This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] 32788R22FWJFW infection

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help,

32788R22FWJFW is a folder in my C drive. It is 5.5 mega bytes, and contains several files of .cfexe type and a sed.cfexe file; all of which show up as bad stuff in google searches. My old machine seems to be running slow, and working hard when it should be doing nothing.

I'm using Windows XP sp3. My browser is Firefox. Security stuff is Avast av, Comodo firewall, Spybot imunation, SpywareBlaster, Malwarebytes', and ThreatFire. I'm good about updating them, however I've been remiss about scans.—-My bad—!

Went through LDTATE'S "Are you infected?" . SysRestorePoint Application failed to initialize (0xc0000135). I couldn't figure any way around this one; however the rest was accomplished.

Any help for an old computer duffer will be greatly appreciated!!!!
Billed

Ouch!! my GMER log file won't upload—-it's 552kb—–Here is some of it.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-02 08:35:33
Windows 5.1.2600 Service Pack 3
Running: m4wq88z0.exe; Driver: C:\DOCUME~1\JUDYDE~1\LOCALS~1\Temp\fgldqpow.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwAdjustPrivilegesToken [0xB4741BDA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB3A336B8]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwConnectPort [0xB47411B8]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateFile [0xB4741840]
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwCreateKey [0xF85E5A1C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreatePort [0xB474109A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSection [0xB474306A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSymbolicLinkObject [0xB4743302]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateThread [0xB4740C60]
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwDeleteKey [0xF85E5C10]
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwDeleteValueKey [0xF85E5CB6]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB3A3314C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwLoadDriver [0xB4742CEC]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwMakeTemporaryObject [0xB474143C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenFile [0xB4741A1C]
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwOpenKey [0xF85E590C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB3A3308C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenSection [0xB47416CC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB3A330F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB3A3376E]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRenameKey [0xB4742720]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRequestWaitReplyPort [0xB4743648]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB3A3372E]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSecureConnectPort [0xB4742A88]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetSecurityObject [0xB4741DC0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetSystemInformation [0xB4742E9A]
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwSetValueKey [0xF85E5E52]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwShutdownSystem [0xB47413D6]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSystemDebugControl [0xB47415C0]
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwTerminateProcess [0xF85E7B30]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateThread [0xB4740E32]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\spoolsv.exe[412] ntdll.dll!NtLoadDriver 7C90D46E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\spoolsv.exe[412] ntdll.dll!NtLoadDriver + 4 7C90D472 2 Bytes [22, 71]
.text C:\WINDOWS\system32\spoolsv.exe[412] ntdll.dll!NtSuspendProcess 7C90DE2E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\spoolsv.exe[412] ntdll.dll!NtSuspendProcess + 4 7C90DE32 2 Bytes [3A, 71]
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!DeviceIoControl 7C801629 6 Bytes JMP 70AB000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!CreateFileA 7C801A28 6 Bytes JMP 70DE000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!VirtualProtectEx 7C801A61 6 Bytes JMP 7126000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!VirtualProtect 7C801AD4 6 Bytes JMP 70D2000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 716B000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 715F000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 7165000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!WriteProcessMemory 7C802213 6 Bytes JMP 7162000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 7150000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 7153000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!VirtualAlloc 7C809AF1 6 Bytes JMP 70D5000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!MultiByteToWideChar 7C809C98 6 Bytes JMP 7084000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!LoadResource 7C80A055 6 Bytes JMP 70C0000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!WideCharToMultiByte 7C80A174 6 Bytes JMP 7063000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!GetProcAddress 7C80AE40 6 Bytes JMP 7114000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 715C000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!CreateMutexW 7C80E957 6 Bytes JMP 708D000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!CreateMutexA 7C80E9DF 6 Bytes JMP 7090000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!OpenMutexW 7C80EA35 6 Bytes JMP 7087000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!OpenMutexA 7C80EABB 6 Bytes JMP 708A000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!GetVolumeInformationW 7C80FA85 6 Bytes JMP 710E000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!CreateRemoteThread 7C8104CC 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!CreateRemoteThread + 4 7C8104D0 2 Bytes [6D, 71]
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!CreateThread 7C8106D7 6 Bytes JMP 70D8000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!CreateFileW 7C810800 6 Bytes JMP 70E1000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!WriteFile 7C810E27 6 Bytes JMP 70A2000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!TerminateThread 7C81CB3B 6 Bytes JMP 7138000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!MoveFileW 7C821261 6 Bytes JMP 705D000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!CreateDirectoryA 7C8217AC 6 Bytes JMP 70A8000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!GetVolumeInformationA 7C821BA5 6 Bytes JMP 7111000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!CopyFileExW 7C827B32 6 Bytes JMP 70B4000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!CopyFileA 7C8286EE 6 Bytes JMP 70BD000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!CopyFileW 7C82F87B 6 Bytes JMP 70BA000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!OpenProcess 7C8309E9 6 Bytes JMP 7054000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!DeleteFileA 7C831EDD 6 Bytes JMP 7075000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!DeleteFileW 7C831F63 6 Bytes JMP 7072000A
.text C:\WINDOWS\system32\spoolsv.exe[412] kernel32.dll!CreateDirectoryW
Hello, billed
Welcome to the WhatTheTech Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.



Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.



Did you run Combofix?



  • Please download OTL from one of the following mirrors:
    • This is THE Mirror
  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
  • Push the Quick Scan button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <– Will be opened
    • Extra.txt <– Will be minimized
Hey Tom— Bill here, Thanks for the reply and I do appreciate the help!!! Your rules of the road make all kinds of sense and make me feel stupid. Between my post and your reply, I allowed QuickTime player to be downloaded (I thought it was already on this machine.) and I uninstalled a program I never used. I don't know what I was thinking; I was quite sure your folks would respond. I'm just a penny waiting for change! The only changes for now are those ordered by Tom and the automatic database updates Avast sends, and I probably can turn those off if we need to. No I did not run Combofix, this computer dummy needs adult supervision to do that. I am assuming that the question means I should go ahead and dowmload the program in preparation for running it. I'll wait for your go-ahead. Off to do my homework . Thanks, Bill
Hey Tom,

My system was already set to show all files.

Here are the two text files.

Thanks,
Bill


OTL.txt

OTL logfile created on: 03/05/10 7:25:57 AM - Run 1
OTL by OldTimer - Version 3.1.34.0 Folder = C:\Documents and Settings\Judy Dengler\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yy

512.00 Mb Total Physical Memory | 125.00 Mb Available Physical Memory | 24.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 47.00% Paging File free
Paging file location(s): c:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.07 Gb Total Space | 23.90 Gb Free Space | 62.77% Space Free | Partition Type: FAT32
Drive D: | 37.34 Gb Total Space | 36.99 Gb Free Space | 99.04% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: WDJD
Current User Name: Judy Dengler
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/03/05 07:19:10 | 000,553,984 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Judy Dengler\My Documents\Downloads\OTL.exe
PRC - [2010/02/18 19:01:42 | 000,908,248 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/02/11 17:20:24 | 001,800,464 | —- | M] (COMODO) – C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
PRC - [2010/02/11 17:20:00 | 000,723,632 | —- | M] (COMODO) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2009/11/24 17:51:40 | 000,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/11/24 17:51:36 | 000,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/11/24 17:51:22 | 000,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/11/24 17:48:48 | 000,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009/11/24 17:43:56 | 000,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/09/23 08:07:38 | 000,382,224 | —- | M] (PC Tools) – C:\Program Files\ThreatFire\TFTray.exe
PRC - [2009/09/23 08:07:34 | 000,070,928 | —- | M] (PC Tools) – C:\Program Files\ThreatFire\TFService.exe
PRC - [2009/05/27 06:19:36 | 000,765,192 | —- | M] (Secunia) – C:\Program Files\Secunia\PSI\psi.exe
PRC - [2008/04/13 19:12:20 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/03/09 11:09:58 | 000,063,712 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
PRC - [2006/04/26 22:01:46 | 000,524,288 | —- | M] (Logitech Inc. ) – D:\Program Files\Logitech\iTouch\iTouch.exe
PRC - [2006/04/26 22:01:46 | 000,032,256 | —- | M] (Logitech Inc. ) – D:\Program Files\Logitech\MouseWare\SYSTEM\EM_EXEC.EXE
PRC - [2006/04/26 22:01:38 | 000,055,808 | —- | M] () – D:\Program Files\Microsoft Office\Office\OSA.EXE
PRC - [2006/04/26 22:01:26 | 000,625,152 | —- | M] () – D:\Program Files\ASUS\Probe\AsusProb.exe
PRC - [2006/04/26 21:52:12 | 000,712,704 | —- | M] (Panicware, Inc.) – C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe
PRC - [2006/04/26 21:51:40 | 000,077,824 | —- | M] (Iomega Corporation) – C:\Program Files\Iomega\System32\AppServices.exe
PRC - [2005/01/17 16:08:48 | 000,110,592 | —- | M] (Arcsoft, Inc.) – C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
PRC - [2001/10/22 12:24:28 | 001,216,512 | R— | M] (C-Media Electronic Inc. (www.cmedia.com.tw)) – C:\WINDOWS\mixer.exe


========== Modules (SafeList) ==========

MOD - [2010/03/05 07:19:10 | 000,553,984 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Judy Dengler\My Documents\Downloads\OTL.exe
MOD - [2009/09/23 08:07:42 | 000,455,952 | —- | M] (PC Tools) – C:\Program Files\ThreatFire\TFWAH.dll
MOD - [2002/05/29 01:59:00 | 000,024,576 | —- | M] (Logitech Inc. ) – D:\Program Files\Logitech\iTouch\KbdHook.dll
MOD - [2002/05/24 09:50:00 | 000,024,576 | —- | M] (Logitech Inc. ) – D:\Program Files\Logitech\MouseWare\SYSTEM\LGMOUSHK.DLL
MOD - [2002/04/29 11:24:24 | 000,057,344 | —- | M] () – C:\Program Files\Panicware\Pop-Up Stopper\DPHOOK32.dll
MOD - [2001/09/16 11:44:04 | 000,040,960 | —- | M] () – C:\WINDOWS\PANICNT.dll
MOD - [2001/08/18 12:00:00 | 000,014,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\serwvdrv.dll
MOD - [2001/08/18 12:00:00 | 000,013,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\umdmxfrm.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (Iomega Activity Disk2)
SRV - File not found [Auto | Stopped] – – (_IOMEGA_ACTIVE_DISK_SERVICE_)
SRV - [2010/02/11 17:20:00 | 000,723,632 | —- | M] (COMODO) [Auto | Running] – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe – (cmdAgent)
SRV - [2009/11/24 17:51:36 | 000,138,680 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus)
SRV - [2009/11/24 17:51:22 | 000,254,040 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner)
SRV - [2009/11/24 17:48:48 | 000,352,920 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner)
SRV - [2009/11/24 17:43:56 | 000,018,752 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv)
SRV - [2009/09/23 08:07:34 | 000,070,928 | —- | M] (PC Tools) [Auto | Running] – C:\Program Files\ThreatFire\TFService.exe – (ThreatFire)
SRV - [2006/04/26 21:51:40 | 000,077,824 | —- | M] (Iomega Corporation) [Auto | Running] – C:\Program Files\Iomega\System32\AppServices.exe – (Iomega App Services)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig?refresh=1#restore"
FF - prefs.js..extensions.enabledItems: [removed]:1.0


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/10/03 16:19:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2005/02/14 19:59:46 | 000,000,000 | —D | M]

[2008/08/26 13:25:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\Mozilla\Extensions
[2005/02/14 20:01:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\Mozilla\Firefox\Profiles\d7r4uq94.default\extensions
[2005/02/14 20:01:54 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/02/24 06:27:14 | 000,380,265 | R— | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13103 more lines…
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ASUS Probe] D:\Program Files\ASUS\Probe\AsusProb.exe ()
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [C-Media Mixer] C:\WINDOWS\mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw))
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [EM_EXEC] D:\Program Files\Logitech\MouseWare\SYSTEM\EM_EXEC.EXE (Logitech Inc. )
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe ()
O4 - HKLM..\Run: [Pop-Up Stopper] C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe (Panicware, Inc.)
O4 - HKLM..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe (PC Tools)
O4 - HKLM..\Run: [zBrowser Launcher] D:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc. )
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk = D:\Program Files\Microsoft Office\Office\OSA.EXE ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Find Fast.lnk = D:\Program Files\Microsoft Office\Office\FINDFAST.EXE ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = D:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
O4 - Startup: C:\Documents and Settings\Judy Dengler\Start Menu\Programs\Startup\Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe (Secunia)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: bleepingcomputer.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: mediafire.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([windowsupdate] http in Trusted sites)
O15 - HKCU\..Trusted Domains: nutnworks.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] http in Trusted sites)
O15 - HKCU\..Trusted Domains: zonealarm.com ([]http in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1146187722687 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1177595026046 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8121.6390856481 (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Judy Dengler\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Judy Dengler\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/12/31 05:48:42 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ FAT32 ]
O33 - MountPoints2\{eb9bb602-13ae-11de-9d46-000c41214de7}\Shell - "" = AutoRun
O33 - MountPoints2\{eb9bb602-13ae-11de-9d46-000c41214de7}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{eb9bb602-13ae-11de-9d46-000c41214de7}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2002/01/01 06:16:48 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\SYSTEM32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (86416155039760384)

========== Files/Folders - Created Within 14 Days ==========

[2010/03/04 06:40:55 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010/03/03 08:06:20 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/03/01 08:15:47 | 000,000,000 | —D | C] – C:\Program Files\TrendMicro
[2010/03/01 06:44:07 | 000,000,000 | —D | C] – C:\Rooter$
[2010/02/27 11:14:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Judy Dengler\Application Data\Uniblue
[2010/02/26 11:41:12 | 000,028,552 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\pavboot.sys
[2010/02/26 11:39:59 | 000,000,000 | —D | C] – C:\Program Files\Panda Security
[2009/11/22 06:47:18 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2009/11/22 06:47:16 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2009/05/20 15:08:06 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2008/03/24 10:08:56 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2008/03/24 10:08:56 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Mozilla
[2002/12/31 05:52:30 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2002/12/31 05:52:30 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2002/01/01 06:22:00 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2002/01/01 06:22:00 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/03/05 06:06:10 | 000,001,610 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/05 06:03:22 | 000,013,310 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/03/05 06:01:42 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/05 06:01:16 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/03/05 06:01:14 | 536,440,832 | -HS- | M] () – C:\hiberfil.sys
[2010/03/04 19:20:28 | 009,437,184 | —- | M] () – C:\Documents and Settings\Judy Dengler\ntuser.dat
[2010/03/04 19:20:28 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Judy Dengler\NTUSER.INI
[2010/03/04 06:02:18 | 536,469,504 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2010/03/03 08:08:36 | 000,001,516 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/03/03 08:06:42 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/03/01 09:07:08 | 000,000,523 | —- | M] () – C:\Documents and Settings\Judy Dengler\Desktop\NTREGOPT.lnk
[2010/03/01 09:07:08 | 000,000,504 | —- | M] () – C:\Documents and Settings\Judy Dengler\Desktop\ERUNT.lnk
[2010/03/01 08:15:50 | 000,001,996 | —- | M] () – C:\Documents and Settings\Judy Dengler\Desktop\HiJackThis.lnk
[2010/02/26 11:21:32 | 000,000,036 | —- | M] () – C:\Documents and Settings\Judy Dengler\Local Settings\Application Data\housecall.guid.cache
[2010/02/24 06:13:16 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/03/04 08:08:50 | 009,437,184 | —- | C] () – C:\Documents and Settings\Judy Dengler\ntuser.dat
[2010/03/03 08:08:34 | 000,001,516 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/03/03 08:06:40 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/03/01 09:07:06 | 000,000,523 | —- | C] () – C:\Documents and Settings\Judy Dengler\Desktop\NTREGOPT.lnk
[2010/03/01 09:07:06 | 000,000,504 | —- | C] () – C:\Documents and Settings\Judy Dengler\Desktop\ERUNT.lnk
[2010/03/01 08:15:48 | 000,001,996 | —- | C] () – C:\Documents and Settings\Judy Dengler\Desktop\HiJackThis.lnk
[2010/02/26 11:21:31 | 000,000,036 | —- | C] () – C:\Documents and Settings\Judy Dengler\Local Settings\Application Data\housecall.guid.cache
[2009/09/30 10:25:14 | 000,000,101 | —- | C] () – C:\WINDOWS\CMMIXER.INI
[2009/09/24 09:19:40 | 000,000,038 | —- | C] () – C:\Documents and Settings\Judy Dengler\Application Data\msnpromo.txt
[2009/05/18 09:18:42 | 000,000,130 | —- | C] () – C:\WINDOWS\cfplogvw.INI
[2009/03/30 11:14:54 | 000,000,065 | —- | C] () – C:\WINDOWS\boc427.ini
[2008/06/19 16:29:32 | 000,017,987 | —- | C] () – C:\Program Files\gpl-2.0.txt
[2008/03/06 12:16:08 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2007/09/04 10:14:05 | 000,045,056 | —- | C] () – C:\Documents and Settings\Judy Dengler\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/08 13:24:51 | 000,000,141 | —- | C] () – C:\WINDOWS\wpd99.drv
[2007/02/08 13:24:35 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2007/01/02 16:32:05 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2006/10/06 14:11:06 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\vusetup.dll
[2004/11/07 08:00:18 | 000,000,000 | —- | C] () – C:\Documents and Settings\Judy Dengler\Application Data\dm.ini
[2004/05/14 16:36:38 | 000,045,056 | —- | C] () – C:\WINDOWS\PANIC32.dll
[2004/05/14 16:36:38 | 000,040,960 | —- | C] () – C:\WINDOWS\PANICNT.dll
[2004/01/08 16:46:07 | 000,000,182 | —- | C] () – C:\WINDOWS\AtxTCBizControl03.ini
[2004/01/08 16:45:57 | 000,000,106 | —- | C] () – C:\WINDOWS\AtxTCBizPref03.ini
[2003/01/01 16:51:49 | 000,000,028 | —- | C] () – C:\WINDOWS\ICOA.INI
[2003/01/01 16:51:36 | 000,000,000 | —- | C] () – C:\WINDOWS\QFN.INI
[2003/01/01 16:51:36 | 000,000,000 | —- | C] () – C:\WINDOWS\QDQICK.INI
[2003/01/01 16:25:40 | 000,098,816 | —- | C] () – C:\WINDOWS\System32\LGUICOM.DLL
[2003/01/01 16:25:40 | 000,000,488 | —- | C] () – C:\WINDOWS\Cmousecc.ini
[2003/01/01 14:00:42 | 000,000,012 | —- | C] () – C:\WINDOWS\QBWCD.INI
[2003/01/01 13:55:21 | 000,000,611 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/01/01 13:55:21 | 000,000,022 | —- | C] () – C:\WINDOWS\EXCHNG.INI
[2003/01/01 00:11:47 | 000,006,272 | —- | C] () – C:\WINDOWS\System32\drivers\ASLM75.SYS
[2003/01/01 00:10:35 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\VIDX16.DLL
[2003/01/01 00:10:31 | 000,003,698 | —- | C] () – C:\WINDOWS\MIXERDEF.INI
[2003/01/01 00:10:07 | 000,000,312 | —- | C] () – C:\WINDOWS\CMISETUP.INI
[2003/01/01 00:10:03 | 000,000,026 | —- | C] () – C:\WINDOWS\CMCDPLAY.INI
[2002/12/31 08:06:09 | 000,003,060 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2002/12/31 08:05:50 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2002/10/15 16:54:04 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2002/10/06 12:42:58 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 17:04:26 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2002/10/04 17:04:26 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 17:04:18 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/10/04 00:01:42 | 000,503,808 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2002/05/15 18:38:40 | 000,091,136 | —- | C] () – C:\WINDOWS\System32\mp4fil32.dll
[2002/05/04 08:19:00 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\avisynthEx.dll
[2002/04/19 09:23:26 | 000,106,137 | —- | C] () – C:\WINDOWS\System32\libpostproc.dll
[2002/04/19 08:51:04 | 000,211,760 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2001/06/22 06:06:02 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\MPEG2DEC.dll
[1997/08/01 00:00:00 | 000,031,232 | —- | C] () – C:\WINDOWS\System32\XLREC.DLL
[1997/08/01 00:00:00 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\RECNCL.DLL
[1997/08/01 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/08/01 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL

========== LOP Check ==========

[2005/07/11 09:14:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATX
[2007/02/08 13:24:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2007/05/31 06:24:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2007/09/20 14:11:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/02/22 11:12:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TaxCut
[2008/08/02 08:50:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2009/03/30 11:31:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/05/16 08:45:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2003/01/01 15:50:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\Active Disk
[2003/03/28 08:43:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\Leadertech
[2005/02/14 20:07:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\Thunderbird
[2005/07/11 09:14:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\ATX
[2007/05/31 06:24:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\iolo
[2008/02/22 11:16:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\TaxCut
[2008/02/22 14:37:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\pdf995
[2008/06/14 13:32:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\GARMIN
[2008/10/27 09:33:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/02/27 11:14:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\Uniblue

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2006/04/26 21:44:16 | 000,077,312 | —- | M] (SiSoftware ) – C:\san2004.SP1-9104-Win32-SSO.exe
[2006/04/26 21:44:16 | 000,145,408 | —- | M] (Symantec Corporation) – C:\FixBlast.exe
[2006/04/26 21:44:16 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\WindowsXP-KB823980-x86-ENU.exe
[2006/04/26 21:44:16 | 000,167,936 | —- | M] (MadOnion.com) – C:\3dmark2001se.exe


< MD5 for: AGP440.SYS >
[2006/04/28 17:51:38 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/08/27 18:39:04 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2006/04/28 17:51:38 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/08/27 18:39:04 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys
[2004/08/04 01:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2002/08/29 03:50:10 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2006/04/28 17:51:38 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/08/27 18:39:04 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2002/08/29 03:50:10 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp1.cab:atapi.sys
[2006/04/28 17:51:38 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008/08/27 18:39:04 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys
[2004/08/04 00:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:54 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:54 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SYSTEM32\eventlog.dll
[2004/08/04 02:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:02 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:02 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SYSTEM32\netlogon.dll
[2004/08/04 02:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 02:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:06 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:06 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SYSTEM32\scecli.dll

< %systemroot%\*. /mp /s >
< End of report >



Extra.txt

OTL Extras logfile created on: 03/05/10 7:25:57 AM - Run 1
OTL by OldTimer - Version 3.1.34.0 Folder = C:\Documents and Settings\Judy Dengler\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yy

512.00 Mb Total Physical Memory | 125.00 Mb Available Physical Memory | 24.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 47.00% Paging File free
Paging file location(s): c:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.07 Gb Total Space | 23.90 Gb Free Space | 62.77% Space Free | Partition Type: FAT32
Drive D: | 37.34 Gb Total Space | 36.99 Gb Free Space | 99.04% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: WDJD
Current User Name: Judy Dengler
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Judy Dengler\Local Settings\Application Data\Abacast\Abaclient.exe" = C:\Documents and Settings\Judy Dengler\Local Settings\Application Data\Abacast\Abaclient.exe:*:Enabled:Abaclient – File not found
"C:\WINDOWS\System32\mmc.exe" = C:\WINDOWS\System32\mmc.exe:*:Disabled:Microsoft Management Console – (Microsoft Corporation)
"C:\Documents and Settings\Judy Dengler\Local Settings\Application Data\AbacastDistributedOnDemand\Node\11\AbacastDistributedOnDemand.exe" = C:\Documents and Settings\Judy Dengler\Local Settings\Application Data\AbacastDistributedOnDemand\Node\11\AbacastDistributedOnDemand.exe:*:Disabled:Abacast Distributed On-Demand – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}" = HiJackThis
"{0878E100-C0BB-41E8-B4C6-C486B61FDA7B}" = Canon PhotoRecord
"{218BBBE3-FE63-4BB2-81A8-7435575A84FA}" = PhotoStitch
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{28291BD5-92D2-4685-82DC-CCA925C53CCA}" = RemoteCapture Task 1.1
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A7BF905-F37D-4DFB-8308-EC3AA4617B36}" = Garmin Communicator Plugin
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{45EF4EE3-F591-4B74-A477-0CAE12934CE7}" = RAW Image Task 1.2
"{4732D4A0-5A47-44D8-9B84-B3BD4906D30D}" = TaxCut Premium 2007
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C96958A-6562-4143-B820-FF4890D3B734}" = Camera Window DVC
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.61
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{79207BEE-6CD3-483C-824C-944663BACAC4}" = TaxCut Premium + Efile 2008
"{8AF1E098-1A5C-4336-BBE2-D047ABB401ED}" = MovieEdit Task
"{8B7917E0-AF55-4E8A-9473-017F0AA03AC8}" = QuickTime
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{91203BD3-6C3E-472F-ADBD-F60FDC7C4010}" = Camera Window DS
"{91B323B5-A79C-4D23-BD6D-046C565F9BCF}" = MadOnion.com/3DMark2001 SE
"{91F1A0D6-23AD-49FE-8D4E-379485652214}" = Camera Support Core Library
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom
"{A654A805-41D9-40C7-AA46-4AF04F044D61}" = Adobe® Photoshop® Album Starter Edition 3.2
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.1
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4BF87C8-3EEC-4774-82A2-584F109187B1}" = SanDisk ImageMate Reader/Writer
"{B947EFD7-D033-49E2-B837-F43C9D73AD4A}" = Tsunami-Filter-Pack Mini
"{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}" = Canon ZoomBrowser EX
"{C7281207-4AA4-425E-B57A-0E9EF8445635}" = Camera Window MC
"{CEC2A5B9-CE19-4F2E-9C8F-F310C0EAB993}" = ArcSoft Media Card Companion
"3554AA4B-9B0B-451a-A269-2B5F53982209_is1" = ThreatFire
"7-Zip" = 7-Zip 4.65
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Adobe® Photoshop® Album Starter Edition 3.2" = Adobe® Photoshop® Album Starter Edition 3.2
"AdobeESD" = Adobe Download Manager 1.2 (Remove Only)
"ASUS Probe V2.17.00" = ASUS Probe V2.17.00
"avast!" = avast! Antivirus
"COMODO Internet Security" = COMODO Internet Security
"DXTXTRA" = Microsoft DirectX Transform optional components
"ERUNT_is1" = ERUNT 1.1j
"ffdshow" = ffdshow (remove only)
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{218BBBE3-FE63-4BB2-81A8-7435575A84FA}" = Canon Utilities PhotoStitch 3.1
"InstallShield_{28291BD5-92D2-4685-82DC-CCA925C53CCA}" = Canon RemoteCapture Task for ZoomBrowser EX
"InstallShield_{45EF4EE3-F591-4B74-A477-0CAE12934CE7}" = Canon RAW Image Task for ZoomBrowser EX
"InstallShield_{4C96958A-6562-4143-B820-FF4890D3B734}" = Canon Camera Window DVC for ZoomBrowser EX
"InstallShield_{8AF1E098-1A5C-4336-BBE2-D047ABB401ED}" = Canon MovieEdit Task for ZoomBrowser EX
"InstallShield_{91203BD3-6C3E-472F-ADBD-F60FDC7C4010}" = Canon Camera Window DS for ZoomBrowser EX
"InstallShield_{91F1A0D6-23AD-49FE-8D4E-379485652214}" = Canon Camera Support Core Library
"InstallShield_{C7281207-4AA4-425E-B57A-0E9EF8445635}" = Canon Camera Window for ZoomBrowser EX
"Logitech Resource Center" = Logitech Resource Center
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.5.8)" = Mozilla Firefox (3.5.8)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NimoCorp" = Nimo Codecs Pack v5.0 (Remove Only)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Office8.0" = Microsoft Office 97, Professional Edition
"PCI Audio Applications" = PCI Audio Applications
"PCI Audio Driver" = PCI Audio Driver
"Pdf995" = Pdf995 (installed by TaxCut)
"PdfEdit995" = PdfEdit995 (installed by TaxCut)
"Picasa 3" = Picasa 3
"Pop-Up Stopper" = Pop-Up Stopper
"Revo Uninstaller" = Revo Uninstaller 1.85
"Secunia PSI" = Secunia PSI
"SiSoftware Sandra Standard 2004.SP1 (Win32 x86)_is1" = SiSoftware Sandra Standard 2004.SP1 (StarSoft Edition)
"SpywareBlaster_is1" = SpywareBlaster 4.2
"TaxCut 2002" = TaxCut 2002
"TaxCut 2003" = TaxCut 2003
"TaxCut 2004" = TaxCut 2004
"TaxCut Premium 2006" = TaxCut Premium 2006
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XviD" = XviD Video Codec 04102002-1 (Koepi's build with EPSZ ME)

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 12/05/08 8:28:31 AM | Computer Name = WDJD | Source = avast! | ID = 33554522
Description = Internal error has occurred in module basEncodeFileToSubmit failed!
, function 0000007B.

Error - 12/05/08 8:28:32 AM | Computer Name = WDJD | Source = avast! | ID = 33554522
Description = Internal error has occurred in module basEncodeFileToSubmit failed!
, function 0000007B.

Error - 12/05/08 8:28:32 AM | Computer Name = WDJD | Source = avast! | ID = 33554522
Description = Internal error has occurred in module basEncodeFileToSubmit failed!
, function 0000007B.

Error - 12/05/08 8:28:32 AM | Computer Name = WDJD | Source = avast! | ID = 33554522
Description = Internal error has occurred in module basEncodeFileToSubmit failed!
, function 0000007B.

Error - 12/05/08 8:28:33 AM | Computer Name = WDJD | Source = avast! | ID = 33554522
Description = Internal error has occurred in module basEncodeFileToSubmit failed!
, function 0000007B.

Error - 12/05/08 8:28:33 AM | Computer Name = WDJD | Source = avast! | ID = 33554522
Description = Internal error has occurred in module basEncodeFileToSubmit failed!
, function 0000007B.

Error - 12/05/08 8:28:33 AM | Computer Name = WDJD | Source = avast! | ID = 33554522
Description = Internal error has occurred in module basEncodeFileToSubmit failed!
, function 0000007B.

Error - 12/05/08 8:28:34 AM | Computer Name = WDJD | Source = avast! | ID = 33554522
Description = Internal error has occurred in module basEncodeFileToSubmit failed!
, function 0000007B.

Error - 12/05/08 8:28:34 AM | Computer Name = WDJD | Source = avast! | ID = 33554522
Description = Internal error has occurred in module basEncodeFileToSubmit failed!
, function 0000007B.

Error - 11/05/09 4:47:50 PM | Computer Name = WDJD | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://clients1.google.com/complete/search…ansion%20mobile
failed, 0000A413.

[ Application Events ]
Error - 03/04/10 7:56:35 PM | Computer Name = WDJD | Source = LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The Error code is the first DWORD in Data section.

Error - 03/04/10 7:56:39 PM | Computer Name = WDJD | Source = LoadPerf | ID = 3006
Description = Unable to read the performance counter strings of the 009 language
ID. The Win32 status returned by the call is the first DWORD in Data section.

Error - 03/04/10 9:04:30 PM | Computer Name = WDJD | Source = LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The Error code is the first DWORD in Data section.

Error - 03/04/10 9:04:33 PM | Computer Name = WDJD | Source = LoadPerf | ID = 3006
Description = Unable to read the performance counter strings of the 009 language
ID. The Win32 status returned by the call is the first DWORD in Data section.

Error - 03/04/10 9:07:13 PM | Computer Name = WDJD | Source = LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The Error code is the first DWORD in Data section.

Error - 03/04/10 9:07:16 PM | Computer Name = WDJD | Source = LoadPerf | ID = 3006
Description = Unable to read the performance counter strings of the 009 language
ID. The Win32 status returned by the call is the first DWORD in Data section.

Error - 03/05/10 8:03:21 AM | Computer Name = WDJD | Source = LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The Error code is the first DWORD in Data section.

Error - 03/05/10 8:03:25 AM | Computer Name = WDJD | Source = LoadPerf | ID = 3006
Description = Unable to read the performance counter strings of the 009 language
ID. The Win32 status returned by the call is the first DWORD in Data section.

Error - 03/05/10 8:06:06 AM | Computer Name = WDJD | Source = LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The Error code is the first DWORD in Data section.

Error - 03/05/10 8:06:10 AM | Computer Name = WDJD | Source = LoadPerf | ID = 3006
Description = Unable to read the performance counter strings of the 009 language
ID. The Win32 status returned by the call is the first DWORD in Data section.

[ System Events ]
Error - 03/04/10 11:05:29 AM | Computer Name = WDJD | Source = System Error | ID = 1003
Description = Error code 1000008e, parameter1 c0000005, parameter2 80564184, parameter3
b26c2564, parameter4 00000000.

Error - 03/04/10 12:30:52 PM | Computer Name = WDJD | Source = Service Control Manager | ID = 7000
Description = The %OWC_USBEHCD.DeviceDesc% service failed to start due to the following
error: %%1058

Error - 03/04/10 12:30:52 PM | Computer Name = WDJD | Source = Service Control Manager | ID = 7000
Description = The Iomega Active Disk service failed to start due to the following
error: %%3

Error - 03/04/10 7:52:32 PM | Computer Name = WDJD | Source = Service Control Manager | ID = 7000
Description = The %OWC_USBEHCD.DeviceDesc% service failed to start due to the following
error: %%1058

Error - 03/04/10 7:52:32 PM | Computer Name = WDJD | Source = Service Control Manager | ID = 7000
Description = The Iomega Active Disk service failed to start due to the following
error: %%3

Error - 03/04/10 8:02:52 PM | Computer Name = WDJD | Source = Fasttrak | ID = 262153
Description = The device, \Device\Scsi\Fasttrak1, did not respond within the timeout
period.

Error - 03/04/10 9:03:15 PM | Computer Name = WDJD | Source = Service Control Manager | ID = 7000
Description = The %OWC_USBEHCD.DeviceDesc% service failed to start due to the following
error: %%1058

Error - 03/04/10 9:03:15 PM | Computer Name = WDJD | Source = Service Control Manager | ID = 7000
Description = The Iomega Active Disk service failed to start due to the following
error: %%3

Error - 03/05/10 8:02:09 AM | Computer Name = WDJD | Source = Service Control Manager | ID = 7000
Description = The %OWC_USBEHCD.DeviceDesc% service failed to start due to the following
error: %%1058

Error - 03/05/10 8:02:09 AM | Computer Name = WDJD | Source = Service Control Manager | ID = 7000
Description = The Iomega Active Disk service failed to start due to the following
error: %%3


< End of report >
Hi :)

I see Comodo Internet Security installed. Do you only use the firewall or the complete Security Suite with Antivirus?


Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
Hey Tom, I'm going to start the scan you ordered now. Mama needed the computer for a rummage sales for the grand kids. Happy wife happy life! Comodo is firewall only. You have a great day, Bill
Tom,

things didn't go just right. Worked from IE8, got to the click start after allowing AstiveX control to install. Got a box remove found threats, and it was checked. There was no Scan unwanted applications to check. there was an option to scan archives which I checked. Turned off comodo and avast, and clicked scan. The scan took about 90 seconds.

Puzzled,
Bill

Logfile:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
esets_scanner_update returned -1 esets_gle=0
# version=7
# IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=4356bc19810bbe4085a059d773efb6e9
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-03-07 12:57:52
# local_time=2010-03-06 06:57:52 (-0600, Central Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=769 16775141 100 98 0 203286626 0 0
# compatibility_mode=2560 16777215 100 0 0 0 0 0
# compatibility_mode=3073 16777213 80 89 1031716 24802724 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=0
# found=0
# cleaned=0
# scan_time=0
esets_scanner_update returned -1 esets_gle=0
# version=7
# IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=4356bc19810bbe4085a059d773efb6e9
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-03-07 01:12:36
# local_time=2010-03-06 07:12:36 (-0600, Central Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=769 16775141 100 98 0 203287510 0 0
# compatibility_mode=2560 16777215 100 0 0 0 0 0
# compatibility_mode=3073 16777213 80 89 1032600 24803608 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=0
# found=0
# cleaned=0
# scan_time=0
Hi,

Did not work, let's try another one.


Please run a BitDefender Online Scan
  • Click I Agree to agree to the EULA.
  • Allow the ActiveX control to install when prompted.
  • Click Click here to scan to begin the scan.
  • Please refrain from using the computer until the scan is finished. This might take a while to run, but it is important that nothing else is running while you scan.
  • When the scan is finished, click on Click here to export the scan results.
  • Save the report to your desktop so you can post it in your next reply.
Hey Tom, Here is the BitDefender log. Have a great day, Bill BitDefender QuickScan Beta 32-bit v0.9.9.9 —————————————— Scan date: Sun Mar 07 13:29:51 2010 Machine ID: E50 No infection found. ——————— Processes ——— AsusProb.exe 1664 D:\Program Files\ASUS\Probe\AsusProb.exe Iomega App Services 2408 C:\Program Files\Iomega\System32\AppServices.exe iTouch 1672 D:\Program Files\Logitech\iTouch\iTouch.exe MCC Monitor 1896 C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe MouseWare 1680 D:\Program Files\Logitech\MouseWare\SYSTEM\EM_EXEC.EXE OSA.EXE 1852 D:\Program Files\Microsoft Office\Office\OSA.EXE Pop-Up Stopper 1688 C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe Adobe Photoshop Album Starter Edition 1712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe Apple Mobile Device Service 2360 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe avast! Antivirus 1704 C:\Program Files\Alwil Software\Avast4\ashDisp.exe avast! Antivirus 3100 C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe avast! Antivirus 1436 C:\Program Files\Alwil Software\Avast4\ashServ.exe avast! Antivirus 3132 C:\Program Files\Alwil Software\Avast4\ashWebSv.exe avast! Antivirus 1388 C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe Bonjour 2380 C:\Program Files\Bonjour\mDNSResponder.exe COMODO Internet Security 1720 C:\Program Files\COMODO\COMODO Internet Security\cfp.exe COMODO Internet Security 912 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe Firefox 1064 C:\Program Files\Mozilla Firefox\firefox.exe Java™ Platform SE 6 U18 2464 C:\Program Files\Java\jre6\bin\jqs.exe Java™ Platform SE Auto Updater 2 0 1756 C:\Program Files\Common Files\Java\Java Update\jusched.exe Microsoft® Windows® Operating System 1468 C:\WINDOWS\Explorer.EXE Microsoft® Windows® Operating System 3480 C:\WINDOWS\System32\alg.exe Microsoft® Windows® Operating System 556 C:\WINDOWS\system32\csrss.exe Microsoft® Windows® Operating System 1788 C:\WINDOWS\system32\ctfmon.exe Microsoft® Windows® Operating System 644 C:\WINDOWS\system32\lsass.exe Microsoft® Windows® Operating System 624 C:\WINDOWS\system32\services.exe Microsoft® Windows® Operating System 492 C:\WINDOWS\System32\smss.exe Microsoft® Windows® Operating System 444 C:\WINDOWS\system32\spoolsv.exe Microsoft® Windows® Operating System 1272 C:\WINDOWS\system32\svchost.exe Microsoft® Windows® Operating System 1148 C:\WINDOWS\System32\svchost.exe Microsoft® Windows® Operating System 952 C:\WINDOWS\system32\svchost.exe Microsoft® Windows® Operating System 844 C:\WINDOWS\system32\svchost.exe Microsoft® Windows® Operating System 796 C:\WINDOWS\system32\svchost.exe Microsoft® Windows® Operating System 2320 C:\WINDOWS\System32\svchost.exe Microsoft® Windows® Operating System 2532 C:\WINDOWS\System32\svchost.exe Microsoft® Windows® Operating System 580 C:\WINDOWS\system32\winlogon.exe Mixer 1656 C:\WINDOWS\Mixer.exe Secunia PSI 1912 C:\Program Files\Secunia\PSI\psi.exe ThreatFire 2552 C:\Program Files\ThreatFire\TFService.exe ThreatFire 1728 C:\Program Files\ThreatFire\TFTray.exe Network activity —————- Process ashWebSv.exe (3132) connected on port 80 (HTTP) - a72-246-149-115.deploy.akamaitechnologies.com Process ashWebSv.exe (3132) connected on port 80 (HTTP) - yw-in-f100.1e100.net Process ashWebSv.exe (3132) connected on port 80 (HTTP) - yw-in-f100.1e100.net Process ashWebSv.exe (3132) connected on port 80 (HTTP) - [removed] Process ashWebSv.exe (3132) connected on port 80 (HTTP) - dc3.122.2o7.net Process svchost.exe (844) listens on ports: 135 (RPC) Autoruns and critical files ————————— Ahead Software Gmbh NeroCheck C:\WINDOWS\system32\\NeroCheck.exe AsusProb.exe D:\Program Files\ASUS\Probe\AsusProb.exe iTouch D:\Program Files\Logitech\iTouch\iTouch.exe MouseWare D:\Program Files\Logitech\MouseWare\SYSTEM\EM_EXEC.EXE Pop-Up Stopper C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe QuickTime C:\Program Files\QuickTime\QTTask.exe Adobe Acrobat C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe Adobe Photoshop Album Starter Edition C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe Adobe Reader and Acrobat Manager C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe Apple Software Update C:\Program Files\Apple Software Update\SoftwareUpdate.exe avast! Antivirus C:\Program Files\Alwil Software\Avast4\ashDisp.exe COMODO Internet Security C:\Program Files\COMODO\COMODO Internet Security\cfp.exe Java™ Platform SE Auto Updater 2 0 C:\Program Files\Common Files\Java\Java Update\jusched.exe Microsoft® Windows® Operating System C:\WINDOWS\System32\BROWSEUI.DLL Microsoft® Windows® Operating System C:\WINDOWS\System32\CRYPT32.DLL Microsoft® Windows® Operating System C:\WINDOWS\System32\CRYPTNET.DLL Microsoft® Windows® Operating System C:\WINDOWS\System32\CSCDLL.DLL Microsoft® Windows® Operating System C:\WINDOWS\system32\ctfmon.exe Microsoft® Windows® Operating System C:\WINDOWS\System32\DIMSNTFY.DLL Microsoft® Windows® Operating System C:\WINDOWS\system32\dumprep.exe Microsoft® Windows® Operating System C:\WINDOWS\system32\logonui.exe Microsoft® Windows® Operating System C:\WINDOWS\system32\sclgntfy.dll Microsoft® Windows® Operating System C:\WINDOWS\System32\SHELL32.DLL Microsoft® Windows® Operating System C:\WINDOWS\System32\STOBJECT.DLL Microsoft® Windows® Operating System c:\windows\system32\userinit.exe Microsoft® Windows® Operating System C:\WINDOWS\System32\WLNOTIFY.DLL Microsoft® Windows® Operating System C:\WINDOWS\System32\WPDShServiceObj.dll Mixer C:\WINDOWS\Mixer.exe ThreatFire C:\Program Files\ThreatFire\TFTray.exe Windows Genuine Advantage C:\WINDOWS\System32\WgaLogon.dll Windows® Internet Explorer C:\WINDOWS\System32\WEBCHECK.DLL Browser plugins ————— Bonjour C:\Program Files\Bonjour\mdnsNSP.dll Garmin Communicator Plug-In C:\Program Files\Garmin GPS Plugin\npGarmin.dll QuickTime Plug-in 7.6.5 C:\Program Files\Internet Explorer\plugins\npqtplugin.dll QuickTime Plug-in 7.6.5 C:\Program Files\Internet Explorer\plugins\npqtplugin2.dll QuickTime Plug-in 7.6.5 C:\Program Files\Internet Explorer\plugins\npqtplugin3.dll QuickTime Plug-in 7.6.5 C:\Program Files\Internet Explorer\plugins\npqtplugin4.dll QuickTime Plug-in 7.6.5 C:\Program Files\Internet Explorer\plugins\npqtplugin5.dll QuickTime Plug-in 7.6.5 C:\Program Files\Internet Explorer\plugins\npqtplugin6.dll QuickTime Plug-in 7.6.5 C:\Program Files\Internet Explorer\plugins\npqtplugin7.dll QuickTime Plug-in 7.6.5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll QuickTime Plug-in 7.6.5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll QuickTime Plug-in 7.6.5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll QuickTime Plug-in 7.6.5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll QuickTime Plug-in 7.6.5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll QuickTime Plug-in 7.6.5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll QuickTime Plug-in 7.6.5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll Shockwave for Director C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll AcroIEHelperShim Library c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll Adobe Acrobat C:\Program Files\Internet Explorer\plugins\nppdf32.dll Adobe Acrobat C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll Adobe® Flash® Player ActiveX C:\WINDOWS\Downloaded Program Files\CONFLICT.1\FP_AX_CAB_INSTALLER.exe Adobe® Flash® Player ActiveX C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe BitDefender QuickScan C:\Documents and Settings\Judy Dengler\Application Data\Mozilla\Firefox\Profiles/d7r4uq94.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll BitDefender QuickScan C:\Documents and Settings\Judy Dengler\Application Data\Mozilla\Firefox\Profiles/d7r4uq94.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll Java Deployment Toolkit 6.0.180.7 C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll Java™ Platform SE 6 U18 c:\program files\java\jre6\bin\jp2ssv.dll Java™ Platform SE 6 U18 c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll Messenger C:\Program Files\Messenger\msmsgs.exe Microsoft® Windows® Operating System C:\WINDOWS\Network Diagnostic\xpnetdiag.exe Microsoft® Windows® Operating System C:\WINDOWS\System32\MSWSOCK.DLL Microsoft® Windows® Operating System C:\WINDOWS\system32\rsvpsp.dll Microsoft® Windows® Operating System C:\WINDOWS\System32\WINRNR.DLL Mozilla Default Plug-in C:\Program Files\Mozilla Firefox\plugins\npnul32.dll NPSWF32.dll C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll Panda ActiveScan 2.0 C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll Picasa C:\Program Files\Google\Picasa3\npPicasa3.dll sdhelper.dll c:\program files\spybot - search & destroy\sdhelper.dll Windows® Internet Explorer C:\WINDOWS\System32\IEFRAME.DLL Scan —- MD5: a5a5af3a7a1dbd4583e3bf577791287d C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\APDBOOT.DLL MD5: 561fa2abb31dfa8fab762145f81667c2 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\MSVCP71.DLL MD5: 86f1895ae8c5e8b17d99ece768a70732 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\MSVCR71.DLL MD5: 6ca1292225b47a5421e941b3cfef48af C:\Program Files\Alwil Software\Avast4\Aavm4h.dll MD5: f3eac60879ae425d81dba70c3da76d13 C:\Program Files\Alwil Software\Avast4\AavmRpch.dll MD5: 60da054e9ddfc242346b879eaaf1ebce C:\Program Files\Alwil Software\Avast4\AhResMai.dll MD5: a7469e3be8770e7015ca499ba6729568 C:\Program Files\Alwil Software\Avast4\ahResMes.dll MD5: b3840eb1f44c28ca25d304fd1da86954 C:\Program Files\Alwil Software\Avast4\AhResNS.dll MD5: d3de25c3ca9bce6805e028c5dd304304 C:\Program Files\Alwil Software\Avast4\AhResOut.dll MD5: 6e5e0ee9c837229c26c3b53b2036e44d C:\Program Files\Alwil Software\Avast4\ahResP2P.dll MD5: 816cae36b3d430622eb4d40cf9cc1e82 C:\Program Files\Alwil Software\Avast4\AhResStd.dll MD5: 0c923a24fb7e7d6b4d210537f36e5296 C:\Program Files\Alwil Software\Avast4\AhResWS.dll MD5: 02bd0feacaa1a65f77806a3c3debd046 C:\Program Files\Alwil Software\Avast4\AhRuiMai.dll MD5: 27bb54223d4aaebbeb0e65df776cf6c2 C:\Program Files\Alwil Software\Avast4\ahRuiMes.dll MD5: 99c120153031fbd057d4fa0499fff755 C:\Program Files\Alwil Software\Avast4\AhRuiNS.dll MD5: 9625471205dfc433fb73e231fc9cbb01 C:\Program Files\Alwil Software\Avast4\AhRuiOut.dll MD5: e5c7e4c34e43bfd68de1cf2034fe9af8 C:\Program Files\Alwil Software\Avast4\ahRuiP2P.dll MD5: cb39a7024be54e75e3b696272fdc0987 C:\Program Files\Alwil Software\Avast4\AhRuiStd.dll MD5: 8f933065a585eafd798dd5e49598cdcb C:\Program Files\Alwil Software\Avast4\AhRuiWS.dll MD5: e8b0edd5c8518d9a1f73ac0c54a94d7c C:\Program Files\Alwil Software\Avast4\ashBase.dll MD5: b26cf29c64fdf7876d0e81c27c80f7bf C:\Program Files\Alwil Software\Avast4\ashSSqlt.dll MD5: 0b9dbfe71f4eb4355985ee60e6a1dc3f C:\Program Files\Alwil Software\Avast4\ashTask.dll MD5: fce48f51523e38c5e74969766b353d73 C:\Program Files\Alwil Software\Avast4\ashUInt.dll MD5: 8ea778943b7e155991ae9e3c818269ab C:\Program Files\Alwil Software\Avast4\aswAux.dll MD5: f8df17a0090f29ee330b34145152f38a C:\Program Files\Alwil Software\Avast4\aswCmnB.dll MD5: 6d6416fa182fa865d265dffa5a03c3c2 C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll MD5: 7d79cd441ed208d062b326145c7b3aed C:\Program Files\Alwil Software\Avast4\aswCmnS.dll MD5: 144137d2e91504f551e82135673d89ae C:\Program Files\Alwil Software\Avast4\aswEngin.dll MD5: d933b267939363888a40f86017561552 C:\Program Files\Alwil Software\Avast4\aswInteg.dll MD5: 7604efea62acc8e90c8d7dcc58d577af C:\Program Files\Alwil Software\Avast4\aswRes.dll MD5: 9fb2179200238536b788cb4046c61c24 C:\Program Files\Alwil Software\Avast4\aswScan.dll MD5: 6b115977a1ca2999eb626e85f3e13333 C:\Program Files\Alwil Software\Avast4\ENGLISH\Base.dll MD5: bc517179b72ca423f2c0d90413d345f7 C:\Program Files\Alwil Software\Avast4\ENGLISH\Lang.dll MD5: 2b2c74a7cc896d33638b74e4187ace24 C:\Program Files\Alwil Software\Avast4\ENGLISH\LangMai.dll MD5: 6c08604b5465de19eaac58c6a537d0bf C:\Program Files\Alwil Software\Avast4\XT1922.dll MD5: dd9f5616505d6fe064eacfe21a009f49 C:\Program Files\ArcSoft\Media Card Companion\EzDll.dll MD5: 19f2f9227aeb3684df1b48b731a8fbde C:\Program Files\ArcSoft\Media Card Companion\FPXLIB.DLL MD5: aa4392765bae85ed47c76949235ec6b5 C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe MD5: ae2aa827d722395b1af71d4ad6b78b3d C:\Program Files\ArcSoft\Media Card Companion\Res_Monitor.dll MD5: a89c5aa9c159ac0df576643f2461359c C:\Program Files\ArcSoft\Media Card Companion\ustor.dll MD5: 292f92469efb2fd402e00742c06d539d C:\Program Files\Bonjour\mdnsNSP.dll MD5: 64b0d7ef65536317ee3f41f352b63e42 C:\Program Files\Garmin GPS Plugin\npGarmin.dll MD5: da548872c3126b09d7832b4abeb54116 C:\Program Files\Internet Explorer\plugins\npqtplugin.dll MD5: da548872c3126b09d7832b4abeb54116 C:\Program Files\Internet Explorer\plugins\npqtplugin2.dll MD5: da548872c3126b09d7832b4abeb54116 C:\Program Files\Internet Explorer\plugins\npqtplugin3.dll MD5: da548872c3126b09d7832b4abeb54116 C:\Program Files\Internet Explorer\plugins\npqtplugin4.dll MD5: da548872c3126b09d7832b4abeb54116 C:\Program Files\Internet Explorer\plugins\npqtplugin5.dll MD5: da548872c3126b09d7832b4abeb54116 C:\Program Files\Internet Explorer\plugins\npqtplugin6.dll MD5: da548872c3126b09d7832b4abeb54116 C:\Program Files\Internet Explorer\plugins\npqtplugin7.dll MD5: 93dafaacfb30f22d401b04b6b0cba514 C:\Program Files\Iomega\System32\AppServices.exe MD5: 86f1895ae8c5e8b17d99ece768a70732 C:\Program Files\Java\jre6\bin\MSVCR71.DLL MD5: 1aab00ae4ffb5c72a0a06a254f80510e C:\Program Files\Mozilla Firefox\freebl3.dll MD5: 39dfd2c92728fca093d5bdefe5f6e801 C:\Program Files\Mozilla Firefox\nssdbm3.dll MD5: 90d8ea7fd1097dca1fc90a78fe2c8fdf C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll MD5: da548872c3126b09d7832b4abeb54116 C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll MD5: da548872c3126b09d7832b4abeb54116 C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll MD5: da548872c3126b09d7832b4abeb54116 C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll MD5: da548872c3126b09d7832b4abeb54116 C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll MD5: da548872c3126b09d7832b4abeb54116 C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll MD5: da548872c3126b09d7832b4abeb54116 C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll MD5: da548872c3126b09d7832b4abeb54116 C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll MD5: 89e6d66ec90b4e8e41b55248eb7c84cb C:\Program Files\Mozilla Firefox\softokn3.dll MD5: 1b1d95e41964c93c2a46677db3246b5f C:\Program Files\Panicware\Pop-Up Stopper\DPHOOK32.DLL MD5: 8c73b323cc7c57c30d92f3a2ea008cc4 C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe MD5: 55d7a219ad8d0db8980528944152a6fd C:\Program Files\QuickTime\QTTask.exe MD5: 43a72158b4e787d57cf441bb1c87fad4 C:\Program Files\Secunia\PSI\psires.dll MD5: 3e9a33113d663d8bd5ed38858e669652 C:\Program Files\ThreatFire\ATL80.DLL MD5: 9452c46d2bc9b7129468ad3b395c540f C:\WINDOWS\PANICNT.DLL MD5: 3e4c03cefad8de135263236b61a49c90 C:\WINDOWS\system32\\NeroCheck.exe MD5: 2a1a7a3d6da6d66a9fa17d91dfbe6168 C:\WINDOWS\System32\COMNCTR.DLL MD5: 71356a1370739e25375a1d17b6ae318f C:\WINDOWS\system32\drivers\aslm75.sys MD5: d4bcb167794fa92d374fce68f65814a4 C:\WINDOWS\system32\drivers\Fasttrak.sys MD5: 9d7069d72c0c72952f05e1688a5ae89d C:\WINDOWS\System32\DRIVERS\iomdisk.sys MD5: a8075787fe38204d8f176fb6be40cf38 C:\WINDOWS\System32\Drivers\ousbehci.sys MD5: db2e4fc8afb22525d90818a30f53ec11 C:\WINDOWS\system32\DRIVERS\psi_mf.sys MD5: 662626bccf060f2f4b6d5af7ac121ff5 C:\WINDOWS\System32\Drivers\VIAPFD.SYS MD5: c0f55cc0903cfdc819f6d857402b697c C:\WINDOWS\System32\Drivers\vulfnth.sys MD5: 545d98a7f61af1c7c4ad38b8f333e0b7 C:\WINDOWS\System32\Drivers\vulfntr.sys MD5: cf08093c5a7a0ca3c681e3d313fe1f7b C:\WINDOWS\System32\LOGILANG.DLL MD5: f35a584e947a5b401feb0fe01db4a0d7 C:\WINDOWS\System32\MFC71.DLL MD5: 561fa2abb31dfa8fab762145f81667c2 C:\WINDOWS\System32\MSVCP71.DLL MD5: 86f1895ae8c5e8b17d99ece768a70732 C:\WINDOWS\System32\MSVCR71.DLL MD5: af238673651efc0226ea74239b502a6f C:\WINDOWS\System32\pdf995mon.dll MD5: 14346fa3755d9decd4b051804962b6b0 C:\WINDOWS\System32\rsvp.exe MD5: 0354ba0abd9386eb800880f20fcdbe4c C:\WINDOWS\SYSTEM\bcbsmp35.bpl MD5: d0dfe2ec29c8531e168da914b36a0bb7 C:\WINDOWS\SYSTEM\CP3240MT.DLL MD5: d971f2c84df82094a4c099d8e5353cec D:\Program Files\ASUS\Probe\ASMIAHD.dll MD5: 3f5d7739af4caf4d2a4a6523d20ed3ea D:\Program Files\ASUS\Probe\AsmiAsus.dll MD5: 6902c33963d433596627efd58cacc135 D:\Program Files\ASUS\Probe\AsmiCtrl.dll MD5: a441c19569134ec2fea9cf5a338cefde D:\Program Files\ASUS\Probe\ASMIDMI.dll MD5: f68be67b88151e1ddec7e0c5ac91dd65 D:\Program Files\ASUS\Probe\AsmiEnum.dll MD5: 4c202895093b1b8b50dc9af336a9050c D:\Program Files\ASUS\Probe\AsmiHwIo.dll MD5: 75723bedf0b468161cb85201f117c98d D:\Program Files\ASUS\Probe\AsmiVia.dll MD5: a01ed01ffcb6d9af437fcf1161a4ab69 D:\Program Files\ASUS\Probe\Asus.dll MD5: efc0029d585b2301239b9a3482e6d976 D:\Program Files\ASUS\Probe\AsusProb.exe MD5: 568089f201cf42a81a4e0ec02dd9f321 D:\Program Files\ASUS\Probe\CODISK.DLL MD5: bbb38c4459e8ef601b4ae4d3b8e74eb4 D:\Program Files\ASUS\Probe\CODMI.DLL MD5: 95fe710e964994f24117a730bb06b97c D:\Program Files\ASUS\Probe\COLM7578.DLL MD5: 873a6ffbca7c1592a5b697e33ee65613 D:\Program Files\ASUS\Probe\COLMIco.dll MD5: fc9af9c3cc765d9adb9ffab2dcd6393a D:\Program Files\ASUS\Probe\DiskIco.dll MD5: 448f24ffc0b7588e0a4aece0b0388428 D:\Program Files\Logitech\iTouch\iTouch.exe MD5: edacb36115d7f12a8b1e5655561026b8 D:\Program Files\Logitech\iTouch\iTouchrc.dll MD5: c0641535f024fcb0a92090a6e32e9381 D:\Program Files\Logitech\iTouch\KbdHook.dll MD5: 32f14e32d983b115e67073b0c0e5afe0 D:\Program Files\Logitech\MouseWare\SYSTEM\ccmsghk.dll MD5: e61304e0c3bd2efc52590a21e9e383f3 D:\Program Files\Logitech\MouseWare\SYSTEM\ccresglb.dll MD5: c7f7c15177bb8135e4d65b2d89601856 D:\Program Files\Logitech\MouseWare\SYSTEM\ccresrce.dll MD5: db6cd05b68691b690b1dd83bebc65b50 D:\Program Files\Logitech\MouseWare\SYSTEM\ccstmglb.dll MD5: b32340a85525ef0b72730c32228e134d D:\Program Files\Logitech\MouseWare\SYSTEM\ccustom.dll MD5: 0b88eb812be6a018d092269732d9822f D:\Program Files\Logitech\MouseWare\SYSTEM\devices.dll MD5: e77f2af6d0757c9dd2d3f669f253e81d D:\Program Files\Logitech\MouseWare\SYSTEM\EM_EXEC.EXE MD5: 24c82c22292c57d972decf82e5056d34 D:\Program Files\Logitech\MouseWare\SYSTEM\EVENTEX.dll MD5: c95c9a0d4cf8d8f6daae6f832c7c865d D:\Program Files\Logitech\MouseWare\SYSTEM\LGMOUSHK.dll MD5: a430faae0a4db973500b6c882f8848e5 D:\Program Files\Logitech\MouseWare\SYSTEM\MFC42.DLL MD5: e0e632f9bb8cdcd80cf6808c5a65ee57 D:\Program Files\Microsoft Office\Office\MSO97.DLL MD5: 2684d7a15ae733fbdcb7707806b37553 D:\Program Files\Microsoft Office\Office\OSA.EXE MD5: 21fbf68c66ad1036d8f19b45101df4f2 D:\Program Files\Microsoft Office\Office\osaintl.dll The following file(s) must be uploaded for server-side scanning: D:\Program Files\ASUS\Probe\AsusProb.exe C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe C:\Program Files\Secunia\PSI\psires.dll D:\Program Files\Logitech\MouseWare\SYSTEM\EM_EXEC.EXE D:\Program Files\Logitech\iTouch\iTouch.exe C:\Program Files\Iomega\System32\AppServices.exe Upload started - 6 file(s) D:\Program Files\Logitech\MouseWare\SYSTEM\EM_EXEC.EXE (32256) C:\Program Files\Iomega\System32\AppServices.exe (77824) D:\Program Files\Logitech\iTouch\iTouch.exe (524288) D:\Program Files\ASUS\Probe\AsusProb.exe (625152) C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe (712704) C:\Program Files\Secunia\PSI\psires.dll (355840) Upload speed - 26 KB/s Upload finished - 6 uploaded, 0 failed The uploaded file(s) were found clean. Scan finished - communication took 89 sec Total traffic - 2.30 MB sent, 2.72 KB recvd Scanned 1121 files and modules - 351 seconds
Hey Tom,

Ran OTL form my downloads folder, and it didn't produce the Extras.txt file as it did on the first run. Used your mirror and downloaded OTL again and ran another scan, but still no Extras.txt file. I don't know whats up. I've included the last OTL.txt file.

my computer is a step slow–it takes several seconds to draw a drop down window such as Bookmarks.

Thanks,
Bill

OTL.txt

OTL logfile created on: 03/08/10 8:32:26 PM - Run 4
OTL by OldTimer - Version 3.1.35.0 Folder = C:\Documents and Settings\Judy Dengler\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yy

512.00 Mb Total Physical Memory | 154.00 Mb Available Physical Memory | 30.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 50.00% Paging File free
Paging file location(s): c:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.07 Gb Total Space | 23.50 Gb Free Space | 61.74% Space Free | Partition Type: FAT32
Drive D: | 37.34 Gb Total Space | 36.99 Gb Free Space | 99.04% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: WDJD
Current User Name: Judy Dengler
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/03/08 20:25:30 | 000,554,496 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Judy Dengler\My Documents\Downloads\OTL.exe
PRC - [2010/02/18 19:01:42 | 000,908,248 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/02/11 17:20:24 | 001,800,464 | —- | M] (COMODO) – C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
PRC - [2010/02/11 17:20:00 | 000,723,632 | —- | M] (COMODO) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2009/11/24 17:51:40 | 000,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/11/24 17:51:36 | 000,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/11/24 17:51:22 | 000,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/11/24 17:48:48 | 000,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009/11/24 17:43:56 | 000,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/09/23 08:07:38 | 000,382,224 | —- | M] (PC Tools) – C:\Program Files\ThreatFire\TFTray.exe
PRC - [2009/09/23 08:07:34 | 000,070,928 | —- | M] (PC Tools) – C:\Program Files\ThreatFire\TFService.exe
PRC - [2009/05/27 06:19:36 | 000,765,192 | —- | M] (Secunia) – C:\Program Files\Secunia\PSI\psi.exe
PRC - [2008/04/13 19:12:20 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/03/09 11:09:58 | 000,063,712 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
PRC - [2006/04/26 22:01:46 | 000,524,288 | —- | M] (Logitech Inc. ) – D:\Program Files\Logitech\iTouch\iTouch.exe
PRC - [2006/04/26 22:01:46 | 000,032,256 | —- | M] (Logitech Inc. ) – D:\Program Files\Logitech\MouseWare\SYSTEM\EM_EXEC.EXE
PRC - [2006/04/26 22:01:38 | 000,055,808 | —- | M] () – D:\Program Files\Microsoft Office\Office\OSA.EXE
PRC - [2006/04/26 22:01:26 | 000,625,152 | —- | M] () – D:\Program Files\ASUS\Probe\AsusProb.exe
PRC - [2006/04/26 21:52:12 | 000,712,704 | —- | M] (Panicware, Inc.) – C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe
PRC - [2006/04/26 21:51:40 | 000,077,824 | —- | M] (Iomega Corporation) – C:\Program Files\Iomega\System32\AppServices.exe
PRC - [2005/01/17 16:08:48 | 000,110,592 | —- | M] (Arcsoft, Inc.) – C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
PRC - [2001/10/22 12:24:28 | 001,216,512 | R— | M] (C-Media Electronic Inc. (www.cmedia.com.tw)) – C:\WINDOWS\mixer.exe


========== Modules (SafeList) ==========

MOD - [2010/03/08 20:25:30 | 000,554,496 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Judy Dengler\My Documents\Downloads\OTL.exe
MOD - [2009/09/23 08:07:42 | 000,455,952 | —- | M] (PC Tools) – C:\Program Files\ThreatFire\TFWAH.dll
MOD - [2002/05/29 01:59:00 | 000,024,576 | —- | M] (Logitech Inc. ) – D:\Program Files\Logitech\iTouch\KbdHook.dll
MOD - [2002/05/24 09:50:00 | 000,024,576 | —- | M] (Logitech Inc. ) – D:\Program Files\Logitech\MouseWare\SYSTEM\LGMOUSHK.DLL
MOD - [2002/04/29 11:24:24 | 000,057,344 | —- | M] () – C:\Program Files\Panicware\Pop-Up Stopper\DPHOOK32.dll
MOD - [2001/09/16 11:44:04 | 000,040,960 | —- | M] () – C:\WINDOWS\PANICNT.dll
MOD - [2001/08/18 12:00:00 | 000,014,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\serwvdrv.dll
MOD - [2001/08/18 12:00:00 | 000,013,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\umdmxfrm.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (Iomega Activity Disk2)
SRV - File not found [Auto | Stopped] – – (_IOMEGA_ACTIVE_DISK_SERVICE_)
SRV - [2010/02/11 17:20:00 | 000,723,632 | —- | M] (COMODO) [Auto | Running] – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe – (cmdAgent)
SRV - [2009/11/24 17:51:36 | 000,138,680 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus)
SRV - [2009/11/24 17:51:22 | 000,254,040 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner)
SRV - [2009/11/24 17:48:48 | 000,352,920 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner)
SRV - [2009/11/24 17:43:56 | 000,018,752 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv)
SRV - [2009/09/23 08:07:34 | 000,070,928 | —- | M] (PC Tools) [Auto | Running] – C:\Program Files\ThreatFire\TFService.exe – (ThreatFire)
SRV - [2006/04/26 21:51:40 | 000,077,824 | —- | M] (Iomega Corporation) [Auto | Running] – C:\Program Files\Iomega\System32\AppServices.exe – (Iomega App Services)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig?refresh=1#restore"
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.9
FF - prefs.js..extensions.enabledItems: [removed]:1.0


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/10/03 16:19:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2005/02/14 19:59:46 | 000,000,000 | —D | M]

[2008/08/26 13:25:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\Mozilla\Extensions
[2005/02/14 20:01:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\Mozilla\Firefox\Profiles\d7r4uq94.default\extensions
[2010/03/07 13:28:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Judy Dengler\Application Data\Mozilla\Firefox\Profiles\d7r4uq94.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2005/02/14 20:01:54 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/02/24 06:27:14 | 000,380,265 | R— | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13103 more lines…
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ASUS Probe] D:\Program Files\ASUS\Probe\AsusProb.exe ()
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [C-Media Mixer] C:\WINDOWS\mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw))
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [EM_EXEC] D:\Program Files\Logitech\MouseWare\SYSTEM\EM_EXEC.EXE (Logitech Inc. )
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe ()
O4 - HKLM..\Run: [Pop-Up Stopper] C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe (Panicware, Inc.)
O4 - HKLM..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe (PC Tools)
O4 - HKLM..\Run: [zBrowser Launcher] D:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc. )
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk = D:\Program Files\Microsoft Office\Office\OSA.EXE ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Find Fast.lnk = D:\Program Files\Microsoft Office\Office\FINDFAST.EXE ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = D:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
O4 - Startup: C:\Documents and Settings\Judy Dengler\Start Menu\Programs\Startup\Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe (Secunia)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: bleepingcomputer.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: mediafire.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([windowsupdate] http in Trusted sites)
O15 - HKCU\..Trusted Domains: nutnworks.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] http in Trusted sites)
O15 - HKCU\..Trusted Domains: zonealarm.com ([]http in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1146187722687 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1177595026046 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8121.6390856481 (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Judy Dengler\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Judy Dengler\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/12/31 05:48:42 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ FAT32 ]
O33 - MountPoints2\{eb9bb602-13ae-11de-9d46-000c41214de7}\Shell - "" = AutoRun
O33 - MountPoints2\{eb9bb602-13ae-11de-9d46-000c41214de7}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{eb9bb602-13ae-11de-9d46-000c41214de7}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2002/01/01 06:16:48 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\SYSTEM32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (86416155039760384)

========== Files/Folders - Created Within 14 Days ==========

[2010/03/07 13:29:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Judy Dengler\Application Data\QuickScan
[2010/03/04 06:40:55 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010/03/03 08:06:20 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/03/01 08:15:47 | 000,000,000 | —D | C] – C:\Program Files\TrendMicro
[2010/03/01 06:44:07 | 000,000,000 | —D | C] – C:\Rooter$
[2010/02/27 11:14:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Judy Dengler\Application Data\Uniblue
[2010/02/26 11:41:12 | 000,028,552 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\pavboot.sys
[2010/02/26 11:39:59 | 000,000,000 | —D | C] – C:\Program Files\Panda Security
[2009/11/22 06:47:18 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2009/11/22 06:47:16 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2009/05/20 15:08:06 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2008/03/24 10:08:56 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2008/03/24 10:08:56 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Mozilla
[2002/12/31 05:52:30 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2002/12/31 05:52:30 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2002/01/01 06:22:00 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2002/01/01 06:22:00 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/03/08 16:53:00 | 000,001,610 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/08 16:50:08 | 000,013,310 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/03/08 16:48:36 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/08 16:48:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/03/08 16:48:04 | 536,440,832 | -HS- | M] () – C:\hiberfil.sys
[2010/03/08 13:13:44 | 009,699,328 | —- | M] () – C:\Documents and Settings\Judy Dengler\ntuser.dat
[2010/03/08 13:13:44 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Judy Dengler\NTUSER.INI
[2010/03/04 06:02:18 | 536,469,504 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2010/03/03 08:08:36 | 000,001,516 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/03/03 08:06:42 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/03/01 09:07:08 | 000,000,523 | —- | M] () – C:\Documents and Settings\Judy Dengler\Desktop\NTREGOPT.lnk
[2010/03/01 09:07:08 | 000,000,504 | —- | M] () – C:\Documents and Settings\Judy Dengler\Desktop\ERUNT.lnk
[2010/03/01 08:15:50 | 000,001,996 | —- | M] () – C:\Documents and Settings\Judy Dengler\Desktop\HiJackThis.lnk
[2010/02/26 11:21:32 | 000,000,036 | —- | M] () – C:\Documents and Settings\Judy Dengler\Local Settings\Application Data\housecall.guid.cache
[2010/02/24 06:13:16 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/03/04 08:08:50 | 009,699,328 | —- | C] () – C:\Documents and Settings\Judy Dengler\ntuser.dat
[2010/03/03 08:08:34 | 000,001,516 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/03/03 08:06:40 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/03/01 09:07:06 | 000,000,523 | —- | C] () – C:\Documents and Settings\Judy Dengler\Desktop\NTREGOPT.lnk
[2010/03/01 09:07:06 | 000,000,504 | —- | C] () – C:\Documents and Settings\Judy Dengler\Desktop\ERUNT.lnk
[2010/03/01 08:15:48 | 000,001,996 | —- | C] () – C:\Documents and Settings\Judy Dengler\Desktop\HiJackThis.lnk
[2010/02/26 11:21:31 | 000,000,036 | —- | C] () – C:\Documents and Settings\Judy Dengler\Local Settings\Application Data\housecall.guid.cache
[2009/09/30 10:25:14 | 000,000,101 | —- | C] () – C:\WINDOWS\CMMIXER.INI
[2009/09/24 09:19:40 | 000,000,038 | —- | C] () – C:\Documents and Settings\Judy Dengler\Application Data\msnpromo.txt
[2009/05/18 09:18:42 | 000,000,130 | —- | C] () – C:\WINDOWS\cfplogvw.INI
[2009/03/30 11:14:54 | 000,000,065 | —- | C] () – C:\WINDOWS\boc427.ini
[2008/06/19 16:29:32 | 000,017,987 | —- | C] () – C:\Program Files\gpl-2.0.txt
[2008/03/06 12:16:08 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2007/09/04 10:14:05 | 000,045,056 | —- | C] () – C:\Documents and Settings\Judy Dengler\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/08 13:24:51 | 000,000,141 | —- | C] () – C:\WINDOWS\wpd99.drv
[2007/02/08 13:24:35 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2007/01/02 16:32:05 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2006/10/06 14:11:06 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\vusetup.dll
[2004/11/07 08:00:18 | 000,000,000 | —- | C] () – C:\Documents and Settings\Judy Dengler\Application Data\dm.ini
[2004/05/14 16:36:38 | 000,045,056 | —- | C] () – C:\WINDOWS\PANIC32.dll
[2004/05/14 16:36:38 | 000,040,960 | —- | C] () – C:\WINDOWS\PANICNT.dll
[2004/01/08 16:46:07 | 000,000,182 | —- | C] () – C:\WINDOWS\AtxTCBizControl03.ini
[2004/01/08 16:45:57 | 000,000,106 | —- | C] () – C:\WINDOWS\AtxTCBizPref03.ini
[2003/01/01 16:51:49 | 000,000,028 | —- | C] () – C:\WINDOWS\ICOA.INI
[2003/01/01 16:51:36 | 000,000,000 | —- | C] () – C:\WINDOWS\QFN.INI
[2003/01/01 16:51:36 | 000,000,000 | —- | C] () – C:\WINDOWS\QDQICK.INI
[2003/01/01 16:25:40 | 000,098,816 | —- | C] () – C:\WINDOWS\System32\LGUICOM.DLL
[2003/01/01 16:25:40 | 000,000,488 | —- | C] () – C:\WINDOWS\Cmousecc.ini
[2003/01/01 14:00:42 | 000,000,012 | —- | C] () – C:\WINDOWS\QBWCD.INI
[2003/01/01 13:55:21 | 000,000,611 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/01/01 13:55:21 | 000,000,022 | —- | C] () – C:\WINDOWS\EXCHNG.INI
[2003/01/01 00:11:47 | 000,006,272 | —- | C] () – C:\WINDOWS\System32\drivers\ASLM75.SYS
[2003/01/01 00:10:35 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\VIDX16.DLL
[2003/01/01 00:10:31 | 000,003,698 | —- | C] () – C:\WINDOWS\MIXERDEF.INI
[2003/01/01 00:10:07 | 000,000,312 | —- | C] () – C:\WINDOWS\CMISETUP.INI
[2003/01/01 00:10:03 | 000,000,026 | —- | C] () – C:\WINDOWS\CMCDPLAY.INI
[2002/12/31 08:06:09 | 000,003,060 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2002/12/31 08:05:50 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2002/10/15 16:54:04 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2002/10/06 12:42:58 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 17:04:26 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2002/10/04 17:04:26 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 17:04:18 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/10/04 00:01:42 | 000,503,808 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2002/05/15 18:38:40 | 000,091,136 | —- | C] () – C:\WINDOWS\System32\mp4fil32.dll
[2002/05/04 08:19:00 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\avisynthEx.dll
[2002/04/19 09:23:26 | 000,106,137 | —- | C] () – C:\WINDOWS\System32\libpostproc.dll
[2002/04/19 08:51:04 | 000,211,760 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2001/06/22 06:06:02 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\MPEG2DEC.dll
[1997/08/01 00:00:00 | 000,031,232 | —- | C] () – C:\WINDOWS\System32\XLREC.DLL
[1997/08/01 00:00:00 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\RECNCL.DLL
[1997/08/01 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/08/01 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL

========== LOP Check ==========

[2005/07/11 09:14:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATX
[2007/02/08 13:24:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2007/05/31 06:24:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2007/09/20 14:11:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/02/22 11:12:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TaxCut
[2008/08/02 08:50:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2009/03/30 11:31:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/05/16 08:45:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2003/01/01 15:50:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\Active Disk
[2003/03/28 08:43:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\Leadertech
[2005/02/14 20:07:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\Thunderbird
[2005/07/11 09:14:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\ATX
[2007/05/31 06:24:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\iolo
[2008/02/22 11:16:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\TaxCut
[2008/02/22 14:37:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\pdf995
[2008/06/14 13:32:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\GARMIN
[2008/10/27 09:33:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/02/27 11:14:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\Uniblue
[2010/03/07 13:29:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Judy Dengler\Application Data\QuickScan

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2006/04/26 21:44:16 | 000,077,312 | —- | M] (SiSoftware ) – C:\san2004.SP1-9104-Win32-SSO.exe
[2006/04/26 21:44:16 | 000,145,408 | —- | M] (Symantec Corporation) – C:\FixBlast.exe
[2006/04/26 21:44:16 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\WindowsXP-KB823980-x86-ENU.exe
[2006/04/26 21:44:16 | 000,167,936 | —- | M] (MadOnion.com) – C:\3dmark2001se.exe


< MD5 for: AGP440.SYS >
[2006/04/28 17:51:38 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/08/27 18:39:04 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2006/04/28 17:51:38 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/08/27 18:39:04 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys
[2004/08/04 01:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2002/08/29 03:50:10 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2006/04/28 17:51:38 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/08/27 18:39:04 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2002/08/29 03:50:10 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp1.cab:atapi.sys
[2006/04/28 17:51:38 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008/08/27 18:39:04 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys
[2004/08/04 00:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:54 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:54 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SYSTEM32\eventlog.dll
[2004/08/04 02:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:02 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:02 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SYSTEM32\netlogon.dll
[2004/08/04 02:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 02:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:06 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:06 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SYSTEM32\scecli.dll

< %systemroot%\*. /mp /s >
< End of report >
Let's try to speed it up a bit :)



Download and Run StartupLite


This program will identify startup entries that are unnecessary to be started at bootup. This will help free some memory.

  • Download StartupLite.exe by MalwareBytes to your desktop.
  • Double click on StartUpLite.exe to run it. If you are using Windows Vista, right click the icon and select Run As Administrator.
  • A list of unecessary startup entries will be compiled.
  • Take a read at the description of each and for most of them you probably won't need it please make sure there is a checkmark next to Disable.
  • Leave all the items as Disabled and click Continue.
  • Restart your computer once it's done.





Please download TFC by Old Timer and save it to your desktop.
alternate download link
  • Save any unsaved work. TFC will close ALL open programs including your browser!
  • Double-click on TFC.exe to run it. If you are using Vista, right-click on the file and choose Run As Administrator.
  • Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
  • Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.
TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder. It also cleans out the %systemroot%\temp folder and checks for .tmp files in the %systemdrive% root folder, %systemroot%, and the system32 folder (both 32bit and 64bit on 64bit OSs). It shows the amount removed for each location found (in bytes) and the total removed (in MB). Before running, it will stop Explorer and all other running apps. When finished, if a reboot is required the user must reboot to finish clearing any in-use temp files.

TFC only cleans temp folders. TFC will not clean URL history, prefetch, or cookies. Depending on how often someone cleans their temp folders, their system hardware, and how many accounts are present, it can take anywhere from a few seconds to a minute or more. TFC will completely clear all temp files where other temp file cleaners may fail. TFC requires a reboot immediately after running. Be sure to save any unsaved work before running TFC.
Hey Tom, I ran both StartupLite and TFC, also did a manual start after each. All the things listed to be disabled were vine with me. I check Java once a week and use JavaRa to remove older versions. Everything seem to go by the book. Regards, Bill

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI