This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Antivirus Live

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Laptop with Vista got something yesterday that produces popup windows indicating any file I try to access is infected Use AVG free Can't access the web, can't open firefox or internet explorer Security warning window popups up so fast, I can't search for problems. Downloaded Spyware Dr. but can't open to search, and see from the download I did on my desktop, it only searches and does nothing without paying to activate it. Windows Security Center pops up with all lights green, but I can't do anything with it. Box stays up just above the clock showing Antivirus software alert – details attack from [removed], port 35774 Attacked port 61694 Threat : Bankerfox.A Wants me to activate the antivirus software which from what I read is not legit. Is there a way to use my desktop to view the laptop and over ride to dowload anything, or would that put my desktop in jeapordy? Could I download to my desktop to a CD some software to rid the laptop, and then try to load the laptop? thanks for any suggestions, as I am stumped.
Hi doug1234, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

If you are planning on using a USB flash drive please do this on the clean computer first.

Insert the flash drive to the computer then

Download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.

Let's have a look and see what going on.

Please note that when running this tool, the rogue you are infected with will probably give you alerts that the file is infected. Please close those alerts with the X. The tool should continue to run.

Download OTL to your desktop and copy to the CD or flashdrive..

Transfer OTL directly to the infected computer's Desktop.
  • Right click on OTL.exe and click "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please transfer these logs to the CD or flash drive and post in your next reply.
Hello oldman960 Thanks for replying to my help call. I'm one of those types of people who searches for help, and sometimes find the right answer. I had been in the wrong safe mode, and not in safe mode with networking, which did allow me to access the web to get the downloads. Once I figured this out, I was able to quarantine the bogus virus. I think everything is working OK I did upgrade to IE 8 which from what I have read has a better safety than the earlier versions. Thank goodness I was able to use my desktop during this frustrating time. Do you think I should still try to put up a hijack this log, or stay where I am for now? Doug
Hi doug1234, I suggest you follow the instructions for OTL. These guys usually don't travel alone. Since you now have internet access with the laptop, download OTL directly to it's desktop and follow the previous instructions. Thanks
OK oldman960

I will see if I can get the scanned results to show.
When I downloaded OTL, I did not see a way to save it to the desktop though.

If you see anything suspicious, I would like to know what it is and what to do

Thanks for your time, and expertise.

Doug



OTL Extras logfile created on: 1/21/2010 2:39:11 PM - Run 1
OTL by OldTimer - Version 3.1.25.3 Folder = C:\Users\Doug\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 44.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.14 Gb Total Space | 17.46 Gb Free Space | 12.73% Space Free | Partition Type: NTFS
Drive D: | 11.91 Gb Total Space | 1.53 Gb Free Space | 12.86% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DOUG-PC
Current User Name: Doug
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{B52C81C6-9931-405D-B71F-E58C5EEC646B}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0233F7DD-C7CF-4084-8E29-C5B3B93F5C4E}" = protocol=17 | dir=in | app=c:\program files\smartftp client\smartftp.exe |
"{170CDA6A-111A-4A9A-98ED-2A85D43D77DB}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{1A9C1718-A771-4E37-8134-5B449EDA9D0D}" = dir=in | app=e:\setup\hpznui01.exe |
"{29DA7670-1067-4EF0-89EE-9BD6B12C9B54}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{2CE979F8-50E4-45B6-A37F-6FD1B3915C79}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{2F635961-175D-4664-B4FD-26A3D12F4096}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{2FD6091D-5372-43D9-86A9-198ED92C5E05}" = dir=in | app=c:\program files\avg\avg8\avgnsx.exe |
"{3EC86714-8387-408B-96E6-981610836165}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{45353C69-11B0-49DF-A153-FAEF489D2F33}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{60474918-1D63-42EF-B4E0-86A5BCD03560}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{6A9BB568-E792-4870-A3AD-DEAB311A7EC5}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{6F50D2C4-8E6C-46EE-88E2-254E72827181}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{7A8533D7-902B-441B-9D5A-1F1E91F44A99}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8C092AE3-4518-4DE1-9AFD-9B735091CBAE}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B81F62E7-E9A4-4330-BE2B-FBF881E4FAB3}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{B9D5E06F-0DF6-4F61-A359-53B94B0B938C}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{B9EBD3D1-E074-4C3A-A6C6-4E0A4360A810}" = protocol=6 | dir=in | app=c:\program files\smartftp client\smartftp.exe |
"{CABE275A-2E71-4CD7-BEFE-592949AFE45F}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{CC14FB36-24BA-4B37-8684-F726B649B099}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{D495A64D-E869-48D6-9A6B-EC675F58BE1F}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{D5DF18AB-9B43-4CB4-8C09-EB9287FBE86E}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{E37508CB-26FD-4702-B9F0-2FC9763AD6A0}" = protocol=1 | dir=in | name=hpnetassist_icmp |
"{EB369CA8-8E0B-435E-A0E8-967EBB3FC14F}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{F6A10BF2-F0DE-4AAE-BFE2-504D153C766F}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{FD108751-87F2-4AC6-BDEC-B8370E318865}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{C98DD3BE-77F3-4A0B-A6CA-C84138CD0F43}C:\program files\hp\hp software update\hpwucli.exe" = protocol=6 | dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"TCP Query User{E05F1394-4F8B-43D9-BF68-996EFAB86902}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{26A7F3D9-6A22-45A3-839E-3F535B84A826}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{FF26BE90-A90A-4305-9593-1C988AF934C8}C:\program files\hp\hp software update\hpwucli.exe" = protocol=17 | dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{03792636-ED5B-4CD3-A93B-19BC2C18F8F8}" = Sentrilock Card Utility
"{03A7C57A-B2C8-409b-92E5-524A0DFD0DD3}" = Status
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{087A66B8-1F0F-4a8d-A649-0CFE276AA7C0}" = WebReg
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{192A3445-56FC-47B3-B706-17D599E3B630}" = CalyxLoanBridge11
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{2284D904-C138-4B58-93EC-5C362AB5130A}" = The Sims™ Life Stories
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{2A329FB6-389D-4396-A974-29656D6864AE}" = MarketResearch
"{2BC2781A-F7F6-452E-95EB-018A522F1B2C}" = PaperPort Image Printer
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{3CCB26F5-E2A7-4C91-8340-9149D7B7C2BE}" = Virtual Earth 3D (Beta)
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{47ECCB1F-2811-49C0-B6A7-26778639ABA0}" = 32 Bit HP CIO Components Installer
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{4D304678-738E-42a0-931A-2B022F49DEB8}" = TrayApp
"{542C0F0B-FBDF-45d9-AF8A-345C1A9B5AE3}" = 8000A809
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{5CD4F991-BA3E-4EC4-A7A1-EFB61F4D7291}" = Setup
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{63505193-EE81-450B-9F74-B1F25FAE64B7}" = Rand McNally SGDE Engine V6.40
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{671B4BAD-D681-4d29-9498-D8BF3F1A389D}" = BPDSoftware
"{67EC0AB2-8CF7-4415-9F70-7FBC593C0D5E}" = ScanSoft PDF Create! 4
"{68471BF2-F1F7-4C89-BBBA-400B94996596}" = ESU for Microsoft Vista
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A3F98BA-338E-49a1-9D79-D786A83E6621}" = HP Officejet Pro 8000 A809 Series
"{6E4EE9B5-F69D-4455-B430-40FA5F0DC988}" = ProductContext
"{6EED4269-588D-45b8-A80C-26A9CA62EE4E}" = HPSSupply
"{6F23C1A3-9F62-470C-BD12-B83F04E67865}" = SmartFTP Client
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{7395D650-AE5D-4D68-B8FE-D3FA6B51467F}" = Driver Detective
"{7DC4A410-9986-4329-9E5D-687B2C42CA39}" = HP QuickTouch 1.00 C4
"{7E42E47F-DA35-47DC-9EBF-9D3AC1225504}" = ScanSoft PaperPort 11
"{7F94FB03-6617-4442-9817-CDDB36EAE529}" = 8000A809_eDocs
"{800E784D-53E3-4948-B491-9E7FA5EACBDC}" = SmartWebPrinting
"{813D9A27-1406-49CC-8E8C-9FCAF282FF7C}" = Street Guide DE Engine Windows Vista Service Pack
"{8347A7A5-4AB8-433F-82AA-496B0D189A9B}" = HP User Guides 0088
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86BC184E-CFCD-48D5-829A-666A36C6ACC9}" = 8000A809_Help
"{87A9A9A9-FAB7-4224-9328-0FA2058C0FD5}" = Network
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9603DE6D-4567-4b78-B941-849322373DE2}" = SolutionCenter
"{96F28051-0D57-4B5C-BD17-0C42F03A8AD0}" = SCR33xx USB Smartcard Reader
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9D1B99B7-DAD8-440d-B4FB-1915332FBCC2}" = HPProductAssistant
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A2C82F57-F312-4525-A19C-40E228E09939}" = Setup
"{A654A805-41D9-40C7-AA46-4AF04F044D61}" = Adobe® Photoshop® Album Starter Edition 3.2
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{ABBA0799-F982-414C-9A8B-17EB03D39677}" = trakAxPC
"{AC13BA3A-336B-45a4-B3FE-2D3058A7B533}" = Toolbox
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{AFB69549-3AAE-4433-A99B-673B8A513379}" = BPDSoftware_Ini
"{AFC1479C-B03A-4587-8246-D308C8C9CC23}" = Rand McNally Street Guide San Diego & Imperial Counties 2006
"{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor
"{B10A30CF-CCFF-4056-9ABC-F8D42BDF141F}" = myPrintMileage (Officejet Pro 8000 A809)
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{BE50CAF7-C98E-4242-B476-C1BCEFC6E22E}" = Rand McNally SGDE Search Databases
"{BF493FC0-48B9-45C1-A482-EF04813926BB}" = Point 6.2
"{BFB8C7BE-3BFA-446C-9F3E-3AFBA5BC1033}" = Nero 7 Ultra Edition
"{C427E746-4EC9-4E3C-AACB-C6BB1F714D7F}" = Uniblue DriverScanner 2009
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{DD6C316A-FE75-4FBB-9D22-4C1920232B72}" = LightScribe System Software
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E56D39F8-2A9F-44B4-B068-A72E45A073E6}" = Safari
"{F05E2B98-DA04-4FFA-8D08-DA218E6A2B47}" = Point
"{F3CA9611-CD42-4562-ADAB-A554CF8E17F1}" = Microsoft WSE 2.0 SP3 Runtime
"{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{F648FD09-7CEA-4257-BC68-A8389189FD51}" = GPBaseService2
"{F769B78E-FF0E-4db5-95E2-9F4C8D6352FE}" = DeviceDiscovery
"{F7F3B252-E772-48AA-93EB-7964BC326067}" = MSCU for Microsoft Vista
"{F88A66C2-FF51-4CBE-A411-E58167C2D174}" = C5100n GDI Driver for Windows Vista
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Adobe® Photoshop® Album Starter Edition 3.2" = Adobe® Photoshop® Album Starter Edition 3.2
"AIM_6" = AIM 6
"AVG9Uninstall" = AVG Free 9.0
"C4B4D7F5499921DF57A4F6B55E59E0F50C2FE298" = Windows Driver Package - SCM Microsystems Inc. (SCR3xx USB Smart Card Reader) SmartCardReader (11/07/2006 4.35.00.01)
"CAL" = Canon Camera Access Library
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"EditPlus 3" = EditPlus 3
"EOS Utility" = Canon Utilities EOS Utility
"Google Updater" = Google Updater
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 12.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 12.0
"HPExtendedCapabilities" = HP Customer Participation Program 12.0
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{7395D650-AE5D-4D68-B8FE-D3FA6B51467F}" = Driver Detective
"InstallShield_{813D9A27-1406-49CC-8E8C-9FCAF282FF7C}" = Street Guide DE Engine Windows Vista Service Pack
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
"Mozilla Thunderbird (2.0.0.23)" = Mozilla Thunderbird (2.0.0.23)
"NVIDIA Drivers" = NVIDIA Drivers
"PC Pitstop Exterminate2_is1" = PC Pitstop Exterminate2 2.0
"Pdf995" = Pdf995
"PdfEdit995" = PdfEdit995
"PhotoStitch" = Canon Utilities PhotoStitch
"QuoteTracker_is1" = QuoteTracker
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 6.0" = RealPlayer
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"Sentrilock Card Utility" = Sentrilock Card Utility
"Shop for HP Supplies" = Shop for HP Supplies
"Sibelius Scorch Plugin_is1" = Sibelius Scorch Plugin [removed]
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.4
"SmartFTP Client 3.0 Setup Files" = SmartFTP Client 3.0 Setup Files (remove only)
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"Thomas Guide DE Quicktour" = Thomas Guide DE Quicktour
"Uniblue DriverScanner 2009" = Uniblue DriverScanner 2009
"ViewpointMediaPlayer" = Viewpoint Media Player
"WildTangent hp Master Uninstall" = My HP Games
"WINForms Desktop" = WINForms Desktop
"WinRAR archiver" = WinRAR archiver
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/19/2010 6:07:33 PM | Computer Name = Doug-PC | Source = MsiInstaller | ID = 11706
Description =

Error - 1/19/2010 7:21:29 PM | Computer Name = Doug-PC | Source = EventSystem | ID = 4609
Description =

Error - 1/19/2010 7:50:23 PM | Computer Name = Doug-PC | Source = EventSystem | ID = 4609
Description =

Error - 1/19/2010 8:07:56 PM | Computer Name = Doug-PC | Source = MsiInstaller | ID = 11706
Description =

Error - 1/20/2010 12:20:30 PM | Computer Name = Doug-PC | Source = EventSystem | ID = 4609
Description =

Error - 1/20/2010 2:26:33 PM | Computer Name = Doug-PC | Source = EventSystem | ID = 4609
Description =

Error - 1/20/2010 2:52:24 PM | Computer Name = Doug-PC | Source = EventSystem | ID = 4609
Description =

Error - 1/20/2010 3:49:31 PM | Computer Name = Doug-PC | Source = EventSystem | ID = 4609
Description =

Error - 1/20/2010 3:56:20 PM | Computer Name = Doug-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 1/20/2010 3:57:07 PM | Computer Name = Doug-PC | Source = MsiInstaller | ID = 11706
Description =

[ Media Center Events ]
Error - 5/26/2008 7:36:54 PM | Computer Name = Doug-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 5/26/2008 8:57:37 PM | Computer Name = Doug-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 5/30/2008 9:18:41 AM | Computer Name = Doug-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 6/6/2008 10:53:12 PM | Computer Name = Doug-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 5/18/2009 7:42:08 PM | Computer Name = Doug-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 8/9/2009 11:46:34 PM | Computer Name = Doug-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 8/10/2009 11:39:43 PM | Computer Name = Doug-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 8/22/2009 3:52:48 PM | Computer Name = Doug-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 10/11/2009 10:15:19 PM | Computer Name = Doug-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 12/20/2009 6:50:46 PM | Computer Name = Doug-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ System Events ]
Error - 1/20/2010 3:53:03 PM | Computer Name = Doug-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 1/20/2010 3:53:03 PM | Computer Name = Doug-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 1/20/2010 3:53:05 PM | Computer Name = Doug-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 1/20/2010 3:56:05 PM | Computer Name = Doug-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 1/20/2010 3:56:05 PM | Computer Name = Doug-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 1/20/2010 4:26:45 PM | Computer Name = Doug-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 1/20/2010 4:26:45 PM | Computer Name = Doug-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 1/21/2010 7:30:42 AM | Computer Name = Doug-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 1/21/2010 7:30:42 AM | Computer Name = Doug-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 1/21/2010 10:54:23 AM | Computer Name = Doug-PC | Source = Service Control Manager | ID = 7011
Description =


< End of report >
Hi Doug1234,

I need the other file that was produced. It will be in the same folder as you saved OTL.

When I downloaded OTL, I did not see a way to save it to the desktop though.

For future reference, in Internet Explorer to save to the desktop, when you click the save button a window will open. You can set the location by using the drop down menu in the top box.


If you are using Firefox, make sure that your download settings are as follows:
-Tools->Options->Main tab
-Set to "Always ask me where to Save the files".

Thanks
OK oldman960

Is this the one you need?

Doug


OTL logfile created on: 1/21/2010 2:39:11 PM - Run 1
OTL by OldTimer - Version 3.1.25.3 Folder = C:\Users\Doug\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 44.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.14 Gb Total Space | 17.46 Gb Free Space | 12.73% Space Free | Partition Type: NTFS
Drive D: | 11.91 Gb Total Space | 1.53 Gb Free Space | 12.86% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DOUG-PC
Current User Name: Doug
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Doug\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgscanx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10c.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\ieuser.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Hewlett-Packard)
PRC - c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe (Hewlett-Packard)
PRC - C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Synaptics, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe ()
PRC - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe ()
PRC - C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
PRC - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Windows\System32\drivers\XAudio.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe ()
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
PRC - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Development Company, L.P.)


========== Modules (SafeList) ==========

MOD - C:\Users\Doug\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (CCALib8) – File not found
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (LightScribeService) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (nvsvc) – C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
SRV - (PCPitstop Scheduling) – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe ()
SRV - (HPSLPSVC) – C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL (Hewlett-Packard Co.)
SRV - (hpqddsvc) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (hpqcxs08) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (Pml Driver HPZ12) – C:\Windows\System32\HPZipm12.dll (Hewlett-Packard)
SRV - (Net Driver HPZ12) – C:\Windows\System32\HPZinw12.dll (Hewlett-Packard)
SRV - (HP Health Check Service) – c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (QPCapSvc) QuickPlay Background Capture Service (QBCS) – C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe ()
SRV - (QPSched) QuickPlay Task Scheduler (QTS) – C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe ()
SRV - (GameConsoleService) – C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (XAudioService) – C:\Windows\System32\drivers\XAudio.exe (Conexant Systems, Inc.)
SRV - (Com4Qlb) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (NBService) – C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
SRV - (ehstart) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (odserv) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (hpqwmiex) – C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (PCTCore) – C:\Windows\system32\drivers\PCTCore.sys (PC Tools)
DRV - (GEARAspiWDM) – C:\Windows\System32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (SCR3XX2K) – C:\Windows\System32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (SCR3xx USB Smart Card Reader) – C:\Windows\System32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (HdAudAddService) – C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (HpqRemHid) – C:\Windows\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\drivers\BrSerId.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (HSFHWAZL) – C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E100B) Intel® – C:\Windows\System32\drivers\e100b325.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (BCM43XV) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (secdrv) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (ialm) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (mdmxsdk) – C:\Windows\System32\drivers\mdmxsdk.sys (Conexant)
DRV - (SCR33X USB Smart Card Reader) – C:\Windows\System32\drivers\SCR33X2K.sys (SCM Microsystems Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.716
FF - prefs.js..extensions.enabledItems: avg@igeared:3.011.025.005
FF - prefs.js..keyword.URL: "http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type;=yahoo_avg_hs2-tb-web_us&p;="

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/04/05 06:11:23 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2009/12/10 10:47:32 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2009/12/17 06:19:57 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2010/01/11 15:57:42 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/20 12:09:58 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/20 12:09:57 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2009/12/20 11:14:57 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2009/12/20 11:14:57 | 00,000,000 | —D | M]

[2010/01/20 12:56:09 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\Mozilla\Extensions
[2010/01/21 14:03:24 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\Mozilla\Firefox\Profiles\oty25t99.default\extensions
[2010/01/20 12:09:56 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/11/19 14:16:28 | 00,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/11/19 14:16:29 | 00,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2008/04/04 07:23:10 | 00,000,854 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QlbCtrl] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QPService] C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/con…s/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {680285A8-96D3-43DA-9D3D-51DD987D0B77} http://www.nero.com/doc/NeroVersionCheckerControl.cab (NeroVersionCheckerControl Control)
O16 - DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} http://utilities.pcpitstop.com/Exterminate…opAntiVirus.dll (PCPitstop AntiVirus)
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} http://tempo5.sandicor.com/5.0.05.46/Control/IRCSharc.cab (GeacRevw Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} http://utilities.pcpitstop.com/Nirvana/con…opAntiVirus.dll (PCPitstop AntiVirus)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://freedom.webex.com/client/T26L/training/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/10/22 23:21:14 | 00,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 07:18:54 | 00,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/21 03:27:29 | 00,000,000 | —D | C] – C:\Program Files\Windows Portable Devices
[2010/01/21 03:10:15 | 00,092,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2010/01/21 03:10:14 | 03,023,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbon.dll
[2010/01/21 03:10:14 | 01,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbonRes.dll
[2010/01/21 03:09:32 | 00,369,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2010/01/21 03:09:31 | 00,829,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2010/01/21 03:09:31 | 00,037,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2010/01/21 03:09:31 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2010/01/21 03:09:30 | 01,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2010/01/21 03:09:30 | 00,974,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecs.dll
[2010/01/21 03:09:30 | 00,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2010/01/21 03:09:30 | 00,828,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2010/01/21 03:09:30 | 00,793,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FntCache.dll
[2010/01/21 03:09:30 | 00,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2010/01/21 03:09:30 | 00,351,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2010/01/21 03:09:30 | 00,321,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2010/01/21 03:09:30 | 00,280,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2010/01/21 03:09:30 | 00,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiag.exe
[2010/01/21 03:09:30 | 00,195,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiagn.dll
[2010/01/21 03:09:30 | 00,189,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2010/01/21 03:09:30 | 00,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2010/01/21 03:09:29 | 01,064,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2010/01/21 03:09:29 | 01,030,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2010/01/21 03:09:29 | 00,519,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2010/01/21 03:09:29 | 00,486,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2010/01/21 03:09:29 | 00,481,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2010/01/21 03:09:29 | 00,218,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2010/01/21 03:09:29 | 00,190,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2010/01/21 03:09:29 | 00,161,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2010/01/21 03:08:49 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\BthMtpContextHandler.dll
[2010/01/21 03:08:49 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDShextAutoplay.exe
[2010/01/21 03:08:47 | 00,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceConnectApi.dll
[2010/01/21 03:08:42 | 00,546,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpd_ci.dll
[2010/01/21 03:08:42 | 00,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceTypes.dll
[2010/01/21 03:08:41 | 00,350,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDSp.dll
[2010/01/21 03:08:41 | 00,334,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2010/01/21 03:08:41 | 00,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceWMDRM.dll
[2010/01/21 03:08:41 | 00,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceClassExtension.dll
[2010/01/21 03:07:38 | 00,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2010/01/21 03:07:38 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll
[2010/01/21 03:01:21 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nshhttp.dll
[2010/01/21 03:01:16 | 00,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\httpapi.dll
[2010/01/20 12:17:52 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/01/20 12:17:52 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/01/20 12:16:33 | 00,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/01/20 12:16:31 | 00,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2010/01/20 12:16:29 | 00,380,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2010/01/20 12:16:03 | 00,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rastls.dll
[2010/01/20 10:31:43 | 00,000,000 | —D | C] – C:\Users\Doug\AppData\Roaming\Malwarebytes
[2010/01/20 10:31:39 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/01/20 10:31:38 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/01/20 10:31:38 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/20 10:31:38 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/01/20 10:15:26 | 00,000,000 | —D | C] – C:\Users\Doug\Documents\Malwarebytes' Anti-Malware
[2010/01/18 20:22:00 | 00,207,792 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTCore.sys
[2010/01/18 20:22:00 | 00,087,784 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTAppEvent.sys
[2010/01/18 20:21:45 | 00,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2010/01/18 19:43:26 | 00,000,000 | —D | C] – C:\fe4033a45e40b700157443b6102b63
[2010/01/18 19:42:51 | 04,493,736 | —- | C] (Microsoft Corporation) – C:\Users\Doug\Desktop\mssefullinstall-x86fre-en-us-vista-win7(2).exe
[2010/01/18 19:42:21 | 04,493,736 | —- | C] (Microsoft Corporation) – C:\Users\Doug\Desktop\mssefullinstall-x86fre-en-us-vista-win7.exe
[2010/01/18 14:54:00 | 00,000,000 | —D | C] – C:\Users\Doug\AppData\Local\jwnnea
[2010/01/18 11:22:43 | 00,000,000 | —D | C] – C:\Users\Doug\Documents\X-Rays 1-18-09
[2010/01/11 16:00:39 | 00,000,000 | —D | C] – C:\ProgramData\WEBREG
[2010/01/11 15:56:51 | 00,000,000 | —D | C] – C:\ProgramData\HP Product Assistant
[2010/01/11 15:53:46 | 00,000,000 | —D | C] – C:\Windows\hpojp8000a809
[2010/01/11 15:47:12 | 00,364,544 | —- | C] (Hewlett-Packard) – C:\Windows\System32\hppldcoi.dll
[2010/01/11 15:47:12 | 00,309,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\difxapi.dll
[2010/01/11 15:46:54 | 00,271,704 | —- | C] (Hewlett-Packard) – C:\Windows\System32\hpzids01.dll
[2010/01/11 15:46:46 | 00,118,272 | —- | C] (Hewlett-Packard Company) – C:\Windows\System32\hpf3l082.dll
[2010/01/08 22:03:09 | 00,000,000 | —D | C] – C:\Users\Doug\AppData\Roaming\Template
[2010/01/06 15:57:42 | 00,000,000 | —D | C] – C:\Users\Doug\Documents\Doug & sue & Pete
[2010/01/04 06:17:37 | 00,000,000 | —D | C] – C:\Users\Doug\Documents\LIving Rm-1-4-2010
[2010/01/01 17:12:27 | 00,000,000 | —D | C] – C:\Users\Doug\Documents\Sunset New Years Day 2010
[2009/12/30 19:20:14 | 00,000,000 | —D | C] – C:\Users\Doug\Documents\Leaves 2
[2009/12/30 18:36:23 | 00,000,000 | —D | C] – C:\Users\Doug\Documents\Leaves 12-09
[2009/12/30 12:36:39 | 00,000,000 | —D | C] – C:\Users\Doug\Documents\Workers Comp - Clinton Polley startup 12-09
[2009/12/26 10:32:08 | 00,000,000 | —D | C] – C:\Program Files\Coupons
[2009/12/25 15:51:16 | 00,000,000 | —D | C] – C:\Users\Doug\Documents\Christmas 09
[83 C:\Users\Doug\Documents\*.tmp files -> C:\Users\Doug\Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/01/21 14:38:16 | 05,767,168 | -HS- | M] () – C:\Users\Doug\ntuser.dat
[2010/01/21 13:53:26 | 00,027,744 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/01/21 13:53:26 | 00,027,744 | —- | M] () – C:\ProgramData\nvModes.001
[2010/01/21 13:53:24 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/01/21 10:00:37 | 54,461,828 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/01/21 08:23:59 | 00,112,847 | —- | M] () – C:\Users\Doug\Documents\–Stenum –13PatientDataSheetStenum2.pdf
[2010/01/21 07:30:11 | 00,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/01/21 07:30:11 | 00,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/01/21 03:36:00 | 00,703,448 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/01/21 03:36:00 | 00,604,012 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/01/21 03:36:00 | 00,105,040 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/01/21 03:31:22 | 00,000,162 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2010/01/21 03:30:12 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/01/21 03:29:33 | 20,791,54176 | -HS- | M] () – C:\hiberfil.sys
[2010/01/21 03:28:15 | 00,524,288 | -HS- | M] () – C:\Users\Doug\ntuser.dat{2418b0c9-bd95-11de-9ae2-001b24f56238}.TMContainer00000000000000000001.regtrans-ms
[2010/01/21 03:28:15 | 00,065,536 | -HS- | M] () – C:\Users\Doug\ntuser.dat{2418b0c9-bd95-11de-9ae2-001b24f56238}.TM.blf
[2010/01/21 03:26:58 | 00,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2010/01/21 03:26:48 | 06,291,456 | -H– | M] () – C:\Users\Doug\AppData\Local\IconCache.db
[2010/01/20 12:12:55 | 00,001,724 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/01/20 11:55:05 | 00,142,495 | —- | M] () – C:\Windows\System32\drivers\Avg\microavi.avg
[2010/01/20 10:31:42 | 00,000,818 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/20 10:22:04 | 00,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
[2010/01/20 10:22:00 | 00,000,326 | —- | M] () – C:\Users\Doug\Desktop\Malwarebytes' Anti-Malware - Shortcut.lnk
[2010/01/19 08:16:21 | 00,089,088 | —- | M] () – C:\Windows\System32\umstartup.etl
[2010/01/19 06:16:17 | 00,086,016 | —- | M] () – C:\Windows\System32\umstartup000.etl
[2010/01/18 19:42:49 | 04,493,736 | —- | M] (Microsoft Corporation) – C:\Users\Doug\Desktop\mssefullinstall-x86fre-en-us-vista-win7(2).exe
[2010/01/18 19:42:20 | 04,493,736 | —- | M] (Microsoft Corporation) – C:\Users\Doug\Desktop\mssefullinstall-x86fre-en-us-vista-win7.exe
[2010/01/17 21:40:54 | 00,003,602 | —- | M] () – C:\Users\Doug\Desktop\Bloomberg.com Futures.url
[2010/01/17 08:21:15 | 00,217,088 | —- | M] () – C:\Users\Doug\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/16 19:09:34 | 00,041,472 | —- | M] () – C:\Users\Doug\Documents\Marinades Steak.doc
[2010/01/15 20:24:46 | 00,000,283 | —- | M] () – C:\Users\Doug\Desktop\After Hours Most Active Stocks - NASDAQ Afterhours.url
[2010/01/15 20:22:49 | 00,055,296 | —- | M] () – C:\Users\Doug\Desktop\Property Management Financial Records–5401 Waring Rd -1.xls
[2010/01/15 12:56:29 | 00,000,171 | —- | M] () – C:\Users\Doug\Desktop\Charles Schwab Investment Services Including Online Investing.url
[2010/01/15 11:43:36 | 00,007,333 | —- | M] () – C:\Users\Doug\Desktop\Yahoo! Message Boards - DryShips, Inc. - quite amazing.url
[2010/01/15 11:42:44 | 00,000,436 | —- | M] () – C:\Users\Doug\Desktop\Yahoo! Message Boards - Search Results (2).url
[2010/01/14 14:45:08 | 00,000,162 | -H– | M] () – C:\Users\Doug\Documents\~$eveland Irrigation clock, root cut, lower pipes 9-19-09.doc
[2010/01/14 14:40:08 | 00,045,568 | —- | M] () – C:\Users\Doug\Documents\Fashion View–1.5 inch RainBird valve replacement 1-13-2010.doc
[2010/01/13 21:49:42 | 00,002,627 | —- | M] () – C:\Users\Doug\Desktop\Money Flows Selling on Strength - Markets Data Center - WSJ.com (2).url
[2010/01/13 21:42:19 | 00,000,122 | —- | M] () – C:\Users\Doug\Desktop\All StockTwits Updates.url
[2010/01/11 15:59:28 | 00,172,671 | —- | M] () – C:\Windows\hpwins21.dat
[2010/01/11 15:57:19 | 00,002,030 | —- | M] () – C:\Users\Public\Desktop\Shop for HP Supplies.lnk
[2010/01/11 15:56:41 | 00,001,176 | —- | M] () – C:\Users\Public\Desktop\HP Solution Center.lnk
[2010/01/11 15:55:49 | 00,001,972 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/01/11 15:23:24 | 00,045,568 | —- | M] () – C:\Users\Doug\Documents\Passwords and Links-8.xls
[2010/01/11 08:02:23 | 00,000,379 | —- | M] () – C:\Users\Doug\Desktop\Stylish Noggins Ltd. - Catalog.url
[2010/01/09 09:28:18 | 00,000,245 | —- | M] () – C:\Users\Doug\Desktop\Cancer, Hats, Hair Loss, Alopecia, Caps, Modesty, Snood, Chemotherapy, Modest clothing..url
[2010/01/09 07:48:30 | 00,000,608 | —- | M] () – C:\Users\Doug\Desktop\Sandicor, Inc. - Home Page.url
[2010/01/08 22:02:59 | 00,000,000 | —- | M] () – C:\Users\Doug\AppData\Roaming\wklnhst.dat
[2010/01/07 17:11:46 | 00,242,176 | —- | M] () – C:\Users\Doug\Documents\Rental-Debit & Credit –Jan- 2010 –5401 Waring Rd 11-09.doc
[2010/01/07 17:10:45 | 00,061,952 | —- | M] () – C:\Users\Doug\Documents\Property Management Financial Records–5401 Waring Rd -1.xls
[2010/01/07 16:07:14 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/01/07 08:36:13 | 00,020,480 | —- | M] () – C:\Users\Doug\StylishNoggins%20Resolution[1].doc
[2010/01/06 20:16:31 | 00,024,603 | -H– | M] () – C:\Users\Doug\Documents\PP11Thumbs.ptn2
[2010/01/06 20:16:30 | 37,168,308 | -H– | M] () – C:\Users\Doug\Documents\PP11Thumbs.ptn
[2010/01/06 20:16:30 | 00,024,052 | -H– | M] () – C:\Users\Doug\Documents\maxdesk.ini2
[2010/01/06 20:16:26 | 00,248,808 | —- | M] () – C:\Users\Doug\Documents\Hillcrest Tree Bid –RFQ for tree timming 12-15-1.pdf
[2010/01/06 11:32:56 | 00,238,592 | —- | M] () – C:\Users\Doug\Documents\Rental-Debit & Credit –December- 2009 –5401 Waring Rd 11-09.doc
[2010/01/06 08:51:21 | 00,240,128 | —- | M] () – C:\Users\Doug\Documents\Rental-Debit & Credit – REVISED– for 2009 –5401 Waring Rd 11-09.doc
[2010/01/06 06:19:46 | 00,000,194 | —- | M] () – C:\Users\Doug\Desktop\ClearStation Welcome to ClearStation!.url
[2010/01/04 18:30:50 | 00,119,247 | —- | M] () – C:\Users\Doug\Documents\RubyAwardNominationForm[1].pdf
[2010/01/02 17:59:09 | 00,028,160 | —- | M] () – C:\Users\Doug\Documents\Pizza dough–grams conversion per pie.doc
[2010/01/02 08:24:13 | 00,029,696 | —- | M] () – C:\Users\Doug\Documents\Stir Fry Sauce 1st time 1.doc
[2010/01/01 16:46:33 | 00,019,456 | —- | M] () – C:\Users\Doug\Documents\Kahula Receipe 2-15-09.doc
[2009/12/31 11:50:57 | 00,037,888 | —- | M] () – C:\Users\Doug\Documents\Bayside– Seed and Topdress Lawns-12-09.doc
[2009/12/31 10:21:36 | 00,049,152 | —- | M] () – C:\Users\Doug\Documents\HILLCREST ASSOC — Tree Trim ( 17 ) Ficus Est 12-29-09.doc
[2009/12/30 13:02:28 | 00,050,688 | —- | M] () – C:\Users\Doug\Documents\Hagen_Terrace–Tree Trim ( 2) 12-29-09.doc
[2009/12/30 08:04:39 | 00,040,960 | —- | M] () – C:\Users\Doug\Documents\Invoice_Mesa_View_HOA__4__–_Decem–09_-_–.doc
[2009/12/29 20:27:17 | 00,000,115 | —- | M] () – C:\Users\Doug\Desktop\Investtalk.com.url
[2009/12/29 20:23:18 | 00,000,185 | —- | M] () – C:\Users\Doug\Desktop\Free Charts - StockCharts.com.url
[2009/12/29 20:07:44 | 00,000,215 | —- | M] () – C:\Users\Doug\Desktop\definition of technical analysis.url
[2009/12/29 11:18:42 | 00,048,640 | —- | M] () – C:\Users\Doug\Documents\HILLCREST ASSOC — Gazania planting by Healthy Back 12-28-09.doc
[2009/12/29 09:34:02 | 00,000,170 | —- | M] () – C:\Users\Doug\Desktop\Speedtest.net - The Global Broadband Speed Test.url
[2009/12/24 07:59:45 | 00,000,211 | —- | M] () – C:\Users\Doug\Desktop\Financial Opinions Updated Daily iamned.com.url
[83 C:\Users\Doug\Documents\*.tmp files -> C:\Users\Doug\Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/01/21 08:23:59 | 00,112,847 | —- | C] () – C:\Users\Doug\Documents\–Stenum –13PatientDataSheetStenum2.pdf
[2010/01/21 03:26:58 | 00,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2010/01/20 11:51:26 | 20,791,54176 | -HS- | C] () – C:\hiberfil.sys
[2010/01/20 10:31:42 | 00,000,818 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/20 10:22:00 | 00,000,326 | —- | C] () – C:\Users\Doug\Desktop\Malwarebytes' Anti-Malware - Shortcut.lnk
[2010/01/20 10:17:55 | 00,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2010/01/18 20:22:00 | 00,007,412 | —- | C] () – C:\Windows\System32\drivers\PCTAppEvent.cat
[2010/01/18 20:22:00 | 00,007,383 | —- | C] () – C:\Windows\System32\drivers\pctcore.cat
[2010/01/15 20:22:49 | 00,055,296 | —- | C] () – C:\Users\Doug\Desktop\Property Management Financial Records–5401 Waring Rd -1.xls
[2010/01/15 11:42:44 | 00,000,436 | —- | C] () – C:\Users\Doug\Desktop\Yahoo! Message Boards - Search Results (2).url
[2010/01/14 14:45:08 | 00,000,162 | -H– | C] () – C:\Users\Doug\Documents\~$eveland Irrigation clock, root cut, lower pipes 9-19-09.doc
[2010/01/14 14:40:06 | 00,045,568 | —- | C] () – C:\Users\Doug\Documents\Fashion View–1.5 inch RainBird valve replacement 1-13-2010.doc
[2010/01/11 15:57:19 | 00,002,030 | —- | C] () – C:\Users\Public\Desktop\Shop for HP Supplies.lnk
[2010/01/11 15:56:41 | 00,001,176 | —- | C] () – C:\Users\Public\Desktop\HP Solution Center.lnk
[2010/01/11 15:55:49 | 00,001,972 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/01/11 15:44:24 | 00,172,671 | —- | C] () – C:\Windows\hpwins21.dat
[2010/01/08 22:02:59 | 00,000,000 | —- | C] () – C:\Users\Doug\AppData\Roaming\wklnhst.dat
[2010/01/07 08:36:13 | 00,020,480 | —- | C] () – C:\Users\Doug\StylishNoggins%20Resolution[1].doc
[2010/01/05 10:46:42 | 00,238,592 | —- | C] () – C:\Users\Doug\Documents\Rental-Debit & Credit –December- 2009 –5401 Waring Rd 11-09.doc
[2010/01/05 10:14:28 | 00,242,176 | —- | C] () – C:\Users\Doug\Documents\Rental-Debit & Credit –Jan- 2010 –5401 Waring Rd 11-09.doc
[2010/01/04 18:30:50 | 00,119,247 | —- | C] () – C:\Users\Doug\Documents\RubyAwardNominationForm[1].pdf
[2010/01/01 16:35:59 | 00,029,696 | —- | C] () – C:\Users\Doug\Documents\Stir Fry Sauce 1st time 1.doc
[2009/12/31 11:50:57 | 00,037,888 | —- | C] () – C:\Users\Doug\Documents\Bayside– Seed and Topdress Lawns-12-09.doc
[2009/12/30 13:26:28 | 00,248,808 | —- | C] () – C:\Users\Doug\Documents\Hillcrest Tree Bid –RFQ for tree timming 12-15-1.pdf
[2009/12/30 13:19:49 | 00,049,152 | —- | C] () – C:\Users\Doug\Documents\HILLCREST ASSOC — Tree Trim ( 17 ) Ficus Est 12-29-09.doc
[2009/12/30 12:55:59 | 00,050,688 | —- | C] () – C:\Users\Doug\Documents\Hagen_Terrace–Tree Trim ( 2) 12-29-09.doc
[2009/12/30 08:00:42 | 00,040,960 | —- | C] () – C:\Users\Doug\Documents\Invoice_Mesa_View_HOA__4__–_Decem–09_-_–.doc
[2009/12/29 20:07:43 | 00,000,215 | —- | C] () – C:\Users\Doug\Desktop\definition of technical analysis.url
[2009/12/29 11:11:59 | 00,048,640 | —- | C] () – C:\Users\Doug\Documents\HILLCREST ASSOC — Gazania planting by Healthy Back 12-28-09.doc
[2009/12/29 09:34:02 | 00,000,170 | —- | C] () – C:\Users\Doug\Desktop\Speedtest.net - The Global Broadband Speed Test.url
[2009/12/24 07:59:45 | 00,000,211 | —- | C] () – C:\Users\Doug\Desktop\Financial Opinions Updated Daily iamned.com.url
[2009/11/29 09:30:16 | 00,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/05/21 20:39:19 | 00,000,244 | —- | C] () – C:\Users\Doug\AppData\Roaming\default.rss
[2009/05/19 06:52:57 | 00,000,039 | —- | C] () – C:\Windows\Irremote.ini
[2009/05/10 15:28:11 | 00,000,058 | —- | C] () – C:\Windows\mchguid.ini
[2009/05/10 15:28:11 | 00,000,058 | —- | C] () – C:\ProgramData\mchguid.ini
[2009/05/10 15:21:50 | 00,021,504 | —- | C] () – C:\Windows\jestertb.dll
[2009/02/16 07:10:39 | 00,027,744 | —- | C] () – C:\ProgramData\nvModes.001
[2009/02/16 07:10:29 | 00,027,744 | —- | C] () – C:\ProgramData\nvModes.dat
[2008/11/19 13:05:10 | 00,000,454 | —- | C] () – C:\Windows\HBCIKRNL.INI
[2008/11/01 20:12:11 | 00,000,058 | —- | C] () – C:\Windows\wininit.ini
[2008/10/29 13:08:56 | 00,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2008/10/29 13:03:57 | 00,031,767 | —- | C] () – C:\Windows\maxlink.ini
[2008/06/18 04:48:44 | 00,000,059 | —- | C] () – C:\Windows\wpd99.drv
[2008/06/18 04:48:43 | 00,051,716 | —- | C] () – C:\Windows\System32\pdf995mon.dll
[2008/06/10 08:03:49 | 00,007,268 | —- | C] () – C:\Users\Doug\AppData\Local\d3d9caps.dat
[2008/02/17 12:33:08 | 00,053,248 | —- | C] () – C:\Windows\System32\Zlib.dll
[2008/02/17 12:33:03 | 00,041,984 | —- | C] () – C:\Windows\System32\ZFExt.dll
[2008/01/22 11:26:44 | 00,217,088 | —- | C] () – C:\Users\Doug\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/22 10:19:00 | 00,000,092 | —- | C] () – C:\Users\Doug\AppData\Local\fusioncache.dat
[2008/01/22 10:18:59 | 00,010,875 | —- | C] () – C:\Windows\ESOA.INI
[2008/01/22 10:18:59 | 00,003,679 | —- | C] () – C:\Windows\GrAddrBk.ini
[2008/01/22 10:18:59 | 00,000,995 | —- | C] () – C:\Windows\GRACE.INI
[2008/01/22 10:18:59 | 00,000,053 | —- | C] () – C:\Windows\PRSRVDLL.INI
[2008/01/22 10:17:49 | 00,001,514 | —- | C] () – C:\Windows\winpoint.ini
[2008/01/22 10:09:00 | 00,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/01/17 19:38:31 | 00,967,244 | —- | C] () – C:\ProgramData\LuUninstall.LiveUpdate
[2008/01/17 16:57:03 | 00,027,240 | —- | C] () – C:\Users\Doug\AppData\Roaming\nvModes.001
[2008/01/17 16:35:02 | 00,027,240 | —- | C] () – C:\Users\Doug\AppData\Roaming\nvModes.dat
[2008/01/17 16:21:15 | 00,000,000 | —- | C] () – C:\Users\Doug\AppData\Local\QSwitch.txt
[2008/01/17 16:21:15 | 00,000,000 | —- | C] () – C:\Users\Doug\AppData\Local\DSwitch.txt
[2008/01/17 16:21:15 | 00,000,000 | —- | C] () – C:\Users\Doug\AppData\Local\AtStart.txt
[2007/12/22 17:50:02 | 00,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2007/10/22 23:35:58 | 00,001,922 | —- | C] () – C:\ProgramData\hpzinstall.log
[2006/11/02 08:12:52 | 00,217,088 | —- | C] () – C:\Windows\System32\missouri.dll
[2006/11/02 04:35:32 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:25:21 | 00,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/01 23:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 14:58:00 | 01,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[1999/01/22 02:46:58 | 00,065,536 | —- | C] () – C:\Windows\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2010/01/06 20:18:01 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\.oit
[2009/11/29 10:33:10 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\admixdj
[2008/06/17 17:08:01 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\Bullzip
[2008/05/24 20:03:32 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\EditPlus 3
[2009/11/30 09:20:05 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\HighAndes
[2008/05/10 06:13:34 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\Leadertech
[2008/06/18 05:13:49 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\pdf995
[2008/11/04 09:05:58 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\ScanSoft
[2008/02/16 14:19:59 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\SentriLock
[2010/01/08 22:03:09 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\Template
[2008/01/17 16:26:55 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\Thunderbird
[2008/10/29 13:56:47 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\Uniblue
[2008/10/29 13:19:15 | 00,000,000 | —D | M] – C:\Users\Doug\AppData\Roaming\Zeon
[2010/01/21 03:27:58 | 00,032,622 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 143 bytes -> C:\Users\Public\Documents\yahoo_au.nws:OECustomProperty
@Alternate Data Stream - 143 bytes -> C:\Users\Public\Documents\yahoo.nws:OECustomProperty
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:3E270DE0
@Alternate Data Stream - 1069 bytes -> C:\Users\Doug\Documents\Emailing Outlook E mail Background with my bus card 10-05.bmp.eml:OECustomProperty
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
Hi doug1234,

Yes, that the log.

Did you use Malwarebytes' Anti-Malware to clean this computer?

A few traces left. and your java is out of date.

  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 18
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u18-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.

Click on the Start button > Control Panel

Depending on your setings, either
  • click on the Uninstall a program option under the Programs category.
  • If you are using the Classic View of the Control Panel, then you would double-click on the Programs and Features icon instead.
Uninstall the following program

Java™ 6 Update 2


Do not uninstall Java TM 6 Update 18 if found! :yeah:

Reboot your computer.

  • Right click on the saved file ( jre-6u18-windows-i586-p.exe) and select "run as Administrator" to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.

Next, Right click on OTL.exe and chose Run as Administrator to run it
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services
:OTL
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered

How is the computer? Any problems?

Thanks
Well oldman960 After the reeboot, this showed up on the screen. Nothing seems out of the ordinary, so hopefully everything you said to do has fixed any issues. Here is what showed up. thanks Doug All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Doug ->Temp folder emptied: 7845503989 bytes ->Temporary Internet Files folder emptied: 779199589 bytes ->Java cache emptied: 3339106 bytes ->FireFox cache emptied: 93598592 bytes ->Apple Safari cache emptied: 1107065 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 65742515 bytes RecycleBin emptied: 5023326979 bytes Total Files Cleaned = 13,172.00 mb OTL by OldTimer - Version 3.1.25.3 log created on 01222010_065957 Files\Folders moved on Reboot… C:\Users\Doug\AppData\Local\Temp\ehmsas.txt moved successfully. Registry entries deleted on Reboot…
Hi doug1234,

We should do one more scan just to be sure.

In order to run this scan your browser must have Administrator rights.
  • Open your browser by right clicking it's icon and clicking "Run as Administrator"
  • Go to the web site linked to below an preform the scan
  • Do not use this instance of your browser for any other type of surfing.
  • When the scan has completed and the results saved, close that instance of your browser.
  • Open your browser the normal way and post the requested logs.


*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.

Please post back with
  • Kaspersky log
  • new OTL scan log, there will only be an OTL.txt this time
Thanks
Hi Oldman960 Not able to get the scan done Clicked on the link you have, and disabled AVG but Kaspery stops and says it can't launch Java application which is interrupted Establish internet connection, which I have through my router, so I'm stumped. Doug
Hi doug1234,

Use this online scanner instead. Make sure you use Internet Explorer run as Administrator.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You must use Internet Explorer for this scan.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.
Please post back with the ESET log.
HI Oldman960 Well the scan took several hours, and showd 1 threat, which was a download I did for Nero, which I found interesting. When I saved the lgo to the text file, it showed it had quaranteened Nero, but now I can't find the text file anywhere. Did a search using both the file names you listed, and then just plugged in ESET, but what came up was the http site. Sorry Doug
Oldman960 Since doing the scan, I can't access my inbox in Thunderbird. Currently trying to search in C program files, but the search circle keeps spinning. Something seems to have changed. Doug No folder in C Progrmas, so I must have done something wrong. Still can't access Thunderbird, as it say folder is being processed. I rebooted the computer, but still having issues. Finally able to get inbox e mails in Tunderbird. Had to click sent, and then clicked inbox, and they populated Think I should run another scan? Doug

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI