This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Do I have a Key Stroke Logger infection?

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I suspect that I might have a keystroke logger infecting my desktop. I recently had a couple fo episodes where emails were being sent from AOL email account. I learned of this when I began receiving many failed delivery notices.

These notices revealed many of the email addresses that were receiving this spam, and when I checked many of these were email addresses that I was familiar with, but which were old and no longer in my Windows Mail Address Book. HOwever they were still in the list of addresses ton which I had sent email that stays on the AOL Email Server.

When I logged into my email account through the IE8 browser, I could see in the Sent folder emails that I did not send. When I changed my AOL password, these stopped for a while, but then began agaion a few weeks later.

So, I think that either someone has hacked into my account of the AOL Server, or they have loaded a keystroke logger onto my system, from which they can garner my AOL email password. Of course, that gives me great concern since they might also garner other passwords I use like to my bank, etc.

I include a Hijack Log below. Could you please take a look at this and see if any keystroke logger shows up. I am having no other problems like hijacked browsers or trojan popups. The computer runs fine.

Thanks in advance,

RonCobb

============================

Log created by WinPatrol [FREE Edition] version 16.0.2009.1:16.0.2009.1
Scan saved at 5:14:43 PM, on 5/22/2010
Platform: Windows Vista SP2 Home Edition Service Pack 2 (Build 6002)
MSIE: Internet Explorer (7.00.6000.16386)
Boot mode: Normal

Running processes:
C:\PROGRAM FILES (X86)\Intel\INTEL MATRIX STORAGE MANAGER\IAAnotif.exe
C:\PROGRAM FILES (X86)\HEWLETT-PACKARD\HP ADVISOR\HPADVISOR.EXE
C:\PROGRAM FILES (X86)\Google\GOOGLETOOLBARNOTIFIER\GOOGLETOOLBARNOTIFIER.EXE
C:\PROGRAM FILES (X86)\URL ADDRESS BOOK\Urlbook.exe
C:\PROGRAM FILES (X86)\HEWLETT-PACKARD\HP ODOMETER\hpsysdrv.exe
C:\PROGRAM FILES (X86)\HP\DIGITAL IMAGING\bin\hpqtra08.exe
C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\Office\FINDFAST.EXE
C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\Office\OSA.EXE
C:\PROGRAM FILES (X86)\HEWLETT-PACKARD\TOUCHSMART\Media\TSMAgent.exe
C:\PROGRAM FILES (X86)\HEWLETT-PACKARD\TOUCHSMART\Media\Kernel\CLML\CLMLSvc.exe
C:\PROGRAM FILES (X86)\HP\HP SOFTWARE UPDATE\HPWUSCHD2.EXE
C:\PROGRAM FILES (X86)\Google\QUICK SEARCH BOX\GOOGLEQUICKSEARCHBOX.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\Avast4\ashDisp.exe
C:\PROGRAM FILES (X86)\BILLP STUDIOS\WINPATROL\WINPATROL.EXE
C:\PROGRAM FILES (X86)\ScanSoft\PAPERPORT\pptd40nt.exe
C:\PROGRAM FILES (X86)\HEWLETT-PACKARD\Media\DVD\DVDAgent.exe
C:\PROGRAM FILES (X86)\HEWLETT-PACKARD\Media\TV\TVAgent.exe
C:\PROGRAM FILES (X86)\Java\jre6\bin\jusched.exe
C:\PROGRAM FILES (X86)\HP\DIGITAL IMAGING\bin\hpqste08.exe
C:\PROGRAM FILES (X86)\HEWLETT-PACKARD\KBD\kbd.exe
C:\PROGRAM FILES (X86)\HP\DIGITAL IMAGING\bin\hpqbam08.exe
C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\firefox.exe
C:\PROGRAM FILES\AMERICAN SYSTEMS\PRINT SCREEN DELUXE\PRINTSCREENDELUXE.EXE
C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\Office\WINWORD.EXE
C:\PROGRAM FILES (X86)\BILLP STUDIOS\WINPATROL\WINPATROLEX.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [hpsysdrv]c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD]C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler]c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [UpdateP2GoShortCut]c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe c:\Program Files (x86)\CyberLink\Power2Go UpdateWithCreateOnce SOFTWARE\CyberLink\Power2Go\6.0
O4 - HKLM\..\Run: [UpdateLBPShortCut]c:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe c:\Program Files (x86)\CyberLink\LabelPrint UpdateWithCreateOnce Software\CyberLink\LabelPrint\2.5
O4 - HKLM\..\Run: [UpdatePDIRShortCut]c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe c:\Program Files (x86)\CyberLink\PowerDirector UpdateWithCreateOnce SOFTWARE\CyberLink\PowerDirector\7.0
O4 - HKLM\..\Run: [UpdatePSTShortCut]c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe UpdateWithCreateOnce Software\CyberLink\PowerStarter
O4 - HKLM\..\Run: [TSMAgent]c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart]c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
O4 - HKLM\..\Run: [HP Software Update]C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Google Quick Search Box]C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe /autorun
O4 - HKLM\..\Run: [avast!]C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WinPatrol [FREE Edition]]C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher]C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKLM\..\Run: [SSBkgdUpdate]C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD]C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch]C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [PPort11reminder]C:\Program Files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe -r C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
O4 - HKLM\..\Run: [DVDAgent]C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
O4 - HKLM\..\Run: [TVAgent]C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched]C:\Program Files (x86)\Java\jre6\bin\jusched.exe
O4 - HKCU\..\Run: [HPAdvisor]C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
O4 - HKCU\..\Run: [swg]C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Urlbook]C:\Program Files (x86)\URL Address Book\Urlbook.exe
O4 - HKU\..\Run: [hpsysdrv]c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
O4 - HKU\..\Run: [KBD]C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.exe
O4 - HKU\..\Run: [HP Health Check Scheduler]c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKU\..\Run: [UpdateP2GoShortCut]c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe c:\Program Files (x86)\CyberLink\Power2Go UpdateWithCreateOnce SOFTWARE\CyberLink\Power2Go\6.0
O4 - HKU\..\Run: [UpdateLBPShortCut]c:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe c:\Program Files (x86)\CyberLink\LabelPrint UpdateWithCreateOnce Software\CyberLink\LabelPrint\2.5
O4 - HKU\..\Run: [UpdatePDIRShortCut]c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe c:\Program Files (x86)\CyberLink\PowerDirector UpdateWithCreateOnce SOFTWARE\CyberLink\PowerDirector\7.0
O4 - HKU\..\Run: [UpdatePSTShortCut]c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe UpdateWithCreateOnce Software\CyberLink\PowerStarter
O4 - HKU\..\Run: [TSMAgent]c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
O4 - HKU\..\Run: [CLMLServer for HP TouchSmart]c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
O4 - HKU\..\Run: [HP Software Update]C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKU\..\Run: [Google Quick Search Box]C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe /autorun
O4 - HKU\..\Run: [avast!]C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - HKU\..\Run: [WinPatrol [FREE Edition]]C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKU\..\Run: [Adobe Reader Speed Launcher]C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKU\..\Run: [SSBkgdUpdate]C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKU\..\Run: [PaperPort PTD]C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKU\..\Run: [IndexSearch]C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKU\..\Run: [PPort11reminder]C:\Program Files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe -r C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
O4 - HKU\..\Run: [DVDAgent]C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
O4 - HKU\..\Run: [TVAgent]C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe
O4 - HKU\..\Run: [SunJavaUpdateSched]C:\Program Files (x86)\Java\jre6\bin\jusched.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk=C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Find Fast.lnk=C:\Program Files (x86)\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk=C:\Program Files (x86)\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: PictureMover.lnk=C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: URLBook - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files (x86)\URL Address Book\Urlbook.exe (HKCU)
O9 - Extra 'Tools' menuitem: URL Address Book - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files (x86)\URL Address Book\Urlbook.exe (HKCU)
O11 - Options group: [] -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/C/0…heckControl.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_17) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} (Java Plug-in 1.6.0_17) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_17) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O23 - Service: avast! iAVS4 Control Service - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe /service
O23 - Service: avast! Web Scanner - - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe /service
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Software Updater - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqcxs08 - Hewlett-Packard Co. - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
O23 - Service: HP CUE DeviceDiscovery Service - Hewlett-Packard Co. - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
O23 - Service: Intel® Matrix Storage Event Monitor - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
O23 - Service: Intuit Update Service - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Net Driver HPZ12 - Hewlett-Packard - C:\Windows\system32\HPZinw12.dll
O23 - Service: Norton Internet Security - - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe /s Norton Internet Security /m C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\diMaster.dll /prefetch:1
O23 - Service: Pml Driver HPZ12 - Hewlett-Packard - C:\Windows\system32\HPZipm12.dll
O23 - Service: TV Background Capture Service (TVBCS) - - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
O23 - Service: TV Task Scheduler (TVTS) - - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
O23 - Service: Windows Defender - - C:\Program Files (x86)\Windows Defender\mpsvc.dll
O23 - Service: Windows Media Player Network Sharing Service - - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe

— Additional WinPatrol Info —
Default Browser: Windows® Internet Explorer - Internet Explorer version 7.00.6000.16386
MSIE: Internet Explorer (7.00.6000.16386)
Firefox 3.6.3 installed in C:\Program Files (x86)\Mozilla Firefox.
2 IE Cookies in Folder: C:\Users\Ron Cobb\AppData\Roaming\Microsoft\Windows\Cookies\
0 Mozilla Cookies in Folder: C:\Users\Ron Cobb\AppData\Roaming\Mozilla\FireFox\Profiles\x4ausi12.default

WP00 - HKLM\CS1: BootExecute = autocheck autochk *
WP00 - HKLM\CCS: BootExecute = autocheck autochk *
WP00 - HKLM\CS3: BootExecute = autocheck autochk *
WP02 - HKLM\CCS: Command = C:\Windows\system32\cmd.exe


WP08 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix: Default = http://
WP08 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes: www = http://

WP31 - Scheduled Tasks: [SyncBack Ron Cobb User Backup.job]C:\Program Files (x86)\2BrightSparks\SyncBack\SyncBack.exe Never
WP31 - Scheduled Tasks: [PCDRScheduledMaintenance.job]C:\Program Files\PC-Doctor for Windows\pcdr5cuiw32.exe 01/29/2010 3:59 PM

WP16 - ActiveX: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} [DjVuCtl Class] C:\PROGRAM FILES (X86)\LIZARDTECH\LIZARDTECH DJVU CONTROL\DjVuCntl.dll 6.1.1.1574
WP16 - ActiveX: {17492023-C23A-453E-A040-C7C580BBF700} [Windows Genuine Advantage Validation Tool] C:\Windows\SysWOW64\LEGITCHECKCONTROL.DLL 1.9.0009.1
WP16 - ActiveX: {2933BF90-7B36-11D2-B20E-00C04F983E60} [XML DOM Document] C:\Windows\System32\msxml3.dll 8.100.5002.0
WP16 - ActiveX: {55136805-B2DE-11D1-B9F2-00A0C98BC547} [Shell Name Space] C:\Windows\SysWOW64\ieframe.dll 7.00.6000.16386
WP16 - ActiveX: {5B7524C8-2446-40E9-9474-94A779DBA224} [InstallShield Update Service Agent] C:\Windows\DOWNLOADED PROGRAM FILES\isusweb.dll 4, 10
WP16 - ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} [Shockwave Flash Object] C:\Windows\SysWOW64\Macromed\Flash\Flash10a.ocx 10,0,12,36
WP16 - ActiveX: {ED8C108E-4349-11D2-91A4-00C04F7969E8} [XML HTTP Request] C:\Windows\System32\msxml3.dll 8.100.5002.0
WP16 - ActiveX: {F6D90F16-9C73-11D3-B32E-00C04F990BB4} [XML HTTP] C:\Windows\System32\msxml3.dll 8.100.5002.0
WP16 - ActiveX: DFEAF541-F3E1-4c24-ACAC-99C30715084A [Microsoft Silverlight] C:\PROGRAM FILES (X86)\MICROSOFT SILVERLIGHT\3.0.40818.0\npctrl.dll 3.0.40818.0
WP16 - ActiveX: {05589fa1-c356-11ce-bf01-00aa0055595a} [ActiveMovieControl Object] C:\Windows\SysWOW64\wmpdxm.dll 11.0.6002.18065
WP16 - ActiveX: {0713E8A2-850A-101B-AFC0-4210102A8DA7} [Microsoft TreeView Control, version 5.0 (SP2)] C:\Windows\SysWOW64\comctl32.ocx 6.00.8105
WP16 - ActiveX: {0713E8D2-850A-101B-AFC0-4210102A8DA7} [Microsoft ProgressBar Control, version 5.0 (SP2)] C:\Windows\SysWOW64\comctl32.ocx 6.00.8105
WP16 - ActiveX: {6D2459CD-9AA2-48a1-A4FB-ABB8E87F4C0D} [AnswerWorks 5 API] C:\PROGRAM FILES (X86)\COMMON FILES\ANSWERWORKS 5.0\awApi5.dll 5, 0, 0, 9
WP16 - ActiveX: {52A2AAAE-085D-4187-97EA-8C30DB990436} [HHCtrl Object] C:\Windows\System32\hhctrl.ocx 6.0.6000.16386
WP16 - ActiveX: {54CE37E0-9834-41ae-9896-4DAB69DC022B} [Microsoft Terminal Services Client Control (redist)] C:\Windows\System32\mstscax.dll 6.0.6001.18000
WP16 - ActiveX: {58DA8D8A-9D6A-101B-AFC0-4210102A8DA7} [Microsoft ListView Control, version 5.0 (SP2)] C:\Windows\SysWOW64\comctl32.ocx 6.00.8105
WP16 - ActiveX: {58DA8D8F-9D6A-101B-AFC0-4210102A8DA7} [Microsoft ImageList Control, version 5.0 (SP2)] C:\Windows\SysWOW64\comctl32.ocx 6.00.8105
WP16 - ActiveX: {6B7E638F-850A-101B-AFC0-4210102A8DA7} [Microsoft StatusBar Control, version 5.0 (SP2)] C:\Windows\SysWOW64\comctl32.ocx 6.00.8105
WP16 - ActiveX: {6A6F4B83-45C5-4ca9-BDD9-0D81C12295E4} [Microsoft Terminal Services Client Control (redist)] C:\Windows\System32\mstscax.dll 6.0.6001.18000
WP16 - ActiveX: {8856F961-340A-11D0-A96B-00C04FD705A2} [Microsoft Web Browser] C:\Windows\SysWOW64\ieframe.dll 7.00.6000.16386
WP16 - ActiveX: {8BD21D50-EC42-11CE-9E0D-00AA006002F3} [Microsoft Forms 2.0 OptionButton] C:\Windows\SysWOW64\FM20.DLL 2.01
WP16 - ActiveX: {971127BB-259F-48c2-BD75-5F97A3331551} [Microsoft Terminal Services Client Control (redist)] C:\Windows\System32\mstscax.dll 6.0.6001.18000
WP16 - ActiveX: {AE24FDAE-03C6-11D1-8B76-0080C744F389} [Microsoft Scriptlet Component] C:\Windows\SysWOW64\mshtml.dll 7.00.6000.16386
WP16 - ActiveX: {CA8A9780-280D-11CF-A24D-444553540000} [Adobe PDF Reader] C:\PROGRAM FILES (X86)\COMMON FILES\Adobe\Acrobat\ActiveX\AcroPDF.dll
WP16 - ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} [Shockwave Flash Object] C:\Windows\SysWOW64\Macromed\Flash\Flash10a.ocx 10,0,12,36

WP32 - Hidden File: C:\bootmgr
WP32 - Hidden File: C:\ffastun.ffa
WP32 - Hidden File: C:\ffastun.ffl
WP32 - Hidden File: C:\ffastun.ffo
WP32 - Hidden File: C:\ffastun0.ffx
WP32 - Hidden File: C:\pagefile.sys
WP32 - Hidden File: C:\Windows\neoqaz2.dll
WP32 - Hidden File: C:\Windows\WindowsShell.Manifest
WP32 - Hidden File: C:\Windows\System32\drivers\103C_HP_CPC_NC829AA-ABA a6857c_YC_0Pavi_QMXU912_E92NAv6PrA2_49_IBenicia_SPEGATRON CORPORATION_V1.01_B5.37_T090223_WUH1_L409_M8182_J640_7Intel_8Core2 Quad Q8200_92.33_#_N10EC8168_Z_G808629C2_OHL-DT-ST DVD-RAM GH40L.MRK
WP32 - Hidden File: C:\Windows\System32\FFASTLOG.TXT
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\etilqs_6bRyYGsT8ggdsRXMbv5Q
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\etilqs_AppFpnoLhOT5b0zWPylb
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\etilqs_blkptaHTRldewAZMkU9J
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\etilqs_f1D4pknxX9fZdbCQhoUW
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\etilqs_k1uUah99k95PJdW5sYGX
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL0005.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL0006.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL0368.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL0449.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL0468.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL0474.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL0796.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL1039.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL1049.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL1256.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL1390.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL1452.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL1513.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL1516.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL1541.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL1871.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL1932.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL1964.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL2122.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL2167.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL2398.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL2476.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL2495.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL2522.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL2602.tmp
WP32 - Hidden File: C:\Users\Ron Cobb\AppData\Local\Temp\~WRL2661.tmp

WP33 - File Type .AVI: [Video Clip]C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:8 /Open %L
WP33 - File Type .BAT: [Windows Batch File]%1 %*
WP33 - File Type .CAB: [Cabinet File]C:\Windows\Explorer.exe /idlist,%I,%L
WP33 - File Type .CAT: [Security Catalog]C:\Windows\system32\rundll32.exe cryptext.dll,CryptExtOpenCAT %1
WP33 - File Type .CHM: [Compiled HTML Help file]C:\Windows\hh.exe %1
WP33 - File Type .COM: [MS-DOS Application]%1 %*
WP33 - File Type .CMD: [Windows Command Script]%1 %*
WP33 - File Type .DOC: [Microsoft Word Document]C:\Program Files (x86)\Microsoft Office\Office\Winword.exe /n
WP33 - File Type .EML: [Internet E-Mail Message]C:\Program Files (x86)\Windows Mail\WinMail.exe /eml:%1
WP33 - File Type .EXE: [Application]%1 %*
WP33 - File Type .INF: [Setup Information]C:\Windows\system32\NOTEPAD.EXE %1
WP33 - File Type .JS: [JScript Script File]C:\Windows\System32\WScript.exe %1 %*
WP33 - File Type .LOG: [Text Document]C:\Windows\system32\NOTEPAD.EXE %1
WP33 - File Type .MSI: [Windows Installer Package]C:\Windows\System32\msiexec.exe /i %1 %*
WP33 - File Type .MSG: [Outlook Item]C:\Program Files (x86)\Microsoft Office\Office\outlook.exe /f %1
WP33 - File Type .MID: [MIDI Sequence]C:\Program Files (x86)\Windows Media Player\wmplayer.exe /Open %L
WP33 - File Type .MP3: [MP3 Format Sound]C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:6 /Open %L
WP33 - File Type .PIF: [Shortcut to MS-DOS Program]%1 %*
WP33 - File Type .REG: [Registration Entries]regedit.exe %1
WP33 - File Type .RTF: [Rich Text Format]C:\Program Files (x86)\Microsoft Office\Office\Winword.exe /n
WP33 - File Type .SCR: [Screen Saver]%1 /S
WP33 - File Type .TXT: [Text Document]C:\Windows\system32\NOTEPAD.EXE %1
WP33 - File Type .URL: [Internet Shortcut]rundll32.exe ieframe.dll,OpenURL %l
WP33 - File Type .VBS: [VBScript Script File]C:\Windows\System32\WScript.exe %1 %*
WP33 - File Type .VBE: [VBScript Encoded File]C:\Windows\System32\WScript.exe %1 %*
WP33 - File Type .WSF: [Windows Script File]C:\Windows\System32\WScript.exe %1 %*
WP33 - File Type .WSH: [Windows Script Host Settings File]C:\Windows\System32\WScript.exe %1 %*
WP33 - File Type .XLS: [Microsoft Excel Worksheet]C:\Program Files (x86)\Microsoft Office\Office\excel.exe /e

Memory currently in use: 47%
Physical Memory Free: 4,194,303 KB
Paging File Free: 4,194,303 KB
Virtual Memory Free: 2,009,344 KB


–
End of file
Hi roncobb

:welcome:

I'm martix and I'll be glad to assist you and look over your PC problems.

Before we proceed please read carefully the following guidelines:

  • Malware removal process takes time so be patient and stick with the thread until I’ve given you the “All clean". Absence of symptoms does not mean your machine is clean!
  • Do not run any scans or install/uninstall any applications without being directed to do so.
  • Follow my instructions carefully and in the order they are posted.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing.
  • If you do not reply within 5 days after my last response the topic will be closed.
Now we can proceed. Please follow the instructions:

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


NEXT


Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt and Attach.txt report in your next reply



    I'll need you to include in your next reply:

    1. GMER log
    2. DDS log
gmer.txt file is very short, so I am positng it rather than attaching it.

Thanks,

Ron Cobb

gmer.txt
======================
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-23 21:12:50
Windows 6.0.6002 Service Pack 2
Running: gmer.exe


—- Files - GMER 1.0.15 —-

File C:\Users\Ron Cobb\AppData\Local\Microsoft\Windows Mail\Local Folders\Sent Items\6EBF73B0-00000769.eml 0 bytes

—- EOF - GMER 1.0.15 —-


============================

DDS.txt

======================


DDS (Ver_10-03-17.01) - NTFSX64
Run by [removed] at 21:15:19.81 on Sun 05/23/2010
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.8181.4666 [GMT -4:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\URL Address Book\Urlbook.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files (x86)\Microsoft Office\Office\OSA.EXE
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\Hewlett-Packard\KBD\kbd.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\splwow64.exe
C:\Program Files\American Systems\Print Screen Deluxe\PrintScreenDeluxe.exe
C:\Program Files\zabkat\xplorer2\xplorer2_64.exe
C:\Users\Ron Cobb\Desktop\gmer.exe
C:\Program Files (x86)\Microsoft Office\Office\FINDFAST.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Ron Cobb\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=92&bd=Pavilion&pf=cndt
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=92&bd=Pavilion&pf=cndt
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=92&bd=Pavilion&pf=cndt
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=92&bd=Pavilion&pf=cndt
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files (x86)\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files (x86)\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files (x86)\msn\toolbar\3.0.0541.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files (x86)\msn\toolbar\3.0.0541.0\msneshellx.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files (x86)\google\google toolbar\GoogleToolbar_32.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [HPAdvisor] c:\program files (x86)\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN
uRun: [swg] "c:\program files (x86)\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Urlbook] c:\program files (x86)\url address book\Urlbook.exe
mRun: [hpsysdrv] c:\program files (x86)\hewlett-packard\hp odometer\hpsysdrv.exe
mRun: [KBD] c:\program files (x86)\hewlett-packard\kbd\KbdStub.EXE
mRun: [HP Health Check Scheduler] c:\program files (x86)\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [UpdateP2GoShortCut] "c:\program files (x86)\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdateLBPShortCut] "c:\program files (x86)\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [UpdatePDIRShortCut] "c:\program files (x86)\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
mRun: [UpdatePSTShortCut] "c:\program files (x86)\cyberlink\cyberlink dvd suite deluxe\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\cyberlink dvd suite deluxe" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [TSMAgent] "c:\program files (x86)\hewlett-packard\touchsmart\media\TSMAgent.exe"
mRun: [CLMLServer for HP TouchSmart] "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\CLMLSvc.exe"
mRun: [HP Software Update] c:\program files (x86)\hp\hp software update\HPWuSchd2.exe
mRun: [Google Quick Search Box] "c:\program files (x86)\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [WinPatrol] "c:\program files (x86)\billp studios\winpatrol\winpatrol.exe" -expressboot
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SSBkgdUpdate] "c:\program files (x86)\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files (x86)\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files (x86)\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files (x86)\scansoft\paperport\ereg\ereg.exe" -r "c:\programdata\scansoft\paperport\11\config\ereg\Ereg.ini
mRun: [DVDAgent] "c:\program files (x86)\hewlett-packard\media\dvd\DVDAgent.exe"
mRun: [TVAgent] "c:\program files (x86)\hewlett-packard\media\tv\TVAgent.exe"
mRun: [SunJavaUpdateSched] "c:\program files (x86)\java\jre6\bin\jusched.exe"
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\micros~2.lnk - c:\program files (x86)\microsoft office\office\FINDFAST.EXE
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\office~1.lnk - c:\program files (x86)\microsoft office\office\OSA.EXE
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\pictur~1.lnk - c:\program files (x86)\picturemover\bin\PictureMover.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Google Sidewiki… - c:\program files (x86)\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: intuit.com\ttlc
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files (x86)\google\google toolbar\GoogleToolbar_64.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg64.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files (x86)\google\google toolbar\GoogleToolbar_64.dll
TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun-x64: [Persistence] c:\windows\system32\igfxpers.exe
mRun-x64: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
mRun-x64: [IAAnotif] "c:\program files (x86)\intel\intel matrix storage manager\iaanotif.exe"
IE-X64: {10954C80-4F0F-11d3-B17C-00C0DFE39736} - c:\program files (x86)\url address book\Urlbook.exe

================= FIREFOX ===================

FF - ProfilePath - c:\users\roncob~1\appdata\roaming\mozilla\firefox\profiles\x4ausi12.default\
FF - component: c:\users\ron cobb\appdata\roaming\mozilla\firefox\profiles\x4ausi12.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files (x86)\mozilla firefox\plugins\npdjvu.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-4-11 89680]
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/06/07 19:05:55];c:\program files (x86)\hewlett-packard\media\dvd\000.fcl [2008-11-28 146928]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-4-11 22096]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-4-11 65616]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-4-11 138680]
R2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files (x86)\hewlett-packard\media\tv\kernel\tv\TVCapSvc.exe [2009-4-22 296320]
R2 TVSched;TV Task Scheduler (TVTS);c:\program files (x86)\hewlett-packard\media\tv\kernel\tv\TVSched.exe [2009-4-22 116104]
S2 Norton Internet Security;Norton Internet Security;"c:\program files (x86)\norton internet security\engine\16.0.0.125\ccsvchst.exe" /s "norton internet security" /m "c:\program files (x86)\norton internet security\engine\16.0.0.125\dimaster.dll" /prefetch:1 –> c:\program files (x86)\norton internet security\engine\16.0.0.125\ccSvcHst.exe [?]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-4-11 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-4-11 352920]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-9-21 89920]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
S3 PCD5SRVC{8AAF211B-043E02A9-05040000};PCD5SRVC{8AAF211B-043E02A9-05040000} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\pc-doc~1\PCD5SRVC_x64.pkms [2008-11-4 28144]
S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-20 19968]

=============== Created Last 30 ================


==================== Find3M ====================

2010-05-12 15:21:16 270208 ——w- c:\windows\system32\MpSigStub.exe
2009-11-13 04:14:12 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-13 04:14:12 51200 —-a-w- c:\windows\inf\infpub.dat
2009-11-13 04:14:12 143360 —-a-w- c:\windows\inf\infstrng.dat
2009-11-13 04:14:12 143360 —-a-w- c:\windows\inf\infstor.dat
2009-04-20 23:12:50 50688 —-a-w- c:\program files (x86)\ATF-Cleaner.exe
2008-01-21 03:21:59 174 –sha-w- c:\program files\desktop.ini
2008-01-21 03:21:59 174 –sha-w- c:\program files (x86)\desktop.ini
2006-11-02 15:14:56 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 15:14:56 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 15:14:56 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 15:14:56 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2007-12-03 20:53:37 108 –sha-r- c:\windows\neoqaz2.dll
2009-03-07 19:09:39 8192 –sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 21:15:32.86 ===============


Attach.txt

========================================


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 3/19/2009 6:46:36 PM
System Uptime: 5/18/2010 3:34:55 PM (126 hours ago)

Motherboard: PEGATRON CORPORATION | | Benicia
Processor: Intel® Core™2 Quad CPU Q8200 @ 2.33GHz | CPU 1 | 2333/1333mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 583 GiB total, 448.093 GiB free.
D: is FIXED (NTFS) - 13 GiB total, 1.805 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (NTFS) - 149 GiB total, 94.508 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP422: 4/10/2010 8:16:07 AM - Restore Operation
RP423: 4/11/2010 12:43:12 AM - Scheduled Checkpoint
RP424: 4/11/2010 4:54:38 PM - Installed TurboTax 2009 wrapper
RP425: 4/11/2010 4:55:03 PM - Installed TurboTax 2009 WinPerReleaseEngine
RP426: 4/11/2010 4:56:10 PM - Installed TurboTax 2009 WinPerFedFormset
RP427: 4/11/2010 4:56:57 PM - Installed TurboTax 2009 WinPerTaxSupport
RP428: 4/11/2010 5:02:17 PM - Installed TurboTax 2009 wgaiper
RP429: 4/13/2010 1:40:05 AM - Windows Update
RP430: 4/13/2010 3:42:54 PM - Scheduled Checkpoint
RP431: 4/14/2010 4:50:44 AM - Scheduled Checkpoint
RP432: 4/15/2010 1:35:23 AM - Scheduled Checkpoint
RP433: 4/16/2010 1:40:03 AM - Windows Update
RP434: 4/18/2010 3:56:23 PM - Scheduled Checkpoint
RP435: 4/18/2010 9:12:08 PM - Restore Operation
RP436: 4/19/2010 2:29:03 AM - Windows Update
RP437: 4/20/2010 2:29:21 AM - Windows Update
RP438: 4/22/2010 12:58:16 AM - Scheduled Checkpoint
RP439: 4/23/2010 1:53:40 AM - Windows Update
RP440: 4/23/2010 3:13:29 PM - Scheduled Checkpoint
RP441: 4/25/2010 8:32:23 PM - Scheduled Checkpoint
RP442: 4/27/2010 1:53:03 AM - Windows Update
RP443: 4/27/2010 9:18:53 PM - Scheduled Checkpoint
RP444: 5/2/2010 8:38:20 PM - Windows Update
RP445: 5/4/2010 2:27:04 AM - Windows Update
RP446: 5/5/2010 - Scheduled Checkpoint
RP447: 5/6/2010 11:16:25 AM - Scheduled Checkpoint
RP448: 5/7/2010 2:27:03 AM - Windows Update
RP449: 5/8/2010 10:52:11 PM - Scheduled Checkpoint
RP450: 5/10/2010 4:46:40 PM - Scheduled Checkpoint
RP451: 5/11/2010 2:27:05 AM - Windows Update
RP452: 5/11/2010 5:07:06 PM - Scheduled Checkpoint
RP453: 5/14/2010 2:27:03 AM - Windows Update
RP455: 5/14/2010 10:59:55 AM - Paint.NET v3.5.5
RP456: 5/15/2010 10:25:32 AM - Scheduled Checkpoint
RP457: 5/18/2010 2:27:03 AM - Windows Update
RP458: 5/18/2010 5:13:21 PM - Scheduled Checkpoint
RP459: 5/20/2010 8:39:40 PM - Scheduled Checkpoint
RP460: 5/21/2010 2:18:08 AM - Windows Update
RP461: 5/23/2010 10:34:54 AM - Scheduled Checkpoint

==== Installed Programs ======================


6200
6200_Help
6200Trb
Acrobat.com
ActiveCheck component for HP Active Support Library
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.1
Aide PDF to DXF Converter 9.5
AIO_CDB_ProductContext
AIO_CDB_Software
AIO_Scan
AnswerWorks 5.0 English Runtime
Applian FLV Player
Argali White & Yellow
avast! Antivirus
BufferChm
Compatibility Pack for the 2007 Office system
Copy
CustomerResearchQFolder
CyberLink DVD Suite Deluxe
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DirectX for Managed Code Update (Summer 2004)
DocProc
DocProcQFolder
Enhanced Multimedia Keyboard Solution
eSupportQFolder
Fax
GnuWin32: Wget-1.11.4-1
Google Toolbar for Internet Explorer
GPL Ghostscript Lite 8.64
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Demo
HP MediaSmart DVD
HP MediaSmart Music/Photo/Video
HP MediaSmart TV
HP Odometer
HP Photosmart Essential
HP Picasso Media Center Add-In
HP Product Assistant
HP Recovery Manager RSS
HP Support Information
HP Total Care Advisor
HP Total Care Setup
HP Update
HPAsset component for HP Active Support Library
HPProductAssistant
HPSSupply
Java™ 6 Update 17
Juno Preloader
LabelPrint
LightScribe System Software
Lizardtech DjVu Control
MarketResearch
Microsoft Live Search Toolbar
Microsoft Office 97, Professional Edition
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Works
Mozilla Firefox (3.6.3)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee Reveal
My HP Games
NetZero Preloader
NoteTab Light 6 (Remove only)
PictureMover
Power2Go
PowerDirector
Print Screen Deluxe
Python 2.6 pywin32-212
Python 2.6.1
Quicken 2009
Realtek High Definition Audio Driver
RootsMagic [removed]
Scan
ScanSoft PaperPort 11
SolutionCenter
sp43204
Status
SyncBack
Toolbox
TrayApp
TurboTax 2008
TurboTax 2008 wgaiper
TurboTax 2008 WinPerFedFormset
TurboTax 2008 WinPerProgramHelp
TurboTax 2008 WinPerReleaseEngine
TurboTax 2008 WinPerTaxSupport
TurboTax 2008 WinPerUserEducation
TurboTax 2008 wrapper
TurboTax 2009
TurboTax 2009 wgaiper
TurboTax 2009 WinPerFedFormset
TurboTax 2009 WinPerReleaseEngine
TurboTax 2009 WinPerTaxSupport
TurboTax 2009 wrapper
UnloadSupport
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
WebReg
WinPatrol 2009
WinRAR archiver
xplorer² professional

==== Event Viewer Messages From Past Week ========

5/18/2010 3:37:14 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SRTSP SRTSPX
5/18/2010 3:37:14 PM, Error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting.
5/18/2010 3:36:55 PM, Error: Service Control Manager [7000] - The Norton Internet Security service failed to start due to the following error: The system cannot find the path specified.
5/18/2010 3:35:11 PM, Error: EventLog [6008] - The previous system shutdown at 9:37:52 AM on 5/18/2010 was unexpected.

==== End Of File ===========================
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
OTL ran to completion.
log files below.

Thanks,

Ron Cobb

================================

OTL logfile created on: 5/25/2010 7:29:41 AM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Users\Ron Cobb\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 5.00 Gb Available Physical Memory | 58.00% Memory free
16.00 Gb Paging File | 13.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 583.32 Gb Total Space | 448.04 Gb Free Space | 76.81% Space Free | Partition Type: NTFS
Drive D: | 12.85 Gb Total Space | 1.81 Gb Free Space | 14.05% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 149.05 Gb Total Space | 94.51 Gb Free Space | 63.41% Space Free | Partition Type: NTFS

Computer Name: RONCOBB-PC
Current User Name: Ron Cobb
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Ron Cobb\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Java\jre6\bin\jp2launcher.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Java\jre6\bin\java.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
PRC - C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\American Systems\Print Screen Deluxe\PrintScreenDeluxe.exe (American Systems)
PRC - C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
PRC - C:\Program Files (x86)\URL Address Book\Urlbook.exe ()
PRC - C:\Program Files (x86)\Microsoft Office\Office\FINDFAST.EXE ()
PRC - C:\Program Files (x86)\Microsoft Office\Office\OSA.EXE ()


========== Modules (SafeList) ==========

MOD - C:\Users\Ron Cobb\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV:64bit: - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV:64bit: - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV:64bit: - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV:64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (IntuitUpdateService) – C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (TVCapSvc) TV Background Capture Service (TVBCS) – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
SRV - (TVSched) TV Task Scheduler (TVTS) – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2006/11/02 09:34:14 | 000,000,000 | —D | M]
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) – C:\Windows\SysWOW64\wbem\vss.mof ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (ALWIL Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\DRIVERS\aswMonFlt.sys (ALWIL Software)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (ALWIL Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr.sys (ALWIL Software)
DRV:64bit: - (PCD5SRVC{8AAF211B-043E02A9-05040000}) – C:\Program Files\PC-Doctor for Windows\pcd5srvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (igfx) – C:\Windows\SysNative\DRIVERS\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iastor.sys (Intel Corporation)
DRV:64bit: - (athr) – C:\Windows\SysNative\DRIVERS\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation )
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (CyberLink Corp.)
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/04/04 13:39:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/04/10 08:17:52 | 000,000,000 | —D | M]

[2009/04/14 15:53:45 | 000,000,000 | —D | M] – C:\Users\Ron Cobb\AppData\Roaming\Mozilla\Extensions
[2010/05/18 23:08:30 | 000,000,000 | —D | M] – C:\Users\Ron Cobb\AppData\Roaming\Mozilla\Firefox\Profiles\x4ausi12.default\extensions
[2010/05/11 11:05:12 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Ron Cobb\AppData\Roaming\Mozilla\Firefox\Profiles\x4ausi12.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/05 12:16:55 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\Ron Cobb\AppData\Roaming\Mozilla\Firefox\Profiles\x4ausi12.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/09/15 08:33:06 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\Ron Cobb\AppData\Roaming\Mozilla\Firefox\Profiles\x4ausi12.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}(155)
[2010/04/10 07:48:27 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2007/02/04 23:02:56 | 001,642,496 | —- | M] (LizardTech) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdjvu.dll
[2009/06/22 11:10:58 | 000,677,152 | —- | M] (Medical Informatics Engineering, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npzzatif.dll

O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg64.dll (Google Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DVDAgent] C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.exe (Microsoft)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort11reminder] C:\Program Files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [TSMAgent] c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TVAgent] C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] c:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Urlbook] C:\Program Files (x86)\URL Address Book\Urlbook.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Ron Cobb\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Ron Cobb\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2008/01/20 23:06:38 | 000,000,000 | —D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll (Microsoft Corporation)
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll (Microsoft Corporation)
NetSvcs: Ias - C:\Windows\SysWOW64\ias [2008/01/20 23:08:35 | 000,000,000 | —D | M]
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)

========== Files/Folders - Created Within 30 Days ==========

[2010/05/25 07:24:58 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Users\Ron Cobb\Desktop\OTL.exe
[2010/05/07 17:16:06 | 000,000,000 | —D | C] – C:\Users\Ron Cobb\Documents\Address Book Copy in HTML

========== Files - Modified Within 30 Days ==========

[2010/05/25 07:27:59 | 004,456,448 | -HS- | M] () – C:\Users\Ron Cobb\ntuser.dat
[2010/05/25 07:24:59 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Ron Cobb\Desktop\OTL.exe
[2010/05/25 05:35:13 | 000,003,744 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/25 05:35:13 | 000,003,744 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/24 14:00:43 | 000,000,000 | —- | M] () – C:\Users\Ron Cobb\Documents\Nuance Image Printer Writer Port
[2010/05/23 09:35:43 | 000,113,763 | —- | M] () – C:\Users\Ron Cobb\Documents\eBay Stolen Property Program.pdf
[2010/05/18 15:41:45 | 000,690,960 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/05/18 15:41:45 | 000,595,446 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/05/18 15:41:45 | 000,101,144 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/05/18 15:35:22 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/05/18 15:35:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/05/14 11:00:44 | 000,000,936 | —- | M] () – C:\Users\Public\Desktop\Paint.NET.lnk
[2010/05/13 09:50:57 | 000,044,032 | —- | M] () – C:\Users\Ron Cobb\Documents\JACKSON JERSEY ARTICLE.wps
[2010/05/12 15:40:16 | 002,701,824 | —- | M] () – C:\Users\Ron Cobb\Documents\Brochure - one page.doc
[2010/05/10 08:35:43 | 000,033,280 | —- | M] () – C:\Users\Ron Cobb\Documents\Reliance Yacht Management Captains contact info.doc
[2010/04/28 23:12:46 | 000,524,288 | -HS- | M] () – C:\Users\Ron Cobb\ntuser.dat{cb884f17-4a6b-11df-9a0b-00248c4a9fe8}.TMContainer00000000000000000001.regtrans-ms
[2010/04/28 23:12:46 | 000,065,536 | -HS- | M] () – C:\Users\Ron Cobb\ntuser.dat{cb884f17-4a6b-11df-9a0b-00248c4a9fe8}.TM.blf
[2010/04/27 13:54:17 | 002,788,645 | -H– | M] () – C:\Users\Ron Cobb\AppData\Local\IconCache.db

========== Files Created - No Company Name ==========

[2010/05/23 09:35:42 | 000,113,763 | —- | C] () – C:\Users\Ron Cobb\Documents\eBay Stolen Property Program.pdf
[2010/05/13 09:50:57 | 000,044,032 | —- | C] () – C:\Users\Ron Cobb\Documents\JACKSON JERSEY ARTICLE.wps
[2010/05/12 15:40:14 | 002,701,824 | —- | C] () – C:\Users\Ron Cobb\Documents\Brochure - one page.doc
[2009/09/21 09:48:29 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/09/21 09:47:50 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/05/02 15:23:23 | 000,001,117 | —- | C] () – C:\Windows\PrintScreenDeluxe.INI
[2009/04/20 22:44:01 | 000,000,233 | —- | C] () – C:\Windows\Brpfx04a.ini
[2009/04/20 22:44:01 | 000,000,093 | —- | C] () – C:\Windows\brpcfx.ini
[2009/04/20 22:41:55 | 000,000,009 | —- | C] () – C:\Windows\Brfaxrx.ini
[2009/04/20 22:41:54 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2009/04/20 22:40:41 | 000,031,567 | —- | C] () – C:\Windows\maxlink.ini
[2009/04/14 13:07:26 | 000,000,171 | —- | C] () – C:\Windows\QUICKEN.INI
[2009/04/14 13:01:32 | 000,000,611 | —- | C] () – C:\Windows\ODBC.INI
[2009/04/14 13:01:32 | 000,000,022 | —- | C] () – C:\Windows\exchng.ini
[2009/04/13 19:55:57 | 000,005,614 | —- | C] () – C:\Windows\unpsd.ini
[2009/04/13 19:36:31 | 000,176,235 | —- | C] () – C:\Windows\SysWow64\Primomonnt.dll
[2009/04/13 19:36:30 | 000,000,129 | —- | C] () – C:\Windows\primopdf.ini
[2009/03/07 15:18:09 | 000,354,816 | —- | C] () – C:\Windows\SysWow64\pythoncom26.dll
[2009/03/07 15:18:09 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\pywintypes26.dll
[2008/01/20 22:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2007/12/03 16:53:37 | 000,000,108 | RHS- | C] () – C:\Windows\neoqaz2.dll
[1997/08/01 03:00:00 | 000,094,208 | —- | C] () – C:\Windows\SysWow64\MSENCODE.DLL
[1997/08/01 03:00:00 | 000,031,232 | —- | C] () – C:\Windows\SysWow64\XLREC.DLL
[1997/08/01 03:00:00 | 000,025,600 | —- | C] () – C:\Windows\SysWow64\RECNCL.DLL
[1997/08/01 03:00:00 | 000,022,016 | —- | C] () – C:\Windows\SysWow64\ODBCSTF.DLL
[1997/08/01 03:00:00 | 000,022,016 | —- | C] () – C:\Windows\SysWow64\DOCOBJ.DLL
[1997/08/01 03:00:00 | 000,012,288 | —- | C] () – C:\Windows\SysWow64\HLINKPRX.DLL

========== LOP Check ==========

[2010/04/10 16:59:16 | 000,000,000 | —D | M] – C:\Users\Ron Cobb\AppData\Roaming\Argali
[2009/05/25 15:15:05 | 000,000,000 | —D | M] – C:\Users\Ron Cobb\AppData\Roaming\Bullzip
[2009/07/15 15:23:45 | 000,000,000 | —D | M] – C:\Users\Ron Cobb\AppData\Roaming\Image Zone Express
[2009/06/19 18:09:16 | 000,000,000 | —D | M] – C:\Users\Ron Cobb\AppData\Roaming\NoteTab Light
[2009/04/11 13:23:47 | 000,000,000 | —D | M] – C:\Users\Ron Cobb\AppData\Roaming\PictureMover
[2009/05/20 14:42:53 | 000,000,000 | —D | M] – C:\Users\Ron Cobb\AppData\Roaming\Printer Info Cache
[2010/01/06 12:34:28 | 000,000,000 | —D | M] – C:\Users\Ron Cobb\AppData\Roaming\RootsMagic
[2009/04/20 18:09:46 | 000,000,000 | —D | M] – C:\Users\Ron Cobb\AppData\Roaming\ScanSoft
[2009/06/07 19:04:04 | 000,000,000 | —D | M] – C:\Users\Ron Cobb\AppData\Roaming\WinBatch
[2009/04/11 13:59:35 | 000,000,000 | —D | M] – C:\Users\Ron Cobb\AppData\Roaming\WinPatrol
[2010/01/30 14:01:28 | 000,000,456 | —- | M] () – C:\Windows\Tasks\PCDRScheduledMaintenance.job
[2010/04/28 23:12:47 | 000,029,360 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2009/11/02 19:54:43 | 000,000,480 | —- | M] () – C:\Windows\Tasks\SyncBack Ron Cobb User Backup.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/01/20 22:46:51 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008/01/20 22:46:51 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/01/20 22:46:50 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2009/04/11 03:15:00 | 000,020,952 | —- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 07:16:48 | 000,014,848 | —- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2007/05/18 01:34:04 | 000,007,216 | —- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 – C:\Program Files (x86)\Cyberlink\PowerDirector\EventLog.dll

< MD5 for: IASTOR.SYS >
[2008/11/03 20:56:40 | 000,327,192 | —- | M] (Intel Corporation) MD5=37769C28E1C6489C56E41DB7A32D58C5 – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008/11/03 14:10:08 | 000,406,040 | —- | M] (Intel Corporation) MD5=5979854E6FDA990107E3170327022117 – C:\hp\DRIVERS\Intel_Storage\IaStor.sys
[2008/11/03 21:10:08 | 000,406,040 | —- | M] (Intel Corporation) MD5=5979854E6FDA990107E3170327022117 – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys

< MD5 for: IASTORV.SYS >
[2008/01/20 22:46:59 | 000,290,872 | —- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2008/01/20 22:51:03 | 000,716,800 | —- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009/04/11 03:11:16 | 000,717,312 | —- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008/01/20 22:48:28 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2008/01/20 22:46:54 | 000,054,328 | —- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/20 22:50:28 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008/01/20 22:49:49 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009/04/11 03:11:23 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

========== Alternate Data Streams ==========

@Alternate Data Stream - 108 bytes -> C:\Windows:
< End of report >

===================================================

OTL Extras logfile created on: 5/25/2010 7:29:41 AM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Users\Ron Cobb\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 5.00 Gb Available Physical Memory | 58.00% Memory free
16.00 Gb Paging File | 13.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 583.32 Gb Total Space | 448.04 Gb Free Space | 76.81% Space Free | Partition Type: NTFS
Drive D: | 12.85 Gb Total Space | 1.81 Gb Free Space | 14.05% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 149.05 Gb Total Space | 94.51 Gb Free Space | 63.41% Space Free | Partition Type: NTFS

Computer Name: RONCOBB-PC
Current User Name: Ron Cobb
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [open_x2] – "C:\Program Files (x86)\zabkat\xplorer2\xplorer2_uc.exe" /1 /M /T "%1" (ZabKat)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [open_x2] – "C:\Program Files (x86)\zabkat\xplorer2\xplorer2_uc.exe" /1 /M /T "%1" (ZabKat)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 5C 4E C9 1F C6 3A CA 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{C91AB5D3-B212-4195-8E07-30E45F32837F}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\common files\intuit\update service\intuitupdateservice.exe |
"{D3896B25-B90A-4918-A851-5C60D7A69150}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\common files\intuit\update service\intuitupdater.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{07C9A38C-6D2C-4A9E-AFEC-05BA7AFF220F}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{0F0415EB-824C-4D02-AB0F-D1C9BC1EB2BA}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe |
"{13B114AA-F9AA-4F3A-9C67-1272898BA225}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe |
"{1686E311-E077-424A-B716-97BAF3B8C00A}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
"{1BE78C6D-2B83-4E64-A004-AD13AE8DB775}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{270E49F8-1272-4894-99F9-F0CFBFD65E77}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{3F13A99B-4F9E-4237-BDB8-09ABB82175CF}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\tv\qpservice.exe |
"{7C9AB438-4AA0-4610-9E65-B4B3D63E0A93}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{7D06D4FA-3E23-416C-A066-15421E4D97B1}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{8025A16A-AF24-456C-9228-9F60BD02B520}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{80869F60-24DD-4C87-8976-64DF894F59D3}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{83D1968F-2561-4195-96DF-0E2D14B6EB65}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe |
"{A963AD5A-BC0B-4128-BAAA-BA734DDA3777}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe |
"{B544FFA3-F6A6-4500-A4AA-172B3B7CC00D}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe |
"{B7F6DD27-44AF-4C78-8EC2-AA35973638FB}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe |
"{B9ED8DB8-B1D2-4B25-AABD-F59CF8F7DDB6}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{E515C584-ABF0-4EF5-AE98-000DB16B03B8}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\tv\qpservice.exe |
"{EB99E355-E719-4A05-8DA2-D76CE66092D8}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe |
"{F50A2073-F124-4417-BB9E-E181B8E6E0BB}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\tv\qp.exe |
"{F7508860-A47B-4CC0-A625-9921EABDDF12}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{F9B122C0-D0D5-45BE-9C2D-C2CC777E855A}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe |
"{FDEC0ADA-2E09-459A-9099-81762B858E11}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\tv\qp.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{17E02F38-FF2D-4c3d-83DF-ECE2A1D20A5E}" = AIO_CDB_ToolboxIni64
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{4FFA2088-8317-3B14-93CD-4C699DB37843}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{78F697ED-EC97-4D8D-881D-838984EA9855}" = 64 Bit HP CIO Components Installer
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D16193A3-921A-4134-B381-597C8F4B8EBD}" = PaperPort Image Printer
"{F0E2B312-D7FD-4349-A9B6-E90B36DB1BD1}" = Paint.NET v3.5.5
"{F1568AA6-5982-4AFB-A871-C68E4328BC3B}" = HP MediaSmart SmartMenu
"Bullzip PDF Printer_is1" = Bullzip PDF Printer 6.0.0.865
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"xplorer2p64" = xplorer² professional 64 bit

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{0295F89F-F698-4101-9A7D-49F407EC2D82}" = HP Active Support Library
"{03BF5CB1-B72E-4CA6-A278-F65680F05420}" = HP Picasso Media Center Add-In
"{049D96D7-E082-4FB5-BF64-CD3460E6877C}_is1" = RootsMagic [removed]
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = Lizardtech DjVu Control
"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1896E712-2B3D-45eb-BCE9-542742A51032}" = PictureMover
"{1CC069FA-1A86-402E-9787-3F04E652C67A}" = HP Support Information
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 17
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{2B14A44F-5815-4136-9ECF-B56E928CEC0F}" = 6200
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZero Preloader
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{374256A0-EAA2-012B-AD60-000000000000}" = TurboTax 2009 wgaiper
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{39CB30DB-27F8-4dd4-A294-CB4AE3B584FD}" = Copy
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{47F36D92-E58E-456D-B73C-3382737E4C42}" = HP Update
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4FAB5122-775E-4418-B8D9-E2873BC93570}" = Microsoft Live Search Toolbar
"{6423EF83-6E1D-4D22-A36F-689CD19FD4D2}" = Juno Preloader
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{68AB3A70-25E1-4D41-BDFF-7ED20C07D623}" = 6200Trb
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{7985F97F-7363-4A1E-80B9-50C4F0E8D19E}" = 6200_Help
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95A747E0-DF19-46CB-A622-20A0107201BD}" = HP Total Care Setup
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{97ABD26A-3249-46CB-B2E2-F66E64B2E480}" = HP Demo
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9CC89170-000B-457D-91F1-53691F85B223}" = Python 2.6.1
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}" = HP Recovery Manager RSS
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B6C89654-A6A2-477C-873B-724EC1C56407}" = ScanSoft PaperPort 11
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CDEFD989-469E-421D-A8B1-EC7AB25C8CB2}" = TurboTax 2008 wgaiper
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D722CF4B-4B06-BF11-FDEA-BD1B319FEA57}" = muvee Reveal
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E1591139-8B44-411B-A81B-D35F83A0565A}" = HP Customer Experience Enhancements
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ED2A3C11-3EA8-4380-B59C-F2C1832731B0}" = Quicken 2009
"{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Aide PDF to DXF Converter_is1" = Aide PDF to DXF Converter 9.5
"Applian FLV Player2.0.24" = Applian FLV Player
"avast!" = avast! Antivirus
"GPL Ghostscript Lite_is1" = GPL Ghostscript Lite 8.64
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"NoteTab Light 6_is1" = NoteTab Light 6 (Remove only)
"Office8.0" = Microsoft Office 97, Professional Edition
"PrintScreenDeluxe" = Print Screen Deluxe
"pywin32-py2.6" = Python 2.6 pywin32-212
"sp43204" = sp43204
"ST5UNST #1" = Argali White & Yellow
"SyncBack_is1" = SyncBack
"TurboTax 2008" = TurboTax 2008
"TurboTax 2009" = TurboTax 2009
"Wget-1.11.4-1_is1" = GnuWin32: Wget-1.11.4-1
"WildTangent hp Master Uninstall" = My HP Games
"WinPatrol" = WinPatrol 2009
"WinRAR archiver" = WinRAR archiver
"xplorer2p" = xplorer² professional

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 11/28/2009 6:57:22 PM | Computer Name = RonCobb-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\SysWOW64\ole32.dll failed, 0000A413.

Error - 11/28/2009 6:57:28 PM | Computer Name = RonCobb-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\System32\davclnt.dll failed, 0000A413.

Error - 11/28/2009 6:57:28 PM | Computer Name = RonCobb-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\System32\crypt32.dll failed, 0000A413.

Error - 11/28/2009 6:57:28 PM | Computer Name = RonCobb-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\System32\msasn1.dll failed, 0000A413.

Error - 11/28/2009 6:57:28 PM | Computer Name = RonCobb-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\System32\cscapi.dll failed, 0000A413.

Error - 11/28/2009 6:57:29 PM | Computer Name = RonCobb-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\Ron Cobb\Documents\Ty Cobb Collection\Al Stump\Draft 4.doc failed, 0000A413.


Error - 11/28/2009 6:57:29 PM | Computer Name = RonCobb-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\System32\wbem\wbemcons.dll failed, 0000A413.

Error - 3/11/2010 11:24:39 AM | Computer Name = RonCobb-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\Ron Cobb\AppData\Local\Adobe\Updater6\Install\reader9rdr-en_US\AdbeRdr930_en_US.msi
failed, 00000005.

Error - 3/14/2010 10:07:22 AM | Computer Name = RonCobb-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\Ron Cobb\AppData\Roaming\Hewlett-Packard\HPAdvisor\HPAdvisorToDo.mdb failed,
00000005.

Error - 4/27/2010 1:54:17 PM | Computer Name = RonCobb-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\Ron Cobb\AppData\Local\Adobe\Updater6\Install\reader9rdr-en_US\AdbeRdr920_en_US.msi
failed, 00000005.

[ Application Events ]
Error - 4/24/2010 9:21:16 AM | Computer Name = RonCobb-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 4/24/2010 9:21:21 AM | Computer Name = RonCobb-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 4/24/2010 9:21:21 AM | Computer Name = RonCobb-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 4/24/2010 9:21:21 AM | Computer Name = RonCobb-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 4/26/2010 5:20:06 PM | Computer Name = RonCobb-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 9.1.0.163, time stamp 0x49a88f00,
faulting module JP2KLib.dll, version 2.0.0.2579, time stamp 0x4973c3d7, exception
code 0xc0000005, fault offset 0x0000abaa, process id 0x1894, application start time
0x01cae586170a4d90.

Error - 4/27/2010 1:57:01 PM | Computer Name = RonCobb-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/28/2010 11:07:34 PM | Computer Name = RonCobb-PC | Source = Application Error | ID = 1000
Description = Faulting application Urlbook.exe, version 0.0.0.0, time stamp 0x2a425e19,
faulting module kernel32.dll, version 6.0.6002.18005, time stamp 0x49e038c0, exception
code 0x0eedfade, fault offset 0x0001e124, process id 0x90c, application start time
0x01cae7490794fb7e.

Error - 4/28/2010 11:08:24 PM | Computer Name = RonCobb-PC | Source = WinMgmt | ID = 10
Description =

Error - 5/2/2010 8:18:41 PM | Computer Name = RonCobb-PC | Source = Application Error | ID = 1000
Description = Faulting application Urlbook.exe, version 0.0.0.0, time stamp 0x2a425e19,
faulting module kernel32.dll, version 6.0.6002.18005, time stamp 0x49e038c0, exception
code 0x0eedfade, fault offset 0x0001e124, process id 0x96c, application start time
0x01caea5625e482d9.

Error - 5/2/2010 8:19:39 PM | Computer Name = RonCobb-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 12/21/2009 9:02:48 AM | Computer Name = RonCobb-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 12/21/2009 9:02:58 AM | Computer Name = RonCobb-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 12/21/2009 9:02:58 AM | Computer Name = RonCobb-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 12/28/2009 11:02:50 AM | Computer Name = RonCobb-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 12/28/2009 11:03:15 AM | Computer Name = RonCobb-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 12/28/2009 11:03:15 AM | Computer Name = RonCobb-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 12/29/2009 1:28:37 PM | Computer Name = RonCobb-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 12:26:18 PM on 12/29/2009 was unexpected.

Error - 12/29/2009 1:30:08 PM | Computer Name = RonCobb-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 12/29/2009 1:30:22 PM | Computer Name = RonCobb-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 12/29/2009 1:30:22 PM | Computer Name = RonCobb-PC | Source = Service Control Manager | ID = 7026
Description =


< End of report >
Ok ron, please follow the instructions:

Run OTL.exe

  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL



    :OTL
    
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    
    
    TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
    
    
    
    :Commands
    
    [purity]
    
    [emptytemp]
    
    [start explorer]
    
    [Reboot]


  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done

  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

NEXT

Please do the following:



  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:





c:\windows\neoqaz2.dll



  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


Tell me also how is your PC running now?
OTL ran successfully with Code provided.

c:\windows\neoqaz2.dll scanned through IE7 at virscan.org with no malware found.

Logs below.


Thanks,

Ron Cobb

==========================================================
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: Ron Cobb
->Temp folder emptied: 902193787 bytes
->Temporary Internet Files folder emptied: 119482659 bytes
->Java cache emptied: 58706584 bytes
->FireFox cache emptied: 100749849 bytes
->Flash cache emptied: 89011 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 69915 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 9737305 bytes



===========================================================

Total Files Cleaned = 1,136.00 mb


OTL by OldTimer - Version 3.2.5.0 log created on 05282010_082911

Files\Folders moved on Reboot…
File move failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot…




=============================================================

VirSCAN.org Scanned Report :
Scanned time : 2010/05/28 08:44:45 (EDT)
Scanner results: Scanners did not find malware!
File Name : neoqaz2.dll
File Size : 108 byte
File Type : data
MD5 : 9e4b56bec71dea09b4b3c0f63a35c0b4
SHA1 : 926099e742cc6a10d5f28d08421f80e500e23521
Online report : http://virscan.org/report/c4bbe2015c0023ab…e8498bd064.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.0.0.8 00050000000000 0005-00-00 40.09 -
AhnLab V3 2010.05.28.01 2010.05.28 2010-05-28 40.09 -
AntiVir 8.2.1.242 7.10.7.193 2010-05-28 0.26 -
Antiy 2.0.18 20100525.4450001 2010-05-25 0.02 -
Arcavir 2009 201005271153 2010-05-27 0.02 -
Authentium 5.1.1 201005280128 2010-05-28 1.27 -
AVAST! 4.7.4 100528-0 2010-05-28 0.00 -
AVG 8.5.793 271.1.1/2901 2010-05-28 0.23 -
BitDefender 7.90123.6104095 7.31876 2010-05-28 3.94 -
ClamAV 0.96.1 11090 2010-05-28 0.00 -
Comodo 3.13.579 4942 2010-05-25 40.08 -
CP Secure 1.3.0.5 2010.05.28 2010-05-28 0.00 -
Dr.Web 5.0.2.3300 2010.05.28 2010-05-28 7.45 -
F-Prot 4.4.4.56 20100528 2010-05-28 1.28 -
F-Secure 7.02.73807 2010.05.28.03 2010-05-28 0.09 -
Fortinet 4.1.133 11.989 2010-05-27 40.09 -
GData 21.244/21.81 20100528 2010-05-28 40.09 -
ViRobot 20100525 2010.05.25 2010-05-25 40.09 -
Ikarus T3.1.01.84 2010.05.28.75954 2010-05-28 6.52 -
JiangMin 13.0.900 2010.05.27 2010-05-27 40.09 -
Kaspersky 5.5.10 2010.05.28 2010-05-28 0.03 -
KingSoft 2009.2.5.15 2010.5.28.12 2010-05-28 40.09 -
McAfee 5400.1158 5995 2010-05-27 16.42 -
Microsoft 1.5802 2010.05.28 2010-05-28 40.09 -
Norman 6.04.12 6.04.00 2010-05-27 8.02 -
Panda 9.05.01 2010.05.27 2010-05-27 40.09 -
Trend Micro 9.120-1004 7.204.08 2010-05-28 0.02 -
Quick Heal 10.00 2010.05.28 2010-05-28 40.09 -
Rising 20.0 22.49.04.04 2010-05-28 40.09 -
Sophos 3.07.1 4.53 2010-05-28 3.58 -
Sunbelt 3.9.2424.2 6366 2010-05-27 40.09 -
Symantec 1.3.0.24 20100527.009 2010-05-27 0.89 -
nProtect 20100527.02 8509573 2010-05-27 40.09 -
The Hacker 6.5.2.0 v00288 2010-05-27 40.10 -
VBA32 3.12.12.5 20100527.2036 2010-05-27 2.59 -
VirusBuster 4.5.11.10 10.126.53/2032268 2010-05-27 2.33 -
My computer is running fine. The worry was that a keystroke logger was running, as I suspected that my email password had stolen somehow. See my initial post about the spam emails being send from my AOL account. This happened at least two times over a period of several months, even after I changed my password. The spam emails from my account have ceased since I last changed my email password. I am beginning to think that the AOL server itself might have been hacked to send these spam emails from my account, rather than my desktop PC - this is assuming you saw no evidence of a keystroke logger operating on my system. Thanks, matrix, I appreciate your assistance. Ron Cobb
Hi Ron,

The spam emails from my account have ceased since I last changed my email password. I am beginning to think that the AOL server itself might have been hacked to send these spam emails from my account, rather than my desktop PC - this is assuming you saw no evidence of a keystroke logger operating on my system.

Your assumption is correct. Your system seems clean but you did well changing your passwords. We need to do a couple of more things before closing this topic though.

Please download Malwarebytes' Anti-Malware from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

NEXT


Please do a scan with Kaspersky Online Scanner or from Here.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
  • Then, click: Save
  • Please post the Kaspersky Online Scanner Report in your reply.

[external image: Posted Image]


Things I'll need in your next reply:


  • MBAM log
  • Kaspersky log
MBAM log below. I could not download Kaspersky. I received a message that it required Java Framework version 1.6 or higher. I have not allowed recent Java updates, because when I did many programs on my 64bit Vista system ceased to run correctly. I think there is not some incompitability with FireFox or Vista64. Each time I try the Java update, I must restore my computer to make my applications run correctly again. I am hesitant to try Java updates again. I know I should update to Windows 7, but have not had the time. I think many of the Vista64 problems are corrected in Windows 7. Thanks, Ron Cobb =============================== Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4161 Windows 6.0.6002 Service Pack 2 Internet Explorer 7.0.6002.18005 6/1/2010 8:55:08 AM mbam-log-2010-06-01 (08-55-08).txt Scan type: Quick scan Objects scanned: 120773 Time elapsed: 3 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
We can try other online scanner - ESET.

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Thie si the content of the Eset log file: ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK ============================== This is the list of threats found and listed in the Eset results window : J:\Backup Set A - C and G-1 Restored\HP Omnibook Files\My Documents\setupwavtomp3.exe a variant of Win32/Adware.Ezula application J:\Old G Drive Restored Partial\HP Omnibook Files\My Documents\setupwavtomp3.exe a variant of Win32/Adware.Ezula application These are on a usb drive that contains old data restored from earlier computers. It is not accesses often. Should I simply delete these? Thanks Ron Cobb

These are on a usb drive that contains old data restored from earlier computers. It is not accesses often. Should I simply delete these?

Yes, delete the files!

  • Click START then RUN
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.

🖼Click to load external image (Posted Image)

NEXT


Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.



NEXT


Lets update your Java to make your system more secure

Download the latest version Here save it, do not install it yet.

Java SE Runtime Environment (JRE)JRE 6 Update 20 <–The wording is confusing but this is what you need

  • Go to your Add Remove Programs in the Control Panel and uninstall any previous versions of Java
  • Reboot your computer
  • Install the latest version



NEXT


Update Adobe Reader.


Run Adobe Reader. Go to Help > Check for updates.
Follow the prompts.

Now, before I give you my Closing speech and close this topic do you have any questions?
The virus files were deleted from the J: drive Programs uninstalled as instructed. Java and Adobe are updated successfully. My system runs fine Thanks Ron Cobb

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI