This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Removal of Win32:rootkit and win32:hilot

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A couple weeks ago, Avast hit upon some trojans. I went into safe mode and tried to get it to kill it, but I think avast is unable to get it (it keeps hitting upon the same virus over and over, inuyaqoxi.dll). I'm really quite scared, since I didn't think much of it at the time (avast gets stuff like that all the time), and this computer has sensitive information on it. I haven't noticed anything really horrible yet, but I'd like to get this eliminated as quickly as possible. Can I please get some help in removing this?
Hello Angry Citizen and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.
Download ERUNT
This ensures we have a valid registry backup. ERUNT (Emergency Recovery Utility NT) allows you to store a complete backup of your registry and restore if needed. Removing modern malware infections often requires making changes to the registry, and a corrupt registry can prevent a system from booting. Compatible with Windows NT, 2000, 2003, XP, Vista, 32 & 64-bit versions.
  • Download ERUNT
  • Double-click erunt_setup.exe to run.
  • Follow the prompts and install using the default configuration (setup language, install location, shortcuts…).
  • Say No to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later

    [external image: Posted Image]
  • Start ERUNT
  • Choose a location for the backup
    The default location The default location C:\WINDOWS\ERDNT\[today's date] is preferred

    [external image: Posted Image]
  • The first two check boxes are ticked by default (System registry and Current user registry).
  • Press OK
  • When prompted, click YES to create a new folder.
  • Progress bars will show backup status.
  • A confirmation window will popup when complete. Click OK to close.

Download DeFogger

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked.
    Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file.
  • Save it where you can easily find it, such as your desktop, and copy/paste the results in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Run DeFogger

To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.

Download and Run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
I attempted to follow your instructions regarding ERUNT. I installed the program exactly as specified. However, while attempting to back up the registry, the program repeatedly encountered an error. The following is the error message received: Error saving file c:\Windows\ERDNT\3-4-2010\security ! Continue with the next file? [RegCreateKeyEx:5 - Access is denied]
Uninstalling and reinstalling allowed it to work. I completed the steps in your original instructions. GMER refused to work and repeatedly froze my computer to the point of being unable to do literally anything. However, booting in safe mode allowed the program to work. Here is the GMER log file:


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-04 22:33:41
Windows 6.0.6001 Service Pack 1
Running: gmer.exe; Driver: C:\Users\Ryan\AppData\Local\Temp\kwldrpog.sys


—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 52\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xE3 0xA3 0x24 0xF4 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xBA 0x83 0x86 0x75 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xEA 0xBD 0x4A 0xC6 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew 0x98 0xBE 0xB8 0xFC …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42@ujdew 0xF4 0xE0 0x7A 0x49 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xB7 0x3F 0x32 0x5E …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x85 0xEB 0x06 0x1A …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xC2 0x3E 0xED 0xCA …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 52\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xE3 0xA3 0x24 0xF4 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xBA 0x83 0x86 0x75 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xEA 0xBD 0x4A 0xC6 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew 0x98 0xBE 0xB8 0xFC …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42@ujdew 0xF4 0xE0 0x7A 0x49 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xB7 0x3F 0x32 0x5E …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x85 0xEB 0x06 0x1A …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xC2 0x3E 0xED 0xCA …

—- EOF - GMER 1.0.15 —-
Here is the 'Extras' OTL log:

OTL Extras logfile created on: 3/4/2010 10:43:38 PM - Run 1
OTL by OldTimer - Version 3.1.34.0 Folder = C:\Users\Ryan\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18865)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 56.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): c:\pagefile.sys 2875 2875 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 326.48 Gb Total Space | 145.87 Gb Free Space | 44.68% Space Free | Partition Type: NTFS
Drive D: | 8.87 Gb Total Space | 1.20 Gb Free Space | 13.58% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RYAN-PC
Current User Name: Ryan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 1
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{22D0BC53-4111-4959-884F-769C4BF7E67E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{2D6672B7-9051-4D93-A841-FA656C455ECE}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0229018C-0272-4D0E-9BFA-15930A5A90F0}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{068B87BC-79BC-41F0-9BA2-A626482CD78F}" = protocol=6 | dir=in | app=c:\program files\clearwire\instalan\instalan.exe |
"{07E3E1B8-D65C-4FA6-A063-830856829C9A}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{0C67B7F7-3EE8-4070-A0D2-5DB336B89B66}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{0E22A5CB-19C4-4D64-ABFD-47D06A7D5C0C}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{1264F8E5-05B9-440C-982D-42D636756A87}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{16AFED14-AD62-4E7B-A9FA-757591451FBB}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{1C322634-6DEB-4D67-88DC-149CA19C45A6}" = protocol=17 | dir=in | app=c:\program files\clearwire\instalan\instalan.exe |
"{20BB4F0F-E472-488C-8BE1-7C2EF7F900A0}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{22B354D7-346B-4F1C-9076-313AC508EAF1}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{2343DC93-A596-472C-823A-AC18250E9253}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{23A8DF8E-A882-4CE6-831A-92B8A287DAC8}" = protocol=6 | dir=in | app=c:\program files\firaxis games\warlords\civ4warlords_pitboss.exe |
"{23CA9210-390D-4DA8-A951-8F91F3E0770B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{259C1A72-FE43-4962-889A-A928879C2414}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{25BF42AB-047B-48D1-9081-AEF838AF9ED9}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{2E07015B-276B-4B0A-8A0D-32279D5680A3}" = protocol=17 | dir=in | app=c:\program files\clearwire\instalan\instalan.exe |
"{3803A72A-9008-4DFF-9EB9-E4BFB8324421}" = protocol=6 | dir=in | app=c:\program files\clearwire\instalan\instalan.exe |
"{3A9E5BCE-3BAD-40AE-9397-DE56AA61F1B5}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{3ECCA35D-F29B-489A-B9AC-99DCF17143B1}" = protocol=17 | dir=in | app=c:\program files\firaxis games\civilization4.exe |
"{3F4EBEC7-98B3-4BB8-BC3F-E66C200A534C}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"{48D158E6-01D4-47B7-B569-5DA9F2F56018}" = protocol=17 | dir=in | app=c:\program files\microsoft games\dungeon siege ii demo\dungeonsiege2.exe |
"{50635C78-1A74-49E3-86FC-71FA1E7CD39D}" = protocol=6 | dir=in | app=c:\program files\firaxis games\warlords\civ4warlords.exe |
"{53636D3D-FA62-4986-93F9-4CC3CB7DE687}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"{590DB413-5856-4E2B-BFB7-E6B90BB5044E}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{5B65481C-7A05-4A17-8165-480B9C982BA3}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{5DBB0B68-602C-4751-8916-CD57C9021764}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{615493FF-2723-4CAF-85DE-D0C95C8ED577}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{625664D5-448A-49AB-8F15-D99CC3F2ECEB}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{6475D994-24F2-4667-B8C1-FCB488194C37}" = protocol=17 | dir=in | app=c:\program files\firaxis games\warlords\civ4warlords.exe |
"{68FDD25E-67FA-4631-90FB-41D0541A5C8E}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{6EA9E7BF-E204-43B7-9283-A2E12608DAD6}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{7A066816-AEFB-4C2B-B27F-C860CDDDE6D1}" = protocol=6 | dir=in | app=c:\program files\firaxis games\beyond the sword\civ4beyondsword.exe |
"{7F31EEBD-B1A0-4F2B-94D2-12658691DA6D}" = protocol=6 | dir=in | app=c:\program files\microsoft games\dungeon siege ii demo\dungeonsiege2.exe |
"{8A910E67-BFF9-412F-81E6-A965B68ED2E9}" = protocol=6 | dir=in | app=c:\program files\firaxis games\civilization4.exe |
"{8AC329A9-7C52-480B-BCC0-845EFE76C5B9}" = protocol=6 | dir=in | app=c:\program files\firaxis games\beyond the sword\civ4beyondsword_pitboss.exe |
"{8CCB897D-1472-4426-9FF3-9A7E24D9AA20}" = protocol=17 | dir=in | app=c:\program files\firaxis games\beyond the sword\civ4beyondsword_pitboss.exe |
"{95A3D2C6-F6D4-4A48-9EC2-EDEB4341987B}" = dir=in | app=c:\program files\msn messenger\livecall.exe |
"{A180B291-A778-4FAA-B77E-67FD48A9D094}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe |
"{A3E2F1AC-100A-4149-A4D4-E0EC93B3B0E9}" = protocol=6 | dir=in | app=c:\program files\microsoft games\dungeon siege 2\dungeonsiege2.exe |
"{AE5B8BB3-404F-445A-B3D8-177B01BDB685}" = protocol=17 | dir=in | app=c:\program files\firaxis games\warlords\civ4warlords_pitboss.exe |
"{AF119A77-1A85-4742-ADF3-DFB0A02E3D46}" = protocol=17 | dir=in | app=c:\program files\firaxis games\beyond the sword\civ4beyondsword.exe |
"{B2EB0A1C-DDBB-46A4-837B-2A4C5A68D070}" = protocol=17 | dir=in | app=c:\program files\microsoft games\dungeon siege 2\dungeonsiege2.exe |
"{B6AA247B-ADA1-41AF-B3B1-3C1252AF8CDF}" = protocol=17 | dir=in | app=c:\program files\clearwire\instalan\instalan.exe |
"{B7BB3BB1-4BAD-4A3A-9B95-F69D9F10C22A}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{BC8D8D61-505D-4F48-855A-0C9F418261CE}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{BD387149-7F94-4C71-9ECF-BF0526B06085}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe |
"{C00A9D8A-3454-47DC-990B-378BB0474A56}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C090C545-F5E6-48A3-89C3-21CE52D21E7B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{C700B50C-32EF-4AFD-BC57-841E7DDB2602}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{C82F8F12-B0D9-442A-8267-DA84059CD5ED}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{C9A51850-C7AB-48AD-8472-20DA48250682}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{DB22CECC-73BD-4729-95FC-07DD4EAA9B57}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{DBF66322-8154-4876-AA22-EFF57796B5D8}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe |
"{EA7B75A9-2641-4FD0-A604-5D95CA672195}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{F4D589E0-7441-46F0-91F2-BFE773BA933A}" = protocol=6 | dir=in | app=c:\program files\clearwire\instalan\instalan.exe |
"{F5F420D8-3923-41F4-991B-E85942BA23E9}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{F7086C8B-A78C-462B-BA9A-19CAE7BAB382}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{FC0F0198-84EB-4BD5-9242-7B472F4EE8A1}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{FC242A90-BEFE-4C22-95FB-85FA7708640B}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{029B5901-1F27-4347-9923-E8ACC8F54E15}" = Snapfish Picture Mover
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
"{0A47BAFF-D4FF-4BD3-96CA-02A22EA62722}" = HP Active Support Library
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0DDA7620-4F8B-43B3-8828-CA5EE292FA3B}" = HP Total Care Advisor
"{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive
"{14AF024E-2E3B-49D0-A175-D1C1A06B155A}" = muvee autoProducer 6.0
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{2CD0168D-FBBC-4667-8810-105CB6EC6348}" = HP Deskjet D1600 Printer Driver Software 13.0 Rel .6
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{2E4E8905-5F24-4AEA-84E2-923CC12E3AB1}" = iPod for Windows 2005-09-06
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Roxio Activation Module
"{38DFF723-C0B1-44AB-A927-62EDB033908F}" = Belkin 54g USB Network Adapter
"{40F7AED3-0C7D-4582-99F6-484A515C73F2}" = HP Easy Setup - Frontend
"{4377F918-E6C9-4ECA-A7F5-754B310B7ED8}" = Sid Meier's Civilization 4
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5727583F-3530-45FD-B09E-7E1CB6C135AD}" = DJ_SF_06_D1600_SW_Min
"{5A29E75C-A8DE-49B4-9AF3-2266CE76C428}" = Sun ODF Plugin for Microsoft Office 1.2
"{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6D3DB611-D5E8-4E4B-8952-0D3F549F9CC6}" = HP Active Support Library 32 bit components
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{90110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{922E8525-AC7E-4294-ACAA-43712D4423C0}" = Adobe Flash Player 10 ActiveX
"{938B1CD7-7C60-491E-AA90-1F1888168240}" = Roxio MyDVD Basic v9
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.1
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support
"{B395BC1D-CC06-425E-9049-4CD985EFF004}" = LightScribe 1.8.15.1
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C5C53176-AAF3-4A35-BE8F-5B7726C52ABB}_is1" = VAPXP 1.1.36
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{CADDE354-C78C-46CB-A006-E2B178EFC271}" = Rise Of Legends
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}" = COWON Media Center - jetAudio Basic
"{EAE8CF06-28CA-4213-839C-A32817A47E00}" = D1600
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"2B0D8F3C-18AD-4D8E-879A-74A867C5C3CB_is1" = Clearwire InstaLAN
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Audacity_is1" = Audacity 1.2.6
"AudioBurst" = AudioBurst FX for Winamp
"avast!" = avast! Antivirus
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP
"Driver Sweeper_is1" = Driver Sweeper 1.0
"Dungeon Siege Legends of Aranna 1.0" = Dungeon Siege Legends of Aranna
"DungeonSiege2" = Dungeon Siege 2
"ERUNT_is1" = ERUNT 1.1j
"ffdshow_is1" = ffdshow [rev 3119] [2009-10-27]
"FLAC" = FLAC 1.2.1b (remove only)
"FrostWire" = FrostWire 4.17.2
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 2.01
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"InFlac" = InFlac 1.1.1
"InstallShield_{2E4E8905-5F24-4AEA-84E2-923CC12E3AB1}" = iPod for Windows 2005-09-06
"InstallShield_{CADDE354-C78C-46CB-A006-E2B178EFC271}" = Rise Of Legends
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Media Control_is1" = Media Control 6.0.2
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.8)" = Mozilla Firefox (3.5.8)
"NVIDIA Drivers" = NVIDIA Drivers
"ODF Viewer Beta 2" = ODF Viewer Beta 2
"OfficeTrial" = Microsoft Office Home and Student 60 day trial
"OsdMaestro" = HP On-Screen Cap/Num/Scroll Lock Indicator
"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
"Rhapsody" = Rhapsody
"Runic Games Torchlight" = Torchlight
"Shop for HP Supplies" = Shop for HP Supplies
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20
"Warcraft III" = Warcraft III
"WildTangent hp Master Uninstall" = My HP Games
"Winamp" = Winamp
"WinRAR archiver" = WinRAR archiver
"Xvid_is1" = Xvid 1.1.3 final uninstall
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{32E4F0D2-C135-475E-A841-1D59A0D22989}" = Sid Meier's Civilization 4 - Beyond the Sword
"{3E4B349F-10B5-4586-9D99-489A90A8B228}" = Sid Meier's Civilization 4 - Warlords
"{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}" = Sid Meier's Civilization 4
"BitTorrent" = BitTorrent
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 2/20/2010 9:53:59 AM | Computer Name = Ryan-PC | Source = avast! | ID = 33554522
Description = Error in aswChestC: chestOpenList Error 1753.

Error - 2/20/2010 9:53:59 AM | Computer Name = Ryan-PC | Source = avast! | ID = 33554522
Description = aswChestInterface - Program error description: CChestListView::LoadFiles()
chestOpenList() failed: 2147422219.

Error - 2/20/2010 9:54:17 AM | Computer Name = Ryan-PC | Source = avast! | ID = 33554522
Description = aswChestInterface - Program error description: CChestListView::OnCreate()
!m_strErrorWnd.IsEmpty().

Error - 2/20/2010 9:54:22 AM | Computer Name = Ryan-PC | Source = avast! | ID = 33554522
Description = Error in aswChestC: chestOpenList Error 1753.

Error - 2/20/2010 9:54:22 AM | Computer Name = Ryan-PC | Source = avast! | ID = 33554522
Description = aswChestInterface - Program error description: CChestListView::LoadFiles()
chestOpenList() failed: 2147422219.

Error - 2/20/2010 9:54:31 AM | Computer Name = Ryan-PC | Source = avast! | ID = 33554522
Description = aswChestInterface - Program error description: CChestListView::OnCreate()
!m_strErrorWnd.IsEmpty().

Error - 2/20/2010 10:01:37 AM | Computer Name = Ryan-PC | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function 00000002.

Error - 2/20/2010 11:00:04 AM | Computer Name = Ryan-PC | Source = avast! | ID = 33554522
Description = Error in aswChestC: chestAddFile Error 1753.

Error - 2/22/2010 8:36:42 AM | Computer Name = Ryan-PC | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function 00000002.

Error - 3/4/2010 12:32:25 AM | Computer Name = Ryan-PC | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function 00000002.

[ Application Events ]
Error - 1/20/2010 6:52:48 PM | Computer Name = Ryan-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 8.1.0.137, time stamp 0x46444e37,
faulting module MSVCR80.dll, version 8.0.50727.3053, time stamp 0x4889d619, exception
code 0xc0000005, fault offset 0x00014a7f, process id 0x16dc, application start time
0x01ca9a23432b8f21.

Error - 1/24/2010 2:00:40 AM | Computer Name = Ryan-PC | Source = Application Error | ID = 1000
Description = Faulting application YAHOOM~1.EXE, version 9.0.0.2162, time stamp
0x4a1cb91c, faulting module YCPFoundation.dll, version 9.0.0.54871, time stamp 0x4a1cbc3f,
exception code 0xc0000005, fault offset 0x00026cf0, process id 0xa08, application
start time 0x01ca9c326c773aeb.

Error - 1/26/2010 3:26:50 PM | Computer Name = Ryan-PC | Source = VSS | ID = 8194
Description =

Error - 2/19/2010 12:39:06 AM | Computer Name = Ryan-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 8.1.0.137, time stamp 0x46444e37,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x3030302e, process id 0xa768, application start time 0x01cab11d731eb060.

Error - 2/19/2010 12:39:09 AM | Computer Name = Ryan-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 8.1.0.137, time stamp 0x46444e37,
faulting module MSVCR80.dll, version 8.0.50727.3053, time stamp 0x4889d619, exception
code 0xc0000005, fault offset 0x00014a7f, process id 0xa768, application start time
0x01cab11d731eb060.

Error - 2/20/2010 9:48:31 AM | Computer Name = Ryan-PC | Source = EventSystem | ID = 4609
Description =

Error - 2/22/2010 8:30:41 AM | Computer Name = Ryan-PC | Source = EventSystem | ID = 4609
Description =

Error - 2/25/2010 1:05:24 AM | Computer Name = Ryan-PC | Source = Application Error | ID = 1000
Description = Faulting application YAHOOM~1.EXE, version 9.0.0.2162, time stamp
0x4a1cb91c, faulting module YCPFoundation.dll, version 9.0.0.54871, time stamp 0x4a1cbc3f,
exception code 0xc0000005, fault offset 0x00026cf0, process id 0x138c, application
start time 0x01cab59c79d931fe.

Error - 3/2/2010 12:05:46 PM | Computer Name = Ryan-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 8.1.0.137, time stamp 0x46444e37,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x0c0c0c0c, process id 0x3d88, application start time 0x01caba2233b2b034.

Error - 3/2/2010 12:28:02 PM | Computer Name = Ryan-PC | Source = EventSystem | ID = 4609
Description =

[ Media Center Events ]
Error - 2/4/2008 4:42:58 PM | Computer Name = Ryan-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 4/17/2008 10:50:55 AM | Computer Name = Ryan-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 5/25/2008 12:10:57 AM | Computer Name = Ryan-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 8/5/2009 3:28:40 PM | Computer Name = Ryan-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 8/16/2009 11:42:26 PM | Computer Name = Ryan-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 2/27/2010 12:38:42 AM | Computer Name = Ryan-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ System Events ]
Error - 3/4/2010 11:36:40 PM | Computer Name = Ryan-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 3/4/2010 11:36:40 PM | Computer Name = Ryan-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 3/4/2010 11:36:40 PM | Computer Name = Ryan-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 3/4/2010 11:36:40 PM | Computer Name = Ryan-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 3/4/2010 11:36:40 PM | Computer Name = Ryan-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 3/4/2010 11:36:43 PM | Computer Name = Ryan-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 3/5/2010 12:35:51 AM | Computer Name = Ryan-PC | Source = HTTP | ID = 15016
Description =

Error - 3/5/2010 12:35:52 AM | Computer Name = Ryan-PC | Source = Microsoft-Windows-ResourcePublication | ID = 1002
Description =

Error - 3/5/2010 12:41:22 AM | Computer Name = Ryan-PC | Source = HTTP | ID = 15016
Description =

Error - 3/5/2010 12:41:23 AM | Computer Name = Ryan-PC | Source = Microsoft-Windows-ResourcePublication | ID = 1002
Description =


< End of report >
I'd also like to express my appreciation for taking the time to help me. Here is the 'OTL' OTL log:


OTL logfile created on: 3/4/2010 10:43:38 PM - Run 1
OTL by OldTimer - Version 3.1.34.0 Folder = C:\Users\Ryan\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18865)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 56.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): c:\pagefile.sys 2875 2875 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 326.48 Gb Total Space | 145.87 Gb Free Space | 44.68% Space Free | Partition Type: NTFS
Drive D: | 8.87 Gb Total Space | 1.20 Gb Free Space | 13.58% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RYAN-PC
Current User Name: Ryan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/03/04 22:42:22 | 000,554,496 | —- | M] (OldTimer Tools) – C:\Users\Ryan\Downloads\OTL.exe
PRC - [2010/02/18 08:38:29 | 000,908,248 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/11/24 17:51:40 | 000,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/11/24 17:51:35 | 000,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/11/24 17:51:21 | 000,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/11/24 17:48:48 | 000,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009/11/24 17:43:56 | 000,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/08/30 12:44:38 | 002,927,104 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/04/10 11:29:08 | 000,037,888 | —- | M] () – C:\Program Files\Winamp\winampa.exe
PRC - [2008/06/10 04:27:04 | 000,054,672 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\jureg.exe
PRC - [2008/02/12 16:18:30 | 000,132,384 | —- | M] (Affinegy Inc) – C:\Program Files\Clearwire\InstaLAN\AffinegyService.exe
PRC - [2008/02/12 16:18:28 | 000,611,616 | —- | M] (Affinegy Inc) – C:\Program Files\Clearwire\InstaLAN\InstaLAN.exe
PRC - [2008/01/18 22:33:28 | 000,151,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\schtasks.exe
PRC - [2007/10/25 05:52:08 | 004,702,208 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
PRC - [2007/10/10 19:51:55 | 000,039,792 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Reader 8.0\Reader\Reader_SL.exe
PRC - [2007/09/12 18:27:24 | 000,554,352 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2007/05/28 10:57:54 | 000,275,968 | —- | M] (Rocket Division Software) – C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe


========== Modules (SafeList) ==========

MOD - [2010/03/04 22:42:22 | 000,554,496 | —- | M] (OldTimer Tools) – C:\Users\Ryan\Downloads\OTL.exe
MOD - [2008/01/18 22:36:26 | 000,038,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\sfc_os.dll
MOD - [2008/01/18 22:35:12 | 002,085,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msi.dll
MOD - [2008/01/18 22:26:36 | 001,684,480 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
MOD - [2006/11/02 03:46:13 | 000,004,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\sfc.dll
MOD - [2006/11/02 03:46:07 | 000,015,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msiltcfg.dll


========== Win32 Services (SafeList) ==========

SRV - [2009/11/24 17:51:35 | 000,138,680 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus)
SRV - [2009/11/24 17:51:21 | 000,254,040 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner)
SRV - [2009/11/24 17:48:48 | 000,352,920 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner)
SRV - [2009/11/24 17:43:56 | 000,018,752 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv)
SRV - [2008/02/12 16:18:30 | 000,132,384 | —- | M] (Affinegy Inc) [Auto | Running] – C:\Program Files\Clearwire\InstaLAN\AffinegyService.exe – (AffinegyService)
SRV - [2008/01/18 22:38:26 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/09/12 18:27:24 | 002,999,664 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE – (LiveUpdate)
SRV - [2007/09/12 18:27:24 | 000,554,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
SRV - [2007/05/28 10:57:54 | 000,275,968 | —- | M] (Rocket Division Software) [Auto | Running] – C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe – (StarWindServiceAE)
SRV - [2007/01/19 11:54:14 | 000,097,136 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\MSN Messenger\usnsvc.exe – (usnjsvc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.19
FF - prefs.js..extensions.enabledItems: [removed]:4.5
FF - prefs.js..extensions.enabledItems: {66B3427F-D646-4C0E-818C-F467B25B255E}:1.9.1

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/26 13:32:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/18 08:38:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/18 08:38:32 | 000,000,000 | —D | M]

[2008/08/27 07:48:50 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Mozilla\Extensions
[2010/02/19 07:55:57 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\9quraduu.default\extensions
[2009/09/02 17:40:45 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\9quraduu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2007/12/25 22:11:55 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\9quraduu.default\extensions\[removed]
[2008/12/12 12:23:54 | 000,002,158 | —- | M] () – C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\9quraduu.default\searchplugins\MySpace.xml
[2008/12/12 16:01:37 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/08/27 07:48:43 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2008/09/03 18:11:24 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2007/07/18 12:19:40 | 002,998,784 | —- | M] (Tamarack Software, Inc.) – C:\Program Files\Mozilla Firefox\plugins\nptgeqplugin.dll

O1 HOSTS File: ([2010/02/19 08:10:12 | 000,381,542 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 13145 more lines…
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files\Clearwire\InstaLAN\InstaLAN.exe (Affinegy Inc)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateReg] C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKLM..\RunOnce: [Launcher] C:\Windows\SMINST\Launcher.exe (soft thinks)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: real.com ([rhap-app-4-0] https in Trusted sites)
O15 - HKCU\..Trusted Domains: real.com ([rhapreg] https in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Ryan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Ryan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/30 06:05:48 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{aea993e7-534f-11dd-bb50-001bb9d72e9e}\Shell - "" = AutoRun
O33 - MountPoints2\{aea993e7-534f-11dd-bb50-001bb9d72e9e}\Shell\AutoRun\command - "" = J:\autorun.exe – File not found
O33 - MountPoints2\{aea993f5-534f-11dd-bb50-001bb9d72e9e}\Shell - "" = AutoRun
O33 - MountPoints2\{aea993f5-534f-11dd-bb50-001bb9d72e9e}\Shell\AutoRun\command - "" = K:\autorun.exe – File not found
O33 - MountPoints2\{aea993f7-534f-11dd-bb50-001bb9d72e9e}\Shell - "" = AutoRun
O33 - MountPoints2\{aea993f7-534f-11dd-bb50-001bb9d72e9e}\Shell\AutoRun\command - "" = L:\autorun.exe – File not found
O33 - MountPoints2\{ecc06527-7c4a-11de-bc68-001bb9d72e9e}\Shell - "" = AutoRun
O33 - MountPoints2\{ecc06527-7c4a-11de-bc68-001bb9d72e9e}\Shell\AutoRun\command - "" = M:\autoplay.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009/10/27 12:50:50 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
OTL cannot create restorepoints on Vista OSs!

========== Files/Folders - Created Within 14 Days ==========

[2010/03/04 21:09:27 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/03/04 21:09:04 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/03/03 19:45:27 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Malwarebytes
[2010/03/03 19:45:23 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/03/03 19:45:22 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/03/03 19:45:21 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/03/03 19:45:21 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/19 07:47:30 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\{66B3427F-D646-4C0E-818C-F467B25B255E}
[5 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/03/04 22:46:05 | 006,029,312 | -HS- | M] () – C:\Users\Ryan\ntuser.dat
[2010/03/04 22:41:22 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/03/04 22:41:21 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/04 22:41:21 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/04 22:41:16 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/03/04 22:40:27 | 000,524,288 | -HS- | M] () – C:\Users\Ryan\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/03/04 22:40:27 | 000,065,536 | -HS- | M] () – C:\Users\Ryan\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/03/04 22:40:17 | 002,942,467 | -H– | M] () – C:\Users\Ryan\AppData\Local\IconCache.db
[2010/03/04 21:09:05 | 000,000,735 | —- | M] () – C:\Users\Ryan\Desktop\NTREGOPT.lnk
[2010/03/04 21:09:05 | 000,000,716 | —- | M] () – C:\Users\Ryan\Desktop\ERUNT.lnk
[2010/03/04 04:29:25 | 000,000,680 | —- | M] () – C:\Users\Ryan\AppData\Local\d3d9caps.dat
[2010/03/03 19:45:26 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/02 15:17:34 | 000,002,990 | —- | M] () – C:\Users\Ryan\AppData\Roaming\wklnhst.dat
[2010/02/25 18:52:13 | 000,021,504 | —- | M] () – C:\Users\Ryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/21 09:14:30 | 000,184,921 | —- | M] () – C:\Users\Ryan\Documents\GED.xps
[2010/02/20 07:42:15 | 000,000,120 | —- | M] () – C:\Users\Ryan\AppData\Local\Gpozahi.dat
[2010/02/20 07:42:13 | 000,000,000 | —- | M] () – C:\Users\Ryan\AppData\Local\Oduvoyamuzage.bin
[2010/02/19 08:10:12 | 000,381,542 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/02/19 07:44:06 | 000,000,024 | —- | M] () – C:\Users\Ryan\AppData\Roaming\cqfyto.dat
[5 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/03/04 21:09:05 | 000,000,735 | —- | C] () – C:\Users\Ryan\Desktop\NTREGOPT.lnk
[2010/03/04 21:09:05 | 000,000,716 | —- | C] () – C:\Users\Ryan\Desktop\ERUNT.lnk
[2010/03/03 19:45:26 | 000,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/21 09:14:28 | 000,184,921 | —- | C] () – C:\Users\Ryan\Documents\GED.xps
[2010/02/19 07:47:30 | 000,000,120 | —- | C] () – C:\Users\Ryan\AppData\Local\Gpozahi.dat
[2010/02/19 07:47:30 | 000,000,000 | —- | C] () – C:\Users\Ryan\AppData\Local\Oduvoyamuzage.bin
[2010/02/19 07:43:47 | 000,000,024 | —- | C] () – C:\Users\Ryan\AppData\Roaming\cqfyto.dat
[2010/01/07 21:48:54 | 000,040,960 | —- | C] () – C:\Windows\System32\B11gUSB.dll
[2009/12/08 16:52:36 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/12/03 16:33:45 | 000,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2009/09/01 14:47:37 | 000,002,990 | —- | C] () – C:\Users\Ryan\AppData\Roaming\wklnhst.dat
[2008/09/11 21:49:37 | 000,765,952 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/09/11 21:49:37 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/08/16 21:19:39 | 000,069,632 | —- | C] () – C:\Windows\System32\xmltok.dll
[2008/08/16 21:19:39 | 000,036,864 | —- | C] () – C:\Windows\System32\xmlparse.dll
[2008/07/16 09:54:28 | 000,721,904 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2008/03/11 00:58:50 | 000,000,092 | —- | C] () – C:\Users\Ryan\AppData\Local\fusioncache.dat
[2008/01/12 14:35:32 | 000,021,504 | —- | C] () – C:\Users\Ryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/02 22:48:09 | 000,008,245 | —- | C] () – C:\ProgramData\LUUnInstall.LiveUpdate
[2007/12/27 09:31:20 | 000,000,680 | —- | C] () – C:\Users\Ryan\AppData\Local\d3d9caps.dat
[2007/08/30 05:56:00 | 000,002,085 | —- | C] () – C:\ProgramData\hpzinstall.log
[2007/08/30 05:40:05 | 000,102,400 | —- | C] () – C:\Windows\System32\pywintypes25.dll
[2007/08/30 05:40:04 | 000,327,680 | —- | C] () – C:\Windows\System32\pythoncom25.dll
[2007/07/19 09:07:52 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/12/14 00:01:36 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/12/14 00:01:36 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/11/02 06:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini

========== LOP Check ==========

[2010/03/02 15:25:36 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\BitTorrent
[2009/09/12 06:48:39 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\COWON
[2009/07/29 08:27:32 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\DAEMON Tools Lite
[2008/07/16 10:04:33 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Firaxis Games
[2010/02/04 09:19:23 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\FrostWire
[2008/03/11 00:58:55 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\GetRightToGo
[2009/01/26 21:34:49 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\LimeWire
[2009/12/03 16:36:45 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Media Control
[2008/12/12 15:38:41 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\ODF
[2008/12/12 16:04:03 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\OpenOffice.org
[2010/02/02 12:42:20 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\runic games
[2007/12/25 16:34:10 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Snapfish
[2009/09/01 14:47:38 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Template
[2008/03/11 00:58:57 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Turbine
[2010/03/04 22:40:20 | 000,032,584 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/01/18 22:42:26 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/18 22:42:26 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2006/11/02 03:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\drivers\AGP440.sys
[2006/11/02 03:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/01/15 23:43:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=224505155EC3E36D7A1F36E446F04C2A – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_ecc53ff9\atapi.sys
[2008/01/15 23:43:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=224505155EC3E36D7A1F36E446F04C2A – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16584_none_daff695624a08568\atapi.sys
[2008/01/18 22:41:32 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\drivers\atapi.sys
[2008/01/18 22:41:32 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/18 22:41:32 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 03:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008/01/15 23:43:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=BFD3DF48C9ED81934FE21E8E3CFC2496 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20707_none_dbe288453d7a8ed6\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 03:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 03:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2008/01/18 22:42:52 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/18 22:42:52 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 03:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\drivers\iaStorV.sys
[2006/11/02 03:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2006/11/02 03:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2008/01/18 22:35:38 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\System32\netlogon.dll
[2008/01/18 22:35:38 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVRD32.SYS >
[2007/10/26 18:51:26 | 000,131,616 | —- | M] (NVIDIA Corporation) MD5=049E81B6FB41C73619ED3FE4DF7D8638 – C:\Windows\System32\DriverStore\FileRepository\nvrd32.inf_0f6358b4\nvrd32.sys

< MD5 for: NVSTOR.SYS >
[2006/11/02 03:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\drivers\nvstor.sys
[2006/11/02 03:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/18 22:42:10 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/18 22:42:10 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: NVSTOR32.SYS >
[2007/10/26 18:51:24 | 000,110,624 | —- | M] (NVIDIA Corporation) MD5=7EBA6C9A0A295B1559EFB9062E701218 – C:\Windows\System32\drivers\nvstor32.sys
[2007/10/26 18:51:24 | 000,110,624 | —- | M] (NVIDIA Corporation) MD5=7EBA6C9A0A295B1559EFB9062E701218 – C:\Windows\System32\DriverStore\FileRepository\nvrd32.inf_0f6358b4\nvstor32.sys
[2007/07/02 11:37:08 | 000,110,112 | —- | M] (NVIDIA Corporation) MD5=A1CE1A6FD74C046F029448FCFA5E386D – C:\hp\DRIVERS\NVIDIA_Serial_ATA\nvstor32.sys
[2007/07/02 11:37:08 | 000,110,112 | —- | M] (NVIDIA Corporation) MD5=A1CE1A6FD74C046F029448FCFA5E386D – C:\Windows\System32\DriverStore\FileRepository\nvstor32.inf_6b03e392\nvstor32.sys

< MD5 for: SCECLI.DLL >
[2008/01/18 22:36:20 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\System32\scecli.dll
[2008/01/18 22:36:20 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006/11/02 03:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/01/18 22:38:04 | 000,242,744 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2008/01/18 22:36:12 | 000,225,792 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\SLC.dll
[5 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009/07/28 20:51:05 | 000,721,904 | —- | M] () Unable to obtain MD5 – C:\Windows\System32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 04:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< End of report >
P2P - I see you have P2P software (BitTorrent and Frostwire) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

You still have some Symantec files on your machine. So that they don't interfere with your Avast Anti-Virus, please run the Norton Removal Tool. If you are not prompted to do so, please reboot after it has completed running.

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following files:

    C:\Users\Ryan\AppData\Local\Oduvoyamuzage.bin
    C:\Users\Ryan\AppData\Local\Gpozahi.dat
    C:\Users\Ryan\AppData\Roaming\cqfyto.dat
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply.
File Gpozahi.dat received on 2010.03.06 03:51:43 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/42 (0%) File cqfyto.dat received on 2010.03.06 03:53:39 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/42 (0%) I tried to send C:\Users\Ryan\AppData\Local\Oduvoyamuzage.bin three times, and all three times it came up with an error stating "0 bytes size received / Se ha recibido un archivo vacio". I successfully removed BitTorrent, Frostwire and Norton from my system.
Download and Install Combofix

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2

[external image: Posted Image]

[external image: Posted Image]

VERY IMPORTANT!!! Save Combo-Fix.exe your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on Combo-Fix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
My computer appears to be running smoothly; however, I don't know whether Avast's passive scanner turned back on, as it is no longer in my tray. Here is the log:

ComboFix 10-03-06.01 - Ryan 03/06/2010 13:28:40.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1918.739 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
AV: avast! antivirus 4.8.1351 [VPS 091027-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1351 [VPS 091027-0] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-1802774392-1170642959-1021826132-500
c:\$recycle.bin\S-1-5-21-192345369-2729201545-2745846667-1000
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-4193381621-254449080-1260556885-500
c:\program files\temp
c:\users\Ryan\AppData\Local\{66B3427F-D646-4C0E-818C-F467B25B255E}
c:\users\Ryan\AppData\Local\{66B3427F-D646-4C0E-818C-F467B25B255E}\chrome.manifest
c:\users\Ryan\AppData\Local\{66B3427F-D646-4C0E-818C-F467B25B255E}\chrome\content\_cfg.js
c:\users\Ryan\AppData\Local\{66B3427F-D646-4C0E-818C-F467B25B255E}\chrome\content\overlay.xul
c:\users\Ryan\AppData\Local\{66B3427F-D646-4C0E-818C-F467B25B255E}\install.rdf
c:\windows\system32\DEBUG.log

.
((((((((((((((((((((((((( Files Created from 2010-02-06 to 2010-03-06 )))))))))))))))))))))))))))))))
.

2010-03-06 19:36 . 2010-03-06 19:36 ——– d—–w- c:\users\Ryan\AppData\Local\temp
2010-03-06 19:36 . 2010-03-06 19:36 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-03-05 03:09 . 2010-03-05 03:09 ——– d—–w- c:\program files\ERUNT
2010-03-04 01:45 . 2010-03-04 01:45 ——– d—–w- c:\users\Ryan\AppData\Roaming\Malwarebytes
2010-03-04 01:45 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-04 01:45 . 2010-03-04 01:45 ——– d—–w- c:\programdata\Malwarebytes
2010-03-04 01:45 . 2010-03-04 01:45 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-04 01:45 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-26 23:36 . 2010-02-26 23:36 658184 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-02-19 13:47 . 2010-02-20 13:42 120 —-a-w- c:\users\Ryan\AppData\Local\Gpozahi.dat
2010-02-19 13:47 . 2010-02-20 13:42 0 —-a-w- c:\users\Ryan\AppData\Local\Oduvoyamuzage.bin
2010-02-04 19:47 . 2010-02-04 19:54 63617 —-a-w- c:\windows\War3Unin.dat
2010-02-04 19:47 . 2010-02-04 19:49 2829 —-a-w- c:\windows\War3Unin.pif
2010-02-04 19:47 . 2010-02-04 19:49 139264 —-a-w- c:\windows\War3Unin.exe
2010-02-04 19:45 . 2010-02-20 02:36 ——– d—–w- c:\program files\Warcraft III

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-06 03:44 . 2007-08-30 12:15 ——– d—–w- c:\program files\Symantec
2010-03-06 03:39 . 2007-08-30 12:15 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-03-06 03:34 . 2009-05-09 19:38 ——– d—–w- c:\program files\BitTorrent
2010-03-06 03:33 . 2009-07-09 16:32 ——– d—–w- c:\users\Ryan\AppData\Roaming\BitTorrent
2010-03-04 10:29 . 2007-12-27 15:31 680 —-a-w- c:\users\Ryan\AppData\Local\d3d9caps.dat
2010-03-04 00:51 . 2007-12-26 01:28 ——– d—–w- c:\program files\CoH
2010-03-02 21:25 . 2009-03-01 04:31 ——– d—–w- c:\users\Ryan\AppData\Roaming\Winamp
2010-03-02 21:17 . 2009-09-01 20:47 2990 —-a-w- c:\users\Ryan\AppData\Roaming\wklnhst.dat
2010-02-19 14:33 . 2008-01-01 19:16 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-02-19 13:44 . 2010-02-19 13:43 24 —-a-w- c:\users\Ryan\AppData\Roaming\cqfyto.dat
2010-02-10 23:02 . 2009-04-29 04:24 ——– d—–w- c:\program files\CohTest
2010-02-04 15:19 . 2009-01-27 03:40 ——– d—–w- c:\users\Ryan\AppData\Roaming\FrostWire
2010-02-02 18:42 . 2010-02-02 18:42 ——– d—–w- c:\users\Ryan\AppData\Roaming\runic games
2010-02-02 17:16 . 2010-02-02 17:16 ——– d—–w- c:\program files\Runic Games
2010-01-31 19:03 . 2007-12-25 22:34 107760 —-a-w- c:\users\Ryan\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-26 19:35 . 2010-01-26 19:35 ——– d—–w- c:\programdata\WEBREG
2010-01-26 19:35 . 2010-01-26 19:34 ——– d—–w- c:\users\Ryan\AppData\Roaming\HP
2010-01-26 19:34 . 2007-08-30 11:55 ——– d—–w- c:\programdata\HP
2010-01-26 19:34 . 2010-01-26 19:24 158587 —-a-w- c:\windows\hphins33.dat
2010-01-26 19:31 . 2007-08-30 11:56 ——– d—–w- c:\program files\HP
2010-01-26 19:30 . 2010-01-26 19:30 ——– d—–w- c:\programdata\HP Product Assistant
2010-01-26 19:28 . 2010-01-26 19:28 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2010-01-15 15:22 . 2008-01-18 16:29 ——– d—–w- c:\programdata\NVIDIA
2010-01-15 15:18 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-01-15 15:07 . 2007-08-30 11:49 ——– d—–w- c:\program files\Realtek
2010-01-08 04:10 . 2008-12-12 22:04 1 —-a-w- c:\users\Ryan\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-01-08 03:48 . 2010-01-08 03:48 ——– d—–w- c:\program files\Belkin
2007-08-30 12:30 . 2007-08-30 12:24 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 52\axcmd.exe" [2008-03-20 216520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-25 4702208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-11 39792]
"SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2008-06-10 54672]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"InstaLAN"="c:\program files\Clearwire\InstaLAN\InstaLAN.exe" [2008-02-12 611616]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-04-10 37888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-04-03 44168]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snapfish Media Detector.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish Media Detector.lnk
backup=c:\windows\pss\Snapfish Media Detector.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2007-05-24 20:13 71176 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 22:24 54840 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
2007-04-18 15:01 65536 —-a-w- c:\hp\support\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2006-12-08 16:16 65536 —-a-w- c:\hp\KBD\KbdStub.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OsdMaestro]
2007-02-15 11:59 118784 —-a-w- c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-01-05 21:18 413696 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 04:38 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-07-29 721904]
S1 aswSP;avast! Self Protection; [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-11-24 20560]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-11-24 53328]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-02-15 c:\windows\Tasks\HPCeeScheduleForRyan.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2007-08-30 23:55]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
FF - ProfilePath - c:\users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\9quraduu.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSeymour.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
FF - plugin: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nptgeqplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-06 13:36
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-03-06 13:39:11
ComboFix-quarantined-files.txt 2010-03-06 19:39

Pre-Run: 155,036,909,568 bytes free
Post-Run: 155,048,800,256 bytes free

- - End Of File - - 0FFDA80A0CB8B2BF0D4F7DF30433AC70
If you have not done so already, please reboot your machine. Avast will likely start when you reboot. If not, from the Start Menu, go to All Programs and find the Avast program folder. There should be an icon you can click to start the program again.

I see you have Malwarebytes already on your machine. Please run it by double clicking the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates. Allow it to check for and apply any updates.
  • Select the Scanner tab, and Perform Quick Scan
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Please post the log in your next reply.

Please do a scan with Kaspersky Online Scanner
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the ]Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
  • Text file [*.txt] Then, click: Save

Please post the Kaspersky Online Scanner Report in your reply.
Malwarebytes' Anti-Malware 1.44 Database version: 3830 Windows 6.0.6001 Service Pack 1 Internet Explorer 8.0.6001.18865 3/6/2010 11:13:44 PM mbam-log-2010-03-06 (23-13-44).txt Scan type: Quick Scan Objects scanned: 112509 Time elapsed: 4 minute(s), 15 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Saturday, March 6, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Saturday, March 06, 2010 20:56:01 Records in database: 3720427 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ Scan statistics: Objects scanned: 205919 Threats found: 1 Infected objects found: 1 Suspicious objects found: 0 Scan duration: 03:32:41 File name / Threat / Threats count C:\Users\Ryan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\145e4a41-17b7adb7 Infected: Trojan-Downloader.Java.OpenStream.af 1 Selected area has been scanned.
Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

The following will implement some cleanup procedures as well as reset System Restore points:
  • Click Start > Run
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

If you notice any remaining tools or files you can delete them by right clicking and choosing delete.

Show Hidden Files and Folders
* Go to Start>Control panel>Folder Options>View
* Choose to "show hidden files and folders,"
* Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
* Close the window with ok

Delete these files
Using Windows Explorer (Windows Key + E), locate the following files/folders, and DELETE them (if still present)

C:\Users\Ryan\AppData\Local\Oduvoyamuzage.bin
C:\Users\Ryan\AppData\Local\Gpozahi.dat
C:\Users\Ryan\AppData\Roaming\cqfyto.dat

If Avast shows the file path of the inuyaqoxi.dll it cannot remove you can manually delete it the same way. I did not see this file on any of your logs, nor was it picked up by any of the other scans. I could be a false positive, or it could simply be in a location that is not being detected (such as your quarantined items). If the full file path is not shown you can use the Search feature of Vista from the Start Menu and try to manually locate the file for deletion.

Exit Explorer

Re-hide hidden folders
* Go to Start>Control panel>Folder Options>View
* Choose to "show hidden files and folders,"
* Check the "hide protected operating system files" and the "hide extensions for know file types" boxes.
* Close the window with ok
Note: While the scans on these files came up negative, they are definitely random file names (which are consistent with malware). I was unable to find any information showing these files are necessary, but I don't want to risk deleting files you may need for a program (such as one of your games) just because I can't find information about them. I have had you delete these items after the other clean-up so they will be in your Recycle Bin. Please allow them to remain in the Recycle Bin for several days, or until you are sure one of your games or programs does not want to use the files. We need to make sure they are still available if we need to restore them. If you do find you need one or more of the files you can simply restore them from the Recycle Bin to their original location. You can always empty the bin later, once you are sure none of your programs want to access the files.

Please let me know when you have completed these steps so I can give you some final instructions.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI