This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow Comp, Long bootup time, and Windows Defender won't run

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I am trying to salvage my girlfriend's computer. It is running very slow, and takes forever to boot up. I ran a defragmentation and tried to turn on her spyware/malware protection, but Windows Defender is off and cannot be turned on. I am sure that there are multiple problems with the computer right now. The computer is an HP 530 laptop running Windows Vista Home Basic. It has McAfee anti-virus and Windows Defender (which doesn't work). Here is the HiJackThis log file:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:55:20 AM, on 5/22/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Users\Your name\Documents\RCA Detective\RCADetective.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\dfrgui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Your name\Desktop\Fixing the Comp\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…b&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…b&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Megaupload Toolbar - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Megaupload Toolbar - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL (file missing)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: RCA Detective.lnk = C:\Users\Your name\Documents\RCA Detective\RCADetective.exe
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AIM Toolbar Search - C:\ProgramData\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…k.cab102118.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.gamehouse.com/games/insaniq/popcaploader.cab
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} (MSN Games – Backgammon) - http://zone.msn.com/bingame/zpagames/ZPA_B…on.cab64162.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Google Update Service (gupdate1ca03648eea6f3d) (gupdate1ca03648eea6f3d) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 12523 bytes

Thanks for the help.
Hello, Musicman710
Welcome to the WhatTheTech Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.



Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.





  • Please download OTL from one of the following mirrors:
    • This is THE Mirror
  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
  • Push the Quick Scan button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <– Will be opened
    • Extra.txt <– Will be minimized





Download GMER from Here. Note the file's name and save it to your root folder, such as C:\.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security program drivers will not conflict with this file.
  • Click on this link to see a list of programs that should be disabled.
  • Double-click on the downloaded file to start the program. (If running Vista, right click on it and select "Run as an Administrator")
  • Allow the driver to load if asked.
  • You may be prompted to scan immediately if it detects rootkit activity.
  • If you are prompted to scan your system click "No", save the log and post back the results.
  • If not prompted, click the "Rootkit/Malware" tab.
  • On the right-side, all items to be scanned should be checked by default except for "Show All". Leave that box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click the Scan button to begin. (Please be patient as it can take some time to complete)
  • When the scan is finished, click Save to save the scan results to your Desktop.
  • Save the file as Results.log and copy/paste the contents in your next reply.
  • Exit the program and re-enable all active protection when done.
Hey, thanks for the help. I will be running the GMER scan later tonight, but here are the logs from the other scan that you asked me to do. I'll try to get the GMER results up tomorrow.

Thanks again.

OTL.txt

OTL logfile created on: 5/23/2010 6:01:51 PM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Users\Your name\Desktop\Fixing the Comp
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 214.00 Mb Available Physical Memory | 21.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 43.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 103.42 Gb Total Space | 25.23 Gb Free Space | 24.40% Space Free | Partition Type: NTFS
Drive D: | 702.31 Mb Total Space | 550.24 Mb Free Space | 78.35% Space Free | Partition Type: UDF
Drive E: | 1.55 Gb Total Space | 1.32 Gb Free Space | 84.85% Space Free | Partition Type: NTFS
Drive F: | 6.82 Gb Total Space | 0.74 Gb Free Space | 10.82% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
Drive H: | 1.87 Gb Total Space | 1.78 Gb Free Space | 95.33% Space Free | Partition Type: FAT
I: Drive not present or media not loaded

Computer Name: SHELBY
Current User Name: Your name
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/05/23 17:59:45 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Your name\Desktop\Fixing the Comp\OTL.exe
PRC - [2009/11/24 22:55:37 | 000,122,880 | —- | M] (Google Inc.) – C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
PRC - [2009/11/24 20:02:25 | 000,386,872 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jucheck.exe
PRC - [2009/09/10 11:21:05 | 000,168,960 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmplayer.exe
PRC - [2009/05/19 11:36:18 | 000,240,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/05/08 11:35:50 | 002,780,432 | —- | M] () – C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009/05/08 11:34:08 | 000,559,888 | —- | M] () – C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2009/04/30 17:01:10 | 000,154,136 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2009/02/06 18:21:00 | 000,224,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Toolbar\wltuser.exe
PRC - [2009/01/26 22:32:06 | 000,039,408 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/11/24 22:31:12 | 000,087,904 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2008/11/24 22:31:08 | 000,239,968 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
PRC - [2008/10/29 02:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2008/05/22 20:50:00 | 000,144,704 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
PRC - [2008/05/22 20:50:00 | 000,111,952 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
PRC - [2008/05/22 20:50:00 | 000,054,608 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
PRC - [2008/04/14 16:40:26 | 001,070,080 | —- | M] (Audiovox Electronics Corp.) – C:\Users\Your name\Documents\RCA Detective\RCADetective.exe
PRC - [2008/01/19 03:38:38 | 001,008,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/01/11 17:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2007/10/25 15:06:00 | 000,086,016 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\Common Framework\Mctray.exe
PRC - [2007/10/25 10:05:40 | 000,136,512 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2007/10/25 10:04:56 | 000,136,512 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2007/10/25 10:03:28 | 000,103,744 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2007/01/04 19:48:52 | 000,112,152 | R— | M] (InterVideo) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
PRC - [2007/01/04 17:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe


========== Modules (SafeList) ==========

MOD - [2010/05/23 17:59:45 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Your name\Desktop\Fixing the Comp\OTL.exe
MOD - [2008/01/19 03:33:00 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msscript.ocx
MOD - [2008/01/19 03:26:34 | 001,684,480 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2009/05/27 03:27:04 | 029,262,680 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe – (MSSQL$MSSMLBIZ) SQL Server (MSSMLBIZ)
SRV - [2009/05/19 11:36:18 | 000,240,512 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2009/04/30 17:01:10 | 000,154,136 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv)
SRV - [2009/02/06 18:08:58 | 000,533,360 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Live\Family Safety\fsssvc.exe – (fsssvc)
SRV - [2008/11/24 22:31:12 | 000,087,904 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe – (SQLWriter)
SRV - [2008/11/24 22:31:08 | 000,239,968 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe – (SQLBrowser)
SRV - [2008/11/24 22:31:08 | 000,045,408 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe – (MSSQLServerADHelper)
SRV - [2008/05/22 20:50:00 | 000,144,704 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe – (McShield)
SRV - [2008/05/22 20:50:00 | 000,054,608 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe – (McTaskManager)
SRV - [2008/01/19 03:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2008/01/11 17:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe – (BcmSqlStartupSvc)
SRV - [2007/10/25 10:03:28 | 000,103,744 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\Program Files\McAfee\Common Framework\FrameworkService.exe – (McAfeeFramework)
SRV - [2007/03/05 14:30:06 | 000,110,592 | —- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe – (Com4Qlb)
SRV - [2007/01/04 19:48:52 | 000,112,152 | R— | M] (InterVideo) [Auto | Running] – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe – (IviRegMgr)
SRV - [2007/01/04 17:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Auto | Running] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)


========== Driver Services (SafeList) ==========

DRV - [2009/10/07 09:49:40 | 006,756,632 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lvuvc.sys – (LVUVC) Logitech Webcam 250(UVC)
DRV - [2009/06/14 20:40:18 | 000,721,904 | —- | M] () [Kernel | Boot | Running] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2009/04/30 19:01:36 | 000,265,496 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lvrs.sys – (LVRS)
DRV - [2009/04/30 19:00:00 | 000,114,712 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lvpopflt.sys – (lvpopflt)
DRV - [2009/04/30 17:00:12 | 000,025,624 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\LVPr2Mon.sys – (LVPr2Mon)
DRV - [2009/02/06 18:08:52 | 000,055,280 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\fssfltr.sys – (fssfltr)
DRV - [2008/05/22 20:50:00 | 000,174,952 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfehidk.sys – (mfehidk)
DRV - [2008/05/22 20:50:00 | 000,072,936 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2008/05/22 20:50:00 | 000,064,232 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2008/05/22 20:50:00 | 000,052,104 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\mfetdik.sys – (mfetdik)
DRV - [2008/05/22 20:50:00 | 000,033,960 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfebopk.sys – (mfebopk)
DRV - [2008/03/28 02:06:00 | 000,199,472 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\SynTP.sys – (SynTP)
DRV - [2008/03/03 11:32:00 | 000,188,416 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\CHDRT32.sys – (CnxtHdAudService)
DRV - [2008/01/23 04:19:44 | 000,501,560 | —- | M] (Protect Software GmbH) [Kernel | Auto | Running] – C:\Windows\System32\drivers\ACEDRV11.sys – (acedrv11)
DRV - [2008/01/19 01:53:23 | 000,073,088 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2007/10/12 23:50:00 | 001,044,984 | —- | M] (Broadcom Corp.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\BCMWL6.SYS – (BCM43XX)
DRV - [2007/10/12 23:50:00 | 001,044,984 | —- | M] (Broadcom Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\BCMWL6.SYS – (BCM43XV)
DRV - [2007/08/24 08:39:56 | 001,899,008 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\igdkmd32.sys – (igfx)
DRV - [2007/08/24 08:39:56 | 001,899,008 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\igdkmd32.sys – (ialm)
DRV - [2007/07/10 06:27:56 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)
DRV - [2007/06/20 03:29:56 | 000,984,064 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSX_DPV.sys – (HSF_DPV)
DRV - [2007/06/20 03:28:34 | 000,208,896 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSXHWAZL.sys – (HSXHWAZL)
DRV - [2007/06/20 03:28:22 | 000,660,480 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSX_CNXT.sys – (winachsf)
DRV - [2007/06/18 16:12:04 | 000,016,768 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HpqKbFiltr.sys – (HpqKbFiltr)
DRV - [2007/02/21 23:24:48 | 000,159,232 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\CHDART.sys – (HdAudAddService)
DRV - [2006/11/02 05:51:45 | 000,900,712 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2006/11/02 05:51:38 | 000,420,968 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2006/11/02 05:51:34 | 000,316,520 | —- | M] (Emulex) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2006/11/02 05:51:32 | 000,297,576 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2006/11/02 05:51:25 | 000,235,112 | —- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2006/11/02 05:51:25 | 000,232,040 | —- | M] (Intel Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2006/11/02 05:51:00 | 000,147,048 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2006/11/02 05:50:52 | 000,128,104 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\System32\drivers\WimFltr.sys – (WimFltr)
DRV - [2006/11/02 05:50:45 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2006/11/02 05:50:41 | 000,112,232 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2006/11/02 05:50:35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006/11/02 05:50:35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006/11/02 05:50:35 | 000,098,408 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2006/11/02 05:50:24 | 000,088,680 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2006/11/02 05:50:19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006/11/02 05:50:17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006/11/02 05:50:17 | 000,041,064 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\tpm.sys – (TPM)
DRV - [2006/11/02 05:50:16 | 000,071,784 | —- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2006/11/02 05:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2006/11/02 05:50:11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006/11/02 05:50:10 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2006/11/02 05:50:10 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2006/11/02 05:50:10 | 000,038,504 | —- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid2.sys – (SiSRaid2)
DRV - [2006/11/02 05:50:10 | 000,037,480 | —- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2006/11/02 05:50:09 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2006/11/02 05:50:09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006/11/02 05:50:07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006/11/02 05:50:05 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2006/11/02 05:50:05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006/11/02 05:50:04 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2006/11/02 05:50:03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006/11/02 05:49:59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006/11/02 05:49:56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006/11/02 05:49:53 | 000,028,776 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2006/11/02 05:49:30 | 000,017,512 | —- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2006/11/02 05:49:28 | 000,016,488 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2006/11/02 05:49:20 | 000,014,952 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2006/11/02 04:25:24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 04:24:47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006/11/02 04:24:46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006/11/02 04:24:45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006/11/02 04:24:44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006/11/02 04:24:44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006/11/02 03:41:49 | 000,200,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTAZL3.SYS – (HSFHWAZL)
DRV - [2006/11/02 03:36:50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)
DRV - [2006/11/02 03:36:43 | 002,028,032 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2006/11/02 03:30:54 | 000,117,760 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2006/11/02 03:30:53 | 000,167,936 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\b57nd60x.sys – (b57nd60x)
DRV - [2006/06/28 14:54:00 | 000,009,472 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\CPQBttn.sys – (HBtnKey)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…b&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…b&pf=laptop
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 80 9E 9E 4C 16 6E CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :0



O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\ScriptCl.dll (McAfee, Inc.)
O2 - BHO: (Megaupload Toolbar) - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL File not found
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll File not found
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (Megaupload Toolbar) - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL File not found
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Megaupload Toolbar) - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Easy Dock] File not found
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Aim6] File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Your name\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RCA Detective.lnk = C:\Users\Your name\Documents\RCA Detective\RCADetective.exe (Audiovox Electronics Corp.)
O8 - Extra context menu item: &AIM Toolbar Search - C:\ProgramData\AIM Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O9 - Extra Button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…k.cab102118.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.gamehouse.com/games/insaniq/popcaploader.cab (PopCapLoader Object)
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} http://zone.msn.com/bingame/zpagames/ZPA_B…on.cab64162.cab (MSN Games – Backgammon)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Your name\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\Your name\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/30 20:01:00 | 000,000,053 | -HS- | M] () - F:\Autorun.inf – [ NTFS ]
O33 - MountPoints2\{24a4b962-43e5-11de-87c4-001eec1a7ddf}\Shell\AutoRun\command - "" = H:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{24a4b962-43e5-11de-87c4-001eec1a7ddf}\Shell\install\command - "" = H:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{24a4b962-43e5-11de-87c4-001eec1a7ddf}\Shell\usermanualEnglish\command - "" = H:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{24a4b962-43e5-11de-87c4-001eec1a7ddf}\Shell\usermanualFrench\command - "" = H:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{24a4b962-43e5-11de-87c4-001eec1a7ddf}\Shell\usermanualSpanish\command - "" = H:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{36ef0a31-791a-11dd-95d9-001eec1a7ddf}\Shell - "" = AutoRun
O33 - MountPoints2\{36ef0a31-791a-11dd-95d9-001eec1a7ddf}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O33 - MountPoints2\{76ea5f91-5945-11de-b717-001eec1a7ddf}\Shell - "" = AutoRun
O33 - MountPoints2\{76ea5f91-5945-11de-b717-001eec1a7ddf}\Shell\adobe\command - "" = G:\goodies\ar405eng.exe – File not found
O33 - MountPoints2\{76ea5f91-5945-11de-b717-001eec1a7ddf}\Shell\AutoRun\command - "" = G:\aocsetup.exe – File not found
O33 - MountPoints2\{76ea5f91-5945-11de-b717-001eec1a7ddf}\Shell\log\command - "" = G:\goodies\machine\machine.exe – File not found
O33 - MountPoints2\{76ea5f91-5945-11de-b717-001eec1a7ddf}\Shell\machine\command - "" = G:\goodies\machine\machine.exe – File not found
O33 - MountPoints2\{76ea5f91-5945-11de-b717-001eec1a7ddf}\Shell\setup\command - "" = G:\aocsetup.exe – File not found
O33 - MountPoints2\{76ea5f91-5945-11de-b717-001eec1a7ddf}\Shell\zone\command - "" = G:\goodies\mszone\zonea660.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/11/11 13:22:16 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 90 Days ==========

[2010/05/22 11:43:56 | 000,000,000 | —D | C] – C:\Users\Your name\Desktop\Fixing the Comp
[2010/04/20 15:14:59 | 000,000,000 | —D | C] – C:\Users\Your name\Desktop\softball pics
[2010/04/12 00:06:00 | 000,000,000 | —D | C] – C:\Users\Your name\Desktop\Rent 4-8-10
[2010/04/04 00:17:08 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/03/18 19:35:03 | 000,000,000 | —D | C] – C:\Users\Your name\Documents\RCA Detective
[2010/03/18 19:31:51 | 000,000,000 | —D | C] – C:\Users\Your name\Documents\RCA EasyRip
[2010/03/09 04:01:44 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2010/03/07 21:01:04 | 000,000,000 | —D | C] – C:\ProgramData\WEBREG
[2010/03/07 20:27:37 | 000,000,000 | —D | C] – C:\ProgramData\HPSSUPPLY
[2010/03/07 20:21:12 | 000,000,000 | —D | C] – C:\ProgramData\HP Product Assistant
[2010/03/07 20:20:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\HP
[2010/03/07 20:17:59 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Hewlett-Packard
[2010/03/07 20:04:26 | 000,000,000 | -H-D | C] – C:\Config.Msi
[2010/03/07 19:43:46 | 000,000,000 | —D | C] – C:\ProgramData\HP

========== Files - Modified Within 90 Days ==========

[2010/05/23 18:16:19 | 003,670,016 | -HS- | M] () – C:\Users\Your name\NTUSER.DAT
[2010/05/23 18:13:35 | 000,000,400 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{F051533B-77B5-4F0B-B73F-C3C73C5E557E}.job
[2010/05/23 17:40:18 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/23 17:30:43 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/05/23 08:40:02 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/23 07:00:45 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/23 07:00:45 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/22 20:20:24 | 000,026,624 | —- | M] () – C:\Users\Your name\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/22 10:26:04 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/05/22 10:25:14 | 1064,755,200 | -HS- | M] () – C:\hiberfil.sys
[2010/05/21 23:27:31 | 000,030,036 | —- | M] () – C:\Users\Your name\Desktop\alg-singer-adam-lambert.jpg
[2010/05/20 22:54:14 | 000,025,088 | —- | M] () – C:\Users\Your name\Desktop\INFORMATION FOR SENIOR NIGHT PROGRAM.doc
[2010/05/20 22:44:59 | 000,769,132 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/05/20 22:44:59 | 000,650,720 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/05/20 22:44:59 | 000,122,562 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/05/19 20:49:48 | 000,027,136 | —- | M] () – C:\Users\Your name\Desktop\rough draft.doc
[2010/05/18 21:00:29 | 000,025,088 | —- | M] () – C:\Users\Your name\Desktop\Rules.doc
[2010/05/17 18:05:31 | 000,000,338 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForYour name.job
[2010/05/12 22:09:13 | 000,110,592 | —- | M] () – C:\Users\Your name\Desktop\Lowell High School Softball Apparel Graphics.doc
[2010/05/11 23:34:28 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/05/11 23:34:10 | 000,524,288 | -HS- | M] () – C:\Users\Your name\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms
[2010/05/11 23:34:10 | 000,065,536 | -HS- | M] () – C:\Users\Your name\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf
[2010/05/11 23:33:35 | 002,349,350 | -H– | M] () – C:\Users\Your name\AppData\Local\IconCache.db
[2010/05/11 22:49:01 | 000,021,504 | —- | M] () – C:\Users\Your name\Desktop\anemia.doc
[2010/05/11 11:41:14 | 000,074,713 | —- | M] () – C:\Users\Your name\Desktop\TaxReturnSam2009.pdf
[2010/05/11 11:03:33 | 000,148,253 | —- | M] () – C:\Users\Your name\Desktop\TaxReturn 2009.pdf
[2010/05/10 21:53:21 | 000,273,408 | —- | M] () – C:\Users\Your name\Desktop\What is Anemia.doc
[2010/05/08 21:25:38 | 000,087,554 | —- | M] () – C:\Users\Your name\Desktop\Shelby TaxReturn.pdf
[2010/05/08 21:06:10 | 000,139,620 | —- | M] () – C:\Windows\hpoins15.dat
[2010/05/08 21:03:19 | 000,000,254 | —- | M] () – C:\Windows\win.ini
[2010/05/05 21:57:16 | 000,000,171 | —- | M] () – C:\Users\Your name\Desktop\Your SAT Registration is complete.url
[2010/05/01 18:02:17 | 000,376,912 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/04/20 22:42:47 | 000,065,536 | —- | M] () – C:\Users\Your name\Documents\LHS roster 2010.xls
[2010/04/18 10:33:23 | 000,000,191 | —- | M] () – C:\Users\Your name\Desktop\01854 Weather Forecast and Conditions.url
[2010/04/04 08:03:19 | 000,000,227 | —- | M] () – C:\Users\Your name\Desktop\Brown Sugar-Glazed Carrots Recipe @CDKitchen.url
[2010/04/04 00:13:03 | 000,000,680 | —- | M] () – C:\Users\Your name\AppData\Local\d3d9caps.dat
[2010/04/04 00:02:23 | 000,000,000 | —- | M] () – C:\Windows\System32\drivers\lvuvc.hs
[2010/04/01 15:54:52 | 000,047,104 | —- | M] () – C:\Users\Your name\Documents\chunky's ad.doc
[2010/03/31 19:24:44 | 000,096,256 | —- | M] () – C:\Users\Your name\Desktop\MARTIN LUTHER KING JR.doc
[2010/03/18 19:35:06 | 000,000,790 | —- | M] () – C:\Users\Your name\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RCA Detective.lnk
[2010/03/18 19:34:55 | 000,000,702 | —- | M] () – C:\Users\Your name\Desktop\RCA EasyRip.lnk
[2010/03/18 19:31:43 | 000,001,375 | —- | M] () – C:\Users\Your name\Desktop\User_Manual_English_PEARL.pdf.lnk
[2010/03/07 20:28:58 | 000,002,016 | —- | M] () – C:\Users\Public\Desktop\HP Photosmart Essential 2.01.lnk
[2010/03/07 20:27:38 | 000,001,850 | —- | M] () – C:\Users\Public\Desktop\Shop for HP Supplies.lnk
[2010/03/07 20:24:12 | 000,001,972 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/03/07 20:22:32 | 000,001,142 | —- | M] () – C:\Users\Public\Desktop\HP Solution Center.lnk
[2010/02/24 14:34:18 | 000,102,048 | —- | M] () – C:\Users\Your name\AppData\Local\GDIPFONTCACHEV1.DAT

========== Files Created - No Company Name ==========

[2010/05/21 23:28:20 | 000,030,036 | —- | C] () – C:\Users\Your name\Desktop\alg-singer-adam-lambert.jpg
[2010/05/20 22:54:13 | 000,025,088 | —- | C] () – C:\Users\Your name\Desktop\INFORMATION FOR SENIOR NIGHT PROGRAM.doc
[2010/05/18 21:00:29 | 000,025,088 | —- | C] () – C:\Users\Your name\Desktop\Rules.doc
[2010/05/14 13:06:42 | 000,000,338 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForYour name.job
[2010/05/13 21:25:55 | 000,027,136 | —- | C] () – C:\Users\Your name\Desktop\rough draft.doc
[2010/05/12 13:57:29 | 000,110,592 | —- | C] () – C:\Users\Your name\Desktop\Lowell High School Softball Apparel Graphics.doc
[2010/05/11 22:43:20 | 000,021,504 | —- | C] () – C:\Users\Your name\Desktop\anemia.doc
[2010/05/11 11:40:15 | 000,074,713 | —- | C] () – C:\Users\Your name\Desktop\TaxReturnSam2009.pdf
[2010/05/11 11:03:27 | 000,148,253 | —- | C] () – C:\Users\Your name\Desktop\TaxReturn 2009.pdf
[2010/05/10 19:59:49 | 000,273,408 | —- | C] () – C:\Users\Your name\Desktop\What is Anemia.doc
[2010/05/08 21:25:10 | 000,087,554 | —- | C] () – C:\Users\Your name\Desktop\Shelby TaxReturn.pdf
[2010/05/05 21:57:16 | 000,000,171 | —- | C] () – C:\Users\Your name\Desktop\Your SAT Registration is complete.url
[2010/04/20 22:05:10 | 000,065,536 | —- | C] () – C:\Users\Your name\Documents\LHS roster 2010.xls
[2010/04/18 10:33:22 | 000,000,191 | —- | C] () – C:\Users\Your name\Desktop\01854 Weather Forecast and Conditions.url
[2010/04/03 23:21:37 | 000,000,227 | —- | C] () – C:\Users\Your name\Desktop\Brown Sugar-Glazed Carrots Recipe @CDKitchen.url
[2010/04/01 15:54:52 | 000,047,104 | —- | C] () – C:\Users\Your name\Documents\chunky's ad.doc
[2010/03/31 19:24:43 | 000,096,256 | —- | C] () – C:\Users\Your name\Desktop\MARTIN LUTHER KING JR.doc
[2010/03/18 19:35:06 | 000,000,790 | —- | C] () – C:\Users\Your name\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RCA Detective.lnk
[2010/03/18 19:34:55 | 000,000,702 | —- | C] () – C:\Users\Your name\Desktop\RCA EasyRip.lnk
[2010/03/07 20:28:58 | 000,002,016 | —- | C] () – C:\Users\Public\Desktop\HP Photosmart Essential 2.01.lnk
[2010/03/07 20:27:38 | 000,001,850 | —- | C] () – C:\Users\Public\Desktop\Shop for HP Supplies.lnk
[2010/03/07 20:24:12 | 000,001,972 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/03/07 20:22:32 | 000,001,142 | —- | C] () – C:\Users\Public\Desktop\HP Solution Center.lnk
[2010/03/07 20:03:00 | 000,001,742 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/03/07 20:02:31 | 000,139,620 | —- | C] () – C:\Windows\hpoins15.dat
[2010/03/07 20:02:30 | 000,001,039 | —- | C] () – C:\Windows\hpomdl15.dat
[2010/03/07 19:43:20 | 000,505,176 | —- | C] () – C:\Windows\System32\autorun.inf
[2009/12/18 23:22:38 | 000,082,289 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2009/06/14 20:40:17 | 000,721,904 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2009/05/08 11:13:04 | 000,013,584 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2009/04/30 17:00:12 | 000,025,624 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2009/01/23 14:44:29 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/08/29 23:31:01 | 000,000,280 | —- | C] () – C:\Windows\System32\epoPGPsdk.dll.sig
[2008/08/08 12:13:59 | 000,000,021 | —- | C] () – C:\Windows\atid.ini
[2008/07/05 09:49:59 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2008/07/05 09:49:59 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2008/07/05 09:49:59 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2008/07/05 09:49:59 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2008/07/05 09:49:59 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2008/07/05 09:49:59 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2007/08/24 08:46:48 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1322.dll
[2007/08/24 08:28:04 | 000,249,856 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/28 16:11:30 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 06:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/09/25 03:02:34 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/25 03:02:34 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/03/09 06:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\Windows\System32\OUTLPERF.INI
[1913/08/01 10:18:54 | 000,056,832 | —- | C] () – C:\Windows\System32\iyvu9_32.dll

========== LOP Check ==========

[2008/08/08 12:14:31 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\acccore
[2008/08/29 21:47:40 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\CiscoCAA
[2009/06/14 21:06:14 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\DAEMON Tools Lite
[2009/12/22 01:28:58 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\GameRanger
[2008/07/05 09:51:11 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\Hewlett Packard
[2009/12/18 23:27:01 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\Leadertech
[2009/12/29 02:16:56 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\LimeWire
[2008/10/01 13:49:00 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\McGraw-HillLicensing
[2009/02/12 21:49:19 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\Megaupload
[2009/02/12 21:48:46 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\MegauploadToolbar
[2009/04/14 00:58:08 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\SampleView
[2010/05/11 23:34:40 | 000,032,596 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/05/23 18:13:35 | 000,000,400 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{F051533B-77B5-4F0B-B73F-C3C73C5E557E}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/01/19 03:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/19 03:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/19 03:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2007/11/05 03:03:45 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=313FF294978EA6AF715722D708FB249F – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20494_none_b858f78adaed51b3\AGP440.sys
[2007/11/05 03:03:45 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=CE71AFD6738AA025D742CDBCFBDC8B9C – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f2490cb0\AGP440.sys
[2007/11/05 03:03:45 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=CE71AFD6738AA025D742CDBCFBDC8B9C – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16399_none_b7d45c31c1cb309c\AGP440.sys
[2006/11/02 05:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\drivers\AGP440.sys
[2006/11/02 05:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/04/11 02:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/19 03:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\drivers\atapi.sys
[2008/01/19 03:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/19 03:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 05:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008/08/12 11:33:49 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008/08/12 11:33:49 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008/08/12 11:33:49 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 05:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2008/01/19 03:42:51 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/19 03:42:51 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 05:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\drivers\iaStorV.sys
[2006/11/02 05:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2006/11/02 05:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/19 03:35:36 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\System32\netlogon.dll
[2008/01/19 03:35:36 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2006/11/02 05:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\drivers\nvstor.sys
[2006/11/02 05:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/19 03:42:09 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/19 03:42:09 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/19 03:36:19 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\System32\scecli.dll
[2008/01/19 03:36:19 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006/11/02 05:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %systemroot%\*. /mp /s >
< End of report >

And here's Extras.txt

OTL Extras logfile created on: 5/23/2010 6:01:51 PM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Users\Your name\Desktop\Fixing the Comp
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 214.00 Mb Available Physical Memory | 21.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 43.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 103.42 Gb Total Space | 25.23 Gb Free Space | 24.40% Space Free | Partition Type: NTFS
Drive D: | 702.31 Mb Total Space | 550.24 Mb Free Space | 78.35% Space Free | Partition Type: UDF
Drive E: | 1.55 Gb Total Space | 1.32 Gb Free Space | 84.85% Space Free | Partition Type: NTFS
Drive F: | 6.82 Gb Total Space | 0.74 Gb Free Space | 10.82% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
Drive H: | 1.87 Gb Total Space | 1.78 Gb Free Space | 95.33% Space Free | Partition Type: FAT
I: Drive not present or media not loaded

Computer Name: SHELBY
Current User Name: Your name
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{067CB1D8-AC23-4F71-867C-5784A8CD9DE0}" = lport=445 | protocol=6 | dir=in | app=system |
"{2DF01963-9284-4BA9-AFB6-D5C0BD9B8FAB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3245D97F-8E12-492D-A838-7058BF685F58}" = lport=137 | protocol=17 | dir=in | app=system |
"{343903A9-2D2D-4350-931B-C8163D1703DE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{365DFCC9-560E-42E1-9B18-6F22287D2304}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{3D018BC8-722F-440F-AE69-935BF56A67BD}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{3E7FDC62-D1AD-4C92-84FE-64CE24FD7DA8}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{436A6E74-E0E8-4B1C-8C99-4763E3B27F17}" = lport=10243 | protocol=6 | dir=in | app=system |
"{43F83258-67FA-4806-A7C4-D55BCB3842D8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4CD182B6-ACC4-4D56-A4A4-741CA7F3B1B0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4FEAE458-B68D-41E2-BC11-225D163A8FE1}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5390166F-6DDD-4D11-A50E-2C9644F56789}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{857FB45A-202F-429D-B757-FB8D486A397B}" = rport=138 | protocol=17 | dir=out | app=system |
"{880830EE-986C-4BE3-B2DB-4C43F1843FC0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8FDD4486-9586-45C5-9B55-AB8852DE8F70}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{8FF85D03-F8AB-4981-BFFC-367C9ABD8AA3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{948CFBB5-BF6B-4177-ACA2-9EC8702CF784}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{9EF11CC0-4C1E-4247-AD2B-C84F1DCDCADE}" = rport=137 | protocol=17 | dir=out | app=system |
"{AB0953CB-D60E-4FD0-8CFB-D046FF5E5D46}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B78164CC-6E20-495D-BD6C-33A48CF2C82F}" = lport=138 | protocol=17 | dir=in | app=system |
"{CEB2F628-ED86-4B85-93F1-E63C05E28F3C}" = rport=10243 | protocol=6 | dir=out | app=system |
"{D08DC149-4644-4EF1-93C7-B63B7B133BC8}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D67102E4-B4D1-4D2A-B53F-81CCF25BDD5F}" = rport=139 | protocol=6 | dir=out | app=system |
"{D84733D6-13AF-42BF-AA93-25AE4CD6580D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DED32AB8-A02F-4278-B201-5C4EFEABCFDB}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{E96A0A08-8458-4CAD-98FA-1007C3F50A78}" = rport=445 | protocol=6 | dir=out | app=system |
"{F271176F-4B52-4514-A5C7-EC16A8A21507}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F4A70DEA-86BC-41F2-9AAB-F2584AC449BC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F5196ED7-53CE-40F5-9680-798CEC56178A}" = lport=139 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0188B2A8-8236-4AE1-988F-23F320FEB13B}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{05C9A87F-120B-4219-ABD0-2A4A9DCA6A80}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{0817C515-FEB2-4E49-9EA8-7F3C83ED9193}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{17822737-6AB8-4B0D-AE23-6A9F16B39A68}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{35E7CBC8-48A7-4B79-A539-82DE3D62F56E}" = protocol=6 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{3C0BD194-2417-4539-8316-D0D8C8715E74}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4A9EA769-E4AA-4B00-8BC1-C4497453E56F}" = protocol=17 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{4BBCAC6F-E25E-4C3D-A025-9935F3D1C26D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{55F29BAD-1219-48ED-A045-9E970E8BE00D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5AC12650-9E36-46E3-B3D4-B91B8B210FEC}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{6177F692-352E-4690-AE50-D51D11DF7684}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{63306666-7445-44DC-B12B-470E24E0BBD1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{68A13F56-B021-4CCE-9A19-580E1A2236EA}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{68BE2FEA-7A25-462E-83F0-AB8287E70374}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{6C0D2278-04DE-43F8-B424-69484B4A7DA5}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{7017095B-6AC6-4DE5-9DE8-CF0BD5C70761}" = protocol=6 | dir=in | app=c:\program files\logitech\logitech vid\vid.exe |
"{7709CD36-5BB9-42DE-ACA5-21B7BBB8B414}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{797B3326-EA4B-47DE-A5F9-251A8CD89C66}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{7ACFDB45-FD75-4239-8912-F48C9E2C6F6A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{7C7119AA-F8CB-4AF7-A79A-D9DCAA50DF93}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{958B0021-9B6A-4D9D-9189-3A33CC7A12F4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9A240FAE-C3D4-4B2E-B8A1-F236A147049C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9C41B18B-5F60-4446-BE93-95DB4252196F}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{9ED55240-989C-4312-A970-98E4B6DA4952}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A2A91D67-14D3-4961-B9DC-98FFE2036AD9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A34E5160-F7DC-448A-A498-B48F4102A366}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{A64C7A44-99CB-4115-A5C1-0369DA84C0E1}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{A95A78FF-A734-46F9-A1A1-90EC14F45ACB}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A9E84B3B-49AE-4D47-9EF7-6AD28B5EAD33}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{B69C4902-EF2A-4E88-A15D-BBA9AE6993EF}" = protocol=17 | dir=in | app=c:\program files\logitech\logitech vid\vid.exe |
"{B6B7DEB3-F000-414D-A967-DF861EF7B37A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C7308B9B-5482-4AD1-A0B8-7BC27A156F18}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{D8F08E3F-1ACF-4542-B80F-5989E39D930B}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{DA488511-C20D-4FF2-87D5-8673EF93B91E}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{ED91463A-7137-4F26-90D1-54EEBA917072}" = protocol=6 | dir=out | app=system |
"{F4D48E53-47FE-4643-B4CB-429B3DFDDB24}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F73ED862-5603-4AA9-AC05-8DB476E994D7}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{41F77CB4-8DE6-42AA-9FDE-93A7B99B78AD}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{6E9E6542-1EB2-4D79-8E56-D4B98A0C9B1F}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{AE80D3B7-0719-4BAF-871D-08BC210F86D7}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{B085D0A8-B1C2-408A-95DE-01BA01E0CB0A}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe |
"TCP Query User{B20AA324-78BD-45D8-B3EE-354B32DCA76D}C:\users\your name\appdata\roaming\gameranger\gameranger\gameranger.exe" = protocol=6 | dir=in | app=c:\users\your name\appdata\roaming\gameranger\gameranger\gameranger.exe |
"TCP Query User{C11451A0-0AAC-4C78-9FC4-B2D94C1ABADA}C:\program files\aim6\aim6.exe" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"UDP Query User{394B33B1-BBB5-4C27-8A6B-1E42076FA95F}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{6CCABD90-B140-4448-858A-DAE1703B26DD}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{813BC0A0-E414-4277-BFFF-C1EF2CA23675}C:\program files\aim6\aim6.exe" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"UDP Query User{82DBA5ED-ED59-4434-9460-2791B6971EA3}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{CBF4DBA8-07C5-4F61-B208-47D64025134D}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe |
"UDP Query User{F7EB2DE1-32A4-4959-AA64-F5C31E99AC30}C:\users\your name\appdata\roaming\gameranger\gameranger\gameranger.exe" = protocol=17 | dir=in | app=c:\users\your name\appdata\roaming\gameranger\gameranger\gameranger.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0EC7C406-B592-4686-BAC1-AD29A85EAE6A}" = HP Driver Diagnostics
"{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp
"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch
"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22466889-7642-488d-AA0E-F619704CF7AB}" = DeviceDiscovery
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{29FA9E38-7A6D-475E-8C15-15EE8BA9639E}" = ESU for Microsoft Vista
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{2C86D799-6203-4BE4-8175-126D69742F2F}" = Vista Default Settings
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 B2
"{35C03C04-3F1F-42C2-A989-A757EE691F65}" = McAfee VirusScan Enterprise
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3912A629-0020-0005-3131-2FBA74D4DF0A}" = InterVideo WinDVD
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}" = Mega Manager
"{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery
"{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}" = HP Backup and Recovery Manager Installer
"{41B9E2CF-0B3F-442A-B5B3-592A4A355634}" = iTunes
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{521F72F4-FFE4-4959-AA88-EED06125211F}" = HP Notebook Accessories Product Tour
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{584B0895-8EF3-4175-8E80-1B68BFA04636}" = HP Help and Support
"{5D97A4A7-C274-4B63-86D9-07A33435F505}" = InterVideo DVD Check
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A6DCB18-3ECB-46DC-894B-5EFE08C0BD9B}" = Mega Manager
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6D3DB611-D5E8-4E4B-8952-0D3F549F9CC6}" = HP Active Support Library 32 bit components
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{70CEFEBA-F757-4DBE-8A21-027C326137CE}" = Application Installer 4.00.B13
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76CD2979-09C0-493A-84B3-8FD97EF4BCEA}" = Windows Live Family Safety
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0120-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9FE8E277-EBFC-4A5E-BD70-6F9B7F32AF0E}" = HP Total Care Advisor
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA9768AA-FF0B-4C66-A085-31E934F77841}" = Apple Mobile Device Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AC96671C-2001-432C-9826-5266D84EF1DC}" = Logitech Webcam Software
"{ACA85783-8EEA-4f0a-B2A3-A8173F30209F}" = C4200_doccd
"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B09BCBF6-87EE-4403-A336-3A9510856535}" = HP Photosmart All-In-One Software 9.0
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP2
"{B51C3024-333B-4FB6-B1EC-49ECE2DE6056}" = HP User Guides 0077
"{BBE5C83E-4DC5-494F-8A23-3AAE242E94C2}" = HP Easy Setup - Frontend
"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{BFDE4176-5DFE-4db9-AA00-8F30CB001BDA}" = c4200_Help
"{C39E671D-0528-4c5e-A034-8470C5BC393A}" = C4200
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D32067CD-7409-4792-BFA0-1469BCD8F0C8}" = HP Wireless Assistant
"{D8B7A682-20DA-4797-8415-B1FB14D4D32B}" = PS_AIO_Software
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{E28750A2-45F2-4b63-99F7-9F81A94B1E2D}" = PS_AIO_Software_min
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{FD7F242B-9AA0-40c3-941E-3A9821D19C09}" = PS_AIO_ProductContext
"{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"AIM_6" = AIM 6
"AIMTunes" = AIMTunes
"Broadcom 802.11b Network Adapter" = Broadcom 802.11 Wireless LAN Adapter
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP2
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"Google Chrome" = Google Chrome
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 9.0
"HP Photosmart Essential" = HP Photosmart Essential 2.01
"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0
"HPExtendedCapabilities" = HP Customer Participation Program 9.0
"HPOCR" = HP OCR Software 9.0
"LimeWire" = LimeWire 4.18.3
"lvdrivers_12.0" = Logitech Webcam Software Driver Package
"MegauploadToolbar" = Megaupload Toolbar
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"PROSet" = Intel® Network Connections Drivers
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"RCA Detective_is1" = RCA Detective [removed]
"RCA EasyRip™_is1" = RCA EasyRip™ [removed]
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GameRanger" = GameRanger
"Play65" = Play65

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/8/2010 4:40:06 PM | Computer Name = Shelby | Source = Google Update | ID = 20
Description =

Error - 5/10/2010 7:17:19 PM | Computer Name = Shelby | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 5/10/2010 7:32:03 PM | Computer Name = Shelby | Source = Application Hang | ID = 1002
Description = The program WINWORD.EXE version 11.0.8313.0 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: ed4 Start Time: 01caf0989f7e6b38 Termination Time: 119

Error - 5/10/2010 7:57:34 PM | Computer Name = Shelby | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18904, time stamp
0x4b835fec, faulting module swg.dll_unloaded, version 0.0.0.0, time stamp 0x4abd66f5,
exception code 0xc0000005, fault offset 0x0538a3db, process id 0x1198, application
start time 0x01caf09c71ea7e38.

Error - 5/11/2010 10:21:01 PM | Computer Name = Shelby | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 5/12/2010 12:38:48 PM | Computer Name = Shelby | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 5/12/2010 12:41:12 PM | Computer Name = Shelby | Source = Google Update | ID = 20
Description =

Error - 5/13/2010 7:26:09 PM | Computer Name = Shelby | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 5/17/2010 6:10:44 PM | Computer Name = Shelby | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 5/22/2010 10:29:28 AM | Computer Name = Shelby | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

[ System Events ]
Error - 5/21/2010 3:00:13 AM | Computer Name = Shelby | Source = Service Control Manager | ID = 7011
Description =

Error - 5/21/2010 3:05:41 AM | Computer Name = Shelby | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 5/21/2010 2:43:24 PM | Computer Name = Shelby | Source = Service Control Manager | ID = 7011
Description =

Error - 5/21/2010 8:05:53 PM | Computer Name = Shelby | Source = Service Control Manager | ID = 7011
Description =

Error - 5/22/2010 3:06:21 AM | Computer Name = Shelby | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 5/22/2010 10:25:46 AM | Computer Name = Shelby | Source = EventLog | ID = 6008
Description = The previous system shutdown at 10:23:40 AM on 5/22/2010 was unexpected.

Error - 5/22/2010 10:26:05 AM | Computer Name = Shelby | Source = HTTP | ID = 15016
Description =

Error - 5/23/2010 3:00:24 AM | Computer Name = Shelby | Source = Service Control Manager | ID = 7011
Description =

Error - 5/23/2010 3:06:18 AM | Computer Name = Shelby | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 5/23/2010 5:30:45 PM | Computer Name = Shelby | Source = Service Control Manager | ID = 7011
Description =


< End of report >
I tried running the GMER scan twice last night, but the computer froze both times. The first time I got a blue screen of death and the computer had an "unexpected shutdown". The second time, the scan started fine, and we left it alone because you said it could take awhile, but when I came back to it, the entire screen had frozen and I had to reboot again. Though it has had problems, neither of those things have happened before, so it had to have something to do with running that scan. Should I just try the scan again? Or is there something else I have to do to get it to work correctly? Thanks
Hi schrauber, I'm waiting for some help on what I should do about the GMER scan not working. I just wanted to make sure that this thread doesn't get closed for inactivity. Let me know when you get a chance. Thanks for the help.
Sorry, I did not get a notification about your answer :(


Please go here and have a look how you can disable your security software.

Download Combofix from any of the links below but rename it to before saving it to your desktop.

Link 1
Link 2



——————————————————————–

Double click on the renamed Combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Hello Tom, I am running the Combofix scan on my girlfriend's computer right now. I had a couple quick questions though. First, we are supposed to remain connected to the internet during the combofix scan, right? in order to install the recovery system if we need to? Also, my McAfee Virusscan is slightly different than the one that the forum explains how to deactivate. Mine doesn't let you deactivate the on-access scan from the taskbar, but I know how to do it from the virusscan console, so I assume that is a valid way of doing it as long as I know how to. Thanks, J
Hey Tom,

I just finished the Combofix scan. It said that it deleted 6 files I think. Here is the log it produced at the end.

ComboFix 10-06-01.01 - Your name 06/01/2010 22:47:16.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1015.433 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Fixing the Comp\schrauber.exe
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Your name\Documents\My Documents.url
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\fmark2.dat
c:\windows\system32\AutoRun.inf
F:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2010-05-02 to 2010-06-02 )))))))))))))))))))))))))))))))
.

2010-06-02 03:12 . 2010-06-02 03:13 ——– d—–w- c:\users\Your name\AppData\Local\temp
2010-06-02 03:12 . 2010-06-02 03:12 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-06-02 02:20 . 2010-06-02 02:33 ——– d—–w- C:\32788R22FWJFW
2010-05-26 02:47 . 2010-04-23 13:55 2048 —-a-w- c:\windows\system32\tzres.dll
2010-05-25 22:20 . 2010-05-25 22:20 8192 —-a-w- c:\users\Your name\AppData\Roaming\LimeWire\browser\xulrunner\AccessibleMarshal.dll
2010-05-25 22:20 . 2010-05-25 22:20 20480 —-a-w- c:\users\Your name\AppData\Roaming\LimeWire\browser\xulrunner\IA2Marshal.dll
2010-05-25 22:12 . 2010-05-25 22:13 24184872 —-a-w- c:\users\Your name\LimeWireWin.exe
2010-05-23 22:56 . 2010-05-23 22:57 293376 —-a-w- c:\users\Your name\016bsggv.exe
2010-05-12 02:42 . 2010-01-29 16:21 738304 —-a-w- c:\windows\system32\inetcomm.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-02 02:36 . 2009-12-19 21:35 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-06-02 02:34 . 2006-11-09 21:16 12 —-a-w- c:\windows\bthservsdp.dat
2010-06-02 02:19 . 2009-07-13 02:50 ——– d—–w- c:\users\Your name\AppData\Roaming\Skype
2010-06-02 01:41 . 2009-07-13 02:58 ——– d—–w- c:\users\Your name\AppData\Roaming\skypePM
2010-05-25 23:45 . 2008-08-08 18:45 ——– d—–w- c:\users\Your name\AppData\Roaming\LimeWire
2010-05-25 22:18 . 2008-08-08 18:44 ——– d—–w- c:\program files\LimeWire
2010-05-12 16:56 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-05-12 15:21 . 2009-10-11 23:10 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-05-09 01:06 . 2010-03-08 00:02 139620 —-a-w- c:\windows\hpoins15.dat
2010-04-15 22:49 . 2010-03-12 18:39 1335048 —-a-w- c:\windows\Help\OEM\scripts\SamsungHDDFW1HC.exe
2010-04-08 20:48 . 2010-04-30 17:23 18184 —-a-w- c:\windows\Help\OEM\scripts\HPHC_BUY_BATTERY.exe
2010-04-08 20:48 . 2010-03-12 18:39 17160 —-a-w- c:\windows\Help\OEM\scripts\HPHCDisableObject.exe
2010-04-06 21:52 . 2010-04-30 17:23 18184 —-a-w- c:\windows\Help\OEM\scripts\HC_Launch.exe
2010-04-04 04:17 . 2010-04-04 04:17 ——– d—–w- c:\program files\Common Files\Skype
2010-04-04 04:13 . 2009-04-16 05:22 680 —-a-w- c:\users\Your name\AppData\Local\d3d9caps.dat
2010-03-07 23:26 . 2010-03-07 23:26 10134 —-a-r- c:\users\Your name\AppData\Roaming\Microsoft\Installer\{0EC7C406-B592-4686-BAC1-AD29A85EAE6A}\ARPPRODUCTICON.exe
2010-03-05 14:01 . 2010-04-14 20:22 420352 —-a-w- c:\windows\system32\vbscript.dll
2007-11-05 06:19 . 2007-11-05 06:18 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 2153472]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-27 39408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-03-09 26100520]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-12 154136]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-12 129560]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-11 317128]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-25 149280]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-11-06 177456]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-05-23 111952]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2007-10-25 136512]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-11-25 122880]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-05-08 2780432]

c:\users\Your name\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
RCA Detective.lnk - c:\users\Your name\Documents\RCA Detective\RCADetective.exe [2010-3-18 1070080]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
DVD Check.lnk - c:\program files\InterVideo\DVD Check\DVDCheck.exe [2008-7-5 192512]
HP Digital Imaging Monitor.lnk - c:\program files\Hp\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-06-15 721904]
R2 gupdate1ca03648eea6f3d;Google Update Service (gupdate1ca03648eea6f3d);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-13 133104]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2006-11-02 167936]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2008-01-23 501560]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-06-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-13 02:49]

2010-06-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-13 02:49]

2010-06-02 c:\windows\Tasks\HPCeeScheduleForYour name.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-11-05 22:46]

2010-06-02 c:\windows\Tasks\User_Feed_Synchronization-{F051533B-77B5-4F0B-B73F-C3C73C5E557E}.job
- c:\windows\system32\msfeedssync.exe [2010-03-30 04:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=smb&pf=laptop
IE: &AIM Toolbar Search - c:\programdata\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {{898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
.
- - - - ORPHANS REMOVED - - - -

BHO-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - c:\progra~1\MEGAUP~2\MEGAUP~1.DLL
Toolbar-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - c:\progra~1\MEGAUP~2\MEGAUP~1.DLL
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - c:\progra~1\MEGAUP~2\MEGAUP~1.DLL
HKCU-Run-Aim6 - (no file)
HKLM-Run-Easy Dock - (no file)
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
AddRemove-MegauploadToolbar - c:\program files\MegauploadToolbar\uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-01 23:13
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-06-01 23:21:39
ComboFix-quarantined-files.txt 2010-06-02 03:21

Pre-Run: 25,979,510,784 bytes free
Post-Run: 27,197,362,176 bytes free

- - End Of File - - 9EFE2E142E247D9FD701264BFD0B3B42
Hi :)

[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.




Please open OTL, set the extra registry tab to use safe list and hit the run scan button, post back with the content of the 2 logfiles :)
Hey Tom,

We ran the scans that you suggested, and here are the log files.


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4166

Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18904

6/3/2010 9:53:46 AM
mbam-log-2010-06-03 (09-53-46).txt

Scan type: Quick scan
Objects scanned: 127352
Time elapsed: 1 hour(s), 33 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Your name\Favorites\Antivirus Scan.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Users\Your name\Documents\My Music\My Music.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Users\Your name\Documents\My Pictures\My Pictures.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Users\Your name\Documents\My Videos\My Video.url (Trojan.Zlob) -> Quarantined and deleted successfully.

OTL.txt


OTL logfile created on: 6/3/2010 6:15:06 PM - Run 2
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Users\Your name\Desktop\Fixing the Comp
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 377.00 Mb Available Physical Memory | 37.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 53.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 103.42 Gb Total Space | 29.49 Gb Free Space | 28.52% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1.55 Gb Total Space | 1.32 Gb Free Space | 84.85% Space Free | Partition Type: NTFS
Drive F: | 6.82 Gb Total Space | 0.74 Gb Free Space | 10.82% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SHELBY
Current User Name: Your name
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/05/23 17:59:45 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Your name\Desktop\Fixing the Comp\OTL.exe
PRC - [2009/11/24 22:55:37 | 000,122,880 | —- | M] (Google Inc.) – C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
PRC - [2009/05/19 11:36:18 | 000,240,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/05/08 11:35:50 | 002,780,432 | —- | M] () – C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009/05/08 11:34:08 | 000,559,888 | —- | M] () – C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2009/04/30 17:01:10 | 000,154,136 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2009/01/26 22:32:06 | 000,039,408 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/11/24 22:31:12 | 000,087,904 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2008/11/24 22:31:08 | 000,239,968 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
PRC - [2008/10/29 02:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2008/05/22 20:50:00 | 000,144,704 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
PRC - [2008/05/22 20:50:00 | 000,111,952 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
PRC - [2008/05/22 20:50:00 | 000,054,608 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
PRC - [2008/04/14 16:40:26 | 001,070,080 | —- | M] (Audiovox Electronics Corp.) – C:\Users\Your name\Documents\RCA Detective\RCADetective.exe
PRC - [2008/01/11 17:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2007/10/25 15:06:00 | 000,086,016 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\Common Framework\Mctray.exe
PRC - [2007/10/25 10:05:40 | 000,136,512 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2007/10/25 10:04:56 | 000,136,512 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2007/10/25 10:03:28 | 000,103,744 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2007/01/04 19:48:52 | 000,112,152 | R— | M] (InterVideo) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
PRC - [2007/01/04 17:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe


========== Modules (SafeList) ==========

MOD - [2010/05/23 17:59:45 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Your name\Desktop\Fixing the Comp\OTL.exe
MOD - [2008/01/19 03:33:00 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msscript.ocx
MOD - [2008/01/19 03:26:34 | 001,684,480 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2009/05/27 03:27:04 | 029,262,680 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe – (MSSQL$MSSMLBIZ) SQL Server (MSSMLBIZ)
SRV - [2009/05/19 11:36:18 | 000,240,512 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2009/04/30 17:01:10 | 000,154,136 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv)
SRV - [2009/02/06 18:08:58 | 000,533,360 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Live\Family Safety\fsssvc.exe – (fsssvc)
SRV - [2008/11/24 22:31:12 | 000,087,904 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe – (SQLWriter)
SRV - [2008/11/24 22:31:08 | 000,239,968 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe – (SQLBrowser)
SRV - [2008/11/24 22:31:08 | 000,045,408 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe – (MSSQLServerADHelper)
SRV - [2008/05/22 20:50:00 | 000,144,704 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe – (McShield)
SRV - [2008/05/22 20:50:00 | 000,054,608 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe – (McTaskManager)
SRV - [2008/01/19 03:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2008/01/11 17:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe – (BcmSqlStartupSvc)
SRV - [2007/10/25 10:03:28 | 000,103,744 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\McAfee\Common Framework\FrameworkService.exe – (McAfeeFramework)
SRV - [2007/03/05 14:30:06 | 000,110,592 | —- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe – (Com4Qlb)
SRV - [2007/01/04 19:48:52 | 000,112,152 | R— | M] (InterVideo) [Auto | Running] – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe – (IviRegMgr)
SRV - [2007/01/04 17:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Auto | Running] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)


========== Driver Services (SafeList) ==========

DRV - [2009/10/07 09:49:40 | 006,756,632 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\lvuvc.sys – (LVUVC) Logitech Webcam 250(UVC)
DRV - [2009/06/14 20:40:18 | 000,721,904 | —- | M] () [Kernel | Boot | Running] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2009/04/30 19:01:36 | 000,265,496 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\lvrs.sys – (LVRS)
DRV - [2009/04/30 19:00:00 | 000,114,712 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lvpopflt.sys – (lvpopflt)
DRV - [2009/04/30 17:00:12 | 000,025,624 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\LVPr2Mon.sys – (LVPr2Mon)
DRV - [2009/02/06 18:08:52 | 000,055,280 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\fssfltr.sys – (fssfltr)
DRV - [2008/05/22 20:50:00 | 000,174,952 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfehidk.sys – (mfehidk)
DRV - [2008/05/22 20:50:00 | 000,072,936 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2008/05/22 20:50:00 | 000,064,232 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2008/05/22 20:50:00 | 000,052,104 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\mfetdik.sys – (mfetdik)
DRV - [2008/05/22 20:50:00 | 000,033,960 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfebopk.sys – (mfebopk)
DRV - [2008/03/28 02:06:00 | 000,199,472 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\SynTP.sys – (SynTP)
DRV - [2008/03/03 11:32:00 | 000,188,416 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\CHDRT32.sys – (CnxtHdAudService)
DRV - [2008/01/23 04:19:44 | 000,501,560 | —- | M] (Protect Software GmbH) [Kernel | Auto | Running] – C:\Windows\System32\drivers\ACEDRV11.sys – (acedrv11)
DRV - [2008/01/19 01:53:23 | 000,073,088 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2007/10/12 23:50:00 | 001,044,984 | —- | M] (Broadcom Corp.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\BCMWL6.SYS – (BCM43XX)
DRV - [2007/10/12 23:50:00 | 001,044,984 | —- | M] (Broadcom Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\BCMWL6.SYS – (BCM43XV)
DRV - [2007/08/24 08:39:56 | 001,899,008 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\igdkmd32.sys – (igfx)
DRV - [2007/08/24 08:39:56 | 001,899,008 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\igdkmd32.sys – (ialm)
DRV - [2007/07/10 06:27:56 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)
DRV - [2007/06/20 03:29:56 | 000,984,064 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSX_DPV.sys – (HSF_DPV)
DRV - [2007/06/20 03:28:34 | 000,208,896 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSXHWAZL.sys – (HSXHWAZL)
DRV - [2007/06/20 03:28:22 | 000,660,480 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSX_CNXT.sys – (winachsf)
DRV - [2007/06/18 16:12:04 | 000,016,768 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HpqKbFiltr.sys – (HpqKbFiltr)
DRV - [2007/02/21 23:24:48 | 000,159,232 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\CHDART.sys – (HdAudAddService)
DRV - [2006/11/02 05:51:45 | 000,900,712 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2006/11/02 05:51:38 | 000,420,968 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2006/11/02 05:51:34 | 000,316,520 | —- | M] (Emulex) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2006/11/02 05:51:32 | 000,297,576 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2006/11/02 05:51:25 | 000,235,112 | —- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2006/11/02 05:51:25 | 000,232,040 | —- | M] (Intel Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2006/11/02 05:51:00 | 000,147,048 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2006/11/02 05:50:52 | 000,128,104 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\System32\drivers\WimFltr.sys – (WimFltr)
DRV - [2006/11/02 05:50:45 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2006/11/02 05:50:41 | 000,112,232 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2006/11/02 05:50:35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006/11/02 05:50:35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006/11/02 05:50:35 | 000,098,408 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2006/11/02 05:50:24 | 000,088,680 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2006/11/02 05:50:19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006/11/02 05:50:17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006/11/02 05:50:17 | 000,041,064 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\tpm.sys – (TPM)
DRV - [2006/11/02 05:50:16 | 000,071,784 | —- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2006/11/02 05:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2006/11/02 05:50:11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006/11/02 05:50:10 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2006/11/02 05:50:10 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2006/11/02 05:50:10 | 000,038,504 | —- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid2.sys – (SiSRaid2)
DRV - [2006/11/02 05:50:10 | 000,037,480 | —- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2006/11/02 05:50:09 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2006/11/02 05:50:09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006/11/02 05:50:07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006/11/02 05:50:05 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2006/11/02 05:50:05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006/11/02 05:50:04 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2006/11/02 05:50:03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006/11/02 05:49:59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006/11/02 05:49:56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006/11/02 05:49:53 | 000,028,776 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2006/11/02 05:49:30 | 000,017,512 | —- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2006/11/02 05:49:28 | 000,016,488 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2006/11/02 05:49:20 | 000,014,952 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2006/11/02 04:25:24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 04:24:47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006/11/02 04:24:46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006/11/02 04:24:45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006/11/02 04:24:44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006/11/02 04:24:44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006/11/02 03:41:49 | 000,200,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTAZL3.SYS – (HSFHWAZL)
DRV - [2006/11/02 03:36:50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)
DRV - [2006/11/02 03:36:43 | 002,028,032 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2006/11/02 03:30:54 | 000,117,760 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2006/11/02 03:30:53 | 000,167,936 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\b57nd60x.sys – (b57nd60x)
DRV - [2006/06/28 14:54:00 | 000,009,472 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\CPQBttn.sys – (HBtnKey)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…b&pf=laptop
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 80 9E 9E 4C 16 6E CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :0


[2010/05/25 18:21:44 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\mozilla\Extensions
[2010/05/25 18:21:44 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\mozilla\Extensions\[removed]

O1 HOSTS File: ([2010/06/01 23:13:38 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\ScriptCl.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll File not found
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Your name\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RCA Detective.lnk = C:\Users\Your name\Documents\RCA Detective\RCADetective.exe (Audiovox Electronics Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &AIM Toolbar Search - C:\ProgramData\AIM Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O9 - Extra Button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…k.cab102118.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.gamehouse.com/games/insaniq/popcaploader.cab (PopCapLoader Object)
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} http://zone.msn.com/bingame/zpagames/ZPA_B…on.cab64162.cab (MSN Games – Backgammon)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Your name\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\Your name\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/06/02 23:48:51 | 000,000,000 | —D | C] – C:\Users\Your name\AppData\Roaming\Malwarebytes
[2010/06/02 23:47:11 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/06/02 23:46:43 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/06/02 23:46:41 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/06/02 23:46:38 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/01 23:22:00 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/06/01 23:21:44 | 000,000,000 | —D | C] – C:\Users\Your name\AppData\Local\temp
[2010/06/01 22:39:44 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/06/01 22:39:36 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/06/01 22:39:36 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/06/01 22:38:58 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/06/01 22:22:11 | 000,000,000 | —D | C] – C:\Qoobox
[2010/06/01 22:21:22 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/06/01 22:20:54 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/05/29 21:47:58 | 000,000,000 | —D | C] – C:\Users\Your name\Desktop\MIKES CAMERA
[2010/05/25 23:42:37 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010/05/25 22:47:22 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/05/25 18:21:43 | 000,000,000 | —D | C] – C:\Users\Your name\AppData\Roaming\Mozilla
[2010/05/25 18:12:22 | 024,184,872 | —- | C] (Lime Wire LLC) – C:\Users\Your name\LimeWireWin.exe
[2010/05/23 21:59:55 | 000,000,000 | —D | C] – C:\Users\Your name\Desktop\poster pics
[2010/05/22 11:43:56 | 000,000,000 | —D | C] – C:\Users\Your name\Desktop\Fixing the Comp

========== Files - Modified Within 30 Days ==========

[2010/06/03 18:42:10 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/03 18:38:28 | 000,000,400 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{F051533B-77B5-4F0B-B73F-C3C73C5E557E}.job
[2010/06/03 18:14:22 | 003,670,016 | -HS- | M] () – C:\Users\Your name\NTUSER.DAT
[2010/06/03 18:00:30 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/03 18:00:30 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/03 10:01:26 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/03 10:00:29 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/03 10:00:17 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/03 09:59:44 | 1064,755,200 | -HS- | M] () – C:\hiberfil.sys
[2010/06/03 09:59:40 | 000,000,000 | —- | M] () – C:\Windows\System32\drivers\lvuvc.hs
[2010/06/03 09:58:02 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/06/03 09:57:40 | 000,524,288 | -HS- | M] () – C:\Users\Your name\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms
[2010/06/03 09:57:40 | 000,065,536 | -HS- | M] () – C:\Users\Your name\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf
[2010/06/02 23:47:25 | 000,000,818 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/01 23:25:34 | 002,360,679 | -H– | M] () – C:\Users\Your name\AppData\Local\IconCache.db
[2010/06/01 23:14:06 | 000,000,215 | —- | M] () – C:\Windows\system.ini
[2010/06/01 23:13:38 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/06/01 22:37:20 | 000,000,338 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForYour name.job
[2010/06/01 21:42:17 | 000,062,976 | —- | M] () – C:\Users\Your name\Documents\LHS roster 2010.xls
[2010/05/29 22:46:30 | 000,769,132 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/05/29 22:46:30 | 000,650,720 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/05/29 22:46:30 | 000,122,562 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/05/29 22:09:34 | 000,027,136 | —- | M] () – C:\Users\Your name\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/25 23:42:32 | 153,738,642 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/05/25 18:18:00 | 000,001,708 | —- | M] () – C:\Users\Your name\Desktop\LimeWire 5.5.8.lnk
[2010/05/25 18:13:22 | 024,184,872 | —- | M] (Lime Wire LLC) – C:\Users\Your name\LimeWireWin.exe
[2010/05/23 19:56:13 | 000,000,191 | —- | M] () – C:\Users\Your name\Desktop\TV Listings - Find Local TV Shows and Movie Schedules - Listings Grid TVGuide.com.url
[2010/05/23 18:57:16 | 000,293,376 | —- | M] () – C:\Users\Your name\016bsggv.exe
[2010/05/21 23:27:31 | 000,030,036 | —- | M] () – C:\Users\Your name\Desktop\alg-singer-adam-lambert.jpg
[2010/05/20 22:54:14 | 000,025,088 | —- | M] () – C:\Users\Your name\Desktop\INFORMATION FOR SENIOR NIGHT PROGRAM.doc
[2010/05/19 20:49:48 | 000,027,136 | —- | M] () – C:\Users\Your name\Desktop\rough draft.doc
[2010/05/18 21:00:29 | 000,025,088 | —- | M] () – C:\Users\Your name\Desktop\Rules.doc
[2010/05/12 22:09:13 | 000,110,592 | —- | M] () – C:\Users\Your name\Desktop\Lowell High School Softball Apparel Graphics.doc
[2010/05/12 11:21:16 | 000,221,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/05/11 22:49:01 | 000,021,504 | —- | M] () – C:\Users\Your name\Desktop\anemia.doc
[2010/05/11 11:41:14 | 000,074,713 | —- | M] () – C:\Users\Your name\Desktop\TaxReturnSam2009.pdf
[2010/05/11 11:03:33 | 000,148,253 | —- | M] () – C:\Users\Your name\Desktop\TaxReturn 2009.pdf
[2010/05/10 21:53:21 | 000,273,408 | —- | M] () – C:\Users\Your name\Desktop\What is Anemia.doc
[2010/05/08 21:25:38 | 000,087,554 | —- | M] () – C:\Users\Your name\Desktop\Shelby TaxReturn.pdf
[2010/05/08 21:06:10 | 000,139,620 | —- | M] () – C:\Windows\hpoins15.dat
[2010/05/08 21:03:19 | 000,000,254 | —- | M] () – C:\Windows\win.ini
[2010/05/05 21:57:16 | 000,000,171 | —- | M] () – C:\Users\Your name\Desktop\Your SAT Registration is complete.url

========== Files Created - No Company Name ==========

[2010/06/02 23:47:25 | 000,000,818 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/01 22:39:46 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/06/01 22:39:37 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/06/01 22:39:36 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/06/01 22:39:36 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/06/01 22:39:36 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/05/25 23:41:09 | 153,738,642 | —- | C] () – C:\Windows\MEMORY.DMP
[2010/05/25 18:18:00 | 000,001,708 | —- | C] () – C:\Users\Your name\Desktop\LimeWire 5.5.8.lnk
[2010/05/23 18:56:59 | 000,293,376 | —- | C] () – C:\Users\Your name\016bsggv.exe
[2010/05/21 23:28:20 | 000,030,036 | —- | C] () – C:\Users\Your name\Desktop\alg-singer-adam-lambert.jpg
[2010/05/20 22:54:13 | 000,025,088 | —- | C] () – C:\Users\Your name\Desktop\INFORMATION FOR SENIOR NIGHT PROGRAM.doc
[2010/05/18 21:00:29 | 000,025,088 | —- | C] () – C:\Users\Your name\Desktop\Rules.doc
[2010/05/14 13:06:42 | 000,000,338 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForYour name.job
[2010/05/13 21:25:55 | 000,027,136 | —- | C] () – C:\Users\Your name\Desktop\rough draft.doc
[2010/05/12 13:57:29 | 000,110,592 | —- | C] () – C:\Users\Your name\Desktop\Lowell High School Softball Apparel Graphics.doc
[2010/05/11 22:43:20 | 000,021,504 | —- | C] () – C:\Users\Your name\Desktop\anemia.doc
[2010/05/11 11:40:15 | 000,074,713 | —- | C] () – C:\Users\Your name\Desktop\TaxReturnSam2009.pdf
[2010/05/11 11:03:27 | 000,148,253 | —- | C] () – C:\Users\Your name\Desktop\TaxReturn 2009.pdf
[2010/05/10 19:59:49 | 000,273,408 | —- | C] () – C:\Users\Your name\Desktop\What is Anemia.doc
[2010/05/08 21:25:10 | 000,087,554 | —- | C] () – C:\Users\Your name\Desktop\Shelby TaxReturn.pdf
[2010/05/05 21:57:16 | 000,000,171 | —- | C] () – C:\Users\Your name\Desktop\Your SAT Registration is complete.url
[2009/12/18 23:22:38 | 000,082,289 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2009/06/14 20:40:17 | 000,721,904 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2009/05/08 11:13:04 | 000,013,584 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2009/04/30 17:00:12 | 000,025,624 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2009/01/23 14:44:29 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/08/29 23:31:01 | 000,000,280 | —- | C] () – C:\Windows\System32\epoPGPsdk.dll.sig
[2008/08/08 12:13:59 | 000,000,021 | —- | C] () – C:\Windows\atid.ini
[2008/07/05 09:49:59 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2008/07/05 09:49:59 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2008/07/05 09:49:59 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2008/07/05 09:49:59 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2008/07/05 09:49:59 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2008/07/05 09:49:59 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2007/08/24 08:46:48 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1322.dll
[2007/08/24 08:28:04 | 000,249,856 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/28 16:11:30 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 06:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/09/25 03:02:34 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/25 03:02:34 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/03/09 06:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\Windows\System32\OUTLPERF.INI
[1913/08/01 10:18:54 | 000,056,832 | —- | C] () – C:\Windows\System32\iyvu9_32.dll
< End of report >

Extra.txt


OTL Extras logfile created on: 6/3/2010 6:15:06 PM - Run 2
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Users\Your name\Desktop\Fixing the Comp
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 377.00 Mb Available Physical Memory | 37.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 53.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 103.42 Gb Total Space | 29.49 Gb Free Space | 28.52% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1.55 Gb Total Space | 1.32 Gb Free Space | 84.85% Space Free | Partition Type: NTFS
Drive F: | 6.82 Gb Total Space | 0.74 Gb Free Space | 10.82% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SHELBY
Current User Name: Your name
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{067CB1D8-AC23-4F71-867C-5784A8CD9DE0}" = lport=445 | protocol=6 | dir=in | app=system |
"{2DF01963-9284-4BA9-AFB6-D5C0BD9B8FAB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3245D97F-8E12-492D-A838-7058BF685F58}" = lport=137 | protocol=17 | dir=in | app=system |
"{343903A9-2D2D-4350-931B-C8163D1703DE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{365DFCC9-560E-42E1-9B18-6F22287D2304}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{3D018BC8-722F-440F-AE69-935BF56A67BD}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{3E7FDC62-D1AD-4C92-84FE-64CE24FD7DA8}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{436A6E74-E0E8-4B1C-8C99-4763E3B27F17}" = lport=10243 | protocol=6 | dir=in | app=system |
"{43F83258-67FA-4806-A7C4-D55BCB3842D8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4CD182B6-ACC4-4D56-A4A4-741CA7F3B1B0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4FEAE458-B68D-41E2-BC11-225D163A8FE1}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5390166F-6DDD-4D11-A50E-2C9644F56789}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{857FB45A-202F-429D-B757-FB8D486A397B}" = rport=138 | protocol=17 | dir=out | app=system |
"{880830EE-986C-4BE3-B2DB-4C43F1843FC0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8FDD4486-9586-45C5-9B55-AB8852DE8F70}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{8FF85D03-F8AB-4981-BFFC-367C9ABD8AA3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{948CFBB5-BF6B-4177-ACA2-9EC8702CF784}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{9EF11CC0-4C1E-4247-AD2B-C84F1DCDCADE}" = rport=137 | protocol=17 | dir=out | app=system |
"{AB0953CB-D60E-4FD0-8CFB-D046FF5E5D46}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B78164CC-6E20-495D-BD6C-33A48CF2C82F}" = lport=138 | protocol=17 | dir=in | app=system |
"{CEB2F628-ED86-4B85-93F1-E63C05E28F3C}" = rport=10243 | protocol=6 | dir=out | app=system |
"{D08DC149-4644-4EF1-93C7-B63B7B133BC8}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D67102E4-B4D1-4D2A-B53F-81CCF25BDD5F}" = rport=139 | protocol=6 | dir=out | app=system |
"{D84733D6-13AF-42BF-AA93-25AE4CD6580D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DED32AB8-A02F-4278-B201-5C4EFEABCFDB}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{E96A0A08-8458-4CAD-98FA-1007C3F50A78}" = rport=445 | protocol=6 | dir=out | app=system |
"{F271176F-4B52-4514-A5C7-EC16A8A21507}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F4A70DEA-86BC-41F2-9AAB-F2584AC449BC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F5196ED7-53CE-40F5-9680-798CEC56178A}" = lport=139 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0188B2A8-8236-4AE1-988F-23F320FEB13B}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{05C9A87F-120B-4219-ABD0-2A4A9DCA6A80}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{0817C515-FEB2-4E49-9EA8-7F3C83ED9193}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{17822737-6AB8-4B0D-AE23-6A9F16B39A68}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{35E7CBC8-48A7-4B79-A539-82DE3D62F56E}" = protocol=6 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{3C0BD194-2417-4539-8316-D0D8C8715E74}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4A9EA769-E4AA-4B00-8BC1-C4497453E56F}" = protocol=17 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{4BBCAC6F-E25E-4C3D-A025-9935F3D1C26D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{55F29BAD-1219-48ED-A045-9E970E8BE00D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5AC12650-9E36-46E3-B3D4-B91B8B210FEC}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{6177F692-352E-4690-AE50-D51D11DF7684}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{63306666-7445-44DC-B12B-470E24E0BBD1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{68A13F56-B021-4CCE-9A19-580E1A2236EA}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{68BE2FEA-7A25-462E-83F0-AB8287E70374}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{6C0D2278-04DE-43F8-B424-69484B4A7DA5}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{7017095B-6AC6-4DE5-9DE8-CF0BD5C70761}" = protocol=6 | dir=in | app=c:\program files\logitech\logitech vid\vid.exe |
"{7709CD36-5BB9-42DE-ACA5-21B7BBB8B414}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{797B3326-EA4B-47DE-A5F9-251A8CD89C66}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{7ACFDB45-FD75-4239-8912-F48C9E2C6F6A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{7C7119AA-F8CB-4AF7-A79A-D9DCAA50DF93}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{958B0021-9B6A-4D9D-9189-3A33CC7A12F4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9A240FAE-C3D4-4B2E-B8A1-F236A147049C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9C41B18B-5F60-4446-BE93-95DB4252196F}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{9ED55240-989C-4312-A970-98E4B6DA4952}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A2A91D67-14D3-4961-B9DC-98FFE2036AD9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A34E5160-F7DC-448A-A498-B48F4102A366}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{A64C7A44-99CB-4115-A5C1-0369DA84C0E1}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{A95A78FF-A734-46F9-A1A1-90EC14F45ACB}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A9E84B3B-49AE-4D47-9EF7-6AD28B5EAD33}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{B69C4902-EF2A-4E88-A15D-BBA9AE6993EF}" = protocol=17 | dir=in | app=c:\program files\logitech\logitech vid\vid.exe |
"{B6B7DEB3-F000-414D-A967-DF861EF7B37A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C7308B9B-5482-4AD1-A0B8-7BC27A156F18}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{D8F08E3F-1ACF-4542-B80F-5989E39D930B}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{DA488511-C20D-4FF2-87D5-8673EF93B91E}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{ED91463A-7137-4F26-90D1-54EEBA917072}" = protocol=6 | dir=out | app=system |
"{F4D48E53-47FE-4643-B4CB-429B3DFDDB24}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F73ED862-5603-4AA9-AC05-8DB476E994D7}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{41F77CB4-8DE6-42AA-9FDE-93A7B99B78AD}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{6E9E6542-1EB2-4D79-8E56-D4B98A0C9B1F}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{AE80D3B7-0719-4BAF-871D-08BC210F86D7}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{B085D0A8-B1C2-408A-95DE-01BA01E0CB0A}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe |
"TCP Query User{B20AA324-78BD-45D8-B3EE-354B32DCA76D}C:\users\your name\appdata\roaming\gameranger\gameranger\gameranger.exe" = protocol=6 | dir=in | app=c:\users\your name\appdata\roaming\gameranger\gameranger\gameranger.exe |
"TCP Query User{C11451A0-0AAC-4C78-9FC4-B2D94C1ABADA}C:\program files\aim6\aim6.exe" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"UDP Query User{394B33B1-BBB5-4C27-8A6B-1E42076FA95F}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{6CCABD90-B140-4448-858A-DAE1703B26DD}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{813BC0A0-E414-4277-BFFF-C1EF2CA23675}C:\program files\aim6\aim6.exe" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"UDP Query User{82DBA5ED-ED59-4434-9460-2791B6971EA3}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{CBF4DBA8-07C5-4F61-B208-47D64025134D}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe |
"UDP Query User{F7EB2DE1-32A4-4959-AA64-F5C31E99AC30}C:\users\your name\appdata\roaming\gameranger\gameranger\gameranger.exe" = protocol=17 | dir=in | app=c:\users\your name\appdata\roaming\gameranger\gameranger\gameranger.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0EC7C406-B592-4686-BAC1-AD29A85EAE6A}" = HP Driver Diagnostics
"{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp
"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch
"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22466889-7642-488d-AA0E-F619704CF7AB}" = DeviceDiscovery
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{29FA9E38-7A6D-475E-8C15-15EE8BA9639E}" = ESU for Microsoft Vista
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{2C86D799-6203-4BE4-8175-126D69742F2F}" = Vista Default Settings
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 B2
"{35C03C04-3F1F-42C2-A989-A757EE691F65}" = McAfee VirusScan Enterprise
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3912A629-0020-0005-3131-2FBA74D4DF0A}" = InterVideo WinDVD
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}" = Mega Manager
"{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery
"{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}" = HP Backup and Recovery Manager Installer
"{41B9E2CF-0B3F-442A-B5B3-592A4A355634}" = iTunes
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{521F72F4-FFE4-4959-AA88-EED06125211F}" = HP Notebook Accessories Product Tour
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{584B0895-8EF3-4175-8E80-1B68BFA04636}" = HP Help and Support
"{5D97A4A7-C274-4B63-86D9-07A33435F505}" = InterVideo DVD Check
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A6DCB18-3ECB-46DC-894B-5EFE08C0BD9B}" = Mega Manager
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6D3DB611-D5E8-4E4B-8952-0D3F549F9CC6}" = HP Active Support Library 32 bit components
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{70CEFEBA-F757-4DBE-8A21-027C326137CE}" = Application Installer 4.00.B13
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76CD2979-09C0-493A-84B3-8FD97EF4BCEA}" = Windows Live Family Safety
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0120-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9FE8E277-EBFC-4A5E-BD70-6F9B7F32AF0E}" = HP Total Care Advisor
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA9768AA-FF0B-4C66-A085-31E934F77841}" = Apple Mobile Device Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AC96671C-2001-432C-9826-5266D84EF1DC}" = Logitech Webcam Software
"{ACA85783-8EEA-4f0a-B2A3-A8173F30209F}" = C4200_doccd
"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
"{AF36CE1D-FD2C-4BA0-93FA-1196785DD610}" = Adobe Flash Player 10 Plugin
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B09BCBF6-87EE-4403-A336-3A9510856535}" = HP Photosmart All-In-One Software 9.0
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP2
"{B51C3024-333B-4FB6-B1EC-49ECE2DE6056}" = HP User Guides 0077
"{BBE5C83E-4DC5-494F-8A23-3AAE242E94C2}" = HP Easy Setup - Frontend
"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{BFDE4176-5DFE-4db9-AA00-8F30CB001BDA}" = c4200_Help
"{C39E671D-0528-4c5e-A034-8470C5BC393A}" = C4200
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D32067CD-7409-4792-BFA0-1469BCD8F0C8}" = HP Wireless Assistant
"{D8B7A682-20DA-4797-8415-B1FB14D4D32B}" = PS_AIO_Software
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{E28750A2-45F2-4b63-99F7-9F81A94B1E2D}" = PS_AIO_Software_min
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{FD7F242B-9AA0-40c3-941E-3A9821D19C09}" = PS_AIO_ProductContext
"{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"AIM_6" = AIM 6
"AIMTunes" = AIMTunes
"Broadcom 802.11b Network Adapter" = Broadcom 802.11 Wireless LAN Adapter
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP2
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Google Chrome" = Google Chrome
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 9.0
"HP Photosmart Essential" = HP Photosmart Essential 2.01
"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0
"HPExtendedCapabilities" = HP Customer Participation Program 9.0
"HPOCR" = HP OCR Software 9.0
"LimeWire" = LimeWire 5.5.8
"lvdrivers_12.0" = Logitech Webcam Software Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"PROSet" = Intel® Network Connections Drivers
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"RCA Detective_is1" = RCA Detective [removed]
"RCA EasyRip™_is1" = RCA EasyRip™ [removed]
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GameRanger" = GameRanger
"Play65" = Play65

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/30/2010 2:40:06 PM | Computer Name = Shelby | Source = Google Update | ID = 20
Description =

Error - 5/30/2010 3:40:06 PM | Computer Name = Shelby | Source = Google Update | ID = 20
Description =

Error - 5/30/2010 4:40:06 PM | Computer Name = Shelby | Source = Google Update | ID = 20
Description =

Error - 5/30/2010 5:40:06 PM | Computer Name = Shelby | Source = Google Update | ID = 20
Description =

Error - 5/30/2010 6:40:06 PM | Computer Name = Shelby | Source = Google Update | ID = 20
Description =

Error - 5/30/2010 7:40:06 PM | Computer Name = Shelby | Source = Google Update | ID = 20
Description =

Error - 5/30/2010 8:40:06 PM | Computer Name = Shelby | Source = Google Update | ID = 20
Description =

Error - 6/1/2010 10:47:20 PM | Computer Name = Shelby | Source = McLogEvent | ID = 259
Description = The file C:\Users\Your name\AppData\Local\Temp\Av-test.txt contains
the EICAR test file Test. No cleaner available, file deleted successfully. Detected
using Scan engine version 5400.1158 DAT version 6000.0000.

Error - 6/1/2010 11:31:28 PM | Computer Name = Shelby | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 6/3/2010 10:05:31 AM | Computer Name = Shelby | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

[ System Events ]
Error - 6/1/2010 10:41:23 PM | Computer Name = Shelby | Source = WMPNetworkSvc | ID = 866312
Description =

Error - 6/1/2010 10:44:56 PM | Computer Name = Shelby | Source = Service Control Manager | ID = 7034
Description =

Error - 6/1/2010 10:46:09 PM | Computer Name = Shelby | Source = Service Control Manager | ID = 7030
Description =

Error - 6/1/2010 11:13:45 PM | Computer Name = Shelby | Source = Service Control Manager | ID = 7030
Description =

Error - 6/1/2010 11:27:47 PM | Computer Name = Shelby | Source = HTTP | ID = 15016
Description =

Error - 6/2/2010 3:04:51 AM | Computer Name = Shelby | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 6/3/2010 3:03:26 AM | Computer Name = Shelby | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 6/3/2010 9:57:43 AM | Computer Name = Shelby | Source = DCOM | ID = 10010
Description =

Error - 6/3/2010 10:00:36 AM | Computer Name = Shelby | Source = HTTP | ID = 15016
Description =

Error - 6/3/2010 10:01:07 AM | Computer Name = Shelby | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 001EEC1A7DDF. The following
error occurred: %%258. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.


< End of report >
Hi :)


Viewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". This changed from what we know in 2006 read this article:

http://www.clickz.com/news/article.php/3561546

I suggest you remove the program now. Click on start > run > and then paste the following into the "open" field: appwiz.cpl and press OK. From within Add or Remove Programs uninstall the following if they exist: Viewpoint, Viewpoint Manager, Viewpoint Media Player.




[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. NOT supported for use in 9x or ME

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 20.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u20-windows-i586.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u20-windows-i586.exe and select "Run as an Administrator.")





Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic




Please visit windows update and install service pack 2. Now please post back with a fresh OTL logfile and tell me how the system is running :)
Hey Tom, I had no problem removing that program or installing the latest version of Java, and the ESET scanner worked fine (though it did take about 10 hours). However, I am having some difficulty installing service pack 2. It does not show as an important or recommended update from Windows Update, and I went on Microsoft's website and tried a few of their troubleshoots to try to get it to appear, but no luck so far. The computer is running slightly better, but startup is still very slow. I want to reduce the number of programs running at startup, but I do not know what some of them are, so I do not want to screw with them. Lastly, whenever I reboot, it still says that Windows Defender isn't running each time. So here is the log from the ESET scan, and if you know what I need to do to get service pack 2, I can finish up that. Thanks again for all of the help. - J ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=7e0d9b3652cb784b8ba50b1d4076b4bf # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-06-06 08:19:22 # local_time=2010-06-06 04:19:22 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=6.0.6001 NT Service Pack 1 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=5892 16776573 100 100 0 112382034 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=157207 # found=9 # cleaned=9 # scan_time=37900 C:\Users\Your name\Documents\LimeWire\Saved\A Beautiful Mind (2001).avi a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined) 00000000000000000000000000000000 C C:\Users\Your name\Documents\LimeWire\Saved\come one get higher matt.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined) 00000000000000000000000000000000 C C:\Users\Your name\Documents\LimeWire\Saved\confrontation les miserables.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined) 00000000000000000000000000000000 C C:\Users\Your name\Documents\LimeWire\Saved\drink with me les miserables(Disk 1).mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined) 00000000000000000000000000000000 C C:\Users\Your name\Documents\LimeWire\Saved\idina menzel penny.wma probably a variant of Win32/Agent trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\Your name\Documents\LimeWire\Saved\look down les miserables - greatest hits.wma WMA/TrojanDownloader.Wimad.N trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\Your name\Documents\LimeWire\Saved\overture les miserables.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined) 00000000000000000000000000000000 C C:\Users\Your name\Documents\LimeWire\Saved\windows down braddigan hot new track.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined) 00000000000000000000000000000000 C C:\Users\Your name\Documents\LimeWire\Saved\Windows_Down_Braddigan.wma a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined) 00000000000000000000000000000000 C
Hi,




Download and Run StartupLite


This program will identify startup entries that are unnecessary to be started at bootup. This will help free some memory.

  • Download StartupLite.exe by MalwareBytes to your desktop.
  • Double click on StartUpLite.exe to run it. If you are using Windows Vista, right click the icon and select Run As Administrator.
  • A list of unecessary startup entries will be compiled.
  • Take a read at the description of each and for most of them you probably won't need it please make sure there is a checkmark next to Disable.
  • Leave all the items as Disabled and click Continue.
  • Restart your computer once it's done.



Please post back with a fresh OTL logfile.
Here's my fresh OTL logfile. I didn't get the "Extras" logfile. Let me know if you want me to run another scan and get that file. I figured out the problem with Windows Defender. Didn't check the "use windows defender" box back on after we disabled it a few steps ago. Still cannot get Service Pack 2, and the update that is available on windows update fails every time I try to install it.

- J


OTL logfile created on: 6/6/2010 1:38:55 PM - Run 3
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Users\Your name\Desktop\Fixing the Comp
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 265.00 Mb Available Physical Memory | 26.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 46.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 103.42 Gb Total Space | 25.40 Gb Free Space | 24.56% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1.55 Gb Total Space | 1.32 Gb Free Space | 84.85% Space Free | Partition Type: NTFS
Drive F: | 6.82 Gb Total Space | 0.74 Gb Free Space | 10.82% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SHELBY
Current User Name: Your name
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/05/23 17:59:45 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Your name\Desktop\Fixing the Comp\OTL.exe
PRC - [2010/05/20 14:56:44 | 000,943,600 | —- | M] (Google Inc.) – C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2009/11/24 22:55:37 | 000,122,880 | —- | M] (Google Inc.) – C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
PRC - [2009/08/18 11:29:22 | 001,529,728 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2009/08/18 11:29:22 | 000,183,152 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2009/05/19 11:36:18 | 000,240,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/05/08 11:35:50 | 002,780,432 | —- | M] () – C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009/05/08 11:34:08 | 000,559,888 | —- | M] () – C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2009/04/30 17:01:10 | 000,154,136 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2009/01/26 22:32:06 | 000,039,408 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/11/24 22:31:12 | 000,087,904 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2008/11/24 22:31:08 | 000,239,968 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
PRC - [2008/10/29 02:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2008/05/22 20:50:00 | 000,144,704 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
PRC - [2008/05/22 20:50:00 | 000,111,952 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
PRC - [2008/05/22 20:50:00 | 000,054,608 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
PRC - [2008/01/19 03:38:38 | 001,008,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/01/11 17:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2007/10/25 15:06:00 | 000,086,016 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\Common Framework\Mctray.exe
PRC - [2007/10/25 10:05:40 | 000,136,512 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2007/10/25 10:04:56 | 000,136,512 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2007/10/25 10:03:28 | 000,103,744 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2007/01/04 19:48:52 | 000,112,152 | R— | M] (InterVideo) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe


========== Modules (SafeList) ==========

MOD - [2010/05/23 17:59:45 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Your name\Desktop\Fixing the Comp\OTL.exe
MOD - [2008/01/19 03:33:00 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msscript.ocx
MOD - [2008/01/19 03:26:34 | 001,684,480 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2009/08/18 11:29:22 | 001,529,728 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE – (wlidsvc)
SRV - [2009/05/27 03:27:04 | 029,262,680 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe – (MSSQL$MSSMLBIZ) SQL Server (MSSMLBIZ)
SRV - [2009/05/19 11:36:18 | 000,240,512 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2009/04/30 17:01:10 | 000,154,136 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv)
SRV - [2009/02/06 18:08:58 | 000,533,360 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Live\Family Safety\fsssvc.exe – (fsssvc)
SRV - [2008/11/24 22:31:12 | 000,087,904 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe – (SQLWriter)
SRV - [2008/11/24 22:31:08 | 000,239,968 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe – (SQLBrowser)
SRV - [2008/11/24 22:31:08 | 000,045,408 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe – (MSSQLServerADHelper)
SRV - [2008/05/22 20:50:00 | 000,144,704 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe – (McShield)
SRV - [2008/05/22 20:50:00 | 000,054,608 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe – (McTaskManager)
SRV - [2008/01/19 03:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2008/01/11 17:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe – (BcmSqlStartupSvc)
SRV - [2007/10/25 10:03:28 | 000,103,744 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\McAfee\Common Framework\FrameworkService.exe – (McAfeeFramework)
SRV - [2007/03/05 14:30:06 | 000,110,592 | —- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe – (Com4Qlb)
SRV - [2007/01/04 19:48:52 | 000,112,152 | R— | M] (InterVideo) [Auto | Running] – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe – (IviRegMgr)


========== Driver Services (SafeList) ==========

DRV - [2009/10/07 09:49:40 | 006,756,632 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lvuvc.sys – (LVUVC) Logitech Webcam 250(UVC)
DRV - [2009/06/14 20:40:18 | 000,721,904 | —- | M] () [Kernel | Boot | Running] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2009/04/30 19:01:36 | 000,265,496 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lvrs.sys – (LVRS)
DRV - [2009/04/30 19:00:00 | 000,114,712 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lvpopflt.sys – (lvpopflt)
DRV - [2009/04/30 17:00:12 | 000,025,624 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\LVPr2Mon.sys – (LVPr2Mon)
DRV - [2009/02/06 18:08:52 | 000,055,280 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\fssfltr.sys – (fssfltr)
DRV - [2008/05/22 20:50:00 | 000,174,952 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfehidk.sys – (mfehidk)
DRV - [2008/05/22 20:50:00 | 000,072,936 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2008/05/22 20:50:00 | 000,064,232 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2008/05/22 20:50:00 | 000,052,104 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\mfetdik.sys – (mfetdik)
DRV - [2008/05/22 20:50:00 | 000,033,960 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfebopk.sys – (mfebopk)
DRV - [2008/03/28 02:06:00 | 000,199,472 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\SynTP.sys – (SynTP)
DRV - [2008/03/03 11:32:00 | 000,188,416 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\CHDRT32.sys – (CnxtHdAudService)
DRV - [2008/01/23 04:19:44 | 000,501,560 | —- | M] (Protect Software GmbH) [Kernel | Auto | Running] – C:\Windows\System32\drivers\ACEDRV11.sys – (acedrv11)
DRV - [2008/01/19 01:53:23 | 000,073,088 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2007/10/12 23:50:00 | 001,044,984 | —- | M] (Broadcom Corp.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\BCMWL6.SYS – (BCM43XX)
DRV - [2007/10/12 23:50:00 | 001,044,984 | —- | M] (Broadcom Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\BCMWL6.SYS – (BCM43XV)
DRV - [2007/08/24 08:39:56 | 001,899,008 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\igdkmd32.sys – (igfx)
DRV - [2007/08/24 08:39:56 | 001,899,008 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\igdkmd32.sys – (ialm)
DRV - [2007/07/10 06:27:56 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)
DRV - [2007/06/20 03:29:56 | 000,984,064 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSX_DPV.sys – (HSF_DPV)
DRV - [2007/06/20 03:28:34 | 000,208,896 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSXHWAZL.sys – (HSXHWAZL)
DRV - [2007/06/20 03:28:22 | 000,660,480 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSX_CNXT.sys – (winachsf)
DRV - [2007/06/18 16:12:04 | 000,016,768 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HpqKbFiltr.sys – (HpqKbFiltr)
DRV - [2007/02/21 23:24:48 | 000,159,232 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\CHDART.sys – (HdAudAddService)
DRV - [2006/11/02 05:51:45 | 000,900,712 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2006/11/02 05:51:38 | 000,420,968 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2006/11/02 05:51:34 | 000,316,520 | —- | M] (Emulex) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2006/11/02 05:51:32 | 000,297,576 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2006/11/02 05:51:25 | 000,235,112 | —- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2006/11/02 05:51:25 | 000,232,040 | —- | M] (Intel Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2006/11/02 05:51:00 | 000,147,048 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2006/11/02 05:50:52 | 000,128,104 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\System32\drivers\WimFltr.sys – (WimFltr)
DRV - [2006/11/02 05:50:45 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2006/11/02 05:50:41 | 000,112,232 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2006/11/02 05:50:35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006/11/02 05:50:35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006/11/02 05:50:35 | 000,098,408 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2006/11/02 05:50:24 | 000,088,680 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2006/11/02 05:50:19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006/11/02 05:50:17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006/11/02 05:50:17 | 000,041,064 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\tpm.sys – (TPM)
DRV - [2006/11/02 05:50:16 | 000,071,784 | —- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2006/11/02 05:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2006/11/02 05:50:11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006/11/02 05:50:10 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2006/11/02 05:50:10 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2006/11/02 05:50:10 | 000,038,504 | —- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid2.sys – (SiSRaid2)
DRV - [2006/11/02 05:50:10 | 000,037,480 | —- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2006/11/02 05:50:09 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2006/11/02 05:50:09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006/11/02 05:50:07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006/11/02 05:50:05 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2006/11/02 05:50:05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006/11/02 05:50:04 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2006/11/02 05:50:03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006/11/02 05:49:59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006/11/02 05:49:56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006/11/02 05:49:53 | 000,028,776 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2006/11/02 05:49:30 | 000,017,512 | —- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2006/11/02 05:49:28 | 000,016,488 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2006/11/02 05:49:20 | 000,014,952 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2006/11/02 04:25:24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 04:24:47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006/11/02 04:24:46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006/11/02 04:24:45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006/11/02 04:24:44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006/11/02 04:24:44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006/11/02 03:41:49 | 000,200,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTAZL3.SYS – (HSFHWAZL)
DRV - [2006/11/02 03:36:50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)
DRV - [2006/11/02 03:36:43 | 002,028,032 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2006/11/02 03:30:54 | 000,117,760 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2006/11/02 03:30:53 | 000,167,936 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\b57nd60x.sys – (b57nd60x)
DRV - [2006/06/28 14:54:00 | 000,009,472 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\CPQBttn.sys – (HBtnKey)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…b&pf=laptop
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 80 9E 9E 4C 16 6E CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :0


[2010/05/25 18:21:44 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\mozilla\Extensions
[2010/05/25 18:21:44 | 000,000,000 | —D | M] – C:\Users\Your name\AppData\Roaming\mozilla\Extensions\[removed]

O1 HOSTS File: ([2010/06/01 23:13:38 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\ScriptCl.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll File not found
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &AIM Toolbar Search - C:\ProgramData\AIM Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O9 - Extra Button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…k.cab102118.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.gamehouse.com/games/insaniq/popcaploader.cab (PopCapLoader Object)
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} http://zone.msn.com/bingame/zpagames/ZPA_B…on.cab64162.cab (MSN Games – Backgammon)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Your name\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\Your name\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/06/05 17:43:13 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/06/05 17:38:34 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/06/05 17:38:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/06/05 17:37:38 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/06/05 17:37:38 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/06/05 17:37:37 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/06/05 17:37:37 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/06/02 23:48:51 | 000,000,000 | —D | C] – C:\Users\Your name\AppData\Roaming\Malwarebytes
[2010/06/02 23:47:11 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/06/02 23:46:43 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/06/02 23:46:41 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/06/02 23:46:38 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/01 23:22:00 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/06/01 23:21:44 | 000,000,000 | —D | C] – C:\Users\Your name\AppData\Local\temp
[2010/06/01 22:39:44 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/06/01 22:39:36 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/06/01 22:39:36 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/06/01 22:38:58 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/06/01 22:22:11 | 000,000,000 | —D | C] – C:\Qoobox
[2010/06/01 22:21:22 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/06/01 22:20:54 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/05/29 21:47:58 | 000,000,000 | —D | C] – C:\Users\Your name\Desktop\MIKES CAMERA
[2010/05/25 23:42:37 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010/05/25 22:47:22 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/05/25 18:21:43 | 000,000,000 | —D | C] – C:\Users\Your name\AppData\Roaming\Mozilla
[2010/05/25 18:12:22 | 024,184,872 | —- | C] (Lime Wire LLC) – C:\Users\Your name\LimeWireWin.exe
[2010/05/23 21:59:55 | 000,000,000 | —D | C] – C:\Users\Your name\Desktop\poster pics
[2010/05/22 11:43:56 | 000,000,000 | —D | C] – C:\Users\Your name\Desktop\Fixing the Comp

========== Files - Modified Within 30 Days ==========

[2010/06/06 13:45:50 | 000,003,296 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/06 13:45:50 | 000,003,296 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/06 13:43:43 | 000,000,400 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{F051533B-77B5-4F0B-B73F-C3C73C5E557E}.job
[2010/06/06 13:40:09 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/06 13:38:09 | 003,670,016 | -HS- | M] () – C:\Users\Your name\NTUSER.DAT
[2010/06/06 11:46:20 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/06 11:45:53 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/06 11:45:31 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/06 11:44:58 | 1064,755,200 | -HS- | M] () – C:\hiberfil.sys
[2010/06/06 11:43:05 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/06/06 11:42:05 | 000,524,288 | -HS- | M] () – C:\Users\Your name\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms
[2010/06/06 11:42:05 | 000,065,536 | -HS- | M] () – C:\Users\Your name\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf
[2010/06/06 11:41:24 | 002,941,924 | -H– | M] () – C:\Users\Your name\AppData\Local\IconCache.db
[2010/06/05 17:36:36 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/06/05 17:36:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/06/05 17:36:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/06/05 17:36:33 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/06/05 17:24:47 | 000,000,338 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForYour name.job
[2010/06/04 22:27:51 | 000,000,000 | —- | M] () – C:\Windows\System32\drivers\lvuvc.hs
[2010/06/02 23:47:25 | 000,000,818 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/01 23:14:06 | 000,000,215 | —- | M] () – C:\Windows\system.ini
[2010/06/01 23:13:38 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/06/01 21:42:17 | 000,062,976 | —- | M] () – C:\Users\Your name\Documents\LHS roster 2010.xls
[2010/05/29 22:46:30 | 000,769,132 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/05/29 22:46:30 | 000,650,720 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/05/29 22:46:30 | 000,122,562 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/05/29 22:09:34 | 000,027,136 | —- | M] () – C:\Users\Your name\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/25 23:42:32 | 153,738,642 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/05/25 18:18:00 | 000,001,708 | —- | M] () – C:\Users\Your name\Desktop\LimeWire 5.5.8.lnk
[2010/05/25 18:13:22 | 024,184,872 | —- | M] (Lime Wire LLC) – C:\Users\Your name\LimeWireWin.exe
[2010/05/23 19:56:13 | 000,000,191 | —- | M] () – C:\Users\Your name\Desktop\TV Listings - Find Local TV Shows and Movie Schedules - Listings Grid TVGuide.com.url
[2010/05/23 18:57:16 | 000,293,376 | —- | M] () – C:\Users\Your name\016bsggv.exe
[2010/05/21 23:27:31 | 000,030,036 | —- | M] () – C:\Users\Your name\Desktop\alg-singer-adam-lambert.jpg
[2010/05/20 22:54:14 | 000,025,088 | —- | M] () – C:\Users\Your name\Desktop\INFORMATION FOR SENIOR NIGHT PROGRAM.doc
[2010/05/19 20:49:48 | 000,027,136 | —- | M] () – C:\Users\Your name\Desktop\rough draft.doc
[2010/05/18 21:00:29 | 000,025,088 | —- | M] () – C:\Users\Your name\Desktop\Rules.doc
[2010/05/12 22:09:13 | 000,110,592 | —- | M] () – C:\Users\Your name\Desktop\Lowell High School Softball Apparel Graphics.doc
[2010/05/12 11:21:16 | 000,221,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/05/11 22:49:01 | 000,021,504 | —- | M] () – C:\Users\Your name\Desktop\anemia.doc
[2010/05/11 11:41:14 | 000,074,713 | —- | M] () – C:\Users\Your name\Desktop\TaxReturnSam2009.pdf
[2010/05/11 11:03:33 | 000,148,253 | —- | M] () – C:\Users\Your name\Desktop\TaxReturn 2009.pdf
[2010/05/10 21:53:21 | 000,273,408 | —- | M] () – C:\Users\Your name\Desktop\What is Anemia.doc
[2010/05/08 21:25:38 | 000,087,554 | —- | M] () – C:\Users\Your name\Desktop\Shelby TaxReturn.pdf
[2010/05/08 21:06:10 | 000,139,620 | —- | M] () – C:\Windows\hpoins15.dat
[2010/05/08 21:03:19 | 000,000,254 | —- | M] () – C:\Windows\win.ini

========== Files Created - No Company Name ==========

[2010/06/02 23:47:25 | 000,000,818 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/01 22:39:46 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/06/01 22:39:37 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/06/01 22:39:36 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/06/01 22:39:36 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/06/01 22:39:36 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/05/25 23:41:09 | 153,738,642 | —- | C] () – C:\Windows\MEMORY.DMP
[2010/05/25 18:18:00 | 000,001,708 | —- | C] () – C:\Users\Your name\Desktop\LimeWire 5.5.8.lnk
[2010/05/23 18:56:59 | 000,293,376 | —- | C] () – C:\Users\Your name\016bsggv.exe
[2010/05/21 23:28:20 | 000,030,036 | —- | C] () – C:\Users\Your name\Desktop\alg-singer-adam-lambert.jpg
[2010/05/20 22:54:13 | 000,025,088 | —- | C] () – C:\Users\Your name\Desktop\INFORMATION FOR SENIOR NIGHT PROGRAM.doc
[2010/05/18 21:00:29 | 000,025,088 | —- | C] () – C:\Users\Your name\Desktop\Rules.doc
[2010/05/14 13:06:42 | 000,000,338 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForYour name.job
[2010/05/13 21:25:55 | 000,027,136 | —- | C] () – C:\Users\Your name\Desktop\rough draft.doc
[2010/05/12 13:57:29 | 000,110,592 | —- | C] () – C:\Users\Your name\Desktop\Lowell High School Softball Apparel Graphics.doc
[2010/05/11 22:43:20 | 000,021,504 | —- | C] () – C:\Users\Your name\Desktop\anemia.doc
[2010/05/11 11:40:15 | 000,074,713 | —- | C] () – C:\Users\Your name\Desktop\TaxReturnSam2009.pdf
[2010/05/11 11:03:27 | 000,148,253 | —- | C] () – C:\Users\Your name\Desktop\TaxReturn 2009.pdf
[2010/05/10 19:59:49 | 000,273,408 | —- | C] () – C:\Users\Your name\Desktop\What is Anemia.doc
[2010/05/08 21:25:10 | 000,087,554 | —- | C] () – C:\Users\Your name\Desktop\Shelby TaxReturn.pdf
[2009/12/18 23:22:38 | 000,082,289 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2009/06/14 20:40:17 | 000,721,904 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2009/05/08 11:13:04 | 000,013,584 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2009/04/30 17:00:12 | 000,025,624 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2009/01/23 14:44:29 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/08/29 23:31:01 | 000,000,280 | —- | C] () – C:\Windows\System32\epoPGPsdk.dll.sig
[2008/08/08 12:13:59 | 000,000,021 | —- | C] () – C:\Windows\atid.ini
[2008/07/05 09:49:59 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2008/07/05 09:49:59 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2008/07/05 09:49:59 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2008/07/05 09:49:59 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2008/07/05 09:49:59 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2008/07/05 09:49:59 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2007/08/24 08:46:48 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1322.dll
[2007/08/24 08:28:04 | 000,249,856 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/28 16:11:30 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 06:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/09/25 03:02:34 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/25 03:02:34 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/03/09 06:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\Windows\System32\OUTLPERF.INI
[1913/08/01 10:18:54 | 000,056,832 | —- | C] () – C:\Windows\System32\iyvu9_32.dll
< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI