuyknf.exe; Driver: F:\DOCUME~1\DANMIL~1\LOCALS~1\Temp\awlyypow.sys


—- System - GMER 1.0.15 —-

Code 8A2F3618 ZwEnumerateKey
Code 8A2F3A80 ZwFlushInstructionCache
Code 8A2F30BE IofCallDriver
Code 8A2F2E7E IofCompleteRequest

—- Modules - GMER 1.0.15 —-

Module \systemroot\system32\drivers\H8SRTjtnaoykmvm.sys (*** hidden *** ) B5904000-B5920000 (114688 bytes)
—- Processes - GMER 1.0.15 —-

Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\system32\svchost.exe [624] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\Explorer.EXE [748] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\System32\svchost.exe [932] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\system32\svchost.exe [1116] 0x00BA0000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\system32\svchost.exe [1196] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\System32\svchost.exe [1352] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\System32\svchost.exe [1456] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\System32\svchost.exe [1612] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\System32\svchost.exe [2060] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\System32\svchost.exe [2240] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\System32\svchost.exe [2508] 0x10000000

—- Services - GMER 1.0.15 —-

Service F:\WINDOWS\system32\drivers\H8SRTjtnaoykmvm.sys (*** hidden *** ) [SYSTEM] H8SRTd.sys <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys@imagepath \systemroot\system32\drivers\H8SRTjtnaoykmvm.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@H8SRTd \\?\globalroot\systemroot\system32\drivers\H8SRTjtnaoykmvm.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@H8SRTc \\?\globalroot\systemroot\system32\H8SRTlkbwsndrgo.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@H8SRTsrcr \\?\globalroot\systemroot\system32\H8SRTxumltehhbm.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@h8srtserf \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@h8srtbbr \\?\globalroot\systemroot\system32\H8SRTixdjkwkpql.dll
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@imagepath \systemroot\system32\drivers\H8SRTjtnaoykmvm.sys
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTd \\?\globalroot\systemroot\system32\drivers\H8SRTjtnaoykmvm.sys
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTc \\?\globalroot\systemroot\system32\H8SRTlkbwsndrgo.dll
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTsrcr \\?\globalroot\systemroot\system32\H8SRTxumltehhbm.dat
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@h8srtserf \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@h8srtbbr \\?\globalroot\systemroot\system32\H8SRTixdjkwkpql.dll

—- EOF - GMER 1.0.15 —-


Computer Name: DANANDBARB
Current User Name: Dan Miller
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - F:\Documents and Settings\Dan Miller\My Documents\OTL.exe (OldTimer Tools)
PRC - F:\Program Files\SUPERAntiSpyware\8a924459-05f3-41e8-848d-af5e0bd2d781.exe (SUPERAntiSpyware.com)
PRC - F:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - F:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - F:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - F:\WINDOWS\MXOALDR.EXE (Cypress Semiconductor)
PRC - F:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - F:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - F:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - F:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - F:\Program Files\Common Files\AOL\1237308355\ee\aolsoftware.exe (AOL LLC)
PRC - F:\Program Files\Common Files\AOL\1237308355\ee\AOLDesktop.exe (AOL LLC)
PRC - F:\WINDOWS\system32\CtHelper.exe (Creative Technology Ltd)
PRC - F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - F:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - F:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
PRC - F:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
PRC - F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe ()
PRC - F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe (Adobe Systems Incorporated)
PRC - F:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe (Maxtor Corporation)
PRC - F:\Program Files\Dantz\Retrospect Express HD\RetroExpress.exe (Dantz Development Corporation)
PRC - F:\Program Files\Dantz\Retrospect Express HD\retrorun.exe (Dantz Development Corporation)
PRC - F:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe (American Power Conversion Corporation)
PRC - F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
PRC - F:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)


========== Modules (SafeList) ==========

MOD - F:\Documents and Settings\Dan Miller\My Documents\OTL.exe (OldTimer Tools)
MOD - F:\WINDOWS\system32\ctagent.dll (Creative Technology Ltd)
MOD - F:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - F:\Program Files\ScanSoft\OmniPageSE\ophook32.dll (ScanSoft, Inc)


========== Win32 Services (SafeList) ==========

SRV - (JavaQuickStarterService) – F:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (gusvc) – F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (TomTomHOMEService) – F:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (AntiVirService) – F:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (iPod Service) – F:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (PCPitstop Scheduling) – F:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (Apple Mobile Device) – F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AntiVirSchedulerService) – F:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (NVSvc) – F:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Bonjour Service) – F:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (hpqcxs08) – F:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (Pml Driver HPZ12) – F:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (Net Driver HPZ12) – F:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (hpqddsvc) – F:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (AOL ACS) – F:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (AdobeActiveFileMonitor5.0) – F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe ()
SRV - (IDriverT) – F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (RetroExpLauncher) – F:\Program Files\Dantz\Retrospect Express HD\retrorun.exe (Dantz Development Corporation)
SRV - (ose) – F:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (APC UPS Service) – F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)


========== Driver Services (SafeList) ==========

DRV - (avgntflt) – F:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (MBAMSwissArmy) – F:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (SASDIFSV) – F:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – F:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – F:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (ssmdrv) – F:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) – F:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (GEARAspiWDM) – F:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (PxHelp20) – F:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ASCTRM) – F:\WINDOWS\system32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (nv) – F:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (avgio) – F:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (hap17v2k) – F:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – F:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – F:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – F:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – F:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – F:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – F:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctdvda2k) – F:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – F:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – F:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTERFXFX.SYS) – F:\WINDOWS\System32\drivers\CTERFXFX.SYS (Creative Technology Ltd)
DRV - (CTERFXFX) – F:\WINDOWS\system32\drivers\CTERFXFX.sys (Creative Technology Ltd)
DRV - (CTSBLFX.SYS) – F:\WINDOWS\System32\drivers\CTSBLFX.SYS (Creative Technology Ltd)
DRV - (CTSBLFX) – F:\WINDOWS\system32\drivers\CTSBLFX.sys (Creative Technology Ltd)
DRV - (CTAUDFX.SYS) – F:\WINDOWS\System32\drivers\CTAUDFX.SYS (Creative Technology Ltd)
DRV - (CTAUDFX) – F:\WINDOWS\system32\drivers\CTAUDFX.sys (Creative Technology Ltd)
DRV - (COMMONFX.SYS) – F:\WINDOWS\System32\drivers\COMMONFX.SYS (Creative Technology Ltd)
DRV - (COMMONFX) – F:\WINDOWS\system32\drivers\COMMONFX.sys (Creative Technology Ltd)
DRV - (Secdrv) – F:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (HPZius12) – F:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HPZipr12) – F:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZid412) – F:\WINDOWS\system32\drivers\HPZid412.sys (HP)
DRV - (BCM43XX) – F:\WINDOWS\system32\drivers\bcmwl5.sys (Broadcom Corporation)
DRV - (MXOPSWD) – F:\WINDOWS\system32\drivers\mxopswd.sys (Maxtor Corp.)
DRV - (MXOFX) USB Storage Adapter FX (MXO) – F:\WINDOWS\system32\drivers\MXOFX.SYS (Cypress Semiconductor)
DRV - (GTNDIS5) – F:\WINDOWS\system32\GTNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (Ptilink) – F:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (E100B) Intel® – F:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (wanatw) WAN Miniport (ATW) – F:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (OMCI) – F:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (MODEMCSA) – F:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (SONYPVU1) Sony USB Filter Driver (SONYPVU1) – F:\WINDOWS\system32\drivers\SONYPVU1.SYS (Sony Corporation)
DRV - (HidBatt) – F:\WINDOWS\system32\drivers\hidbatt.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com
IE - HKCU\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


[2009/07/18 10:24:27 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Mozilla\Extensions
[2009/07/18 10:24:27 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Mozilla\Extensions\[removed]

O1 HOSTS File: (734 bytes) - F:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (IEToolbarBHO Class) - {1A1DAC8C-074D-440F-8707-7009A672D7D1} - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedInIEToolbar.dll (LinkedIn)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - F:\Program Files\AVG\AVG9\avgssie.dll File not found
O2 - BHO: (AOL Toolbar Loader) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - F:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - F:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (LinkedIn Toolbar) - {BB670D0B-5C46-40C7-B38B-40DD26987723} - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedInIEToolbar.dll (LinkedIn)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (LinkedIn Toolbar) - {BB670D0B-5C46-40C7-B38B-40DD26987723} - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedInIEToolbar.dll (LinkedIn)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [Adobe Photo Downloader] F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] F:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] F:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CTHelper] F:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [HostManager] F:\Program Files\Common Files\AOL\1237308355\ee\aolsoftware.exe (AOL LLC)
O4 - HKLM..\Run: [HP Software Update] F:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [MaxtorOneTouch] F:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe (Maxtor Corporation)
O4 - HKLM..\Run: [MXOBG] F:\WINDOWS\MXOALDR.EXE (Cypress Semiconductor)
O4 - HKLM..\Run: [NvCplDaemon] F:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] F:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] F:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [Omnipage] F:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)
O4 - HKLM..\Run: [QuickTime Task] F:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RetroExpress] F:\Program Files\Dantz\Retrospect Express HD\RetroExpress.exe (Dantz Development Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] F:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] F:\Program Files\SUPERAntiSpyware\8a924459-05f3-41e8-848d-af5e0bd2d781.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk = F:\Program Files\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)
O4 - Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\AOL Desktop.lnk = F:\Program Files\Common Files\AOL\Launch\aollaunch.exe (AOL LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &AOL; Toolbar Search - F:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Linked&In; Search - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedinIEToolbar.dll (LinkedIn)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - F:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1237306142784 (WUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://intercall.webex.com/client/T26L10NS…bex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/da2/PCPitStop2.cab (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - F:\Program Files\AVG\AVG9\avgpp.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - F:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - F:\Program Files\SUPERAntiSpyware\SASWINLO.dll - F:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - F:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/16 16:49:43 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{7545388f-13f9-11de-b1df-00038a000015}\Shell\AutoRun\command - "" = G:\wd_windows_tools\WDSetup.exe – File not found
O33 - MountPoints2\{acf46578-eccc-11de-b370-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{acf46578-eccc-11de-b370-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{acf46578-eccc-11de-b370-00038a000015}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{acf46579-eccc-11de-b370-00038a000015}\Shell\AutoRun\command - "" = H:\setupSNK.exe – File not found
O33 - MountPoints2\{d1fc906c-73ae-11de-b29c-00038a000015}\Shell\AutoRun\command - "" = G:\InstallTomTomHOME.exe – File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2009/12/30 14:17:11 | 00,513,536 | —- | C] (OldTimer Tools) – F:\Documents and Settings\Dan Miller\My Documents\OTL.exe
[2009/12/30 14:10:17 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\gmer
[2009/12/30 11:46:56 | 00,000,000 | —D | C] – F:\Program Files\Trend Micro
[2009/12/30 10:55:14 | 00,096,104 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\avipbb.sys
[2009/12/30 10:55:14 | 00,056,816 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\avgntflt.sys
[2009/12/30 10:55:14 | 00,045,416 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\avgntdd.sys
[2009/12/30 10:55:14 | 00,022,360 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\avgntmgr.sys
[2009/12/30 10:55:13 | 00,028,520 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\ssmdrv.sys
[2009/12/30 10:55:12 | 00,000,000 | —D | C] – F:\Program Files\Avira
[2009/12/30 10:55:12 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Application Data\Avira
[2009/12/30 10:29:46 | 00,000,000 | —D | M] – F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/12/30 10:10:00 | 00,000,000 | –SD | M] – F:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/12/30 10:10:00 | 00,000,000 | –SD | M] – F:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/12/30 10:10:00 | 00,000,000 | —D | M] – F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/12/30 07:49:44 | 00,000,000 | —D | C] – F:\Program Files\AxBx
[2009/12/30 07:27:23 | 00,000,000 | RH-D | C] – F:\Documents and Settings\Dan Miller\Recent
[2009/12/30 07:25:21 | 00,000,000 | —D | C] – F:\Program Files\CCleaner
[2009/12/30 07:24:42 | 03,357,024 | —- | C] (Piriform Ltd) – F:\Documents and Settings\Dan Miller\My Documents\ccsetup227.exe
[2009/12/30 05:22:00 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Application Data\avg9
[2009/12/30 04:26:26 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/12/30 04:22:08 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\SUPERAntiSpyware.com
[2009/12/30 04:22:08 | 00,000,000 | —D | C] – F:\Program Files\SUPERAntiSpyware
[2009/12/29 18:26:19 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\AVG8
[2009/12/29 18:26:10 | 00,891,248 | —- | C] (AVG Technologies) – F:\Documents and Settings\Dan Miller\My Documents\avg_free_stb_all_9_40_cnet.exe
[2009/12/29 08:42:53 | 00,470,528 | —- | C] (Microsoft Corporation) – F:\WINDOWS\System32\dllcache\aclayers.dll
[2009/12/29 08:41:44 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – F:\WINDOWS\System32\javaws.exe
[2009/12/29 08:41:44 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – F:\WINDOWS\System32\javaw.exe
[2009/12/29 08:41:44 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – F:\WINDOWS\System32\java.exe
[2009/12/19 13:31:45 | 00,000,000 | —D | C] – F:\Program Files\Common Files\SWF Studio
[2009/12/19 13:31:18 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\U3
[2009/12/18 17:22:41 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\Pictures for Mom
[2009/12/14 08:10:18 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\Adobe
[2009/12/14 08:02:11 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Documents\Adobe PDF
[2009/12/13 19:49:46 | 00,000,000 | R–D | C] – F:\Documents and Settings\Dan Miller\My Documents\My Videos
[2009/12/11 12:22:14 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\ScheduleOCR Output
[2009/12/11 12:22:14 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\ScheduleOCR Input
[2009/12/09 14:08:55 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2009/12/09 14:08:49 | 00,000,000 | —D | C] – F:\Program Files\TweetDeck
[2009/12/03 17:19:23 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\CensusTestingSitesHtfdWinter2009
[2009/03/17 11:46:53 | 00,000,000 | —D | M] – F:\Documents and Settings\LocalService\Local Settings\Application Data\AOL
[2008/06/27 17:26:00 | 00,010,752 | —- | C] ( ) – F:\WINDOWS\System32\a3d.dll
[7 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp -> ]
[6 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ]
[3 F:\Documents and Settings\Dan Miller\My Documents\*.tmp files -> F:\Documents and Settings\Dan Miller\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2009/12/30 14:26:23 | 00,000,199 | —- | M] () – F:\WINDOWS\System32\srcr.dat
[2009/12/30 14:23:47 | 00,212,641 | —- | M] () – F:\WINDOWS\System32\nvapps.xml
[2009/12/30 14:23:00 | 00,000,006 | -H– | M] () – F:\WINDOWS\tasks\SA.DAT
[2009/12/30 14:22:55 | 00,002,048 | –S- | M] () – F:\WINDOWS\bootstat.dat
[2009/12/30 14:17:14 | 00,513,536 | —- | M] (OldTimer Tools) – F:\Documents and Settings\Dan Miller\My Documents\OTL.exe
[2009/12/30 14:12:34 | 00,293,376 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\q5zuyknf.exe
[2009/12/30 14:08:06 | 00,284,915 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\gmer.zip
[2009/12/30 14:04:39 | 00,525,946 | —- | M] () – F:\WINDOWS\System32\PerfStringBackup.INI
[2009/12/30 14:04:39 | 00,444,028 | —- | M] () – F:\WINDOWS\System32\perfh009.dat
[2009/12/30 14:04:39 | 00,071,904 | —- | M] () – F:\WINDOWS\System32\perfc009.dat
[2009/12/30 14:02:04 | 00,000,988 | —- | M] () – F:\WINDOWS\win.ini
[2009/12/30 11:46:56 | 00,001,734 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\HijackThis.lnk
[2009/12/30 11:10:27 | 00,056,816 | —- | M] (Avira GmbH) – F:\WINDOWS\System32\drivers\avgntflt.sys
[2009/12/30 11:02:11 | 05,767,168 | -H– | M] () – F:\Documents and Settings\Dan Miller\NTUSER.DAT
[2009/12/30 11:02:11 | 00,030,912 | —- | M] () – F:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 11:02:11 | 00,030,120 | —- | M] () – F:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 11:02:11 | 00,030,120 | —- | M] () – F:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 11:02:11 | 00,011,564 | —- | M] () – F:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 11:02:10 | 00,030,912 | —- | M] () – F:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 11:01:55 | 04,958,588 | —- | M] () – F:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.CDF
[2009/12/30 11:01:55 | 04,958,588 | —- | M] () – F:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.BAK
[2009/12/30 10:55:27 | 00,001,707 | —- | M] () – F:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2009/12/30 08:28:16 | 00,008,640 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_082754.reg
[2009/12/30 07:35:42 | 00,071,042 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073444.reg
[2009/12/30 07:34:31 | 00,061,044 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073302.reg
[2009/12/30 07:32:39 | 00,018,652 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073045.reg
[2009/12/30 07:25:22 | 00,001,548 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\CCleaner.lnk
[2009/12/30 07:24:50 | 03,357,024 | —- | M] (Piriform Ltd) – F:\Documents and Settings\Dan Miller\My Documents\ccsetup227.exe
[2009/12/30 06:35:29 | 00,891,248 | —- | M] (AVG Technologies) – F:\Documents and Settings\Dan Miller\My Documents\avg_free_stb_all_9_40_cnet.exe
[2009/12/30 04:22:10 | 00,000,780 | —- | M] () – F:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/12/30 04:20:51 | 00,000,675 | —- | M] () – F:\WINDOWS\System32\krl32mainweq.dll
[2009/12/29 14:26:00 | 00,000,472 | —- | M] () – F:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/12/29 14:17:55 | 00,000,696 | —- | M] () – F:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/29 13:52:45 | 00,000,278 | -HS- | M] () – F:\Documents and Settings\Dan Miller\ntuser.ini
[2009/12/29 08:42:40 | 00,002,422 | —- | M] () – F:\WINDOWS\System32\wpa.dbl
[2009/12/28 22:31:34 | 00,000,008 | —- | M] () – F:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2009/12/18 13:03:10 | 00,131,072 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Legal_Drinking_Age_-_Generational_shifts 2.xls
[2009/12/18 12:57:19 | 00,131,072 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Legal Drinking Age - Generational shifts.xls
[2009/12/18 10:28:54 | 00,026,624 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\people born by year.xls
[2009/12/17 08:21:43 | 00,002,497 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\Microsoft Office Word 2003.lnk
[2009/12/16 15:01:33 | 02,418,688 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\tiger.pps
[2009/12/15 19:07:00 | 34,650,112 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 6.doc
[2009/12/15 17:26:43 | 00,001,076 | —- | M] () – F:\WINDOWS\System32\settingsbkup.sfm
[2009/12/15 17:26:43 | 00,001,076 | —- | M] () – F:\WINDOWS\System32\settings.sfm
[2009/12/14 15:52:03 | 00,026,624 | —- | M] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/14 15:01:10 | 00,090,128 | —- | M] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/12/14 14:59:09 | 00,313,968 | —- | M] () – F:\WINDOWS\System32\FNTCACHE.DAT
[2009/12/14 13:35:22 | 00,025,600 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Letter to Mother.doc
[2009/12/14 11:48:24 | 34,648,576 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 5.doc
[2009/12/14 11:37:15 | 34,650,624 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 4.doc
[2009/12/14 11:24:07 | 34,651,648 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 3.doc
[2009/12/14 10:56:22 | 34,651,136 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 2.doc
[2009/12/14 10:38:31 | 34,652,160 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 1.doc
[2009/12/14 10:11:36 | 03,434,269 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Barb and Dan for Xmas cards 2009.jpg
[2009/12/14 08:02:18 | 00,000,988 | —- | M] () – F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\Adobe Gamma.lnk
[2009/12/14 08:01:41 | 00,001,882 | —- | M] () – F:\Documents and Settings\All Users\Desktop\Adobe Premiere Elements 3.0.lnk
[2009/12/14 07:59:41 | 00,053,248 | —- | M] () – F:\WINDOWS\System32\pxhpinst.exe
[2009/12/13 11:30:20 | 04,402,988 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Dan & Barb Xmas shot.JPG
[2009/12/12 19:20:07 | 01,620,362 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\lourcey.jpg
[2009/12/12 16:06:24 | 00,002,483 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\Microsoft Office PowerPoint 2003.lnk
[2009/12/11 12:22:24 | 01,647,104 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Gingerbread house.doc
[2009/12/09 14:08:51 | 00,000,640 | —- | M] () – F:\Documents and Settings\All Users\Desktop\TweetDeck.lnk
[2009/12/09 14:08:17 | 02,652,400 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\TweetDeck_0_32.1.air
[2009/12/03 17:19:23 | 00,963,023 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\CensusTestingSitesHtfdWinter2009.zip
[2009/12/03 16:14:06 | 00,038,224 | —- | M] (Malwarebytes Corporation) – F:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/12/03 16:13:56 | 00,019,160 | —- | M] (Malwarebytes Corporation) – F:\WINDOWS\System32\drivers\mbam.sys
[2009/12/01 20:11:41 | 00,015,360 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Santini Letter.xls
[2009/12/01 20:00:00 | 00,002,495 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\Microsoft Office Excel 2003.lnk
[2009/12/01 19:48:18 | 00,024,064 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Letter for Santini.doc
[2009/12/01 18:30:10 | 00,074,240 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\DanMiller_Resume.doc
[2009/12/01 11:24:35 | 00,089,088 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\CaputoValueProp.pps
[2009/12/01 11:14:39 | 00,232,448 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Value Added Discussions.doc
[2009/12/01 10:08:28 | 00,122,412 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\2009Friends-Family.pdf
[2009/12/01 08:57:17 | 00,064,592 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\NST-EST2008-alldata.csv
[7 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp -> ]
[6 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ]
[3 F:\Documents and Settings\Dan Miller\My Documents\*.tmp files -> F:\Documents and Settings\Dan Miller\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2009/12/30 14:26:23 | 00,000,199 | —- | C] () – F:\WINDOWS\System32\srcr.dat
[2009/12/30 14:12:31 | 00,293,376 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\q5zuyknf.exe
[2009/12/30 14:08:04 | 00,284,915 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\gmer.zip
[2009/12/30 11:46:56 | 00,001,734 | —- | C] () – F:\Documents and Settings\Dan Miller\Desktop\HijackThis.lnk
[2009/12/30 10:55:27 | 00,001,707 | —- | C] () – F:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2009/12/30 08:27:55 | 00,008,640 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_082754.reg
[2009/12/30 07:38:00 | 04,958,588 | —- | C] () – F:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.BAK
[2009/12/30 07:34:45 | 00,071,042 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073444.reg
[2009/12/30 07:33:04 | 00,061,044 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073302.reg
[2009/12/30 07:30:49 | 00,018,652 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073045.reg
[2009/12/30 07:25:22 | 00,001,548 | —- | C] () – F:\Documents and Settings\Dan Miller\Desktop\CCleaner.lnk
[2009/12/30 04:22:10 | 00,000,780 | —- | C] () – F:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/12/30 04:20:51 | 00,000,675 | —- | C] () – F:\WINDOWS\System32\krl32mainweq.dll
[2009/12/28 22:31:34 | 00,000,008 | —- | C] () – F:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2009/12/18 13:03:07 | 00,131,072 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Legal_Drinking_Age_-_Generational_shifts 2.xls
[2009/12/18 10:41:48 | 00,131,072 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Legal Drinking Age - Generational shifts.xls
[2009/12/16 15:01:27 | 02,418,688 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\tiger.pps
[2009/12/14 18:12:06 | 34,650,112 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 6.doc
[2009/12/14 13:01:14 | 00,025,600 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Letter to Mother.doc
[2009/12/14 11:39:25 | 34,648,576 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 5.doc
[2009/12/14 11:24:13 | 34,650,624 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 4.doc
[2009/12/14 10:59:43 | 34,651,648 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 3.doc
[2009/12/14 10:38:36 | 34,651,136 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 2.doc
[2009/12/14 10:14:50 | 34,652,160 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 1.doc
[2009/12/14 10:11:33 | 03,434,269 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Barb and Dan for Xmas cards 2009.jpg
[2009/12/14 08:02:18 | 00,000,988 | —- | C] () – F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\Adobe Gamma.lnk
[2009/12/14 08:01:41 | 00,001,882 | —- | C] () – F:\Documents and Settings\All Users\Desktop\Adobe Premiere Elements 3.0.lnk
[2009/12/13 11:28:04 | 04,402,988 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Dan & Barb Xmas shot.JPG
[2009/12/12 19:21:50 | 01,620,362 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\lourcey.jpg
[2009/12/11 12:22:21 | 01,647,104 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Gingerbread house.doc
[2009/12/09 14:08:10 | 02,652,400 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\TweetDeck_0_32.1.air
[2009/12/03 17:19:20 | 00,963,023 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\CensusTestingSitesHtfdWinter2009.zip
[2009/12/01 20:02:40 | 00,015,360 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Santini Letter.xls
[2009/12/01 19:48:17 | 00,024,064 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Letter for Santini.doc
[2009/12/01 11:24:32 | 00,089,088 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\CaputoValueProp.pps
[2009/12/01 11:14:38 | 00,232,448 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Value Added Discussions.doc
[2009/12/01 10:08:28 | 00,122,412 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\2009Friends-Family.pdf
[2009/12/01 09:46:01 | 00,026,624 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\people born by year.xls
[2009/12/01 08:57:10 | 00,064,592 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\NST-EST2008-alldata.csv
[2009/08/15 10:40:36 | 00,005,957 | —- | C] () – F:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/07/28 10:10:06 | 00,038,460 | —- | C] () – F:\Documents and Settings\Dan Miller\Application Data\Microsoft Excel.ADR
[2009/07/18 11:53:35 | 00,025,713 | —- | C] () – F:\WINDOWS\CSTBox.INI
[2009/07/18 11:41:31 | 00,040,960 | —- | C] () – F:\WINDOWS\System32\IPPCPUID.DLL
[2009/07/18 11:41:31 | 00,000,105 | —- | C] () – F:\WINDOWS\UMXADDIN.INI
[2009/07/18 11:41:31 | 00,000,091 | —- | C] () – F:\WINDOWS\PM20.INI
[2009/07/18 11:41:15 | 00,011,776 | —- | C] () – F:\WINDOWS\System32\pmsbfn32.dll
[2009/07/18 11:40:36 | 00,000,074 | —- | C] () – F:\WINDOWS\PMINI.ini
[2009/07/18 10:45:45 | 00,000,525 | —- | C] () – F:\WINDOWS\MAXLINK.INI
[2009/04/07 17:24:56 | 00,000,133 | —- | C] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\fusioncache.dat
[2009/03/31 18:44:13 | 00,008,704 | —- | C] () – F:\WINDOWS\System32\CNMVS7D.DLL
[2009/03/18 19:32:35 | 00,026,624 | —- | C] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/17 11:58:25 | 00,012,288 | —- | C] () – F:\WINDOWS\System32\e100bmsg.dll
[2009/03/16 19:22:40 | 00,094,208 | —- | C] () – F:\WINDOWS\System32\GTW32N50.dll
[2009/03/16 17:01:49 | 00,000,376 | —- | C] () – F:\WINDOWS\ODBC.INI
[2009/02/18 14:44:00 | 01,724,416 | —- | C] () – F:\WINDOWS\System32\nvwdmcpl.dll
[2009/02/18 14:44:00 | 01,507,328 | —- | C] () – F:\WINDOWS\System32\nview.dll
[2009/02/18 14:44:00 | 01,101,824 | —- | C] () – F:\WINDOWS\System32\nvwimg.dll
[2009/02/18 14:44:00 | 00,466,944 | —- | C] () – F:\WINDOWS\System32\nvshell.dll
[2008/06/27 18:05:08 | 00,049,565 | —- | C] () – F:\WINDOWS\System32\instwdm.ini
[2008/06/27 18:05:06 | 00,000,054 | —- | C] () – F:\WINDOWS\System32\ctzapxx.ini
[2008/06/27 17:27:54 | 00,043,520 | —- | C] () – F:\WINDOWS\System32\CTBurst.dll
[2007/08/13 20:45:02 | 00,077,824 | —- | C] () – F:\WINDOWS\System32\ctmmactl.dll
[2006/10/02 17:25:18 | 00,000,307 | —- | C] () – F:\WINDOWS\System32\kill.ini
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – F:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2009/08/31 23:19:04 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\Age of Empires 3 XPack Trial
[2009/10/03 23:39:38 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\Age of Empires 3 YPack Trial
[2009/12/30 11:42:15 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\avg9
[2009/03/31 18:44:18 | 00,000,000 | -H-D | M] – F:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/03/17 12:14:39 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\DriverScanner
[2009/03/18 19:21:28 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\espionServerData
[2009/08/15 16:45:22 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\Geek Squad
[2009/08/15 14:00:28 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\PCPitstop
[2009/12/30 14:26:42 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\RetroExp
[2009/07/18 10:52:18 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/08/02 10:53:21 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\Sony
[2009/07/18 10:52:34 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2009/07/18 11:11:40 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\SSScanWizard
[2009/07/18 10:24:40 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\TomTom
[2009/03/17 11:46:19 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/18 13:42:28 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/03/17 12:14:00 | 00,000,000 | -H-D | M] – F:\Documents and Settings\All Users\Application Data\{66E2F539-12B6-4870-A500-7689CDE75C5E}
[2009/04/07 14:57:29 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/10/30 16:51:19 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Acapela Group
[2009/03/17 11:47:21 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\acccore
[2009/07/18 13:18:46 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Canon
[2009/03/17 12:17:25 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/04/28 14:07:31 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\FoxPlayerAIR.01F2E49DE175CC541F416F2DF78BDD5E63AD0096.1
[2009/04/24 17:30:51 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\LinkedIn
[2009/09/25 09:01:09 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Opera
[2009/08/02 10:56:21 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Publish Providers
[2009/07/18 10:45:46 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\ScanSoft
[2009/08/02 11:01:26 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Sony
[2009/08/02 10:46:27 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Sony Setup
[2009/07/18 10:24:22 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\TomTom
[2009/06/29 14:53:29 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2009/12/09 14:08:55 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2009/03/17 12:13:59 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Uniblue
[2009/06/09 07:40:45 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Viewpoint
[2009/05/26 08:19:41 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\webex
[2009/10/02 11:44:20 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\WinPatrol
[2009/10/30 16:51:30 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Xtranormal
[2009/12/29 14:26:00 | 00,000,472 | —- | M] () – F:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

========== Purity Check ==========


< End of report >


OTL Extras logfile created on: 12/30/2009 2:25:16 PM - Run 1
OTL by OldTimer - Version 3.1.20.1 Folder = F:\Documents and Settings\Dan Miller\My Documents
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 81.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): f:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = F: | %SystemRoot% = F:\WINDOWS | %ProgramFiles% = F:\Program Files
Drive C: | 149.05 Gb Total Space | 28.22 Gb Free Space | 18.94% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 931.50 Gb Total Space | 869.95 Gb Free Space | 93.39% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DANANDBARB
Current User Name: Dan Miller
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "F:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome File not found
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 File not found
htmlfile [print] – "F:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome File not found
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "F:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "F:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"F:\Program Files\Dantz\Retrospect Express HD\RetroExpress.exe" = F:\Program Files\Dantz\Retrospect Express HD\RetroExpress.exe:*:Disabled: – (Dantz Development Corporation)
"F:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = F:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialer – (AOL LLC)
"F:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = F:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL Connectivity Service – (AOL LLC)
"F:\Program Files\Common Files\AOL\1237308355\ee\aolsoftware.exe" = F:\Program Files\Common Files\AOL\1237308355\ee\aolsoftware.exe:*:Enabled:AOL Shared Components – (AOL LLC)
"F:\Program Files\Common Files\AOL\Loader\aolload.exe" = F:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"F:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe" = F:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL Topspeed – (AOL LLC)
"F:\Program Files\Common Files\AOL\1237308355\ee\AOLDesktop.exe" = F:\Program Files\Common Files\AOL\1237308355\ee\AOLDesktop.exe:*:Enabled:AOL Desktop – (AOL LLC)
"F:\Documents and Settings\Dan Miller\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = F:\Documents and Settings\Dan Miller\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"F:\Program Files\iTunes\iTunes.exe" = F:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"F:\Program Files\TomTom HOME 2\xulrunner\TomTomHOMERuntime.exe" = F:\Program Files\TomTom HOME 2\xulrunner\TomTomHOMERuntime.exe:*:Enabled:TomTom HOME – (Mozilla Foundation)
"F:\Program Files\Microsoft Games\Age of Empires II Trial\EMPIRES2.EXE" = F:\Program Files\Microsoft Games\Age of Empires II Trial\EMPIRES2.EXE:*:Disabled:Age of Empires II – File not found
"F:\Program Files\BitTorrent\bittorrent.exe" = F:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – File not found
"F:\Documents and Settings\Dan Miller\Local Settings\Temp\StateInstaller.exe" = F:\Documents and Settings\Dan Miller\Local Settings\Temp\StateInstaller.exe:*:Enabled:Xtranormal State – (Xtranormal)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{03F1CC67-5BD8-4C36-8394-76311B2AE69A}" = ArcSoft PhotoStudio 5
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{1596D886-C831-4192-AFC6-8A8027CC895F}" = iPod mini Software Updater 1.0
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1E88F516-C8AA-4D17-9A54-8AB0768F34C1}" = Retrospect Express HD 1.0
"{1EB321CB-3D1D-4cf2-ACB5-9F20874B8E69}" = HP Officejet Pro All-In-One Series
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{231F68F4-70E4-41A6-BEDA-7E7934169B54}" = Maxtor OneTouch
"{25569723-DC5A-4467-A639-79535BF01B71}" = Adobe Help Center 2.1
"{25F3BD52-7D3E-4265-A36C-70F09854D720}" = iPod mini 1.0 for Windows User Guide
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 17
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}" = BPDSoftware_Ini
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}" = BPD_HPSU
"{530AFAFF-6F0A-48BB-88D0-04F9658322D3}" = Adobe Premiere Elements 3.0
"{580183A6-FF92-11D5-9294-0050BA073EEC}" = Presto! PageManager 6
"{5A0C892E-FD1C-4203-941E-0956AED20A6A}" = APC PowerChute Personal Edition
"{6249C22D-E6A8-407B-BA8B-40298848ED94}" = OmniPage SE
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6EACDDF4-4220-49A3-9204-984C86852C3D}" = Adobe Premiere Elements 3.0 Templates
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83E5FE05-31F4-FA91-BB29-3D987008BA49}" = TweetDeck
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8868D822-2CBA-46B2-A286-B400B6185769}" = 7500_7600_7700_Help
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{8F968232-15C6-4872-84C2-9FCDAA1AEAB6}" = MPM
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{9455959E-D588-EFAE-329C-F66CC797F32A}" = Adobe Media Player
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{97E038E1-41AD-4C93-BCDC-6A2394AEE352}" = Vegas Movie Studio Platinum 9.0b
"{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}" = iTunes
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A495D4DC-4036-4914-9CB2-0FCF6A3166EF}" = L7500
"{A7B609FB-83D8-4FC3-8477-1BC65ECFE85B}" = Adobe Photoshop Elements 5.0
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.3
"{B7C7A59F-CF70-481E-A94F-7C2563AA5ADD}" = Sony DVD Architect Studio 4.5
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{BF953F1A-F946-4804-875D-94B6A6C05CE1}" = Business Card Factory Deluxe 3.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1D14C0D-FDAA-4DF2-8441-A902805CCE8C}" = ArcSoft PhotoBase 3
"{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}" = Apple Mobile Device Support
"{C427E746-4EC9-4E3C-AACB-C6BB1F714D7F}" = Uniblue DriverScanner 2009
"{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}" = Microsoft Plus! Digital Media Edition
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{D9261CAB-3E1D-423C-9DD6-2001056DA292}" = Manual CanoScan 5000,5000F,8000F
"{DEB9AEF7-3ADA-40a9-9C98-546D54FE9CBD}" = ProductContext
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop Elements 5" = Adobe Photoshop Elements 5.0
"AOL Regclient" = AOL Registration
"AOL Toolbar" = AOL Toolbar for Internet Explorer
"AOL Toolbar for Firefox" = AOL Toolbar for Firefox
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AolCoach" = AOL Coach Version 1.0(Build:20020823.1)
"AudioConSole" = Creative Audio Console
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2702" = Conexant SmartHSFi V92 56K Speakerphone PCI Modem
"DriverGuide DriverScan" = DriverGuide DriverScan
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"ie8" = Windows Internet Explorer 8 Release Candidate 1
"InstallShield_{1596D886-C831-4192-AFC6-8A8027CC895F}" = iPod mini Software Updater 1.0
"InstallShield_{231F68F4-70E4-41A6-BEDA-7E7934169B54}" = Maxtor OneTouch
"InstallShield_{25F3BD52-7D3E-4265-A36C-70F09854D720}" = iPod mini 1.0 for Windows User Guide
"LinkedIn Internet Explorer Toolbar" = LinkedIn Internet Explorer Toolbar
"LinkedIn Outlook Toolbar" = LinkedIn Outlook Toolbar
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Multi Virus Cleaner 2009_is1" = Multi Virus Cleaner 2009
"MXOFX" = USB Storage Adapter FX (MXO)
"NVIDIA Drivers" = NVIDIA Drivers
"PC Pitstop Driver Alert2_is1" = PC Pitstop Driver Alert2 2.0.0.0
"PC Pitstop Optimize3_is1" = PC Pitstop Optimize3 3.0
"PremElem30" = Adobe Premiere Elements 3.0
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer Basic
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SystemRequirementsLab" = System Requirements Lab
"TomTom HOME" = TomTom HOME 2.7.2.1825
"Uniblue DriverScanner 2009" = Uniblue DriverScanner 2009
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 2
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Media Player" = Move Media Player
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/30/2009 12:03:27 PM | Computer Name = DANANDBARB | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 12/30/2009 3:00:03 PM | Computer Name = DANANDBARB | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 12/30/2009 3:23:42 PM | Computer Name = DANANDBARB | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

[ System Events ]
Error - 12/30/2009 3:02:30 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.

Error - 12/30/2009 3:02:30 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053

Error - 12/30/2009 3:25:13 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Avira AntiVir Scheduler
service to connect.

Error - 12/30/2009 3:25:13 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7000
Description = The Avira AntiVir Scheduler service failed to start due to the following
error: %%1053

Error - 12/30/2009 3:25:13 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Avira AntiVir Guard service
to connect.

Error - 12/30/2009 3:25:13 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7000
Description = The Avira AntiVir Guard service failed to start due to the following
error: %%1053

Error - 12/30/2009 3:25:48 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 12/30/2009 3:25:48 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 12/30/2009 3:26:19 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.

Error - 12/30/2009 3:26:19 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053


< End of report >
Hi Dan Miller,

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3 CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log. How's the computer?

Thanks
Oldman960, thanks for helping me on this journey. I downloaded ComboFix.exe to my files and when I doubleclick..I get a few seconds of the hour glass…and then nothing. Nothing seems to be running in the background and no software appears on my screen. FYI…I did turn off Super Anti-SpyWare on the lower right. Hoping you can assist. Dan
Hi Dan Miller,

Ok, let's do it this way.

Locate combofix.exe on your desktop, right click it and select delete.

Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Link 1
Link 2
to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to jgh.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe (jgh.exe in your case) & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log
How is the computer?

Thanks
Oldman960, per your request…combofix log below. It did stall and ask for a reboot mid-stream. I believe it mentioned the presence of rootkit activity. Came back on and and went thru various staging and checks. Also deleted 4-5 files and a folder. After another reboot, this is what came back to me. I'm not certain if things are good now; however I was able to move around IE explorer a bit to get to this sight without being frozen. :) I look forward to hearing from you. Cheers, Dan

ComboFix 09-12-29.06 - Dan Miller 12/30/2009 15:41:29.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2047.1691 [GMT -5:00]
Running from: f:\documents and settings\[removed]\My Documents\jgh.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

f:\program files\Common Files\Uninstall
f:\windows\system32\drivers\H8SRTjtnaoykmvm.sys
f:\windows\system32\H8SRTbuiqrbcjlq.dll
f:\windows\system32\H8SRTixdjkwkpql.dll
f:\windows\system32\H8SRTlkbwsndrgo.dll
f:\windows\system32\H8SRTxumltehhbm.dat
f:\windows\system32\krl32mainweq.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_H8SRTd.sys
——-\Legacy_H8SRTd.sys


((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-30 )))))))))))))))))))))))))))))))
.

2009-12-30 16:46 . 2009-12-30 16:46 ——– d—–w- f:\program files\Trend Micro
2009-12-30 15:55 . 2009-12-30 16:10 56816 —-a-w- f:\windows\system32\drivers\avgntflt.sys
2009-12-30 15:55 . 2009-03-30 14:33 96104 —-a-w- f:\windows\system32\drivers\avipbb.sys
2009-12-30 15:55 . 2009-02-13 16:29 22360 —-a-w- f:\windows\system32\drivers\avgntmgr.sys
2009-12-30 15:55 . 2009-02-13 16:17 45416 —-a-w- f:\windows\system32\drivers\avgntdd.sys
2009-12-30 15:55 . 2009-12-30 15:55 ——– d—–w- f:\program files\Avira
2009-12-30 15:55 . 2009-12-30 15:55 ——– d—–w- f:\documents and settings\All Users\Application Data\Avira
2009-12-30 15:03 . 2009-12-30 15:03 ——– d-sh–w- f:\documents and settings\Administrator.DANANDBARB\PrivacIE
2009-12-30 15:03 . 2009-12-30 15:03 ——– d-sh–w- f:\documents and settings\Administrator.DANANDBARB\IETldCache
2009-12-30 14:57 . 2009-12-30 14:57 ——– d—–w- f:\documents and settings\Administrator.DANANDBARB\Application Data\U3
2009-12-30 12:49 . 2009-12-30 12:49 ——– d—–w- f:\program files\AxBx
2009-12-30 12:25 . 2009-12-30 12:25 ——– d—–w- f:\program files\CCleaner
2009-12-30 10:22 . 2009-12-30 16:42 ——– d—–w- f:\documents and settings\All Users\Application Data\avg9
2009-12-30 09:27 . 2009-12-30 09:27 52224 —-a-w- f:\documents and settings\Dan Miller\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-30 09:27 . 2009-12-30 09:27 117760 —-a-w- f:\documents and settings\Dan Miller\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-30 09:26 . 2009-12-30 09:26 ——– d—–w- f:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-12-30 09:22 . 2009-12-30 11:26 ——– d—–w- f:\program files\SUPERAntiSpyware
2009-12-30 09:22 . 2009-12-30 09:22 ——– d—–w- f:\documents and settings\Dan Miller\Application Data\SUPERAntiSpyware.com
2009-12-30 09:06 . 2009-12-30 09:06 ——– d-sh–w- f:\windows\system32\config\systemprofile\IETldCache
2009-12-29 23:26 . 2009-12-29 23:26 ——– d—–w- f:\documents and settings\Dan Miller\Application Data\AVG8
2009-12-29 13:42 . 2009-11-21 16:36 470528 -c—-w- f:\windows\system32\dllcache\aclayers.dll
2009-12-29 13:41 . 2009-12-29 13:41 152576 —-a-w- f:\documents and settings\Dan Miller\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-19 18:31 . 2006-05-24 18:36 110592 —-a-w- f:\documents and settings\Dan Miller\Application Data\U3\temp\cleanup.exe
2009-12-19 18:31 . 2009-12-19 18:31 ——– d—–w- f:\program files\Common Files\SWF Studio
2009-12-19 18:31 . 2009-12-29 01:05 ——– d—–w- f:\documents and settings\Dan Miller\Application Data\U3
2009-12-09 19:08 . 2009-12-09 19:08 ——– d—–w- f:\documents and settings\Dan Miller\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
2009-12-09 19:08 . 2009-12-09 19:08 ——– d—–w- f:\program files\TweetDeck
2009-12-04 18:50 . 2009-12-04 18:50 79488 —-a-w- f:\documents and settings\Barb Emery\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-30 20:38 . 2009-04-07 22:23 ——– d—–w- f:\documents and settings\All Users\Application Data\RetroExp
2009-12-30 16:42 . 2009-03-18 16:38 ——– d—–w- f:\program files\AVG
2009-12-30 16:42 . 2009-03-18 16:38 ——– d—–w- f:\documents and settings\All Users\Application Data\avg8
2009-12-30 15:58 . 2009-12-30 18:53 144278 —-a-w- f:\windows\PCHealth\HelpCtr\Config\Cache\Personal_32_1033.dat
2009-12-30 09:21 . 2009-03-17 16:21 ——– d—–w- f:\program files\Common Files\Wise Installation Wizard
2009-12-29 21:21 . 2009-09-04 16:59 ——– d—–w- f:\program files\Malwarebytes' Anti-Malware
2009-12-29 18:51 . 2009-03-17 19:25 ——– d—–w- f:\program files\Lavasoft
2009-12-29 17:45 . 2009-04-28 15:57 ——– d—–w- f:\program files\Citrix
2009-12-29 13:41 . 2009-05-19 18:15 ——– d—–w- f:\program files\Java
2009-12-29 13:41 . 2009-11-24 11:58 79488 —-a-w- f:\documents and settings\Dan Miller\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-14 20:01 . 2009-03-17 17:51 90128 —-a-w- f:\documents and settings\Dan Miller\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-14 13:02 . 2009-03-16 22:43 ——– d—–w- f:\program files\Common Files\Adobe
2009-12-03 21:14 . 2009-09-04 16:59 38224 —-a-w- f:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 21:13 . 2009-09-04 16:59 19160 —-a-w- f:\windows\system32\drivers\mbam.sys
2009-11-28 18:03 . 2009-03-16 22:14 ——– d—–w- f:\documents and settings\Dan Miller\Application Data\MSN6
2009-11-21 16:36 . 2003-07-16 20:23 470528 —-a-w- f:\windows\AppPatch\aclayers.dll
2009-11-17 14:14 . 2009-11-17 14:14 20299200 —-a-w- f:\documents and settings\Dan Miller\Application Data\TomTom\HOME\Profiles\iqvztyf1.default\Updates\v2_7_3_1894_win.exe
2009-11-05 21:43 . 2009-11-05 21:43 593920 —-a-w- f:\documents and settings\Dan Miller\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv305hw-0910190-0-main.dll
2009-11-03 04:33 . 2009-11-24 12:22 899944 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\waol-0.4337.155.1.exe
2009-11-03 04:11 . 2009-11-24 12:22 3858056 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\Vwpt.exe
2009-11-03 04:11 . 2009-11-24 12:22 49152 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\AOLVPChk.dll
2009-11-03 04:11 . 2009-11-24 12:22 61440 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\VPPrePop.exe
2009-11-03 04:11 . 2009-11-24 12:22 607392 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\wbsetup.exe
2009-11-03 04:11 . 2009-11-24 12:22 57344 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\tsverchk.dll
2009-11-03 04:11 . 2009-11-24 12:22 49152 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\Dacldll.dll
2009-11-03 04:10 . 2009-11-24 12:22 1878296 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\aol_toolbar.exe
2009-11-03 04:10 . 2009-11-24 12:22 6144 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\tbinst.dll
2009-11-03 04:10 . 2009-11-24 12:22 404568 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\tbsetup.exe
2009-11-03 04:10 . 2009-11-24 12:22 711104 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\SinfInst.exe
2009-11-03 04:10 . 2009-11-24 12:22 54832 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\AOLParconLink.exe
2009-11-03 04:10 . 2009-11-24 12:22 45056 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\SiNdInst.dll
2009-11-03 04:10 . 2009-11-24 12:22 845814 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\muinst.exe
2009-11-03 04:09 . 2009-11-24 12:22 1362936 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\msvc9rt.exe
2009-11-03 04:09 . 2009-11-24 12:22 109552 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\aolSearch.exe
2009-11-03 04:09 . 2009-11-24 12:22 289960 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\aolDailyScoop.exe
2009-11-03 04:08 . 2009-11-24 12:22 1962544 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\flashax.exe
2009-11-03 04:08 . 2009-11-24 12:22 470600 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\dtbsetup.exe
2009-11-03 04:08 . 2009-11-24 12:22 188176 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\dtblpins.exe
2009-11-03 04:07 . 2009-11-24 12:22 2396152 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\dskcorlp.exe
2009-11-03 04:07 . 2009-11-24 12:22 339808 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\dskcore.exe
2009-11-03 04:04 . 2009-11-24 12:22 3346592 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\ocpinst.exe
2009-11-03 04:04 . 2009-11-24 12:22 21296 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\acsshutd.exe
2009-11-03 04:04 . 2009-11-24 12:22 74536 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\acscompsinstSup.dll
2009-11-03 04:04 . 2009-11-24 12:22 62248 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\ocpgc.exe
2009-11-03 04:04 . 2009-11-24 12:22 15144 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\ocpchk.dll
2009-11-03 04:04 . 2009-11-24 12:22 148232 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\acsrollb.exe
2009-11-03 04:04 . 2009-11-24 12:22 1613832 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\acslang.exe
2009-11-03 04:03 . 2009-11-24 12:22 964440 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\acslaeu.exe
2009-11-03 04:03 . 2009-11-24 12:22 37680 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\AcsInstC.dll
2009-11-03 04:03 . 2009-11-24 12:22 45872 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\acscompsAcsInstA.dll
2009-11-03 04:03 . 2009-11-24 12:22 45872 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\AcsInstA.dll
2009-11-03 04:03 . 2009-11-24 12:22 1480888 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\acscore.exe
2009-10-27 21:44 . 2009-03-20 00:22 89464 —-a-w- f:\documents and settings\Barb Emery\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-21 06:00 . 2004-08-04 07:56 75776 —-a-w- f:\windows\system32\strmfilt.dll
2009-10-21 06:00 . 2004-08-04 07:56 25088 —-a-w- f:\windows\system32\httpapi.dll
2009-10-20 14:58 . 2004-08-04 06:00 263552 —-a-w- f:\windows\system32\drivers\http.sys
2009-10-14 17:40 . 2009-08-15 18:20 149260 —-a-w- f:\windows\hpwins05.dat
2009-10-13 10:53 . 2006-05-14 09:13 266752 —-a-w- f:\windows\system32\oakley.dll
2009-10-12 13:54 . 2003-07-16 20:42 112128 —-a-w- f:\windows\system32\rastls.dll
2009-10-12 13:54 . 2003-07-16 20:42 69632 —-a-w- f:\windows\system32\raschap.dll
2009-10-11 09:17 . 2009-06-29 11:09 411368 —-a-w- f:\windows\system32\deploytk.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="f:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="f:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-29 39408]
"SUPERAntiSpyware"="f:\program files\SUPERAntiSpyware\8a924459-05f3-41e8-848d-af5e0bd2d781.exe" [2009-11-23 2001648]
"ctfmon.exe"="f:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="f:\program files\Common Files\AOL\1237308355\ee\AOLSoftware.exe" [2008-11-06 41264]
"Adobe Reader Speed Launcher"="f:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"NvCplDaemon"="f:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"nwiz"="nwiz.exe" [2009-02-18 1657376]
"NvMediaCenter"="f:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"CTHelper"="CTHELPER.EXE" [2008-06-27 19456]
"Adobe Photo Downloader"="f:\program files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 61440]
"MaxtorOneTouch"="f:\program files\Maxtor\OneTouch\utils\Onetouch.exe" [2004-12-22 823296]
"RetroExpress"="f:\progra~1\Dantz\RETROS~1\RetroExpress.exe" [2004-07-30 6946816]
"MXOBG"="f:\windows\MXOALDR.EXE" [2009-04-07 94208]
"QuickTime Task"="f:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"Omnipage"="f:\program files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 49152]
"HP Software Update"="f:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"SunJavaUpdateSched"="f:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"avgnt"="f:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

f:\documents and settings\Dan Miller\Start Menu\Programs\Startup\
Adobe Gamma.lnk - f:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
AOL Desktop.lnk - f:\program files\Common Files\AOL\Launch\aollaunch.exe [2008-6-24 41824]

f:\documents and settings\All Users\Start Menu\Programs\Startup\
APC UPS Status.lnk - f:\program files\APC\APC PowerChute Personal Edition\Display.exe [2009-3-16 209005]
HP Digital Imaging Monitor.lnk - f:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "f:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 —-a-w- f:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"f:\\Program Files\\Dantz\\Retrospect Express HD\\RetroExpress.exe"=
"f:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"f:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"f:\\Program Files\\Common Files\\AOL\\1237308355\\ee\\aolsoftware.exe"=
"f:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"f:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"f:\\Program Files\\Common Files\\AOL\\1237308355\\ee\\AOLDesktop.exe"=
"f:\\Documents and Settings\\Dan Miller\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"f:\\Program Files\\iTunes\\iTunes.exe"=
"f:\\Program Files\\TomTom HOME 2\\xulrunner\\TomTomHOMERuntime.exe"=

R1 SASDIFSV;SASDIFSV;f:\program files\SUPERAntiSpyware\sasdifsv.sys [11/23/2009 8:43 AM 9968]
R1 SASKUTIL;SASKUTIL;f:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/23/2009 8:43 AM 74480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;f:\program files\Avira\AntiVir Desktop\sched.exe [12/30/2009 10:55 AM 108289]
R2 TomTomHOMEService;TomTomHOMEService;f:\program files\TomTom HOME 2\TomTomHOMEService.exe [8/27/2009 10:05 AM 92008]
R3 COMMONFX.SYS;COMMONFX.SYS;f:\windows\system32\drivers\COMMONFX.sys [6/27/2008 7:21 PM 99352]
R3 CTAUDFX.SYS;CTAUDFX.SYS;f:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 7:21 PM 555032]
R3 CTSBLFX.SYS;CTSBLFX.SYS;f:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 7:21 PM 566296]
R3 SASENUM;SASENUM;f:\program files\SUPERAntiSpyware\SASENUM.SYS [11/23/2009 8:43 AM 7408]
S0 Lbd;Lbd;f:\windows\system32\DRIVERS\Lbd.sys –> f:\windows\system32\DRIVERS\Lbd.sys [?]
S3 COMMONFX;COMMONFX;f:\windows\system32\drivers\COMMONFX.sys [6/27/2008 7:21 PM 99352]
S3 CTAUDFX;CTAUDFX;f:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 7:21 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;f:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 7:21 PM 100888]
S3 CTERFXFX;CTERFXFX;f:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 7:21 PM 100888]
S3 CTSBLFX;CTSBLFX;f:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 7:21 PM 566296]
S3 MBAMSwissArmy;MBAMSwissArmy;f:\windows\system32\drivers\mbamswissarmy.sys [9/4/2009 11:59 AM 38224]
S4 PCPitstop Scheduling;PCPitstop Scheduling;f:\program files\PCPitstop\PCPitstopScheduleService.exe [8/15/2009 1:55 PM 85504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.cnn.com
uInternet Settings,ProxyOverride = *.local
IE: &AOL; Toolbar Search - f:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
IE: &Search;
IE: E&xport; to Microsoft Excel - f:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Linked&In; Search - f:\program files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedinIEToolbar.dll/ContextMenu.htm
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-30 15:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(884)
f:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(2244)
f:\program files\ScanSoft\OmniPageSE\ophook32.dll
f:\windows\system32\ieframe.dll
f:\windows\system32\webcheck.dll
f:\windows\system32\WPDShServiceObj.dll
f:\windows\system32\PortableDeviceTypes.dll
f:\windows\system32\PortableDeviceApi.dll
f:\program files\SUPERAntiSpyware\SASSEH.DLL
f:\windows\system32\browselc.dll
f:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
———————— Other Running Processes ————————
.
f:\program files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
f:\program files\Avira\AntiVir Desktop\avguard.exe
f:\program files\APC\APC PowerChute Personal Edition\mainserv.exe
f:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
f:\program files\Bonjour\mDNSResponder.exe
f:\program files\Java\jre6\bin\jqs.exe
f:\windows\system32\nvsvc32.exe
f:\windows\system32\RUNDLL32.EXE
f:\program files\Common Files\AOL\1237308355\ee\AOLDesktop.exe
f:\program files\APC\APC PowerChute Personal Edition\apcsystray.exe
f:\program files\Common Files\AOL\ACS\AOLacsd.exe
f:\windows\system32\wscntfy.exe
f:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
f:\program files\HP\Digital Imaging\bin\hpqbam08.exe
f:\progra~1\Dantz\RETROS~1\retrospect.exe
f:\progra~1\Dantz\RETROS~1\retrorun.exe
.
**************************************************************************
.
Completion time: 2009-12-30 15:55:12 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-30 20:55

Pre-Run: 933,928,132,608 bytes free
Post-Run: 937,815,355,392 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(1)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - B46B66FB64F5257D3820203EA9A5AF9E
Hi Dan Miller,

Running from: f:\documents and settings\Dan Miller\My Documents\jgh.exe


It's important that combofix be directly on the DeskTop, otherwise some routines will not work.

Open Windows Explorer (right click your start button and click explore)
-Navigate to this folder f:\documents and settings\Dan Miller\My Documents, click on it
-Move the slider in the left panel up so you can see the folder named DeskTop.
-In the right hand panel locate jgh.exe
-Right click on it and hold the mouse button down
-Drag the file to the Desktop folder in the left panel
-Let go of the mouse button and click Move here.

Next

Click your Start button > Add/Remove programs and uninstall

Java™ 6 Update 7

Do not uninstall Java™ 6 Update 17

Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Next

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad windows. OTL.Txt, no Extra.txt this time.

Please post back with
  • MBAM log
  • OTL.txt
Thanks

Thanks
Oldman960, per your request. MBAM log and OLT.txt results. If can't begin to tell you how much I appreciate your time and help with this matter. If I'm lucky enough to be in a good position with my system…please let me know what I can do to repay you the favor.

Malwarebytes' Anti-Malware 1.43
Database version: 3459
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18372

12/30/2009 5:09:35 PM
mbam-log-2009-12-30 (17-09-35).txt

Scan type: Quick Scan
Objects scanned: 137071
Time elapsed: 5 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




OTL logfile created on: 12/30/2009 5:17:18 PM - Run 2
OTL by OldTimer - Version 3.1.20.1 Folder = F:\Documents and Settings\Dan Miller\My Documents
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 75.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): f:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = F: | %SystemRoot% = F:\WINDOWS | %ProgramFiles% = F:\Program Files
Drive C: | 149.05 Gb Total Space | 28.22 Gb Free Space | 18.93% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 931.50 Gb Total Space | 873.52 Gb Free Space | 93.77% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DANANDBARB
Current User Name: Dan Miller
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - F:\Documents and Settings\Dan Miller\My Documents\OTL.exe (OldTimer Tools)
PRC - F:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - F:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - F:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - F:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - F:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - F:\WINDOWS\MXOALDR.EXE (Cypress Semiconductor)
PRC - F:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - F:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - F:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - F:\Program Files\Common Files\AOL\1237308355\ee\aolsoftware.exe (AOL LLC)
PRC - F:\Program Files\Common Files\AOL\1237308355\ee\AOLDesktop.exe (AOL LLC)
PRC - F:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard Co.)
PRC - F:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)
PRC - F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - F:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - F:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
PRC - F:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
PRC - F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe ()
PRC - F:\Program Files\Dantz\Retrospect Express HD\RetroExpress.exe (Dantz Development Corporation)
PRC - F:\Program Files\Dantz\Retrospect Express HD\Retrospect.exe (Dantz Development Corporation)
PRC - F:\Program Files\Dantz\Retrospect Express HD\retrorun.exe (Dantz Development Corporation)
PRC - F:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe (American Power Conversion Corporation)
PRC - F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
PRC - F:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)


========== Modules (SafeList) ==========

MOD - F:\Documents and Settings\Dan Miller\My Documents\OTL.exe (OldTimer Tools)
MOD - F:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - F:\Program Files\ScanSoft\OmniPageSE\ophook32.dll (ScanSoft, Inc)


========== Win32 Services (SafeList) ==========

SRV - (JavaQuickStarterService) – F:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (gusvc) – F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (TomTomHOMEService) – F:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (AntiVirService) – F:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (iPod Service) – F:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (PCPitstop Scheduling) – F:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (Apple Mobile Device) – F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AntiVirSchedulerService) – F:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (NVSvc) – F:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Bonjour Service) – F:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (hpqcxs08) – F:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (Pml Driver HPZ12) – F:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (Net Driver HPZ12) – F:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (hpqddsvc) – F:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (AOL ACS) – F:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (AdobeActiveFileMonitor5.0) – F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe ()
SRV - (IDriverT) – F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (RetroExpLauncher) – F:\Program Files\Dantz\Retrospect Express HD\retrorun.exe (Dantz Development Corporation)
SRV - (ose) – F:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (APC UPS Service) – F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)


========== Driver Services (SafeList) ==========

DRV - (catchme) – File not found
DRV - (avgntflt) – F:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (SASDIFSV) – F:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – F:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – F:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (ssmdrv) – F:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) – F:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (GEARAspiWDM) – F:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (PxHelp20) – F:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ASCTRM) – F:\WINDOWS\system32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (nv) – F:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (avgio) – F:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (hap17v2k) – F:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – F:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – F:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – F:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – F:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – F:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – F:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctdvda2k) – F:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – F:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – F:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTERFXFX.SYS) – F:\WINDOWS\System32\drivers\CTERFXFX.SYS (Creative Technology Ltd)
DRV - (CTERFXFX) – F:\WINDOWS\system32\drivers\CTERFXFX.sys (Creative Technology Ltd)
DRV - (CTSBLFX.SYS) – F:\WINDOWS\System32\drivers\CTSBLFX.SYS (Creative Technology Ltd)
DRV - (CTSBLFX) – F:\WINDOWS\system32\drivers\CTSBLFX.sys (Creative Technology Ltd)
DRV - (CTAUDFX.SYS) – F:\WINDOWS\System32\drivers\CTAUDFX.SYS (Creative Technology Ltd)
DRV - (CTAUDFX) – F:\WINDOWS\system32\drivers\CTAUDFX.sys (Creative Technology Ltd)
DRV - (COMMONFX.SYS) – F:\WINDOWS\System32\drivers\COMMONFX.SYS (Creative Technology Ltd)
DRV - (COMMONFX) – F:\WINDOWS\system32\drivers\COMMONFX.sys (Creative Technology Ltd)
DRV - (Secdrv) – F:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (HPZius12) – F:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HPZipr12) – F:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZid412) – F:\WINDOWS\system32\drivers\HPZid412.sys (HP)
DRV - (BCM43XX) – F:\WINDOWS\system32\drivers\bcmwl5.sys (Broadcom Corporation)
DRV - (MXOPSWD) – F:\WINDOWS\system32\drivers\mxopswd.sys (Maxtor Corp.)
DRV - (MXOFX) USB Storage Adapter FX (MXO) – F:\WINDOWS\system32\drivers\MXOFX.SYS (Cypress Semiconductor)
DRV - (GTNDIS5) – F:\WINDOWS\system32\GTNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (Ptilink) – F:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (E100B) Intel® – F:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (wanatw) WAN Miniport (ATW) – F:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (OMCI) – F:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (MODEMCSA) – F:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (SONYPVU1) Sony USB Filter Driver (SONYPVU1) – F:\WINDOWS\system32\drivers\SONYPVU1.SYS (Sony Corporation)
DRV - (HidBatt) – F:\WINDOWS\system32\drivers\hidbatt.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com
IE - HKCU\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


[2009/07/18 10:24:27 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Mozilla\Extensions
[2009/07/18 10:24:27 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Mozilla\Extensions\[removed]

O1 HOSTS File: (27 bytes) - F:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (IEToolbarBHO Class) - {1A1DAC8C-074D-440F-8707-7009A672D7D1} - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedInIEToolbar.dll (LinkedIn)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - F:\Program Files\AVG\AVG9\avgssie.dll File not found
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AOL Toolbar Loader) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - F:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - F:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (LinkedIn Toolbar) - {BB670D0B-5C46-40C7-B38B-40DD26987723} - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedInIEToolbar.dll (LinkedIn)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (LinkedIn Toolbar) - {BB670D0B-5C46-40C7-B38B-40DD26987723} - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedInIEToolbar.dll (LinkedIn)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [Adobe Photo Downloader] F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] F:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] F:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CTHelper] F:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [HostManager] F:\Program Files\Common Files\AOL\1237308355\ee\aolsoftware.exe (AOL LLC)
O4 - HKLM..\Run: [HP Software Update] F:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [MaxtorOneTouch] F:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe (Maxtor Corporation)
O4 - HKLM..\Run: [MXOBG] F:\WINDOWS\MXOALDR.EXE (Cypress Semiconductor)
O4 - HKLM..\Run: [NvCplDaemon] F:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] F:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] F:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [Omnipage] F:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)
O4 - HKLM..\Run: [QuickTime Task] F:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RetroExpress] F:\Program Files\Dantz\Retrospect Express HD\RetroExpress.exe (Dantz Development Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] F:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] F:\Program Files\SUPERAntiSpyware\8a924459-05f3-41e8-848d-af5e0bd2d781.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] F:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk = F:\Program Files\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)
O4 - Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\AOL Desktop.lnk = F:\Program Files\Common Files\AOL\Launch\aollaunch.exe (AOL LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &AOL; Toolbar Search - F:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Linked&In; Search - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedinIEToolbar.dll (LinkedIn)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre6\bin\npjpi160_17.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - F:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1237306142784 (WUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://intercall.webex.com/client/T26L10NS…bex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/da2/PCPitStop2.cab (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - F:\Program Files\AVG\AVG9\avgpp.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - F:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - F:\Program Files\SUPERAntiSpyware\SASWINLO.dll - F:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - F:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/16 16:49:43 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2009/12/30 15:27:30 | 00,212,480 | —- | C] (SteelWerX) – F:\WINDOWS\SWXCACLS.exe
[2009/12/30 15:27:30 | 00,161,792 | —- | C] (SteelWerX) – F:\WINDOWS\SWREG.exe
[2009/12/30 15:27:30 | 00,136,704 | —- | C] (SteelWerX) – F:\WINDOWS\SWSC.exe
[2009/12/30 15:27:30 | 00,031,232 | —- | C] (NirSoft) – F:\WINDOWS\NIRCMD.exe
[2009/12/30 15:27:02 | 00,000,000 | —D | C] – F:\WINDOWS\ERDNT
[2009/12/30 15:25:46 | 00,000,000 | —D | C] – F:\Qoobox
[2009/12/30 14:17:11 | 00,513,536 | —- | C] (OldTimer Tools) – F:\Documents and Settings\Dan Miller\My Documents\OTL.exe
[2009/12/30 14:10:17 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\gmer
[2009/12/30 11:46:56 | 00,000,000 | —D | C] – F:\Program Files\Trend Micro
[2009/12/30 10:55:14 | 00,096,104 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\avipbb.sys
[2009/12/30 10:55:14 | 00,056,816 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\avgntflt.sys
[2009/12/30 10:55:14 | 00,045,416 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\avgntdd.sys
[2009/12/30 10:55:14 | 00,022,360 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\avgntmgr.sys
[2009/12/30 10:55:13 | 00,028,520 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\ssmdrv.sys
[2009/12/30 10:55:12 | 00,000,000 | —D | C] – F:\Program Files\Avira
[2009/12/30 10:55:12 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Application Data\Avira
[2009/12/30 10:29:46 | 00,000,000 | —D | M] – F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/12/30 10:10:00 | 00,000,000 | –SD | M] – F:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/12/30 10:10:00 | 00,000,000 | –SD | M] – F:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/12/30 10:10:00 | 00,000,000 | —D | M] – F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/12/30 07:27:23 | 00,000,000 | RH-D | C] – F:\Documents and Settings\Dan Miller\Recent
[2009/12/30 07:25:21 | 00,000,000 | —D | C] – F:\Program Files\CCleaner
[2009/12/30 07:24:42 | 03,357,024 | —- | C] (Piriform Ltd) – F:\Documents and Settings\Dan Miller\My Documents\ccsetup227.exe
[2009/12/30 05:22:00 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Application Data\avg9
[2009/12/30 04:26:26 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/12/30 04:22:08 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\SUPERAntiSpyware.com
[2009/12/30 04:22:08 | 00,000,000 | —D | C] – F:\Program Files\SUPERAntiSpyware
[2009/12/29 18:26:19 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\AVG8
[2009/12/29 18:26:10 | 00,891,248 | —- | C] (AVG Technologies) – F:\Documents and Settings\Dan Miller\My Documents\avg_free_stb_all_9_40_cnet.exe
[2009/12/29 08:42:53 | 00,470,528 | —- | C] (Microsoft Corporation) – F:\WINDOWS\System32\dllcache\aclayers.dll
[2009/12/29 08:41:44 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – F:\WINDOWS\System32\javaws.exe
[2009/12/29 08:41:44 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – F:\WINDOWS\System32\javaw.exe
[2009/12/29 08:41:44 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – F:\WINDOWS\System32\java.exe
[2009/12/19 13:31:45 | 00,000,000 | —D | C] – F:\Program Files\Common Files\SWF Studio
[2009/12/19 13:31:18 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\U3
[2009/12/18 17:22:41 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\Pictures for Mom
[2009/12/14 08:10:18 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\Adobe
[2009/12/14 08:02:11 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Documents\Adobe PDF
[2009/12/13 19:49:46 | 00,000,000 | R–D | C] – F:\Documents and Settings\Dan Miller\My Documents\My Videos
[2009/12/11 12:22:14 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\ScheduleOCR Output
[2009/12/11 12:22:14 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\ScheduleOCR Input
[2009/12/09 14:08:55 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2009/12/09 14:08:49 | 00,000,000 | —D | C] – F:\Program Files\TweetDeck
[2009/12/03 17:19:23 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\CensusTestingSitesHtfdWinter2009
[2009/03/17 11:46:53 | 00,000,000 | —D | M] – F:\Documents and Settings\LocalService\Local Settings\Application Data\AOL
[2008/06/27 17:26:00 | 00,010,752 | —- | C] ( ) – F:\WINDOWS\System32\a3d.dll
[7 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp -> ]
[6 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ]
[3 F:\Documents and Settings\Dan Miller\My Documents\*.tmp files -> F:\Documents and Settings\Dan Miller\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2009/12/30 15:54:38 | 00,525,946 | —- | M] () – F:\WINDOWS\System32\PerfStringBackup.INI
[2009/12/30 15:54:38 | 00,444,028 | —- | M] () – F:\WINDOWS\System32\perfh009.dat
[2009/12/30 15:54:38 | 00,071,904 | —- | M] () – F:\WINDOWS\System32\perfc009.dat
[2009/12/30 15:51:02 | 00,000,227 | —- | M] () – F:\WINDOWS\system.ini
[2009/12/30 15:51:00 | 04,958,588 | —- | M] () – F:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.CDF
[2009/12/30 15:51:00 | 04,958,588 | —- | M] () – F:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.BAK
[2009/12/30 15:50:53 | 00,212,641 | —- | M] () – F:\WINDOWS\System32\nvapps.xml
[2009/12/30 15:50:41 | 00,000,027 | —- | M] () – F:\WINDOWS\System32\drivers\etc\hosts
[2009/12/30 15:50:22 | 00,000,006 | -H– | M] () – F:\WINDOWS\tasks\SA.DAT
[2009/12/30 15:50:20 | 00,002,048 | –S- | M] () – F:\WINDOWS\bootstat.dat
[2009/12/30 15:49:44 | 05,767,168 | -H– | M] () – F:\Documents and Settings\Dan Miller\NTUSER.DAT
[2009/12/30 15:49:44 | 00,030,912 | —- | M] () – F:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 15:49:44 | 00,030,912 | —- | M] () – F:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 15:49:44 | 00,030,120 | —- | M] () – F:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 15:49:44 | 00,030,120 | —- | M] () – F:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 15:49:44 | 00,011,564 | —- | M] () – F:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 15:25:24 | 03,877,972 | R— | M] () – F:\Documents and Settings\Dan Miller\Desktop\jgh.exe
[2009/12/30 14:55:24 | 00,038,224 | —- | M] (Malwarebytes Corporation) – F:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/12/30 14:54:58 | 00,019,160 | —- | M] (Malwarebytes Corporation) – F:\WINDOWS\System32\drivers\mbam.sys
[2009/12/30 14:29:16 | 00,000,988 | —- | M] () – F:\WINDOWS\win.ini
[2009/12/30 14:17:14 | 00,513,536 | —- | M] (OldTimer Tools) – F:\Documents and Settings\Dan Miller\My Documents\OTL.exe
[2009/12/30 14:12:34 | 00,293,376 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\q5zuyknf.exe
[2009/12/30 14:08:06 | 00,284,915 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\gmer.zip
[2009/12/30 11:46:56 | 00,001,734 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\HijackThis.lnk
[2009/12/30 11:10:27 | 00,056,816 | —- | M] (Avira GmbH) – F:\WINDOWS\System32\drivers\avgntflt.sys
[2009/12/30 10:55:27 | 00,001,707 | —- | M] () – F:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2009/12/30 08:28:16 | 00,008,640 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_082754.reg
[2009/12/30 07:35:42 | 00,071,042 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073444.reg
[2009/12/30 07:34:31 | 00,061,044 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073302.reg
[2009/12/30 07:32:39 | 00,018,652 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073045.reg
[2009/12/30 07:25:22 | 00,001,548 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\CCleaner.lnk
[2009/12/30 07:24:50 | 03,357,024 | —- | M] (Piriform Ltd) – F:\Documents and Settings\Dan Miller\My Documents\ccsetup227.exe
[2009/12/30 06:35:29 | 00,891,248 | —- | M] (AVG Technologies) – F:\Documents and Settings\Dan Miller\My Documents\avg_free_stb_all_9_40_cnet.exe
[2009/12/30 04:22:10 | 00,000,780 | —- | M] () – F:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/12/29 14:17:55 | 00,000,696 | —- | M] () – F:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/29 13:52:45 | 00,000,278 | -HS- | M] () – F:\Documents and Settings\Dan Miller\ntuser.ini
[2009/12/29 08:42:40 | 00,002,422 | —- | M] () – F:\WINDOWS\System32\wpa.dbl
[2009/12/28 22:31:34 | 00,000,008 | —- | M] () – F:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2009/12/18 13:03:10 | 00,131,072 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Legal_Drinking_Age_-_Generational_shifts 2.xls
[2009/12/18 12:57:19 | 00,131,072 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Legal Drinking Age - Generational shifts.xls
[2009/12/18 10:28:54 | 00,026,624 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\people born by year.xls
[2009/12/17 08:21:43 | 00,002,497 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\Microsoft Office Word 2003.lnk
[2009/12/16 15:01:33 | 02,418,688 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\tiger.pps
[2009/12/15 19:07:00 | 34,650,112 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 6.doc
[2009/12/15 17:26:43 | 00,001,076 | —- | M] () – F:\WINDOWS\System32\settingsbkup.sfm
[2009/12/15 17:26:43 | 00,001,076 | —- | M] () – F:\WINDOWS\System32\settings.sfm
[2009/12/14 15:52:03 | 00,026,624 | —- | M] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/14 15:01:10 | 00,090,128 | —- | M] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/12/14 14:59:09 | 00,313,968 | —- | M] () – F:\WINDOWS\System32\FNTCACHE.DAT
[2009/12/14 13:35:22 | 00,025,600 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Letter to Mother.doc
[2009/12/14 11:48:24 | 34,648,576 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 5.doc
[2009/12/14 11:37:15 | 34,650,624 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 4.doc
[2009/12/14 11:24:07 | 34,651,648 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 3.doc
[2009/12/14 10:56:22 | 34,651,136 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 2.doc
[2009/12/14 10:38:31 | 34,652,160 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 1.doc
[2009/12/14 10:11:36 | 03,434,269 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Barb and Dan for Xmas cards 2009.jpg
[2009/12/14 08:02:18 | 00,000,988 | —- | M] () – F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\Adobe Gamma.lnk
[2009/12/14 08:01:41 | 00,001,882 | —- | M] () – F:\Documents and Settings\All Users\Desktop\Adobe Premiere Elements 3.0.lnk
[2009/12/14 07:59:41 | 00,053,248 | —- | M] () – F:\WINDOWS\System32\pxhpinst.exe
[2009/12/13 11:30:20 | 04,402,988 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Dan & Barb Xmas shot.JPG
[2009/12/12 19:20:07 | 01,620,362 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\lourcey.jpg
[2009/12/12 16:06:24 | 00,002,483 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\Microsoft Office PowerPoint 2003.lnk
[2009/12/11 12:22:24 | 01,647,104 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Gingerbread house.doc
[2009/12/09 22:54:07 | 00,261,632 | —- | M] () – F:\WINDOWS\PEV.exe
[2009/12/09 14:08:51 | 00,000,640 | —- | M] () – F:\Documents and Settings\All Users\Desktop\TweetDeck.lnk
[2009/12/09 14:08:17 | 02,652,400 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\TweetDeck_0_32.1.air
[2009/12/03 17:19:23 | 00,963,023 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\CensusTestingSitesHtfdWinter2009.zip
[2009/12/01 20:11:41 | 00,015,360 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Santini Letter.xls
[2009/12/01 20:00:00 | 00,002,495 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\Microsoft Office Excel 2003.lnk
[2009/12/01 19:48:18 | 00,024,064 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Letter for Santini.doc
[2009/12/01 18:30:10 | 00,074,240 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\DanMiller_Resume.doc
[2009/12/01 11:24:35 | 00,089,088 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\CaputoValueProp.pps
[2009/12/01 11:14:39 | 00,232,448 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Value Added Discussions.doc
[2009/12/01 10:08:28 | 00,122,412 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\2009Friends-Family.pdf
[2009/12/01 08:57:17 | 00,064,592 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\NST-EST2008-alldata.csv
[7 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp -> ]
[6 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ]
[3 F:\Documents and Settings\Dan Miller\My Documents\*.tmp files -> F:\Documents and Settings\Dan Miller\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2009/12/30 15:27:30 | 00,261,632 | —- | C] () – F:\WINDOWS\PEV.exe
[2009/12/30 15:27:30 | 00,098,816 | —- | C] () – F:\WINDOWS\sed.exe
[2009/12/30 15:27:30 | 00,080,412 | —- | C] () – F:\WINDOWS\grep.exe
[2009/12/30 15:27:30 | 00,077,312 | —- | C] () – F:\WINDOWS\MBR.exe
[2009/12/30 15:27:30 | 00,068,096 | —- | C] () – F:\WINDOWS\zip.exe
[2009/12/30 15:25:15 | 03,877,972 | R— | C] () – F:\Documents and Settings\Dan Miller\Desktop\jgh.exe
[2009/12/30 14:12:31 | 00,293,376 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\q5zuyknf.exe
[2009/12/30 14:08:04 | 00,284,915 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\gmer.zip
[2009/12/30 11:46:56 | 00,001,734 | —- | C] () – F:\Documents and Settings\Dan Miller\Desktop\HijackThis.lnk
[2009/12/30 10:55:27 | 00,001,707 | —- | C] () – F:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2009/12/30 08:27:55 | 00,008,640 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_082754.reg
[2009/12/30 07:38:00 | 04,958,588 | —- | C] () – F:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.BAK
[2009/12/30 07:34:45 | 00,071,042 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073444.reg
[2009/12/30 07:33:04 | 00,061,044 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073302.reg
[2009/12/30 07:30:49 | 00,018,652 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073045.reg
[2009/12/30 07:25:22 | 00,001,548 | —- | C] () – F:\Documents and Settings\Dan Miller\Desktop\CCleaner.lnk
[2009/12/30 04:22:10 | 00,000,780 | —- | C] () – F:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/12/28 22:31:34 | 00,000,008 | —- | C] () – F:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2009/12/18 13:03:07 | 00,131,072 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Legal_Drinking_Age_-_Generational_shifts 2.xls
[2009/12/18 10:41:48 | 00,131,072 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Legal Drinking Age - Generational shifts.xls
[2009/12/16 15:01:27 | 02,418,688 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\tiger.pps
[2009/12/14 18:12:06 | 34,650,112 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 6.doc
[2009/12/14 13:01:14 | 00,025,600 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Letter to Mother.doc
[2009/12/14 11:39:25 | 34,648,576 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 5.doc
[2009/12/14 11:24:13 | 34,650,624 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 4.doc
[2009/12/14 10:59:43 | 34,651,648 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 3.doc
[2009/12/14 10:38:36 | 34,651,136 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 2.doc
[2009/12/14 10:14:50 | 34,652,160 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 1.doc
[2009/12/14 10:11:33 | 03,434,269 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Barb and Dan for Xmas cards 2009.jpg
[2009/12/14 08:02:18 | 00,000,988 | —- | C] () – F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\Adobe Gamma.lnk
[2009/12/14 08:01:41 | 00,001,882 | —- | C] () – F:\Documents and Settings\All Users\Desktop\Adobe Premiere Elements 3.0.lnk
[2009/12/13 11:28:04 | 04,402,988 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Dan & Barb Xmas shot.JPG
[2009/12/12 19:21:50 | 01,620,362 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\lourcey.jpg
[2009/12/11 12:22:21 | 01,647,104 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Gingerbread house.doc
[2009/12/09 14:08:10 | 02,652,400 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\TweetDeck_0_32.1.air
[2009/12/03 17:19:20 | 00,963,023 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\CensusTestingSitesHtfdWinter2009.zip
[2009/12/01 20:02:40 | 00,015,360 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Santini Letter.xls
[2009/12/01 19:48:17 | 00,024,064 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Letter for Santini.doc
[2009/12/01 11:24:32 | 00,089,088 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\CaputoValueProp.pps
[2009/12/01 11:14:38 | 00,232,448 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Value Added Discussions.doc
[2009/12/01 10:08:28 | 00,122,412 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\2009Friends-Family.pdf
[2009/12/01 09:46:01 | 00,026,624 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\people born by year.xls
[2009/12/01 08:57:10 | 00,064,592 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\NST-EST2008-alldata.csv
[2009/08/15 10:40:36 | 00,005,957 | —- | C] () – F:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/07/28 10:10:06 | 00,038,460 | —- | C] () – F:\Documents and Settings\Dan Miller\Application Data\Microsoft Excel.ADR
[2009/07/18 11:53:35 | 00,025,713 | —- | C] () – F:\WINDOWS\CSTBox.INI
[2009/07/18 11:41:31 | 00,040,960 | —- | C] () – F:\WINDOWS\System32\IPPCPUID.DLL
[2009/07/18 11:41:31 | 00,000,105 | —- | C] () – F:\WINDOWS\UMXADDIN.INI
[2009/07/18 11:41:31 | 00,000,091 | —- | C] () – F:\WINDOWS\PM20.INI
[2009/07/18 11:41:15 | 00,011,776 | —- | C] () – F:\WINDOWS\System32\pmsbfn32.dll
[2009/07/18 11:40:36 | 00,000,074 | —- | C] () – F:\WINDOWS\PMINI.ini
[2009/07/18 10:45:45 | 00,000,525 | —- | C] () – F:\WINDOWS\MAXLINK.INI
[2009/04/07 17:24:56 | 00,000,133 | —- | C] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\fusioncache.dat
[2009/03/31 18:44:13 | 00,008,704 | —- | C] () – F:\WINDOWS\System32\CNMVS7D.DLL
[2009/03/18 19:32:35 | 00,026,624 | —- | C] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/17 11:58:25 | 00,012,288 | —- | C] () – F:\WINDOWS\System32\e100bmsg.dll
[2009/03/16 19:22:40 | 00,094,208 | —- | C] () – F:\WINDOWS\System32\GTW32N50.dll
[2009/03/16 17:01:49 | 00,000,376 | —- | C] () – F:\WINDOWS\ODBC.INI
[2009/02/18 14:44:00 | 01,724,416 | —- | C] () – F:\WINDOWS\System32\nvwdmcpl.dll
[2009/02/18 14:44:00 | 01,507,328 | —- | C] () – F:\WINDOWS\System32\nview.dll
[2009/02/18 14:44:00 | 01,101,824 | —- | C] () – F:\WINDOWS\System32\nvwimg.dll
[2009/02/18 14:44:00 | 00,466,944 | —- | C] () – F:\WINDOWS\System32\nvshell.dll
[2008/06/27 18:05:08 | 00,049,565 | —- | C] () – F:\WINDOWS\System32\instwdm.ini
[2008/06/27 18:05:06 | 00,000,054 | —- | C] () – F:\WINDOWS\System32\ctzapxx.ini
[2008/06/27 17:27:54 | 00,043,520 | —- | C] () – F:\WINDOWS\System32\CTBurst.dll
[2007/08/13 20:45:02 | 00,077,824 | —- | C] () – F:\WINDOWS\System32\ctmmactl.dll
[2006/10/02 17:25:18 | 00,000,307 | —- | C] () – F:\WINDOWS\System32\kill.ini
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – F:\WINDOWS\System32\OUTLPERF.INI
< End of report >
Hi Dan Miller,

Help around here is free.

I formerly had AVG 8.5, which I uninstalled. I've been able to to download AVG 9.0, but can't get it activated. The actual error I receive is "Action failed for file avgwdsvc.exe starting service…" I've also attempted to download Avira Antivirus and…that to is unable to be opened.

Avg is not shown as installed and Avira is shown as installed.

Combofix also shows Avira as outdated and disabled.

Let's do this online scan to check our handiwork. We will sort out your antivirus situation afterwards.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.

Thanks
Looking forward to your input. Dan ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, December 30, 2009 Operating system: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, December 30, 2009 23:52:44 Records in database: 3417797 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 157922 Threats found: 1 Infected objects found: 3 Suspicious objects found: 0 Scan duration: 03:00:53 File name / Threat / Threats count F:\Qoobox\Quarantine\F\WINDOWS\system32\H8SRTbuiqrbcjlq.dll.vir Infected: Packed.Win32.TDSS.aa 1 F:\Qoobox\Quarantine\F\WINDOWS\system32\H8SRTixdjkwkpql.dll.vir Infected: Packed.Win32.TDSS.aa 1 F:\Qoobox\Quarantine\F\WINDOWS\system32\H8SRTlkbwsndrgo.dll.vir Infected: Packed.Win32.TDSS.aa 1 Selected area has been scanned.
Hi Dan Miller,

The Kaspersky detections are files we have quarantined. They will be removed when we remove the tools.

We'll cleanup the tools, then work on getting you a working antivirus program.

From your desktop, please delete
  • any notepads/logs that we created
  • GMER.zip
  • Gmer.exe

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /u

We'll keep OTL for the moment.

Go to Add/Remove programs and uninstall

Avira AntiVir Personal - Free Antivirus

It may have been malware blocking AVG9 from installing. You could try installing it again or run the AVG removal tool first to ensure that all traces of the previous version have been removed.

AVG Removal Tool

Download it to your desktop, double click it to run it and follow the prompts.

Try installing AVG9.

Please let us know how you make out. If you recieve an error message, please post the entire message including the code.

Thanks
Avira uninstalled…AVG 9.0 cleaned out and reinstalled. Up and running. Results below are from the combofix. Machine seems to be 100 fold better. Looking forward to hearing from you. Enjoy your New Year's Eve. Dan



ComboFix 09-12-30.04 - Dan Miller 12/31/2009 9:28.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2047.1456 [GMT -5:00]
Running from: f:\docume~1\DANMIL~1\Desktop\jgh.exe
Command switches used :: /u
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-31 )))))))))))))))))))))))))))))))
.

2009-12-30 22:02 . 2009-12-30 22:02 5061520 —-a-w- f:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-30 16:46 . 2009-12-30 16:46 ——– d—–w- f:\program files\Trend Micro
2009-12-30 15:55 . 2009-12-30 16:10 56816 —-a-w- f:\windows\system32\drivers\avgntflt.sys
2009-12-30 15:55 . 2009-03-30 14:33 96104 —-a-w- f:\windows\system32\drivers\avipbb.sys
2009-12-30 15:55 . 2009-02-13 16:29 22360 —-a-w- f:\windows\system32\drivers\avgntmgr.sys
2009-12-30 15:55 . 2009-02-13 16:17 45416 —-a-w- f:\windows\system32\drivers\avgntdd.sys
2009-12-30 15:55 . 2009-12-30 15:55 ——– d—–w- f:\program files\Avira
2009-12-30 15:55 . 2009-12-30 15:55 ——– d—–w- f:\documents and settings\All Users\Application Data\Avira
2009-12-30 15:03 . 2009-12-30 15:03 ——– d-sh–w- f:\documents and settings\Administrator.DANANDBARB\PrivacIE
2009-12-30 15:03 . 2009-12-30 15:03 ——– d-sh–w- f:\documents and settings\Administrator.DANANDBARB\IETldCache
2009-12-30 14:57 . 2009-12-30 14:57 ——– d—–w- f:\documents and settings\Administrator.DANANDBARB\Application Data\U3
2009-12-30 12:25 . 2009-12-30 12:25 ——– d—–w- f:\program files\CCleaner
2009-12-30 10:22 . 2009-12-30 16:42 ——– d—–w- f:\documents and settings\All Users\Application Data\avg9
2009-12-30 09:27 . 2009-12-30 09:27 52224 —-a-w- f:\documents and settings\Dan Miller\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-30 09:27 . 2009-12-30 09:27 117760 —-a-w- f:\documents and settings\Dan Miller\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-30 09:26 . 2009-12-30 09:26 ——– d—–w- f:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-12-30 09:22 . 2009-12-31 02:42 ——– d—–w- f:\program files\SUPERAntiSpyware
2009-12-30 09:22 . 2009-12-30 09:22 ——– d—–w- f:\documents and settings\Dan Miller\Application Data\SUPERAntiSpyware.com
2009-12-30 09:06 . 2009-12-30 09:06 ——– d-sh–w- f:\windows\system32\config\systemprofile\IETldCache
2009-12-29 23:26 . 2009-12-29 23:26 ——– d—–w- f:\documents and settings\Dan Miller\Application Data\AVG8
2009-12-29 13:42 . 2009-11-21 16:36 470528 -c—-w- f:\windows\system32\dllcache\aclayers.dll
2009-12-29 13:41 . 2009-12-29 13:41 152576 —-a-w- f:\documents and settings\Dan Miller\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-19 18:31 . 2006-05-24 18:36 110592 —-a-w- f:\documents and settings\Dan Miller\Application Data\U3\temp\cleanup.exe
2009-12-19 18:31 . 2009-12-19 18:31 ——– d—–w- f:\program files\Common Files\SWF Studio
2009-12-19 18:31 . 2009-12-29 01:05 ——– d—–w- f:\documents and settings\Dan Miller\Application Data\U3
2009-12-09 19:08 . 2009-12-09 19:08 ——– d—–w- f:\documents and settings\Dan Miller\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
2009-12-09 19:08 . 2009-12-09 19:08 ——– d—–w- f:\program files\TweetDeck
2009-12-04 18:50 . 2009-12-04 18:50 79488 —-a-w- f:\documents and settings\Barb Emery\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-31 12:47 . 2009-04-07 22:23 ——– d—–w- f:\documents and settings\All Users\Application Data\RetroExp
2009-12-30 22:02 . 2009-09-04 16:59 ——– d—–w- f:\program files\Malwarebytes' Anti-Malware
2009-12-30 19:55 . 2009-09-04 16:59 38224 —-a-w- f:\windows\system32\drivers\mbamswissarmy.sys
2009-12-30 19:54 . 2009-09-04 16:59 19160 —-a-w- f:\windows\system32\drivers\mbam.sys
2009-12-30 16:42 . 2009-03-18 16:38 ——– d—–w- f:\program files\AVG
2009-12-30 16:42 . 2009-03-18 16:38 ——– d—–w- f:\documents and settings\All Users\Application Data\avg8
2009-12-30 15:58 . 2009-12-30 18:53 144278 —-a-w- f:\windows\PCHealth\HelpCtr\Config\Cache\Personal_32_1033.dat
2009-12-30 09:21 . 2009-03-17 16:21 ——– d—–w- f:\program files\Common Files\Wise Installation Wizard
2009-12-29 18:51 . 2009-03-17 19:25 ——– d—–w- f:\program files\Lavasoft
2009-12-29 17:45 . 2009-04-28 15:57 ——– d—–w- f:\program files\Citrix
2009-12-29 13:41 . 2009-05-19 18:15 ——– d—–w- f:\program files\Java
2009-12-29 13:41 . 2009-11-24 11:58 79488 —-a-w- f:\documents and settings\Dan Miller\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-14 20:01 . 2009-03-17 17:51 90128 —-a-w- f:\documents and settings\Dan Miller\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-14 13:02 . 2009-03-16 22:43 ——– d—–w- f:\program files\Common Files\Adobe
2009-11-28 18:03 . 2009-03-16 22:14 ——– d—–w- f:\documents and settings\Dan Miller\Application Data\MSN6
2009-11-21 16:36 . 2003-07-16 20:23 470528 —-a-w- f:\windows\AppPatch\aclayers.dll
2009-11-17 14:14 . 2009-11-17 14:14 20299200 —-a-w- f:\documents and settings\Dan Miller\Application Data\TomTom\HOME\Profiles\iqvztyf1.default\Updates\v2_7_3_1894_win.exe
2009-11-05 21:43 . 2009-11-05 21:43 593920 —-a-w- f:\documents and settings\Dan Miller\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv305hw-0910190-0-main.dll
2009-11-03 04:33 . 2009-11-24 12:22 899944 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\waol-0.4337.155.1.exe
2009-11-03 04:11 . 2009-11-24 12:22 3858056 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\Vwpt.exe
2009-11-03 04:11 . 2009-11-24 12:22 49152 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\AOLVPChk.dll
2009-11-03 04:11 . 2009-11-24 12:22 61440 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\VPPrePop.exe
2009-11-03 04:11 . 2009-11-24 12:22 607392 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\wbsetup.exe
2009-11-03 04:11 . 2009-11-24 12:22 57344 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\tsverchk.dll
2009-11-03 04:11 . 2009-11-24 12:22 49152 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\Dacldll.dll
2009-11-03 04:10 . 2009-11-24 12:22 1878296 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\aol_toolbar.exe
2009-11-03 04:10 . 2009-11-24 12:22 6144 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\tbinst.dll
2009-11-03 04:10 . 2009-11-24 12:22 404568 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\tbsetup.exe
2009-11-03 04:10 . 2009-11-24 12:22 711104 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\SinfInst.exe
2009-11-03 04:10 . 2009-11-24 12:22 54832 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\AOLParconLink.exe
2009-11-03 04:10 . 2009-11-24 12:22 45056 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\SiNdInst.dll
2009-11-03 04:10 . 2009-11-24 12:22 845814 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\muinst.exe
2009-11-03 04:09 . 2009-11-24 12:22 1362936 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\msvc9rt.exe
2009-11-03 04:09 . 2009-11-24 12:22 109552 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\aolSearch.exe
2009-11-03 04:09 . 2009-11-24 12:22 289960 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\aolDailyScoop.exe
2009-11-03 04:08 . 2009-11-24 12:22 1962544 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\flashax.exe
2009-11-03 04:08 . 2009-11-24 12:22 470600 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\dtbsetup.exe
2009-11-03 04:08 . 2009-11-24 12:22 188176 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\dtblpins.exe
2009-11-03 04:07 . 2009-11-24 12:22 2396152 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\dskcorlp.exe
2009-11-03 04:07 . 2009-11-24 12:22 339808 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\dskcore.exe
2009-11-03 04:04 . 2009-11-24 12:22 3346592 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\ocpinst.exe
2009-11-03 04:04 . 2009-11-24 12:22 21296 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\acsshutd.exe
2009-11-03 04:04 . 2009-11-24 12:22 74536 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\acscompsinstSup.dll
2009-11-03 04:04 . 2009-11-24 12:22 62248 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\ocpgc.exe
2009-11-03 04:04 . 2009-11-24 12:22 15144 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\ocpchk.dll
2009-11-03 04:04 . 2009-11-24 12:22 148232 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\acsrollb.exe
2009-11-03 04:04 . 2009-11-24 12:22 1613832 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\acslang.exe
2009-11-03 04:03 . 2009-11-24 12:22 964440 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\acslaeu.exe
2009-11-03 04:03 . 2009-11-24 12:22 37680 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\AcsInstC.dll
2009-11-03 04:03 . 2009-11-24 12:22 45872 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\acscompsAcsInstA.dll
2009-11-03 04:03 . 2009-11-24 12:22 45872 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\AcsInstA.dll
2009-11-03 04:03 . 2009-11-24 12:22 1480888 ——w- f:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4471.2.4\acscore.exe
2009-10-27 21:44 . 2009-03-20 00:22 89464 —-a-w- f:\documents and settings\Barb Emery\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-21 06:00 . 2004-08-04 07:56 75776 —-a-w- f:\windows\system32\strmfilt.dll
2009-10-21 06:00 . 2004-08-04 07:56 25088 —-a-w- f:\windows\system32\httpapi.dll
2009-10-20 14:58 . 2004-08-04 06:00 263552 —-a-w- f:\windows\system32\drivers\http.sys
2009-10-14 17:40 . 2009-08-15 18:20 149260 —-a-w- f:\windows\hpwins05.dat
2009-10-13 10:53 . 2006-05-14 09:13 266752 —-a-w- f:\windows\system32\oakley.dll
2009-10-12 13:54 . 2003-07-16 20:42 112128 —-a-w- f:\windows\system32\rastls.dll
2009-10-12 13:54 . 2003-07-16 20:42 69632 —-a-w- f:\windows\system32\raschap.dll
2009-10-11 09:17 . 2009-06-29 11:09 411368 —-a-w- f:\windows\system32\deploytk.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-12-30_20.51.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-31 12:40 . 2009-12-31 12:40 16384 f:\windows\Temp\Perflib_Perfdata_28c.dat
+ 2003-07-16 20:41 . 2009-12-31 12:47 71904 f:\windows\system32\perfc009.dat
- 2003-07-16 20:41 . 2009-12-30 20:43 71904 f:\windows\system32\perfc009.dat
+ 2003-07-16 20:41 . 2009-12-31 12:47 444028 f:\windows\system32\perfh009.dat
- 2003-07-16 20:41 . 2009-12-30 20:43 444028 f:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="f:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="f:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-29 39408]
"SUPERAntiSpyware"="f:\program files\SUPERAntiSpyware\8a924459-05f3-41e8-848d-af5e0bd2d781.exe" [2009-11-23 2001648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="f:\program files\Common Files\AOL\1237308355\ee\AOLSoftware.exe" [2008-11-06 41264]
"Adobe Reader Speed Launcher"="f:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"NvCplDaemon"="f:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"nwiz"="nwiz.exe" [2009-02-18 1657376]
"NvMediaCenter"="f:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"CTHelper"="CTHELPER.EXE" [2008-06-27 19456]
"Adobe Photo Downloader"="f:\program files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 61440]
"MaxtorOneTouch"="f:\program files\Maxtor\OneTouch\utils\Onetouch.exe" [2004-12-22 823296]
"RetroExpress"="f:\progra~1\Dantz\RETROS~1\RetroExpress.exe" [2004-07-30 6946816]
"MXOBG"="f:\windows\MXOALDR.EXE" [2009-04-07 94208]
"QuickTime Task"="f:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"Omnipage"="f:\program files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 49152]
"HP Software Update"="f:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"avgnt"="f:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="f:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

f:\documents and settings\Dan Miller\Start Menu\Programs\Startup\
Adobe Gamma.lnk - f:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
AOL Desktop.lnk - f:\program files\Common Files\AOL\Launch\aollaunch.exe [2008-6-24 41824]

f:\documents and settings\All Users\Start Menu\Programs\Startup\
APC UPS Status.lnk - f:\program files\APC\APC PowerChute Personal Edition\Display.exe [2009-3-16 209005]
HP Digital Imaging Monitor.lnk - f:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "f:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 —-a-w- f:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"f:\\Program Files\\Dantz\\Retrospect Express HD\\RetroExpress.exe"=
"f:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"f:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"f:\\Program Files\\Common Files\\AOL\\1237308355\\ee\\aolsoftware.exe"=
"f:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"f:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"f:\\Program Files\\Common Files\\AOL\\1237308355\\ee\\AOLDesktop.exe"=
"f:\\Documents and Settings\\Dan Miller\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"f:\\Program Files\\iTunes\\iTunes.exe"=
"f:\\Program Files\\TomTom HOME 2\\xulrunner\\TomTomHOMERuntime.exe"=

R1 SASDIFSV;SASDIFSV;f:\program files\SUPERAntiSpyware\sasdifsv.sys [11/23/2009 8:43 AM 9968]
R1 SASKUTIL;SASKUTIL;f:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/23/2009 8:43 AM 74480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;f:\program files\Avira\AntiVir Desktop\sched.exe [12/30/2009 10:55 AM 108289]
R2 TomTomHOMEService;TomTomHOMEService;f:\program files\TomTom HOME 2\TomTomHOMEService.exe [8/27/2009 10:05 AM 92008]
R3 COMMONFX.SYS;COMMONFX.SYS;f:\windows\system32\drivers\COMMONFX.sys [6/27/2008 7:21 PM 99352]
R3 CTAUDFX.SYS;CTAUDFX.SYS;f:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 7:21 PM 555032]
R3 CTSBLFX.SYS;CTSBLFX.SYS;f:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 7:21 PM 566296]
R3 SASENUM;SASENUM;f:\program files\SUPERAntiSpyware\SASENUM.SYS [11/23/2009 8:43 AM 7408]
S0 Lbd;Lbd;f:\windows\system32\DRIVERS\Lbd.sys –> f:\windows\system32\DRIVERS\Lbd.sys [?]
S3 COMMONFX;COMMONFX;f:\windows\system32\drivers\COMMONFX.sys [6/27/2008 7:21 PM 99352]
S3 CTAUDFX;CTAUDFX;f:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 7:21 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;f:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 7:21 PM 100888]
S3 CTERFXFX;CTERFXFX;f:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 7:21 PM 100888]
S3 CTSBLFX;CTSBLFX;f:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 7:21 PM 566296]
S4 PCPitstop Scheduling;PCPitstop Scheduling;f:\program files\PCPitstop\PCPitstopScheduleService.exe [8/15/2009 1:55 PM 85504]

— Other Services/Drivers In Memory —

*NewlyCreated* - SASDIFSV

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.cnn.com
uInternet Settings,ProxyOverride = *.local
IE: &AOL Toolbar Search - f:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
IE: &Search
IE: E&xport to Microsoft Excel - f:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Linked&In Search - f:\program files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedinIEToolbar.dll/ContextMenu.htm
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-31 09:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(872)
f:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(5872)
f:\program files\ScanSoft\OmniPageSE\ophook32.dll
f:\windows\system32\ieframe.dll
f:\windows\system32\webcheck.dll
f:\windows\system32\WPDShServiceObj.dll
f:\windows\system32\PortableDeviceTypes.dll
f:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-12-31 09:36:00
ComboFix-quarantined-files.txt 2009-12-31 14:35
ComboFix2.txt 2009-12-30 20:55

Pre-Run: 937,762,107,392 bytes free
Post-Run: 937,855,594,496 bytes free

- - End Of File - - 84E385A359A4A9B037503B98987E8FD7
Hi Dan Miller,

Sorry I gave you the wrong command for combofix, please do this

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /uninstall

Please post one more OTL scan log and we'll clean up and send you on your way.

Happy New Year's to you too.

Thanks
Oldman960, Last OTL provided per request. AVG up and running. I can't thank you enough for your patience and guidance on this one. For the record, do you know what exactly got into my system? It had it out for my registry. Here's to a great evening as the calendar turns. DAn

OTL logfile created on: 12/31/2009 3:33:17 PM - Run 3
OTL by OldTimer - Version 3.1.20.1 Folder = F:\Documents and Settings\Dan Miller\My Documents
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): f:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = F: | %SystemRoot% = F:\WINDOWS | %ProgramFiles% = F:\Program Files
Drive C: | 149.05 Gb Total Space | 28.21 Gb Free Space | 18.92% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 931.50 Gb Total Space | 873.49 Gb Free Space | 93.77% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DANANDBARB
Current User Name: Dan Miller
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - F:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - F:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - F:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - F:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - F:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - F:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - F:\Documents and Settings\Dan Miller\My Documents\OTL.exe (OldTimer Tools)
PRC - F:\Program Files\SUPERAntiSpyware\8a924459-05f3-41e8-848d-af5e0bd2d781.exe (SUPERAntiSpyware.com)
PRC - F:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - F:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - F:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - F:\WINDOWS\MXOALDR.EXE (Cypress Semiconductor)
PRC - F:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - F:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - F:\Program Files\Common Files\AOL\1237308355\ee\aolsoftware.exe (AOL LLC)
PRC - F:\Program Files\Common Files\AOL\1237308355\ee\AOLDesktop.exe (AOL LLC)
PRC - F:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard Co.)
PRC - F:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)
PRC - F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - F:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - F:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
PRC - F:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
PRC - F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe ()
PRC - F:\Program Files\Dantz\Retrospect Express HD\RetroExpress.exe (Dantz Development Corporation)
PRC - F:\Program Files\Dantz\Retrospect Express HD\Retrospect.exe (Dantz Development Corporation)
PRC - F:\Program Files\Dantz\Retrospect Express HD\retrorun.exe (Dantz Development Corporation)
PRC - F:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe (American Power Conversion Corporation)
PRC - F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
PRC - F:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)


========== Modules (SafeList) ==========

MOD - F:\Documents and Settings\Dan Miller\My Documents\OTL.exe (OldTimer Tools)
MOD - F:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - F:\Program Files\ScanSoft\OmniPageSE\ophook32.dll (ScanSoft, Inc)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – F:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (JavaQuickStarterService) – F:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (gusvc) – F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (TomTomHOMEService) – F:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (iPod Service) – F:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (PCPitstop Scheduling) – F:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (Apple Mobile Device) – F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (NVSvc) – F:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Bonjour Service) – F:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (hpqcxs08) – F:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (Pml Driver HPZ12) – F:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (Net Driver HPZ12) – F:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (hpqddsvc) – F:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (AOL ACS) – F:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (AdobeActiveFileMonitor5.0) – F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe ()
SRV - (IDriverT) – F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (RetroExpLauncher) – F:\Program Files\Dantz\Retrospect Express HD\retrorun.exe (Dantz Development Corporation)
SRV - (ose) – F:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (APC UPS Service) – F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – F:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – F:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – F:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (SASDIFSV) – F:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – F:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – F:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (GEARAspiWDM) – F:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (PxHelp20) – F:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ASCTRM) – F:\WINDOWS\system32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (nv) – F:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (hap17v2k) – F:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – F:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – F:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – F:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – F:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – F:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – F:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctdvda2k) – F:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – F:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – F:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTERFXFX.SYS) – F:\WINDOWS\System32\drivers\CTERFXFX.SYS (Creative Technology Ltd)
DRV - (CTERFXFX) – F:\WINDOWS\system32\drivers\CTERFXFX.sys (Creative Technology Ltd)
DRV - (CTSBLFX.SYS) – F:\WINDOWS\System32\drivers\CTSBLFX.SYS (Creative Technology Ltd)
DRV - (CTSBLFX) – F:\WINDOWS\system32\drivers\CTSBLFX.sys (Creative Technology Ltd)
DRV - (CTAUDFX.SYS) – F:\WINDOWS\System32\drivers\CTAUDFX.SYS (Creative Technology Ltd)
DRV - (CTAUDFX) – F:\WINDOWS\system32\drivers\CTAUDFX.sys (Creative Technology Ltd)
DRV - (COMMONFX.SYS) – F:\WINDOWS\System32\drivers\COMMONFX.SYS (Creative Technology Ltd)
DRV - (COMMONFX) – F:\WINDOWS\system32\drivers\COMMONFX.sys (Creative Technology Ltd)
DRV - (Secdrv) – F:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (HPZius12) – F:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HPZipr12) – F:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZid412) – F:\WINDOWS\system32\drivers\HPZid412.sys (HP)
DRV - (BCM43XX) – F:\WINDOWS\system32\drivers\bcmwl5.sys (Broadcom Corporation)
DRV - (MXOPSWD) – F:\WINDOWS\system32\drivers\mxopswd.sys (Maxtor Corp.)
DRV - (MXOFX) USB Storage Adapter FX (MXO) – F:\WINDOWS\system32\drivers\MXOFX.SYS (Cypress Semiconductor)
DRV - (GTNDIS5) – F:\WINDOWS\system32\GTNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (Ptilink) – F:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (E100B) Intel® – F:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (wanatw) WAN Miniport (ATW) – F:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (OMCI) – F:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (MODEMCSA) – F:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (SONYPVU1) Sony USB Filter Driver (SONYPVU1) – F:\WINDOWS\system32\drivers\SONYPVU1.SYS (Sony Corporation)
DRV - (HidBatt) – F:\WINDOWS\system32\drivers\hidbatt.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com
IE - HKCU\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


[2009/07/18 10:24:27 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Mozilla\Extensions
[2009/07/18 10:24:27 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Mozilla\Extensions\[removed]

O1 HOSTS File: (27 bytes) - F:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (IEToolbarBHO Class) - {1A1DAC8C-074D-440F-8707-7009A672D7D1} - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedInIEToolbar.dll (LinkedIn)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - F:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AOL Toolbar Loader) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - F:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - F:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (LinkedIn Toolbar) - {BB670D0B-5C46-40C7-B38B-40DD26987723} - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedInIEToolbar.dll (LinkedIn)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (LinkedIn Toolbar) - {BB670D0B-5C46-40C7-B38B-40DD26987723} - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedInIEToolbar.dll (LinkedIn)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [Adobe Photo Downloader] F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] F:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] F:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CTHelper] F:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [HostManager] F:\Program Files\Common Files\AOL\1237308355\ee\aolsoftware.exe (AOL LLC)
O4 - HKLM..\Run: [HP Software Update] F:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [MaxtorOneTouch] F:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe (Maxtor Corporation)
O4 - HKLM..\Run: [MXOBG] F:\WINDOWS\MXOALDR.EXE (Cypress Semiconductor)
O4 - HKLM..\Run: [NvCplDaemon] F:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] F:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] F:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [Omnipage] F:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)
O4 - HKLM..\Run: [QuickTime Task] F:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RetroExpress] F:\Program Files\Dantz\Retrospect Express HD\RetroExpress.exe (Dantz Development Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] F:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] F:\Program Files\SUPERAntiSpyware\8a924459-05f3-41e8-848d-af5e0bd2d781.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk = F:\Program Files\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)
O4 - Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\AOL Desktop.lnk = F:\Program Files\Common Files\AOL\Launch\aollaunch.exe (AOL LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &AOL; Toolbar Search - F:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Linked&In; Search - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedinIEToolbar.dll (LinkedIn)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre6\bin\npjpi160_17.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - F:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1237306142784 (WUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://intercall.webex.com/client/T26L10NS…bex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/da2/PCPitStop2.cab (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - F:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - F:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - F:\Program Files\SUPERAntiSpyware\SASWINLO.dll - F:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - F:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - F:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/16 16:49:43 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2009/12/31 10:57:15 | 00,000,000 | -H-D | C] – F:\$AVG
[2009/12/31 10:57:05 | 00,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – F:\WINDOWS\System32\avgrsstx.dll
[2009/12/31 10:57:03 | 00,360,584 | —- | C] (AVG Technologies CZ, s.r.o.) – F:\WINDOWS\System32\drivers\avgtdix.sys
[2009/12/31 10:56:56 | 00,333,192 | —- | C] (AVG Technologies CZ, s.r.o.) – F:\WINDOWS\System32\drivers\avgldx86.sys
[2009/12/31 10:56:55 | 00,028,424 | —- | C] (AVG Technologies CZ, s.r.o.) – F:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/12/31 10:56:50 | 00,000,000 | —D | C] – F:\WINDOWS\System32\drivers\Avg
[2009/12/30 15:27:02 | 00,000,000 | —D | C] – F:\WINDOWS\ERDNT
[2009/12/30 14:17:11 | 00,513,536 | —- | C] (OldTimer Tools) – F:\Documents and Settings\Dan Miller\My Documents\OTL.exe
[2009/12/30 14:10:17 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\gmer
[2009/12/30 11:46:56 | 00,000,000 | —D | C] – F:\Program Files\Trend Micro
[2009/12/30 10:55:14 | 00,056,816 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\avgntflt.sys
[2009/12/30 10:29:46 | 00,000,000 | —D | M] – F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/12/30 10:10:00 | 00,000,000 | –SD | M] – F:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/12/30 10:10:00 | 00,000,000 | –SD | M] – F:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/12/30 10:10:00 | 00,000,000 | —D | M] – F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/12/30 07:27:23 | 00,000,000 | RH-D | C] – F:\Documents and Settings\Dan Miller\Recent
[2009/12/30 07:25:21 | 00,000,000 | —D | C] – F:\Program Files\CCleaner
[2009/12/30 07:24:42 | 03,357,024 | —- | C] (Piriform Ltd) – F:\Documents and Settings\Dan Miller\My Documents\ccsetup227.exe
[2009/12/30 05:22:00 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Application Data\avg9
[2009/12/30 04:26:26 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/12/30 04:22:08 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\SUPERAntiSpyware.com
[2009/12/30 04:22:08 | 00,000,000 | —D | C] – F:\Program Files\SUPERAntiSpyware
[2009/12/29 18:26:10 | 00,891,248 | —- | C] (AVG Technologies) – F:\Documents and Settings\Dan Miller\My Documents\avg_free_stb_all_9_40_cnet.exe
[2009/12/29 08:42:53 | 00,470,528 | —- | C] (Microsoft Corporation) – F:\WINDOWS\System32\dllcache\aclayers.dll
[2009/12/29 08:41:44 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – F:\WINDOWS\System32\javaws.exe
[2009/12/29 08:41:44 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – F:\WINDOWS\System32\javaw.exe
[2009/12/29 08:41:44 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – F:\WINDOWS\System32\java.exe
[2009/12/19 13:31:45 | 00,000,000 | —D | C] – F:\Program Files\Common Files\SWF Studio
[2009/12/19 13:31:18 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\U3
[2009/12/18 17:22:41 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\Pictures for Mom
[2009/12/14 08:10:18 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\Adobe
[2009/12/14 08:02:11 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Documents\Adobe PDF
[2009/12/13 19:49:46 | 00,000,000 | R–D | C] – F:\Documents and Settings\Dan Miller\My Documents\My Videos
[2009/12/11 12:22:14 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\ScheduleOCR Output
[2009/12/11 12:22:14 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\ScheduleOCR Input
[2009/12/09 14:08:55 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2009/12/09 14:08:49 | 00,000,000 | —D | C] – F:\Program Files\TweetDeck
[2009/12/03 17:19:23 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\CensusTestingSitesHtfdWinter2009
[2009/03/17 11:46:53 | 00,000,000 | —D | M] – F:\Documents and Settings\LocalService\Local Settings\Application Data\AOL
[2008/06/27 17:26:00 | 00,010,752 | —- | C] ( ) – F:\WINDOWS\System32\a3d.dll
[7 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp -> ]
[6 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ]
[3 F:\Documents and Settings\Dan Miller\My Documents\*.tmp files -> F:\Documents and Settings\Dan Miller\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2009/12/31 15:27:59 | 04,958,588 | —- | M] () – F:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.CDF
[2009/12/31 15:27:59 | 04,958,588 | —- | M] () – F:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.BAK
[2009/12/31 10:57:05 | 00,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – F:\WINDOWS\System32\avgrsstx.dll
[2009/12/31 10:57:05 | 00,001,507 | —- | M] () – F:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2009/12/31 10:57:03 | 00,360,584 | —- | M] (AVG Technologies CZ, s.r.o.) – F:\WINDOWS\System32\drivers\avgtdix.sys
[2009/12/31 10:56:56 | 00,333,192 | —- | M] (AVG Technologies CZ, s.r.o.) – F:\WINDOWS\System32\drivers\avgldx86.sys
[2009/12/31 10:56:55 | 47,284,692 | —- | M] () – F:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/12/31 10:56:55 | 00,113,461 | —- | M] () – F:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2009/12/31 10:56:55 | 00,028,424 | —- | M] (AVG Technologies CZ, s.r.o.) – F:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/12/31 10:56:50 | 06,061,540 | —- | M] () – F:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/12/31 10:56:50 | 00,492,629 | —- | M] () – F:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/12/31 10:56:50 | 00,128,231 | —- | M] () – F:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/12/31 10:50:28 | 00,525,946 | —- | M] () – F:\WINDOWS\System32\PerfStringBackup.INI
[2009/12/31 10:50:28 | 00,444,028 | —- | M] () – F:\WINDOWS\System32\perfh009.dat
[2009/12/31 10:50:28 | 00,071,904 | —- | M] () – F:\WINDOWS\System32\perfc009.dat
[2009/12/31 10:49:28 | 00,212,641 | —- | M] () – F:\WINDOWS\System32\nvapps.xml
[2009/12/31 09:45:51 | 00,000,006 | -H– | M] () – F:\WINDOWS\tasks\SA.DAT
[2009/12/31 09:45:49 | 00,002,048 | –S- | M] () – F:\WINDOWS\bootstat.dat
[2009/12/31 09:45:14 | 05,767,168 | -H– | M] () – F:\Documents and Settings\Dan Miller\NTUSER.DAT
[2009/12/31 09:45:14 | 00,030,912 | —- | M] () – F:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/31 09:45:14 | 00,030,912 | —- | M] () – F:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/31 09:45:14 | 00,030,120 | —- | M] () – F:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/31 09:45:14 | 00,030,120 | —- | M] () – F:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/31 09:45:14 | 00,011,564 | —- | M] () – F:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/31 09:44:51 | 00,000,278 | -HS- | M] () – F:\Documents and Settings\Dan Miller\ntuser.ini
[2009/12/31 09:34:24 | 00,000,227 | —- | M] () – F:\WINDOWS\system.ini
[2009/12/30 22:00:13 | 00,070,144 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\PU vs Uconn.doc
[2009/12/30 21:58:57 | 00,002,497 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\Microsoft Office Word 2003.lnk
[2009/12/30 17:31:49 | 00,000,988 | —- | M] () – F:\WINDOWS\win.ini
[2009/12/30 15:50:41 | 00,000,027 | —- | M] () – F:\WINDOWS\System32\drivers\etc\hosts
[2009/12/30 14:55:24 | 00,038,224 | —- | M] (Malwarebytes Corporation) – F:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/12/30 14:54:58 | 00,019,160 | —- | M] (Malwarebytes Corporation) – F:\WINDOWS\System32\drivers\mbam.sys
[2009/12/30 14:17:14 | 00,513,536 | —- | M] (OldTimer Tools) – F:\Documents and Settings\Dan Miller\My Documents\OTL.exe
[2009/12/30 14:12:34 | 00,293,376 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\q5zuyknf.exe
[2009/12/30 11:46:56 | 00,001,734 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\HijackThis.lnk
[2009/12/30 11:10:27 | 00,056,816 | —- | M] (Avira GmbH) – F:\WINDOWS\System32\drivers\avgntflt.sys
[2009/12/30 08:28:16 | 00,008,640 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_082754.reg
[2009/12/30 07:35:42 | 00,071,042 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073444.reg
[2009/12/30 07:34:31 | 00,061,044 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073302.reg
[2009/12/30 07:32:39 | 00,018,652 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073045.reg
[2009/12/30 07:25:22 | 00,001,548 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\CCleaner.lnk
[2009/12/30 07:24:50 | 03,357,024 | —- | M] (Piriform Ltd) – F:\Documents and Settings\Dan Miller\My Documents\ccsetup227.exe
[2009/12/30 06:35:29 | 00,891,248 | —- | M] (AVG Technologies) – F:\Documents and Settings\Dan Miller\My Documents\avg_free_stb_all_9_40_cnet.exe
[2009/12/30 04:22:10 | 00,000,780 | —- | M] () – F:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/12/29 14:17:55 | 00,000,696 | —- | M] () – F:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/29 08:42:40 | 00,002,422 | —- | M] () – F:\WINDOWS\System32\wpa.dbl
[2009/12/28 22:31:34 | 00,000,008 | —- | M] () – F:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2009/12/18 13:03:10 | 00,131,072 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Legal_Drinking_Age_-_Generational_shifts 2.xls
[2009/12/18 12:57:19 | 00,131,072 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Legal Drinking Age - Generational shifts.xls
[2009/12/18 10:28:54 | 00,026,624 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\people born by year.xls
[2009/12/15 19:07:00 | 34,650,112 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 6.doc
[2009/12/15 17:26:43 | 00,001,076 | —- | M] () – F:\WINDOWS\System32\settingsbkup.sfm
[2009/12/15 17:26:43 | 00,001,076 | —- | M] () – F:\WINDOWS\System32\settings.sfm
[2009/12/14 15:52:03 | 00,026,624 | —- | M] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/14 15:01:10 | 00,090,128 | —- | M] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/12/14 14:59:09 | 00,313,968 | —- | M] () – F:\WINDOWS\System32\FNTCACHE.DAT
[2009/12/14 13:35:22 | 00,025,600 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Letter to Mother.doc
[2009/12/14 11:48:24 | 34,648,576 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 5.doc
[2009/12/14 11:37:15 | 34,650,624 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 4.doc
[2009/12/14 11:24:07 | 34,651,648 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 3.doc
[2009/12/14 10:56:22 | 34,651,136 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 2.doc
[2009/12/14 10:38:31 | 34,652,160 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 1.doc
[2009/12/14 10:11:36 | 03,434,269 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Barb and Dan for Xmas cards 2009.jpg
[2009/12/14 08:02:18 | 00,000,988 | —- | M] () – F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\Adobe Gamma.lnk
[2009/12/14 08:01:41 | 00,001,882 | —- | M] () – F:\Documents and Settings\All Users\Desktop\Adobe Premiere Elements 3.0.lnk
[2009/12/14 07:59:41 | 00,053,248 | —- | M] () – F:\WINDOWS\System32\pxhpinst.exe
[2009/12/13 11:30:20 | 04,402,988 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Dan & Barb Xmas shot.JPG
[2009/12/12 19:20:07 | 01,620,362 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\lourcey.jpg
[2009/12/12 16:06:24 | 00,002,483 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\Microsoft Office PowerPoint 2003.lnk
[2009/12/11 12:22:24 | 01,647,104 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Gingerbread house.doc
[2009/12/09 14:08:51 | 00,000,640 | —- | M] () – F:\Documents and Settings\All Users\Desktop\TweetDeck.lnk
[2009/12/09 14:08:17 | 02,652,400 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\TweetDeck_0_32.1.air
[2009/12/03 17:19:23 | 00,963,023 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\CensusTestingSitesHtfdWinter2009.zip
[2009/12/01 20:11:41 | 00,015,360 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Santini Letter.xls
[2009/12/01 20:00:00 | 00,002,495 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\Microsoft Office Excel 2003.lnk
[2009/12/01 19:48:18 | 00,024,064 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Letter for Santini.doc
[2009/12/01 18:30:10 | 00,074,240 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\DanMiller_Resume.doc
[7 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp -> ]
[6 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ]
[3 F:\Documents and Settings\Dan Miller\My Documents\*.tmp files -> F:\Documents and Settings\Dan Miller\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2009/12/31 10:57:05 | 00,001,507 | —- | C] () – F:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2009/12/31 10:56:55 | 00,113,461 | —- | C] () – F:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2009/12/31 10:56:50 | 47,284,692 | —- | C] () – F:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/12/31 10:56:50 | 06,061,540 | —- | C] () – F:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/12/31 10:56:50 | 00,492,629 | —- | C] () – F:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/12/31 10:56:50 | 00,128,231 | —- | C] () – F:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/12/30 22:00:13 | 00,070,144 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\PU vs Uconn.doc
[2009/12/30 14:12:31 | 00,293,376 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\q5zuyknf.exe
[2009/12/30 11:46:56 | 00,001,734 | —- | C] () – F:\Documents and Settings\Dan Miller\Desktop\HijackThis.lnk
[2009/12/30 08:27:55 | 00,008,640 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_082754.reg
[2009/12/30 07:38:00 | 04,958,588 | —- | C] () – F:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.BAK
[2009/12/30 07:34:45 | 00,071,042 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073444.reg
[2009/12/30 07:33:04 | 00,061,044 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073302.reg
[2009/12/30 07:30:49 | 00,018,652 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073045.reg
[2009/12/30 07:25:22 | 00,001,548 | —- | C] () – F:\Documents and Settings\Dan Miller\Desktop\CCleaner.lnk
[2009/12/30 04:22:10 | 00,000,780 | —- | C] () – F:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/12/28 22:31:34 | 00,000,008 | —- | C] () – F:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2009/12/18 13:03:07 | 00,131,072 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Legal_Drinking_Age_-_Generational_shifts 2.xls
[2009/12/18 10:41:48 | 00,131,072 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Legal Drinking Age - Generational shifts.xls
[2009/12/14 18:12:06 | 34,650,112 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 6.doc
[2009/12/14 13:01:14 | 00,025,600 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Letter to Mother.doc
[2009/12/14 11:39:25 | 34,648,576 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 5.doc
[2009/12/14 11:24:13 | 34,650,624 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 4.doc
[2009/12/14 10:59:43 | 34,651,648 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 3.doc
[2009/12/14 10:38:36 | 34,651,136 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 2.doc
[2009/12/14 10:14:50 | 34,652,160 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 1.doc
[2009/12/14 10:11:33 | 03,434,269 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Barb and Dan for Xmas cards 2009.jpg
[2009/12/14 08:02:18 | 00,000,988 | —- | C] () – F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\Adobe Gamma.lnk
[2009/12/14 08:01:41 | 00,001,882 | —- | C] () – F:\Documents and Settings\All Users\Desktop\Adobe Premiere Elements 3.0.lnk
[2009/12/13 11:28:04 | 04,402,988 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Dan & Barb Xmas shot.JPG
[2009/12/12 19:21:50 | 01,620,362 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\lourcey.jpg
[2009/12/11 12:22:21 | 01,647,104 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Gingerbread house.doc
[2009/12/09 14:08:10 | 02,652,400 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\TweetDeck_0_32.1.air
[2009/12/03 17:19:20 | 00,963,023 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\CensusTestingSitesHtfdWinter2009.zip
[2009/12/01 20:02:40 | 00,015,360 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Santini Letter.xls
[2009/12/01 19:48:17 | 00,024,064 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Letter for Santini.doc
[2009/08/15 10:40:36 | 00,005,957 | —- | C] () – F:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/07/28 10:10:06 | 00,038,460 | —- | C] () – F:\Documents and Settings\Dan Miller\Application Data\Microsoft Excel.ADR
[2009/07/18 11:53:35 | 00,025,713 | —- | C] () – F:\WINDOWS\CSTBox.INI
[2009/07/18 11:41:31 | 00,040,960 | —- | C] () – F:\WINDOWS\System32\IPPCPUID.DLL
[2009/07/18 11:41:31 | 00,000,105 | —- | C] () – F:\WINDOWS\UMXADDIN.INI
[2009/07/18 11:41:31 | 00,000,091 | —- | C] () – F:\WINDOWS\PM20.INI
[2009/07/18 11:41:15 | 00,011,776 | —- | C] () – F:\WINDOWS\System32\pmsbfn32.dll
[2009/07/18 11:40:36 | 00,000,074 | —- | C] () – F:\WINDOWS\PMINI.ini
[2009/07/18 10:45:45 | 00,000,525 | —- | C] () – F:\WINDOWS\MAXLINK.INI
[2009/04/07 17:24:56 | 00,000,133 | —- | C] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\fusioncache.dat
[2009/03/31 18:44:13 | 00,008,704 | —- | C] () – F:\WINDOWS\System32\CNMVS7D.DLL
[2009/03/18 19:32:35 | 00,026,624 | —- | C] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/17 11:58:25 | 00,012,288 | —- | C] () – F:\WINDOWS\System32\e100bmsg.dll
[2009/03/16 19:22:40 | 00,094,208 | —- | C] () – F:\WINDOWS\System32\GTW32N50.dll
[2009/03/16 17:01:49 | 00,000,376 | —- | C] () – F:\WINDOWS\ODBC.INI
[2009/02/18 14:44:00 | 01,724,416 | —- | C] () – F:\WINDOWS\System32\nvwdmcpl.dll
[2009/02/18 14:44:00 | 01,507,328 | —- | C] () – F:\WINDOWS\System32\nview.dll
[2009/02/18 14:44:00 | 01,101,824 | —- | C] () – F:\WINDOWS\System32\nvwimg.dll
[2009/02/18 14:44:00 | 00,466,944 | —- | C] () – F:\WINDOWS\System32\nvshell.dll
[2008/06/27 18:05:08 | 00,049,565 | —- | C] () – F:\WINDOWS\System32\instwdm.ini
[2008/06/27 18:05:06 | 00,000,054 | —- | C] () – F:\WINDOWS\System32\ctzapxx.ini
[2008/06/27 17:27:54 | 00,043,520 | —- | C] () – F:\WINDOWS\System32\CTBurst.dll
[2007/08/13 20:45:02 | 00,077,824 | —- | C] () – F:\WINDOWS\System32\ctmmactl.dll
[2006/10/02 17:25:18 | 00,000,307 | —- | C] () – F:\WINDOWS\System32\kill.ini
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – F:\WINDOWS\System32\OUTLPERF.INI
< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI